Data Protection Policy
Definitions
This Data Protection Policy sets out the principles, responsibilities and procedures adopted by the Company to ensure that personal data is handled securely, lawfully and in accordance with applicable UK data protection legislation.
Company: Kateryna Shamshuryna-Acland, trading as Keko Club Art Studio. Where required by law, the Company is registered with the Information Commissioner's Office (ICO) and pays the applicable data protection fee.
Data Protection Law: The UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018"), the Data (Use and Access) Act 2025 ("DUAA"), the Privacy and Electronic Communications Regulations 2003 ("PECR") where applicable, and any other applicable UK data protection or privacy legislation as amended or replaced from time to time.
Personal Data: Any information relating to an identified or identifiable living individual.
Special Category Data: Personal data requiring additional protection under UK data protection law, including information concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, or data concerning a person's sex life or sexual orientation.
Controller: An organisation which determines the purposes and means of processing personal data.
Processor: An organisation which processes personal data on behalf of a Controller.
The Company may act as either a Controller or Processor depending on the nature of the processing being undertaken.
Responsible Person: The person appointed by the Company to oversee data protection compliance. This person may be referred to as the Data Protection Lead. Where the Company is legally required to appoint a Data Protection Officer ("DPO"), the Responsible Person shall include or work with the appointed DPO.
Data Processing Register: The Company's internal record of systems, services, business processes and other contexts in which personal data is processed, including any Record of Processing Activities ("ROPA") required under Data Protection Law.
1. Data Protection Principles
The Company is committed to processing personal data in accordance with Data Protection Law.
Personal data shall be:
- Processed lawfully, fairly and transparently in relation to individuals.
- Collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes, except where further processing is permitted by law.
- Adequate, relevant and limited to what is necessary for the purposes for which it is processed.
- Accurate and, where necessary, kept up to date. Reasonable steps shall be taken to rectify or erase inaccurate personal data without undue delay.
- Kept for no longer than is necessary for the purposes for which it is processed, except where longer retention is permitted or required by law and appropriate safeguards are in place.
- Processed securely, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.
The Company shall also comply with the accountability principle and must be able to demonstrate its compliance with these requirements.
2. General Provisions
This policy applies to all personal data processed by the Company.
The Company shall comply with its obligations under Data Protection Law whether it is acting as a Controller or Processor.
The Responsible Person shall oversee the Company's ongoing compliance with this policy.
All employees, contractors and other personnel who process personal data on behalf of the Company shall comply with this policy and any supporting data protection and information security procedures.
Appropriate data protection awareness and training shall be provided to personnel where relevant to their role.
This policy shall be reviewed at least annually and additionally following any significant change to applicable law, the Company's processing activities or the systems used to process personal data.
The Company shall pay the ICO data protection fee and maintain its entry on the ICO register where required by law. Where an exemption applies, the Company shall periodically review whether that exemption remains applicable.
3. Accountability and Records of Processing
The Company shall maintain an appropriate Data Processing Register documenting its processing of personal data.
The register shall, where applicable, identify:
- the purpose of the processing;
- the categories of individuals and personal data involved;
- the Company's role as Controller or Processor;
- the lawful basis relied upon where the Company is acting as Controller;
- any additional condition relied upon for Special Category Data;
- recipients or categories of recipients of the data;
- third-party processors and service providers;
- relevant systems and storage locations;
- applicable retention periods;
- international transfers of personal data; and
- appropriate security measures where relevant.
The Data Processing Register shall be kept sufficiently current to accurately reflect the Company's material processing activities and shall be formally reviewed at least annually.
4. Lawful, Fair and Transparent Processing
The Company shall only process personal data where there is a valid lawful basis under Data Protection Law.
Where the Company acts as Controller, the appropriate lawful basis shall be identified before processing begins and documented where required.
The lawful bases available under the UK GDPR are:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a public task;
- legitimate interests; and
- recognised legitimate interests, where the statutory conditions for that basis are satisfied.
Where the Company relies on legitimate interests, it shall consider whether the processing is necessary and whether the Company's interests are overridden by the rights and freedoms of the individuals concerned, unless Data Protection Law provides otherwise.
Where the Company processes Special Category Data, it shall identify both an appropriate lawful basis and an applicable condition for processing Special Category Data under the UK GDPR and DPA 2018.
Where required, individuals shall be provided with clear and accessible privacy information explaining how their personal data is collected, used, stored and shared.
5. Consent and Marketing Communications
Where consent is relied upon as the lawful basis for processing personal data, the Company shall ensure that consent is freely given, specific, informed and capable of being demonstrated.
Individuals shall be able to withdraw consent as easily as it was given, and the Company's systems shall be updated appropriately following withdrawal.
The Company shall not treat consent as the default lawful basis where another lawful basis is more appropriate.
Where the Company conducts direct marketing by electronic communication, it shall comply with PECR and other applicable direct marketing requirements in addition to its obligations under the UK GDPR.
Recipients shall be provided with an appropriate means of opting out of direct marketing communications where required.
6. Individual Rights
The Company shall respect and facilitate the rights available to individuals under Data Protection Law, including, where applicable, the rights to:
- be informed about the processing of their personal data;
- access their personal data;
- have inaccurate personal data rectified;
- have personal data erased;
- restrict processing;
- data portability;
- object to processing; and
- safeguards in relation to certain automated decision-making.
Requests relating to these rights shall be handled without undue delay and within the statutory time limits.
Subject Access Requests shall normally be responded to within one month of receipt, subject to any lawful extension or permitted pause to the applicable time period.
When responding to a Subject Access Request, the Company shall carry out a reasonable and proportionate search for the personal data covered by the request.
The Company shall take reasonable steps to verify the identity of an individual making a request where necessary and proportionate.
7. Data Protection Complaints
The Company shall provide individuals with an accessible means of making complaints concerning the Company's handling of their personal data.
Data protection complaints shall be acknowledged within 30 days of receipt.
The Company shall, without undue delay:
- take appropriate steps to investigate the complaint;
- make any enquiries reasonably necessary to determine the circumstances;
- keep the complainant appropriately informed; and
- inform the complainant of the outcome.
Individuals shall also be informed, where appropriate, of their right to raise a complaint with the Information Commissioner's Office.
Records of material data protection complaints and their outcomes shall be retained as appropriate.
8. Data Minimisation
The Company shall ensure that personal data collected and processed is adequate, relevant and limited to what is reasonably necessary for the identified purpose.
Personal data shall not be collected on a speculative basis or retained solely because it may be useful at some unspecified point in the future.
Where practical, systems and processes shall be configured to minimise the amount of personal data collected, accessed or retained.
9. Accuracy
The Company shall take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date.
The degree of verification and updating required shall take account of the purpose for which the information is processed and the potential consequences of inaccurate data.
Where the Company becomes aware that personal data is materially inaccurate, reasonable steps shall be taken to rectify or erase it without undue delay.
10. Retention, Archiving and Deletion
The Company shall retain personal data only for as long as necessary for the purposes for which it is processed or for as long as required by applicable law, contractual obligations or legitimate business requirements.
Appropriate retention periods shall be established for relevant categories of personal data.
Retention requirements shall consider:
- the purpose for which the data is held;
- statutory or regulatory retention requirements;
- contractual requirements;
- the establishment, exercise or defence of legal claims;
- whether the data continues to be required for legitimate business purposes; and
- the risks associated with continued retention.
Retention periods and practices shall be reviewed periodically and at least annually as part of the Company's data protection review.
When personal data is no longer required, it shall be securely deleted, anonymised or otherwise disposed of as appropriate.
11. Security
The Company shall implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access.
Security measures shall be proportionate to the nature of the information processed and the risks associated with the processing and may include, where appropriate:
- access controls and least-privilege access;
- appropriate authentication controls;
- encryption of data in transit and at rest where appropriate;
- secure configuration and maintenance of systems;
- timely application of relevant security updates;
- logging and monitoring;
- appropriate backup arrangements;
- disaster recovery and business continuity arrangements;
- secure disposal of data and equipment; and
- controls designed to prevent unauthorised disclosure or sharing.
Access to personal data shall be limited to personnel and third parties who require access for an authorised purpose.
Security arrangements shall be reviewed periodically and following any material change to systems, processing activities or identified risks.
12. Data Protection by Design and Default
The Company shall consider data protection requirements when designing or materially changing systems, services and business processes involving personal data.
Where reasonably practicable, systems shall be designed so that only the personal data necessary for the relevant purpose is collected, used and made accessible by default.
Where processing is likely to result in a high risk to the rights and freedoms of individuals, the Company shall carry out a Data Protection Impact Assessment ("DPIA") before commencing the processing.
Identified risks shall be addressed through appropriate technical and organisational measures before processing begins wherever reasonably practicable.
13. Third Parties and Data Processors
The Company shall take reasonable steps to ensure that third parties processing personal data on its behalf provide sufficient guarantees regarding data protection and information security.
Where required by Data Protection Law, processing by a third-party Processor shall be governed by a written agreement containing the appropriate data protection provisions.
Where the Company acts as Processor on behalf of a customer or other Controller, it shall process personal data only in accordance with the Controller's documented instructions, except where otherwise required by law.
The Company shall maintain appropriate oversight of material sub-processors and service providers.
14. International Transfers
The Company shall not make a restricted transfer of personal data outside the United Kingdom unless the transfer complies with Data Protection Law.
Where applicable, the Company shall ensure that an appropriate transfer mechanism is in place, which may include:
- UK adequacy regulations;
- an appropriate safeguard recognised under the UK GDPR, including an International Data Transfer Agreement or approved UK Addendum;
- another legally recognised safeguard; or
- an applicable statutory exception.
Where required when relying on appropriate safeguards, the Company shall undertake an appropriate transfer risk assessment.
International transfers shall be recorded in the Company's Data Processing Register where appropriate.
15. Personal Data Breaches
Any employee, contractor or other person acting on behalf of the Company who becomes aware of an actual or suspected personal data breach shall report it to the Responsible Person without undue delay.
The Company shall promptly:
- take reasonable steps to contain and mitigate the breach;
- establish the nature and extent of the breach;
- assess the likely consequences for affected individuals;
- determine whether notification to the ICO is required; and
- determine whether affected individuals must be notified.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the Company shall notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where the breach is likely to result in a high risk to affected individuals, the Company shall also notify those individuals without undue delay unless an applicable legal exception applies.
The Company shall maintain appropriate records of personal data breaches, including breaches which do not require notification to the ICO.
16. Policy Review and Responsibility
Responsibility for oversight of this policy rests with the Responsible Person.
The Responsible Person shall periodically assess the Company's compliance with this policy and identify any corrective actions required.
This policy shall be reviewed:
- at least annually;
- following any material personal data breach;
- following a significant change to the Company's processing activities;
- following a material change to the Company's systems or services; or
- following a significant change in applicable Data Protection Law.