Privacy Notice
This Privacy Notice («Notice») informs visitors to our website, subscribers to our publications, participants at our events, current and prospective clients, counterparties and other parties involved in matters on which we act, business partners, job applicants, visitors to our offices, and any other party – or person acting on behalf of such a party – («you») how 5Gambit Disputes AG and 5Gambit Disputes New York PLLC (together «5Gambit», «we», «us») process personal data («data») in accordance with the Swiss Federal Act on Data Protection («FADP») and, where applicable, the Regulation (EU) 2016/679 (General Data Protection Regulation) («EU GDPR») and United Kingdom («UK») General Data Protection Regulation, as incorporated into UK law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 («UK GDPR») (together «GDPR»).
This applies when you use our website, communicate with us, subscribe to our publications, register for or attend our events, instruct us or are otherwise involved in a matter on which we act («Services»), visit our offices, apply for a position with us, or in any other situation described in section 3 below.
References to the GDPR in this Notice apply only to the extent that the GDPR is applicable.
We may provide you with additional privacy notices where we consider it useful, for example in connection with a specific engagement or a specific event. Any such notice supplements this Notice and should be read together with it.
1. Controllers, Representatives and Contact Details
The controllers are:
5Gambit Disputes AG, Alte Rentenanstalt, Genferstrasse 1, 8002 Zurich, Switzerland
5Gambit Disputes New York PLLC, One World Trade Center, New York, NY 10007, United States
Which entity is the controller depends on the context. 5Gambit Disputes AG is the controller for the website, for our publications and events, for our Swiss-law and international arbitration Services, and for recruitment. 5Gambit Disputes New York PLLC is the controller for Services provided by that entity. Where both entities are involved in the same matter, each acts as a separate controller in respect of the data it processes, and data may be shared between them as described in section 4.
Contact for all data protection matters: enquiry@5gambit.com
Please note that communications relating to data protection, in particular where addressed to a representative in the European Economic Area («EEA») or the UK, may not be covered by Swiss professional secrecy or by legal privilege.
GDPR European Representative: Pursuant to Art. 27 of the GDPR, 5Gambit Disputes AG has appointed European Data Protection Office (EDPO) as its GDPR Representative in the EU. You can contact EDPO regarding matters pertaining to the GDPR (i) by using EDPO’s online request form: https://edpo.com/gdpr-data-request/ or (ii) by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.
UK GDPR UK Representative: Pursuant to Art. 27 of the UK GDPR, 5Gambit Disputes AG has appointed EDPO UK Ltd as its UK GDPR representative. You can contact EDPO UK regarding matters pertaining to the UK GDPR (i) by using EDPO’s online request form: https://edpo.com/uk-gdpr-data-request/ or (ii) by writing to EDPO UK at Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom.
2. Our Collection of Data, and Data You Provide About Others
You are generally under no obligation to provide us with data. If you do not provide data we need for the purposes described in section 3, however, we may be unable to respond to your enquiry, contact you, send you our publications, invite you to our events, negotiate or conclude a contract with you, provide our Services, or process your application.
In order to provide our Services, we collect data relating to those Services from you, from your or our business partners (for example, correspondent law firms), and from other parties involved in the matter, including counterparties, courts, arbitral tribunals and other authorities. We may also collect data from third-party providers or from public sources, such as commercial registers, sanctions and watch lists, court records, land and debt enforcement registers, and providers of business information and fraud prevention services.
If you provide us with data about other individuals – for example your employees, colleagues, beneficial owners or relatives – we assume that data is accurate. By providing it to us, you confirm that you are entitled to do so and that you have informed the individuals concerned of this Notice and of our processing of their data.
3. Data Processed, Purposes and Legal Bases
3.1. Use of the Website
Categories of data. When you access our website, the following information about your access and device may be collected automatically: IP address, operating system, device type, browser name and version, date and time of access, and the address of the website from which you were referred («Website Usage Data»). We may analyze your use of the website using web analytics tools («Website Analytics Data»).
Purpose and legal basis. We process Website Usage Data on the basis of our legitimate interest in the operation and security of the website, in particular to ensure the stability and integrity of our systems (Art. 6(1)(f) GDPR). We may carry out basic analytics to improve usability and to understand how our website is used, also on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Extended analytics using cookies is, within the scope of the GDPR, based on your consent (Art. 6(1)(a) GDPR); see section 3.2.
3.2. Cookies
Cookies are small files stored on your device by your browser when you visit our website. You can disable cookies in your browser settings, although some functions of the website may then not work correctly.
Categories of data. Website Usage Data and Website Analytics Data.
Purpose and legal basis. We may use cookies to provide a functioning website experience, for example session cookies, on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Extended analytics using cookies is, within the scope of the GDPR, based on your consent (Art. 6(1)(a) GDPR).
3.3. Communication
We may communicate with you through various channels, including where you complete a contact form on our website, send us an e-mail, or use other electronic or printed means of communication («Communication Data»).
Categories of data. Your name, e-mail address or other communication identifier, telephone number, the subject and content of your message, associated metadata, and any other information you provide.
Purpose and legal basis. We use Communication Data to deal with your enquiry and any related questions arising in connection with our Services (Art. 6(1)(b) GDPR), and with any further matters arising from the content of your communication (Art. 6(1)(f) GDPR). We may retain this data to document our communications with you, for quality assurance and follow-up enquiries (Art. 6(1)(f) GDPR), and for regulatory purposes (Art. 6(1)(c) GDPR).
3.4. Publications, Events and Marketing
Categories of data. Your contact details (name, organisation, function, e-mail address, postal address), your preferences and areas of interest, information about your attendance at our events including photographs, information about your use of our publications, references you provide to us (for example for legal directories such as Chambers and Partners or The Legal 500), and Communication Data («Marketing Data»).
Purpose and legal basis. We process Marketing Data for relationship management and to inform you about our Services, our publications and our events, by e-mail, telephone or other channels for which we hold your contact details, and to publish photographs from events on our website and other media. We do so on the basis of our legitimate interest in informing you and other interested parties about our Services (Art. 6(1)(f) GDPR), to the extent permitted under applicable marketing rules, or, where required, on the basis of your consent (Art. 6(1)(a) GDPR). You may object to being contacted for marketing purposes, or withhold or withdraw your consent, at any time.
3.5. Legal Services
Categories of data. In connection with our Services we may collect and further process all information we require or receive in order to provide those Services. This may include Contract Data (as described in section 3.6), date of birth, nationality, identification documents, title, occupation, role and function, financial details including shareholdings and beneficial ownership, client history, sanctions and adverse media information, and your feedback. In providing our Services we may also process e-mails, text messages, letters and other communications, including image data from videoconferences and associated metadata, information relating to transactions and payments, and any other information contained in matter files or otherwise connected with the Services (together «Services Data»).
Services Data may include data relating to counterparties, witnesses, experts and other individuals involved in a matter who are not our clients, and may include sensitive data, in particular data relating to criminal proceedings, sanctions and administrative or criminal measures.
Purpose and legal basis. Services Data is used to provide our Services, including legal advice and representation, the conduct of investigations, the operation of data rooms, and invoicing (Art. 6(1)(b) GDPR), and to comply with applicable law and our internal rules, including conflict checks, know-your-client procedures, sanctions screening, and anti-money-laundering and fraud prevention obligations (Art. 6(1)(c) and (f) GDPR). Where we act for a client, our processing of data relating to counterparties and other third parties is based on our legitimate interest, and that of our client, in the establishment, exercise or defense of legal claims (Art. 6(1)(f) GDPR; Art. 9(2)(f) GDPR for sensitive data). We may also process Services Data to document our Services and our communications with you, for training and quality assurance, and to improve our Services and processes on the basis of our legitimate interests (Art. 6(1)(f) GDPR).
Professional secrecy. Services Data is subject to Swiss lawyers’ professional secrecy (Art. 13 of the Federal Act on the Free Movement of Lawyers and Art. 321 of the Swiss Criminal Code) and, in respect of 5Gambit Disputes New York PLLC, to the duty of confidentiality under Rule 1.6 of the New York Rules of Professional Conduct, and may be protected by legal privilege or the work-product doctrine. Professional secrecy and privilege take precedence over your rights under section 6, and we may refuse, restrict or defer a request where necessary to protect professional secrecy, the overriding interests of third parties, or the interests of our clients (Art. 26 FADP; Art. 15(4) GDPR and applicable national derogations).
3.6. Contracts and Business Partners
Categories of data. Where we conclude or negotiate a contract with you, we may process your name, contact details, information about your employer, and bank and payment details (together «Contract Data»), and Services Data as described in section 3.5.
Purpose and legal basis. We use Contract Data to prepare, conclude, perform and administer our contractual relationships and any questions arising in that connection (Art. 6(1)(b) GDPR). Such processing may be necessary to comply with legal requirements and our internal rules (Art. 6(1)(c) and (f) GDPR; see section 3.5).
3.7. Job Applications
Categories of data. Your name, photograph, contact details, information on your work permit, education and professional experience, references, and any further information you provide in connection with your application («Application Data»). Where relevant to the position, we may also request or obtain an extract from the criminal records register and from the debt enforcement reg-ister. Such extracts constitute sensitive data.
Purpose and legal basis. We process Application Data to assess your application, to verify your references, identity and background where relevant to the position, and to negotiate, prepare, conclude and perform an employment contract with you (Art. 6(1)(b) GDPR). Where we process sensitive data for these purposes, we do so on the basis of your consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) or where necessary to assess your suitability for a position that is subject to professional or regulatory requirements. If no employment contract is concluded, we may retain your application for future openings where you have consented (Art. 6(1)(a) GDPR).
3.8. Alumni
Categories of data. If you are a former partner or employee of 5Gambit, we process your name and contact details, information about your engagement with us and your subsequent career, and any other information you provide to us («Alumni Data»).
Purpose and legal basis. We process Alumni Data to stay in contact with you, to invite you to our events and to send you our publications, on the basis of our legitimate interest in maintaining our professional network (Art. 6(1)(f) GDPR). You may object at any time.
3.9. Office Visits
Please note that the common areas of the building in which our offices in Zurich and New York are located may be subject to CCTV operated by the building owner or manager. Any processing of personal data through such CCTV is carried out by the respective operator in accordance with its own privacy practices.
4. Disclosure of Data
4.1. Categories of Recipients
We may disclose your data to the following recipients, in accordance with applicable law:
- the other 5Gambit entity (5Gambit Disputes AG or 5Gambit Disputes New York PLLC, as the case may be), and correspondent law firms and local counsel;
- contractual partners, where disclosure follows from the contract concerned, for example where you use our Services under a contract we have with your employer;
- other parties involved, for example where a person holds a power of attorney over your affairs, or where the Services require disclosure to counterparties, their legal representatives, experts, witnesses or insurers;
- external service providers, including providers of IT and communications services, document and case management systems, data rooms, e-discovery and forensic services, translation and transcription services, digital signature and document destruction services, business information and compliance screening providers, event and publication management providers, financial institutions and debt collection agencies;
- legal, tax and accounting advisers and auditors;
- our data protection representatives in the EU and the UK (see section 1), which receive correspondence relating to data subject requests and supervisory authorities and hold a copy of our record of processing activities;
- competent authorities, including courts, arbitral tribunals, supervisory and bar authorities, tax, enforcement and bankruptcy authorities, where necessary for the provision of our Services, where we are legally required or entitled to disclose, or where disclosure appears necessary to protect our interests; and
- transaction partners and their advisers, in connection with any merger, acquisition or other business transaction involving us.
In certain circumstances, data may be published on our website or in other media in accordance with applicable law, for example photographs from events you have attended or references you have provided for legal directories.
Disclosure of data covered by professional secrecy is subject to section 3.5.
4.2. Transfers Abroad
In connection with the disclosures described in section 4.1, we may transfer data to countries that provide an adequate level of protection under the FADP and the GDPR, including the member states of the EEA and the United Kingdom.
We may also transfer data to countries that do not provide an adequate level of protection under the FADP and/or the GDPR. This includes, in particular, the United States, where 5Gambit Disputes New York PLLC is established, and to which data is transferred in connection with matters involving that entity and for certain IT and communications services. It may also include other countries where necessary for the relevant processing purpose, for example in connection with cross-border proceedings.
Where a recipient country does not provide an adequate level of protection, we will take steps to ensure the transfer is safeguarded by appropriate measures, in particular the European Commission’s standard contractual clauses, including the annex required for transfers subject to the FADP and recognised by the Swiss Federal Data Protection and Information Commissioner, or is based on a statutory derogation – for example where you have consented, where the transfer is directly connected with the conclusion or performance of a contract with you, or where the transfer is necessary for the establishment, exercise or defense of legal claims before a foreign court or authority. Under the GDPR you may request a copy of the relevant safeguards by contacting us as described in section 1.
5. Retention and Deletion
We process and retain data for as long as required by the purpose of the processing, by statutory retention periods, and by our legitimate interest in documentation. Unless subject to other statutory or contractual obligations, we will delete or anonymize your data once the retention or processing period has expired. For certain categories of data, we generally retain your data as follows:
- Website Usage Data: for as long as necessary to provide access and to ensure the stability and integrity of the systems concerned.
- Website Analytics Data: for as long as necessary to carry out the analysis, after which it is deleted or anonymized.
- Cookies: for the duration of the relevant purpose.
- Communication Data: deleted once your enquiry has been dealt with, unless we are re-quired to retain it or have an overriding or legitimate interest in retaining it for documentation, quality assurance, or the establishment, exercise or defense of legal claims.
- Services Data and Contract Data: as a rule for ten years from the end of the matter or the contractual relationship, reflecting statutory accounting retention requirements and the limitation period for contractual claims under Swiss law, and longer where a longer statutory retention obligation applies or where we have an overriding or legitimate interest in retention. Matter files of 5Gambit Disputes New York PLLC are additionally subject to the record-keeping requirements of the New York Rules of Professional Conduct.
- Marketing Data: for as long as necessary for the relevant purpose, unless we are required to retain it or have an overriding or legitimate interest in retaining it.
- Application Data: for the duration of the application process and three months thereafter, unless you ask or permit us to retain your application for longer, or unless we need to retain it to assess, establish or defend legal claims.
6. Your Rights
Subject to section 3.5, you have the right to request information about the data we process about you, and to exercise further rights in relation to that processing. You have, or may have depending on the circumstances, the right to:
- access – to ask whether we process data about you and, if so, to request further information about that data;
- rectification – to ask us to correct or complete your data where it is inaccurate or incomplete;
- erasure – to ask us to delete your data, unless we are required to retain it or have an overriding or legitimate interest in retaining it;
- object – to object to processing based on our legitimate interest (Art. 6(1)(f) GDPR), setting out the specific grounds and circumstances on which your objection is based;
- restriction – to ask us to restrict the processing of your data temporarily;
- data portability – to ask us to provide data you have given us in electronic form to you or to another controller, where technically feasible; and
- withdraw consent – where you have given consent for a specific processing purpose. This does not affect the lawfulness of processing carried out before withdrawal, or on another legal basis, and may mean we can no longer provide our Services to you.
To exercise any of these rights, please contact us as described in section 1. We may ask you to verify your identity and confirm your residency before processing your requests, so as to ensure your data is not disclosed to an unauthorized person. Verification may include providing government-issued identification, a sworn statement, or other information as permitted by law.
We may be unable to process a request if we cannot verify your identity or understand the request. We may deny a request as permitted by law, including where necessary to protect professional secrecy or legal privilege, where required by the overriding interests of third parties or by our own overriding interests, or where the request is manifestly unfounded, excessive or pursues a purpose contrary to data protection law. We will inform you of the grounds for our decision to the extent permitted or required by law.
You will generally not have to pay a fee to exercise your rights. Where applicable data protection law permits us to charge a contribution towards the costs of providing access, we may do so and will inform you in advance.
US Privacy Rights Notice
U.S. residents of states that have enacted privacy laws granting specific rights to individuals, including but not limited to, the California Consumer Privacy Act («CCPA»), the Virginia Consumer Data Protection Act («VCDPA»), the Colorado Privacy Act («CPA»), and the Connecticut Data Privacy Act («CTDPA») may have additional rights to those described in section 6; eligibility depends on the particular state of residence.
In addition to your rights outlined above, depending on your state’s privacy laws, you may file a complaint with your state’s applicable enforcement authority if you are not satisfied with our rejection of your request. Where applicable, in our response rejecting your request, we will provide you with a mechanism through which you may contact the relevant authority.
European Privacy Rights Notice
Personal information under the GDPR does not include «anonymous data»» (i.e., information where the identity of the individual has been permanently and irreversibly removed); however, it does include pseudonymized and/or aggregated personal information.
FADP and GDPR require us to ensure we have a legal basis and purpose for which we use your data. The legal basis for our processing of your data is described throughout this Privacy Notice based on the type of data and the specific context in which we process it. If you have questions about the legal basis of how we process your data, please contact us as described in section 1. In addition to your rights outlined above, if you are not satisfied with our response to a request you make, or how we process your data, you may file a complaint to the data protection regulator in your habitual place of residence.
- For EEA users, the contact information for the data protection regulator in your place of residence can be found here: https://edpb.europa.eu/about-edpb/board/members_en
- For UK users, the contact information for the UK data protection regulator is below: The Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: +44 303 123 1113
Website: https://ico.org.uk/make-a-complaint/ - For Swiss users, the contact information for the Swiss data protection regulator is below: Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, CH-3003
Bern, Switzerland
Tel: +41 58 462 43 95
Website: https://www.edoeb.admin.ch
7. Data Security
We have implemented appropriate technical and organizational security policies and procedures to protect your data against loss, misuse, unauthorized access or disclosure, alteration and destruction, in electronic and in physical form. Access to our premises is controlled and our electronic systems are protected by access controls.
Our partners, employees and the third-party service providers who have access to confidential information, including personal data, are bound by duties of confidentiality and, where required, have entered into data processing agreements with us.
Despite these measures, security risks in the processing of data cannot be entirely excluded.
Payment instructions. We will never notify you of new or amended bank account details by e-mail, including by attachment. If any payment instruction purporting to come from us differs from the details you have used before, do not act on it – verify by telephone on a number already known to you.
8. Changes to this Notice
This Notice is not part of any contract with you and may be amended by us at any time. The version published on our website is the version currently in force.
Last updated: 25 August 2026
