Privacy & Data Protection Policy
HGSL Privacy Policy
Howden Group Services Limited
| Owner | Robert de Souza |
|---|---|
| Approved by | Andy Searle – Group Data Protection Officer |
| Date | July 2026 |
| Review Due | July 2027 |
| Version | V8.5 |
| Applicability | Howden Group Services Limited |
Contents
| 01. Overview |
| 02. Processing Your Data |
| 03. Departmental Data Processing Tables |
| 04. Legal Basis |
| 05. Processing Special Categories of Personal Data |
| 06. Criminal Conviction Data |
| 07. Consent |
| 08. Data Collection |
| 09. Data Retention |
| 10. Data Sharing |
| 11. Transfer of Personal Information |
| 12. Use of Artificial Intelligence and Automated Decision-Making |
| 13. Server-Side Tracking and Storage/Access Technologies |
| 14. Your Rights |
| 15. Queries |
| 16. Version control |
| 17. Policy Approval History |
01. Overview
Howden Group Services Limited (HGSL), part of Howden, is committed to protecting the privacy and security of your personal information. In this Policy, “we”, “us” and “our” means HGSL. This Policy explains how we collect, use, store and protect personal information in line with applicable data protection law, including UK data protection law and, where relevant, other privacy, electronic communications and AI and financial services regulatory requirements.
This Policy explains how we process personal information about individuals that we collect during the normal course of business. It explains what information we collect, why we use it, who we may share it with, how long we keep it and what rights you have.
02. Processing Your Data
We are the controller for the personal data covered by this Policy. This means we decide why and how that information is used.
Our registered office is One Creechurch Place, London, United Kingdom, EC3A 5AF. The data protection contact is the Data Protection Officer: [email protected]
When we use personal information, we follow the main data protection principles. In practical terms, this means we use your information fairly and transparently, only for clear purposes, only where we need it, keep it accurate, protect it, and keep appropriate records showing how we comply.
We may update this Policy from time to time. If we make a material change to how we use personal information, we will let you know or make the updated Policy available to you.
Where we process personal data to support an FCA- or PRA-regulated Howden entity, we identify the relevant controller, purpose and legal basis. A regulatory requirement does not remove the need to comply with data protection principles, including fairness, transparency, necessity, proportionality and data minimisation.
03. Departmental Data Processing Tables
The tables below explain, in practical terms, the main types of information different departments may process. They are examples rather than a complete list. Where more than one lawful basis is shown, the basis we use depends on the specific activity. We do not rely on all of them at once or apply them without review. For higher-risk activities, such as legitimate interests, sensitive data, criminal offence data, AI, monitoring or tracking, the applicable basis and any extra-legal condition should be assessed and recorded where required. The exact information used, lawful basis and retention period will depend on the activity, the people affected and any relevant notice, policy or contract.
3.1 Human Resources (HR)
HR uses personal data as part of the recruitment process, to manage the employment relationship, to administer pay and benefits, support employees and meet applicable legal & contractual obligations.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Name, home address, date of birth, personal and work contact details, employee ID, photograph, emergency contacts and next of kin. | To recruit and onboard you, manage your employment or engagement, keep workforce records, support travel and emergencies, and maintain internal directories. |
|
| Nationality, immigration or right-to-work evidence, references, qualifications, licences and relevant screening results. | To check you can work, assess suitability for a role, meet regulatory requirements and help prevent fraud. |
|
| Bank details, payroll records, pension and benefit details, expenses, bonus records, HMRC information and National Insurance number. | To pay you, administer benefits and pensions, process tax deductions, meet reporting duties and support finance controls. |
|
| Appraisals, disciplinary and grievance records, attendance, training, promotion and succession planning information. | To manage performance, conduct, capability, employee relations, workforce planning, training and legal claims. |
|
| Sickness information, occupational health reports, reasonable adjustment needs, diversity monitoring responses and accident records. | To manage absence, health and safety, equality monitoring, reasonable adjustments, well-being support and statutory reporting. |
|
| CVs, application forms, interview notes, psychometric results and approved meeting transcripts or summaries. | To assess candidates, make hiring decisions, keep an audit trail and handle challenges or appeals. |
|
| Information generated as part of the general course of business including business activity information, system access logs, CCTV. | Investigations into allegations of fraud & misconduct, breaches of contract, internal policies/procedures, breaches of external regulations or other civil/criminal offences |
|
| Social mobility and diversity monitoring data, such as type of school attended, eligibility for free school meals and highest level of qualifications obtained, where collected. | To support voluntary diversity, inclusion and social mobility monitoring and reporting, and to assess the effectiveness and fairness of recruitment and employment practices. |
|
3.2 Legal
The Legal team may use information about employees, clients, directors, officers, suppliers, claimants, witnesses, complainants, shareholders and other third parties where this is needed for legal work, governance, advice, claims, investigations or regulatory matters.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Names, job titles, signatures, business contact details, correspondence, negotiation history, instructions and approvals. | To draft, review, negotiate and manage contracts, transactions, disputes and legal advice. |
|
| Director details, shareholder information where relevant, declarations of interest, board minutes, registers and filings. | To manage legal entities, governance, Companies House filings, internal approvals and audits. |
|
| Statements, allegations, emails, interview notes, evidence bundles, settlement details and related communications. | To handle investigations, complaints, litigation, regulator responses and legal claims. |
|
| Identity details, ownership information, adverse media, sanctions matches and conflict declarations. | To carry out risk screening, conflicts checks, anti-fraud, anti-bribery and due diligence work. |
|
| Criminal offence, alleged offence, misconduct, sanctions or regulatory-risk information where relevant, necessary and lawful. | To support investigations, whistleblowing, disciplinary escalation and legal risk management. |
|
| Personal data included in communications with external advisers, courts, regulators or authorities. | To obtain advice, meet legal or regulatory requests, cooperate with regulators and record disclosure decisions. |
|
3.3 Finance
Finance may use information about employees, clients, suppliers, payees, advisers and other business contacts where this is needed for payroll, payments, expenses, tax, audit and financial controls.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Names, payroll IDs, bank details, pay, deductions, tax codes, pension information and expenses. | To run payroll, reimburse expenses, keep accounts, report tax, support audits and maintain finance controls. |
|
| Supplier contact details, invoice approvers, bank details and payment history. | To onboard suppliers, process invoices, make payments, reconcile accounts and prevent fraud. |
|
| Contact details, remittance records and payment correspondence. | To manage billing, collections, financial administration and payment disputes. |
|
| HMRC identifiers, transaction support, declarations and supporting evidence. | To meet tax, statutory reporting, audit, anti-fraud and internal control requirements. |
|
| Access logs, approval trails, exception reports and investigation records. | To prevent unauthorised payments, detect unusual activity and evidence approvals. |
|
| Travel, corporate card and expense documents, which may sometimes include sensitive details such as accommodation needs. | To reimburse expenses, support travel, keep an audit trail and help with wellbeing accommodations. |
|
3.4 Procurement
Procurement may use information about supplier contacts, bidders, consultants, agency representatives, referees and internal business owners to manage sourcing, onboarding, contracts and supplier risk and, where applicable, support regulatory reporting on material third-party arrangements.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Supplier and bidder names, job titles, work email addresses, phone numbers, signature blocks and meeting notes. | To source services, run tenders, negotiate contracts, onboard suppliers and manage supplier relationships. |
|
| Beneficial ownership details, sanctions or KYC results, insurance contacts, declarations and conflicts information. | To assess suppliers, manage third-party risk, meet regulatory needs and help prevent fraud. |
|
| CVs of proposed consultants, capability statements and references. | To evaluate tenders, score proposals, check suitability and manage contract performance. |
|
| Supplier contact names, escalation records, complaints, incidents and corrective actions. | To manage supplier performance, resolve issues, maintain service quality and support audits. |
|
| Banking and payment setup information for suppliers or independent contractors. | To set up authorised payments, process invoices and prevent payment diversion fraud. |
|
| Supplier diversity, sustainability or workforce metrics where relevant. | To support supplier reporting, responsible procurement and contractual commitments. |
|
| Supplier owners, key contacts, service and data locations, subcontractor contacts, incident and resilience records, risk assessments and materiality classifications. | To maintain third-party inventories, assess material arrangements, support operational resilience, and prepare required notifications or register submissions to the FCA or PRA. |
|
3.5 Corporate Services
Corporate Services may use information about visitors, employees, contractors, event attendees, travel bookers and facilities contacts to run offices safely and effectively.
This includes reception, facilities, office administration, business continuity and physical security. CCTV, access control and visitor records should be clearly signposted, kept only for a defined period and accessed only by people who need them.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Visitor names, employer, contact details, host, times in and out, and badge details. | To manage reception, building access, health and safety, evacuation and site security. |
|
| Access card logs, CCTV images, alarm records and incident reports. | To keep premises secure, investigate incidents, protect assets and support safety. |
|
| Travel plans, event details, dietary needs, accessibility needs, seating lists and emergency contacts. | To arrange travel, deliver events and support visitors and employees. |
|
| Mailroom, courier and workplace operation records such as sender, recipient, delivery reference and service tickets. | To support business continuity, secure delivery, records administration and facilities support. |
|
| Accident forms, witness details, first-aid logs and evacuation records. | To meet health and safety duties, respond to incidents, support insurance and manage claims. |
|
| Desk or locker allocations, equipment issue logs and office service requests. | To provide a safe working environment and manage internal office services. |
|
3.6 IT
IT may use information about employees, clients, contractors, visitors using guest systems, supplier support contacts and other authorised users of our systems to keep systems secure and working properly.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Usernames, email addresses, employee IDs, roles, MFA details, password reset records and directory information. | To set up and manage system access, authenticate users, apply least privilege and run IT services. |
|
| IP addresses, device IDs, login history, browser or system data, support tickets and activity logs. | To protect systems, troubleshoot issues, monitor performance, detect incidents and keep audit trails. |
|
| Email, collaboration and telephony metadata and, where authorised, content. | To support services, security reviews, business continuity, e-discovery, legal holds and investigations. |
|
| Helpdesk queries, call recordings where used, screenshots, remote support sessions and support tickets. | To fix issues, fulfil requests, maintain systems and improve support. |
|
| Malware alerts, anomaly detections, vulnerability scans, DLP incidents and forensic records. | To detect threats, investigate security issues, respond to incidents and improve resilience. |
|
| Backup, disaster recovery and restoration records that may contain copies of live personal data. | To support business continuity, test resilience and restore services after incidents. |
|
| Cookies, tags, pixels, click and link data, IP addresses, device and browser data, timestamps, session IDs, page interactions, consent choices and email open or click data where applicable. | To secure, operate and improve employee, candidate and internal platforms, manage preferences, measure performance and detect misuse or security issues. |
|
| Incident reports, affected-user and supplier contact details, service-impact records, system logs, remediation actions and regulator correspondence. | To investigate and manage operational or personal data incidents, assess notification thresholds and report to the FCA, PRA, ICO or other authorities where required. |
|
3.7 Internal Audit
Internal Audit may use information about employees, clients, directors, process owners, suppliers, whistleblowers, complainants, witnesses and others where this is needed for audit work, assurance, investigations or tracking actions.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Names, job titles, work contact details, audit sponsors, control owners, meeting records and risk assessments. | To plan audits, define scope, allocate responsibilities and record risk-based oversight. |
|
| Emails, approvals, transactions, access logs, screenshots, reports and extracts used as audit samples. | To test controls, support findings, check compliance and evidence conclusions. |
|
| Interview notes, declarations, explanations, action owners and sign-offs. | To carry out fieldwork, verify facts, record responses and agree actions. |
|
| Issue logs, action trackers, deadlines, escalation records and status updates. | To track actions, report overdue items and support governance committees. |
|
| Allegations, witness details, disciplinary information or misconduct evidence where Internal Audit supports an investigation. | To support investigations, fraud reviews, control failure analysis and legal claims. |
|
| Board, Audit Committee and senior management reporting packs with named stakeholders or escalation histories. | To provide assurance reporting, escalate material risks and evidence governance oversight. |
|
3.8 Business Services
Business Services may use information about employees, contractors, internal requestors, supplier contacts, service recipients, consultants, visitors and others involved in shared-service or operational support.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Names, job titles, work contact details, request descriptions, correspondence, tickets and status updates. | To manage service requests, coordinate support, resolve queries and keep an audit trail. |
|
| Requestors, approvers, timestamps, comments, attachments and completion histories. | To run workflows, validate approvals, allocate work and evidence internal controls. |
|
| Names, work email addresses, phone numbers, roles and meeting notes. | To coordinate shared services, communicate with stakeholders and maintain operating procedures. |
|
| Supplier and outsourced support contacts, escalation paths, service reviews and issue logs. | To manage third-party service relationships, resolve incidents and support continuity. |
|
| Reports that may include named owners, productivity metrics, case histories or exceptions. | To produce service reporting, identify bottlenecks, allocate resources and improve performance. |
|
| Travel, event or administrative support records, including itineraries, accessibility needs or emergency contacts where relevant. | To coordinate logistics, support business operations and help with staff welfare. |
|
3.9 Company Secretariat
Company Secretariat may use information about directors, officers, shareholders, persons with significant control, board and committee attendees, authorised signatories, advisers and governance contacts.
Information we may use | Why we use it | Our legal bases |
|---|---|---|
| Director, officer and authorised signatory details, including names, service address, required date of birth elements, nationality, appointments, specimen signatures and work contact details. | To manage entities, approvals, statutory records, delegations and authorised signatories. |
|
| Board and committee attendee lists, biographies, declarations of interest, minutes, resolutions, approvals and action trackers. | To support board and committee administration, record decisions, manage conflicts and evidence governance. |
|
| Director, secretary, PSC and shareholder information and Companies House submission records. | To maintain statutory registers, make filings and show compliance with corporate governance duties. |
|
| Due diligence contacts, reorganization approvals, signing authorities and adviser correspondence. | To support incorporations, restructurings, intercompany governance, transactions and record management. |
|
| Conflict, independence and related-party declarations, registers of interests and annual confirmations. | To manage governance risks, conflicts and board, audit or regulatory review. |
|
| Shareholder, ownership and investor communication records, including contact details, notices and voting documents where relevant. | To manage shareholder communications, approvals, written resolutions and corporate records. |
|
04. Legal Basis
We need a lawful reason to process your personal data. The main reasons we rely on are set out below and in the tables above. In plain terms, we may use your personal data because it is needed for your employment or engagement, because the law or regulation requires it, because it is needed for legal claims, because it protects someone in an emergency, or because we or another party has a legitimate business reason that does not unfairly override your rights.
- For the performance of a contract relating to you
- For compliance with a legal or regulatory obligation to which we are subject
- To initiate/defend legal claims
- To protect the vital interests of individuals
- For our Legitimate Interests (or those of a third party)
- With your consent
When we rely on legitimate interests, we consider whether the use is necessary, proportionate and fair to the people affected. Where required, we record this assessment. Our legitimate interests include recruiting suitable people, managing and supporting staff, running the business effectively, protecting our systems and premises, meeting governance standards and defending legal claims. Where more than one lawful basis could appear relevant, we choose the most appropriate basis for the purpose and check whether any extra condition is needed for sensitive or criminal offence data.
Where personal data is processed to meet an FCA or PRA requirement, legal obligation is relied on only where that obligation applies to HGSL or the relevant controller. Where HGSL supports another Howden entity, the controller and processor roles, lawful basis and decision-making responsibilities are documented.
Some activities may be explained in more detail in local notices, contracts or other policies. We may also use information from corporate systems, such as system logs, email/Teams records, CCTV and building access records, where this is needed for security, compliance, business continuity or legitimate investigations.
05. Processing Special Categories of Personal Data
Some personal data is more sensitive and is defined as “special category data”. This includes information about health, disability, race or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, trade union membership, or similar information.
We only use this type of data where the law allows it, where we have a lawful reason and where an additional condition for sensitive data applies. Depending on the situation, this may include explicit consent, employment or social security law, health and safety, occupational medicine, equality monitoring, legal claims, substantial public interest or protecting someone in an emergency. Where the law requires an appropriate policy document or extra safeguards, we will put those in place.
Examples include checking right to work, supporting reasonable adjustments, managing sickness absence, administering benefits, meeting equality and diversity obligations, handling trade union-related rights, or managing grievances and complaints where the information is relevant. Diversity, equality and social mobility monitoring will be voluntary where appropriate and reported on an aggregated or anonymised basis where possible.
Where we process vulnerability-related information in support of a regulated activity, it may include special category data and other sensitive information about health, disability, financial difficulty, bereavement, communication needs or other circumstances affecting the support an individual requires. We seek to record the support need rather than unnecessary underlying detail, use structured indicators where appropriate, restrict access and periodically review whether the information remains accurate and necessary. We do not systematically collect new protected-characteristic data solely for regulatory outcome monitoring unless this is necessary, lawful and proportionate.
Access to special category data is limited to people who genuinely need it. We expect this information to be handled carefully, confidentially and only for the relevant purpose.
06. Criminal Conviction Data
In some circumstances, and only where the law allows it, we may need information about criminal allegations, offences or convictions. This may be relevant for pre-employment screening, regulated roles, policy risk assessments, fit and proper assessments, fraud enquiries, whistleblowing or misconduct investigations, safeguarding concerns or legal claims.
We only use criminal offence data where we have a valid legal basis and specific authority under data protection law. This may include employment or regulatory requirements, preventing or detecting unlawful acts, safeguarding, legal claims or substantial public interest. We do not rely on consent for criminal offence data unless this has been separately assessed as appropriate and lawful. Where required, we keep an appropriate policy document, restrict access and apply extra safeguards. The information is only used where it is reasonable and necessary.
07. Consent
Most of the time, we do not rely on consent to process personal data and instead, we usually rely on another lawful reason, such as contract, legal obligation or legitimate interests.
Where we do need your consent, we will ask for it separately and explain what we are asking you to agree to. We will also explain what happens if you choose not to give consent and, where the law allows, you may be able to withdraw consent at a later stage.
08. Data Collection
We usually collect information directly from you. We may also collect information from other people or organisations where this is necessary and lawful.
This may include information from your manager, family members or representatives, previous employers, recruitment agencies, screening providers, benefit providers, professional bodies, government agencies such as HMRC, courts or regulators, other insurance related entities & claims providers.
We do not deliberately collect more information than we need. If we ask you to provide information that is mandatory, we will tell you. If you do not provide information that is needed for a legal, contractual or essential business reason, we may not be able to complete the relevant process. For example, without bank details we cannot pay you.
You may sometimes provide information about other people, such as dependents, beneficiaries, emergency contacts or next of kin. Before giving us their information, please make sure they understand that you are sharing it with us and why.
09. Data Retention
We keep personal data for as long as we need it for the reason it was collected, and for any related legal, regulatory, audit or business requirement.
As a general rule, we keep most business records for seven years following the end of our relationship with you. This is a default position only and may be overridden by the HGH UK Retention, Archiving and Disposal (RAD) Policy, any applicable legal or regulatory requirement, local record schedules, system-specific retention rules or the purpose for which the data is held. Some records may be kept for shorter periods, such as CCTV, access logs or unsuccessful recruitment records, and some for longer periods, such as statutory, tax, pension, corporate governance, legal hold or claims records. More details are available in the HGH UK Retention, Archiving and Disposal (RAD) Policy.
If there is a legal hold, investigation, dispute, audit or regulatory request, deletion may be paused until the matter is resolved. When information no longer needs to be kept, it will be securely deleted, anonymised or destroyed using an appropriate method.
10. Data Sharing
We only share personal data where there is a proper reason to do so. Internally, we look to ensure that access is limited to people who need the information for their role.
This may include HR, your managers, senior management, Business Risk/Compliance, Legal, Information Security, IT, Finance, system administrators and other teams who need access for a specific task, system support, security, legal, regulatory or business reason.
Some basic work information, such as your name, role, contact details, location, employee number, photograph and published skills or experience profile, may be visible to other employees through internal systems.
We may also share information with trusted third parties that support our business, such as recruitment providers, screening providers, payroll and benefits providers, professional advisers, insurers, auditors, tax advisers, global mobility providers, employee survey providers, IT and HR system providers, government bodies and regulators.
Third parties may act as processors, independent controllers or, in limited cases, joint controllers depending on the service and the purpose of the sharing. Where a third party processes information on our behalf, they must follow our instructions and meet appropriate contractual, confidentiality and security requirements. Where a third party acts as an independent controller, we only share personal data where it is lawful and fair to do so, and where appropriate we provide or signpost relevant privacy information.
Where personal data is shared across a regulated product or distribution chain, or with a regulator, we limit the disclosure to what is necessary for the relevant purpose. We consider whether anonymised or aggregated information is sufficient, document the parties’ roles and apply appropriate data-sharing arrangements.
We may disclose limited personal data to the FCA, PRA, ICO or another competent authority when reporting or responding to an operational incident, personal data breach, material third-party arrangement or regulatory enquiry. Separate regulatory tests may apply, and reporting to one authority does not automatically satisfy any obligation to another.
11. Transfer of Personal Information
Your personal data may be accessed or used by other Howden group companies and by trusted service providers that support us. Some of these organisations, systems or support teams may be based outside the UK or the European Economic Area.
Where personal information is transferred internationally, we take steps required by applicable data protection law to protect it. Depending on the circumstances, this may include recognised transfer safeguards, transfer risk assessments, encryption, access controls, audit rights and technical separation of data.
If you would like more information about the safeguards used for transfers of your personal data, please contact the Data Protection Officer.
12. Use of Artificial Intelligence and Automated Decision-Making
Some approved tools used by us may include artificial intelligence (AI), machine learning, algorithms, profiling, automated decision-support, automated decision-making or general-purpose AI. These tools may be used to support activities such as recruitment administration, candidate assessment support, meeting transcription and summarisation, workforce administration, information retrieval, security, analytics and operational support.
AI can be useful, but it can also create risks such as unfair outcomes, bias, discrimination, inaccurate results, lack of transparency, over-reliance on automated outputs, security risks and confidentiality issues. Before approved AI tools process personal data, we assess the intended purpose, data used, necessity and proportionality, the people affected, accuracy, security, retention, access controls, human oversight, supplier arrangements, international transfers and whether a DPIA, legitimate interests assessment or AI governance review is required. AI outputs must not be treated as final where they may affect individuals unless there has been appropriate human review. Where AI supports an FCA-regulated activity, the assessment also considers Consumer Duty outcomes, the treatment of customers in vulnerable circumstances, senior management accountability and applicable FCA rules or guidance.
We do not use AI for practices prohibited by applicable law, such as unlawful manipulation, social scoring, prohibited biometric categorisation or workplace emotion recognition, unless a narrow lawful exception has been confirmed by Legal and Data Protection. We do not make significant decisions about you based solely on automated processing, including profiling, unless the use is lawful, approved, explained to you and subject to the safeguards required by law. Where those safeguards apply, you can ask for human involvement, make representations and challenge the decision.
AI use-case transparency - Where an approved AI tool processes personal data, we should describe the relevant use case in plain English where this is necessary and appropriate. This may include the personal data used, the purpose of use, the lawful basis, any relevant supplier or sharing arrangement, retention, safeguards and whether the tool only assists staff or materially supports decisions about individuals.
Human involvement, automated decision-making and profiling - Where AI is used only as a staff-support or decision-support tool, meaningful human involvement should remain in place and staff must not treat AI outputs as final without appropriate review. Where automated processing, profiling or AI is used to make, or materially support, a decision with legal or similarly significant effects, we assess that use against the applicable automated decision-making requirements and apply the required safeguards.
Data protection assessment and DPIA - New initiatives involving personal data, including AI-enabled processing, should be assessed before go-live. A full DPIA is required where the processing is likely to result in a high risk to individuals. This may include new technology, profiling, large-scale processing, sensitive data, criminal offence data, monitoring or decisions affecting individuals. The level of assessment should be proportionate to the risk and supported by the relevant operational controls and approval process.
13. Server-Side Tracking and Storage/Access Technologies
We may use cookies, tags, pixels, scripts, link tracking, tag management tools and similar technologies to support business operations. Server-side tracking means information about how someone uses a website, application, email or online service may be sent to a server or tag-management environment before it is shared with approved internal teams or approved third-party providers. The information processed may include IP address, device and browser details, identifiers, login or session data, page views, button clicks, form events, referral information, timestamps, consent choices, security events and email open or click information. Where technology stores information on, or accesses information from, a user’s device, we assess whether consent is required. Where consent is required, we obtain it before using non-essential technologies and provide information about the technologies used and how choices can be managed.
14. Your Rights
You have rights over your personal data. These rights are not always absolute, and there may be situations where we cannot fully meet a request, but we will explain our position if that happens.
Access - you can ask for a copy of personal information we hold about you.
Correction - you can ask us to correct information that is wrong or incomplete, if you cannot correct yourself.
Erasure - you can ask us to delete information where there is no longer a valid reason for us to keep it, where consent has been withdrawn and no other lawful basis applies, where you have successfully objected, or where the information has been used unlawfully.
Portability - where we use information you provided to us based on consent or contract and the processing is automated, you can ask to receive it in a structured, commonly used and machine-readable format. You can also ask us to transfer it to another controller where technically possible.
Restriction - you can ask us to restrict how we use information in certain circumstances, for example while accuracy is being checked, where the use is unlawful, but you do not want deletion, where you need the information for legal claims, or while we assess an objection.
Objection - where we rely on legitimate interests, you can object to that use. We will stop unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the information for legal claims.
Withdraw consent - where we rely on your consent, you can withdraw it at any time. This will not affect processing that took place before consent was withdrawn.
Automated decision-making and profiling - where a significant decision is made about you based solely on automated processing, including profiling, we apply the safeguards required by law. This includes giving you meaningful information about the decision and a route to make representations, ask for meaningful human intervention and challenge the decision, unless a lawful exemption applies.
Complaints - if you are unhappy with how we use your information, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO). The ICO contact details are below.
Data protection complaints process - If you make a data protection complaint, you can raise it with the Data Protection Officer. We acknowledge eligible data protection complaints within 30 days, take appropriate steps to investigate and respond without undue delay, keep you informed where appropriate, record the complaint and tell you the outcome. Complaints received through the DPO mailbox, HR, Legal, Compliance, IT or another route should be triaged and escalated to the appropriate data protection owner. This does not affect your right to complain to the ICO.
| England | Scotland | Wales | Northern Ireland |
|---|---|---|---|
Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF | Information Commissioner's Office 45 Melville Street Edinburgh EH3 7HL | Information Commissioner's Office 2nd floor Churchill House Churchill way Cardiff CF10 2HH | Information Commissioner's Office 3rd Floor 14 Cromac Place Belfast BT7 2JB |
| Tel: 0303 123 1113 | Tel: 0131 244 9001 | Tel:029 2067 8400 | Tel: 0303 123 1114 |
| Email: [email protected] | Email: [email protected] | Email: [email protected] | Email: [email protected] |
15. Queries
If you have a question, want to exercise your rights, or want to raise a concern about how your personal information is used, please contact the Data Protection Officer at [email protected]
Routing and ownership - Where a complaint relates to another Howden operating business or another controller, we may route or coordinate the complaint with the relevant business or controller so that it is handled by the correct owner.
You can raise privacy concerns or complaints, including electronically where appropriate. Eligible data protection complaints will be acknowledged within 30 days and responded to without undue delay.
16. Version control
| Version number | Author | Date |
|---|---|---|
| V1 | AM | April 2018 |
| V2 | AM | August 2018 |
| V3 | AM | February 2019 |
| V4 | AM | September 2019 |
| V5 | AS | November 2020 |
| V6 | AS | April 2021 |
| V7 | AS | September 2021 |
| V8 | AS | February 2022 |
| V8.1 | AS | October 2022 |
| V8.2 | Andy Searle | November 2024 |
| V8.3 | Andy Searle | November 2025 |
| V8.4 | Robert de Souza | June 2026 |
| V8.5 | Robert de Souza | July 2026 |
17. Policy Approval History
| Version number | Approver | Date |
|---|---|---|
| V8.2 | Andy Searle and Emily Marshall | November 2024 |
| V8.3 | Andy Searle & Brian Davidson | November 2025 |
| V8.4 | Andy Searle & Rob de Souza | June 2026 |
| V8.5 | Andy Searle & Rob de Souza | July 2026 |
This is an internal document intended for use by Howden and should not be relied upon, cited or used by any third party without express permission.