Privacy, data protection and copyright
Revised 15/8/2025
This page describes:
- The purpose of this website
- The use of cookies and analytics on this website
- Other data collection through this website
- TRL’s policy on newsletters and marketing emails
- The wider policy of TRL Insight on data collection, processing and retention
- The sources of images used on this website and copyright queries.
Purpose of this website
This website exists to offer my professional advisory, support and consultancy services, and to provide public access to the outputs produced by TRL Insight.
Cookies and analytics on this website
Cookies
This website uses files known as cookies. A cookie is a small text file of letters and numbers that gets put onto your computer when you visit a website. This allows the site to distinguish you from other users. A cookie isn’t a computer program, can’t read files on your computer, can’t carry viruses and can’t install malware onto your computer. Most web browsers allow some control of most cookies through the browser settings.
To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.
Analytics
I care about your privacy and handling your data with sensitivity and respect. I try to ensure that I keep data collection and analysis to a minimum.
This site uses Google Analytics. This tool collects a variety of information about visitors to the site, as described below. It uses cookies (see above), as described here. The way in which it collects data is described here. To opt out of being tracked by Google Analytics across all websites, visit http://tools.google.com/dlpage/gaoptout. Other methods of opting out may be available for your particular browser. This data is analysed by the Google Analytics tool and the results are viewable to me in the form of series of dashboards. The data I collect with Google Analytics is NOT shared with Google. Specifically, the tool contains toggles for setting the circumstances under which data is shared with Google and I have opted to switch all of these to OFF:
- I do not share Google Analytics data with Google to help improve Google’s products and services;
- I do not contribute aggregated measurement data to enable enhanced features like predictions, modelled data, and benchmarking;
- I do not let Google technical support representatives access my Google Analytics data;
- I do not give Google sales access to my Google Analytics data and account for purposes such as improving my configuration and analysis, and providing me with insights, optimization tips and recommendations;
- I do not give all Google sales experts access to your data and account, to provide more in depth analysis, insights, and recommendations.
I do not share any data collected by Google Analytics with any third parties. Data collected that I am able to view (but do not necessarily view – see below) includes:
- Number of visits to each page;
- Estimated visits which are from new users and from returning users;
- Duration each page is viewed;
- Landing and exit pages;
- Visitors who have clicked through to the site from social media;
- Time of day;
- Country (I am also informed of the number of visitors from particular cities when traffic is particularly high from that city);
- Type of device (desktop/tablet/mobile);
- Browser;
- Operating system;
- Service provider;
- Screen resolution for mobiles.
I view this data very irregularly, to:
- Gauge the impact of particular actions by me or others in publicising this website and my outputs;
- Get a sense of how much interest there is in particular outputs, and how this varies over time;
- See whether interest in my work is stronger in particular parts of the country, and how this varies over time;
and for similar purposes. Some correlations between the above data sets are provided automatically by Google Analytics, but I do not view detailed information about individual visits. Furthermore, where detailed analysis is provided for a group of visitors with particular characteristics, I have a policy of not viewing this. For example, I may view the number of visitors from each geographical location, but I do not view the average number of pages per session or duration of visits from a particular city or network provider. Similarly, I have a policy of not viewing data relating to visitors’ devices (browser, operating system and screen resolution), apart from in exceptional circumstances for the purpose of diagnosing faults with the site. Google Analytics collects your IP address but I do not view this directly – I only see a summary of the estimated locations of visitors, as set out above. You can mask your IP address by using a Virtual Private Network (VPN). I do not carry out any analysis of user demographics or users’ interests. Data collected and processed by Google Analytics is automatically deleted 26 months after your last visit to the site (or sooner). It is kept securely and confidentially: details about how this data is safeguarded can be found here.
Other data collection through this website
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.) from other websites.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content.
Data sent using the Contact page
Any data or message sent through the Contact page will be checked through at least one automated spam detection service. It is then forwarded to me as an email. See below for more on data I receive in the form of emails. In future, subscriptions to TRL Insight’s newsletter may be shared automatically with an email delivery service (EDS). In this case, this privacy policy will be updated accordingly. See below for more on this.
Other
I do not receive any other information about visitors to this website from any other sites or providers.
Newsletter and marketing emails
Receiving newsletters and marketing emails requires a specific opt-in, and will contain a method of opting out from receiving them in future. If you wish me not to use your name or contact details for any other purpose, please contact me and I shall ensure your choices are respected.
In future, newsletters may be provided through an email delivery service (EDS). This means that if you opt in to receiving newsletters, your name, email address, and any other personal information which is collected in relation to providing you with the newsletter will be shared with the EDS provider. Data will be shared under the terms of the privacy policy and/or data processing agreement of TRL Insight and/or the EDS provider. As and when TRL Insight forms such an agreement with an EDS provider, this privacy policy will be updated to provide links to relevant policies and documents. Sharing such data may be automated. It may include transfers of data to the providers’ sub-processors and transfers outside the UK.
Such data sharing and processing will be in accordance with TRL Insight’s policy on collecting, processing and retaining personal, as set out below.
TRL Insight policy on collecting, processing and retaining personal and sensitive data
TRL Insight is a sole trader business. You can contact TRL Insight in various ways, as set out on the Contact page.
The General Data Protection Regulation (GDPR) gives you rights over the processing of your personal data, where it:
- is carried out wholly or partly by automated means; or
- forms part of a filing system or is intended to form part of a filing system.
This does not apply to most data held by TRL Insight:
- other than data collected through this website (see above) and newsletters (see below), all data collection and processing is done manually by TRL Insight;
- as explained below, most personal data that is received by TRL Insight is never incorporated into a filing system (and there is no intention to do so), and indeed much of it is not further processed at all.
This policy describes all data held by TRL Insight to which the GDPR applies, but also much of the data to which the GDPR does not apply. This description is provided to provide you with clarity about TRL Insight’s operation and the sources from which TRL Insight obtains data.
For some projects carried out by TRL Insight for clients, the contract with the client specifies that the client is the data controller and TRL Insight is the data processor, under the terms of the General Data Protection Regulation (GDPR). For any other data processing carried out by TRL Insight, TRL Insight is both data controller and data processor. If TRL Insight is contacting you with regard to a particular project, this contact will specify whether TRL Insight is data controller for this particular project.
TRL Insight collects or receives personal data from you in the following ways:
- From visits to this website – see above for a description of how data is collected;
- In emails addressed to TRL Insight (including through the contact form described above) and their attachments;
- Through messages sent to me through online platforms such as Twitter and LinkedIn;
- In paper documents you have supplied, such as business cards, flyers and brochures;
- From public web pages, including organisation websites and LinkedIn profiles;
- Through telephone calls, face-to-face conversations, presentations, training sessions, webcasts etc;
- From text messages and mobile and landline call records;
- In digital documents downloaded from the World Wide Web (including from servers for which registration to a particular service is required).
TRL Insight does not use software such as scrapers or crawlers for collecting information. TRL Insight does not contract data collection or processing to any third parties, though an EDS may be used in future for processing data in relation to distributing email newsletters.
The sections below explain:
- How TRL Insight stores this data;
- A general description of personal data received by TRL Insight;
- Details on the processing of this data: the lawful basis for processing it, who it is shared with and how long it is held. This information is grouped in themes relating to the work of TRL Insight;
- Sensitive data: its processing, storage and retention;
- Your rights over personal data relating to you.
Storage of documents and emails
Emails sent to TRL Insight, including through the web contact form, are held on a secure mail server. This is operated by GoDaddy, so any emails sent to TRL Insight will be processed by their server. They are accessed solely through password-protected ITC devices. Some emails and most attachments are saved locally as stand-alone files on these devices. Very occasionally, some may be printed.
All files relating to TRL Insight are encrypted and held on password-protected devices, and appropriate security software is used. Except where this data is shared as described below, the only copies made of this data are for backup purposes. Such backups are encrypted and held securely.
Notes and other paper documents are held securely at a single location.
General description of personal data received by TRL Insight
In many documents received by TRL Insight (both digital and paper), personal data is a key part of what is being provided, including:
- Business cards;
- Emails sent to me by people wishing to make contact with me;
- Documents containing the email addresses or phone numbers of people I wish to contact for case studies or other advice.
Certain classes of personal data require additional protection under GDPR. This is often known as “sensitive data”. Almost all of the sensitive data held by TRL Insight is either:
- Political affiliation. This almost exclusively relates to elected representatives of political parties, such as councillors. TRL Insight does not collect this information about anyone else unless it is provided by that individual to TRL Insight – this may occasionally happen when a communication from that individual mentions another post they hold within a political party.
- Other political opinion, where this has been shared in an email or attachment sent to TRL Insight, in a presentation, conversation or phone call or in a document acquired from the World Wide Web or in paper form. Given the political nature of the work of TRL Insight, this is sometimes required for the completion of work that TRL Insight is contracted to undertake.
Other (“non-sensitive”) personal data held by TRL Insight essentially consists of:
- Names;
- Job titles/descriptions and organisations;
- Contact details: phone numbers, email addresses, web addresses, postal addresses, Twitter handles/social media links;
- Biographical data – where either i) it has been provided to me to complete a task we are jointly involved in, such as submitting a bid for a contract, or ii) it forms part of the papers for a publicly-available report or an event such as a conference;
- Gender – only where it happens to be mentioned in an email or document, for example referring to “he” or “she”;
- Photographic images received in notifications from platforms such as LinkedIn and Airbnb;
- Bank details – for situations where I need to make a payment or series of payments;
- Signatures – where either i) provided in a financial transaction with me or ii) in a publicly-available document such as open letters from ministers or MPs.
Often, personal information will be incidentally contained in a document sent to TRL Insight and not further processed (beyond saving of the document as a whole). This can include non-sensitive data (such as names and email addresses in a briefing) and data which could be viewed as sensitive (such as special access/dietary requirements for a training session).
Processing, retention and sharing of personal data, including lawful basis
Personal data of clients, subcontractors and collaborators on projects
I carry out work both under general associate agreements and contracts for specific outputs. Some projects involve collaborating with other providers; this can be with another associate, or it can be under a contract in which I am lead contractor or another provider is the lead contractor.
There is a high level of information exchange between TRL Insight, those with whom I collaborate, and clients. Most of the processing carried out by TRL Insight for these purposes does not involve any form of filing system, so is not covered by the GDPR. (This includes processing invoices and contracts, and processing data for project planning, project execution, financial record keeping and business administration.)
In addition to the above, the names and contact details of clients and collaborators may be used for the following:
- Connecting with them on social media;
- Providing contact details for third parties, if requested by the data subject and/or the third party, if I honestly believe it is in the interests of both parties to be put into contact (names and contact details will only be given to individuals, not supplied through any automated procedure);
- Informing them of the activities of TRL Insight and briefing them on developments they may wish to know about, through emails and newsletters.
Receiving newsletters and marketing emails require a specific opt-in. Any such emails contain a method of opting out from receiving them in future. If any client, collaborator or subcontractor wishes me not to use their names or contact details for any other purpose listed above, please contact me and I shall ensure your choices are respected.
Lawful grounds for processing under Article 6 of the GPDR:
- For any processing that is necessary for the fulfilment of project undertaken under an associate agreement or under a contract, the lawful ground is performance of a contract.
- Where records of payments made and received need to be retained for tax purposes, the lawful ground is compliance with a legal obligation.
- For distributing newsletters and marketing emails, the lawful ground is consent.
- For all other processing, the lawful ground is legitimate interest. These legitimate interests are:
- Project planning and execution;
- Keeping records for future reference/follow-up;
- Attendance at events associated with contract/agreement;
- Business planning & record-keeping;
- Connecting on social media;
- Providing to third parties (only as set out above).
In general, political opinions will not be processed beyond what is needed for the execution of a project and will not be incorporated into any filing system or database. See the section below on sensitive data for more on this.
Other than providing contact details to third parties on the grounds set out above, and with each other for the purpose of planning and executing the project, the personal data of clients, collaborators and subcontractors will not be shared with anyone without the express consent of all concerned.
If TRL Insight decides to provide newsletters through an EDS, and clients, collaborators and subcontractors opt in to receiving newsletters, their data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails.
All of this data will be retained for six years after the end of the relevant contract (or project, if there is no contract specifically for that project), in case of legal disputes or insurance claims. Where the personal data relates to a person who is outside the jurisdiction of English and Welsh law, the data may be retained longer than this, depending on the statute of limitations in the jurisdiction.
Personal data of third parties received/collected/processed in the course of executing projects
Paid projects undertaken by TRL Insight often involve TRL Insight receiving the personal data of individuals who are not party to the contract (that is, not from the client’s organisation or subcontractors). This may arise from interactions between TRL Insight and clients, subcontractors or other third parties. (For example, a recommendation to call a particular person to get an answer to a particular question, or an attendance list for training session I am running.) Alternatively, the data may be contained in reports, brochures and other documents.
This may (or may not) be used in contacting these individuals for specific queries, such as questions for a Government department on a policy or statistical matter. At the other extreme, it may involve close working over an extended period, such as with an interviewee, someone who has agreed to act as an unpaid adviser for the project, or guest speakers at events I am arranging.
In addition, TRL Insight sometimes undertakes unpaid projects, which may involve similar processing of personal data.
Besides the above purposes, the names and contact details of fellow associates may be used for the following:
- Connecting with them on social media;
- Providing contact details for third parties, if requested by the data subject and/or the third party, if I honestly believe it is in the interests of both parties to be put into contact (names and contact details will only be given to individuals, not supplied through any automated procedure);
- Informing them of the activities of TRL Insight and briefing them on developments they may wish to know about, through emails and newsletters.
Receiving newsletters and marketing emails will require a specific opt-in, and will contain a method of opting out from receiving them in future. If any fellow associate wishes me not to use their names or contact details for any other purpose listed above, please contact me and I shall ensure your choices are respected.
Lawful grounds for processing under Article 6 of the GPDR:
- For distributing newsletters and marketing emails to fellow associates with an organisation, the lawful ground is consent.
- For all other processing, the lawful ground is legitimate interest. These legitimate interests are:
- Project planning and execution;
- Keeping records for future reference/follow-up;
- Attendance at events associated with contract/agreement;
- Assisting colleagues;
- For fellow associates of an organisation:
- Connecting on social media;
- Marketing (only as set out above);
- Providing to third parties (only as set out above).
If TRL Insight decides to provide newsletters through an EDS, and fellow associates opt in to receiving newsletters, their data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails.
The personal data covered in this section will only be shared:
- With clients, subcontractors, collaborators and other third parties as necessary for the execution of the project; or
- For providing contact details of fellow associates to third parties on the grounds set out above.
Some clients, collaborators, subcontractors and third parties may be outside the UK. Data sharing with subcontractors will be subject to an agreement which requires a similar level of data protection to this privacy policy.
All of this data will be retained for six years after the end of the relevant contract (or project, if there is no contract specifically for that project), in case of legal disputes or insurance claims. Where the personal data relates to a person who is outside the jurisdiction of English and Welsh law, the data may be retained longer than this, depending on the statute of limitations in the jurisdiction. Also, data received in documents which are in the public domain may be retained longer than this.
Personal data received/collected/processed in the course of preparing project proposals
There is a high level of information exchange between TRL Insight and those with whom I collaborate on a project proposal. Personal data of these persons may be used in putting together a project proposal. This may involve an exchange of views and opinions – for political opinions, see the section below on sensitive data. Personal data of representatives of the potential client may also be used during the development of project bid or other proposal. Collaboration on a project proposal does not always lead to a contract.
In addition to the above, the names and contact details of collaborators on project bids may be used for the following:
- Connecting with them on social media;
- Providing contact details for third parties, if requested by the data subject and/or the third party, if I honestly believe it is in the interests of both parties to be put into contact (names and contact details will only be given to individuals, not supplied through any automated procedure);
- Informing them of the activities of TRL Insight and briefing them on developments they may wish to know about, through emails and newsletters.
Receiving newsletters and marketing emails will require a specific opt-in, and will contain a method of opting out from receiving them in future. If any collaborator wishes me not to use their names or contact details for any other purpose listed above, please contact me and I shall ensure your choices are respected.
Lawful grounds for processing under Article 6 of the GPDR:
- For the processing of a potential client’s data that is necessary to complete a bid at their request (including that of a lead bidder to whom I would be subcontracting if successful), the lawful ground is performance of a contract.
- For distributing newsletters and marketing emails, the lawful ground is consent.
- For all other processing, the lawful ground is legitimate interest. These legitimate interests are:
- Selecting and administering project bids and proposals;
- Business planning & record-keeping;
- Connecting with collaborators on social media;
- Providing to third parties (only as set out above).
Other than providing contact details to third parties on the grounds set out above, and with each other for the purpose of putting together and submitting a bid or other proposal, the personal data of collaborators and potential clients will not be shared with anyone without the express consent of all concerned.
If TRL Insight decides to provide newsletters through an EDS, and collaborators opt in to receiving newsletters, their data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails.
Some collaborators, potential clients and third parties may be outside the UK.
Personal data obtained in the course of preparing a project proposal under an associate agreement will be retained for six years after the end of the associateship.
For data obtained outside an associate agreement, the retention period will depend on the outcome of the project proposal. If the project proposal does not result in a bid, the data will be retained for two years after the last communication on the proposal. If it results in a bid, but this is unsuccessful, the data will be retained for two years after the date the bid closes. If it results in a bid which is successful, it will be retained for six years from the end of the project, in case of legal disputes or insurance claims. Where the personal data relates to a person who is outside the jurisdiction of English and Welsh law, the data may be retained longer than this, depending on the statute of limitations in the jurisdiction.
Discussion of potential future projects
From time to time I hold conversations by email, telephone or face-to-face with people about potential future projects. I keep records, solely for my own reference, of any communications which I believe may result in future work. These records may include personal data such as names, job titles, organisations and contact details. The communications through which I receive this data may also include political opinions if these have been expressed – see the section below on sensitive data.
The personal details of such individuals may be used for developing a project in line with our conversations. The names and contact details may also be used for the following:
- Connecting with them on social media;
- Providing contact details for third parties who have approached me, if I honestly believe it is in the interests of both parties to be put into contact (names and contact details will only be given to individuals, not supplied through any automated procedure);
- Informing them of the activities of TRL Insight and briefing them on developments they may wish to know about, through emails and newsletters.
Receiving newsletters and marketing emails will require a specific opt-in, and will contain a method of opting out from receiving them in future. If you have held a conversation with me about potential future work for TRL Insight and wish me not to use your name or contact details for any other purpose listed above, please contact me and I shall ensure your choices are respected
Lawful grounds for processing under Article 6 of the GPDR:
- For distributing newsletters and marketing emails, the lawful ground is consent.
- For all other processing, the lawful ground is legitimate interest. These legitimate interests are:
- Keeping records for future reference/follow-up;
- Business planning & record-keeping;
- Connecting on social media;
- Providing to third parties (only as set out above).
Other than providing contact details to third parties on the grounds set out above, and with each other for the purpose of putting together and submitting a bid or other proposal, the personal data of collaborators and potential clients will not be shared with anyone without the express consent of all concerned.
If TRL Insight decides to provide newsletters through an EDS, and collaborators opt in to receiving newsletters, their data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails.
Such records which list potential future work and contacts for such work will be regularly updated and will not contain any data more than four years old.
Personal data of providers of services and goods to TRL Insight
Such providers include telecommunications providers, web developers and organisations with which TRL Insight has or may in future have taken out membership or a subscription.
This data is never processed automatically or incorporated into a filing system for personal data. For reasons of brevity, TRL Insight’s policy regarding such data is not stated here – please get in touch if you want to know TRL Insight’s policy on such data.
Other personal data and its uses
The personal data of other individuals may be used/processed for purposes such as:
- Processing an endorsement, recommendation, reference or quote you have given or agreed to give me, (with your express consent);
- Setting up a phone call, video- or teleconference, or face-to-face meeting with you;
- Research purposes, queries, following up on a conversation, returning forms you have asked me to complete, or otherwise responding to you; (“research purposes” here means the kind of research TRL Insight undertakes, into policy, practice, finance and governance of the public sector and issues impacting on these);
- Connecting with you on social media or keeping in touch in other ways;
- Providing contact details for third parties, if requested by the data subject and/or the third party, if I honestly believe it is in the interests of both parties to be put into contact (names and contact details will only be given to individuals, not supplied through any automated procedure);
- Informing you of the activities of TRL Insight and briefing you on developments you may wish to know about, through emails, newsletters and social media.
Receiving newsletters and marketing emails will require a specific opt-in, and will contain a method of opting out from receiving them in future. If you have held a conversation with me about potential future work for TRL Insight and wish me not to use your name or contact details for any other purpose listed above, please contact me and I shall ensure your choices are respected.
Lawful grounds for processing under Article 6 of the GPDR:
- For processing an endorsement, recommendation, reference, quote or mention, and for distributing newsletters and marketing emails, the lawful ground is consent;
- For all other processing, the lawful ground is legitimate interest. These legitimate interests are:
- Processing personal references;
- Keeping records for future reference/follow-up;
- Business planning & record-keeping;
- Connecting on social media;
- Providing to third parties (only as set out above).
For an endorsement, recommendation or reference, or for quotes or mentions on marketing material, I will discuss with you who this will be shared with when I seek your consent for this. Quotes or mentions on this website will be publicly visible.
Other than providing contact details to third parties on the grounds set out above, and with each other for the purpose of putting together and submitting a bid or other proposal, the personal data of collaborators and potential clients will not be shared with anyone without the express consent of all concerned.
If TRL Insight decides to provide newsletters through an EDS, and you opt in to receiving newsletters, your data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails.
Some third parties may be outside the UK.
Where data is used for contacting you, for example for marketing purposes, it may be retained up to six years after last contact. Where it is held in relation to an associateship (e.g. a personal reference or in relation to a meeting held by the organisation), the data will not be retained for more than six years beyond the end of the associateship. (It may be deleted sooner if it is not needed.)
To determine the appropriate retention period for any other personal data, I consider the nature of this personal data, the potential risk of harm from unauthorised use or disclosure of the personal data, the purposes for which I received or collected this data, whether I can achieve those purposes through other means, and the applicable legal requirements. Such data:
- Is likely to be integral to documents which are being held for purposes other than the personal data they contain;
- Is unlikely to be held in a filing system of personal data;
- Is unlikely to be held for more than ten years after I obtained it, unless the document is in the public domain, or a longer period is necessary to comply with legal obligations.
Data sharing outside the UK
If TRL Insight decides to provide newsletters through an EDS, and individuals have opted in to receiving newsletters from TRL Insight, their data will be shared with the EDS provider, as set out in the section Newsletter and marketing emails. This may include transfers of data outside the UK.
The only other cases in which I transfer any data outside the UK are communications with colleagues with whom I work on projects who are based outside the UK. (For example, forwarding a client’s email to them as subcontractor, or forwarding an email containing a question I believe they may be able to answer.)
There may also be data transfers outside the UK in future if I am contacting someone outside the UK regarding an international comparison of public policy. In the rare cases that data is shared outside the UK, (other than with Sinch), the recipient will be requested to process it in accordance with this privacy policy.
Processing, retention and sharing of sensitive data, including lawful basis
Under Article 9 of the GDPR, certain “special categories” of data are regarded as particularly sensitive. Such data cannot be processed unless it is covered by one of ten exemptions.
One of these exemptions is data which is manifestly made public by the data subject. Most of the sensitive data received or collected by TRL Insight consists of political opinions which are manifestly made public by the data subject. These may be contained, for example, in published reports (including political forewords), briefings for which TRL Insight is included in a circulation list, or published evidence to a committee of Parliament or a local authority.
In some cases, you may inform TRL Insight of your political opinions on your own initiative, unsolicited by TRL Insight, for example by email or in a conversation in person or by telephone. If there is no indication that these opinions have been manifestly made public by you, then the lawful ground for processing this data will be consent. If I wish to carry out further processing of this data, I will seek your explicit consent for doing so, explaining how it will be used. You have the right to withdraw consent to future processing at any time, by the same method that you provided it (for example, by email or by telephone).
Where such sensitive data relates to a contract which TRL Insight currently has with a supplier, it will be retained for six years after the end of the relevant contract, in case of legal disputes or insurance claims. Where the sensitive data relates to a person who is outside the jurisdiction of English and Welsh law, the data may be retained longer than this, depending on the statute of limitations in the jurisdiction.
In other cases, TRL Insight may request information/views from you, which may be considered to include political opinions. This will be in relation to a specific project being undertaken by TRL Insight. (Key examples are the views and opinions of interviewees or unpaid advisers for the project.) In such cases, the lawful ground for processing this data is consent. I will inform you of the nature of the project and how your data may be processed and used. The political opinions you choose to provide will not be used for any other purposes. You have the right to withdraw consent to future processing at any time, by the same method that you provided it (for example, by email or by telephone).
Occasionally, TRL Insight may be contracted to fulfil a project for a particular client, with the client acting as data controller and TRL Insight acting as data processor, and the client may share the views of their stakeholders with TRL Insight. (For example, this may be the views of a governance body of the client or a sounding board they are using for the project.) In such cases, TRL Insight will process this data in accordance with this privacy policy and the contract with the client. Any sensitive data provided to TRL Insight in this way will not be used for any other purposes.
Other than political opinions, TRL Insight very rarely holds sensitive data. This would only occur when you have provided it to TRL Insight unsolicited, and it is incidental to the purpose for which the document or communication is held. (For example, mentioning your health or ethnicity in an email on another topic.) Such data will not be further processed. You have the right to withdraw consent to future processing at any time, by the same method that you provided it (for example, by email or by telephone).
Other than data which you have manifestly made public, TRL Insight will only share sensitive data with others (such as collaborators/subcontractors) if your explicit consent has been given for this. If this data sharing is with a subcontractor for the purpose of fulfilling a contract, it will be subject to an agreement which requires a similar level of data protection to this privacy policy. In the rare cases that data is shared outside the UK, the recipient will be requested to process it in accordance with this privacy policy.
Your rights
The GDPR gives you rights over the processing of your personal data, where it:
- is carried out wholly or partly by automated means
- forms part of a filing system or is intended to form part of a filing system.
Under Article 13 and Article 14 of the GDPR, you have the following rights:
- The right to request access to your personal data (including sensitive data) from the data controller (see Article 15);
- The right to know which sources (other than you) this data has been obtained from (see Article 15);
- The right to request from the data controller that errors in your data be rectified, and/or that your data be deleted (Article 16 and Article 17);
- The right to object to processing of your data (Article 21) and/or request from the data controller that the processing of your data be restricted (Article 18);
- The right to data portability (Article 20). Note that this only applies to data processed by automatic means – in the case of TRL Insight, this means data collected when you interact with this website (see “Cookies and analytics on this website” and “Other data collection through this website”);
- The right to complain to the regulator in the country in which you reside or where you believe any misuse of your data has taken place. The UK Information Commissioner’s Office can be contacted directly if you believe that TRL Insight has failed to address your concerns – see ico.org.uk.
If your data has been provided to TRL Insight with your consent, you also have the right to withdraw that consent at any time, without repercussions for you. This does not affect the lawfulness of processing based on consent before you withdrew it.
Image sources and copyright
Images used in the banner on this site are courtesy of Keattikorn and Pong at FreeDigitalPhotos.net and via Good Free Photos. All other items shown in this website have been created solely by me. For any queries regarding any copyright issues, please contact me at the following e-mail address: tom@trlinsight.co.uk