Last updated August 2025
Milliman, Inc. and its affiliates (“Milliman” or “we”) take data privacy very seriously. This Privacy Policy sets out the principles governing Milliman’s and the Hong Kong affiliate’s (Milliman Hong Kong) collection, use, disclosure, transfer (“Processing”) and protection of Personal Data (as defined below) that website visitors, prospective clients, and clients residing within Hong Kong (“you”) share with us. Milliman is committed to handling Personal Data in accordance with this Privacy Policy, the Personal Data (Privacy) Ordinance (Cap. 486) as amended in 2021 (PDPO), and other applicable data protection and privacy laws.
Milliman, Inc., USA, Milliman India Private Limited, India and Milliman Limited, Hong Kong, are acting as Data Users in accordance with the PDPO with respect to the processing of Personal Data described in this Privacy Policy. This means that Milliman, Inc., Milliman India Private Limited and Milliman Limited are responsible for compliance with applicable data protection laws. Milliman Sàrl (France) will be considered as a Data User only in such cases where a Data Subject exercises their rights by using DSAR platform under the control of Milliman Sàrl (France).
Like many companies, Milliman monitors the use of its websites by collecting aggregate data. No Personal Data is collected in this process. Typically, Milliman collects data about the number of visitors to the website, to each web page, and the originating domain name of the visitor's Internet Service Provider. This data is used to improve the usability, performance, and effectiveness of Milliman’s website.
For more detailed information describing how Milliman uses cookies and your choices surrounding the use and opt-out of such cookies, including information about third-party embedded content on Milliman’s website and how Milliman responds to Do Not Track signals in browsers, please review our Cookie Policy which can be found here.
In this Privacy Policy, "Personal Data" means any data regarding individuals who are identified or can be identified, either separately or in combination with other information, directly or indirectly, using an electronic and/or non-electronic system.
The Personal Data we collect varies depending upon the nature of the services provided and our interactions with you. In the context of the collection of Personal Data through this website, Milliman’s marketing activities, and contract administration, we may, to the extent permitted by law or with your consent, collect, use, disclose, store, and otherwise process Personal Data of:
We may also collect, and process limited Personal Data about you from public resources (such as LinkedIn), including your name/surname, email address, telephone number, organization, title/position, profession, and professional interests, to allow us to assess a potential interest in our services and to contact you for marketing purposes.
When we communicate with you regarding the products and services we offer or develop, you will be given the opportunity in each communication to unsubscribe and prevent future communications of that sort. If you do not want us to collect your Personal Data for our marketing emails or if you wish to unsubscribe from direct marketing communications from us, you may reach out to us by filling out the data subject request form as available under the section “Rights”. We will cease using your Personal Data for direct marketing purposes once you have requested us to do so.
If you provide us with Personal Data of another individual, it is your duty to make sure that these individuals have consented to or are appropriately informed about the Processing of their Personal Data by Milliman.
You should also ensure that all Personal Data submitted to us is complete, accurate, true, and correct. Failure on your part to do so may result in our inability to provide you with products and services you have requested.
No automated decision-making is undertaken based on the Personal Data collected from you.
All Milliman websites, products, and services are provided in cooperation with Milliman, Inc., U.S. and Milliman India Private Limited, India. Any Personal Data may be shared between Milliman Limited, Hong Kong, Milliman India Private Limited and Milliman, Inc. or other entities controlled by or under common control with Milliman, Inc., for the purposes of centralization of Milliman’s General Corporate Services including: administrative services, contract management, including for billing purposes, due diligence, Know Your Customer (KYC), conflict checks, Client Relationship Management (CRM), IT maintenance and security, data privacy(management of data subjects’ request) and marketing services (cookie management, inquiry tracking via Milliman’s website form, communication regarding Milliman’s products, services, or events).
We may also share Personal Data with affiliated entities using the MILLIMAN® mark, in which case we will require those affiliates to comply with this Privacy Policy. Please note that we may be transferring your Personal Data to a country that does not have the same data protection laws as your home country. However, Milliman ensures that Milliman and its affiliates will process Personal Data in compliance with this Privacy Policy.
Milliman also may share Personal Data with authorized third-party agents or contractors that perform services for Milliman. If Milliman shares Personal Data with a third party, Milliman requires that those third parties agree to process Personal Data based on Milliman’s instructions and in compliance with this Privacy Policy.
Any transfers of Personal Data are subject to appropriate safeguards using contractual or other means to provide a similarly adequate level of protection in compliance with PDPO.
Milliman may also disclose Personal Data and other related information in response to subpoenas, court orders, or other lawful requests by public authorities, and to meet national security or law enforcement requirements. Milliman may collect and share Personal Data in order to investigate or take action regarding illegal activities, suspected fraud, violations of Milliman's Terms of Use, or as otherwise required by law or regulation.
Milliman stores Personal Data on a secure server that is password protected and shielded from unauthorized access by a firewall. Milliman has in place security policies that are intended to ensure the security and integrity of all Personal Data. Milliman has appropriate technical and organizational measures in place to protect against unauthorized or unlawful Processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data held or processed by Milliman. If Milliman forwards Personal Data to any third party, Milliman requires that those third parties have appropriate technical and organizational measures in place to comply with this Privacy Policy and applicable laws.
Milliman retains Personal Data only as long as necessary to fulfil the purposes outlined in this Privacy Policy unless a longer retention period is required or not prohibited by law. Milliman will delete your Personal Data once the purpose of the collection and Processing of such Personal Data has been fulfilled and the adequate duration for documentation and backup storage of such Personal Data has lapsed. If you have unsubscribed from receiving marketing information from us, we will continue to maintain your Personal Data for any other purpose for which we still have legal grounds for Processing such Personal Data (such as for the purposes of complying with a legal obligation or when the Processing is necessary for the purpose of our legitimate interest). In certain cases, if no other legal grounds exist, we will maintain limited Personal Data (such as your email address) about you on record, so as to be able to ensure for the future that such marketing communications are no longer sent to you.
Milliman’s websites, products, and services are not directed to children, and Milliman does not knowingly collect Personal Data from children. If a parent or legal guardian becomes aware that his or her child has provided Milliman with Personal Data without their consent, the parent or legal guardian should contact us by filling out the data subject request form as available under the section “Rights”, and we will take steps to delete any such Personal Data.
Milliman’s website may contain links to websites hosted and operated by companies other than us (“Third-Party Websites”) to which you can export (part of) your Personal Data.
We do not disclose your Personal Data to these Third-Party Websites without your explicit consent. Note that any information you disclose to Third-Party Websites is no longer under our control and no longer subject to this Data Privacy Policy.
You should review the privacy policy practices of any such Third-Party Website to understand how that Third-Party Website collects and uses your Personal Data should you have decided to disclose your Personal Information to them. We are not responsible for the content or performance of these Third-Party Websites. We are in no way responsible or liable for the manner in which a Third-Party Website treats any Personal Data that you choose to provide to such a Third-Party Website and use of Third-Party Websites is strictly at your own risk.
Milliman may change its Privacy Policy from time to time. Milliman therefore asks all persons concerned to check it occasionally to ensure that they are aware of the most recent version.
Depending on the applicable law, you have a number of rights under the PDPO or such other applicable data protection and privacy laws in relation to your Personal Data, including:
Please note that withdrawing consent does not affect our right to continue to collect, use, and disclose Personal Data where such collection, use, and disclosure without consent is permitted or required under applicable laws, and any Processing of your Personal Data prior to the deletion of your account with us, or your request that we no longer contact you for direct marketing purposes will remain valid under the legal grounds then prevailing.
You can exercise any of your rights as stated above, by filling out the data subject request form available here. For such requests, Milliman uses the Data Subject Access Request platform of the service provider One Trust. One Trust acts as Milliman’s data processor. We will endeavour to respond to any such request as soon as possible, and in any event within 40 days or as otherwise prescribed under the applicable laws. We will endeavour to respond to any such request as soon as possible, and in any event within the legal deadline.
If you have any questions, complaints, or feedback relating to your Personal Data or about this Privacy Policy, please contact us at [email protected].
Please note that if your Personal Data has been provided to us by a third party (e.g., your employer), you should contact that organization or individual to make such queries, complaints, and access and correction requests to Milliman on your behalf.
This Privacy Policy shall be governed in all respects by the laws of Hong Kong.