Legal
GDPR Compliance
How Procius Limited meets its obligations under the UK General Data Protection Regulation and the Data Protection Act 2018.
1. Our approach
DBS applications involve sensitive personal data, and we treat data protection as a core part of our service, not an afterthought. We apply the principles of data minimisation, purpose limitation and storage limitation to everything we build.
2. Security measures
- All data is transmitted over encrypted (TLS) connections.
- Personal data is stored encrypted at rest within the UK/EEA.
- Access to applicant data is restricted to trained staff on a need-to-know basis.
- We maintain audit logs of access to sensitive records.
3. Data processing agreements
Where we use third-party processors (such as hosting or payment providers), we have data processing agreements in place and only use providers with adequate safeguards.
4. International transfers
Applicant data is processed in the UK. If any transfer outside the UK is ever required, it will only take place under an adequacy decision or appropriate safeguards such as standard contractual clauses.
5. Data breach procedures
We maintain an incident response plan. Where a breach is likely to result in a risk to individuals, we will notify the ICO within 72 hours and inform affected individuals without undue delay.
6. Exercising your rights
To make a subject access request or exercise any other data protection right, email [email protected]. We respond to all requests within one calendar month.