Data Protection and Data security Policy

 

Data Protection and Data Security Policy (September 2025 Revision)

Statement and Purpose of Policy

Intelidat Ltd (“the Employer”) is fully committed to processing all personal data in accordance with UK data protection law, including the Data (Use and Access) Act 2025 (DUAA) and UK GDPR. Intelidat Ltd acts as a data controller for personal data in connection with your employment and determines the purposes and means of processing.

This policy aims to:

  • Notify staff of the types of personal information we may hold about them, customers, suppliers, and other third parties, and describe our processing practices.

  • Set out the rules and legal standards for collecting, handling, processing, transferring, and storing personal data.

  • Clarify staff responsibilities and duties with respect to data protection and security.

This policy may be amended at any time at our discretion.

Definitions

  • Data Protection Laws: All applicable laws relating to processing personal data, including UK GDPR and DUAA.

  • Data Subject: The individual to whom personal data relates.

  • Personal Data: Any information relating to an identifiable living individual.

  • Processing: Any use of data, including collection, storage, amendment, disclosure, or destruction.

  • Special Categories of Personal Data: Data relating to an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, sexual orientation, or biometric data.

Data Protection Principles

All staff must comply with the following principles:

  1. Lawfulness, Fairness, Transparency: Personal data must be processed lawfully, fairly, and transparently. Lawful bases include:

    • Contract performance

    • Legal obligation

    • Legitimate interests (including “recognised legitimate interests” under DUAA, e.g. crime prevention, safeguarding, and emergencies)

    • Consent or other specified bases

  2. Purpose Limitation: Data is only collected for specified, explicit, and legitimate purposes.

  3. Data Minimisation: Data is processed only where necessary for the purpose.

  4. Accuracy: Reasonable steps are taken to ensure accuracy and rectify or delete inaccurate information.

  5. Storage Limitation: Data is kept no longer than necessary.

  6. Security: Appropriate technical and organisational measures must be in place.

Responsibilities

Maintaining data protection is a collective task encompassing all staff, including employees, contractors, officers, and volunteers. Managers lead by example and enforce compliance. The Data Compliance Officer oversees policy implementation and must be notified of breaches or suspected breaches.

Scope of Covered Data

This policy applies to personal data:

  • Relating to identifiable natural individuals and stored electronically or physically

  • Provided by data subjects, third parties, or sourced from public domain

  • Including employment, contact, pay, IT use, performance, and sensitive categories

Processing Sensitive Personal Data

Sensitive data is processed only when a lawful basis and a special condition under UK GDPR/DUAA is met. Explicit consent, legal rights, vital interests, public interest, and legal claims are examples of valid special conditions.

Use of Personal Data

Personal data is used for business administration, employment management, compliance, and other legitimate purposes. We will only use information as notified in our privacy notice and not process for incompatible reasons without consent.

Accuracy and Relevance

We strive to ensure data is accurate, complete, and relevant. Data is only processed for compatible purposes; changes or corrections should be reported to the Data Compliance Officer.

Storage and Retention

Personal and sensitive data are stored securely following our Information Security Policy and retention schedules described in our privacy notice.

Individual Rights

Data subjects have the right to:

  • Make subject access requests (DSARs).
    DUAA 2025 update: We may request clarification (“stop the clock”) and respond with reasonable, proportionate effort. Manifestly unfounded or excessive requests may be declined.

  • Rectify inaccurate data

  • Erasure (“right to be forgotten”)

  • Restrict or object to processing

  • Data portability

  • Complain to the Information Commission (formerly ICO)

Automated Decision-Making

Intelidat Ltd may use automated decision-making in some processes. If decisions have significant effects, individuals may request human intervention, challenge the decision, and receive an explanation of the logic involved.

Data Security

We protect data with appropriate technical and organisational measures:

  • Authorised access only

  • Encryption and pseudonymisation where practical

  • Secure storage and access protocols

  • Approved secure cloud/server usage

  • Regular backups per policy

  • Secure destruction of obsolete records

Data Breaches

Breaches posing risks will be reported to the Information Commission within 72 hours; affected individuals will be notified if high risks are likely. All breaches are recorded per our Breach Response Policy.

International Data Transfers

Personal data may be transferred outside the UK only where protection is not materially lower than UK standards, assessed through risk reviews and appropriate safeguards. For further details, contact the Data Compliance Officer.

Staff Duties

Staff must help ensure:

  • Data accuracy

  • Secure access and transmission of personal data

  • Reporting and handling breaches

  • Compliance with security and privacy protocols

Training

Regular staff training and guidance are provided, with additional targeted education for staff with specialist or frequent data management duties.


This policy reflects current UK legal requirements, including DUAA 2025 updates. For further clarification, contact privacy@intelidat.net or the Data Compliance Officer.