Kith London - Employee Notice of Data Collection, Processing and Transfer

This Employee Notice of Data Collection, Processing and Transfer (the “Notice”) is provided by Kith London Limited (the “Company”), registered offices 2nd Floor 168 Shoreditch High Street, London, United Kingdom, E1 6R. The Company is a data controller when processing your Personal Data. This Notice addresses the following topics: 

  • Collection of Your Personal Data 
  • Use of Your Personal Data 
    • Disclosures of Your Personal Data 
    • International Transfers of your Personal Data 
    • Safeguards for, and Retention of, Your Personal Data 
    • Statement Regarding No Automated Decision Making 
    • Your Rights Regarding Your Personal Data 

For purposes of this Notice, 

  • “Authorized Employees” refers to employees of Kith London Limited with a business need to access your Personal Data and who are obligated by agreement or Company policy or procedures to maintain the confidentiality of your Personal Data; 
  • “Personal Data” means any information concerning an identified or identifiable individual; and 
  • “Processing” means any operation with respect to Personal Data, such as collection, retrieval, access, use, disclosure, storage or disposal of Personal Data. 

A. Collection of Your Personal Data 

The Company collects Personal Data from you during the application process, either directly from you or sometimes from an employment agency or background check provider, that is integrated into your personnel file upon hire. During your employment, the Company collects Personal Data directly from you as well as from Authorized Employees, for example, through administration of your benefits, performance evaluations and other job-related activities. The Company may also collect Personal Data about you from third parties for job-related purposes, for example professional licensing bodies or certification providers, or insurance providers. 

The Personal Data collected includes, but is not limited to, the following: 

(1) Identification, demographic, and contact information, such as your picture, name, gender, date of birth, social security number/national personal identification number, home address, personal email address, personal phone number, employee ID number, work contact details (phone, email, and physical address), nationality, immigration status and copies of identity documentation; 

(2) Benefits and Beneficiary information, including employee benefit eligibility and enrolment, emergency contacts, marital status, information about family members (name, date of birth, gender and social security number/national personal identification number) where necessary for the provision of applicable benefits, guarantees or relocation assistance; 

(3) Financial Information: bank account details and social security number/national personal ID number for payment and taxation purposes; 

(4) Employment information, such as job title, compensation, benefits, professional experience, education and qualifications, performance history, training records, skills, employee background checks, expense records (such as details of out-of-pocket expenses and mobile phone costs), information concerning performance and appraisals, career plans and geographic mobility, conduct and information about actual or alleged violations of laws or breach of Company policies, disciplinary proceedings and in certain countries, where permitted, details of professional registrations, and sanctions with professional bodies or criminal convictions where permitted by law. 

(5) Experience information, such as education, skills, work experience and/or CVs, military status, employee records and performance reviews, and statements of opinion or intention regarding employees; 

(6) Payroll information, such as current and historic compensation, pension contributions, deductions, tax status and allowance information and family data to manage entitlements, and banking information for direct deposit; 

(7) Talent development information, such as career profile, development planning, skills catalogue, work experience, succession planning, mentorship assignments; 

(8) Absence management information, such as vacation, paid time off, or sick time entitlement and used, leave tracking; 

(9) Company-sponsored training information, such as completed and assigned training; 

(10) Employee Monitoring Information: desk phone, mobile phone, written and electronic communications, internet usage, and information collected on CCTV and via other access and security controls; 

(11) Other information necessary for employment, such as Social Security numbers or national personal ID number, social insurance numbers, tax IDs, national ID number, driver’s license number, and other governmental identifiers. 

Sensitive Personal Data: The Company may process sensitive Personal Data (also, known as “special category Personal Data”) in limited circumstances with your explicit written consent, or, as permitted by applicable law, without your consent. The categories of sensitive Personal Data that the Company may collect about you, include: 

(13)Health information: As required by law or as necessary to manage the employment agreement, including benefits administration, occupational health, fitness for duty, reasonable accommodation/adjustments of disabilities, workers’ compensation, sick leave, managing performance and handling complaints/grievances and litigation; 

(14)Disability Status and Information: Only as required by law, or on a purely voluntary basis and only where legally permissible, to ensure meaningful equal opportunity monitoring and reporting; or to provide reasonable accommodations; 

(15)Diversity Data: Race, national or ethnic origin, religious, philosophical or moral beliefs, or your sexual life or sexual orientation, on a purely voluntary basis and only where legally permissible, to ensure meaningful equal opportunity monitoring and reporting and assist the Company in advancing its Inclusion and Diversity goals and initiatives; 

(16)Religious Affiliation: To calculate and deduct the legally required church tax where applicable; 

(17)Union Membership: As required by law to ensure benefits, terms of employment, and employment policies comply with the Union’s requirements. 

Information About Others: Information provided by you to the Company relating to other people (e.g. your partner, dependents, etc.) will be processed by the Company in accordance with this Notice. You are responsible for the accuracy of such information and for ensuring that those people are aware of the nature of the information you have provided and the way in which it will be processed by the Company. 

B. Use of Your Personal Data 

The Company uses Personal Data, as necessary, for all purposes related to the creation, administration and termination of your employment relationship with the Company. These purposes and the Company’s lawful basis for processing your personal data include the following, for each numbered category of Personal Data described above: 

1.1 Recruitment & Staffing 

Purpose for Use 

Category(ies) of Personal Data

Lawful Basis

Recruitment and staffing 

Identification, demographic, and contact information; Employment information; Experience information; Talent development information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce

Assessing qualifications for a particular job or task, including decisions about promotions

Employment information; Experience information; Talent development information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce

Training and development purposes, including performance management

Talent development information; Company-sponsored Training information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in training and development of employees

Management planning 

Identification, demographic, and contact information; Employment information; Experience information; Talent development information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce



1.2 Administration of the Employment Relationship 

Purpose for Use 

Category(ies) of Personal Data

Lawful Basis

Determining and administering the terms  on which you work for the Company

Employment information; Experience information

As necessary for the Company to fulfill its obligations under its employment agreement with you.

Where sensitive Personal Data is processed, as required to comply with the Company’s legal obligations and to exercise its rights.

Administration of salaries and expenses, pension, sickness benefit or other benefits, payments and contributions due under the contract of employment

Benefits and Beneficiary information; Employment information; Financial information; Other information necessary for employment

As necessary for the Company to fulfill its obligations under its employment agreement with you. 

Where sensitive Personal Data is processed, as required to comply with the Company’s legal obligations and to exercise its rights.

Determine physical and/or mental fitness for work

Employment information; Absence management information

As necessary for the Company to fulfill its obligations under its employment agreement with you. 

Where sensitive Personal Data is processed, as required to comply with the Company’s legal obligations and to exercise its rights.

Appraisal, promotion and salary progression exercises

Employment information; Talent development information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce

Tracking of disciplinary and grievance procedures

Employment information 

As necessary for the Company to fulfill its obligations under its employment agreement with you 

Where sensitive Personal Data is processed, as required to comply with the Company’s legal obligations and to exercise its rights

Contacting close family and emergency services in the event of an emergency, for example, illness, 

serious injury to a member of staff or bereavement

Benefits and Beneficiary information

As necessary for the Company to fulfill its obligations under its employment agreement with you, with your consent, and as required to comply with the Company’s legal obligations and to exercise its rights



1.3 Specific Legal Compliance Obligations 

Purpose for Use 

Category(ies) of Personal Data

Lawful Basis

Management of legal requirements in respect of trade unions or other employee representatives

Any categories, where you have agreed to provide them or where required by applicable law

As required to comply with the Company’s legal obligations and to exercise its rights

Responding to requests from law enforcement or government authorities where necessary to comply with applicable law, including to a subpoena or court order or discovery request

Any categories, where you have agreed to provide them or where required by applicable law

As required to comply with the Company’s legal obligations and to exercise its rights

Checking you are legally entitled to work in the location to which you are assigned, including declaring employment to local authorities as required by law

Any categories, where you have agreed to provide them or where required by applicable law

As required to comply with the Company’s legal obligations and to exercise its rights

Complying with health and safety obligations

Any categories, where you have agreed to provide them or where required by applicable law

The Company’s legitimate interest in protecting its employees, customers, and assets, As required to comply with the Company’s legal obligations and to exercise its rights

Complying with mandatory government reporting requirements

Any categories, where you have agreed to provide them or where required by applicable law

As required to comply with the Company’s legal obligations and to exercise its rights



1.4 Other Corporate-wide Purposes 

Purpose for Use 

Category(ies) of Personal Data

Lawful Basis

Administration of global incentive compensation programs

Benefits and Beneficiary information

The Company’s legitimate interest in managing its workforce

Administration of policies and procedures 

Identification, demographic, and contact information; Company-sponsored training information 

As necessary for the Company to fulfill its obligations under its employment agreement with you, the Company’s legitimate interest in managing its 

workforce and protecting its employees, customers, and assets, and required to comply with the Company’s legal obligations and to exercise its rights 

Investigation of suspected misconduct, illegal activity, violation of the Code of Business Conduct, other policies, or non-performance of duties

Identification, demographic, and contact information; Employee Monitoring Information; Absence management information; Employment information

The Company’s legitimate interest in protecting its employees, customers, and assets, and required to comply with the Company’s legal obligations and to exercise its rights

Production of published employee lists, including the company address book and telephone and e-mail directories for both internal and external use

Identification, demographic, and contact information; Employment information

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce

Facilitating the efficient operation of Kith Inc. corporate group business, including, but not limited to realignment of human resource business unit support functions from time to time

Identification, demographic, and contact information; Employment information

The Company’s legitimate interest in managing its workforce, and efficiently administering the employment relationship

In relation to the provision of Kith Inc. business services and other non-business-related services (for example, car parking, IT and communication systems)

Any categories, as applicable and on a need to know basis.

As necessary for the Company to fulfill its obligations under its employment agreement with you, and for the Company’s legitimate interest in managing its workforce

In connection with a corporate restructuring, sale, or assignment of assets, merger, divestiture, or other changes of control or financial status of any member of the Kith Inc. corporate group

Any categories, as applicable and on a need to know basis.

The Company’s legitimate interest in managing its workforce and efficient business operations, and as required to comply with the Company’s legal obligations and to exercise its rights

On a strictly need to know basis only, enabling persons to whom data is being disclosed to carry out their respective roles, (e.g., for reporting or analyzing purposes or simply to permit the efficient and correct administration of data)

Any categories, as applicable and on a need to know basis.

The Company’s legitimate interest in managing its workforce, and efficiently administering the employment relationship

Communication among Kith Inc. corporate group employees and relevant third-party service providers (including by email, instant messaging and other electronic means) in furtherance of the foregoing

Identification, demographic, and contact information; Employment information

The Company’s legitimate interest in managing its workforce, to communicate with employees, and to allow employees to communicate with one another

Equal opportunities monitoring and data collection in support of Inclusion and Diversity initiatives

Identification, demographic, and contact information; employment information

Our legitimate interest to promote a diverse and inclusive workforce, your explicit consent and, where processing is necessary, for the purposes of identifying or keeping under review the existence or absence of equality of opportunity or treatment, and to comply with the Company’s legal obligations and to exercise its rights

Preparing headcount reports and other reports related to the workforce

Identification, demographic, and contact information; employment information

The Company’s legitimate interest in managing its workforce, and efficiently administering the employment relationship

Providing employee business contact information to current and prospective customers

Identification, demographic, and contact information; employment information

The Company’s legitimate interest in managing its workforce and ongoing business operations.

Conducting audits as required by law and Company policy

Any categories, where the individual has agreed to provide them or where necessary under applicable law

The Company’s legitimate interest in managing its workforce and ongoing business operations, and as required to comply with the Company’s legal obligations and to exercise its rights

Exercising the Company’s rights under applicable law and to support any claim, defense, or declaration in a case or before a jurisdictional and/or administrative authority, arbitration, or mediation panel

Any categories, where the individual has agreed to provide them or where necessary under applicable law

As required to comply with the Company’s legal obligations and to exercise its rights


Use for Administrative Functions: The Company also may use your Personal Data to facilitate administrative functions, including, but not limited to, the management and operation of information technology and communications systems, risk management and insurance functions, budgeting, financial management and reporting, strategic planning, and the maintenance of licenses, permits and authorizations applicable to the Company’s business operations. 

You are required to provide certain Personal Data, such as identification data, by law or because the Personal Data is necessary for the Company to enter into an employment agreement with you, where applicable, and to perform its obligations under that agreement. Please understand that if you do not provide your Personal Data when required by law or contract, the Company may not be able to provide you with certain benefits of employment. For example, the Company requires your national ID number to process payroll. Furthermore, if you do not provide your Personal Data, the Company may be prevented from complying with its legal obligations, such as maintaining a safe work environment. In general, you are obligated to provide the Personal Data, except where we indicate, at the time of collection, that providing such Personal Data is voluntary. 

C. Disclosures of Your Personal Data 

There are limited circumstances when the Company may disclose the Personal Data we collect about you to third parties, most notably: 

  • Service Providers: With third-party service providers under written contract with the Company and acting under the Company’s direction and instructions, such as auditors, administrative service providers, travel agencies, and any other entity providing services to the Company. 
  • Corporate Affiliates: With affiliated companies, such as grandparent, parent and/or subsidiary corporations, for the purposes described above. 
  • Required by Law: When required by law, such as to tax authorities or when we respond to subpoenas, court orders, legal process, or a discovery request(s) in civil litigation; 
  • Protect Your Health and Safety: When necessary to protect your health or safety, such as disclosure to emergency medical personnel if you experience a medical emergency in the workplace. 
  • Protect Our Rights: If we believe that your actions violate applicable law, or threaten the rights, property, or safety of the Company’s employees or others. We also may disclose Personal Data to third parties as necessary to establish or exercise our legal rights in litigation, or to defend against legal claims. 
  • Corporate Transactions: If we sell some or all of our business, we may disclose all of the information that we have collected about you to a purchaser or, in due diligence, to a potential purchaser, but subject to a confidentiality agreement, or if we are involved in a bankruptcy proceeding. 

The Company will make such disclosures only as permitted by and in accordance with applicable data protection laws. 

D. International Transfers of Personal Data 

Because the Company is part of a global multinational corporation, your Personal Data, including the categories listed above, may be accessed by Authorized Employees of other members of the Kith Retail, LLC corporate group (collectively, “Group Members”). The Group Member’s Authorized Employees will process your Personal Data for the purposes described above. You can obtain the contact details for these Group Members by emailing dataprotectionUK@kithnyc.com. The third countries where these Group Members are located may provide a different level of protection for your Personal Data from the level of protection in your country of residence. These Group Members will be permitted to access your Personal Data only if the Group Member takes steps to provide an adequate level of protection for your transferred Personal Data. 

The Company has certified to the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework (collectively, the “DPF”) to ensure an adequate level of protection for your transferred Personal Data. You can review a copy of the Company’s Data Privacy Framework Privacy Policy by submitting a request to [insert contact details] or accessing the policy here [insert link to policy on the Company’s intranet]. 

The Company and the Group Members will transfer your Personal Data to service providers, located in third countries, for the purposes described above. Before transferring your Personal Data directly to any service provider located in the United States or another third country, the Company, or Kith Retail, LLC (the Company’s parent corporation), on the Company’s behalf, will confirm that all necessary data transfer requirements have been satisfied, including, where legally required, executing Standard Contractual Clauses or Mandatory Clauses approved by the relevant government authority to ensure an adequate level of protection for the transferred Personal Data. You can obtain a copy of any relevant, Standard Contractual Clauses by submitting a request dataprotectionUK@kithnyc.com

E. Security Measures for, and Retention of, Personal Data: 

The Company has implemented reasonable and appropriate administrative, physical, and technical safeguards for your Personal Data. For example, your Personal Data will be stored on a secure server when in electronic form and in physically secure areas when in paper form. Technical and physical controls restrict access to your Personal Data to Authorized Employees. 

The Company will retain your Personal Data throughout the employment relationship and as long thereafter as is permitted by applicable law. For additional information about the Company’s retention of your Personal Data, please or contact dataprotectionUK@kithnyc.com. 

F. No Automated Decision Making: 

The Company does not make any decisions concerning your employment only by automated means. 

G. Your Rights With Respect to Your Personal Data: 

Subject to applicable law, you have the right to: 

  • request access to your Personal Data; 
  • request that the Company update, correct or delete your Personal Data; and/or 
  • withdraw your consent to the processing of your Personal Data, in circumstances where it was previously provided. 

More on the right to withdraw consent: If the Company requests your consent to process your Personal Data and you do consent, you may use the contact information below to withdraw your consent. Any withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal, and the Company will continue to retain the information that you provided us before you withdrew your consent for as long as allowed or required by applicable law. 

Subject to applicable law, your country of residence may also provide you with the right to: 

  • request restriction of processing of your Personal Data; 
  • request data portability; 
  • object to the processing of your Personal Data; and/or 
  • be informed about the collection and use of your personal data. 

More on the right to data portability: Subject to certain limitations, the right to data portability allows you to obtain from the Company, or to ask the Company to send to a third party, a copy of your Personal Data in electronic form that you provided to the Company in connection with the performance of your employment agreement or with your consent. 

More on the right to object: You have the right to object to the processing of your Personal Data based solely on the Company’s or the Parent Corporation’s legitimate interests. If you do object in these circumstances, the processing of your Personal Data will be stopped unless there is an overriding, compelling reason to continue the processing or the processing is necessary to establish, pursue or defend legal claims. 

How to exercise these rights: You can exercise these rights by submitting an email to dataprotectionUK@kithnyc.com. The Company will respond to such requests in accordance with applicable data protection law. The Company will recognize any additional rights you may have under applicable law, but it will not grant you more rights than applicable law provides. 

If you believe that your Personal Data has been processed in violation of applicable data protection law, you have the right to lodge a complaint with the data protection authority where you live, where you work, or where you believe the violation occurred.