Overview MGI is committed to safeguarding the privacy of personal data that it collects, and complying with Data Protection Laws that apply to it across all jurisdictions.
- As a US-based company, MGI is governed by Gramm-Leach-Bliley Act (GLBA).
- As a company operating across European Union, MGI is likewise subject to General Data Protection Regulation (GDPR).
To best protect its employees, customers and business partners, MGI has adopted the GDPR standards worldwide and adjusted itself to meet specific local regulations, whenever required.
- Additionally, MGI adheres to additional privacy regulations in certain jurisdictions, as appropriate, such as California Consumer Privacy Act (CCPA) for California residents and transactions.
MGI respects rights of data subjects, including their right to submit various privacy-related inquiries (refer to Identifying Customer Request Types below) via Privacy Form, including, but not limited to:
- Requesting information on/access to their personal data processed by MGI,
- Correcting/deleting their personal data processed by MGI,
- Restricting the processing/transmitting of their personal data to another controller,
- Objecting to the processing of their personal data and/or being the subject to automated individual decision-making.
Below persons/entities can submit Privacy Form; after the form is submitted, they will receive an e-mail notification from MGI.
- Customers
- Current/former/prospective (job applicants) MGI employees
- Agents on behalf of themselves
- 3rd parties or agents on behalf of data subjects
- Others
Click on the below links to access MGI privacy documents.
- Global Personal Data Privacy and Protection
- Consumer Privacy Notice: www.moneygram.com/privacy-notice
Internal Policies for Handling Personal Data
Follow the below guidelines when handling customer personal data.
- Never enter license numbers, Social Security Numbers, passport numbers, etc. in any field, except for corresponding fields on Salesforce cases or Mainframe, e.g. do not enter these numbers in the transaction Message field where they can be exposed to third parties (e.g. receivers or receive agents).
- Only use scratch pads and recent typing to record personal data for call-handling purposes; once you are done using this data, always delete it.
- Do not save personal data on your computer.
MGI performs periodic scans of company computers to ensure compliance with this policy.
Important
- Whenever a customer claims that someone used their personal information or used/stole their ID/credit/debit card to send an MGI transaction, complete Third Party Unauthorized Use of Personal Information as such scenarios are not related to privacy, but rather to unauthorized use of personal information.
- Whenever a customer states they received an e-mail notification with the link to verify their e-mail address, advise them this is not a spam but an actual Privacy Form-related notification sent from our company system, and if the verification is not completed within 7 days, their case will be closed and they will need to submit a new request.
Prerequisites Note: for MGO customers, profiles in Salesforce are auto-created; if there is no profile, do not create it manually but instead open a stand-alone case.
When you are a Non-MGO Representative, Then complete Customer Profile Process.
Identifying Customer Request Types
Below grid lists all the available Privacy categories and corresponding customer request types; in all these scenarios, complete Process below in order to:
- Populate Privacy Form online,
- Follow up on the existing customer's request, or
- Identify when the form is not necessary.
Right to Rectification exception: when a customer requests to update their personal data (e.g. name, phone number, e-mail address, etc.) and marketing preferences, do not fill out Privacy Form online, but instead proceed to update their profile; refer to Customer Profile Process.
Process Complete the below process to assist a customer.
- Proceed based on whether this is an initial or follow-up request.
- Select Who is calling?
- Select the What is the Caller Requesting? option; refer to Identifying Customer Request Types above. Note: with each selection, additional fields will appear.
- Populate additional fields, as required; refer to Identifying Customer Request Types above.
- Enter the caller's first name and key-spell it. Note: GSS Representatives do not need to key-spell.
- Enter the caller's last name and key-spell it. Note: GSS Representatives do not need to key-spell.
- Enter the caller's language based on the language of your conversation.
- Enter the caller's e-mail address. Note: for callers with no e-mail address, enter noemail@noemail.com and then the mailing address in the next field (mandatory).
- Select Caller's Country of Residence from the drop-down list (including the state for US and Canada).
- Enter your MoneyGram LAN ID.
- Proceed based on whether this is an initial request and customer provided their e-mail address.
When this is an Initial request And the caller Provided their e-mail address, then: a. Read the disclaimer from the website to the customer and select the check box next to this disclaimer. b. Proceed to the next step.
When this is a Follow-up request and the caller Did not provide their e-mail address, then Proceed to the next step.
-
Click Submit to submit the form. Note: you can click Reset to clear and re-populate the form, as needed.
-
Open and close a Consumer Support case as below; refer to Opening and Closing Case.
- Case Reason: General Assistance and Comments
- Case Sub-Reason: General Inquiry on MoneyGram Products