Changing LanesLimited

Legal

Data protection policy (summary)

The internal rules our staff follow when handling personal data.

Draft for legal review

This document has been prepared from the platform as it is built today and must be reviewed by a UK solicitor before it is relied on. Details marked [to be confirmed: …] are company details we are still confirming (3 in this document).
Version
1.0 (draft)
Effective date
Applies to
Everyone
Owner and next review
Data Protection Lead · by
All legal documents

Purpose

This is a published summary of the internal policy every member of staff and contractor follows when handling personal data at Changing Lanes Limited. It supports our Privacy notice.

Responsibilities

  • The directors are accountable for data protection compliance.
  • Our Data Protection Lead ([to be confirmed: Data Protection Lead (name or role holder)]) advises, keeps the records of processing and the data protection impact assessments (DPIAs), handles rights requests and complaints, and reports breaches. We have assessed that we are not required to appoint a statutory Data Protection Officer; the Data Protection Lead performs the equivalent role — [to be confirmed by the Data Protection Lead].
  • Every member of staff completes data protection training at induction and every year, and follows this policy.
  • We pay the ICO data protection fee: [to be confirmed: ICO data protection fee registration number].

Principles we follow

Personal data is used lawfully, fairly and transparently; only for specified purposes; limited to what is needed; kept accurate; kept no longer than needed (Data retention schedule); kept secure; and we can show that we comply.

How the platform supports this

  • One record per thing. Each kind of information is held once and referenced elsewhere, so it can be corrected, exported or erased in one place.
  • Restricted data stays restricted. Health, benefit, safeguarding and staff identity details are held in separate tables with tighter access rules, never in lists, exports, logs or notification text.
  • Access by role. Row-level security in the database means each person sees only what their role allows; employers see only the consent-filtered candidate view.
  • No personal data in logs. Error reports and logs are scrubbed before leaving our systems.
  • Audit trail. Staff actions on records are recorded.
  • Human review. Automation prepares; people decide (Automated processing and AI notice).
  • Retention and erasure tooling with legal holds (Your data rights and how to use them).

Special category and criminal offence data

We process health, benefit-status and driving-offence information, and for staff in certain roles DBS results, only under the conditions in Schedule 1 to the Data Protection Act 2018. We keep an appropriate policy document describing the conditions we rely on and how we meet the principles for this data — [to be confirmed: appropriate policy document to be finalised by the Data Protection Lead].

New processing and DPIAs

Before we start any new processing that is likely to be high risk — for example new uses of health data, new data sharing with funders or employers, or new automated tools — we complete a DPIA and record the decision.

Data sharing

We share only what is necessary, with a lawful basis, recorded, and under a written agreement where appropriate (Employer data sharing agreement, Processors we use).

Breaches

Anyone who suspects a personal data breach reports it immediately to the Data Protection Lead. We contain it, assess the risk, record it even if we do not notify, notify the ICO within 72 hours of becoming aware where required, and tell affected people without undue delay if the risk to them is high.

Complaints about data protection

We have a complaints procedure for data protection complaints as required by section 164A of the Data Protection Act 2018 (from 19 June 2026): complaints can be made by any method including electronically, are acknowledged within 30 days, investigated without undue delay, and the complainant is kept informed of progress and the outcome (Complaints policy and procedure).

Review

This policy is reviewed every year and whenever the law or the platform changes.

Change history

Change history for Data protection policy (summary)
VersionDateChangeAcceptance needed again
1.0First draft for legal review, written from the platform as built.Yes — material change