GDPR and Data Protection Policy.

Document Version: 2026.11

Effective Date: 11/08/2026

Date last updated: 11/08/2026

1.Purpose

This policy explains how ACS-APT Computer Systems Ltd (the Company) will comply with applicable data protection law and protect personal data throughout its lifecycle. It establishes responsibilities and minimum controls for personal data processed in connection with customers, prospects, suppliers, personnel, contractors, website users and other individuals.

The Company will apply this policy alongside its privacy notices, information security policies, retention schedule, records of processing activities, incident response procedure, employee policies and contracts with customers, suppliers and processors.

2.Scope                                                                                      

This policy applies to all directors, employees, temporary workers, contractors and other persons who process personal data for or on behalf of the Company. It applies to personal data in electronic and paper form, whether the Company acts as controller, joint controller or processor.

  • All business systems, devices, networks, cloud services, email, collaboration tools, support platforms, backups and physical records.

  • All stages of processing, including collection, use, access, disclosure, storage, transfer, archiving and deletion.

  • Processing carried out in the United Kingdom and, where applicable, processing subject to the EU GDPR or other local privacy laws.

3.Legal and Regulatory Framework

The Company will comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and applicable amendments including those made by the Data (Use and Access) Act 2025. If the Company offers goods or services to, or monitors individuals in, the European Economic Area, it will also assess and meet applicable EU GDPR obligations, including representative requirements where relevant.

Where another law imposes a higher or additional standard, the Company will identify and apply that requirement to the relevant processing.

4.Key Definitions

Term Meaning
Personal data Information relating to an identified or identifiable living individual.
Special category data Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health data, or data about sex life or sexual orientation.
Criminal offence data Personal data relating to criminal convictions, offences or related security measures.
Processing Any operation performed on personal data, including collection, access, use, sharing, storage, alteration or deletion.
Controller The person or organisation that determines why and how personal data is processed.
Processor A person or organisation that processes personal data on behalf of a controller.
Personal data breach A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Data subject The individual to whom personal data relates.

5.Data protection principles

The Company will ensure that personal data is:

  • processed lawfully, fairly and transparently;

  • collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes;

  • adequate, relevant and limited to what is necessary;

  • accurate and kept up to date where necessary;

  • kept in identifiable form no longer than necessary;

  • protected by appropriate technical and organisational security measures; and

  • processed under demonstrable accountability and governance controls.

6.Governance and Responsibilities

6.1  Board and senior management

Senior management is accountable for ensuring that adequate resources, authority and oversight are provided for data protection compliance. It approves this policy, reviews material risks and breaches, and requires remediation where controls are ineffective.

6.2 Data Protection Lead

Data Protection Officer - Sailesh Devlukia

ACS-APT Computer Systems Ltd

Unit 22, Empire Centre,

Imperial Way

Watford

Hertfordshire

WD24 4YH

Email:Contact@acs-apt.com

Tel: 01923 244444

The Data Protection Lead coordinates compliance, maintains this policy and the records of processing activities, advises on data protection impact assessments (DPIAs), manages rights requests and breach assessments, oversees training, and reports significant matters to senior management. The Company will document whether appointment of a statutory Data Protection Officer is required. If appointed, the DPO must operate independently and report to the highest management level.

6.3 Managers and System Owners

Managers and system owners must identify personal data in their areas, maintain accurate processing records, enforce least-privilege access, complete supplier due diligence, apply retention rules, escalate incidents and consult the Data Protection Lead before introducing or materially changing processing.

6.4 All personnel

All personnel must follow this policy, use personal data only for authorised business purposes, keep credentials and devices secure, complete training, promptly report incidents and suspected breaches, and seek advice where requirements are unclear.

7.Data inventory and records of processing

The Company will maintain proportionate records of processing activities (ROPA) and data flows. Records must describe categories of individuals and data, purposes, lawful bases, recipients, transfers, retention, systems, processors and security measures. Records will be reviewed at least annually and when processing changes.

  • Business owners must notify the Data Protection Lead before deploying a new system, integrating a new data source, changing purposes, collecting new data fields or sharing data with a new party.

  • The Company will keep evidence supporting lawful-basis decisions, consent, legitimate interests assessments, DPIAs, processor reviews, rights requests and breach decisions.

8.Lawful, fair and Automated Decision-Making

8.1 Lawful bases

A documented lawful basis must be identified before personal data is processed. Depending on the purpose, the Company may rely on consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, or legitimate interests that are not overridden by individuals’ interests, rights and freedoms.

Where legitimate interests is relied upon, the Company will complete and retain a legitimate interests assessment where appropriate. Consent will be specific, informed, freely given, unambiguous, recorded and as easy to withdraw as to give.

8.2 Special Category and Criminal offence data

The Company will process special category data only where both an Article 6 lawful basis and an Article 9 condition apply. Criminal offence data will be processed only with official authority or where authorised by law, with any required policy document and safeguards. Access will be strictly restricted..

8.3 Privacy Information

Individuals will receive concise, intelligible and accessible privacy information at or before collection, or within the legally permitted period where data is obtained elsewhere. Notices will state the controller’s identity and contact details, purposes, lawful bases, recipients, transfers, retention, rights, complaint routes and any relevant automated decision-making information.

8.4 Privacy Limitation

Personal data must not be used for a new incompatible purpose without a documented compatibility assessment, a new lawful basis where required, and updated privacy information. Personnel must not use customer or employee data for personal purposes.

9.Data minisation and accuracy

The Company will collect only the personal data reasonably necessary for defined purposes. Forms, integrations, reports and exports will be reviewed to remove unnecessary fields. Where practicable, data will be aggregated, anonymised or pseudonymised.

Reasonable steps will be taken to keep personal data accurate and current. Material inaccuracies will be corrected or deleted promptly, and recipients will be informed where required.

10.Retention and secure disposal

Personal data will be retained only for as long as necessary to fulfil the documented purpose for which it was collected, to comply with applicable legal, regulatory, tax and accounting obligations, to manage disputes or establish, exercise or defend legal claims, and to meet legitimate business needs where an appropriate lawful basis exists 

The Company will maintain and periodically review a data retention schedule covering relevant categories of personal data and records. The schedule will identify, as appropriate, the record category, responsible owner, retention trigger, applicable retention period and approved disposal method.

Typically, contract-related personal data will be retained for no longer than 10 years following the end of the relevant contractual relationship, unless a longer retention period is required or permitted by applicable law, or is reasonably necessary for the establishment, exercise or defence of legal claims.

Billing, accounting and transaction records will be retained for at least 7 financial years, where required for applicable tax, accounting and audit purposes. Other personal data will be retained for the minimum period required by applicable law or, where no statutory retention period applies, for no longer than is reasonably necessary for the purpose for which it was collected and while the Company continues to have a lawful basis for its processing.

Retention periods will be reviewed periodically and when there are material changes to legal, regulatory, contractual or business requirements. Personal data should not be retained indefinitely merely because storage remains available or because it may potentially be useful in the future.

At the end of the applicable retention period, and where there is no continuing legal, regulatory, contractual or legitimate business requirement for retention, personal data will be securely deleted, destroyed or irreversibly anonymised in accordance with the Company's data retention and disposal procedures. Disposal requirements will apply, as appropriate, to active systems, removable media and physical/paper records.

Where personal data is held in backup or archival systems and cannot reasonably be deleted immediately, it will be protected from further routine processing and will be deleted, overwritten or otherwise rendered inaccessible in accordance with the Company's established backup lifecycle and retention procedure

Where records are subject to a legal hold, regulatory investigation, dispute, litigation or other requirement that necessitates continued retention, routine deletion will be suspended for the affected records. Any such hold, including its scope, reason, owner and subsequent release, must be appropriately documented. Once the hold is released, the applicable retention and secure disposal requirements will resume.

11.Security of personal data

The Company will implement risk-appropriate technical and organisational measures to protect confidentiality, integrity, availability and resilience. Controls will be proportionate to the nature, volume, context and risks of the processing and will be tested and reviewed regularly.

  • role-based access, least privilege, prompt access removal and periodic access reviews;

  • multi-factor authentication where supported, strong authentication and secure credential management;

  • encryption in transit and at rest where appropriate, with controlled key management;

  • secure configuration, patching, endpoint protection, logging, monitoring and vulnerability management;

  • segregation of customer environments and controlled administrative access;

  • resilient backups, tested restoration and business continuity arrangements;

  • secure development, change control, testing and vulnerability remediation;

  • physical security, clear-desk practices and secure disposal; and

  • staff confidentiality obligations, awareness training and phishing/social-engineering controls.

Personal data must not be copied to unauthorised devices, personal email, consumer cloud storage, unapproved AI services or removable media. Remote access and home working must comply with the Company’s security requirements.

12.Data protection by design and default

Data protection must be embedded into procurement, system design, software development, customer implementations and process change. Default settings will limit collection, visibility, access, sharing and retention to what is necessary.

A DPIA must be completed before processing that is likely to result in high risk to individuals, including certain large-scale monitoring, sensitive-data processing, innovative technology, systematic profiling or decisions with significant effects. High residual risk must be escalated to the Data Protection Lead and, where legally required, the ICO before processing begins.

13.Individual rights

Where required by applicable data protection law, the Company will facilitate the exercise of individuals’ rights in relation to their personal data. These may include the rights to:

be informed about the processing of their personal data;

  • access their personal data;

  • have inaccurate personal data rectified and incomplete data completed;

  • have personal data erased in certain circumstances;

  • restrict the processing of personal data in certain circumstances;

  • receive and transmit personal data under the right to data portability, where applicable;

  • object to processing in certain circumstances;

  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;

  • not be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects, except where permitted by law and subject to applicable safeguards; and

  • lodge a complaint with the Information Commissioner’s Office (ICO).

These rights are subject to the conditions, limitations and exemptions provided by applicable law.

All requests relating to individual rights must be forwarded immediately to the Data Protection Lead. The Company will verify the requester's identity where necessary, using measures that are reasonable and proportionate to the circumstances.

The Company will respond to valid requests without undue delay and, in accordance with the UK GDPR, normally within one month of receipt. Where permitted by law, this period may be extended by up to a further two months, taking into account the complexity and number of requests. The individual will be informed of any extension, and the reasons for it, within the initial one-month period. 

Requests will normally be handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may, where permitted by law, charge a reasonable fee reflecting the administrative costs involved or refuse to act on the request.

The Company will maintain appropriate records of rights requests and their handling, including identity verification where applicable, searches undertaken, information reviewed or disclosed, redactions, exemptions relied upon, decisions made and communications with the individual.

Rights Request contact:  contact@acs-apt.com

ACS-APT Computer Systems Ltd

Unit 22, Empire Centre,

Imperial Way

Watford

Hertfordshire

WD24 4YH

14.Children and vulnerable individuals

The Company does not intentionally offer services directly to children unless expressly approved. Before processing children’s data or targeting services to children, the business owner must consult the Data Protection Lead, assess age-appropriate transparency and consent requirements, and complete a DPIA where appropriate. Additional care will be taken where individuals may be vulnerable.

15.Direct marketing and cookies

Electronic marketing and use of cookies or similar technologies must comply with UK GDPR and PECR. Marketing lists must have a documented lawful basis and, where required, valid consent. Opt-outs and objections must be actioned promptly and suppression records retained only as necessary to honour preferences.

Non-essential cookies or similar technologies will not be set before valid consent where consent is legally required. The website must provide an accurate cookie notice and preference controls. Purchased or third-party marketing data must undergo documented due diligence before use.

16.Processors, Suppliers and customer data

16.1 Supplier and processor management

Before a supplier processes personal data, the Company will assess its security, privacy practices, location, sub-processors and ability to support compliance. A written contract must include all legally required processor terms, including documented instructions, confidentiality, security, sub-processor controls, support for rights and breaches, deletion or return, and audit information.

Material processors will be reviewed periodically and on significant change. Unapproved suppliers must not be used to process Company or customer personal data.

16.2 Acting as a processor

Where the Company processes personal data for a customer, it will act only on documented lawful instructions, ensure confidentiality and security, control sub-processors, assist the customer with rights requests, DPIAs and breaches as contractually required, and delete or return data at the end of services unless law requires retention. Instructions believed to infringe data protection law will be escalated.

17.Data sharing and disclosures

Personal data may be shared only where authorised, necessary, proportionate and supported by a lawful basis. Recipients must be verified, and data minimised. Regular or high-risk sharing must be governed by an appropriate agreement or documented arrangement.

Requests from law enforcement, regulators, courts or third parties must be referred to the Data Protection Lead or authorised senior manager. The Company will validate the requester, legal authority and scope, and will record the decision. Emergency disclosures to protect vital interests must be documented as soon as practicable.

18.International transfers

The Company will ensure that any transfer of personal data outside the United Kingdom is undertaken in accordance with applicable data protection law, including the UK GDPR and Data Protection Act 2018.

Before making an international transfer, the Company will identify and document the countries involved, the exporter and recipient(s), the categories of personal data and data subjects affected, the purpose and necessity of the transfer, any onward transfers, and the lawful transfer mechanism relied upon.

Where personal data is transferred to a country or recipient not covered by applicable UK adequacy regulations, the Company will ensure that an appropriate safeguard or other lawful transfer mechanism is in place. This may include, as applicable, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised under applicable UK data protection law.

Where required, the Company will complete and retain an appropriate transfer risk assessment before the transfer takes place. The assessment will consider whether the relevant transfer mechanism provides effective protection in the circumstances of the transfer, including relevant laws and practices in the destination country and the nature and sensitivity of the personal data.

Where necessary, the Company will implement appropriate supplementary contractual, technical and/or organisational measures to ensure an appropriate level of protection. Such measures may include encryption, pseudonymisation, access restrictions, data minimisation, enhanced contractual controls, security requirements and controls governing onward transfers.

International transfers must be subject to appropriate due diligence, contractual controls and ongoing review. The Company will take reasonable steps to ensure that recipients process personal data consistently with the protections required by applicable data protection law and that any onward transfer is appropriately controlled.

Access to personal data from outside the United Kingdom, including remote access by employees, contractors, group companies or service providers located overseas, may constitute an international transfer and must therefore be identified and assessed before such access is authorised.

The Company will provide individuals with appropriate information about international transfers, including the relevant safeguards and how to obtain further information about those safeguards, where required by law.

Records of international transfers, transfer mechanisms, assessments, supplementary measures and relevant approvals will be retained as part of the Company's data protection and accountability records. International transfer arrangements will be reviewed periodically and when there is a material change to the transfer, recipient, destination country, applicable law, processing activity or associated risk.

19.Automated decision-making AI

The Company will identify processing involving profiling, AI or automated decision-making. Personal data must not be entered into unapproved AI services. Before deploying AI that uses personal data, the business owner must document the purpose, lawful basis, data provenance, transparency, accuracy, security, human oversight, bias and rights impacts, and complete a DPIA where high risk is likely.

Solely automated decisions that produce legal or similarly significant effects will be used only where legally permitted and with required safeguards, including meaningful information and routes for human review and challenge.

20.Personal data breach management

Anyone who becomes aware of an actual or suspected personal data breach must immediately preserve evidence and report it through the Company’s incident route. They must not investigate beyond their competence, contact affected individuals, admit liability or notify external parties without authorisation.

Incident Route: Email to ACS Incident response team at Contact@acs-apt.com

The response team will contain the incident, establish facts, assess risks to individuals, document decisions, preserve evidence and coordinate recovery. All personal data breaches must be recorded, including those not reported externally

Where a breach is likely to risk individuals’ rights and freedoms, the Company will notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware. Where high risk is likely, affected individuals will also be informed without undue delay unless a lawful exception applies. Processor incidents must be reported to the relevant controller without undue delay in accordance with contract and law.

21.Training, confidentially and monitoring

Personnel will receive data protection and security training at induction and refresher training at least annually, with role-specific training for higher-risk functions. Completion will be recorded. Personnel are bound by confidentiality obligations that continue after their engagement ends.

The Company will monitor compliance through risk reviews, access reviews, supplier reviews, sampling, audits, incident trends and management reporting. Breaches of this policy may result in disciplinary action, contract termination and, where appropriate, legal or regulatory action.

22.Complaints and regulator contact

Privacy complaints must be acknowledged promptly, investigated fairly and documented. The Company will aim to resolve concerns directly while informing individuals of their right to complain to the Information Commissioner’s Office.

Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; website ico.org.uk. Verify contact details before external publication.

23.Policy review and exceptions

This policy will be reviewed at least annually and sooner after significant legal guidance, business change, technology change, audit findings, material incidents or changes in processing risk. The document owner will retain approval and version records.

Exceptions require a documented business justification, risk assessment, compensating controls, time limit and written approval from the Data Protection Lead and an appropriate senior manager. An exception cannot authorise unlawful processing.

Appendix A – Minimum implementation actions

Action Required outcome
Complete company details Insert registered address, company number, privacy contact, incident route, approver and dates.
Map processing Complete or refresh the ROPA and data-flow inventory for customers, staff, suppliers, marketing, website and support services.
Confirm roles Document when ACS-APT acts as controller, joint controller and processor; align contracts and notices.
Set lawful bases Record Article 6 bases and any Article 9/10 conditions; complete LIAs where appropriate.
Publish notices Approve separate customer/website, recruitment and workforce privacy notices.
Approve retention Create a record-category retention schedule and automated deletion controls.
Review suppliers Inventory processors and sub-processors; complete due diligence, transfer checks and Article 28 contract reviews.
Test rights handling Create an intake log, identity verification process, search playbook, redaction review and deadline tracking.
Test incident response Run a breach tabletop exercise covering the 72-hour assessment window and processor/customer escalation.
Train staff Deliver induction and annual refreshers; provide enhanced training for support, HR, sales, engineering and administrators.
Review ICO obligations Confirm data protection fee/registration position and monitor current ICO guidance, including changes under the Data (Use and Access) Act 2025.

Appendix B – Approval Record

Policy Owner: Sailesh Devlukia

Approved by: Rustum Khedkar

Effective date : 25/08/2026

Next scheduled review : 25/08/2027

Appendix C – Authoritative references         

  • Information Commissioner’s Office, Guide to accountability and governance (current guidance, including updates reflecting the Data (Use and Access) Act 2025): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/

  • Information Commissioner’s Office, Personal data breaches: a guide: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/

  • Data Protection Act 2018: https://www.legislation.gov.uk/ukpga/2018/12/contents

  • Information Commissioner’s Office, UK GDPR guidance and resources: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/