EDUK Data Protection Policy

Last updated: 1 September 2026

1. Purpose and scope

This policy sets out how Equality and Diversity UK Ltd (EDUK) manages and protects personal information. It applies to personal information handled through our services, website and business activities, including information relating to customers, delegates, contacts, staff and contractors.

Our data protection framework includes the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and, where relevant, PECR.

EDUK is registered with the ICO: ZB518334.

2. Data protection principles

  • Processed lawfully, fairly and transparently
  • Collected for specified, explicit and legitimate purposes
  • Adequate, relevant and limited to what is necessary
  • Accurate and, where necessary, kept up to date
  • Kept for no longer than necessary
  • Handled with appropriate security

EDUK is responsible for, and must be able to demonstrate, compliance with these principles.

3. Personal information we handle

Depending on the relationship and purpose, this may include contact details, organisation and job information, bookings and orders, communications, payment and transaction information, website and technical information, accessibility information, and staff or contractor records.

4. Lawful processing

Before processing personal information, we identify an appropriate lawful basis. Depending on the circumstances this may be contract, consent, legitimate interests, recognised legitimate interests, legal obligation or vital interests.

Recognised legitimate interests are used only where processing meets one of the specific statutory conditions. The absence of a balancing test for that lawful basis does not remove the requirements of necessity, transparency, fairness, data minimisation or the other data protection principles.

5. Special category and criminal offence information

Where we process special category information, we identify both an Article 6 lawful basis and an applicable Article 9 condition. Where required, we maintain an Appropriate Policy Document. Criminal offence information is only processed where an appropriate lawful condition and safeguards apply.

6. Privacy information and transparency

We provide privacy information in a clear and accessible form. Our public Privacy & Cookies Policy explains how we use personal information and how individuals can exercise their rights.

7. Individual rights and subject access

We have processes for recognising and responding to requests relating to data protection rights. Subject access requests are handled without undue delay and normally within one month, subject to the circumstances permitted by law.

When responding to SARs, we carry out searches that are reasonable and proportionate. This does not justify superficial searches or arbitrary restrictions on the information sought.

Identity evidence is requested only where reasonably necessary and proportionate to verify the requester. Our online route is at Subject Access Request.

8. Data protection complaints

EDUK provides a clear and accessible way for people to complain about how their personal information has been handled. Data protection complaints are acknowledged within 30 days, investigated without undue delay, and complainants are kept appropriately informed and told the outcome.

Complaints and the action taken are recorded. See our Data Protection Complaints Procedure.

9. Automated decision-making and AI-assisted processing

EDUK does not currently make decisions about individuals that have legal or similarly significant effects based solely on automated processing. If such processing is introduced, we will identify an appropriate lawful basis, assess the risks and apply the safeguards required by law.

Where automated or AI-assisted systems support decision-making, we consider accuracy, transparency, accessibility, data quality and the risk of unfair or discriminatory outcomes. Human involvement will be meaningful where required rather than a token review.

10. Data protection by design, DPIAs and equality considerations

We consider privacy and data protection when designing or changing processes, systems and services. A Data Protection Impact Assessment (DPIA) is completed where processing is likely to result in a high risk to people’s rights and freedoms.

Where relevant, we also consider whether data practices or technology could create unequal or discriminatory effects, including barriers for disabled people, digitally excluded people or other groups who may be disproportionately affected.

11. Sharing personal information

Personal information is shared only where there is a lawful and necessary reason. Recipients may include service providers, training partners, professional advisers, regulators and public authorities. Appropriate contractual or other safeguards are used where required.

We do not sell personal information.

12. International transfers

Where personal information is transferred outside the UK, we ensure an appropriate transfer mechanism or exception applies, which may include UK adequacy regulations, the IDTA, or the UK Addendum to the EU Standard Contractual Clauses.

13. Security

We apply organisational and technical security measures appropriate to the information and risks involved, including access controls, secure systems, staff awareness and training, supplier review, secure disposal and incident management.

14. Retention and disposal

Personal information is retained only for as long as necessary for its purpose and relevant legal, contractual, accounting or regulatory requirements. Retention periods are reviewed and information securely deleted or disposed of when no longer required.

15. Personal data breaches

Suspected personal data breaches are assessed promptly. Where notification to the ICO is required, we do so without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Individuals are notified without undue delay where the law requires it.

16. Cookies and electronic marketing

We comply with PECR and applicable data protection law when using cookies, similar technologies and electronic marketing. We obtain consent where required and only rely on an exception where its statutory conditions are met.

17. Children’s information

If we provide an online service likely to be accessed by children, we expressly take children’s needs into account when deciding how their personal information is used and apply appropriate protections.

18. Responsibilities and training

Anyone handling personal information on EDUK’s behalf must follow relevant policies and procedures, protect confidentiality, report suspected breaches promptly, and complete appropriate data protection awareness or training.

19. Contact

Data Protection Department
Equality and Diversity UK
Warwick House
14 Lowes Road
Bury
BL9 6PJ
Email: dp@equalityanddiversity.co.uk

Related policies