Data Protection Policy

Purpose

This Data Protection Policy ensures that Online Account Entry (OAE) complies with all applicable data protection legislation, including the UK GDPR and the Data Protection Act 2018, and upholds the privacy rights of individuals whose data we process.

Policy Statement

OAE recognises the importance of safeguarding all personal and business data entrusted to us. We commit to processing data lawfully, fairly, and transparently while maintaining its security and accuracy.

Key Principles

We adhere to the following principles:

  1. Lawfulness, fairness, and transparency – Data is processed openly and fairly.

  2. Purpose limitation – Data is collected for specific, legitimate purposes.

  3. Data minimisation – Only data necessary for service delivery is collected.

  4. Accuracy – Data is maintained accurately and updated when necessary.

  5. Storage limitation – Data is retained only for as long as necessary.

  6. Integrity and confidentiality – Data is protected by appropriate technical and organisational measures.

Roles and Responsibilities

  • The Data Protection Officer (DPO) oversees compliance with data protection laws.

  • All employees and contractors are responsible for safeguarding data within their control.

  • Clients are expected to ensure the data provided is accurate and complete.

Data Subject Rights

OAE ensures that individuals can exercise their rights, including:

  • Access, rectification, and erasure of data.

  • Restriction and objection to processing.

  • Portability of their personal data.

Requests are processed within one month unless legally exempted.

Data Breach Management

  • Any suspected data breach must be reported immediately to the DPO.

  • All incidents are logged, assessed, and, where applicable, reported to the ICO within 72 hours.

  • Affected clients are notified promptly.

Third-Party Processing

OAE only works with third-party processors that comply with data protection standards and enter into written data processing agreements.

Data Security

  • Encryption, secure servers, and controlled access are applied to all stored data.

  • Regular audits and penetration testing are conducted.

  • Portable devices and removable media are encrypted and monitored.

International Transfers

Personal data transferred outside the UK follows the UK GDPR requirements for lawful cross-border transfers, including adequacy decisions and binding safeguards.

Training and Awareness

All employees receive training on data protection principles, security awareness, and reporting procedures.

Compliance and Monitoring

OAE regularly reviews and updates its data protection measures to ensure ongoing compliance and continual improvement.