Data Protection Policy

1. POLICY STATEMENT

1.1

Everyone has rights with regard to how their Personal Data is handled. During the course of our activities we will collect, store and process Personal Data about our staff, suppliers, customers and other individuals we communicate with, and we recognise the need to treat it in an appropriate, lawful and transparent manner.

1.2

The types of Personal Data that we may be required to handle include details of current, past and prospective employees, contractors, suppliers, customers, website users and other individuals. The information, which may be held on paper or electronically, is subject to legal safeguards specified in:

● UK General Data Protection Regulation (UK GDPR)

● Data Protection Act 2018

● Privacy and Electronic Communications Regulations (PECR)

● Data (Use and Access) Act 2025 (DUAA)

● Any other applicable UK data protection legislation

Where processing activities involve individuals located within the European Economic Area (EEA), EU GDPR may also apply.

1.3

We are committed to ensuring that Personal Data is processed in line with applicable legislation and that all staff conduct themselves in accordance with this policy and associated procedures.

1.4

Where third parties process Personal Data on our behalf, we will ensure appropriate contractual, organisational and technical safeguards are in place.

1.5

This policy sets out our standards and responsibilities regarding the collection, use, storage, transfer, retention and destruction of Personal Data.

1.6

If any individual believes this policy has not been followed, concerns should be raised immediately with the Privacy Officer, a manager or a Director.

1.7

This policy does not form part of any employee contract and may be amended from time to time to reflect legal, operational or regulatory developments.

2. WHO IS COVERED BY THIS POLICY?

2.1

This policy applies to:

● Employees

● Directors and officers

● Workers and agency workers

● Consultants and contractors

● Volunteers and interns

● Temporary staff

● Any third party handling Personal Data on behalf of With Data

2.2

All third parties with access to Personal Data must comply with equivalent contractual obligations and data protection standards.

3. WHO IS RESPONSIBLE FOR THIS POLICY?

3.1

The Privacy Officer is responsible for overseeing compliance with applicable data protection legislation and this policy.

3.2

Managers are responsible for ensuring that staff within their teams understand and comply with this policy.

3.3

All staff are responsible for:

● Handling Personal Data appropriately

● Reporting concerns or incidents promptly

● Following data protection procedures

● Completing required training

4. DEFINITION OF DATA PROTECTION TERMS

4.1 Personal Data

Any information relating to an identified or identifiable living individual.

4.2 Data Subject

The individual to whom Personal Data relates.

4.3 Data Controller

The organisation that determines the purposes and means of processing Personal Data.

4.4 Data Processor

A person or organisation processing Personal Data on behalf of a Data Controller.

4.5 Processing

Any operation performed on Personal Data including collection, storage, use, disclosure, deletion or destruction.

4.6 Special Category Data

Sensitive Personal Data including health data, racial or ethnic origin, religious beliefs, biometric data and sexual orientation.

4.7 Criminal Offence Data

Personal Data relating to criminal convictions or offences.

4.8 Data Breach

Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

4.9 Automated Decision-Making (ADM)

Decision-making carried out by automated means without meaningful human involvement.

4.10 Artificial Intelligence (AI)

Systems or technologies capable of performing tasks that normally require human intelligence, including machine learning, generative AI, profiling and predictive analytics.

5. DATA PROTECTION PRINCIPLES

We will comply with the core principles of UK GDPR and DUAA. Personal Data must be:

1. Processed lawfully, fairly and transparently

2. Collected for specified, explicit and legitimate purposes

3. Adequate, relevant and limited to what is necessary

4. Accurate and kept up to date

5. Retained only for as long as necessary

6. Processed securely and confidentially

7. Protected when transferred internationally

8. Processed in accordance with individuals’ rights

We are accountable for demonstrating compliance with these principles.

6. FAIRNESS AND LAWFULNESS

6.1

We will only process Personal Data where a lawful basis applies, including:

● Performance of a contract

● Compliance with legal obligations

● Legitimate interests

● Vital interests

● Public task

● Consent

● Recognised Legitimate Interests under DUAA where applicable

6.2

Where consent is relied upon:

● Consent must be freely given, specific, informed and unambiguous

● Individuals may withdraw consent at any time

● Withdrawal requests will be actioned promptly

6.3

Special Category Data and Criminal Offence Data will only be processed where additional legal conditions are satisfied.

7. TRANSPARENCY

7.1

We will provide clear and accessible Privacy Notices explaining:

● What Personal Data we collect

● Why we collect it

● The lawful basis for processing

● Who we share it with

● International transfers

● Retention periods

● Individual rights

● How complaints can be made

7.2

Privacy information will be written in plain language and made easily accessible.

7.3

Where services are likely to be accessed by children, child-friendly privacy information will be provided where appropriate.

8. PURPOSE LIMITATION

Personal Data will only be used for the purposes for which it was collected unless a compatible lawful basis applies.

Where purposes change materially, individuals will be informed through an updated Privacy Notice.

9. DATA MINIMISATION

We will only collect and process Personal Data necessary for legitimate business purposes. Excessive, irrelevant or unnecessary data must not be collected or retained.

10. ACCURACY

We will take reasonable steps to ensure Personal Data remains accurate and up to date. Inaccurate or outdated information will be corrected, restricted or deleted where appropriate.

11. STORAGE LIMITATION

11.1

Personal Data will only be retained for as long as necessary for the purpose collected and in line with our Data Retention Policy.

11.2

Retention periods may be extended where necessary:

● To comply with legal obligations

● To investigate complaints

● To establish, exercise or defend legal claims

● To comply with DUAA complaint handling obligations

11.3

Data that is no longer required will be securely deleted, anonymised or destroyed.

12. SECURITY, INTEGRITY AND CONFIDENTIALITY

12.1

We will implement appropriate technical and organisational security measures to protect Personal Data.

12.2

Security measures may include:

● Access controls

● Encryption

● Secure backups

● Multi-factor authentication

● Secure disposal procedures

● Restricted access folders

● Monitoring and logging

12.3

Staff must:

● Keep passwords secure

● Prevent unauthorised access

● Avoid sharing Personal Data unnecessarily

● Report suspicious activity immediately

12.4

We will regularly test and review security measures.

13. TRANSFER LIMITATION

13.1

International transfers of Personal Data will only occur where appropriate safeguards are in place.

13.2

This may include:

● UK adequacy regulations

● International Data Transfer Agreements (IDTAs)

● Standard Contractual Clauses (SCCs)

● Approved certification mechanisms

● Other lawful safeguards

13.3

International transfer risk assessments will be conducted where required.

14. DATA SUBJECT RIGHTS AND REQUESTS

Individuals have the right to:

● Be informed

● Access their data

● Rectify inaccurate data

● Erase data in certain circumstances

● Restrict processing

● Object to processing

● Data portability

● Object to direct marketing

● Challenge automated decision-making

● Withdraw consent

● Lodge a complaint with the ICO

14.1 Data Subject Access Requests (DSARs)

All DSARs must be forwarded immediately to the Privacy Officer.

We will:

● Verify identity where appropriate

● Respond within statutory deadlines

● Maintain records of requests and responses

● Apply DUAA proportionality requirements where relevant

15. AUTOMATED PROCESSING (INCLUDING PROFILING) AND AUTOMATED DECISION-MAKING (ADM)

15.1

Any use of profiling or automated decision-making must comply with applicable legislation.

15.2

Where legally required, meaningful human oversight will be implemented.

15.3

Individuals will be informed where automated decision-making significantly affects them. 15.4

We recognise that DUAA broadens permitted use of certain automated decision-making activities, but safeguards for individuals remain mandatory.

16. ARTIFICIAL INTELLIGENCE (AI) AND EMERGING TECHNOLOGIES

16.1

The use of Artificial Intelligence (AI) systems must comply with data protection, confidentiality and information security requirements.

16.2

AI systems must not be used:

● To process Personal Data without an identified lawful basis

● To input confidential client or employee data into unauthorised public AI tools ● To make significant decisions without appropriate human oversight where legally required

16.3

Before implementing new AI systems or tools, the business will assess:

● Privacy risks

● Security risks

● Supplier compliance

● International transfers

● Accuracy and bias risks

● Whether a DPIA is required

16.4

Any AI tool processing Personal Data on behalf of With Data must be subject to appropriate contractual protections and security review.

16.5

Staff must follow all separate AI governance, acceptable use and cyber security guidance issued by the business.

17. DIRECT MARKETING

17.1

Direct marketing activities must comply with UK GDPR and PECR.

17.2

Where consent is required, records of consent will be maintained.

17.3

Individuals must be provided with clear opt-out mechanisms.

17.4

Marketing practices involving analytics, cookies or tracking technologies must comply with current PECR and DUAA requirements.

18. DATA PROTECTION COMPLAINTS PROCESS (DUAA REQUIREMENT)

18.1

In accordance with the Data (Use and Access) Act 2025 (DUAA), With Data maintains a formal process for handling data protection complaints.

18.2

Individuals may submit complaints relating to:

● Use of their Personal Data

● Security of their Personal Data

● Data breaches

● Data retention

● Accuracy of Personal Data

● Responses to DSARs

● Marketing communications

● Any other data protection concern

18.3

Complaints may be submitted:

● By email

● In writing

● By telephone

● Through any designated online form or process

18.4

Complaints will:

● Be acknowledged promptly and within statutory requirements

● Be investigated appropriately

● Be escalated where necessary

● Be responded to without undue delay

● Be securely logged and retained

18.5

The business will maintain:

● A complaint handling procedure

● Complaint records and logs

● Template responses

● Escalation processes

● Appropriate restricted-access storage

18.6

Where a complaint relates to a third-party supplier or processor, we may liaise with the supplier to investigate and resolve the matter.

18.7

Where services are accessed by children, complaints will be handled with safeguarding considerations and age-appropriate communication.

18.8

Complainants will be informed of their right to escalate complaints to the Information Commissioner’s Office (ICO).

19. BREACH NOTIFICATION

19.1

Any suspected or actual Personal Data Breach must be reported immediately to the Privacy Officer.

19.2

Where required, breaches will be reported to the ICO within 72 hours.

19.3

Affected individuals will be notified where there is a high risk to their rights and freedoms.

19.4

All breaches and near misses will be recorded in the Data Breach Log.

19.5

Staff must preserve evidence relating to suspected breaches.

20. TRAINING

20.1

All staff must complete mandatory data protection and information security training.

20.2

Additional specialist training may be required for:

● Managers

● HR personnel

● Marketing teams

● Staff handling complaints

● Staff using AI systems

20.3

Training records will be maintained.

21. RECORDS AND ACCOUNTABILITY

21.1

We will maintain appropriate records demonstrating compliance, including:

● Records of Processing Activities (RoPAs)

● Data Breach Logs

● DSAR Logs

● Complaint Logs

● DPIAs

● Supplier assessments

● Retention schedules

● Training records

21.2

We will regularly review third-party processor arrangements and associated contractual protections.

22. MONITORING AND REVIEW OF THE POLICY

22.1

This policy will be reviewed regularly and updated where required to reflect:

● Changes in legislation

● ICO guidance

● Operational changes

● Security developments

● AI and technology developments

● Lessons learned from incidents or complaints

22.2

Non-compliance with this policy may result in disciplinary action and/or termination of contracts.