This policy sets out our commitment to the UK GDPR, the Data Protection Act 2018 and related privacy requirements. It complements our public privacy policy and applies to personal information handled in our business operations.
Our commitment
We process personal information lawfully, fairly and transparently; collect it for specified purposes; limit it to what is necessary; keep it accurate; retain it no longer than needed; and protect it with appropriate security. We must also be able to demonstrate compliance with these principles.
Roles and responsibility
Essex and Cambridge Events Limited T/A 3D Events Group is normally the controller for customer, prospect, supplier and website information. Everyone handling personal information for the business must follow this policy, use approved systems, maintain confidentiality and raise concerns promptly. Where we process data solely on documented instructions for another controller, the relevant contract will define those responsibilities.
Lawful basis and transparency
Before processing personal information, we identify an appropriate lawful basis such as contract, steps before a contract, legal obligation, legitimate interests or consent. Special-category or criminal-offence information requires an additional legal condition and must not be collected routinely. We provide privacy information in a concise and accessible form.
Data minimisation, accuracy and retention
We collect only information relevant to the task, take reasonable steps to correct inaccurate records, and follow retention periods based on legal, financial, insurance, safety and operational needs. Information reaching the end of its retention period is securely deleted or anonymised unless a valid reason requires continued preservation.
Security and access
Access is limited according to role and business need. We use proportionate controls for accounts, devices, storage, sharing and disposal. Personal information must not be placed in unapproved systems or shared with unauthorised recipients. Suppliers handling personal information are subject to appropriate diligence and contractual protections.
Individual rights
Requests to exercise data protection rights must be passed promptly to the person responsible for privacy. We verify identity where appropriate, locate relevant information, apply any lawful exemptions and respond within the statutory period. We do not disadvantage a person for exercising their rights.
Data protection by design
Privacy and security are considered when introducing a new service, supplier, system or material use of personal information. A data protection impact assessment is completed where processing is likely to create a high risk to people. International transfers require an approved UK transfer mechanism and any necessary risk assessment.
Personal data breaches
Any suspected loss, unauthorised access, disclosure or alteration of personal information must be reported internally immediately. We will contain and assess the incident, document the decision and notify the Information Commissioner’s Office within 72 hours where the legal threshold is met. Affected people will also be informed where a breach is likely to create a high risk to them.
Training, review and contact
People handling personal information receive guidance appropriate to their role. We review this policy and our practices periodically and after material changes or incidents. Questions or concerns should be sent to sales@3deventsgroup.com.