Data Protection and UK GDPR Governance Policy
1. Purpose and Policy Status
This policy establishes the governance requirements that apply whenever The Mining Shop UK Limited collects, accesses, uses, shares, stores, transfers, archives or deletes personal data.
It is a public summary of our governance framework. Detailed inventories, risk assessments, contracts, incident records, security configurations and staff records are kept internally because publishing them could expose personal data, confidential information or security controls.
Publication of this policy does not state that the company is certified to ISO 27001, ISO 27701, SOC 2, Cyber Essentials or any other accreditation. It records the control framework against which implementation, evidence and future readiness are reviewed.
2. Scope and Legal Framework
The policy applies to directors, employees, temporary workers, contractors and service providers handling personal data for the company. It covers website visitors, customers, prospective customers, suppliers, repair and hosting contacts, workers and other identifiable individuals.
The framework is designed around the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and applicable amendments. Where overseas processing or customers create additional requirements, the company identifies the relevant role, law and transfer mechanism before processing proceeds.
The Privacy Policy explains what personal data we process, why we use it, our lawful bases, recipients, retention approach and individual rights. The Cookie Policy explains consent and tracking technologies.
3. Accountability and Governance
The director has overall accountability for data-protection governance, resourcing and material risk decisions. Day-to-day privacy enquiries and rights requests are coordinated through the administration team at [email protected].
The company has not appointed a statutory Data Protection Officer. This position is reviewed if the nature, scale or risk of processing changes. The decision and its rationale must be recorded internally, and sufficient responsible staff and external specialist advice must be available to meet legal obligations.
Material privacy risks, overdue corrective actions, significant incidents and high-risk processing proposals must be escalated to the director. Nobody may be penalised for raising a genuine data-protection or information-security concern in good faith.
4. Data Protection Principles
Personal data must be handled in accordance with the following principles:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
The company must be able to explain and evidence how these principles are applied in proportion to the processing and its risks.
5. Records, Lawful Bases and Transparency
The company maintains proportionate records of processing activities and data flows. Records should identify the purpose, data categories, individuals affected, lawful basis, recipients, international transfers, retention, security expectations and accountable business owner.
A valid lawful basis must be identified before processing begins. Special-category or criminal-offence information requires an additional legal condition and appropriate safeguards where applicable. Consent must be specific, informed, affirmative and capable of withdrawal when consent is the basis relied upon.
Privacy information must be concise, accessible and kept aligned with actual processing. New providers, purposes, analytics, advertising features, identity checks or material changes must be assessed before public notices are updated or processing begins.
6. Data Protection by Design and Default
Privacy must be considered when designing or changing websites, checkout flows, analytics, customer systems, hosting services, repair processes, marketing, automation and integrations.
Default settings must limit personal data to what is necessary for the stated purpose. Access, collection, sharing, retention and visibility must be proportionate to need and risk.
A Data Protection Impact Assessment must be completed before processing likely to create a high risk to individuals. Lower-risk projects should still record a proportionate privacy review. An unresolved high risk must be escalated and, where legally required, referred to the Information Commissioner's Office before processing proceeds.
7. Individual Rights and Requests
The company must provide workable routes for access, correction, erasure, restriction, portability and objection requests, and for concerns about automated decisions where the relevant right applies.
Requests must be logged, identity verified proportionately and answered within the applicable legal period. The company must not request more identity information than is reasonably needed. Any extension, refusal or lawful exemption must be documented and explained.
Operational teams and service providers must preserve relevant records and assist promptly when a rights request is received. Our public request and complaint routes are described in the Privacy Policy and Complaints Procedure.
8. Processors, Sharing and Contracts
Before appointing a processor, the company must conduct proportionate due diligence covering capability, security, confidentiality, resilience, location, subprocessors, deletion and assistance with rights and incidents.
Required controller-processor terms must be recorded in a written contract or other binding instrument. Material processors and data-sharing arrangements must be reviewed when services, risks or legal requirements change.
Personal data may be shared only for an identified purpose, on an appropriate lawful basis and with the minimum necessary recipient access. The company does not sell personal data. Provider purposes and principal categories of recipient are disclosed in the Privacy Policy.
9. International Transfers
The company must identify whether an arrangement creates a restricted transfer of personal data from the UK. Transfers may proceed only where an applicable UK adequacy regulation, appropriate safeguard or lawful exception is available.
Where required, the company must use an approved transfer mechanism, such as the UK International Data Transfer Agreement or UK Addendum, and complete the appropriate transfer risk or data-protection assessment. Transfer documentation and provider locations must be reviewed when the service or legal position changes.
10. Security and Access Control
Personal data must be protected by technical and organisational measures proportionate to its sensitivity, volume, context and risk. Controls may include role-based access, least privilege, strong authentication, encryption where appropriate, secure configuration, backups, logging, patching, supplier controls and tested recovery arrangements.
Access must be authorised, reviewed and removed promptly when no longer required. Personal data must not be placed in unapproved systems, sent to unintended recipients or exposed through public links.
Security weaknesses should be reported using our Security and Vulnerability Disclosure Policy. That policy does not authorise access to personal data or destructive testing.
11. Personal Data Breaches
Suspected loss, alteration, unauthorised disclosure, access or unavailability of personal data must be reported internally without delay. The company must contain and investigate the incident, assess risk to individuals, preserve evidence and record decisions and remedial actions.
All personal-data breaches must be recorded, including those not reported externally. Where a breach is likely to risk individuals' rights and freedoms, the company must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Individuals must be informed without undue delay where the applicable high-risk threshold is met.
Processors must notify the company promptly and provide the information and assistance required by the applicable contract and law.
12. Retention and Secure Disposal
Personal data must be retained only for as long as required for its purpose, legal obligations, dispute handling, fraud prevention or the establishment, exercise or defence of legal claims.
Retention rules must be documented by record category and reviewed periodically. When retention ends, information must be securely deleted, anonymised or destroyed, including copies held by processors where applicable. Legal holds and active disputes suspend ordinary deletion only for the records reasonably required.
13. Cookies, Analytics and Direct Marketing
Non-essential cookies, analytics and advertising technologies must be governed through the site's consent controls where required. A refusal must be as easy and prominent as acceptance, and withdrawal must remain available.
Marketing must comply with the UK GDPR and PECR. Consent, legitimate-interests assessments, suppression records and opt-outs must be handled according to the channel and relationship. Marketing objections and unsubscribe requests must be actioned promptly.
Current website technologies and their purposes are described in the Cookie Policy. The Privacy Policy explains analytics, advertising measurement and related data sharing.
14. Staff, Contractors and Awareness
People handling personal data must receive proportionate instructions and awareness training appropriate to their access and responsibilities. Confidentiality obligations continue after employment or engagement ends.
Staff and contractors must use approved systems, follow access and disposal requirements, recognise rights requests and report suspected incidents immediately. Deliberate or reckless misuse may result in access removal, disciplinary or contractual action and, where appropriate, referral to an authority.
15. Monitoring, Assurance and Improvement
The company shall periodically review processing records, privacy notices, consent controls, supplier arrangements, access, incidents, rights requests, retention and training evidence. Reviews must be proportionate to risk and triggered by material changes or recurring issues.
Findings must have an owner, priority and target date. Material actions and accepted risks must be visible to the director. Lessons from incidents, complaints, audits and system changes must inform improvements.
This policy supports future accreditation readiness but is not evidence that every certification control has been independently audited or certified.
16. Review, Contact and Complaints
This policy is owned by the director and reviewed at least annually and after a material legal, organisational, service or processing change. The public update date will be changed when a substantive revision is published.
For a privacy question or rights request, email [email protected], call 01429 408034, or use our Complaints Procedure. You may also complain to the Information Commissioner's Office.
The complete website policy set is available from our Legal, Policies and Terms index.
17. Common Questions
Does this replace the Privacy Policy? No. This policy explains governance and accountability. The Privacy Policy provides the detailed notice to individuals about the company's processing.
Have you appointed a statutory Data Protection Officer? No. The director retains overall accountability and the administration team coordinates privacy matters. The need for a DPO is reviewed if processing changes.
Does this policy mean the company is ISO or SOC certified? No. It supports structured improvement and future readiness but does not claim certification or independent assurance.
How do I exercise a data-protection right? Email [email protected] and state the right or concern involved. Identity will be checked proportionately before personal information is released or changed.
How do I report a suspected breach or security weakness? Email [email protected] for a suspected personal-data incident. Use the Security and Vulnerability Disclosure Policy for a technical vulnerability and do not access personal data to demonstrate a report.
Where are cookie and analytics choices managed? Use the cookie-preferences control and read the Cookie Policy.
Data Protection Questions And Requests
Email [email protected], call 01429 408034, or use our Complaints Procedure. Do not send passwords, seed phrases, private keys or complete payment-card details.