Our Data Protection Policy is in accordance with the regulatory requirements of the Royal Institution of Chartered Surveyors (RICS).
Purpose and Scope
This policy sets out how the business protects personal data and maintains client confidentiality in accordance with UK GDPR, the Data Protection Act 2018, and professional obligations. It applies to all information handled by the business, whether in physical or digital form, and to any third parties engaged to support service delivery.
Commitment to Data Protection
The business is committed to processing personal data lawfully, fairly, and transparently. Personal data is collected only where necessary for legitimate business purposes and is handled in a manner that ensures appropriate security, confidentiality, and integrity. All responsibilities under this policy are fulfilled personally by the Principal, being the Director of the company at any given time.
Client Confidentiality
All client information, whether personal, commercial, or sensitive, is treated as confidential. Information is not disclosed to third parties unless: the client has provided explicit consent, disclosure is required by law or regulation, or it is necessary for the performance of contracted services and appropriate safeguards are in place. Confidential information is never used for personal advantage or shared inappropriately.
Lawful Basis for Processing
Personal data is processed only where a lawful basis exists, including: performance of a contract, compliance with legal obligations, legitimate business, interests, explicit client consent where required, special category data is processed only where legally permitted and strictly necessary.
Data Minimisation and Accuracy
Only the minimum amount of personal data required for the intended purpose is collected. Data is kept accurate and updated where necessary, with clients encouraged to provide updated information when relevant.
Data Security
Appropriate technical and organisational measures are in place to protect data from loss, unauthorised access, alteration, or disclosure. These measures include secure storage, password protection, controlled access, and safe disposal of records. Digital data is stored on secure systems with appropriate encryption and access controls. Physical documents are stored securely and accessed only when necessary.
Retention and Disposal
Personal data is retained only for as long as necessary to fulfil legal, regulatory, and professional obligations. Once retention periods expire, data is securely deleted or destroyed in a manner that prevents recovery or misuse.
Data Sharing and Third Parties
Where third party service providers are used (such as IT support, cloud storage, or professional advisers), they must operate to standards consistent with this policy. Contracts or agreements ensure that data is handled securely and lawfully. Data is never transferred outside the UK without appropriate safeguards.
Client Rights
Clients have the right to: access their personal data, request correction of inaccurate information, request deletion where legally appropriate, restrict or object to processing, request data portability, withdraw consent where consent is the lawful basis, requests are handled promptly and in accordance with legal requirements.
Data Breaches
Any suspected or actual data breach is investigated immediately by the Principal. Where required, breaches are reported to the Information Commissioner’s Office within statutory timeframes, and affected individuals are notified when necessary.
Training and Awareness
The Principal maintains up to date knowledge of data protection requirements and ensures that practices remain compliant with evolving legislation and professional standards.
Monitoring and Review
This policy is reviewed regularly to ensure continued compliance with legal and professional obligations. Updates are made where necessary to reflect changes in law, guidance, or business practices.
Approval
This policy is approved and adopted by the Principal.