Privacy Policy | Validus Risk Management

Privacy Policy

As of June 2026

1. Who We Are

The Validus Group consists of various legal entities, including Validus Risk Management Limited, Validus Europe AS, Validus NA Inc., Validus USA, Inc, Validus Group Limited and Validus Risk Management Asia Pte Ltd. The “Validus Group”, “we”, “our” or “us” means the Validus Group entity responsible for the collection and use of personal data depending on the jurisdiction. The Validus Group may process certain personal data about you, depending on the scope of your specific relationship with us. This processing of personal data is regulated under the: Data Protection Act of the United Kingdom, General Data Protection Regulation (2016/679), including the Law on the Processing of Personal Data applicable in Norway ( together the GDPR) and the e-Privacy Directive (2002/58/EC), which both apply across the European Union, Personal Data Protection Act (PDPA), Personal Information Protection and Electronic Documents Act (the PIPEDA), New York Privacy Act (together referred to as the Data Protection Laws). Depending on the activity, we are responsible as ‘data controller’ of your personal data for the purposes of Data Protection Laws.

2. What Does This Privacy Notice Cover?

This privacy notice (the Privacy Notice) will apply when you:

  • directly and/or indirectly use our services as a potential or current client or representative;
  • visit and use our website;
  • apply for a role with us and
  • have been contacted through our direct marketing strategy, either via phone or

3. Data Protection Principles

We take your privacy seriously and we are committed to collecting and using your personal data fairly and in accordance with requirements of applicable data protection legislation. We will comply with the principles set out in the Data Protection Laws, which state that the personal data we hold about you must be:

  • used lawfully, fairly and in a transparent way;
  • with your consent, a request for which shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language;
  • collected only for valid purposes that we have clearly explained to you;
  • relevant to the purposes we have told you about and limited only to those purposes;
  • accurate and kept up to date;
  • kept only as long as necessary for the purposes set out in this notice, including to meet legal, regulatory, accounting, or reporting requirements and;
  • kept securely

Personal data means any information about an individual from which that person can be identified.

4. Personal Data We Collect About You

We may ask for and collect from you personally identifiable and other information at certain points via our website and via your relationship and interactions with us. We may collect, use, store, transfer or otherwise process different kinds of data about you, as follows:

  • Identity data including your name, date of birth, place of birth, gender, nationality, copies of your identity card, passport and/or driving licence, right to work and, where offered to us, data relating to your education and employment background.
  • Contact data including your billing/registered/residential address, email address, telephone number and emergency contact information.
  • Client-related data including business information, relationship with you (or with a client of whom you are an employee or other staff member), information about any shareholdings, business contact details.
  • Financial data including your bank account details, your tax status information, your tax identification number and your fiscal residence.
  • Other background identification data including evidence of beneficial ownership and source of funds to comply with our client due diligence, know your customer (“KYC”) and anti-money laundering regulations and collected as part of our client acceptance and ongoing monitoring procedures as required by law.
  • Usage data including data obtained through your use of our website or interface that we provide to you through our website as well as data collected through cookies, server logs and other similar tracking technologies.

We may collect data relating to criminal convictions and offences subject to compliance with the strict conditions set out under the applicable data protection legislation.

5. How and Why We Collect / Use Personal Data

We use your personal data mainly to: interact with you; to provide you with support services; to make it easy to navigate our website; to improve our website and our products; and to offer you content and services that might interest you. Your information may be stored and processed by us in the following ways and for the following purposes (by way of a non-exhaustive list):

  • understanding your needs and interests;
  • allowing you to use and access the functionality provided by our website services;
  • communicating with you, where you have requested or consented, regarding any service or any other situation where you have engaged us to provide you with information;
  • recording of incoming and outgoing calls for training, monitoring, and security purposes;
  • identification verification, money laundering and other checks to confirm your identity and to ensure that the investments which we handle for you are done in compliance with our legal obligations;
  • reviewing and improving the performance of our website and your use of it (including any personalisation which you may have indicated and which we have retained using cookies;
  • managing and administering our business;
  • complying and assessing compliance with applicable law, rules and regulations and internal policies and procedures;
  • administering and maintaining databases that store information;
  • for marketing communications (where it is lawful for us to do so and where you have not objected to the use of your information for these purposes);
  • identifying and evaluating candidates for potential employment, as well as for future roles that may become available;
  • maintaining records in relation to recruiting and hiring;
  • conducting background checks (if you receive an offer from us) including, to the extent permitted by applicable law, criminal history checks; or
  • to deal with requests from you to exercise your rights under data protection

Where we need to collect, or you are required by law or contract to provide, personal data, and you fail to provide the personal data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services). In this case, we may have to decline to provide or receive the relevant services. We process your personal data on the basis of one or more of the following legal grounds: performance of a contract, compliance with a legal obligation, our legitimate interests (provided these are not overridden by your rights), and, where applicable, your consent.

6. Who Your Personal Data May Be Shared With?

We may share your personal information with other group companies, affiliates and other third parties to help us process your personal information for the purposes set out in this Privacy Notice. This may include:

  • Contractors, sub-contractors, business partners, introducers, suppliers and/or service providers within Validus Group and its subsidiaries that help us perform our business functions;
  • Legal, regulatory or competent , authorities in connection with any investigation to help prevent unlawful activity;
  • Legal representatives and consultants in situations where expert advice and legal opinions are required; and/or
  • Processors that maintain our IT

Your personal data is never sold and any personal data that is shared is in line with the Data Protection Laws.

7. How Long Your Personal Data Will Be Kept

We will maintain your personal data through-out the lifecycle of the contract. We may need to keep your data for a longer period where we need to retain personal data to comply with legal or regulatory requirements, such as to help us respond to complaints or preventing fraud and financial crime. If we are not required to retain the personal data, we will destroy, delete or anonymise it at the point it is no longer required.

8. Keeping Your Personal Data Secure

We store your personal data in a secure environment. We have appropriate security measures in place to prevent personal data from being lost, accessed or used in an unauthorised way, including encryption and other forms of security. We limit access to your personal data to those who have a genuine business need to know it. Those processing your personal data will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Whilst we will use all reasonable efforts to secure your personal data, in using the website you acknowledge the use of the internet is not entirely secure and for this reason we cannot guarantee the security or integrity of personal data that is transferred from you.

9. Storage, Transfers and Retention –  Outside of the United Kingdom

We may transfer your personal data outside the United Kingdom and/or European Economic Area, including to jurisdictions which may not provide an equivalent level of protection. Where we do so, we ensure that appropriate safeguards are in place in accordance with applicable data protection laws.

These safeguards may include adequacy regulations, the UK International Data Transfer Agreement (or UK Addendum), the EU Standard Contractual Clauses, and other legally recognised mechanisms. Where relevant, we carry out transfer risk assessments and apply supplementary measures to ensure your data remains protected. Further details of these safeguards are available on request.

10. Marketing

We would like to send you information about our services and our business, which may be of interest to you. Such information could be sent by email, or telephone.

We will ask whether you would like us to send you marketing messages on the first occasion that you provide any relevant contact information. If you do opt in to receive such marketing from us, you can opt out at any time (see section 12 below: ‘What rights do you have?’ for further information). If you have any queries about how to opt out, or if you are receiving messages, you do not want to, you can contact us using the details provided below.

11. Your Rights and Choices

We would like to make sure you are fully aware of all your data protection rights.

You have the right to opt out of the processing of your personal data for the purposes described above at any time. If you wish to exercise this right, please contact us by email atlandc@validusrm.com. We will process your request promptly and in accordance with applicable data protection laws.

The right to access – You have the right to request us for copies of your personal data and how we process the data. This is called a data subject access request and you can make a request by writing to us using the contact details below. We may require further information from you in order to verify your identity before disclosing any personal information to you.

The right to rectification – You have the right to request that we correct any personal data you believe is inaccurate. You also have the right to request we complete personal data you believe is incomplete.

The right to erasure – You have the right to request that we erase your personal data, under certain conditions. If you enforce this right at the same time as you object to the processing we will have to maintain basic identification data to ensure we do not contact you again.

The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.

The right to object to processing – You have the right to object to our processing of your personal data, this means if you do not want to be contacted for the purposes set out in this notice then we will stop processing your data.

The right to complain – In certain jurisdictions you may also have the right to lodge a complaint with a data protection authority (see “Complaints” below).

The right to data portability –  In certain jurisdictions you may also have  the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions.

If you wish to exercise any of the rights set out above, you can contact us using the details at the end of this Privacy Notice. If you make a request, we have one month to respond to you.

From time to time, we may have other methods to unsubscribe (opt-out) from any direct marketing including, for example, unsubscribe buttons or weblinks. If such are offered, please note that there may be some period after selecting to unsubscribe in which marketing may still be received while your request is being processed.

12. Changes to the Privacy Notice

We may update or amend this Privacy Notice from time to time. You should check this Privacy Notice frequently to ensure you are aware of the most recent version that will apply each time you access this website. We will also attempt to notify users of any changes by:

  • Email if you have opted to receive emails; and/or
  • A notice on the website

13. Contacting Us

If you have any questions about this Privacy Notice or the personal data we hold about you, please contact us by:

  • Email – landc@validusrm.com
  • Post – 90 Whitfield Street, 5th Floor, London, UK, W1T4EZ

14. Complaints

If you have any concerns or complaints regarding the way in which we process your personal data, please contact us in the first instance using the contact details set out above. We are committed to investigating and resolving complaints in a fair and timely manner.

If you are not satisfied with our response, you have the right to lodge a complaint with the competent data protection authority in the jurisdiction in which you are located, work, or where the alleged infringement has occurred.

For individuals in the United Kingdom, the relevant supervisory authority is the Information Commissioner’s Office (ICO). Further details can be found at this website:
Make a complaint to the ICO

For individuals located in other jurisdictions (including Norway, Canada, or Singapore), you may contact your local data protection authority or regulator: