Effective Date: July 21, 2023
California Notice at Collection/US State Law Privacy Rights : See the US State law privacy rights section below for important information about your rights under applicable US state privacy laws.
This Privacy Policy describes how Nasdaq, Inc. and its subsidiaries and affiliates (collectively, “ Nasdaq,” “ we,” “ our” or “ us”) collects, uses and discloses Personal Data about individuals (collectively, “ users” or “ you”) receiving our products and services, exploring or maintaining a business relationship with us (either directly or through an intermediary such as your financial services provider, your appointed legal or other representative or your employer) and/or using our websites, mobile applications, or other online features (each a “ Site” or collectively, our “ Sites”). As used in this Privacy Policy, Personal Data means any information relating to an identified or identifiable natural person; Personal Data is intended to cover all information subject to Personal Data processing and privacy laws applicable to our business.
Without limiting the generality of the preceding paragraph, this Privacy Policy applies to all Personal Data provided to Nasdaq’s European exchanges (namely, Nasdaq Copenhagen A/S, Nasdaq Helsinki Ltd, Nasdaq Iceland hf., Nasdaq Oslo A/S, Nasdaq Riga AS, Nasdaq Stockholm AB, Nasdaq Tallinn AS and AB Nasdaq Vilnius), the clearinghouse Nasdaq Clearing AB, central shares depositories (namely, Nasdaq CSD SE and Nasdaq CSD Iceland hf.) and AB Pensionkeskus (collectively, our “EEA Regulated Entities”) subject only to the exclusions from this policy set forth below. Nasdaq may also provide additional or supplemental privacy policies to individuals for specific products or services that we offer at the time we collect Personal Data.
The Privacy Policy also describes your rights, where applicable, and how to exercise them. You may contact us at any time with questions related to our Personal Data processing and privacy via email at privacy@nasdaq.com .
In some instances, we may post or provide materials that provide further description of Personal Data processing related to certain products and services. We may also post information about how we comply with specific Personal Data laws or regulations like European Union or United States privacy laws. Such materials are for informational purposes only and are not intended as an exhaustive listing of Personal Data processing related to the product and service. The materials should not be construed as modifying this Privacy Policy.
You can download a printable copy of this Privacy Policy here.
Information that we collect from you, your representative, or automatically |
We collect information that is reasonably necessary for us to provide the relevant product or service, business relationship and/or communication consistent with the nature of such product, service, business relationship and/or communication. |
Information that we collect about you from third-party sources |
Based on the specific products or services you use, we may collect certain categories of Personal Data about you from third parties such as public data sources, government agencies, or social media services. |
Depending on which products or services you use, we may use your Personal Data for a variety of purposes such as such as processing transactions or complying with legal obligations, as well as our legal basis for these uses where applicable. |
|
We do not engage in automated decision-making based solely on automated processing, including profiling, which produces legal effects concerning an individual or similarly significantly affects an individual. |
|
Depending on the products or services you use, we may share your Personal Data with third parties such as with our service providers, in the context of a business transfer, or to process your payments. |
|
This section describes how we process your Personal Data for direct marketing and advertising purposes and how to opt-out of direct marketing communications. |
|
This section describes the rights and choices that may be available to users. |
|
We employ a number of technical, administrative and physical security measures designed to protect your information |
|
This section explains that Personal Data may be transferred to countries outside of your home country. |
|
We will retain your Personal Data for as long as reasonably necessary to maintain the Sites, to meet legal and accounting obligations, and for the other purposes described in this Privacy Policy, or as otherwise required or permitted by law, unless specifically authorized to be retained longer. |
|
This section explains that the Sites use cookies and other similar technologies. For more information see our Cookie Statement. |
|
This section explains that users can refer others to the Sites. |
|
The Sites may contain links to other websites or services that are not owned or controlled by Nasdaq and that you should review the privacy policies of any linked third-party websites when you leave one of our Sites. |
|
You must be at least 18 years old to use the Sites. |
|
This section explains the rights available to residents of California, Virginia, Colorado, and other US states to extent they have applicable privacy laws. |
|
Nasdaq may revise our Privacy Policy from time to time to in order to reflect changes to our information practices. |
|
This section describes how to contact us with comments or questions. |
As a global organization, different Nasdaq entities, products/services and Sites may be subject to different privacy laws based on where our entity operates, where the products/services are delivered and/or where you are located. For example, the European Union General Data Protection Regulation imposes certain requirements on some Nasdaq entities or services that are not applicable to all of our entities or services. Where this Privacy Policy states that a provision applies “to the extent required by applicable law,” such provision will be applicable only to the extent that Nasdaq is subject to legal requirements imposing it.
For purposes of data protection laws, except where this Privacy Policy does not apply, as described below, the Nasdaq entity that will be the “controller” of your Personal Data will be the entity that delivers the products or services you (or the company for whom you are working or have a business relationship) are receiving or maintains the Site that you are using. You can identify the Nasdaq company that hosts a particular Site through the Site’s footer or “About” link. A list of Nasdaq’s different business locations is available here.
Although your data controller may be a specific Nasdaq entity, contact and other customer relationship information that we collect may be held in a customer relationship management or contact database which can be accessed by other Nasdaq entities which may be located globally; further information about international transfers of information is provided below. To the extent required or permitted by applicable law, by visiting or using our Sites, you are consenting to us collecting and processing information about you in accordance with this Privacy Policy.
This Privacy Policy also does not apply to Personal Data processed in connection with delivery of services to Nasdaq by suppliers or contractors; such relationships are governed solely by the Personal Data processing terms and conditions between Nasdaq and the supplier/contractor. It also does not apply to job applicants (which are covered by our separate Job Applicant Privacy Policy) or employees, which are subject to relevant separate privacy notices.
This Privacy Policy does not apply to the extent that:
We collect information that is reasonably necessary for us to provide the relevant product or service, business relationship and/or communication consistent with the nature of such product, service, business relationship and/or communication. Based on the specific products, services, business relationship or Sites involved as well as requirements under applicable law, we may collect the following categories of personal information (“Personal Data”) that you or your representative (such as your employer, financial services provider, legal representative, company where you are an officer, director or significant shareholder) provide to us:
If you create a Nasdaq+ account with us, we may also collect the following Personal Data from, or about, you:
We may also automatically collect the following categories of information from devices (e.g., mobile, computer, laptop, tablet) used to visit or use our Sites (“Device Information”):
Certain Device Information may be deemed Personal Data in accordance with applicable law. Personal Data and Device Information are collectively referred to as “information.”
Based on the specific products, services, business relationship or Sites involved (as well as requirements under applicable law), we may collect the following categories of Personal Data on our own or from third parties about you in accordance with applicable law:
The following is an overview of Nasdaq’s purposes for processing Personal Data. Often due to the nature of the product or service involved or the context in which the Personal Data is used, it will be apparent how we intend to use the information. Additional information about processing related to a particular product or service may be separately posted on the relevant Site or contained in the applicable terms and conditions.
We may use the information we collect for the purposes identified below. To the extent required by applicable law, each purpose for the processing of Personal Data is substantiated by one or more lawful bases for processing. Unless otherwise identified with respect to a particular product or service, our processing is done based of one or more of the following:
Provide you (or your employer/represented company) with our services and products and communicate with you about your (or your employer/represented company) accounts or use of our products, services and/or Sites
Process transactions through one of our services including, but not limited to, processing financial transactions initiated by your or your representative and maintaining your Nasdaq+ or other personal Nasdaq accounts
Comply with our obligations as an exchange, clearinghouse, broker-dealer, central shares depository, pension system administrator and/or other regulated/licensed business including, but not limited to regulations applicable to our EEA Regulated Entities such as, for example, the Markets in Financial Instruments Regulation
Perform transaction and regulatory reporting requirements under applicable law
Perform our obligations as a Self-Regulatory Organization, trading venue and/or market operator including, but not limited to, conducting surveillance of issuers and trading activities, conducting disciplinary proceedings and reporting suspected to misconduct to regulators and other authorities
Monitor for security threats and fraud involving the use of our products, services, Sites or physical facilities
Maintain your status as a representative of an exchange or clearinghouse member or certified advisor to issuers
Register or establish an account for you (or the company for whom you are an employee, officer or director) as a customer
Register you (or your employer/represented company) to receive services or information through one or more of our Sites
To the extent permitted by applicable law, identify you (or your employer/represented company) as a prospective customer for products or services and provide you with relevant information and/or invitations to events
Manage our relationship with you (or your employer/represented company) as a customer, business prospect and/or information recipient
To pursue or enforce our legal rights related to our business, products, services or Sites and/or defend against claims made against us
Communicate with you (or your employer/represented company) about your account or use of our products, services or Sites
Create informational materials and statistical extracts for our products and services
Develop, provide content for, operate, deliver, and market our services and Sites
Develop and deliver marketing of our products and services and those of our advertisers, sponsors and partners
Improve the quality of our Sites and tailor them to your preferences
Implement social networking features you have activated (e.g., Facebook “Like” button and LinkedIn integration)
We also use your information for compliance with our company policies and procedures, for accounting and financial purposes, and otherwise as required or permitted by applicable law. If you do not provide us with information as described above, we may not be able to fulfill the applicable purpose of collection, such as completing a contemplated transaction, responding to your queries or providing access to our Sites to you.
With respect to situations where we process Personal Data based on our legitimate business interest, reflecting that, outside of certain direct consumer interactions, such as our Nasdaq+ services, we are generally a business-to-business product and service provider, we typically collect and process limited Personal Data about corporate customer points of contact and individuals acting in their professional capacities as part of our overall effect to reduce the privacy impact on individuals. To the extent required by applicable law, you have the right to object to the processing of your Personal Data based on a legitimate interest as legal basis. Please see the section below regarding your rights to find out more. Where processing is based on your consent, you have the right to withdraw that consent at any time.
Nasdaq does not engage decision-making based solely on automated processing, including profiling, which produces legal effects concerning an individual or similarly significantly affects an individual.
As part of Nasdaq’s surveillance programs for its exchanges, we utilize certain software that uses machine intelligence and learning to identify situations that potentially constitute market abuse, insider trading, fraud or violations of our published rules. Such software relies on identifying patterns indicating misconduct based on past activity. The conduct involved may include conduct by a corporate member, trading algorithm or individual action. Alerts are referred for investigation by our Surveillance team which determines which actions to take based on our published rules and applicable law.
From time to time, to the extent permitted by applicable law and subject to any contractual limitations on sharing Personal Data set forth in a relevant contract for products and services, we may share your information with our affiliates, subsidiaries, business partners, customers/members (such as where we process your Personal Data in connection with your role with your employer or financial services provider), third party service providers and authorities in the following circumstances:
We may share your information with other parties as directed by you or subject to your consent. We may also share and otherwise process aggregated information or de-identified information that does not identify you individually with other parties. For example, from time to time, we may utilize survey information collected from you on an aggregate, not individually identifiable, basis. We also use this aggregated or de-identified information for our various business purposes, including the creation and sale of other products and services to our clients and potential clients. This aggregate or de-identified information is not traceable to any particular client or user and will not be used by a third party to contact you.
For certain Sites that are intended for public use, news posting and other information distribution, the Site works on advertising-supported basis. On such sites, we may participate with third parties who provide services related to the advertising appearing on such Site or provide us information on your use of our Sites; such third parties may operate as a “data controller” with respect to Personal Data collected by them from your use of our site which they may use to provide tailored advertising to you on the Site or other sites of their customers. We post a current list of such third parties along with a link to their respective privacy policies on our Website Third Party Participant List.
We process Personal Data within the scope of our marketing and market segmentation. With market segmentation, we mean that we categorize our customer base based on professional affiliations and functions, alignment with our services and products and information gathered from public sources of information. For customers or users of our Sites, we may also use information gathered from your use of our products, services and/or Sites for marketing purposes to market our products and services to you, as well as to tailor advertisements of products and services of our advertisers, sponsors and partners to you when you are on our Sites. You always have right to request that we stop using your Personal Data for direct marketing purposes.
To the extent required by applicable law, you have the right to object to the processing of your Personal Data based on a legitimate interest as legal basis. You also always have the right to withdraw your consent at any time when we need your consent in order to process your Personal Data. If you withdraw your consent, you will no longer receive information and offers that are tailored for you. Please see the section below for more information about your rights.
If you no longer wish to receive direct marketing communications from us, you may opt-out of receiving marketing-related emails by: (1) using the unsubscribe method provided in our communications; (2) if you created an online account when you registered to receive our emails, you may log-in to your account on the applicable Site and make changes to your communication preferences; or (3) you can opt out by updating your preferences in the Email Alert section of our Sites. In particular, you have the right to object our use of your Personal Data for direct marketing and in certain other situations (in accordance with applicable law) by contacting us at privacy@nasdaq.com. If you are having difficulty unsubscribing from our email marketing communications using the above methods, please contact us as at privacy@nasdaq.com.
We will try to comply with your request as soon as reasonably practicable as required by applicable law. Please note that we may need to retain certain information for recordkeeping purposes, to complete any transactions that you began prior to your request, or for other purposes as required or permitted by applicable law. In addition, please note that even if you opt-out of receiving marketing communications from one or all of our Sites, we may need to send you service-related communications.
We, our service providers and our third-party advertising partners may also process your Personal Data and information about your interactions (including the data described in the ’information we collect from you, your representee, or automatically’ above) with the Sites, our communications and other online services over time, and use that information to serve online ads that they think will interest you. This is called interest-based advertising. We may also share information about our users with these companies to facilitate interest-based advertising to those or similar users on other online platforms.
In this section, we describe the rights and choices available to all users. Users who are located outside of the United States, or in California or other US states with omnibus consumer privacy laws can find information about their additional rights below.
To the extent required by applicable law, in our capacity as the controller of your Personal Data, we will also provide you with the opportunity to be informed of whether we are processing your Personal Data and at any time to access, correct, update, oppose, delete, block, limit or object to our use of your Personal Data. The foregoing rights will be afforded to you free of charge (except to the extent that your requests are manifestly unfounded or excessive, in which case, we may charge an administrative fee or refuse to meet your request). Please note that legal obligations that apply to our business – for example, financial regulations that apply to our EEA Regulated Business - may prevent us from immediately deleting parts of your information. To exercise your rights, please contact us as detailed under the Contact Us heading below.
To prevent fraudulent activity, we may require you to authenticate your identity when you contact us. We will try to comply with your request as soon as reasonably practicable and within timeframes required by applicable law. Please note that in some instances, due to the nature of the information that we receive, we may require you to provide additional information that will help us identify which information is yours. For requests subject to the European General Data Protection Regulation, we will respond to your request within one month of our receipt of it. We may extend this period by two further months taking into account the complexity of your request or the number of requests that we have received; we will inform you of any such extension within one month of receiving your request along with the reasons for the delay and information about your right to file a complaint with the supervisory authority.
The following sets out a summary of your rights to the extent that your Personal Data is processed subject to the European General Data Protection Regulation:
However, there might be requirements under applicable law, or other compelling reasons, that prevents us from immediately erasing your Personal Data. In such case, we will stop using your Personal Data for any other reasons than to comply with the applicable law, or the relevant compelling reason.
We will take all reasonable and possible actions to notify any recipients of your Personal Data regarding any rectification, erasure or restrictions carried out by us. At your request, we will also inform you with which third parties we have shared your Personal Data.
We employ a number of technical, administrative and physical security measures designed to protect your information. However, no method of transmission over the Internet, or method of electronic storage is 100% secure, so we unfortunately cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure (e.g., if you feel that the security of any account you might have with us has been compromised), please contact us immediately as detailed under the “Contact Us” heading below.
Some of the parties with which we may share your information, as detailed in “ How We Share Your Information”, may be located in countries that do not provide an equivalent level of protection as your home country. Where required, Nasdaq has implemented appropriate cross-border transfer solutions to provide adequate protection for transfers of certain Personal Data, including, but not limited to, the European Commission’s Standard Contractual Clauses (available at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en. To the extent permitted by applicable law, by using our Sites, and providing us information about you, you consent to the international transfer of information about you to the above parties.
We will retain each category of Personal Data identified below for as long as reasonably necessary to maintain the Sites, to meet legal and accounting obligations, and for the other purposes described in this Privacy Policy, or as otherwise required or permitted by law, unless specifically authorized to be retained longer.
When you use our Sites, we along with our affiliates, subsidiaries and third-party service providers may use “cookies” and similar technologies (e.g., log files, clear gifs, pixel tags and Flash LSOs) (collectively, “technology”). This technology may involve placing small files/code on your device or browser that serve a number of purposes, such as remembering your preferences (e.g., language) and generally improving your experience on our Sites. Specifically, we may use such technology for purposes such as to:
To learn more about the technology used on our Sites and how to disable some of the technology, visit our more comprehensive Cookie Statement.
If you choose to use our referral service to tell someone about our products or services or Sites, we will ask you for your friend’s name and email address. Please do not refer someone to us or share their contact details with us unless you have their permission to do so. We will send your referral a one-time email to invite him/her to access the Site or with information about the product or service, and store his/her email address for the sole purpose of sending this one-time email and tracking the success of our referral program. Your referral may contact us as detailed under the “ Contact Us” heading below to request we remove this information from our database.
Our Sites may contain links to other websites or services that are not owned or controlled by Nasdaq, including links to websites of our advertisers, sponsors and partners. This Privacy Policy only applies to information collected by our Sites. We have no control over these third-party websites, and your use of third-party websites and features are subject to privacy policies posted on those websites. We are not responsible or liable for the privacy or business practices of any third-party websites linked to our Sites. Your use of third parties’ websites linked to our Sites is at your own risk, so we encourage you to read the privacy policies of any linked third-party websites when you leave one of our Sites.
None of our Sites are targeted for use by children under the age of eighteen. We do not target any of our products or services or Site content/features for use by children of such age.
Except as otherwise provided, this section applies to residents of California and other states to extent they have privacy laws applicable to us that grant their residents the rights described below. For purposes of this section, Personal Data has the meaning given to “personal data”, “personal information” or similar terms under the applicable privacy laws of the state in which you reside. Please note that not all rights listed below may be afforded to all users and that if you are not a resident of the relevant states, you may not be able to exercise these rights. In addition, we may not be able to process your request if you do not provide us with sufficient detail to allow us to confirm your identity or understand and respond to it.
In some cases, we may provide a different privacy notice to certain categories of residents of these states, such as job applicants, in which case that notice will apply with respect to the activities it describes instead of this section.
Your privacy rights. You may have some or all of the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law.
Exercising your right to information/know, access, appeal, correction, and deletion. You may submit requests to exercise your right to information/know, access, correction, or deletion by contacting us as provided in the “Contact Us” section.
We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
If you are a resident of Virginia, you can ask to appeal any denial of your request in the same manner through which you may submit a request.
Right to opt-out of the “sale” or “sharing” of your Personal Data. While we do not sell Personal Data for money, like many companies, we use services that help deliver interest-based ads to you. Our use of some of these services may be classified under California law as a “sale” or “share” of your Personal Data to the companies that provide the services because they collect information from our users (e.g., device data and online activity data) to help them serve ads more likely to interest you. You can request to opt-out of this “sale” of your Personal Data here: Do Not Sell My Personal Information. Your request to opt-out will apply only to the browser and the device from which you submit the request. We do not have actual knowledge that we have sold or shared the Personal Data of California residents who are under 16 years of age. You can also broadcast the Global Privacy Control (GPC) to opt-out for each participating browser system that you use. Learn more at the Global Privacy Control website.
Verification of Identity; Authorized Agents. We reserve the right to confirm your residency to process your requests and will need to confirm your identity to process your requests to exercise your information, access or deletion rights. As a part of this process, government identification may be required.
Consistent with applicable law, you may designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, the requester’s valid government-issued identification, and the authorized agent’s valid government issued identification. We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
Retention. We will retain each category of Personal Data identified below for as long as reasonably necessary to maintain the Sites, to meet legal and accounting obligations, and for the other purposes described in this Privacy Policy, or as otherwise required or permitted by law, unless specifically authorized to be retained longer. We may anonymize and/or aggregate Personal Data and store it in order to analyze aggregate metrics and trends. For more information about our retention policy, including how we determine the appropriate retention period for Personal Data, please see the Retention section earlier in this Privacy Policy.
Deidentification. We do not to attempt to reidentify deidentified information derived from Personal Data, except for the purpose of testing whether our deidentification processes comply with applicable law.
Personal Data that we collect, use and disclose. The chart below summarizes the Personal Data we collect by reference to the categories of Personal Data specified in the CCPA (Cal. Civ. Code §1798.140) and describes our practices currently and during the 12 months preceding the effective date of this Privacy Policy. The terms in the chart refer to the categories of information, statutory categories, and third parties described above in this Privacy Policy in more detail. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of Personal Data not described below. The categories of sources from which the Personal Data is or was collected and the business or commercial purposes for collecting such information are as described in the “Information we collect from you, your representative, or automatically” and “How we use your information” sections above.
Statutory Category / Personal Data We Collect |
Categories of Third Parties to Whom We Disclose Personal Data for a Business Purpose |
Categories of Third Parties to Whom We "Share" Personal Data |
---|---|---|
Identifiers
|
|
|
California Customer Records (as defined in California Civil Code §1798.80)
|
|
|
Commercial Information
|
|
|
Internet or Network Information
|
|
|
Professional or Employment Information
|
|
|
Education Information
|
|
|
Inferences May be derived from:
|
|
|
Protected Classification Characteristics
|
|
|
Shine the light law. Under California’s Shine the Light law (California Civil Code Section 1798.83), California residents may ask companies with whom they have formed a business relationship primarily for personal, family or household purposes to provide the names of third parties to which they have disclosed certain personal information (as defined under the Shine the Light law) during the preceding calendar year for their own direct marketing purposes, and the categories of personal information disclosed. You may send us requests for this information to us as provided in the “Contact Us” section. In your request, you must include the statement “Shine the Light Request,” and provide your first and last name and mailing address and certify that you are a California resident. We reserve the right to require additional information to confirm your identity and California residency. Please note that we will not accept requests via telephone, mail, or facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.
Except to the extent limited by applicable law, we reserve the right to update this Privacy Policy to reflect changes to our information practices by prominently posting notice of the update on our Sites. Unless otherwise noted, any updates will become effective 15 days after posting the updates to the Privacy Policy, and apply to all information collected about you. If we make any changes to this Privacy Policy that materially impact previously collected information about you, we will, to the extent that we have your email address, notify you by email.
If you have any questions about this Privacy Policy or information we have collected about you, please contact us by email at privacy@nasdaq.com or by postal mail at:
Office of General Counsel – Privacy Team
Nasdaq, Inc.
805 King Farm Blvd
First Floor
Rockville, MD 20850
Office of General Counsel – Stockholm Office
Tullvaktsvägen 15,
10578 Stockholm
Sweden
For our EEA Regulated Entities, you may also contact our Data Protection Officer:
Cirio Advokatbyrå AB
Box 3294, 103 65 Stockholm
Mäster Samuelsgatan 20
+46 8 527 91 600
Att: Caroline Olstedt Carlström – Nasdaq Data Protection Officer
With respect to Personal Data processing subject to European Union jurisdiction, in addition to contacting our business contacts and Data Protection Officer (for our EEA Regulated Businesses), you may also contact a data protection supervisory authority. Within Europe, Nasdaq’s headquarters is located in Sweden, making the responsible data protection supervisory authority:
The Swedish Data Protection Authority
Contact details:
Telefon: 08-657 61 00
E-post: datainspektionen@datainspektionen.se
Fax: 08-652 86 52
Postadress:
Datainspektionen
Box 8114
104 20 Stockholm