Principles
Participating Businesses process personal information:
- lawfully, fairly and transparently;
- for specified and legitimate purposes;
- only to the extent necessary;
- accurately and with reasonable correction arrangements;
- for no longer than required;
- with appropriate security; and
- with accountability for decisions and controls.
Expected information use
Depending on its activities, a Participating Business may process customer and enquiry details, supplier and subcontractor records, workforce information, financial and transaction records, website information, communications and evidence required for safety, service or legal purposes. Its privacy notice explains the actual categories, purposes, lawful bases, recipients, retention and rights.
Special-category or criminal-offence information is processed only where necessary, lawful and subject to appropriate safeguards.
Rights and requests
People may exercise applicable data-protection rights through the contact route published by the responsible business. Identity is verified proportionately, requests are recorded and responses are provided within applicable timescales.
Suppliers and systems
Processors are selected with regard to privacy and security. Written terms are used where required. New forms, systems, automations and integrations are assessed before production use, with additional impact assessment where processing may create high risk.
International transfers
Personal information is not intentionally transferred outside the UK unless the responsible business establishes a lawful transfer mechanism, suitable safeguards and transparent privacy information before the transfer.
Incidents
Suspected loss, disclosure, alteration or misuse is reported immediately to the responsible business, contained, assessed and documented. Required notifications are made to affected people and regulators.
Registration
Each Participating Business assesses its own obligation to pay a data-protection fee or register with the Information Commissioner's Office and keeps that assessment under review.
Accountability and lifecycle controls
Each controller maintains a proportionate record of processing, identifies a lawful basis before use, provides privacy information at the point of collection or within the applicable period, and uses special-category or criminal-offence information only where an additional legal condition is documented. Consent is used only when it is freely given, specific, informed, unambiguous and as easy to withdraw as to give.
Collection is limited to information reasonably required. Accuracy, access, disclosure, retention and deletion are controlled throughout the lifecycle. Requests to exercise information rights are identified promptly, identity is verified proportionately and statutory deadlines are tracked. No person is disadvantaged for making a legitimate request.
Processors receive documented instructions and suitable contractual terms. Due diligence considers security, confidentiality, sub-processors, assistance with rights, deletion, audit and breach reporting. International transfers are identified and supported by an applicable UK adequacy regulation, safeguard or exception, with a transfer-risk assessment where required.
New systems, forms, tracking, CCTV, monitoring, automation or AI-supported processing are reviewed before use. A data-protection impact assessment is completed where processing is likely to create high risk. Solely automated decisions producing legal or similarly significant effects are not introduced without specific review, safeguards and transparent information.
Suspected loss, unauthorised access, disclosure or alteration is contained and reported internally without delay. The controller assesses risk, documents its decision and notifies the ICO and affected people where the legal tests and deadlines require it.
Approval
Approved by David Swaddle, Founder, on 30 August 2026.