Snapshot 64091
Normalized text
Scripts and page chrome removed; this is what change detection compares.
GLOBAL PRIVACY NOTICE
This Global Privacy Notice ("Notice") explains why and how RWS Holdings plc and its subsidiaries ("RWS", "we", "us", or "our" whether collectively or individually as applicable) process your personal data.
"Subsidiaries" has the meaning given in section 1159 of the UK Companies Act 2006. This Notice applies to all companies in the RWS Group; a full list is available at RWS Companies.
"Personal data" means any information relating to an identified or identifiable natural person — that is, someone who can be identified, directly or indirectly, by reference to a name, identification number, location data, online identifier, or other factors specific to that person's physical, physiological, genetic, mental, economic, cultural, or social identity.
We are committed to protecting and handling your personal data responsibly, in compliance with applicable data protection and privacy laws, including:
EU General Data Protection Regulation of 2016 ("GDPR")
UK Data Protection Act of 2018 ("DPA")
Canada Personal Information Protection and Electronic Documents Act of 2000 ("PIPEDA")
California Consumer Privacy Act of 2018 ("CCPA")
Brazil General Personal Data Protection Law of 2018 ("LGPD")
Australia Privacy Act 1988 ("Privacy Act")
Who is the entity responsible for your personal data?
Under applicable privacy laws, the "controller" is the entity that determines why and how personal data is processed.
The controller of your personal data is the RWS group company operating in your country or region, unless RWS Holdings plc or another RWS group company identifies itself as the controller for a specific interaction.
Where RWS processes personal data on behalf of another organization, we act as a processor. This applies, for example, when you use our localization services. In those cases, a separate Data Processing Agreement governs our responsibilities, and the other organization's privacy notice applies to you.
This Global Privacy Notice applies only where RWS acts as a controller.
If you use RWS products or services through your employer
If you use RWS products or services licensed to your employer or another organisation, or if your organisation has engaged RWS to provide services and you are a point of contact, your records will be associated with that organisation. Your use of those products or services is subject to your organisation’s policies and the contract between your organisation and RWS. Other authorised users within your organisation may be able to monitor your activity, configure product settings (including privacy and security settings), and access data you enter. For any privacy questions about products or services licensed to your organisation, please contact your employer in the first instance.
Where we have a contract to provide services to an organisation and that organisation shares your personal data with us so that we can interact with you for the purposes of delivering those services, we process that data on the basis of our legitimate interests in fulfilling our contractual obligations.
In the event of any conflict between this Notice and any contract or Data Processing Agreement between RWS and a customer, the terms of that contract or agreement will prevail.
What does this notice cover?
This Notice applies whenever we collect and process your personal data through our interactions with you, including via our websites, applications, software, products and services, events, marketing activities, supplier engagements, recruitment, product licensing, support channels, or visits to our offices.
This Notice describes our collection, use, and sharing of your personal data for the purposes and on the lawful bases set out below. Where appropriate, we will provide additional information at the point of collection and, where required, seek your consent.
When you visit our websites, complete a form, download content, or create an account, we will provide you with relevant privacy information, including through our Cookie Notice.
When there are product-specific privacy notices, we will provide them separately.
What personal data do we collect?
We process personal data you provide directly to us, collected through automated means, or obtained through other sources.
Personal data we collect directly from you
Contact data. We collect contact details when you sign up to receive communications, attend one of our events, visit our offices, work with us, download our content, subscribe to our newsletters, or ask us to respond to a query. The personal data we collect includes your name, personal and business email and postal addresses, telephone number, job title, company, role, country of residence, and language preferences.
Marketing and communications data. We collect personal data relating to your preferences regarding receiving marketing information from us and your communication preferences (as permitted under applicable privacy laws).
Financial and payment information. We collect bank account details, payment card information, billing addresses, and transaction information as necessary to process orders, manage accounts, and fulfil contracts.
Service and support information. We collect information relating to the use of our product and services, course enrolments, test results, certification records, support queries, correspondence, feedback, complaints, and enquiries.
Recruitment information. Where you apply for a position with us, we collect CVs, applications, references, background checks, right-to-work documents, and related information.
Event information. We collect event registration details when you sign up to attend events, webinars or activities hosted or co-hosted by RWS.
Account and security information. We collect usernames, passwords, and security-verification information to manage your account access and ensure the security of our systems.
Personal data we collect through automated means
Data relating to your use of our website(s). We collect personal data about how you use our website(s) and applications. This includes data relating to the pages you visit, the services or information you search for, and the links and content you choose to access, for the purposes of improving our products and services, trouble-shooting and customer support.
Technical data. We collect personal data about the device(s) you use to access our website(s) and applications, including your IP address, approximate location, device, operating system, browser, and cookie data. For more information on the cookies we use and the purposes for which we use them, see our Cookie Notice.
Data we collect from other sources
We may collect personal data about you from third parties. Such third parties include business partners, resellers, payment and credit providers, due-diligence and marketing providers, referrals, and publicly available sources. We may also collect personal data where you register and/or attend an event which we host or are a named affiliate partner of.
Sensitive personal data
In some cases, we may collect sensitive personal data (also known as Special Category Data). We process such data only where we have a lawful basis to do so — for example, where you have given explicit consent. For details, see the processing activities table above.
Why do we collect your personal data?
Processing Activity Types of data used Lawful basis
Providing products, services, support and maintenance: We process personal data to deliver our translation, localisation, IP support, and language technology services. Contact details, account information, service and support-related data, communications, technical data Performance of a contract
Processing orders, billing and payments: Managing orders, invoices, and payment processing. Contact details, financial and payment information Performance of a contract
Account administration: Creating and maintaining your account, verifying your identity, and managing access. Contact details, identity, account and security information Performance of a contract
Supplier contract fulfilment: Engaging and managing suppliers and freelancers who support our service delivery. Contact details, financial and payment information, communications Performance of a contract
Recruitment and employment management: Managing applications, conducting interviews, background checks, onboarding and ongoing administration. Contact details, identity, recruitment information, communications, sensitive data (as required) Performance of a contract; Legal obligation (right-to-work verification); Legitimate interests (suitability assessments); Explicit consent (where required for sensitive personal data)
Background checks: Where permitted by law, to assess candidate suitability. Identity, recruitment information Legitimate interests (determining suitability)
Certification programmes: Managing enrolment, assessment, and — where applicable — publication of your certification status in connection with RWS product certification programmes. Contact details, identity, service and support information, test results and certification records Performance of a contract; Consent (for publication of certification status)
Marketing and business development: Sending newsletters, information about our services, managing events, and generating leads. Contact details, marketing and communications data, event information, data from third parties Legitimate interests or Consent (where expressly provided)
Direct marketing to existing customers: Sending electronic marketing about similar products or services to individuals who have previously purchased from or enquired with RWS. Contact details, purchase and enquiry history, marketing preferences Legitimate interests. You may opt out at any time.
Receiving personal data from third parties: Collecting personal data from business partners, lead-generation providers, and publicly available sources to identify potential customers or verify existing relationships. Contact details, professional information, data from third parties Legitimate interests (business development and relationship verification)
Service improvement and personalisation: Analysing usage patterns to improve our services, websites, and content relevance. Technical data, website/product usage data, service and support information Legitimate interests
Analytics in marketing communications: Using tracking technologies (such as tracking pixels) in marketing emails to understand engagement, and to maintain the security and deliverability of our email systems. Technical data, marketing and communications data, email interaction data Consent (for marketing analytics, where required by applicable law); Legitimate interests (for system security and delivery management)
Security and fraud prevention: Protecting against malicious activity, ensuring network and information security, and preventing fraud. Technical data, account and security information Legitimate interests
Complaints and correspondence handling: Managing and responding to complaints, data subject requests, and general correspondence, including from individuals who are not customers or suppliers. Contact details, communications, any personal data relevant to the complaint or request Legitimate interests; Legal obligation (where responding to data subject rights requests)
Compliance with tax, accounting, corporate, employment and regulatory obligations: Including lawful requests and sanctions screening. All personal data listed above as relevant and proportionate to the purposes Legal obligation
With whom do we share your personal data?
We do not sell your personal data.
General principle. We share personal data only where it is necessary to provide you with requested services or to carry out legitimate business functions. Access is controlled on a need-to-know basis and subject to appropriate contractual and security safeguards.
Information shared with third-party service providers. We use a number of third parties to perform business functions on our behalf. These service providers act as processors and are contractually bound to comply with our instructions and to protect your personal data. We will only disclose the information necessary to enable them to perform their services. They may include:
cloud hosting and infrastructure providers;
payment processors and financial service providers;
analytics and marketing service providers;
customer service and support platforms;
debt collection agencies;
certification and examination providers;
IT security and communications providers; and
third-party cookie and analytics providers, as described in our Cookie Notice.
Channel partners and resellers. Where RWS operates through authorised partners or resellers in your country or industry sector, we may share your contact details with them so they can provide you with information about our products and services. These partners act as independent controllers of your personal data and are subject to their own privacy notices.
Professional advisers and due diligence providers. We may share personal data with lawyers, auditors, insurers, consultants, referees, background-check and sanctions-screening providers, where necessary for our operations, recruitment, or compliance activities.
Group company transfers. We share your personal data within the RWS group for the purposes described in this Notice. These transfers are governed by an Intra-Group Data Transfer Agreement, which provides appropriate safeguards for transfers of personal data across jurisdictions. For further information on these intra-group data transfers, please contact privacy@rws.com.
Transaction counterparties. We may disclose personal data to potential buyers, investors, joint venture partners, and other parties involved in a merger, acquisition, sale, restructuring, or similar corporate transaction. For example, if part of our business is sold, we may provide the relevant customer or supplier data as part of that transaction.
Disclosures required or permitted by law. Where required or permitted by law, personal data may be provided to regulators, law enforcement agencies, and courts — for example, in response to a court order, a regulatory request, or where we believe it is necessary to investigate, prevent, or act regarding illegal activities.
Protecting our rights and security. We may also share personal data where necessary to defend legal claims, enforce our terms of service, or protect the rights, safety, or security of RWS, our customers, or others.
How do we transfer your personal data internationally?
RWS is a global group with offices, subsidiaries, and service providers located around the world. Your personal data may be transferred to, stored in, or accessed from countries other than the country in which you are located, including countries that may not provide the same level of data protection as your home jurisdiction.
Where we transfer personal data outside the UK, the European Economic Area (EEA), or other jurisdictions with transfer restrictions, we ensure that appropriate safeguards are in place. These may include:
transfers to countries that have been recognised as providing an adequate level of data protection.
standard contractual clauses approved by the European Commission or the UK Information Commissioner’s Office.
our Intra-Group Data Transfer Agreement, which governs transfers between RWS group companies.
other transfer mechanisms permitted under applicable law.
The RWS group entities based in the United States — including SDL Inc (together with SDL XyEnterprise LLC) — are certified under the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. For further information, please see our United States Data Privacy Notices
What about third-party websites and integrations?
Our websites and services may include links to, or integrations with, third-party websites, applications, plugins, widgets, or authentication providers ("Third-Party Tools"). These Third-Party Tools operate independently from RWS and may collect, use, or share information about you in accordance with their own privacy practices.
Where you choose to interact with such features — for example, by following an external link, using an embedded tool, or authenticating through a third-party provider — the relevant third party may process certain information about you. Where you connect a third-party account or authenticate through a third-party provider, we may also receive certain profile information in accordance with your settings on that service.
RWS is not responsible for the privacy, security, or content of Third-Party Tools, and this Notice does not apply to their processing activities. We encourage you to review the privacy notices of any third-party services you choose to use.
How do we use artificial intelligence?
RWS uses artificial intelligence ("AI") technologies, including generative AI, machine translation, and machine learning, to support our business operations and the processing activities described throughout this Notice.
Where we engage third-party suppliers to provide AI-powered services that process your personal data, we ensure that appropriate contractual safeguards are in place and that such providers comply with applicable data protection requirements.
We have implemented internal safeguards to ensure that any personal data processed using AI is handled securely and in accordance with applicable law, including data minimisation, purpose limitation, and appropriate access controls.
For detailed information on our AI-powered products — including the data they use, the legal bases we rely on, the security measures we apply — please refer to our product-specific AI Privacy Transparency Notices:
Language Weaver — AI-powered machine translation, including Neural Machine Translation, Adaptive Machine Translation and LLM-based translation
Trados — AI-powered translation, localisation and content transformation
Tridion Agentic Platform — Tridion Agent, Tridion Connect and Tridion Docs Genius
As our AI capabilities evolve, we will publish additional notices to ensure you always have clear visibility into how AI is used across the RWS product portfolio.
How long do we retain your personal data?
We will keep your personal data for as long as is necessary to fulfil the relevant purpose, for the length of time regulators, professional bodies, or associations require us to retain records, and to comply with tax, company laws and regulations, including contractual obligations.
Retention periods vary depending on the data category and the purpose for which the data is processed. For example, we will retain data relating to a contract for as long as the contract is in force and for a reasonable period thereafter in accordance with applicable legal and compliance requirements. Marketing contact data is retained until you opt out or we no longer have a legitimate basis to contact you. In situations where we process payment card information, this data is only retained for the duration of the subscription and until all payments are processed, and is then deleted without delay.
After this time, your personal data will either be securely deleted, destroyed, or anonymised. We may retain minimal items of your personal data for the purpose of recording your opt-out preferences, including where you have requested the deletion of your personal data.
You may request further information about our retention periods by contacting us using the details set out in "Contact us" below, or request that we delete your data as set out in "Your rights" below. All such requests will be considered in accordance with the applicable law.
How do we ensure your personal data is safe?
RWS implements and maintains administrative, organisational, technical and physical security measures to safeguard our systems and your personal data against unauthorised access, unlawful processing, accidental loss, destruction and damage. These measures include relevant encryption of data in transit between your device and RWS systems, and hosting of our products with third-party providers implementing industry-leading security standards.
We also require that our service providers and any approved external third parties who process personal data on our behalf implement a level of security and data protection at least as stringent as set out in this Notice and to the standard required by applicable law.
In the event that RWS becomes aware of a personal data breach, we will comply with all applicable requirements to notify affected individuals and relevant supervisory authorities in accordance with the applicable law.
What are your rights?
Depending on the applicable privacy laws in your jurisdiction, you may have some or all of the following rights in relation to your personal data. Not all rights are available in every jurisdiction. Where a right does not apply under your local law, we will let you know. You will not be subject to any adverse consequences for exercising your rights.
Accessing your personal data. You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about how it is being used.
Requesting correction of your personal data. You have the right to have incomplete or inaccurate personal data corrected. If you believe the personal data we hold about you is incorrect, please let us know and we will rectify it.
Requesting erasure of your personal data. You may ask us to delete your personal data where you believe we no longer need it. We may be required to retain certain data to comply with legal obligations or to support legitimate business purposes; where this applies, we will let you know.
Requesting restriction of processing. In certain circumstances, you can ask us to temporarily restrict our processing of your personal data — for example, while we are investigating a complaint or verifying the accuracy of your data. While restricted, we may continue to store the data but will not otherwise process it without your consent.
Objecting to processing. Where we rely on legitimate interests (or those of a third party) as our lawful basis, you have the right to object if you believe the processing impacts your fundamental rights and freedoms. You also have the right to object at any time to the use of your personal data for direct marketing, including profiling related to direct marketing. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Requesting data portability. In certain circumstances such as where our processing is based on performance of contract, and is carried out by automated means, you may ask us to provide your personal data in a structured, commonly used, machine-readable format, or to transmit it directly to another controller where technically feasible. This right applies only to personal data you have provided to us.
Withdrawing consent and opting out of marketing. Where we process your personal data based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew. If you receive marketing communications from us, you can opt out at any time by clicking the "unsubscribe" link in the communication or by updating your preferences at our Preference Centre. Please note that opting out of marketing will not affect non-marketing communications, such as service updates or messages relating to your account.
Automated decision-making. You have the right to be informed about any use of your personal data to make solely automated decisions about you — including profiling — that produce legal or similarly significant effects. Where such processing takes place, you have the right to obtain meaningful information about the logic involved, the significance of the decision, and its envisaged consequences, and to request human intervention or contest the decision.
How to exercise your rights
You can exercise any of the rights described above by:
updating your preferences through our Preference Centre at https://www.rws.com/about/preference-centre/.
emailing us at privacy@rws.com.
We will respond to all legitimate requests within the time frames required by applicable law. We will verify your identity before acting on your request.
Making a complaint
We will do our best to resolve any complaint. However, if you feel we have not adequately addressed your concerns, you have the right to complain to your local data protection authority. For example, in the UK, you can contact the Information Commissioner's Office (ICO). For a list of supervisory authorities, please visit RWS Companies. You may also have the right to pursue a judicial remedy under applicable law.
How will we update this notice?
This Notice may be updated from time to time to reflect changes in law, best practice, changes in our business, or changes in the way we handle personal data. The date of the most recent revision will appear at the top of this page under "Last Updated".
We encourage you to review this Notice periodically.
How can you contact us?
If you have any questions about this Notice, you can contact our Trust, AI & Privacy Office in any of the following ways:
Contact: Christel Cao-Delebarre, Group VP Head of Trust, AI & Privacy
Email: privacy@rws.com
Address: Trust, AI & Privacy Office, RWS Holdings plc, Compass House, Vanwall Business Park, Vanwall Road, Maidenhead, Berkshire SL6 4UB, United Kingdom
RWS Holdings plc is a company registered in England with registered number 03002645.
Which law governs this notice?
This Notice is governed by the laws of England and Wales, except where the data protection law of your country of residence or the country in which the relevant RWS entity operates applies by mandatory operation of law.
Version 1.4
Last Updated: 21/09/2026