Data Processing Statement 

1. Nature of work – General investigative services and process serving. 

2. Date: 25 May 2018 

3. Description of processing

3.1. The following is a broad description of the way this organisation processes personal information in accordance with the Data Protection Act 1998 (DPA) and General Data Protection Regulation 2018 (GDPR). To understand how your own personal information is processed you may need to refer to any personal communications you have received with the data controller, check any privacy notices that the organisation has provided or contact the organisation to ask about your personal circumstances. 

3.2. Reasons/purposes for processing information

We process personal information to enable us to:

  • provide investigatory services on the written instructions of a data controller (our client)

  • to maintain our own accounts and records 

  • and to support and manage our employees. 

4. Type/classes of information processed

4.1. We process information relating to the above reasons/purposes. This information may include:

  • personal details 

  • the investigation brief, results and related information 

  • lifestyle and social circumstances 

  • family details 

  • goods and services 

  • financial details 

  • education and employment and/or business details 

4.2. We also process sensitive classes of information that may include:

  • physical or mental health details 

  • racial or ethnic origin 

  • trade union membership 

  • religious or other beliefs 

  • criminality 

5. Who the information is processed about

5.1. We process personal information about:

  • customers and clients, including prospective clients

  • witnesses 

  • the subjects of investigations 

  • business contacts 

  • advisers and other professional experts 

  • suppliers 

  • employees 

6. Who the information may be shared with

6.1. We sometimes need to share the personal information we process with the individual themselves and also with other organisations. Where this is necessary we are required to comply with all aspects of the DPA and GDPR. What follows is a description of the types of organisations we may need to share some of the personal information we process with for one or more reasons.

6.2. Where necessary or required we share information with:

  • financial organisations 

  • credit reference, debt collection and tracing agencies 

  • police forces 

  • professional investigators 

  • government 

  • business associates and other professional bodies and advisers 

  • suppliers 

  • current, past or prospective employers 

  • education and examining bodies 

  • family, associates or representatives of the person whose personal data we are processing

7. Sharing personal information

7.1. Personal information is shared as a primary business function. For this reason the information processed may include name, contact details, family details, financial details, employment details, and goods and services. This information may be about customers and clients. 

7.2. The information may be shared with business associates and professional advisers, agents, service providers, customers and clients, and traders in personal data. 

8. Undertaking research

8.1. Personal information is also processed in order to undertake research. 

8.2. For this reason the information processed may include name, contact details, family details, lifestyle and social circumstances, financial details, good and services. 

8.3. The sensitive types of information may include physical or mental health details, racial or ethnic  origin and religious or other beliefs. 

8.4. This information is about survey respondents. Where necessary or required this information may be shared with customers and clients, agents, service providers, survey and research organisations. 

9. Consulting and advisory services

9.1. Information is processed for consultancy and advisory services that are offered. 

9.2. For this reason the information processed may include name, contact details, family details, financial details, and the goods and services provided.

9.3. This information may be about customers and clients. 

9.4. Where necessary this information is shared with the data subject themselves, business associates and other professional advisers, current, past or prospective employers and service providers. 

10. Transfers

10.1. It may sometimes be necessary to transfer personal information overseas. 

10.2. When this is needed information may be transferred to countries or territories around the world. 

10.3. Any transfers made will be in full compliance with all aspects of the DPA and GDPR. 

11. Security

11.1. All personal data will be accessible only to those who need to use it. It will be stored securely with controlled access. 

11.2. Personal data will not be kept no longer than is necessary after which it will be securely disposed of. 

11.3. Where necessary transmission of personal data by email will be password protected or encrypted. 

11.4. Data transferred electronically will be transferred in full compliance with all aspects of the DPA and GDPR.