Signed in as:
filler@godaddy.com
Signed in as:
filler@godaddy.com
DATA PROTECTION POLICY
PGSO Ltd, company number 12960911. Version 1.0, August 2026. Reviewed annually.
PURPOSE AND SCOPE
This policy sets out how PGSO Ltd complies with the UK General Data Protection
Regulation and the Data Protection Act 2018. It applies to all personal data processed
by the company, and to anyone working for or on behalf of PGSO Ltd, including
subcontractors.
RESPONSIBILITY
PGSO Ltd is a small consultancy and is not required to appoint a Data Protection
Officer. The Director holds overall responsibility for data protection and is the point
of contact for all data protection matters.
PRINCIPLES
Personal data processed by PGSO Ltd is:
- processed lawfully, fairly and transparently
- collected for specified, explicit and legitimate purposes only
- limited to what is necessary for those purposes
- kept accurate and up to date
- retained no longer than necessary
- kept secure against unauthorised access, loss or damage
WHAT WE PROCESS
Enquiry and contact data from the website and direct correspondence. Client contact and
site contact details. Subcontractor and supplier contact and payment details. Records
required for accounting, VAT and insurance.
We do not process special category data, and we do not carry out automated
decision-making or profiling.
DATA MINIMISATION
We collect only what is needed to deliver the engagement. Survey outputs record assets,
plant and buildings. Where individuals appear incidentally in survey photography, images
are not used for identification and are not published.
SECURITY
Data is held in access-controlled business systems with multi-factor authentication
enabled. Devices used for company work are password protected and encrypted. Survey
data is transferred to controlled storage promptly after site work and not retained on
portable devices longer than necessary. Access is limited to those who need it for the
engagement.
SUBCONTRACTORS AND PROCESSORS
Third parties processing personal data on our behalf do so under written terms
requiring them to act only on our instructions, to keep the data secure, and to delete
or return it at the end of the engagement. Where a subcontractor is engaged on a client
project, only the contact details necessary for that project are shared.
INTERNATIONAL TRANSFERS
Where a provider processes data outside the UK, transfers are made under UK adequacy
regulations or the International Data Transfer Agreement, as applicable.
RETENTION
Enquiries not leading to work: [PERIOD]. Client engagement records: [PERIOD] after
completion. Accounting records: six years from the end of the relevant accounting
period. Data is deleted at the end of its retention period.
DATA SUBJECT REQUESTS
Requests are acknowledged on receipt and answered within one month. Identity is
verified before any data is released. Requests are logged, with the date received, the
action taken and the date of response.
PERSONAL DATA BREACHES
Any suspected breach is assessed immediately. Where a breach is likely to result in a
risk to individuals, it is reported to the Information Commissioner within 72 hours of
becoming aware of it. Where the risk is high, affected individuals are informed without
undue delay. All breaches are recorded, whether or not they are reportable.
ICO REGISTRATION
PGSO Ltd is registered with the Information Commissioner as a data controller and pays
the annual data protection fee.
REVIEW
This policy is reviewed annually by the Director, and following any material change to
how PGSO Ltd processes personal data.
Approved by Peter Oram, Director, PGSO Ltd, August 2026.
Copyright © 2026 PGSO Ltd - All Rights Reserved.
Company Reg 12960911 - VAT no. 361 0777 04