1. Personal Data
Personal data refers to information that can identify an individual when used alone or in combination with other information. Such data is submitted to us by you when you use our websites, products, or services, or when you interact with us. Alternatively, we may obtain it by recording how you interact with our websites, products, or services, for example, through technologies such as cookies. The data we collect depends on the websites you visit or the products and services you use, and may include personal data such as your name, address, email address, phone number, and similar information. We collect personal data to contact you for the purpose of providing relevant services or sending important notifications.
2. Privacy Policy
W&H Law Firm and its global affiliates (hereinafter referred to as “W&H,” “we,” or “our”) fully recognize the importance of personal data to our clients and users. To this end, W&H Law Firm places great emphasis on protecting the personal data of our clients and users, and has implemented a series of measures to ensure that relevant business operations comply with applicable personal data protection requirements (such as the GDPR).
2.1 To ensure effective implementation of personal data protection requirements, Beijing W&H Law Firm has appointed a Data Protection Officer (DPO).
2.2 Beijing W&H Law Firm employs industry-recognized personal data protection methods and practices. In business scenarios subject to the GDPR, the firm utilizes Data Protection Impact Assessments (DPIAs) to evaluate and mitigate personal data security risks within its products and services.
2.2.1 Beijing W&H Law Firm requires a comprehensive assessment of personal data involved in products and services, with projects involving personal data subject to a Data Protection Impact Assessment (DPIA).
2.2.2 Projects involving personal data must establish data inventories and data flow diagrams;
2.2.3 Items involving personal data shall identify potential risks throughout the data processing lifecycle (including collection, use, storage, sharing, deletion, etc.) and implement corresponding measures (including administrative, physical, and technical measures) based on risk levels.
2.2.4 After completing the DPIA, a corresponding report must be produced and approved by the DPO.
2.3. Beijing W&H Law Firm has implemented technical measures including intrusion detection, access control, encryption, data leak prevention, anti-spam, endpoint security protection, and vulnerability scanning. The firm also conducts penetration testing to verify the effectiveness of its personal data protection measures.
2.4. Beijing W&H Law Firm has established a personal data breach emergency response mechanism. In the event of a personal data breach, Beijing W&H Law Firm will immediately activate its emergency response procedures to minimize potential losses resulting from the breach and ensure affected individuals receive appropriate notification.
2.5. Beijing W&H Law Firm has established a continuous employee privacy policy training mechanism to ensure that every employee involved in GDPR matters accurately understands the legal principles of data protection based on their specific job responsibilities and strictly implements the company's applicable systems and procedures.
2.6. To ensure compliance, Beijing W&H Law Firm has implemented necessary technical and procedural audits for personal data protection.
Personal data protection is not only a legal requirement but also a corporate social responsibility. Beijing W&H Law Firm will continue to optimize its products and services to ensure security and privacy, thereby reducing personal data protection risks for clients and users.
3. Policy Updates
Beijing W&H Law Firm reserves the right to update or modify this policy from time to time. Should any changes be made to this policy, we will publish the latest version here. If we make significant changes to the privacy policy, we may also notify you through various channels, such as posting a notice on our website or sending you a separate notification.