1. Introduction

The Company is committed to protecting the personal information of its employees, workers, clients, prospective clients, customers, suppliers, contractors and other individuals with whom it deals.

This policy sets out how the Company collects, uses, stores, shares and protects personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended.

Personal information may include names, addresses, telephone numbers, email addresses, identification information, employment records and other information relating to an identifiable individual.

All employees and persons processing personal information on behalf of the Company must comply with this policy.

If an employee is unsure whether personal information can be accessed, used or disclosed, advice should be obtained from the Company's Data Protection Lead before taking further action.

Serious or deliberate breaches of this policy may result in disciplinary action.

2. Data Protection Principles

The Company will ensure that personal information is:

  • Lawful, fair and transparent - processed lawfully, fairly and transparently.
  • Collected for specified purposes - collected for specified, explicit and legitimate purposes and not subsequently used in a manner incompatible with those purposes.
  • Adequate, relevant and limited - only information reasonably necessary for the relevant purpose will be collected and processed.
  • Accurate and up to date - reasonable steps will be taken to ensure inaccurate information is corrected or deleted.
  • Retained only as long as necessary - information will not be retained for longer than reasonably required for legal, contractual, regulatory or legitimate business purposes.
  • Secure - appropriate technical and organisational measures will be implemented to protect information against unauthorised or unlawful processing, accidental loss, destruction, alteration or disclosure.
  • Accountable - the Company will maintain appropriate policies, procedures and records to demonstrate compliance with its data protection obligations.

3. Lawful Basis for Processing

The Company will identify an appropriate lawful basis before processing personal information.

Depending on the circumstances, the lawful basis may include:

  • Consent
  • Performance of a contract
  • Taking steps before entering into a contract
  • Compliance with a legal obligation
  • Protection of vital interests
  • Legitimate interests or
  • Performance of a task carried out in the public interest, where applicable.

Consent will only be relied upon where it is appropriate to do so.

Where the Company relies on legitimate interests, it will consider the purpose of the processing, whether the processing is necessary and the rights and interests of the individual concerned.

4. Special Category and Criminal Offence Data

Certain categories of personal information require additional protection. These include information concerning:

  • Race or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data used for identification
  • Health
  • Sex life or
  • Sexual orientation.

The Company will only process special category personal information where there is an appropriate lawful basis and an applicable legal condition for doing so.

Criminal offence information will only be processed where there is an appropriate legal basis and suitable safeguards are in place.

5. Employee Information

The Company may process employee information where necessary for purposes including:

  • Recruitment and employment
  • Payroll and benefits
  • Pension administration
  • Attendance and absence management
  • Health and safety
  • Training and competency
  • Performance management
  • Disciplinary and grievance procedures
  • Equality monitoring
  • Legal and regulatory compliance
  • Protection of the Company's legitimate business interests.

Employees are responsible for ensuring that personal information they provide to the Company is accurate and for notifying the Company of relevant changes.

The Company will not rely solely on an employee's consent simply because the employee has signed an employment contract or this policy.

6. Client, Prospective Client and Certification Enquiry Information

The Company processes personal and business contact information provided by clients and prospective clients for the purposes of responding to enquiries, preparing quotations, arranging certification services, providing consultancy services and managing ongoing client relationships.

Where an enquiry relates to certification, assessment, accreditation or other third-party services, relevant client details may be shared with the appropriate certification body, assessment body, accreditation-related organisation or other service provider where reasonably necessary to obtain quotations, arrange services, verify or clarify certification or accreditation information, respond to questions concerning the proposed certification service, or otherwise support the client's enquiry.

Information shared may include, where relevant:

  • Name and job title
  • Company name
  • Business email address
  • Business telephone or mobile number
  • Company address
  • Details of the certification or service enquiry and
  • Other information reasonably necessary to process, support or clarify the enquiry.

Such information will only be shared where there is an appropriate lawful basis and where the sharing is necessary and proportionate for the relevant business purpose.

Depending on the circumstances, the Company may rely on an appropriate lawful basis including taking steps at the individual's request before entering into a contract, contractual necessity or legitimate interests.

Client information will not be shared with unrelated third parties for purposes incompatible with the original enquiry unless there is an appropriate lawful basis to do so.

7. Sharing Personal Information with Third Parties

Personal information may be shared with third parties where this is necessary and lawful for the Company's business activities.

Relevant third parties may include:

  • Certification bodies
  • Assessment bodies
  • Accreditation-related organisations
  • Auditors and assessors
  • Professional advisers
  • Consultants and specialist service providers
  • IT and cloud service providers
  • Payroll and accounting providers
  • Government departments
  • Regulators
  • Law enforcement agencies
  • Other organisations supporting the delivery of the requested service.

Before sharing personal information, employees should consider:

  • The purpose for which the information is being shared
  • Whether there is an appropriate lawful basis
  • Whether the recipient is appropriate
  • Whether the information being shared is relevant and necessary
  • Whether the sharing is proportionate to the intended purpose and
  • Whether appropriate security measures are in place.

Only the information reasonably required for the particular purpose should be shared.

8. Security of Personal Information

Employees must take appropriate steps to protect personal information.

This includes:

  • Using strong passwords and approved authentication methods
  • Locking computers when unattended
  • Restricting access to authorised persons
  • Using approved Company systems
  • Protecting information transmitted electronically
  • Keeping paper records securely
  • Avoiding unnecessary copying or downloading
  • Checking recipients before sending confidential information
  • Securely disposing of information when it is no longer required.

Personal information must not be stored on unauthorised personal devices or transferred using unapproved systems.

9. Data Retention

Personal information will only be retained for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable legal, contractual, regulatory and legitimate business requirements.

Different categories of information may have different retention periods.

Information that is no longer required will be securely deleted, destroyed or anonymised.

10. Individual Rights

Individuals have rights under UK data protection legislation, which may include the right to:

  • Be informed about how their personal information is used
  • Access their personal information
  • Have inaccurate information corrected
  • Request erasure in certain circumstances
  • Request restriction of processing in certain circumstances
  • Data portability where applicable
  • Object to certain processing and
  • Rights relating to automated decision-making.

These rights are subject to applicable legal requirements, conditions and exemptions.

11. Subject Access Requests

Individuals may request access to personal information held about them.

A Subject Access Request (SAR) may be made verbally or in writing and does not need to use any particular wording or form.

Any employee receiving a Subject Access Request must forward it promptly to the Company's Data Protection Lead.

The Company will normally respond without undue delay and within one month, subject to applicable legal provisions.

Where permitted by law, the response period may be extended where a request is complex or where multiple requests have been received.

The Company will normally not charge a fee for responding to a Subject Access Request. A reasonable fee may be charged in limited circumstances permitted by law.

The Company may request reasonable evidence of identity where necessary before disclosing personal information.

12. International Data Transfers

Personal information must not be transferred or made accessible to a separate organisation outside the UK unless the transfer complies with applicable UK data protection requirements.

Where required, the Company will ensure that an appropriate mechanism or safeguard is in place for the international transfer of personal information.

This may include:

  • UK adequacy regulations
  • Appropriate contractual safeguards
  • The International Data Transfer Agreement (IDTA)
  • The UK Addendum to approved contractual clauses or another legally permitted transfer mechanism or exception.

Appropriate transfer risk assessments will be undertaken where required.

13. Personal Data Breaches

A personal data breach may include accidental or unlawful loss, destruction, alteration, unauthorised disclosure or unauthorised access to personal information.

Examples may include:

  • Sending information to the wrong recipient
  • Losing a device containing personal information
  • Unauthorised access to Company systems
  • Accidentally publishing personal information
  • Disclosing information to an unauthorised third party.

Employees must report any actual or suspected personal data breach to the Data Protection Lead immediately.

The Company will investigate the incident, assess the risks to affected individuals and document the assessment and actions taken.

Where legally required, the Company will notify the Information Commissioner's Office (ICO) and/or affected individuals within the applicable statutory timescales.

Employees must not attempt to conceal a data protection incident.

14. Data Protection Complaints

Any individual who believes the Company has not handled their personal information appropriately may raise a complaint.

All data protection complaints must be referred to the Company's Data Protection Lead.

The Company will:

  • Record the complaint
  • Acknowledge receipt
  • Investigate the circumstances
  • Review relevant records and evidence
  • Provide an appropriate response
  • Identify any corrective or improvement actions required
  • Inform the complainant of their right to raise concerns with the Information Commissioner's Office where appropriate.

All employees must cooperate fully with investigations into data protection complaints.

15. Employees' Responsibilities

All employees must:

  • Only access personal information required for their duties
  • Keep personal information confidential
  • Use personal information only for authorised business purposes
  • Verify identities where appropriate before releasing information
  • Only share personal information with authorised and relevant third parties
  • Ensure information shared is appropriate and proportionate for the intended purpose
  • Follow Company information security procedures
  • Immediately report actual or suspected personal data breaches
  • Forward data protection requests and complaints to the appropriate person
  • Complete required data protection training and
  • Seek advice where they are uncertain about the appropriate handling of personal information.

Employees must not access another person's records without a legitimate and authorised business reason.

Deliberate, reckless or serious misuse of personal information may result in disciplinary action and, where appropriate, further legal or regulatory action.

16. Data Protection by Design and Default

Data protection and privacy considerations should be incorporated into new systems, services, projects and processes from the outset.

The Company will consider whether a Data Protection Impact Assessment (DPIA) is required where proposed processing is likely to result in a high risk to individuals.

Only the minimum amount of personal information reasonably necessary for the relevant purpose should be collected, accessed, processed and retained.

17. Training and Awareness

Employees who handle personal information will receive appropriate data protection and information security awareness training.

Additional training may be provided to employees with specific responsibilities for handling sensitive information, managing data subject requests, investigating complaints, managing information security, sharing information with third parties or responding to personal data breaches.

18. Data Protection Contact

Questions, requests, incidents or complaints relating to data protection should be referred to:

Data Protection Lead: Muhammad Naeem Ulfat
Email: admin@tritact.co.uk
Telephone: 02080773222

Individuals also have the right to raise concerns with the Information Commissioner's Office (ICO) where applicable.

19. Policy Compliance

Compliance with this policy is the responsibility of all employees, workers, contractors and other persons who process personal information on behalf of the Company.

Failure to comply with this policy may result in disciplinary action and, in serious circumstances, termination of employment or engagement.

Where appropriate, breaches may also be reported to relevant regulatory or law enforcement authorities.

20. Policy Review

This policy will be reviewed at least annually and whenever there are significant changes to data protection legislation, regulatory guidance, Company operations, information systems, processing activities or identified data protection risks.

Policy Owner: Muhammad Naeem Ulfat
Approved By: Director
Version: 1
Issue Date: 01/01/2026
Next Review Date: 01/01/2027