Our commitment to UK GDPR and data protection excellence
Swift Staffing Ltd is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We recognise the importance of data protection and privacy for all individuals whose data we process.
Registration Number: ZA123456
UK GDPR, DPA 2018, PECR compliant
Our GDPR compliance framework covers:
Our Pledge: We treat data protection as a fundamental right, not just a legal requirement. We integrate privacy by design and by default into all our processes.
We have implemented a comprehensive GDPR compliance framework based on the following pillars:
| Pillar | Components | Status |
|---|---|---|
| Governance | Policies, procedures, accountability | Implemented |
| Data Mapping | RoPA, data flows, third parties | Implemented |
| Risk Management | DPIA, risk assessments, mitigation | Implemented |
| Security | Technical & organisational measures | Implemented |
| Individual Rights | SAR procedures, rights management | Implemented |
| Breach Management | Detection, response, notification | Implemented |
| Third Party Management | DPAs, vendor assessments | Implemented |
| Training & Awareness | Staff training, ongoing education | Implemented |
We adhere to the seven data protection principles of UK GDPR:
Processing with valid legal basis, fairness, and transparency
Collect for specified, explicit, legitimate purposes
Adequate, relevant, limited to what's necessary
Keep accurate, up-to-date data
Keep only for as long as necessary
Appropriate security against unauthorised processing
Take responsibility for compliance
We implement these principles through:
We only process personal data when we have a valid lawful basis under UK GDPR:
| Processing Activity | Lawful Basis | Documentation |
|---|---|---|
| Candidate placement | Contractual necessity, legitimate interests | Service agreement, RoPA |
| Client service delivery | Contractual necessity | Client contract, RoPA |
| Compliance checks | Legal obligation | Compliance policy, RoPA |
| Marketing communications | Consent, legitimate interests | Consent records, RoPA |
| Staff administration | Contractual necessity, legal obligation | Employment contracts, RoPA |
| Website analytics | Legitimate interests | Cookie policy, RoPA |
Where we rely on consent, we ensure it is:
Consent Records: We maintain detailed records of consent, including what was consented to, when, and how. Consent can be withdrawn at any time through our privacy portal.
We have established robust procedures to facilitate data subject rights under UK GDPR:
One-month response timeframe, no fee (usually)
Procedure: SAR form, identity verification, data compilation
Subject to legal limitations and exemptions
Grounds: Withdrawn consent, unlawful processing, objection to legitimate interests
Temporary restriction of processing
Circumstances: Accuracy challenged, processing unlawful, objection pending
Structured, commonly used, machine-readable format
Scope: Data provided by data subject, processed by consent or contract
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk:
We implement data protection principles from the initial design stage of any new processing activity:
We have established clear procedures for detecting, reporting, and investigating personal data breaches:
24/7 monitoring, staff reporting procedures, risk assessment matrix
ICO: Within 72 hours of awareness, Individuals: Without undue delay if high risk
Root cause analysis, impact assessment, containment measures
Security improvements, process updates, training reinforcement
Our dedicated breach response team includes:
We have appointed a Data Protection Officer (DPO) in accordance with UK GDPR requirements:
Name: [DPO Name]
Email: dpo@swiftstaffing.co.uk
Phone: +44 1773 442061 (Ext. 2)
Qualifications: Certified Data Protection Officer (C-DPO), UK GDPR Specialist
Independence: Our DPO operates independently and reports directly to senior management. The DPO's contact details are publicly available and provided to the ICO.
We ensure all staff receive appropriate data protection training:
| Training Type | Frequency | Audience | Content |
|---|---|---|---|
| Induction Training | On joining | All new staff | Basic principles, policies, reporting procedures |
| Annual Refresher | Yearly | All staff | Updates, case studies, best practices |
| Role-Specific | As needed | High-risk roles | Specialist training for recruiters, IT staff |
| Management Training | Bi-annual | Managers | Obligations, incident management, team oversight |
Our ongoing awareness program includes:
We conduct regular audits and reviews to ensure ongoing compliance:
Quarterly reviews by DPO, annual comprehensive audit
Bi-annual third-party audits, ICO readiness assessments
Our improvement cycle includes:
Metrics & Reporting: We track key compliance metrics including SAR response times, breach incidents, training completion rates, and audit findings to drive continuous improvement.
Swift Staffing Ltd is committed to maintaining the highest standards of data protection and privacy. We regularly review and update our compliance framework to ensure ongoing alignment with UK GDPR requirements and best practices.
Date of Last Framework Review: March 17, 2026