STEMpura CIO, Data Protection Policy
Aligns with UK GDPR & Data Protection Act 2018
1. Purpose and Scope
This Data Protection Policy sets out how STEMpura CIO collects, uses, stores, shares, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all employees, contractors, temporary staff, and anyone handling personal data on behalf of the organisation.
2. Definitions
Personal Data: Any information relating to an identified or identifiable individual.
Special Category Data: Sensitive data requiring extra protection (e.g., health, ethnicity, biometric data).
Data Controller: The organisation determining how and why personal data is processed.
Data Processor: A third party processing data on behalf of the controller.
3. Data Protection Principles
We commit to processing personal data in line with the six UK GDPR principles:
Lawfulness, fairness, transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability (demonstrating compliance)
4. Lawful Bases for Processing
We will only process personal data where at least one lawful basis applies, such as
Consent
Contractual necessity
Legal obligation
Vital interests
Public task
Legitimate interests (balanced against individual rights)
5. Data Subject Rights
Individuals have the right to:
Access their data
Rectification
Erasure (“right to be forgotten”)
Restrict processing
Data portability
Object to processing
Rights related to automated decision‑making We will respond to all requests within statutory timeframes.
6. Roles and Responsibilities
Data Protection Officer (DPO) or responsible senior manager: Gareth James, Managing Director
All staff must follow this policy and complete mandatory data protection training.
Managers must ensure compliance within their teams.
7. Data Security Measures
We implement appropriate technical and organisational measures, including:
Access controls and authentication
Encryption and secure storage
Regular security audits
Secure disposal of data
Staff training on data handling. These measures help prevent unauthorised access, loss, or damage.
8. Data Retention and Deletion
Personal data will be retained only as long as necessary for the purpose collected and in line with our Data Retention Schedule, which aligns with the requirements of the ICO. Data will be securely deleted or anonymised when no longer required.
9. Data Sharing and Third‑Party Processors
We may share data with trusted third parties where necessary and only under:
Written contracts
Adequate safeguards
UK GDPR‑compliant processing agreements International transfers will follow UK adequacy regulations or appropriate safeguards.
10. Data Breach Reporting
All staff must report suspected data breaches immediately to the DPO. We will assess incidents promptly and notify the ICO and affected individuals where legally required.
11. Policy Review
This policy will be reviewed annually or sooner if significant changes occur in legislation or organisational practices.