TrustedTech Workforce Privacy Notice — United Kingdom, Ireland & European Union
Trusted Tech Team Limited (UK) · Trusted Tech Team Limited (Ireland)
Effective Date: August 28, 2026
Applies to: Job applicants, employees, workers, former employees, directors, officers, apprentices, agency and contract personnel engaged by Trusted Tech Team Limited in the United Kingdom, the Republic of Ireland, or elsewhere in the European Economic Area, and their emergency contacts, dependants, and pension or benefit beneficiaries (collectively, “you”).
This Notice is provided to you under Articles 13 and 14 of the UK GDPR and the EU GDPR. It does not form part of your contract of employment or engagement and does not create contractual rights or obligations.
1. Who Is the Controller
| Entity | Details | Registered Address |
|---|---|---|
| Trusted Tech Team Limited (UK) | A private limited company registered in England and Wales, company number 14762212 | 3 New Street Square, London EC4A 3BF, United Kingdom |
| Trusted Tech Team Limited (Ireland) | A private limited company registered in Ireland, company number 822833 | Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland |
The entity that employs or engages you is the controller of your personal data. At present, all workforce members in the UK, Ireland, and the EEA are employed or engaged by Trusted Tech Team Limited (UK), which is therefore the controller for the processing described in this Notice. Where the Irish entity becomes your employer, it will be the controller and this Notice will apply to it in the same terms.
Data protection and privacy contact:
Justin Sharrocks, Director
Trusted Tech Team Limited
3 New Street Square, London EC4A 3BF, United Kingdom
Email: compliance@trustedtechteam.com
2. The Law That Applies
This Notice complies with the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, for workforce members in the United Kingdom, and with the EU GDPR and the Irish Data Protection Act 2018 (or the equivalent national law of your Member State) for workforce members in Ireland and the wider EEA.
3. Categories of Personal Data We Process
a. Identity and contact data. Name, former names, preferred name, home address, personal and work email addresses and telephone numbers, date of birth, gender, marital or civil partnership status where relevant to benefits, photograph, signature, employee number, and next-of-kin and emergency contact details.
b. Identification and eligibility data. National Insurance number or PPS number, passport, national identity card, birth certificate, driving licence, visa and immigration status, right-to-work documentation, and nationality.
c. Recruitment data. CV, cover letter, application form, employment and education history, qualifications, professional memberships and certifications, references, interview notes and scores, assessment and test results, salary expectations, and details of any recruitment agency involved.
d. Employment and engagement data. Contract of employment or engagement, job title, department, work location, manager, start and end dates, working pattern and hours, timekeeping and attendance records, holiday records, probation and performance reviews, objectives and appraisals, training and development records, disciplinary and grievance records, and details of investigations in which you are involved.
e. Pay, tax, and benefits data. Salary, hourly rate, bonus and commission, equity or incentive plan participation, bank account details, payroll deductions, tax code and PAYE or PRSI records, pension scheme membership and contributions, benefits enrolment and elections, expense claims, and beneficiary and dependant details.
f. Health and absence data. Sickness absence records, fit notes and medical certificates, occupational health reports, records of workplace accidents and injuries, disability and reasonable adjustment records, and maternity, paternity, adoption, parental, and other family leave records.
g. Equal opportunities data. Racial or ethnic origin, religion or belief, sexual orientation, gender identity, and disability status, where you voluntarily provide it for equal opportunities monitoring. Providing this is entirely voluntary and it is held in anonymised or pseudonymised form for reporting purposes wherever possible. Declining to provide it has no consequence for you.
h. Criminal offence data. Where a role requires it and where lawful, the results of criminal record checks (including Disclosure and Barring Service checks in the UK or Garda vetting in Ireland), and information about sanctions or restricted-party screening.
i. IT, systems, and monitoring data. Login credentials and authentication records, IP and device identifiers, system and application access logs, email and messaging metadata and, where lawful and necessary, content, internet usage records, and alerts generated by our security, endpoint protection, and data loss prevention tools.
j. Physical security data. Building access and badge records, visitor logs, and CCTV footage at our premises.
k. Communications and recordings. Correspondence with you, and recordings of business calls, customer support sessions, and internal meetings where recording is used and notified.
We do not process biometric data — including fingerprints, facial geometry, and voiceprints — for identification, timekeeping, or access control. If this changes, we will update this Notice and carry out a data protection impact assessment before doing so. In this regard, however, we note that some applications may invite users to use facial recognition or fingerprints as an optional mechanism to access certain applications; however, such invitations are optional—based on user preference, and any biometric data collection is effected by the application provider and not by us; accordingly, please look to the privacy policies of such application providers for further information regarding their management of such biometric information.
4. Where We Get Your Personal Data
We obtain personal data from you directly, and from: recruitment agencies and job boards; referees, former employers, and educational institutions; background screening and vetting providers, including the Disclosure and Barring Service or An Garda Síochána; occupational health providers and your GP or specialist, with your consent; HMRC, the Irish Revenue Commissioners, the Department for Work and Pensions, and other government bodies; pension providers, insurers, and benefits administrators; our own IT, security, timekeeping, and access control systems; managers, colleagues, customers, and third parties in the course of performance management or investigations; and publicly available sources, including professional networking sites and public registers.
5. Purposes and Legal Bases
We process your personal data on the following legal bases under Article 6 of the GDPR.
| Purpose | Legal Basis |
|---|---|
| Assessing your application, verifying your qualifications and references, and making hiring decisions | Legitimate interests (recruiting suitable staff); Contract (steps prior to entering into a contract at your request) |
| Verifying your right to work and immigration status | Legal obligation (Immigration, Asylum and Nationality Act 2006; Employment Permits Acts) |
| Administering your employment or engagement, including payroll, benefits, expenses, and pension | Contract (performance of your contract); Legal obligation (tax, pensions auto-enrolment, and social security law) |
| Deducting and reporting income tax, National Insurance, and PRSI | Legal obligation |
| Managing working time, holiday, sickness, and family leave | Contract; Legal obligation (Working Time Regulations 1998; Organisation of Working Time Act 1997; statutory pay and leave legislation) |
| Managing performance, training, development, promotion, and succession | Contract; Legitimate interests (running our business effectively) |
| Conducting disciplinary, grievance, capability, and investigation processes | Contract; Legitimate interests (maintaining standards and resolving workplace issues); Legal obligation where a statutory procedure applies |
| Making reasonable adjustments and managing health and safety | Legal obligation (Equality Act 2010; Employment Equality Acts 1998–2015; Health and Safety at Work etc. Act 1974; Safety, Health and Welfare at Work Act 2005) |
| Equal opportunities monitoring and reporting, including gender pay gap reporting | Legal obligation where reporting is mandatory; Legitimate interests (promoting equality and diversity) |
| Criminal record and sanctions screening for roles that require it | Legal obligation; Legitimate interests (protecting our business, customers, and data) |
| Monitoring use of our IT systems and premises for security, compliance, and business continuity | Legitimate interests (protecting our systems, data, personnel, and customers); Legal obligation where monitoring is required to meet a regulatory duty |
| Managing redundancy, restructuring, transfer of undertakings, and corporate transactions | Legal obligation (TUPE and European Communities (Protection of Employees on Transfer of Undertakings) Regulations); Legitimate interests |
| Establishing, exercising, or defending legal claims, and responding to regulators, tribunals, and courts | Legal obligation; Legitimate interests (protecting our legal position) |
| Contacting your next of kin or emergency contact in an emergency | Vital interests of you or another person; Legitimate interests |
We do not generally rely on your consent to process your personal data, because the imbalance between employer and worker means consent is unlikely to be freely given. Where we do ask for your consent — for example, to obtain an occupational health report, to use your photograph in external marketing, or to provide a personal reference — we will make that clear, and you may refuse or withdraw consent at any time without detriment.
6. Special Category and Criminal Offence Data
Special category data (health, racial or ethnic origin, religion or belief, sexual orientation, and trade union membership) is processed only where an Article 9 condition applies, in particular:
- Article 9(2)(b) — carrying out obligations and exercising rights in the field of employment, social security, and social protection law, as authorised by paragraph 1 of Schedule 1 to the Data Protection Act 2018 (UK) or section 46 of the Data Protection Act 2018 (Ireland). This covers sickness absence, family leave, reasonable adjustments, and health and safety.
- Article 9(2)(f) — establishment, exercise, or defence of legal claims.
- Article 9(2)(h) — occupational medicine and assessment of your working capacity, subject to professional confidentiality obligations.
- Article 9(2)(j) and paragraph 8 of Schedule 1 to the Data Protection Act 2018 (UK) — equality of opportunity or treatment monitoring.
- Article 9(2)(a) — your explicit consent, where none of the above applies.
Criminal offence data is processed under Article 10 of the GDPR and, in the UK, in reliance on a condition in Schedule 1 to the Data Protection Act 2018, or, in Ireland, section 55 of the Data Protection Act 2018.
Where we rely on a Schedule 1 condition that requires it, we maintain an Appropriate Policy Document as required by Part 4 of Schedule 1 to the Data Protection Act 2018, explaining our procedures for compliance with the data protection principles and our retention and erasure policies for that data. You may request a copy from the Data Protection Officer.
Criminal record check results are reviewed by a limited number of authorised personnel, are not retained beyond the period necessary to make the relevant decision (and in any event no longer than six months after the decision, other than a record of the fact that a check was carried out, the date, and the outcome), and are stored securely and separately from your general personnel file.
7. Monitoring in the Workplace
We provide IT systems, devices, accounts, and premises for business purposes. To protect our systems, data, personnel, and customers, and to meet our legal and contractual obligations, we log and monitor use of those systems. This includes system and network access logs, internet usage, email and messaging metadata, endpoint security events, and data loss prevention alerts. We also operate CCTV at our premises for security purposes; cameras are not sited in toilets, changing areas, or other places where you would have a reasonable expectation of privacy.
We access the content of communications or files stored on our systems only where there is a specific and legitimate business reason to do so — for example, a security incident, a workplace investigation, a legal hold, a regulatory request, or business continuity where you are absent — and where doing so is necessary and proportionate. Access is authorised in advance by the Data Protection Officer or a senior manager, and is recorded.
We carry out a data protection impact assessment before introducing any new form of systematic monitoring, in line with the Information Commissioner’s guidance on monitoring workers, and we will tell you about it before it begins. We do not use covert monitoring except in the exceptional circumstances permitted by law, where we suspect criminal activity or gross misconduct and telling you would prejudice the investigation, and then only for as long as necessary and with senior authorisation.
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
8. Who We Share Your Personal Data With
- Our group companies — Trusted Tech Team, LLC (United States) — for group HR administration, IT support, and management purposes;
- Payroll, HR information system, pension, and benefits providers, insurers, brokers, and administrators;
- Recruitment agencies, background screening, and vetting providers, including the Disclosure and Barring Service and An Garda Síochána;
- Occupational health providers and employee assistance programme providers;
- IT, cloud hosting, cybersecurity, and communications providers;
- Professional advisers, including employment lawyers, accountants, auditors, and insurers;
- Government bodies and regulators, including HMRC, the Irish Revenue Commissioners, the Department for Work and Pensions, the Health and Safety Executive, and the Pensions Regulator;
- Courts, tribunals, and parties to legal proceedings, where necessary to establish, exercise, or defend legal claims;
- Customers, where your name, business contact details, job title, and professional qualifications are provided in connection with the services you deliver; and
- Acquirers, transferees, and their advisers, in connection with a corporate transaction or a transfer of undertakings.
Processors act only on our documented instructions under a written contract meeting the requirements of Article 28 of the GDPR.
9. International Transfers
Your personal data is stored within the United Kingdom and the European Economic Area. It is accessed from the United States by Trusted Tech Team, LLC for group HR, IT, and management purposes, and may be accessed from the United Arab Emirates by TrustedTech FZCO for the same purposes.
Where we transfer your personal data outside the UK or the EEA, we rely on:
- an adequacy decision or adequacy regulations, where one applies to the recipient — including, where the US recipient is self-certified and the transfer falls within its scope, the EU–US Data Privacy Framework and the UK Extension to it; or
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) for EU transfers, and the International Data Transfer Agreement or the UK Addendum for UK transfers, in each case supported by a transfer risk assessment and, where appropriate, supplementary measures.
Transfers to the United Arab Emirates are made under Standard Contractual Clauses or the International Data Transfer Agreement, supported by a transfer risk assessment. The United Arab Emirates is not the subject of an adequacy decision or adequacy regulations.
You may request a copy of the safeguards we have in place from the Data Protection Officer.
10. How Long We Keep Your Personal Data
We keep your personal data for the periods required by law and, where no period is prescribed, for as long as necessary for the purposes described above. Where more than one period applies to a record, we apply the longest. The periods below run from the end of your employment or engagement unless stated otherwise.
| Category of Record | Retention Period | Basis for the Period |
|---|---|---|
| Recruitment records for unsuccessful applicants (application, CV, interview notes, assessment results) | 12 months from the date of the decision | Limitation periods for discrimination claims: Equality Act 2010, s. 123 (3 months, extendable); Employment Equality Acts 1998–2015, s. 77 (6 months, extendable to 12) |
| Personnel file, contract, and employment records | 6 years from the end of employment | Limitation Act 1980, s. 5 (UK); Statute of Limitations 1957, s. 11(1) (Ireland) — 6-year limitation period for contract claims |
| Payroll and PAYE records, including tax and National Insurance | UK: 3 years after the end of the tax year to which they relate, retained for 6 years in practice. Ireland: 6 years | UK: Income Tax (Pay As You Earn) Regulations 2003, reg. 97; Ireland: Taxes Consolidation Act 1997, s. 886 |
| National Minimum Wage / National Minimum Wage records | UK: 6 years. Ireland: 3 years | National Minimum Wage Act 1998, s. 9 and NMW Regulations 2015, reg. 59 (UK); National Minimum Wage Act 2000, s. 22 (Ireland) |
| Working time and holiday records | UK: 2 years. Ireland: 3 years | Working Time Regulations 1998, reg. 9 (UK); Organisation of Working Time Act 1997, s. 25 and S.I. No. 473/2001 (Ireland) |
| Statutory maternity, paternity, adoption, shared parental, and neonatal care pay records | 3 years after the end of the tax year in which the payment period ends | Statutory Maternity Pay (General) Regulations 1986, reg. 26, and equivalent regulations for other statutory payments |
| Statutory sick pay and sickness absence records | 3 years after the end of the tax year | HMRC guidance; Limitation Act 1980 for related claims |
| Right-to-work and immigration documentation | Duration of employment plus 2 years | Home Office right-to-work checking guidance; Immigration, Asylum and Nationality Act 2006 |
| Pension auto-enrolment records | 6 years (opt-out notices: 4 years) | Employers’ Duties (Registration and Compliance) Regulations 2010, reg. 5 |
| Occupational pension scheme records | 6 years from the end of the scheme year | Registered Pension Schemes (Provision of Information) Regulations 2006 |
| Accident book entries and RIDDOR reports | 3 years from the date of the last entry or the date of the report | Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013, reg. 12; Social Security (Claims and Payments) Regulations 1979, reg. 25 |
| Health records relating to exposure to hazardous substances | 40 years from the date of the last entry | Control of Substances Hazardous to Health Regulations 2002, reg. 11 |
| Occupational health reports and medical certificates | Duration of employment plus 6 years, held separately and with restricted access | Limitation periods for personal injury and discrimination claims |
| Criminal record check (DBS / Garda vetting) results | 6 months from the date of the recruitment or vetting decision; thereafter only a record of the fact, date, and outcome of the check | DBS Code of Practice; data minimisation under Article 5(1)(c) |
| Equal opportunities monitoring data | Held in anonymised or aggregated form for reporting; identifiable form deleted within 12 months of collection | Data minimisation; gender pay gap reporting obligations |
| Disciplinary and grievance records | 6 years from the conclusion of the process; warnings are disregarded for decision-making purposes once expired | Limitation Act 1980, s. 5; Acas Code of Practice |
| IT system, email, network, and security logs | 24 months | Security and incident investigation needs; no statutory period |
| CCTV footage | 31 days, unless retained for a specific investigation | ICO CCTV and video surveillance guidance; data minimisation |
| Building access and badge records | 24 months | Security needs; no statutory period |
| Records of data subject rights requests | 12 months from completion | GDPR Art. 5(2) accountability |
| Records subject to a legal hold, tribunal claim, or regulatory investigation | For the duration of the hold or proceedings, notwithstanding any shorter period above | Legal preservation obligations |
At the end of the applicable period we securely delete, destroy, or anonymise the data.
11. Your Rights
You have the following rights in relation to your personal data, subject to the conditions and exemptions in the legislation:
- Access — to be told whether we process personal data about you and to receive a copy of it and information about how we use it;
- Rectification — to have inaccurate data corrected and incomplete data completed;
- Erasure — to have data deleted where it is no longer necessary, where you have withdrawn consent and there is no other basis, or where it has been processed unlawfully. This right is limited in the employment context, because we are required by law to keep most workforce records for the periods set out above;
- Restriction — to ask us to limit our use of your data, for example while we check its accuracy or consider an objection;
- Portability — to receive data you provided to us, where we process it by automated means on the basis of consent or contract, in a structured, commonly used, machine-readable format;
- Objection — to object to processing based on our legitimate interests, on grounds relating to your particular situation;
- Withdrawal of consent — where we rely on your consent, to withdraw it at any time without detriment;
- Rights relating to automated decision-making — not to be subject to a decision based solely on automated processing producing legal or similarly significant effects; and
- Complaint — to complain to us and to a supervisory authority.
How to exercise your rights. Email compliance@trustedtechteam.com, or write to the Data Protection Officer at the address in Section 1. There is no charge. We may ask you for information to verify your identity, and we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
We will respond within one month. We may extend that by up to two further months where the request is complex or where you have made a number of requests, and we will tell you within one month if we do so and why.
You will not suffer any detriment for exercising your rights, and we will not treat you less favourably as a result.
12. Complaints
If you have a concern about how we handle your personal data, please raise it first with the Data Protection Officer at compliance@trustedtechteam.com. We will acknowledge your complaint without undue delay and respond within 30 days.
You may also complain at any time to:
- United Kingdom — the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; https://ico.org.uk/make-a-complaint/
- Ireland — the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28; https://www.dataprotection.ie/
- Elsewhere in the EEA — the supervisory authority in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
13. Your Obligations
You are required to provide certain personal data so that we can perform our contract with you and comply with our legal obligations — for example, your bank details for payroll, your National Insurance or PPS number for tax, and your right-to-work documentation. If you do not provide it, we may be unable to employ or engage you, pay you, or administer your benefits.
Please keep us informed if your personal data changes during your employment or engagement, and let us know if the data we hold about you is inaccurate or incomplete.
14. Security
We maintain appropriate technical and organisational measures to protect your personal data, including role-based access controls, encryption, network and endpoint security, secure storage of paper records, confidentiality obligations on those who handle HR data, vendor due diligence, and staff training. HR records are accessible only to those with a genuine need. We maintain a personal data breach response procedure and will notify the Information Commissioner’s Office or the Data Protection Commission, and where required you, in accordance with Articles 33 and 34 of the GDPR.
15. Changes to This Notice
We may update this Notice from time to time. We will notify you of any material changes and make the current version available through our HR systems and on request from the Data Protection Officer.
16. Contact
Data protection and privacy contact: Justin Sharrocks, Director, Trusted Tech Team Limited
Email: compliance@trustedtechteam.com
Address: 3 New Street Square, London EC4A 3BF, United Kingdom
Telephone: +44 8081 642033