STEMpura CIO, Data Protection Policy

Aligns with UK GDPR & Data Protection Act 2018

1. Purpose and Scope

This Data Protection Policy sets out how STEMpura CIO collects, uses, stores, shares, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all employees, contractors, temporary staff, and anyone handling personal data on behalf of the organisation.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable individual.

  • Special Category Data: Sensitive data requiring extra protection (e.g., health, ethnicity, biometric data).

  • Data Controller: The organisation determining how and why personal data is processed.

  • Data Processor: A third party processing data on behalf of the controller.

3. Data Protection Principles

We commit to processing personal data in line with the six UK GDPR principles:

  • Lawfulness, fairness, transparency

  • Purpose limitation

  • Data minimisation

  • Accuracy

  • Storage limitation

  • Integrity and confidentiality

  • Accountability (demonstrating compliance)

4. Lawful Bases for Processing

We will only process personal data where at least one lawful basis applies, such as

  • Consent

  • Contractual necessity

  • Legal obligation

  • Vital interests

  • Public task

  • Legitimate interests (balanced against individual rights)

5. Data Subject Rights

Individuals have the right to:

  • Access their data

  • Rectification

  • Erasure (“right to be forgotten”)

  • Restrict processing

  • Data portability

  • Object to processing

  • Rights related to automated decision‑making We will respond to all requests within statutory timeframes.

6. Roles and Responsibilities

  • Data Protection Officer (DPO) or responsible senior manager: Gareth James, Managing Director

  • All staff must follow this policy and complete mandatory data protection training.

  • Managers must ensure compliance within their teams.

7. Data Security Measures

We implement appropriate technical and organisational measures, including:

  • Access controls and authentication

  • Encryption and secure storage

  • Regular security audits

  • Secure disposal of data

  • Staff training on data handling. These measures help prevent unauthorised access, loss, or damage.

8. Data Retention and Deletion

Personal data will be retained only as long as necessary for the purpose collected and in line with our Data Retention Schedule, which aligns with the requirements of the ICO. Data will be securely deleted or anonymised when no longer required.

9. Data Sharing and Third‑Party Processors

We may share data with trusted third parties where necessary and only under:

  • Written contracts

  • Adequate safeguards

  • UK GDPR‑compliant processing agreements International transfers will follow UK adequacy regulations or appropriate safeguards.

10. Data Breach Reporting

All staff must report suspected data breaches immediately to the DPO. We will assess incidents promptly and notify the ICO and affected individuals where legally required.

11. Policy Review

This policy will be reviewed annually or sooner if significant changes occur in legislation or organisational practices.