Privacy Notice v4.0 | thedataprivacygroup.com

Privacy Notice

The Data Privacy Group Ltd., trading as The DPG

Version 4.0  |  Last updated 4 September 2026

1. About this notice

This notice explains how The Data Privacy Group Ltd., trading as The DPG (“The DPG”, “we”, “us”, “our”), collects and uses personal data when you visit our websites, engage us as a client, express interest in our services, supply goods or services to us, or otherwise interact with us.

It applies to thedpg.com and thedataprivacygroup.com, and to our privacy centre and complaint form, which are hosted for us by our privacy management platform and appear within our own pages.

It covers the personal data for which we are the controller, meaning data we decide the purposes and means of processing for. Section 3 explains what happens where we act as a processor on behalf of our clients, which is a large part of what we do and is governed by different rules.

Separate notices apply to our people. If you are an employee, worker, contractor or job applicant, please refer to our privacy notice for staff or our candidate privacy notice rather than this document.

2. Who we are

The Data Privacy Group Ltd. is a company registered in England and Wales, company number 09457485, with its registered office at Chandos House, School Lane, Buckingham, MK18 1HD, United Kingdom. We trade as The DPG.

We are registered with the Information Commissioner’s Office under registration number ZA497846.

We are a data privacy, AI governance and vendor risk consultancy. We provide advisory services, fractional privacy and AI governance officers, professional services on privacy platforms, engineering services, and managed privacy services to organisations worldwide.

We are established in the United Kingdom. Our people work from the United Kingdom and, through an employer of record arrangement, from the Philippines and North Macedonia.

LocationAddress
Registered officeChandos House, School Lane, Buckingham, MK18 1HD, United Kingdom
OperationsUnity Place, Floor 2, Suite 21, 200 Grafton Gate, Milton Keynes, MK9 1UP, United Kingdom

3. When we are a controller and when we are a processor

As a controller

We decide how and why personal data is processed when we market our services, manage client and supplier relationships, run our business, and operate our websites. This notice describes that processing.

As a processor

When we deliver managed services, professional services or engineering services, we handle personal data belonging to our clients and under their instructions.

How we work with client data

As a matter of standard practice we work inside our clients’ own environments. Our people access the client’s own OneTrust, Transcend or MineOS tenant, and their other systems where required, using access the client grants and controls. Client personal data stays in the client’s systems. We do not routinely copy, export or store client personal data on DPG systems.

There is one exception. A client may occasionally ask us to manipulate a data set in a way that cannot be done inside their environment. Where that requires the data to be brought onto a DPG engineer’s device, we obtain the client’s specific written authorisation first. That authorisation records what data may be downloaded and what processing is permitted on it. The data is held only for the duration of that task and securely removed once the work is complete. This takes place under the terms of our data processing agreement with the client and is subject to our security controls.

In all of the above the client is the controller and their privacy notice governs the processing, not this one. If you believe your personal data is being processed by us on behalf of one of our clients and you wish to exercise your rights, please contact that organisation directly. If you contact us instead, we will pass your request to the relevant client and tell you we have done so, but we cannot act on it without their instruction.

Where our people hold roles in client organisations

We supply Data Protection Officers, Chief Privacy Officers and AI Governance Officers to clients on a fractional basis. When a member of our team acts in that capacity, they do so on behalf of the client organisation. Correspondence with them in that role is processing carried out by the client, not by us as controller.

4. How to contact us

We are not required to appoint a Data Protection Officer, and we have not appointed one. Accountability for data protection at The DPG sits with our Chief Trust Officer, and our published contact point for anything to do with personal data is privacy@thedpg.com.

PurposeContact
General privacy enquiriesprivacy@thedpg.com
Person responsible for data protectionMr Peter Borner, Chief Trust Officer
Direct contactpeter.borner@thedpg.com
Telephone+44 1908 915660
PostThe Chief Trust Officer, The Data Privacy Group Ltd., Chandos House, School Lane, Buckingham, MK18 1HD, United Kingdom

5. Who this notice applies to

We process personal data about:

  • Visitors to our websites
  • Prospective clients and their personnel
  • Clients and their personnel, including the individuals we work with day to day
  • Individuals who contact us, subscribe to our communications, download our materials, or attend our events and webinars
  • Suppliers, vendors and business partners, and their personnel
  • Individuals who exercise privacy rights with us, or who correspond with us about privacy matters
  • Professional advisers, insurers and other third parties in the ordinary course of business

6. What personal data we collect

Identification and contact data. Name, job title, employer, business email address, business telephone number, business postal address, professional profile information.

Relationship and engagement data. Records of our correspondence with you, meeting notes, records of services provided or discussed, contract details, and your preferences.

Marketing data. Subscription status, communication preferences, engagement with our emails and content, event and webinar attendance.

Financial and transactional data. Billing contact details, purchase orders, invoices, payment records. We do not collect payment card details through our websites.

Technical and online data. IP address, device and browser information, operating system, referring URLs, pages viewed, time spent, and similar analytics data, plus cookie and tracking identifiers. See our Cookie Notice for detail.

Meeting and call data. Where you meet with us online, the meeting may be recorded using the recording feature built into Microsoft Teams. We ask the participants for permission immediately before recording is enabled, and you may decline.

Rights requests and complaints. What you tell us when you use our privacy centre or our complaint form, or when you contact us about a privacy matter, including anything you choose to attach.

Recruitment data. Covered by our separate candidate privacy notice.

We do not seek to collect special category personal data about you in the ordinary course of our business. If you volunteer such data to us, for example accessibility requirements when attending an event, we process it only for that purpose and on the basis of your explicit consent.

7. How we collect personal data

Directly from you, when you contact us, complete a form, subscribe, attend an event, negotiate or enter into a contract, or correspond with us.

Automatically, through cookies and similar technologies on our websites. See section 10.

From third parties and public sources, including your employer, our clients, professional networking platforms, company registries, and publicly available sources, where we use these to identify and research prospective clients. Where we obtain your personal data from a source other than you, we will tell you within one month of obtaining it, or at the point we first contact you, unless an exemption applies.

8. Why we process personal data, and our legal basis

PurposePersonal data usedLegal basis
Providing advisory, fractional, professional, engineering and managed services to clientsIdentification, contact, relationship, financialContract, or legitimate interests where our client is a corporate entity and you are its personnel
Managing our relationship with clients and suppliersIdentification, contact, relationship, financialContract; legitimate interests
Business development, marketing and promoting our servicesIdentification, contact, marketing, technicalLegitimate interests for business-to-business direct marketing; consent where required by PECR
Operating, securing and improving our websitesTechnicalLegitimate interests; consent where required for cookies (see section 10)
Events, webinars and publicationsIdentification, contact, marketingConsent; legitimate interests
Meeting recordingMeeting and call dataConsent, asked for immediately before recording is enabled
Financial management, invoicing and credit controlIdentification, contact, financialContract; legal obligation; legitimate interests
Compliance with legal and regulatory obligations, including tax, accounting and anti-money-launderingIdentification, contact, financialLegal obligation
IT, network and information security, business continuity and fraud preventionTechnical, identificationLegitimate interests; legal obligation
Responding to privacy rights requests and complaintsIdentification, contact, correspondenceLegal obligation
Establishing, exercising or defending legal claims, and obtaining professional or insurance adviceAny of the aboveLegitimate interests; legal claims
Corporate transactions, including any sale, merger or reorganisationIdentification, contact, relationship, financialLegitimate interests

Our legitimate interests. Where we rely on legitimate interests, our interests are in operating, promoting, protecting and growing our business, maintaining our client and supplier relationships, and keeping our systems secure. UK law expressly recognises that direct marketing and ensuring the security of network and information systems may constitute legitimate interests. We have assessed our interests against your interests, rights and freedoms and consider our processing proportionate and within your reasonable expectations. You can ask us for a summary of the relevant balancing assessment, and you have the right to object at any time (see section 14).

9. Marketing

We send business-to-business marketing about our services, insights and events. Where we rely on consent, you may withdraw it at any time. Every marketing email includes an unsubscribe link, and you can also use our privacy centre in section 14 and choose “Stop marketing to me”. You have an absolute right to object to direct marketing at any time, and we will stop.

Withdrawing marketing consent does not affect service communications relating to a contract between us.

10. Cookies and similar technologies

Our websites use cookies and similar technologies. Our consent banner is operated using OneTrust.

Most non-essential cookies are set only where you have consented. UK law permits a limited set of low-risk cookies to be used without consent, including those used solely to collect statistical information to improve a service and those that adapt the appearance or function of a site to your preferences. Where we rely on those exceptions we give you clear information and a straightforward way to opt out.

You can change your preferences at any time through the cookie settings link on our websites. Full detail is in our Cookie Notice.

11. Who we share personal data with

We share the personal data described in this notice with:

  • Our people, including colleagues in the United Kingdom, the Philippines and North Macedonia, on a need-to-know basis
  • Our service providers and sub-processors, listed below
  • Our clients, where you are one of their personnel or where we are delivering services to them
  • Professional advisers, including lawyers, accountants, auditors and insurers
  • Regulators and authorities, where we are legally required to do so
  • Acquirers or investors, in connection with any actual or proposed corporate transaction

We do not sell personal data.

Our principal service providers

The providers below support our own business. Client personal data is not routinely placed into these systems, because we work inside our clients’ own environments as described in section 3.

ProviderPurposePrimary location of processing
MicrosoftEmail, productivity, collaboration, identityEU/UK, with support access from other regions
AtlassianProject and service managementUS and EU
PipedriveCustomer relationship managementEU
BreatheHRPersonnel recordsUK
XeroAccounting, invoicing and payrollUS and Australia
EMAPTAEmployer of record for our colleagues in the Philippines and North MacedoniaPhilippines, North Macedonia
DocuSign, PandaDocContract executionUS
CalendlyMeeting schedulingUS
KnowBe4Security awareness trainingUS
OneTrustConsent management for our own websitesUS and EU
MineOS (Saymine Technologies)Privacy management platform, including our privacy centre and complaint formEU
Anthropic, OpenAIAI toolingUS
Supabase, Railway, Cloudflare, Resend, Browserless, Bright Data, GeonodeInfrastructure supporting the products and integrations we build and operateUS and other regions

Our engineering infrastructure. We do not use personal data when developing software. Development and testing are carried out without live personal data. Where a product or integration we have built is in production use, personal data may be processed by the infrastructure providers in the final row above.

Where these providers process personal data on our behalf they act as processors under a written contract meeting the requirements of Article 28 of the UK GDPR.

12. International transfers

Some of our processing takes place outside the United Kingdom.

Where personal data goes. Our colleagues in the Philippines and North Macedonia access our systems in the course of their work, which is itself a transfer even though the data remains stored in the United Kingdom or the European Economic Area. A number of our service providers are established in the United States or process data there. Some providers operate global infrastructure and may process data in other territories.

How we protect it. Where a transfer is not covered by UK adequacy regulations, we rely on appropriate safeguards:

  • the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses
  • the European Commission’s Standard Contractual Clauses, where we act as a processor for a client established in the European Economic Area
  • UK adequacy regulations where they apply, including the UK Extension to the EU-US Data Privacy Framework for certified recipients in the United States

Where we rely on the International Data Transfer Agreement or the UK Addendum, we carry out a transfer risk assessment before doing so, applying the data protection test in UK law, which asks whether the standard of protection for the data subject in the destination country is materially lower than under UK law. We apply supplementary technical and organisational measures where the assessment indicates they are needed, and we keep our assessments under review.

You may request a copy of the safeguards we rely on by emailing privacy@thedpg.com.

13. How long we keep personal data

CategoryRetention period
Client contract and engagement records6 years from the end of the contract
Enquiries that do not lead to a contract12 months from last contact
Enquiries that lead to a contract6 years from the end of the contract
Marketing contacts and preferencesUntil you opt out, with a review of continued relevance every 2 years
Supplier records6 years from the end of the relationship
Financial and accounting records6 years from the end of the relevant financial year
Website analytics and cookie dataAs set out in our Cookie Notice
Meeting recordings90 days
Privacy rights requests and complaints records12 months from closure. Extended to 6 years where the matter leads to a regulatory investigation or a legal claim, or where one is reasonably anticipated
Documents you attach to a rights request or a complaintDeleted once the request or complaint is closed
Client personal data held temporarily on a DPG device under section 3Deleted on completion of the task, and in any event within 30 days of receipt
Records held under legal holdUntil the hold is lifted

Where we are required to keep records for longer by law, or need them to establish, exercise or defend legal claims, we retain them for that period.

14. Your rights

Under the UK GDPR and the Data Protection Act 2018 you have the right to:

  • Be informed about how we use your personal data, which is the purpose of this notice
  • Access the personal data we hold about you
  • Rectification of inaccurate or incomplete data
  • Erasure of your data in certain circumstances
  • Restriction of our processing in certain circumstances
  • Data portability, where processing is based on consent or contract and is carried out by automated means
  • Object to processing based on legitimate interests, and to object at any time to direct marketing
  • Withdraw consent at any time where we rely on it, without affecting processing carried out before withdrawal
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects

Exercise your rights

Please use our privacy centre. Tell us which country you are in, choose the right you want to use, and we will take it from there. Requests made through the privacy centre are logged, tracked and answered under our data subject request procedure, which is why we ask you to use it rather than any other route.

You can also open the privacy centre on its own page. You do not need to use any particular form of words, and if you need a different way to make a request, for example because of a disability, tell us and we will make a reasonable adjustment.

How we handle your request

We may need to confirm your identity before we act, and we may ask you to clarify your request where we process a large amount of information about you. Where we reasonably require that identity confirmation or clarification, the time limit for our response pauses until you provide it.

We will respond within one month of receiving your request, or of receiving the information we have asked you for. Where a request is complex or you have made a number of requests, we may extend this by up to two further months, and we will tell you within the first month if we do and explain why.

When responding to an access request we carry out a reasonable and proportionate search for your personal data.

There is no charge for exercising your rights, though we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, and we will explain our reasons if we do.

15. Automated decision-making and artificial intelligence

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

We use AI-assisted tools in the course of our work, including for drafting and research. These tools support our people; they do not make decisions about individuals.

We do not use client personal data to train artificial intelligence models, and we do not permit our providers to do so.

16. Children

Our services are directed at organisations, not individuals, and we do not knowingly collect personal data from children. If you believe we hold data about a child, please contact us. We will look into it and delete the data where we have no lawful reason to keep it.

17. Security

We operate an information security management system certified to ISO/IEC 27001, certificate number 24/2042.

We maintain technical and organisational measures appropriate to the risk, including access controls, encryption in transit and at rest, multi-factor authentication, security awareness training, supplier due diligence, and incident response procedures.

18. Complaints

If you are unhappy with how we have handled your personal data, please tell us so we can put it right.

How to complain to us

Please use our complaint form, below. It records your complaint directly into our complaints log, which is how we make sure it is acknowledged, tracked and answered under our complaints procedure. You do not need to use any particular form of words.

We will acknowledge your complaint within 5 working days of receiving it. The acknowledgement will confirm what we understand your complaint to be, tell you what happens next and by when, and give you a named contact. We will then make appropriate enquiries, keep you informed of progress, and give you an outcome in plain language, normally within 30 days of receiving your complaint. Where a complaint is complex we may need up to three months. If we are not going to meet the 30 days we will tell you before they expire, explain why, and give you a revised date.

Complaining costs you nothing, and it will never count against you.

Complaining to the regulator

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office. We will not discourage you from doing so, and we do not make complaining to us a condition of anything.

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone 0303 123 1113. ico.org.uk

We would ask you to raise your concern with us first, so that we have the chance to look into it and put it right. It is usually quicker, and in most cases we can resolve the matter ourselves.

You can also open the complaint form on its own page. If you need a different way to complain, for example because of a disability, tell us and we will make a reasonable adjustment. Our full complaints procedure is available on request.

19. Changes to this notice

We review this notice at least annually and whenever our processing changes materially. We will publish any updated version on our websites and, where the change is significant, tell you directly.

VersionDateSummary of changes
4.04 September 2026Removed the references to a Data Protection Officer, recording that we are not required to appoint one and have not appointed one, and named the Chief Trust Officer as the person responsible for data protection. Made our privacy centre the route for a rights request and our complaint form the route for a complaint, so that both are logged and answered under the right procedure. Brought the complaint handling timescales into line with our complaints procedure. Updated the service provider list, including the removal of our meeting transcription provider, whose service was discontinued and whose data was deleted in August 2026, and updated what we say about meeting recording to reflect our use of Microsoft Teams. Clarified when a transfer risk assessment is carried out
3.018 August 2026Full revision. Updated the international transfers position and safeguards, named our service providers, set out when we act as controller and as processor and how we work with client data, added automated decision-making and artificial intelligence, added a complaints procedure, and updated the notice for the Data (Use and Access) Act 2025
2.012 February 2025Previous version

The Data Privacy Group Ltd. Version 4.0, 4 September 2026.