- This Privacy Policy (the “Policy”) explains how Cataphract Ltd (“Cataphract”, “we”, “us”, “our”) collects and processes personal data and how we comply with applicable UK data protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”), and the Data (Use and Access) Act 2025 (“DUAA”) to the extent commenced. This Policy also reflects relevant requirements of ISO/IEC 27001:2022 and ISO 9001:2015, and industry standards for screening (BS 7858:2019).
Scope and who this policy applies to
- This policy applies to:
- Clients using our Disclosure and Pre‑employment Screening and Vetting services (“Clients”).
- Individuals undergoing checks (“Applicants”).
- Visitors to our websites, suppliers and other business contacts.
- Our website and services are not intended for children, and we do not knowingly collect data relating to children.
Our privacy and quality principles
- We follow these principles:
- We process only the personal data necessary for the intended purpose (data minimisation).
- Access is role‑based and limited to those who need it to perform their duties.
- We retain personal data only for as long as necessary and in line with defined schedules.
- Decisions about you are based on accurate, up‑to‑date information; inaccuracies are corrected promptly.
- We protect personal data against unauthorised or accidental access, alteration or disclosure with appropriate technical and organisational controls (including encryption, access control, logging and monitoring, and supplier assurance).
- We operate a certified Information Security Management System (ISMS) to ISO/IEC 27001:2022 and a Quality Management System to ISO 9001:2015, supporting risk‑based controls, internal audits, corrective actions and continual improvement.
Who we are
- Cataphract Ltd, registered in England (Company No. 04650409). Registered address: Southgate Office Village, 286a Chase Road, London, N14 6HF. ICO Registration Number: Z8625473.
Our role (Controller and Processor)
- We act as a Data Controller for personal data relating to our own clients, suppliers, employees and candidates who apply to Cataphract. We act as a Data Processor on behalf of Clients when we conduct pre‑employment screening and vetting of their candidates. In both roles, we maintain Records of Processing Activities (RoPA) and implement appropriate safeguards.
What personal data we collect
- We collect only what we need for screening, onboarding and service delivery. Depending on the service, this may include:
- Identity and contact information (name, previous names, addresses for the last 5 years, email, phone).
- Date of birth, nationality and gender (where required for checks).
- Employment and education history, references, professional memberships.
- National Insurance number (where required for checks).
- Identity verification records and images of identity documents (e.g., passport or driving licence details) and results from identity service providers.
- DBS application metadata (e.g., Disclosure reference number and issue date). We do not retain the contents of police‑held information or full certificates beyond permitted timelines.
- System and security logs required for audit and security monitoring (aligned to ISO/IEC 27001 controls).
- Special category data: We do not routinely collect special category data (e.g., health, race, religion, trade union membership) as part of standard screening, unless strictly necessary for a specific statutory or safeguarding purpose and clearly explained in advance. Criminal offence data: Where criminal record checks are required (e.g., via DBS), we process criminal offence data in accordance with Article 10 UK GDPR and Schedule 1 DPA 2018 using an appropriate policy document and safeguards. We do not keep a comprehensive register of criminal convictions.
Lawful bases for processing
- We rely on one or more of the following lawful bases under Article 6 UK GDPR, as appropriate to the context:
- Contract: to deliver our services to Clients and Applicants (e.g., administering and conducting vetting).
- Legal obligation: where we are required to process data to meet legal or regulatory obligations (e.g., safeguarding requirements, responding to statutory requests).
- Legitimate interests: to operate and improve our services, ensure network and information security, prevent fraud, and manage supplier performance. Where we rely on legitimate interests, we balance our interests against your rights and expectations. Some activities may constitute “recognised legitimate interests” under the DUAA once commenced.
- Consent: for direct marketing communications and where required for specific non‑essential cookies or optional features. You can withdraw consent at any time.
- Criminal offence data: Where we process criminal offence data (e.g., DBS outcomes), we identify and document a relevant Schedule 1 DPA 2018 condition (for example, employment, social security and social protection), maintain an Appropriate Policy Document, and apply enhanced safeguards, including restricted access and shortened retention.
Use of Personal Data and Third-Party Information Sharing
- We use your personal data to deliver the screening and vetting services requested by you or your organisation, to manage our relationships with clients and applicants, and to comply with our legal and regulatory obligations.
- To carry out vetting and screening checks, we may share your personal data with, and obtain personal data about you from, relevant third parties. We only do this where it is necessary, proportionate, and lawful.
- Depending on the nature of the role, regulatory requirements, and geographic scope, these third parties may include (but are not limited to):
- Government departments and public authorities responsible for safeguarding and regulatory oversight.
- Law enforcement bodies and criminal record agencies.
- Disclosure bodies and vetting authorities.
- Current and former employers.
- Educational institutions and awarding bodies.
- Credit reference and financial background checking agencies.
- Identity verification and authentication service providers.
- Professional and personal referees.
- International screening partners where overseas checks are required.
- Service providers supporting the screening process, including secure digital platforms, electronic signature providers, and customer feedback tools (limited to necessary contact data only).
- All third parties are engaged under appropriate contractual arrangements and process personal data only on our documented instructions. They are subject to confidentiality obligations and are required to implement appropriate technical and organisational security measures.
- We conduct due diligence and ongoing monitoring of our third-party providers to ensure they meet our data protection, information security, and quality standards, including those aligned to ISO/IEC 27001 and ISO 9001. Further details of specific third-party organisations can be made available on request
Data security (ISO/IEC 27001:2022)
- We implement layered security controls proportionate to risk, including encryption in transit and at rest, multi‑factor authentication for administrative access, role‑based access controls, asset and information classification, secure development and change control, vulnerability management and testing, event logging and monitoring, and incident response processes. Access to screening data is strictly limited and auditable. Our secure portals use TLS (SSL) to protect data in transit.
Pre‑employment screening and vetting (BS 7858:2019)
- We perform screening to BS 7858:2019 where applicable. Information on identity, employment history and referees is retained only for as long as necessary to determine suitability and to evidence the screening outcome, then securely deleted in line with our retention schedule.
Retention of personal data
- We operate documented retention schedules. In summary:
- DBS certificate information: normally retained no longer than 6 months to allow for resolution of queries or disputes; thereafter, only minimal metadata (reference number and date) is retained.
- Vetting file data: retained for a minimum of 6 months from application, and longer where required to evidence security clearance cycles or to meet legal obligations
- Security clearance management records: typically retained for 1 year after the end of employment for footprint/audit purposes, then securely deleted.
- System security logs: retained for security monitoring and audit for a defined period (typically 12–24 months) depending on risk and legal requirements.
- Where disputes, legal requirements or safeguarding obligations require longer retention, we document the justification and apply additional safeguards. When data is no longer needed, it is securely erased or destroyed.
Storage and locations
- Personal data is stored in secure systems with restricted access. We use UK or EEA data centres where feasible. Where international transfers are necessary, we apply the safeguards set out below.
International data transfers
- If we transfer personal data outside the UK (or receive access from outside the UK), we assess whether the transfer is restricted and, if so, apply appropriate safeguards. Depending on the destination and context, we use UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to EU Standard Contractual Clauses (SCCs), supported by transfer risk assessments and additional technical and organisational measures as needed.
Your privacy rights
- You have rights under the UK GDPR, subject to limitations, including: to be informed; to access; to rectification; to erasure; to restrict processing; to object; to data portability; and to withdraw consent where we rely on consent. You also have rights concerning automated decision‑ We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
Accessing your personal data (Subject Access Requests)
- You can request a copy of your personal data (a “subject access request”) free of charge in most cases. We will respond without undue delay and within one month of receipt. Where requests are complex or numerous, we may extend by up to two further months and will inform you within the first month. We may request identity verification before responding.
Right to erasure
- In certain circumstances, you can request deletion of your personal data, for example where the data is no longer necessary for the purposes for which it was collected, you withdraw consent (where consent is the lawful basis), you successfully object to processing, we have processed the data unlawfully, or we must erase it to comply with law. We will assess requests case‑by‑case and inform you of the outcome and reasons if we cannot fully comply (e.g., due to legal obligations).
Cookies and similar technologies
- Our website uses necessary cookies to function. Non‑essential cookies (e.g., analytics) are used only with your consent. Where we use analytics, we do so to understand and improve site performance; analytics cookies are not set until you opt in. You can withdraw consent at any time via cookie controls. We do not use marketing cookies to build advertising profiles unless expressly stated and consented to.
Links to other websites
- Our website may include links to third‑party sites. We are not responsible for their privacy notices or practices. We encourage you to read the privacy information on any site you visit.
Changes to this policy
- We may update this Policy to reflect legal, technical or business changes. Material changes will be communicated on our website and, where appropriate, directly to Clients and Applicants.
Contact and complaints
Data Protection Officer: Barry Clark
Postal address: Data Protection Officer, PO Box 70507, London, N20 2DB
Telephone: 020 8446 4695 | Email: notifications@cataphract.co.uk
- You have the right to lodge a complaint with the Information Commissioner’s Office (ICO). We would always welcome the opportunity to address your concerns first.
Service Contacts
DBS and Security Vetting Enquiries: dbs@cataphract.co.uk | 0208 446 4695
Office: Unit 7, Lower Floor, Station Approach, Wendover, Bucks, HP22 6BN
Company Number: 04650409