Data Protection Policy
Our approach to data protection under UK GDPR and the Data Protection Act 2018.
DRAFT — UNDER DEVELOPMENT
This policy is not yet formally approved.Policy Owner
[INFORMATION REQUIRED BEFORE PUBLICATION]
Version
0.1 Draft
Effective Date
[INFORMATION REQUIRED BEFORE PUBLICATION]
Last Reviewed
[INFORMATION REQUIRED BEFORE PUBLICATION]
Next Review
[INFORMATION REQUIRED BEFORE PUBLICATION]
Contact
[INFORMATION REQUIRED BEFORE PUBLICATION]
1Lawfulness
We only process personal information where we have a lawful basis.
2Fairness
We process personal information fairly and do not use it in ways that would be unexpected.
3Transparency
We are clear about how we use personal information through privacy notices and policies.
4Purpose limitation
We only use personal information for the purposes for which it was collected.
5Data minimisation
We only collect the minimum information necessary. If Larry doesn't need the information, Larry shouldn't ask for it.
6Accuracy
We keep personal information accurate and up to date.
7Storage limitation
We do not retain personal information for longer than is necessary. See our Data Retention & Deletion Policy.
8Security
We apply appropriate technical and organisational security measures.
9Accountability
We take responsibility for our data protection practices and maintain documentation.
10Privacy by Design
We embed privacy into product design from the beginning, not as an afterthought.
11Children's information
Children's information is treated with particular care. We apply the UK Age Appropriate Design Code (Children's Code).
12Data subject rights
We respect and facilitate individuals' rights under UK GDPR.
13Processor management
We ensure processors are bound by appropriate data processing agreements.
14Incident management
We have procedures for identifying, reporting and responding to data protection incidents. See our Data Breach & Incident Response information.
Questions about this policy?
We welcome questions about any of our policies. Please get in touch.