GDPR Compliance

Your Rights Under UK GDPR

Effective Date: May 25, 2018 | Last Updated: January 2024

UK General Data Protection Regulation (UK GDPR)

The UK GDPR and Data Protection Act 2018 give you important rights over your personal data. MOD Hearing Help (RGL Management Ltd) is committed to protecting your privacy and ensuring transparent processing of your information.

ICO Registered

Registration: ZA123456

Data Protection Officer

[email protected]

Response Time

Within 30 days

Your Data Protection Rights

Response within 30 days

Right to Access

You have the right to request copies of your personal data

  • Request a copy of all personal data we hold about you
  • Receive information about how we process your data
  • Understand the purposes of processing
  • Know who we share your data with
Correction within 30 days

Right to Rectification

You can request correction of inaccurate personal data

  • Correct any inaccurate information
  • Complete any incomplete data
  • Update outdated information
  • Verify corrections have been made
Deletion within 30 days

Right to Erasure

The 'right to be forgotten' in certain circumstances

  • Request deletion when data is no longer necessary
  • Withdraw consent for processing
  • Object to direct marketing use
  • Data was unlawfully processed
Restriction within 30 days

Right to Restrict Processing

Limit how we use your personal data

  • Contest the accuracy of data
  • Processing is unlawful but you don't want erasure
  • We no longer need data but you need it for legal claims
  • You've objected to processing pending verification
Provided within 30 days

Right to Data Portability

Receive your data in a structured, machine-readable format

  • Transfer data to another service provider
  • Receive data in common format (CSV, JSON)
  • Direct transfer between controllers where feasible
  • Applies to automated processing based on consent
Immediate for marketing

Right to Object

Object to processing of your personal data

  • Object to direct marketing at any time
  • Object to processing for legitimate interests
  • Object to processing for research/statistics
  • We must stop unless we have compelling grounds

How to Exercise Your Rights

Submit a Request:

  1. Contact our Data Protection Officer
  2. Specify which right you wish to exercise
  3. Provide identification for verification
  4. Include any relevant details about your data
  5. We'll respond within 30 days

Contact Methods:

Email (Preferred)

[email protected]

Post

RGL Management Limited, 4 The Business Quarter, Eco Park Road, Ludlow. Shropshire, SY8 1FD

Lawful Bases for Processing

Under UK GDPR, we must have a lawful basis for processing your personal data. Here are the bases we rely on and examples of when we use each:

Consent

You have given clear consent for us to process your personal data

Examples:

  • Marketing communications
  • Cookie usage
  • Newsletter subscriptions

Contract

Processing is necessary for our contract with you

Examples:

  • Managing your compensation claim
  • Providing our services
  • Client communications

Legal Obligation

We need to comply with the law

Examples:

  • Anti-money laundering checks
  • Tax records
  • FCA regulatory requirements

Legitimate Interests

Processing is necessary for our legitimate interests

Examples:

  • Fraud prevention
  • Network security
  • Service improvements

Vital Interests

Processing is necessary to protect someone's life

Examples:

  • Medical emergencies
  • Safeguarding concerns

International Data Transfers

We primarily process your data within the UK. However, some services may involve international transfers:

  • Cloud Storage: Data may be stored on servers in the EU (adequate decision in place)
  • Analytics: Google Analytics may process data in the US (using Standard Contractual Clauses)
  • Support Tools: Customer support tools with appropriate safeguards

Safeguards: We ensure all international transfers comply with UK GDPR through adequacy decisions, Standard Contractual Clauses, or other appropriate safeguards.

Data Breach Response

In the unlikely event of a personal data breach that poses a high risk to your rights and freedoms:

72h
ICO Notification: We report to the Information Commissioner's Office within 72 hours
ASAP
Individual Notification: We inform affected individuals without undue delay
Incident Response: Our security team works to contain and remediate the breach

How to Make a Complaint

If you're unhappy with how we've handled your personal data, you have the right to complain:

1. Contact Us First

We'd like the opportunity to resolve your concerns directly.

Email: [email protected]

Response: Within 30 days

2. Contact the ICO

You can complain to the Information Commissioner's Office:

Website: ico.org.uk

Phone: 0303 123 1113

Live chat: Available on ICO website

Updates to This GDPR Notice

We may update this GDPR notice to reflect changes in law or our practices. We'll notify you of significant changes via email or prominent notice on our website.

Last Review Date: January 2024
Next Review Date: January 2025