Best Supplier Prices
Legal & Compliance

GDPR & Your Data Rights

Under the GDPR, you hold specific rights regarding your personal data. At business-utility.com, we fully support and facilitate your ability to exercise the following rights:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate or incomplete information.

Right to Erasure ("Right to be Forgotten")

Request that we permanently delete your data when it is no longer required.

Right to Restrict or Object

Object to or limit how we process your personal data under certain conditions.

Right to Data Portability

Request the transfer of your data to another organization in a structured format.

Right to Withdraw Consent

Easily withdraw your consent at any time if we rely on it to process your data.

Documented Policy Mapping & Summaries

The policies and procedures below govern how we protect personal data across every part of our organisation — from how information is classified and accessed, to how incidents are handled and vendors are assessed.

1. Data Classification and Handling

Data Classification and Handling Policy

Defines how data is categorised within our organisation based on sensitivity (e.g., Public, Internal, Confidential, Restricted/PII). It outlines specific technical controls and handling requirements for each tier, including mandatory encryption protocols for data at rest and in transit.

2. Physical Security

Physical and Environmental Security Policy

Outlines the physical safeguards established to protect our facilities, data centres, and corporate offices. It regulates visitor access management, clean-desk standards, security camera surveillance, and the physical locking of server rooms or cabinets containing hardware that processes personal data.

3. Acceptable Use

Acceptable Use Policy (AUP)

Establishes the rules governing the acceptable use of all company assets, networks, systems, and devices. It explicitly details employee obligations regarding the prevention of unauthorised data sharing, password hygiene, and prohibitions against using unapproved third-party software for corporate work.

4. Access Control

Access Control Policy

Grounded in the principles of "least privilege" and "need-to-know", this framework dictates how user access is provisioned, modified, and revoked. It enforces the use of Multi-Factor Authentication (MFA), role-based access controls (RBAC), and mandates quarterly access reviews for critical environments housing personal data.

5. Incident Management and Response Procedures

Incident Response Plan (IRP)

Provides a structured operational framework for detecting, containing, investigating, and recovering from security incidents. It outlines the specific roles of our Incident Response Team (IRT) and includes dedicated procedures for evaluating and executing regulatory and consumer notification obligations in the event of a personal data breach.

6. Retention and Destruction of Data

Data Retention and Disposal Policy

Defines the maximum and minimum retention periods for various categories of personal data based on legal, regulatory, and business requirements. It mandates secure destruction methods, such as certified cryptographic erasure for digital assets and cross-cut shredding for physical documentation.

7. Individual Rights Fulfilment

Data Subject Rights (DSR) Procedure

Provides step-by-step instructions for internal teams to verify, process, and respond to data subject requests (such as access, deletion, correction, and portability requests) within legally mandated timeframes.

8. Respecting and Protecting Personal Data by Employees

Employee Privacy and Security Awareness Code

Embedded within our employee handbook and mandatory annual training, this document outlines the ethical and contractual duties of staff. It covers confidentiality obligations, social engineering awareness, and the direct disciplinary actions associated with policy non-compliance or negligent data handling.

9. Third-Party Onboarding

Vendor Risk Management Policy

Governs our procurement and vendor management lifecycle. It requires all third-party vendors and processors handling personal data to undergo rigorous security assessments, sign Data Processing Agreements (DPAs) containing standard contractual clauses, and submit to periodic security audits.

Third-Party Data Disclosures

We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers (such as hosting partners or analytics platforms) who are contractually bound by rigorous Data Processing Agreements (DPAs) to ensure your data stays safe and compliant.

Contact Our Privacy Team

If you have any questions about this statement, want to exercise your data rights, or need to contact our Data Protection Officer (DPO), please reach out to us directly:

Website

business-utility.com

Registered

England & Wales, UK

Submit a data request

Use this form to request access to your data, ask us to correct or delete it, restrict processing, export it, or withdraw your consent. You will receive a confirmation email with your reference number.

What would you like us to do? *
We respond within 30 days, as required by UK GDPR.

To exercise any of the rights listed above, submit a request through our data request form above or email us at privacy@business-utility.com and we will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters.

Last updated: 5 September 2026