The Company is committed to protecting the personal information of its employees, workers, clients, prospective clients, customers, suppliers, contractors and other individuals with whom it deals.
This policy sets out how the Company collects, uses, stores, shares and protects personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended.
Personal information may include names, addresses, telephone numbers, email addresses, identification information, employment records and other information relating to an identifiable individual.
All employees and persons processing personal information on behalf of the Company must comply with this policy.
If an employee is unsure whether personal information can be accessed, used or disclosed, advice should be obtained from the Company's Data Protection Lead before taking further action.
Serious or deliberate breaches of this policy may result in disciplinary action.
The Company will ensure that personal information is:
The Company will identify an appropriate lawful basis before processing personal information.
Depending on the circumstances, the lawful basis may include:
Consent will only be relied upon where it is appropriate to do so.
Where the Company relies on legitimate interests, it will consider the purpose of the processing, whether the processing is necessary and the rights and interests of the individual concerned.
Certain categories of personal information require additional protection. These include information concerning:
The Company will only process special category personal information where there is an appropriate lawful basis and an applicable legal condition for doing so.
Criminal offence information will only be processed where there is an appropriate legal basis and suitable safeguards are in place.
The Company may process employee information where necessary for purposes including:
Employees are responsible for ensuring that personal information they provide to the Company is accurate and for notifying the Company of relevant changes.
The Company will not rely solely on an employee's consent simply because the employee has signed an employment contract or this policy.
The Company processes personal and business contact information provided by clients and prospective clients for the purposes of responding to enquiries, preparing quotations, arranging certification services, providing consultancy services and managing ongoing client relationships.
Where an enquiry relates to certification, assessment, accreditation or other third-party services, relevant client details may be shared with the appropriate certification body, assessment body, accreditation-related organisation or other service provider where reasonably necessary to obtain quotations, arrange services, verify or clarify certification or accreditation information, respond to questions concerning the proposed certification service, or otherwise support the client's enquiry.
Information shared may include, where relevant:
Such information will only be shared where there is an appropriate lawful basis and where the sharing is necessary and proportionate for the relevant business purpose.
Depending on the circumstances, the Company may rely on an appropriate lawful basis including taking steps at the individual's request before entering into a contract, contractual necessity or legitimate interests.
Client information will not be shared with unrelated third parties for purposes incompatible with the original enquiry unless there is an appropriate lawful basis to do so.
Personal information may be shared with third parties where this is necessary and lawful for the Company's business activities.
Relevant third parties may include:
Before sharing personal information, employees should consider:
Only the information reasonably required for the particular purpose should be shared.
Employees must take appropriate steps to protect personal information.
This includes:
Personal information must not be stored on unauthorised personal devices or transferred using unapproved systems.
Personal information will only be retained for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable legal, contractual, regulatory and legitimate business requirements.
Different categories of information may have different retention periods.
Information that is no longer required will be securely deleted, destroyed or anonymised.
Individuals have rights under UK data protection legislation, which may include the right to:
These rights are subject to applicable legal requirements, conditions and exemptions.
Individuals may request access to personal information held about them.
A Subject Access Request (SAR) may be made verbally or in writing and does not need to use any particular wording or form.
Any employee receiving a Subject Access Request must forward it promptly to the Company's Data Protection Lead.
The Company will normally respond without undue delay and within one month, subject to applicable legal provisions.
Where permitted by law, the response period may be extended where a request is complex or where multiple requests have been received.
The Company will normally not charge a fee for responding to a Subject Access Request. A reasonable fee may be charged in limited circumstances permitted by law.
The Company may request reasonable evidence of identity where necessary before disclosing personal information.
Personal information must not be transferred or made accessible to a separate organisation outside the UK unless the transfer complies with applicable UK data protection requirements.
Where required, the Company will ensure that an appropriate mechanism or safeguard is in place for the international transfer of personal information.
This may include:
Appropriate transfer risk assessments will be undertaken where required.
A personal data breach may include accidental or unlawful loss, destruction, alteration, unauthorised disclosure or unauthorised access to personal information.
Examples may include:
Employees must report any actual or suspected personal data breach to the Data Protection Lead immediately.
The Company will investigate the incident, assess the risks to affected individuals and document the assessment and actions taken.
Where legally required, the Company will notify the Information Commissioner's Office (ICO) and/or affected individuals within the applicable statutory timescales.
Employees must not attempt to conceal a data protection incident.
Any individual who believes the Company has not handled their personal information appropriately may raise a complaint.
All data protection complaints must be referred to the Company's Data Protection Lead.
The Company will:
All employees must cooperate fully with investigations into data protection complaints.
All employees must:
Employees must not access another person's records without a legitimate and authorised business reason.
Deliberate, reckless or serious misuse of personal information may result in disciplinary action and, where appropriate, further legal or regulatory action.
Data protection and privacy considerations should be incorporated into new systems, services, projects and processes from the outset.
The Company will consider whether a Data Protection Impact Assessment (DPIA) is required where proposed processing is likely to result in a high risk to individuals.
Only the minimum amount of personal information reasonably necessary for the relevant purpose should be collected, accessed, processed and retained.
Employees who handle personal information will receive appropriate data protection and information security awareness training.
Additional training may be provided to employees with specific responsibilities for handling sensitive information, managing data subject requests, investigating complaints, managing information security, sharing information with third parties or responding to personal data breaches.
Questions, requests, incidents or complaints relating to data protection should be referred to:
Data Protection Lead: Muhammad Naeem Ulfat
Email: admin@tritact.co.uk
Telephone: 02080773222
Individuals also have the right to raise concerns with the Information Commissioner's Office (ICO) where applicable.
Compliance with this policy is the responsibility of all employees, workers, contractors and other persons who process personal information on behalf of the Company.
Failure to comply with this policy may result in disciplinary action and, in serious circumstances, termination of employment or engagement.
Where appropriate, breaches may also be reported to relevant regulatory or law enforcement authorities.
This policy will be reviewed at least annually and whenever there are significant changes to data protection legislation, regulatory guidance, Company operations, information systems, processing activities or identified data protection risks.
Policy Owner: Muhammad Naeem Ulfat
Approved By: Director
Version: 1
Issue Date: 01/01/2026
Next Review Date: 01/01/2027