Data Protection Notice
Last Updated: 15-08-2026
Brennan Wealth Group is committed to processing personal data fairly, lawfully and transparently.
This Data Protection Notice explains in greater detail how we process personal data, why we process it, the legal bases we rely upon, who we may share it with and the rights available to individuals.
The Irish Data Protection Commission recommends that a data protection notice reflects an organisation’s actual processing activities and explains matters such as processing purposes, recipients, retention periods and data-subject rights.
1. Data Controller
Controller: Thomas Brennan trading as BRENNAN WEALTH GROUP
Address: Redgap, Ratcoole, Co. Dublin
Email: [email protected]
If you have any questions regarding the processing of your personal data, please contact us using the details above.
2. Categories of Personal Data
Depending on our relationship with you, we may process:
Identity Information
- Name.
- Date of birth.
- Identification documents.
- PPS number or other identification information where legally required.
Contact Information
- Address.
- Email address.
- Telephone number.
Financial Information
- Income.
- Expenditure.
- Assets.
- Liabilities.
- Savings.
- Investments.
- Pension arrangements.
- Insurance arrangements.
- Tax-related information where relevant.
- Business interests.
Financial Planning Information
- Financial objectives.
- Retirement objectives.
- Investment experience.
- Investment timeframe.
- Attitude to risk.
- Capacity for loss.
- Family circumstances.
- Dependants.
- Other information relevant to providing suitable financial advice.
Communication Information
- Emails.
- Letters.
- Telephone records where applicable.
- Notes of meetings.
- Records of advice and recommendations.
3. Why We Process Personal Data
We may process personal data for purposes including:
- Providing financial advice.
- Assessing your financial needs and circumstances.
- Making suitable recommendations.
- Arranging financial products.
- Administering client relationships.
- Communicating with you.
- Meeting legal and regulatory requirements.
- Maintaining appropriate records.
- Preventing fraud and financial crime.
- Handling complaints.
- Managing our business and professional obligations.
- Protecting our legal rights.
4. Legal Bases
We may rely on one or more of the following lawful bases:
Contract
Where processing is necessary to provide services to you or take steps at your request before entering into a contract.
Legal Obligation
Where processing is required to comply with applicable legislation or regulatory obligations.
Legitimate Interests
Where processing is necessary for our legitimate business interests and those interests are not overridden by your fundamental rights and freedoms.
Consent
Where we ask for and rely upon your consent for a particular processing activity.
Where consent is the legal basis, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Special Categories of Data
In certain circumstances, financial planning or protection advice may require information that falls within special categories of personal data under GDPR.
Where such information is processed, we will ensure that an appropriate legal condition applies and that suitable safeguards are in place.
We will only request information that is relevant to the service being provided.
6. Sources of Personal Data
We may obtain personal data:
- Directly from you.
- From your authorised representatives.
- From product providers.
- From pension providers.
- From investment providers.
- From insurance providers.
- From professional advisers acting on your behalf.
- From publicly available sources where appropriate.
- From regulatory or governmental sources where legally permitted.
7. Recipients of Personal Data
Where necessary, we may disclose personal data to:
- Financial product providers.
- Pension providers.
- Investment firms.
- Insurance companies.
- Compliance providers.
- Professional advisers.
- IT and technology providers.
- Cloud-service providers.
- Legal advisers.
- Accountants.
- Regulators and government authorities.
- Other service providers involved in delivering services to you.
We require appropriate safeguards where third-party service providers process information on our behalf.
8. International Transfers
Where personal data is transferred outside the European Economic Area, we will ensure that an appropriate legal mechanism and safeguards are in place as required under applicable data protection law.
9. Retention of Personal Data
We retain personal data only for as long as necessary for the relevant purposes and to meet applicable legal, regulatory, accounting and reporting requirements.
Different categories of information may be retained for different periods depending on the nature of the service and the applicable legal or regulatory requirements.
10. Your Rights
Subject to applicable legal conditions and exemptions, you may have the right to:
- Access your personal data.
- Correct inaccurate or incomplete information.
- Request erasure.
- Request restriction of processing.
- Object to certain processing.
- Receive certain personal data in a portable format.
- Withdraw consent where consent is the lawful basis.
- Lodge a complaint with the relevant data protection supervisory authority.
The Data Protection Commission states that individuals should be informed of their rights and how those rights can be exercised.
11. Exercising Your Rights
To exercise your data protection rights, please contact:
Data Protection Contact
Brennan Wealth Group
Redgap, Ratcoole, Co. Dublin
Email: [email protected]
We may need to verify your identity before processing certain requests.
We will respond to valid requests within the timeframe required by applicable data protection legislation.
12. Data Protection Commission
If you are unhappy with how we have handled your personal data, we encourage you to contact us first so that we can investigate your concern.
You also have the right to lodge a complaint with the Data Protection Commission (DPC).
The DPC is the Irish supervisory authority responsible for upholding individuals’ data protection rights under the GDPR and relevant Irish legislation.
13. Changes to This Notice
We may update this Data Protection Notice when our processing activities, legal obligations or regulatory requirements change.
The latest version will always be made available on our website.