TrustedTech Workforce Privacy Notice — United Kingdom, Ireland & European Union
Trusted Tech Team Limited (UK) · Trusted Tech Team Limited (Ireland)
Effective Date: September 14, 2026
This version replaces the draft dated 18 August 2026. It has been revised to reflect the Intra-Company Data Transfer Agreement (United Kingdom – United States Transfers of Workforce Personal Data) between Trusted Tech Team Limited and Trusted Tech Team, LLC, the internal process memorandum "Handling UK Employee Data in the United States" dated 14 September 2026, and data protection impact assessment DPIA-2026-09-14.
Applies to: Job applicants and candidates for UK roles, employees, workers, former employees, directors, officers, apprentices, agency and contract personnel engaged by Trusted Tech Team Limited in the United Kingdom, the Republic of Ireland, or elsewhere in the European Economic Area, and their emergency contacts, dependants, and pension or benefit beneficiaries (collectively, "you").
This Notice is provided to you under Articles 13 and 14 of the UK GDPR and the EU GDPR. It does not form part of your contract of employment or engagement and does not create contractual rights or obligations.
1. Who Is the Controller
| Entity | Details | Registered Address |
|---|---|---|
| Trusted Tech Team Limited (UK) | A private limited company registered in England and Wales, company number 14762212. ICO registration number ZC238906 | 3 New Street Square, London EC4A 3BF, United Kingdom |
| Trusted Tech Team Limited (Ireland) | A private limited company registered in Ireland, company number 822833 | Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland |
The entity that employs or engages you is the controller of your personal data. At present, all workforce members are employed or engaged by Trusted Tech Team Limited (UK), which is therefore the controller for the processing described in this Notice. Where the Irish entity becomes your employer, it will be the controller and this Notice will apply to it in the same terms.
Trusted Tech Team, LLC (United States) accesses your personal data, and in most respects does so as our processor acting on our documented instructions under the Intra-Company Data Transfer Agreement. For a limited set of activities — group governance and management oversight, group-level workforce reporting, corporate transactions, and compliance with legal obligations to which it is itself subject — it acts as an independent controller and relies on its own lawful basis. Section 11 explains the access and the safeguards that apply to it.
Data protection and privacy contacts
We have assessed whether we are required to appoint a statutory Data Protection Officer and have concluded that we are not. We have instead designated the following contacts, who between them hold responsibility for data protection compliance:
- Privacy Owner (approvals, incidents, and privacy questions): Jared Pandolfi, Director of IT, Trusted Tech Team, LLC — compliance@trustedtechteam.com or jared.pandolfi@trustedtechteam.com, +1 (949) 617-0199
- UK Entity director and HR contact (employment and workforce matters): Justin Sharrocks, Director and General Manager EMEA, Trusted Tech Team Limited, 3 New Street Square, London EC4A 3BF — justin.sharrocks@trustedtechteam.com, +44 8081 642033
You may raise any matter under this Notice with either contact, or with compliance@trustedtechteam.com.
2. The Law That Applies
This Notice complies with the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, for workforce members in the United Kingdom, and with the EU GDPR and the Irish Data Protection Act 2018 (or the equivalent national law of your Member State) for workforce members in Ireland and the wider EEA.
References in this Notice to the "GDPR" mean the UK GDPR or the EU GDPR, as applicable to you.
3. Categories of Personal Data We Process
Not every category applies to every individual. We hold considerably less about a candidate who is not appointed than about an employee.
a. Identity and contact data. Name, former names, preferred name, home address, personal and work email addresses and telephone numbers, date of birth, gender, marital or civil partnership status where relevant to benefits, photograph, signature, employee number, and next-of-kin and emergency contact details.
b. Identification and eligibility data. National Insurance number or PPS number, passport, national identity card, birth certificate, driving licence, visa and immigration status, right-to-work documentation, and nationality.
c. Recruitment and candidate data. CV, cover letter, application form, employment and education history, qualifications, professional memberships and certifications, references, interview notes, scores and debriefs, assessment and test results, salary expectations, and details of any recruitment agency involved. Where we source candidates through a professional networking or sourcing platform, this also includes profile data obtained from that platform, recruiter-generated notes and ratings, pipeline or project membership, and direct-messaging correspondence.
d. Interview recordings, transcripts, and summaries. Where an interview for a UK role is recorded, the audio or video recording, the transcript, and any automatically generated summary. Section 9 explains how this works and how to decline.
e. Employment and engagement data. Contract of employment or engagement, job title, department, work location, manager, start and end dates, working pattern and hours, timekeeping and attendance records, holiday records, probation and performance reviews, objectives and appraisals, training and development records, disciplinary and grievance records, and details of investigations in which you are involved.
f. Pay, tax, and benefits data. Salary, hourly rate, bonus and commission, equity or incentive plan participation, bank account details, payroll deductions, tax code and PAYE or PRSI records, pension scheme membership and contributions, benefits enrolment and elections, expense and corporate card records, and beneficiary and dependant details.
g. Health and absence data. Sickness absence records, fit notes and medical certificates, occupational health reports, records of workplace accidents and injuries, disability and reasonable adjustment records, health information provided in connection with benefits, insurance, or pension arrangements, and maternity, paternity, adoption, parental, and other family leave records.
h. Equal opportunities data. Racial or ethnic origin, religion or belief, sexual orientation, gender identity, and disability status, where you voluntarily provide it for equal opportunities monitoring. Providing this is entirely voluntary and it is held in anonymised or pseudonymised form for reporting purposes wherever possible. Declining to provide it has no consequence for you.
i. Criminal offence data. Where a role requires it and where lawful, the results of criminal record checks (including Disclosure and Barring Service checks in the UK or Garda vetting in Ireland), and information about sanctions or restricted-party screening.
j. IT, systems, and monitoring data. Login credentials and authentication records, IP and device identifiers, directory and device-management records, system and application access logs, email and messaging metadata and, where lawful and necessary, content, internet and network usage records, security awareness training and phishing simulation results, and alerts generated by our security, endpoint protection, and data loss prevention tools.
k. Electronic signature audit data. Where an employment or engagement document is executed electronically, the signature image, signer email address, IP address, device and browser data, authentication method, viewing and signing timestamps, and the certificate of completion. The certificate of completion is personal data and is retained and deleted together with the document to which it relates.
l. Physical security data. Building access and badge records, visitor logs, and premises video surveillance footage at our locations.
m. Communications and recordings. Correspondence with you, and recordings, transcripts, and summaries of business calls, customer support sessions, and internal meetings where recording is used and notified.
We do not process biometric data — including fingerprints, facial geometry, and voiceprints — for identification, timekeeping, or access control. If this changes, we will update this Notice and carry out a data protection impact assessment before doing so. We note that some applications may invite users to use facial recognition or a fingerprint as an optional means of unlocking the application on their own device; that is a matter of user preference, any biometric data is collected by the application provider and not by us, and you should refer to that provider’s privacy policy for information about it.
4. Where We Get Your Personal Data
We obtain personal data from you directly, and from: recruitment agencies and job boards; professional networking and candidate sourcing platforms; employee and third-party referrals; referees, former employers, and educational institutions; background screening and vetting providers, including the Disclosure and Barring Service or An Garda Síochána; occupational health providers and your GP or specialist, with your consent; HMRC, the Irish Revenue Commissioners, the Department for Work and Pensions, and other government bodies; pension providers, insurers, and benefits administrators; our own IT, security, timekeeping, and access control systems; managers, colleagues, customers, and third parties in the course of performance management or investigations; and publicly available sources, including professional networking sites and public registers.
Where we obtain your data from a source other than you — for example, where a recruiter identifies you on a sourcing platform or you are referred to us — we will tell you the source and provide the information required by Article 14 of the GDPR within a reasonable period and in any event within one month of obtaining the data, or at the point we first contact you if that is sooner.
5. Purposes and Legal Bases
We process your personal data on the following legal bases under Article 6 of the GDPR.
| Purpose | Legal Basis |
|---|---|
| Assessing your application, sourcing and screening candidates, verifying your qualifications and references, and making hiring decisions | Legitimate interests (recruiting suitable staff); Contract (steps prior to entering into a contract at your request) |
| Scheduling interviews and related candidate correspondence | Contract (steps taken at your request prior to entering into a contract) |
| Recording, transcribing, and summarising interviews for UK roles | Legitimate interests (accurate and consistent assessment), where you have been notified in advance and offered an opt-out. We do not rely on consent for this, and recording is not a condition of your consideration for a role — see Section 9 |
| Verifying your right to work and immigration status | Legal obligation (Immigration, Asylum and Nationality Act 2006; Employment Permits Acts) |
| Administering your employment or engagement, including payroll, benefits, expenses, and pension | Contract (performance of your contract); Legal obligation (tax, pensions auto-enrolment, and social security law) |
| Deducting and reporting income tax, National Insurance, and PRSI, and supplying payroll and tax data to our UK payroll tax agent for the preparation of our statutory returns and filings | Legal obligation |
| Supplying enrolment, eligibility, and contribution data to our UK benefits, insurance, and pension providers | Contract; Legal obligation (pension auto-enrolment) |
| Managing working time, holiday, sickness, and family leave | Contract; Legal obligation (Working Time Regulations 1998; Organisation of Working Time Act 1997; statutory pay and leave legislation) |
| Managing performance, training, development, promotion, and succession | Contract; Legitimate interests (running our business effectively) |
| Preparing, despatching, and executing employment and engagement documents electronically, and retaining the executed document and its certificate of completion | Contract |
| Conducting disciplinary, grievance, capability, and investigation processes | Contract; Legitimate interests (maintaining standards and resolving workplace issues); Legal obligation where a statutory procedure applies |
| Workforce reporting and people analytics | Legitimate interests (planning, resourcing, and managing our business), using aggregated data wherever aggregates meet the purpose |
| Making reasonable adjustments and managing health and safety | Legal obligation (Equality Act 2010; Employment Equality Acts 1998–2015; Health and Safety at Work etc. Act 1974; Safety, Health and Welfare at Work Act 2005) |
| Equal opportunities monitoring and reporting, including gender pay gap reporting | Legal obligation where reporting is mandatory; Legitimate interests (promoting equality and diversity) |
| Criminal record and sanctions screening for roles that require it | Legal obligation; Legitimate interests (protecting our business, customers, and data) |
| Monitoring use of our IT systems, devices, networks, and premises for security, compliance, and business continuity | Legitimate interests (protecting our systems, data, personnel, and customers); Legal obligation where monitoring is required to meet a regulatory duty |
| Managing redundancy, restructuring, transfer of undertakings, and corporate transactions | Legal obligation (TUPE and the European Communities (Protection of Employees on Transfer of Undertakings) Regulations); Legitimate interests |
| Establishing, exercising, or defending legal claims, and responding to regulators, tribunals, and courts | Legal obligation; Legitimate interests (protecting our legal position) |
| Contacting your next of kin or emergency contact in an emergency | Vital interests of you or another person; Legitimate interests |
We do not generally rely on your consent to process your personal data, because the imbalance between employer and worker means consent is unlikely to be freely given. Where we do ask for your consent — for example, to obtain an occupational health report, to use your photograph in external marketing, or to provide a personal reference — we will make that clear, and you may refuse or withdraw consent at any time without detriment.
Legitimate interests. Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and concluded that our processing does not override them. You may ask the Privacy Owner for details of the relevant assessment.
6. Special Category and Criminal Offence Data
Special category data (health, racial or ethnic origin, religion or belief, sexual orientation, and trade union membership) is processed only where an Article 9 condition applies, in particular:
- Article 9(2)(b) — carrying out obligations and exercising rights in the field of employment, social security, and social protection law, as authorised by paragraph 1 of Schedule 1 to the Data Protection Act 2018 (UK) or section 46 of the Data Protection Act 2018 (Ireland). This covers sickness absence, family leave, reasonable adjustments, health and safety, and health data processed in the administration of benefits, insurance, and pension arrangements.
- Article 9(2)(f) — establishment, exercise, or defence of legal claims.
- Article 9(2)(h) — occupational medicine and assessment of your working capacity, subject to professional confidentiality obligations.
- Article 9(2)(j) and paragraph 8 of Schedule 1 to the Data Protection Act 2018 (UK) — equality of opportunity or treatment monitoring.
- Article 9(2)(a) — your explicit consent, where none of the above applies.
Criminal offence data is processed under Article 10 of the GDPR in reliance on paragraph 1 of Schedule 1 to the Data Protection Act 2018 (UK) or, in Ireland, section 55 of the Data Protection Act 2018.
We maintain an Appropriate Policy Document as required by Part 4 of Schedule 1 to the Data Protection Act 2018, explaining our procedures for compliance with the data protection principles and our retention and erasure policies for this data. It is reviewed at least annually and you may request a copy from the Privacy Owner.
Restrictions on where this data goes
Special category and criminal offence data is held under enhanced controls: segregated storage with a distinct access group, access granted to named individuals rather than by role, additional logging reviewed monthly, and retention limited to what the decision it relates to requires. The following specific restrictions apply and are contractual obligations on both entities, not internal guidance:
- Occupational health reports, fit notes, medical certificates, clinical correspondence, religious or philosophical belief data, and trade union membership are not accessible from outside the United Kingdom.
- Equal opportunities and diversity monitoring data is accessible from outside the United Kingdom in aggregated form only. Access at individual record level requires the Privacy Owner’s written approval and a documented purpose.
- Health, disability, adjustment, and case material, and record-level health data held for benefits and pension administration, require prior written approval before being transferred or accessed at record level outside the United Kingdom. Approval is given by our UK HR contact for health, absence, adjustment, and case material and by the Privacy Owner in other cases.
- Where the fact and dates of an absence, or the fact and outcome of a check, are sufficient for the purpose, the underlying medical or investigatory material is not transferred or accessed.
- Special category and criminal offence data is never placed in our messaging or electronic signature platforms — not in a channel, a direct message, an envelope, an envelope field, or an attachment. This prohibition is absolute and there is no exception for urgency.
Criminal record check results are reviewed by a limited number of authorised personnel, are not retained beyond the period necessary to make the relevant decision (and in any event no longer than six months after the decision, other than a record of the fact that a check was carried out, the date, and the outcome), and are stored securely and separately from your general personnel file.
7. Monitoring in the Workplace
We provide IT systems, devices, accounts, and premises for business purposes. To protect our systems, data, personnel, and customers, and to meet our legal and contractual obligations, we log and monitor use of those systems. This includes identity, directory, and authentication records; device management and compliance records; system and network access logs; internet and web-filtering records; email and messaging metadata; mail security and filtering records; endpoint detection and response telemetry; security awareness training and phishing simulation results; and data loss prevention alerts. Our email, files, and messaging content is also archived and subject to retention and legal hold tooling. We operate premises video surveillance at our locations for security purposes; cameras are not sited in toilets, changing areas, or other places where you would have a reasonable expectation of privacy.
We access the content of communications or files stored on our systems only where there is a specific and legitimate business reason to do so — for example, a security incident, a workplace investigation, a legal hold, a regulatory request, or business continuity where you are absent — and where doing so is necessary and proportionate. Access is authorised in advance by the Privacy Owner or a senior manager, and is recorded.
We carry out a data protection impact assessment before introducing any new form of systematic monitoring, in line with the Information Commissioner’s guidance on monitoring workers, and we will tell you about it before it begins. We do not use covert monitoring except in the exceptional circumstances permitted by law, where we suspect criminal activity or gross misconduct and telling you would prejudice the investigation, and then only for as long as necessary and with senior authorisation.
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
8. Artificial Intelligence
We use a small number of approved artificial intelligence tools in ways that affect, or could affect, workforce personal data. Our position is as follows.
- Employee relations guidance. Our HR and legal functions use approved general-purpose AI assistants to think through employee relations questions. They are queried with generalised, hypothetical scenarios only. Names, identifying details, and pasted records are not entered, and every output is reviewed by an HR or legal colleague before it is acted on.
- Code assistance. Our IT function uses an approved AI coding assistant on internal code repositories and automation workflow files. Some of those files contain workplace messaging display names and user identifiers, which are personal data. We are removing or pseudonymising those identifiers where the workflow does not require them.
- Meeting and call recording tools. Where recording, transcription, and summarisation tools are used for interviews, meetings, or calls at which employment matters are discussed, the outputs are reviewed by the meeting or call owner. Meetings and calls concerning special category data or case files are not recorded.
- Embedded features are switched off. The AI, agreement analysis, and document intelligence features within our payroll platform and our electronic signature platform are disabled at tenant level. Enabling any of them requires a privacy review and a formal amendment to the Intra-Company Data Transfer Agreement before use.
Your personal data is not used to train, fine-tune, or evaluate any AI model. Our approved suppliers operate under terms that exclude the use of our inputs and outputs for model training. No AI tool outside our approved list may be used with workforce personal data of any kind, and entering workforce data into an unapproved tool is a reportable incident.
No AI tool is used to make, or to materially inform, a decision about you that produces legal or similarly significant effects. AI scoring or ranking of individuals, and AI inference of personality, sentiment, or protected characteristics, are prohibited.
9. Recruitment, Sourcing, and Interview Recording
This Section applies if you are a candidate for a role with Trusted Tech Team Limited.
Sourcing
We source and screen candidates for UK roles through a professional networking and candidate sourcing platform. The licence and the account for that platform are held by Trusted Tech Team, LLC (United States), not by the UK entity, and our UK recruitment is carried out through that account. The platform provider acts as our processor in respect of the data we enter, and as an independent controller in respect of the member data held on its own platform, which is governed by its own privacy notice. The platform is contracted through an Irish entity with onward processing in the United States.
If your data reached us from that platform, from a referral, or from another source rather than from you, we will tell you the source when we first contact you or, at the latest, within one month of obtaining it.
Your candidate data is accessible from the United States by the named individuals recorded in our Access Register, and by the hiring managers involved in your application, each of whom must be recorded in that Register before your documents are sent to them. Section 11 explains the safeguard that applies to that access.
Interview recording
We record, transcribe, and produce automated summaries of interviews for UK roles, so that assessment is accurate and consistent between interviewers. Where we intend to do this:
- we will tell you in advance, in the scheduling communication and again at the start of the interview, that the interview will be recorded, by what tool, for what purpose, who will have access, how long the recording and the transcript will be kept, and how to decline;
- you may decline, before or at the start of the interview. Declining is straightforward, requires no negotiation, and will not affect your consideration for the role. If you decline, the interview goes ahead without recording;
- our legal basis is legitimate interests, not consent. We say so plainly because recording is our default across interviews of this kind, and it would be misleading to describe your position as consent when you have not been asked to give it; and
- we do not record interviews at which special category data or case material is discussed.
The recording is deleted within 30 days of the hiring decision. The transcript and any automated summary are kept with the recruitment file and deleted 12 months from the date of the decision, or, if you are appointed, for the duration of your employment plus six years.
10. Who We Share Your Personal Data With
Within our group
Trusted Tech Team, LLC (United States) accesses your personal data for HR administration, payroll and benefits administration, recruitment, IT support and security, group management, and workforce reporting. Access is not granted to the US entity at large, by role, or as a standing entitlement. It is granted to a defined list of named individuals, each recorded in an Access Register against a specific purpose, set of systems, data categories, and review date. That group presently comprises the Co-Manager, the HR Manager, the Director of IT, Group Corporate Counsel, the Chief Visionary Officer, the Chief Revenue Officer, and the Head of Talent, together with any hiring manager recorded in the Register in connection with a live vacancy. The Register is reviewed at least annually, is checked quarterly as part of access recertification, and access is revoked within 24 hours of a change of role or departure.
Service providers
We use the following categories of service provider. All act as our processors under written contracts meeting the requirements of Article 28 of the GDPR, except where identified otherwise, and none may use your data for its own purposes.
| What they do | Examples |
|---|---|
| HR information system and payroll | Paycom (our HR and payroll system of record); ADP (legacy, read-only, pending deletion of historic records) |
| Email, documents, calendars, and file storage | Microsoft 365 (including OneDrive and SharePoint) and Google Workspace, together with Google Vault for archiving, retention, and legal hold |
| Messaging and collaboration | Slack (Salesforce) |
| Electronic signature | DocuSign |
| Recruitment and candidate sourcing | LinkedIn Recruiter (licensed by Trusted Tech Team, LLC); Calendly (interview scheduling); Fathom (interview recording, transcription, and summarisation) |
| Call recording and conversation analytics | Gong |
| Identity, device, and endpoint management | Microsoft Entra ID; Microsoft Intune; CrowdStrike; Keeper (password and secrets management) |
| Network, email, and web security | Mimecast; Cisco Secure Access; Cisco Meraki (network infrastructure and premises video surveillance) |
| Security awareness training | KnowBe4 |
| Compliance and security assurance | Drata, together with Rhymetec as our virtual chief information security officer, which is an approved onward recipient |
| Backup and recovery | Datto |
| Finance, expenses, and corporate cards | NetSuite (Oracle); Ramp |
| Issue tracking and internal documentation | Atlassian |
| Business telephony | Vonage |
| Workflow automation | n8n, self-hosted on our own infrastructure |
UK advisers, benefits, and pension providers
Data held in our payroll platform is extracted or accessed for the purpose of supplying the following firms, each of which is established in the United Kingdom, is engaged by and contracts with Trusted Tech Team Limited, and is supplied either through scoped access to the payroll platform or through a dedicated shared folder rather than by emailed extract:
- Oury Clark, TPA — our payroll tax agent, which prepares our statutory payroll tax returns and filings. It receives identity, contact, employment, compensation, payroll, and time and attendance data.
- Howden Employee Benefits & Wellbeing Limited — our employee benefits and pension consultants. It receives identity, contact, employment, compensation, benefit election, and dependant and beneficiary data, and health data only where that has been specifically approved.
We record for each of these firms whether it acts as our processor or as an independent controller in respect of a given activity, and we have a written Article 28 contract or data sharing arrangement in place with each accordingly.
Others
- Recruitment agencies, background screening, and vetting providers, including the Disclosure and Barring Service and An Garda Síochána;
- Occupational health providers and employee assistance programme providers;
- Insurers, brokers, and scheme administrators in connection with benefits and pension arrangements;
- Professional advisers, including employment lawyers, accountants, auditors, and insurers;
- Government bodies and regulators, including HMRC, the Irish Revenue Commissioners, the Department for Work and Pensions, the Health and Safety Executive, and the Pensions Regulator;
- Courts, tribunals, and parties to legal proceedings, where necessary to establish, exercise, or defend legal claims;
- Customers, where your name, business contact details, job title, and professional qualifications are provided in connection with the services you deliver; and
- Acquirers, transferees, and their advisers, in connection with a corporate transaction or a transfer of undertakings.
Neither we nor Trusted Tech Team, LLC may disclose your personal data to any recipient that is not on the approved list recorded in the Intra-Company Data Transfer Agreement without our prior written approval. We do not sell your personal data and we do not use it for marketing, product development, or commercial analytics.
11. International Transfers
Where your data is held
You should understand the position accurately: the systems in which most of your personal data is held are hosted in the United States. Our HR and payroll system, our electronic signature platform, our messaging platform, and our email, calendar, and file storage all sit in the United States. We operate a single Microsoft 365 tenant and a single Google Workspace tenant, each shared between the UK and US entities and hosted in the United States, and no UK or EU data residency option is applied to either. A document containing your personal data is therefore transferred outside the United Kingdom at the moment it is created or uploaded, whoever creates it and wherever they are sitting — not only when a colleague in the United States opens it. A small number of our systems are hosted in the United Kingdom or the European Union, including our mail security, network access, and backup services, but support for those services may be provided from outside the United Kingdom.
Access to your personal data from the United States is itself a transfer, whether or not anything is sent, emailed, or downloaded.
The safeguard we rely on
Trusted Tech Team, LLC is not self-certified under the EU–US Data Privacy Framework or the UK Extension to it. We therefore do not, and cannot, rely on adequacy for transfers to it. If you have seen an earlier version of this Notice or another TrustedTech notice suggesting otherwise, this Section states the correct position.
Transfers of your personal data from the United Kingdom to Trusted Tech Team, LLC are made under:
- the Intra-Company Data Transfer Agreement (United Kingdom – United States Transfers of Workforce Personal Data) between Trusted Tech Team Limited and Trusted Tech Team, LLC, which records the purposes, the named individuals permitted to access data, the approved systems and channels, the restrictions on special category data, and the retention periods; and
- the International Data Transfer Agreement (IDTA) issued by the Information Commissioner under section 119A of the Data Protection Act 2018, which is the transfer mechanism for the purposes of Article 46 of the UK GDPR.
We have completed a data protection test — the assessment introduced by the Data (Use and Access) Act 2025, which came into force on 5 February 2026 and replaced the transfer risk assessment — of whether the standard of protection for you in the United States is not materially lower than the standard under the UK GDPR and the Data Protection Act 2018. We review that assessment at least annually and on any material change. Among other things it takes into account that the United Kingdom is a designated qualifying state for the purposes of Executive Order 14086, so that the redress mechanism established by that Order is available in respect of your data.
For transfers to our service providers, the safeguard is recorded against each provider and is either the IDTA or the European Commission’s Standard Contractual Clauses with the UK International Data Transfer Addendum, in each case supported by a data protection test. Where a provider’s own certification under the Data Privacy Framework is relied upon, we verify that the certification is active, that it includes the UK Extension, and that it expressly covers HR data.
The Intra-Company Data Transfer Agreement also commits Trusted Tech Team, LLC to: process your data only on our documented instructions where it acts as our processor; notify us of any personal data breach within 24 hours; forward any rights request it receives to us the same day; challenge any government or law-enforcement request for your data that appears unlawful, overbroad, or disproportionate, disclose only the minimum lawfully required, and notify us unless legally prohibited; and delete or return your data at the end of the applicable retention period. We may suspend transfers and revoke access immediately where the safeguard ceases to be valid.
Ireland and the EEA
The Intra-Company Data Transfer Agreement provides safeguards for United Kingdom to United States transfers only. At present no member of our workforce is employed or engaged in Ireland or elsewhere in the EEA. If that changes, transfers originating in the EEA will be made under the European Commission’s Standard Contractual Clauses or another valid EU transfer mechanism, and this Notice will be updated before any such transfer takes place.
Copies of the safeguards
You may request a copy of the transfer safeguards we have in place by emailing compliance@trustedtechteam.com. Commercially sensitive terms may be redacted.
12. How Long We Keep Your Personal Data
We keep your personal data for the periods required by law and, where no period is prescribed, for as long as necessary for the purposes described above. Where more than one period applies to a record, we apply the longest. Retention settings in our messaging, file storage, and electronic signature platforms are configured to give effect to these periods and are not left at the platform default. United Kingdom limitation periods and statutory retention requirements govern; any United States requirement applies in addition and does not displace them. The periods below run from the end of your employment or engagement unless stated otherwise.
| Category of Record | Retention Period | Basis for the Period |
|---|---|---|
| Recruitment records for unsuccessful applicants (application, CV, interview notes, debriefs, ratings, assessment results, scheduling data) | 12 months from the date of the hiring decision, across every location in which they are held | Limitation periods for discrimination claims: Equality Act 2010, s. 123; Employment Equality Acts 1998–2015, s. 77 |
| Interview recordings | Deleted within 30 days of the hiring decision, whether or not the candidate is appointed | Data minimisation under Article 5(1)(c) |
| Interview transcripts and automated summaries | 12 months from the date of the decision; for appointed candidates, employment plus 6 years with the personnel file | Data minimisation; limitation periods as above |
| Personnel file, contract, and employment records | Employment plus 6 years | Limitation Act 1980, s. 5 (UK); Statute of Limitations 1957, s. 11(1) (Ireland) |
| Executed employment and engagement documents and their certificates of completion | Employment plus 6 years. The document and its certificate are deleted together. Documents that are not executed, and documents relating to an unsuccessful candidate, are deleted 12 months from the date of the decision | Limitation Act 1980, s. 5; data minimisation |
| Payroll and PAYE records, including tax and National Insurance | UK: 3 years after the end of the tax year to which they relate, retained for 6 years in practice. Ireland: 6 years | UK: Income Tax (Pay As You Earn) Regulations 2003, reg. 97; Ireland: Taxes Consolidation Act 1997, s. 886 |
| Payroll and tax data supplied to our UK payroll tax agent | 6 years from the end of the tax year to which the records relate | Statutory filing and tax recordkeeping requirements |
| National Minimum Wage records | UK: 6 years. Ireland: 3 years | National Minimum Wage Act 1998, s. 9 and NMW Regulations 2015, reg. 59 (UK); National Minimum Wage Act 2000, s. 22 (Ireland) |
| Working time and holiday records | UK: 2 years. Ireland: 3 years | Working Time Regulations 1998, reg. 9 (UK); Organisation of Working Time Act 1997, s. 25 and S.I. No. 473/2001 (Ireland) |
| Statutory maternity, paternity, adoption, shared parental, and neonatal care pay records | 3 years after the end of the tax year in which the payment period ends | Statutory Maternity Pay (General) Regulations 1986, reg. 26, and equivalent regulations for other statutory payments |
| Statutory sick pay and sickness absence records | 3 years after the end of the tax year | HMRC guidance; Limitation Act 1980 for related claims |
| Right-to-work and immigration documentation | Duration of employment plus 2 years. Held by Trusted Tech Team Limited and not placed in an electronic signature envelope, a shared folder, or sent to a recipient in the United States | Home Office right-to-work checking guidance; Immigration, Asylum and Nationality Act 2006 |
| Pension auto-enrolment records | 6 years (opt-out notices: 4 years) | Employers’ Duties (Registration and Compliance) Regulations 2010, reg. 5 |
| Benefits, insurance, and occupational pension scheme records | 6 years from the end of the scheme year | Registered Pension Schemes (Provision of Information) Regulations 2006 |
| Accident book entries and RIDDOR reports | 3 years from the date of the last entry or the date of the report | Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013, reg. 12; Social Security (Claims and Payments) Regulations 1979, reg. 25 |
| Health records relating to exposure to hazardous substances | 40 years from the date of the last entry | Control of Substances Hazardous to Health Regulations 2002, reg. 11 |
| Occupational health reports and medical certificates | Duration of employment plus 6 years, held separately in the United Kingdom and with restricted access | Limitation periods for personal injury and discrimination claims |
| Criminal record check (DBS / Garda vetting) results | 6 months from the date of the recruitment or vetting decision; thereafter only a record of the fact, date, and outcome of the check | DBS Code of Practice; data minimisation under Article 5(1)(c) |
| Equal opportunities monitoring data | Held in anonymised or aggregated form for reporting; identifiable form deleted within 12 months of collection | Data minimisation; gender pay gap reporting obligations |
| Disciplinary and grievance records, and employee relations investigations | 6 years from the conclusion of the process; warnings are disregarded for decision-making purposes once expired | Limitation Act 1980, s. 5; Acas Code of Practice |
| Workforce reporting and people analytics records | Current year plus 6 years | Business need; alignment with employment record retention |
| Email, messaging, and file storage content concerning employment matters | Employment plus 6 years, save where a shorter period applies to the underlying record | These channels are not systems of record; content is removed once its purpose is served |
| IT system, email, network, and security logs | 24 months | Security and incident investigation needs; no statutory period |
| Premises video surveillance footage | 31 days, unless retained for a specific investigation | ICO video surveillance guidance; data minimisation |
| Building access and badge records | 24 months | Security needs; no statutory period |
| Records of data subject rights requests | 12 months from completion | GDPR Art. 5(2) accountability |
| Records subject to a legal hold, tribunal claim, or regulatory investigation | For the duration of the hold or proceedings, notwithstanding any shorter period above | Legal preservation obligations |
At the end of the applicable period we securely delete, destroy, or anonymise the data.
Historic candidate records — the current position
We want to be straightforward with you about one area where our practice does not yet match the table above. Candidate records for UK roles have historically been kept without a formal deletion schedule, and records dating from 2022 onwards may still exist in our applicant tracking system, our former HR information system, our candidate sourcing platform, email, file storage, our messaging platform, and on local devices. That does not meet the storage limitation principle in Article 5(1)(e) of the GDPR or the periods set out above.
We are carrying out a documented search of each of those locations, deleting every candidate record that is past its period, and configuring platform retention where the platform allows it. That exercise is to be completed by 10 December 2026 and the outcome recorded. Until it is complete, we will not represent the periods above as describing the position in fact, and any response we give to a request for access to your data will describe what we actually hold rather than what we intend to hold.
13. Your Rights
You have the following rights in relation to your personal data, subject to the conditions and exemptions in the legislation:
- Access — to be told whether we process personal data about you and to receive a copy of it and information about how we use it;
- Rectification — to have inaccurate data corrected and incomplete data completed;
- Erasure — to have data deleted where it is no longer necessary, where you have withdrawn consent and there is no other basis, or where it has been processed unlawfully. This right is limited in the employment context, because we are required by law to keep most workforce records for the periods set out above;
- Restriction — to ask us to limit our use of your data, for example while we check its accuracy or consider an objection;
- Portability — to receive data you provided to us, where we process it by automated means on the basis of consent or contract, in a structured, commonly used, machine-readable format;
- Objection — to object to processing based on our legitimate interests, on grounds relating to your particular situation;
- Withdrawal of consent — where we rely on your consent, to withdraw it at any time without detriment;
- Rights relating to automated decision-making — not to be subject to a decision based solely on automated processing producing legal or similarly significant effects; and
- Complaint — to complain to us and to a supervisory authority.
How to exercise your rights. Email compliance@trustedtechteam.com, or write to the Privacy Owner or the UK Entity HR contact at the addresses in Section 1. There is no charge. We may ask you for information to verify your identity, and we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
You can raise a request with anyone at either company. You do not need to find the right person. If you send a request to a colleague or manager in the United States, it is forwarded to us — the same day where it is received by HR or management, and in any event within two business days — and the statutory time limit runs from the moment either company receives it, not from when it reaches the Privacy Owner.
Our response time. We will respond within one month. We may extend that by up to two further months where the request is complex or where you have made a number of requests, and we will tell you within one month if we do so and why. If the request is for copies of personnel or payroll records, we will respond within any shorter timeframe required by applicable law.
You will not suffer any detriment for exercising your rights, and we will not treat you less favourably as a result.
14. Complaints
If you have a concern about how we handle your personal data, please raise it first with the Privacy Owner at compliance@trustedtechteam.com. We will acknowledge your complaint without undue delay and respond within 30 days.
You may also complain at any time to:
- United Kingdom — the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; https://ico.org.uk/make-a-complaint/
- Ireland — the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28; https://www.dataprotection.ie/
- Elsewhere in the EEA — the supervisory authority in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
15. Your Obligations
You are required to provide certain personal data so that we can perform our contract with you and comply with our legal obligations — for example, your bank details for payroll, your National Insurance or PPS number for tax, and your right-to-work documentation. If you do not provide it, we may be unable to employ or engage you, pay you, or administer your benefits.
Please keep us informed if your personal data changes during your employment or engagement, and let us know if the data we hold about you is inaccurate or incomplete.
16. Security
We maintain appropriate technical and organisational measures to protect your personal data, including role-based access controls granted on a least-privilege basis, multi-factor authentication, encryption in transit and at rest, network and endpoint security, device management, secure storage of paper records, confidentiality obligations on those who handle HR data, vendor due diligence, and annual data protection training. Access to HR records is limited to those with a genuine need, is recorded in the Access Register, is reviewed at least quarterly, and is revoked within 24 hours of a change of role or departure. Access to HR records is logged, and those logs are retained for at least 12 months.
We maintain a personal data breach response procedure. Trusted Tech Team, LLC is required to notify us of any breach or suspected breach affecting workforce data within 24 hours, which is deliberately shorter than the regulatory deadline so that we have time to assess it. We will notify the Information Commissioner’s Office or the Data Protection Commission, and where required you, in accordance with Articles 33 and 34 of the GDPR.
17. Changes to This Notice
We may update this Notice from time to time. We will notify you of any material changes and make the current version available through our HR systems and on request from the Privacy Owner. We review this Notice at least annually, and on any change to the systems we use, the individuals with access to your data, or the transfer mechanism we rely on.
18. Contact
Privacy Owner: Jared Pandolfi, Director of IT — compliance@trustedtechteam.com / jared.pandolfi@trustedtechteam.com, +1 (949) 617-0199
UK Entity director and HR contact: Justin Sharrocks, Director and General Manager EMEA, Trusted Tech Team Limited — justin.sharrocks@trustedtechteam.com, +44 8081 642033
Address: 3 New Street Square, London EC4A 3BF, United Kingdom
Telephone: +44 8081 642033
General privacy inbox: compliance@trustedtechteam.com