Opsel Compliance Consultancy Services Ltd

Version 2.0

Effective date: 23rd July 2026     Next review: 22nd July 2027]

Applies to website, staff, consultants and third parties processing personal data on our behalf

1. Introduction

Opsel Compliance Consultancy Services Ltd (“Opsel”, “we”, “us”) needs to collect and use certain information about individuals, including visitors to our website, clients, staff, consultants and suppliers.

We collect and process personal data through your dealings with us, including your use of our website, our marketing communications, and any service we provide.

This policy explains how that personal data is collected, used, stored and protected, in order to meet Opsel’s data protection standards and to comply with UK data protection law.

2. Why This Policy Exists

  • Complies with data protection law and follows good practice.
  • Protects the rights of staff, clients, website visitors, partners and other individuals whose data we process.
  • Is transparent about how Opsel collects, uses and stores personal data.
  • Protects Opsel from the risks of a data breach and associated regulatory, financial and reputational harm.

3. Legal Framework

This policy is based on the following UK legislation, which governs how organisations must collect, handle and store personal data, regardless of whether it is held electronically, on paper, or in any other format:

  • The UK General Data Protection Regulation (UK GDPR), as it forms part of UK law under the European Union (Withdrawal) Act 2018.
  • The Data Protection Act 2018 (DPA 2018), which supplements the UK GDPR and sets out additional UK-specific provisions.
  • The Data (Use and Access) Act 2025 (DUAA), which amends the UK GDPR and DPA 2018 (most relevant provisions in force from 5 February 2026), including changes to subject access request handling and complaints procedures.
  • The Privacy and Electronic Communications Regulations (PECR), which govern cookies, similar tracking technologies and direct electronic marketing on our website.

To comply with the law, personal data must be collected and used fairly, stored securely, and not disclosed unlawfully.

4. Scope

This policy applies to all staff, consultants, facilitators, delegates, partners, volunteers, website users and other individuals or organisations working on Opsel’s behalf, and to all personal data Opsel holds or processes relating to identifiable living individuals, including but not limited to:

  • Identity data: name, title, date of birth, gender.
  • Contact data: postal address, billing address, email address, telephone number.
  • Financial data: bank account and payment details.
  • Technical data: IP address, browser type, device identifiers, cookie identifiers, and other online identifiers collected via the website.
  • Usage data: information about how individuals use our website and services.

Special category data (e.g. data concerning health, racial or ethnic origin, religious beliefs, or trade union membership) and criminal offence data are subject to additional legal conditions under Article 9 and Article 10 UK GDPR, and will only be processed where a specific condition for processing is met and additional safeguards are in place.

5. Data Protection Principles

Article 5 of the UK GDPR sets out the principles that Opsel must follow whenever personal data is processed. Personal data must be:

  • Processed lawfully, fairly and in a transparent manner (“lawfulness, fairness and transparency”).
  • Collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes (“purpose limitation”).
  • Adequate, relevant and limited to what is necessary (“data minimisation”).
  • Accurate and kept up to date, with inaccurate data corrected or erased without delay (“accuracy”).
  • Kept in a form that permits identification for no longer than necessary (“storage limitation”).
  • Processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage (“integrity and confidentiality”).

Opsel is also responsible for, and must be able to demonstrate compliance with, these principles (the “accountability” principle), including through this policy, our records of processing activity, and staff training.

6. Lawful Basis for Processing

Opsel will only process personal data where at least one lawful basis under Article 6 UK GDPR applies. Depending on the activity, this may be:

  • Consent – the individual has given clear consent (e.g. opting in to marketing emails or non-essential cookies).
  • Contract – processing is necessary to perform a contract with the individual, or to take steps before entering one.
  • Legal obligation – processing is necessary to comply with the law.
  • Legitimate interests – processing is necessary for Opsel’s legitimate business interests, provided these are not outweighed by the individual’s rights and freedoms.

Where special category data is processed, an additional condition under Article 9 UK GDPR (such as explicit consent) will also be identified and documented.

7. Roles and Responsibilities

Everyone who works for or with Opsel has some responsibility for ensuring data is collected, stored and handled appropriately. Key roles are:

Role

Responsibilities

Director

Ultimately accountable for ensuring Opsel meets its legal data protection obligations.

Data Protection Officer (DPO) Nana Mantey

Advises the board on data protection risks and obligations; reviews data protection procedures and policies on a scheduled basis; arranges staff training; handles data protection queries; manages subject access and other individual rights requests; approves contracts with third parties who process personal data on Opsel’s behalf; acts as the point of contact for the ICO.

Marketing / Communications Lead Nana Mantey

Approves data protection statements in communications and on the website; ensures marketing activity (including cookies and email marketing) complies with PECR and UK GDPR; liaises with media enquiries on data protection matters.

 

8. Rights of Individuals

Individuals whose personal data Opsel holds have the following rights under the UK GDPR:

  • The right to be informed about how their data is used.
  • The right of access to their personal data (see Section 9, Subject Access Requests).
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure (“right to be forgotten”) in certain circumstances.
  • The right to restrict processing in certain circumstances.
  • The right to data portability, allowing data to be moved, copied or transferred to another provider.
  • The right to object to processing based on legitimate interests or for direct marketing.
  • Rights related to automated decision-making and profiling, where applicable.

Requests to exercise any of these rights should be sent to the Data Protection Officer at info@opselcompliance.com or via the contact page on the Opsel website.

9. Subject Access Requests

An individual may ask Opsel what personal data it holds about them and why, how to access it, how to keep it up to date, and how Opsel is meeting its data protection obligations. This is a Subject Access Request (SAR).

  • Requests may be made by email to info@opselcompliance.com or via the website contact page. Opsel does not require requests to use a specific form.
  • Subject access requests are free of charge. A reasonable fee may only be charged where a request is manifestly unfounded, excessive, or for additional copies of data already provided, in line with Article 12(5) UK GDPR.
  • Opsel will respond without undue delay and within one calendar month of receipt of a valid request, extendable by up to a further two months for complex or numerous requests (the requester will be told within the first month if an extension applies).
  • Where identity verification or clarification of the request is genuinely required, the one-month clock may be paused while Opsel waits for a response, in line with the Data (Use and Access) Act 2025.
  • Opsel will always verify the identity of the requester before releasing any information.
  • Certain information may be withheld under statutory exemptions (for example, data about other individuals, legally privileged material, or information that would prejudice the prevention or detection of crime).

Individuals who are unhappy with how a request has been handled may use Opsel’s complaints procedure (Section 16) or contact the Information Commissioner’s Office.

10. Website Users, Cookies and Online Tracking

This section applies specifically to visitors to the Opsel website.

  • Our website will display a cookie/consent notice before setting any non-essential cookies or similar tracking technologies, in line with PECR and the UK GDPR. Strictly necessary cookies required for the website to function do not require consent, but must still be disclosed.
  • Where analytics, advertising or third-party embedded content (e.g. social media widgets) set cookies, individuals will be able to accept or reject these categories separately, and to change their preferences at any time.
  • The website’s privacy notice will explain what personal data is collected through the site (including IP addresses and device data), the purposes of collection, retention periods, and any third parties or processors the data is shared with.
  • Opsel will not use website data for automated decision-making that produces legal or similarly significant effects on individuals without appropriate safeguards.

11. Data Storage and Security

11.1 Paper records

  • Paper records, and any printouts of electronic data, must be kept in a locked drawer or cabinet when not in use.
  • Printouts must not be left unattended where unauthorised people could see them (e.g. on a printer).
  • Paper records must be securely shredded when no longer required.

11.2 Electronic records

  • Personal data must be protected by strong, unique passwords (and multi-factor authentication where available), never shared between staff.
  • Data should only be stored on designated systems and approved cloud services, not on personal devices or unapproved apps.
  • Servers and systems holding personal data must be protected by up-to-date security software, firewalls and access controls.
  • Data must be backed up regularly, with backups tested in line with Opsel’s backup procedures.
  • Where personal data is genuinely needed on a laptop, tablet or phone for business purposes, the device must be encrypted, password/PIN or biometric protected, and configured so data can be remotely wiped if lost or stolen.
  • Screens must be locked whenever left unattended.

Personal data should not be sent by ordinary, unencrypted email or shared informally. Where personal data must be shared electronically with an authorised third party, it should be sent using an approved secure method (e.g. encrypted email, a secure file-transfer or client portal) – the DPO can advise on the appropriate method for a given transfer.

12. Data Accuracy and Retention

Opsel must take reasonable steps to keep personal data accurate and up to date, and must not keep it for longer than necessary. Staff should:

  • Hold data in as few places as necessary and avoid creating unnecessary additional data sets.
  • Take opportunities to update records, for example when confirming a client’s details.
  • Correct or remove inaccurate data as soon as inaccuracies are identified.
  • Check marketing databases against relevant suppression files at least every six months.

Indicative retention periods (to be confirmed and completed by the DPO):

Data category

Retention period

Client contract and billing records

 6 years after the relationship ends, to align with limitation periods

Website enquiry / contact form submissions

12 months if no relationship results

Marketing consents and preferences

Until consent is withdrawn, plus a record of withdrawal

Staff and HR records

Per Opsel’s HR retention schedule

 

13. International Data Transfers

Personal data protected under UK data protection law may lose that protection if transferred to a country without equivalent safeguards. Opsel may use service providers based outside the UK (for example, cloud hosting, payment processors or training partners) to help deliver our website and services.

  • Where data is transferred outside the UK, Opsel will only do so where the destination is covered by UK adequacy regulations, or where appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised under Article 46 UK GDPR.
  • Where Opsel also processes personal data of individuals in the EU, transfers out of the EU are separately subject to EU GDPR transfer rules, and Opsel will consider whether an EU representative is required under Article 27 EU GDPR.

This replaces the previous, outdated wording which referred only to transfers “outside the EEA” under the 1998 Act framework.

14. Personal Data Breaches

A personal data breach is any incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

  • Any suspected or actual data breach must be reported immediately to the DPO.
  • Where a breach is likely to result in a risk to individuals’ rights and freedoms, Opsel must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.
  • Where a breach is likely to result in a high risk to individuals, those individuals must also be informed without undue delay.
  • Opsel will keep an internal record of all personal data breaches, regardless of whether they were notifiable, including their effects and the remedial action taken.

15. Disclosing Data for Other Reasons

In certain circumstances, the UK GDPR permits personal data to be disclosed to law enforcement agencies without the consent of the data subject. Opsel will only disclose data in these circumstances where the DPO is satisfied the request is legitimate, seeking legal advice where necessary.

16. Complaints and the Information Commissioner’s Office

Individuals who have concerns about how Opsel handles their personal data may raise these with the Data Protection Officer at info@opselcompliance.com in the first instance.

If an individual remains dissatisfied, they have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection, at ico.org.uk or on 0303 123 1113.

17. Children’s Data

Opsel’s website and services are not directed at children. Where Opsel becomes aware that it holds personal data relating to a child without appropriate parental consent or other lawful basis, it will take steps to delete that data, unless retention is otherwise required by law.

18. Training and Awareness

Opsel will provide data protection training to all employees and relevant consultants to ensure they understand their responsibilities. Staff who are unsure about any aspect of data protection should contact the DPO.

19. Providing Information to Individuals

Opsel aims to ensure individuals understand how their data is used and how to exercise their rights. This is set out in Opsel’s separate website privacy notice, which should be read alongside this policy and kept consistent with it.

20. Policy Review

This policy will be reviewed by the DPO at least annually, and sooner if there is a material change in the law, Opsel’s processing activities, or ICO guidance. Next scheduled review: 22nd July 2027.