Company policies · Security, information & environment

Data Protection & Privacy Policy

Standards for handling personal, client, employee and operational information with appropriate confidentiality, access control and security.

View all policies
Scroll
Purpose

What this policy is designed to do.

To reduce privacy and information-security risk by collecting only what is needed, limiting access, protecting records and responding responsibly to security incidents.

Who it applies to: Employees, contractors and systems that collect, access, store, transmit or dispose of personal, client or commercially sensitive information.

Our commitments

The standards we expect in practice.

These principles guide decisions, conduct and day-to-day execution across the relevant parts of our business.

01

Collect and use personal information for legitimate, defined business purposes.

02

Limit access to people who genuinely need the information for their role.

03

Use reasonable technical and organizational safeguards appropriate to the sensitivity of the data.

04

Protect beneficiary and vulnerable-person information with particular care.

05

Report suspected loss, unauthorized access or disclosure promptly.

How we apply it

Controls that turn policy into evidence.

Controls are scaled to the nature, value and risk of the activity rather than treated as a one-size-fits-all checklist.

01

Role-based access and least-privilege principles for business systems.

02

Strong authentication and multi-factor controls where supported and appropriate.

03

Secure storage, backup and transmission methods for sensitive information.

04

Periodic security review, vulnerability assessment and access review.

05

Incident-response procedures covering containment, assessment, notification and remediation.

Accountability

Clear ownership matters.

System owners maintain appropriate access and security controls.

Managers approve business access based on job need.

Users protect credentials and report suspicious activity.

Compliance or designated management coordinates serious privacy incidents.

Policy documentation

Need a policy pack, signed statement or supporting compliance evidence for an RFP or due-diligence review?