Chapter 12

Data Protection

(Non-contractual policy. Statutory obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply regardless.)

Overview

ACT Acoustics processes personal data in the course of its business — about employees, clients, contacts, and members of the public affected by our projects. We are committed to complying with the UK GDPR and the Data Protection Act 2018.

The company’s Data Protection Officer is Mike Wood (m.wood@actacoustics.co.uk).

Data Protection Principles

We will ensure that personal data is:

  1. Processed lawfully, fairly, and transparently.
  2. Collected for specified, explicit, and legitimate purposes.
  3. Adequate, relevant, and limited to what is necessary.
  4. Accurate and kept up to date.
  5. Not kept longer than necessary.
  6. Processed securely.

Your Responsibilities

As an employee, you handle personal data in the course of your work (for example, client contact details, noise complaint records, employee information). You must:

  • Only access personal data that you need for your work.
  • Not share personal data with anyone who does not need it.
  • Store personal data securely (see Equipment & IT on data security).
  • Not transfer personal data outside the UK without prior approval.
  • Report any data breach or suspected breach to the Data Protection Officer immediately.

A data breach includes any accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. This could be as simple as sending an email to the wrong person or losing an unencrypted USB drive.

Your Rights as an Employee

Under the UK GDPR, you have rights regarding the personal data we hold about you, including the right to access your data, to have inaccuracies corrected, and in some cases to have data erased. The company’s privacy notice (provided separately) explains these rights in full.

Subject Access Requests

If the company receives a request from an individual to see the personal data we hold about them, refer it immediately to the Data Protection Officer. We must respond within one calendar month.

← Back to contents