Skip to content
PropertyMomentum
Legal

Data protection policy.

How Property Momentum Limited collects, uses, shares and protects personal data. Version 1.0, effective 25 June 2026.

Document control

Company
Property Momentum Limited, registered office 128 City Road, London EC1V 2NX, company number 15294936
Policy owner
The Board
Data Protection Lead
Chirag Sachdev, dpo@propertymomentum.uk
ICO registration
ZB854904 (Tier 1), expires 19 January 2027
Version
1.0
Effective date
25 June 2026
Next review
25 June 2027
Approved by
Chirag Sachdev, Director

1. Purpose and scope

1.1

This policy sets out how Property Momentum Limited (the Company) collects, uses, shares and protects personal data, and what you must do when you handle personal data in the course of the Company's work.

1.2

This policy applies to all directors, employees and workers of the Company (staff), and to all subcontractors, suppliers and any other third party who handles personal data on the Company's behalf. Where this policy says "you", it means anyone within this scope. Compliance is a condition of your employment or engagement. Failure to comply may lead to disciplinary action or termination of a contract, and can expose the Company and individuals to regulatory action by the Information Commissioner's Office (ICO) and to legal claims.

1.3

The policy covers all personal data processed by the Company in any format, digital or paper, across both parts of the business: residential property acquisition, sourcing, due diligence and conveyancing management for institutional and public sector clients; and property refurbishment and maintenance delivered through direct labour and subcontractors.

1.4

The Company acts in two distinct capacities, and this policy addresses both. It is a controller for personal data relating to its own staff, job applicants, subcontractors, suppliers and business contacts. It is a processor when it handles personal data on behalf of client organisations, for example information about occupants of properties where the Company carries out works, or transaction data processed under a client's instructions. Section 5 covers the controller role and section 6 covers the processor role.

1.5

The legal framework for this policy is the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR), each as amended by the Data (Use and Access) Act 2025 (DUAA 2025). This policy reflects the law in force at the effective date, including the DUAA 2025 data protection provisions commenced on 5 February 2026 and the duty to facilitate complaints in section 164A of the DPA 2018, commenced on 19 June 2026.

1.6

The Company is registered with the ICO as a data protection fee payer under registration ZB854904 (Tier 1), which expires on 19 January 2027. The Data Protection Lead is responsible for keeping the registration in force.

2. Definitions

2.1

Personal data means any information relating to a living individual who can be identified from that information, directly or indirectly, alone or in combination with other information. It includes names, contact details, identity documents, payroll and bank details, records of dealings with an individual, and photographs or video in which a person can be recognised.

2.2

Special category data means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data used to identify a person; and data concerning health, sex life or sexual orientation.

2.3

Criminal offence data means personal data relating to criminal convictions and offences, including allegations, proceedings and related security measures. This includes information obtained through Disclosure and Barring Service (DBS) checks.

2.4

Controller means the organisation that decides why and how personal data is processed.

2.5

Processor means an organisation that processes personal data on behalf of a controller and on its instructions.

2.6

Sub-processor means a further processor engaged by a processor to carry out some or all of the processing on the controller's behalf.

2.7

Processing means anything done with personal data, including collecting, recording, storing, viewing, using, sharing, amending, erasing and destroying it.

2.8

Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. A breach does not require deliberate wrongdoing: a lost site folder, a misdirected email or a stolen phone can all be breaches.

3. Data protection principles

3.1

The Company applies the seven principles in Article 5 of the UK GDPR to all processing, whether acting as controller or processor:

  1. Lawfulness, fairness and transparency. Personal data is processed lawfully, fairly and in a way people would reasonably expect, with clear privacy information provided.
  2. Purpose limitation. Personal data is collected for specified, explicit and legitimate purposes and not used for incompatible purposes.
  3. Data minimisation. Only the personal data that is adequate, relevant and necessary for the purpose is collected and used. Section 10 applies this to site work.
  4. Accuracy. Personal data is kept accurate and up to date, and inaccurate data is corrected or erased without delay.
  5. Storage limitation. Personal data is kept no longer than necessary. Section 11 sets out retention periods.
  6. Integrity and confidentiality. Personal data is protected by appropriate security measures against unauthorised or unlawful processing, loss, damage or destruction. Section 12 sets out those measures.
  7. Accountability. The Company is responsible for compliance and must be able to demonstrate it, through the records, assessments, training and governance described in section 16.

4. Roles and responsibilities

4.1

The Board owns this policy. It approves the policy and material changes to it, ensures adequate resources for data protection compliance, receives reports from the Data Protection Lead at least annually and after any significant incident, and carries ultimate accountability for compliance.

4.2

The Data Protection Lead is Chirag Sachdev (dpo@propertymomentum.uk). The Data Protection Lead has day-to-day responsibility for data protection across the Company, including: advising the business; maintaining the records of processing, the retention schedule, the breach register, the complaints log and the list of sub-processors; handling individuals' rights requests and complaints; managing personal data breaches; liaising with the ICO and keeping the fee registration in force; overseeing training; and monitoring compliance with this policy. The Data Protection Lead is a designated internal role. It is not a Data Protection Officer appointed under Article 37 of the UK GDPR, and nothing in this policy or in the Company's dealings should be read as implying a statutory appointment. The Company keeps under review whether a statutory appointment becomes required.

4.3

Line managers and project managers must make sure the people they direct, including subcontractor operatives, understand and follow the rules in this policy that apply to their work; that no one is given access to personal data before completing induction training and agreeing confidentiality terms; and that requests, complaints, incidents and risks are passed to the Data Protection Lead the same working day.

4.4

All staff must follow this policy; access only the personal data needed for their role; complete data protection training when required; keep passwords and devices secure; use only Company-approved systems for storing and sharing personal data, never personal email or personal messaging accounts; report any suspected personal data breach immediately (section 14); and pass any rights request or complaint to the Data Protection Lead without delay (sections 8 and 9).

4.5

Subcontractors and suppliers who handle personal data on the Company's behalf must comply with this policy and with the data protection terms in their contract; use the data only to deliver the contracted works or services; make sure their operatives are briefed on the site rules in section 10; report any incident, request or complaint to their Company contact immediately; and return or securely delete the data at the end of the engagement.

5. The Company as controller: lawful bases

5.1

The Company is the controller for personal data about its staff, job applicants, subcontractor and supplier personnel, and business contacts such as client personnel, vendors, sellers, estate agents and council officers, and for any other personal data it collects for its own purposes.

5.2

Before processing begins, a lawful basis under Article 6 of the UK GDPR is identified and recorded in the record of processing. The Company relies on the following bases.

  1. Consent. The individual has given a clear, freely given, specific and informed indication of agreement. Consent is recorded and can be withdrawn at any time, as easily as it was given. Example: keeping an unsuccessful job applicant's CV on file for future vacancies with their agreement.
  2. Contract. Processing is necessary to perform a contract with the individual, or to take steps at their request before entering one. Example: processing a sole trader subcontractor's contact and bank details to administer the subcontract and pay for completed works.
  3. Legal obligation. Processing is necessary to comply with the law. The Company relies on this basis for payroll, tax and HMRC records, including Construction Industry Scheme records where applicable; right-to-work checks under the Immigration, Asylum and Nationality Act 2006; DBS checks where required for a role or project; health and safety records; and RIDDOR reporting of workplace accidents and dangerous occurrences. Example: keeping the accident book entry and RIDDOR report after an operative is injured on site.
  4. Legitimate interests. Processing is necessary for the Company's legitimate interests or those of a third party, and those interests are not overridden by the individual's rights and interests. A balancing assessment is carried out and recorded before this basis is relied on. Example: holding an estate agent's name, email address and phone number on the acquisitions pipeline to progress a property purchase.
  5. Vital interests. Processing is necessary to protect someone's life. Example: giving paramedics the known medical details of an operative who has collapsed on site.

5.3

Electronic direct marketing is sent only in accordance with PECR. Every marketing message identifies the Company and offers a simple way to opt out, and opt-outs are actioned promptly.

5.4

The Company provides clear privacy information to individuals at the point their data is collected, or as soon as reasonably possible afterwards. The Data Protection Lead maintains the Company's privacy notices.

6. The Company as processor: obligations to clients

6.1

The Company acts as a processor when it handles personal data on behalf of a client organisation, which is the controller of that data. Typical examples are occupant, resident or leaseholder information shared by a client so that the Company can plan and carry out refurbishment or maintenance works, and vendor or transaction information processed under a client's instructions within an acquisition or conveyancing management programme. In this role the client decides the purposes of processing and the Company acts only on the client's behalf.

6.2

Whenever the Company acts as a processor, it will:

  1. process the personal data only on the client's documented instructions, as set out in the contract, works orders or other written instructions, including in relation to any transfer of the data outside the UK, unless UK law requires otherwise, in which case the Company will inform the client of that legal requirement before processing unless the law prohibits this;
  2. inform the client immediately if, in the Company's opinion, an instruction infringes UK data protection law;
  3. ensure that everyone authorised to access the data, including staff and subcontractor operatives, is subject to a written obligation of confidentiality;
  4. apply the technical and organisational security measures in section 12, in line with Article 32 of the UK GDPR;
  5. not engage any sub-processor without the client's prior written authorisation, and, where authorised, put in place a written contract imposing on the sub-processor obligations equivalent to those in this section, with the Company remaining fully responsible to the client for the sub-processor's performance (section 15);
  6. taking into account the nature of the processing, assist the client with appropriate technical and organisational measures to respond to individuals' rights requests, and pass any request the Company receives directly to the client without undue delay (section 8.8);
  7. assist the client in meeting its obligations on security, personal data breach notification, data protection impact assessments and prior consultation with the ICO, taking into account the nature of the processing and the information available to the Company;
  8. at the end of the engagement, return the personal data to the client or securely delete it, as the client directs, unless UK law requires the Company to retain it, and provide written certification of deletion;
  9. make available to the client the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits and inspections conducted by the client or an auditor appointed by the client; and
  10. notify the client without undue delay after becoming aware of a personal data breach affecting the client's data (section 14.6).

6.3

Practical rules when you handle client data. Use it only for the specific job or instruction it was provided for. Never use it for the Company's own marketing or any other Company purpose. Do not copy it to personal devices or accounts. If an occupant or any other individual asks you about their data, makes a request or complains, do not respond on the client's behalf: acknowledge it and pass it to the Data Protection Lead the same working day so the Company can forward it to the client without undue delay.

6.4

The Data Protection Lead keeps a record of the categories of processing carried out for each client, as required by Article 30(2) of the UK GDPR.

7. Special category and criminal offence data

7.1

Special category data and criminal offence data carry higher risk and are subject to extra conditions and safeguards. You must not collect or record this data unless your role requires it and this section is satisfied.

7.2

As controller, the Company processes special category data mainly in relation to its own workforce: health information such as sickness absence records, fit notes, occupational health reports, first aid and accident records, and information needed to make reasonable adjustments. The Company processes criminal offence data where DBS checks or self-declarations are required for a role or project. As processor, the Company may receive occupant health or vulnerability information from a client where it is needed to plan and carry out works safely; that data is processed only on the client's instructions and under the minimisation rules in section 10.

7.3

The Company processes special category data only where a condition under Article 9 of the UK GDPR applies, together with the relevant condition in Schedule 1 to the DPA 2018 where required. The conditions relied on are:

  1. Article 9(2)(b), processing necessary for obligations and rights in employment, social security and social protection law, with the condition in Schedule 1, Part 1, paragraph 1 of the DPA 2018. This covers workforce health data, statutory pay, absence management and health and safety records.
  2. Article 9(2)(f), processing necessary for the establishment, exercise or defence of legal claims.
  3. Article 9(2)(c), processing necessary to protect vital interests where the individual is physically or legally incapable of giving consent, for example in a medical emergency.
  4. Article 9(2)(a), explicit consent, in limited cases where the individual has volunteered information and genuine choice exists.
  5. Article 9(2)(g), substantial public interest, with the relevant condition in Schedule 1, Part 2 of the DPA 2018, including paragraph 18 (safeguarding of children and of individuals at risk) where staff or operatives report a safeguarding concern encountered during works.

7.4

Criminal offence data is processed only in accordance with Article 10 of the UK GDPR and section 10 of the DPA 2018, relying principally on the employment condition in Schedule 1, Part 1, paragraph 1 for DBS checks and declarations. DBS results are seen only by the Data Protection Lead and those with a strict need to know, and are handled in line with the DBS code of practice.

7.5

Where Schedule 1, Part 4 of the DPA 2018 requires one, the Company maintains an Appropriate Policy Document explaining how the data protection principles are met and how long the data is retained. This is a separate document, the Property Momentum Appropriate Policy Document, available from the Data Protection Lead.

7.6

Special category and criminal offence data must never be included in works orders, site paperwork or messages to operatives beyond what section 10 permits, and access to it is restricted under section 12.

8. Individuals' rights

8.1

Individuals have the following rights over their personal data: to be informed about how it is used; to access it and receive a copy (a subject access request); to have inaccurate data rectified; to have data erased in certain circumstances; to restrict processing in certain circumstances; to data portability for certain data they provided; to object to processing based on legitimate interests, and an absolute right to object to direct marketing; and rights in relation to solely automated decision-making with legal or similarly significant effects.

8.2

A request can be made by any individual, in any form, to anyone in the business. There is no required wording. If you receive anything that looks like a rights request, pass it to the Data Protection Lead the same working day and do not attempt to answer it yourself.

8.3

Requests are free of charge. Where a request is manifestly unfounded or excessive, the Company may charge a reasonable fee or refuse to act, and will explain its reasons. When responding to a subject access request, the Company carries out reasonable and proportionate searches, as the UK GDPR as amended by DUAA 2025 provides.

8.4

Timescales. The Company responds without undue delay and at the latest within the applicable time period under Article 12A of the UK GDPR. That period is one month beginning with the relevant time, which is the latest of: the day the Company receives the request; the day the Company receives any information it has reasonably requested to confirm the requester's identity; and the day any fee properly charged is paid. For complex or numerous requests the period may be extended by up to two further months, in which case the individual is told within the first month, with reasons.

8.5

Stop the clock. Where the Company reasonably needs further information to be able to act on a request, for example clarification of the scope of a very broad subject access request, it will ask for that information promptly and tell the individual that the deadline is paused. Under Article 12A, the period between the day the Company asks for the information and the day it receives it does not count towards the applicable time period. If the information is not provided, the Company will respond to the extent it reasonably can.

8.6

Identity verification. The Company must be satisfied of the requester's identity before releasing personal data. Checks are proportionate: where the requester is known and uses established contact details, little or nothing more may be needed; where there is doubt, the Company requests only the minimum evidence necessary. Where a request is made on someone's behalf, evidence of their authority is required. Verification requests are made promptly and never used to delay a response.

8.7

If the Company refuses a request in whole or in part, it will tell the individual the reasons and inform them of their right to complain to the Company under section 9, their right to complain to the ICO, and their right to seek a judicial remedy through the courts, in line with Article 12(4) of the UK GDPR.

8.8

Where a request relates to personal data the Company processes for a client, the Company acknowledges it, forwards it to the client without undue delay, tells the requester this has been done, and assists the client with its response. The client, as controller, is responsible for responding.

9. Data protection complaints

9.1

Under section 164A of the DPA 2018, anyone has the right to complain to the Company if they consider that the Company has infringed the UK GDPR or the DPA 2018 in relation to their personal data. The Company facilitates such complaints and treats them seriously. Making a complaint is free, and no one will be disadvantaged for complaining.

9.2

A complaint can be made: by completing the Company's electronic complaints form at propertymomentum.uk/data-complaints; by email to dpo@propertymomentum.uk; or by post to the Data Protection Lead, Property Momentum Limited, 128 City Road, London EC1V 2NX.

9.3

The Company acknowledges receipt of a complaint within 30 days of receiving it.

9.4

The Company then, without undue delay, takes appropriate steps to respond, including making enquiries into the subject matter of the complaint, keeping the complainant informed about progress, and informing the complainant of the outcome.

9.5

Complaints are handled by the Data Protection Lead. A complaint about the Data Protection Lead is handled by a director.

9.6

Where a complaint concerns processing the Company carries out for a client as processor, the Company passes it to the client without undue delay, tells the complainant it has done so, and assists the client with its investigation.

9.7

The Data Protection Lead keeps a log of all complaints, responses and outcomes, and reports on complaint volumes and themes to the Board.

9.8

Complainants also have the right to complain to the ICO at any time, at ico.org.uk or by post to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow SK9 5AF. They do not have to complain to the Company first, although the Company welcomes the opportunity to resolve concerns directly.

10. Data minimisation and need-to-know access

10.1

Collect and record only the personal data needed for the task. Forms, systems and templates must not ask for information the Company does not need.

10.2

Access to personal data is granted on a need-to-know basis through the role-based access controls in section 12. Having access to a system does not entitle you to browse data you do not need for your work.

10.3

Site operatives receive only the information required to carry out the works. Works orders and job instructions may include the property address, access arrangements, appointment details, hazard and safe-working information, and specific practical requirements, for example that an occupant requires 24 hours' notice before entry, or that equipment in a particular room must not be disturbed or isolated. They must not include the underlying personal circumstances of occupants, such as medical conditions or diagnoses, care arrangements, financial or legal circumstances, immigration status, or the reasons a household is considered vulnerable. Anyone preparing a works order is responsible for applying this rule. If a client provides more information than the operative needs, the excess must not be copied into works orders, messages or site paperwork.

10.4

Photographs and video taken during surveys or works must be limited to what the job requires. Avoid capturing occupants, their documents and their personal possessions wherever practicable, and retake or crop images where they are captured unnecessarily. Site imagery must never be posted to personal social media or shared outside Company-approved systems.

10.5

Personal data must be shared only through Company-approved systems and accounts, never through personal email, personal cloud storage or personal messaging apps.

10.6

Where CCTV or site cameras are in use, signage and site sign-in documents make clear that cameras are in place and why. Footage is retained in line with section 11.

11. Retention

11.1

Personal data is kept for no longer than necessary for the purposes for which it is processed, and then securely destroyed or deleted in accordance with section 12. The table below sets out the Company's retention schedule, which the Data Protection Lead maintains. Records are kept beyond these periods only where a specific legal hold applies, for example live or reasonably anticipated litigation, and the Data Protection Lead approves.

11.2

Personal data held for a client as processor is retained in accordance with the client's contract and instructions, and is returned or securely deleted, with written certification, at the end of the engagement (section 6.2(h)).

Record typeRetention periodBasis
Recruitment records of unsuccessful applicants6 months from notifying the outcomeDefence of discrimination and other claims under the Equality Act 2010; kept longer for future vacancies only with the applicant's consent
Employee records after employment ends6 years from the end of employmentDefence of legal claims within limitation periods under the Limitation Act 1980; responding to references and statutory enquiries
Payroll, tax and National Insurance records, including CIS records6 years from the end of the relevant tax yearHMRC requirements: PAYE records must be kept for at least 3 years after the end of the tax year, and CIS records for at least 3 years
Health and safety and accident records6 years from the date of the record; 40 years for any COSHH health surveillance recordsRIDDOR 2013 requires records to be kept for at least 3 years; certain health surveillance records must be kept for 40 years under COSHH; longer retention may be justified to defend personal injury claims
DBS and criminal record check recordsCertificate information: no longer than 6 months from the recruitment decision; record of the check, its date and outcome level: duration of the engagementDBS code of practice: certificate information should not normally be retained once a recruitment decision is made, and in any event no longer than 6 months; a record that a check was completed, its date and outcome level may be kept where justified
Right-to-work recordsDuration of employment plus 2 yearsHome Office guidance: retain for the duration of employment plus 2 years to preserve the statutory excuse
Property transaction and conveyancing records12 years from completionLimitation Act 1980: 6 years for simple contracts and 12 years for deeds; where held for a client as processor, the client's contract and instructions apply
Vendor, seller and estate agent contact data2 years from the last meaningful contact, then reviewed and deletedLegitimate interests while the relationship or acquisition pipeline remains active, subject to periodic review
Subcontractor and supplier records6 years from the end of the engagementContract administration and defence of claims under the Limitation Act 1980; HMRC and CIS record requirements
Client contract records6 years from the end of the contract; 12 years where executed as a deedLimitation Act 1980: 6 years for simple contracts and 12 years for contracts executed as deeds
Data protection complaints records6 years from the complaint being closedDemonstrating compliance with section 164A of the DPA 2018 and defending claims within limitation periods
Site survey photography and video that may capture occupants or their possessions2 years from completion of the works, unless required for a live defect or claimKept only while needed for the works, quality assurance or the resolution of defects and claims, and minimised at capture under section 10.4
CCTV and site camera footage30 days, unless footage relates to a specific incident, in which case until the incident and any related claim are resolvedICO video surveillance guidance: short default retention unless footage is needed for a specific incident

12. Technical and organisational measures

12.1

The Company applies technical and organisational measures appropriate to the risk, in line with Article 32 of the UK GDPR. They apply to all processing, whether the Company acts as controller or processor, and the Data Protection Lead reviews them as part of the annual policy review and after any significant incident.

12.2

Role-based access control. Access to systems and records containing personal data is granted on a least-privilege basis, according to role, and only with the approval of the relevant line manager. Access rights are reviewed at least annually and whenever someone changes role.

12.3

Multi-factor authentication. Multi-factor authentication is enforced on every Microsoft 365 and Zoho Books account, and is required on any other Company system that supports it.

12.4

Encryption. Personal data must be encrypted in transit using TLS 1.2 or above and at rest using AES-256 or equivalent encryption. Company laptops and mobile devices must have device encryption enabled.

12.5

Hosting and data residency. The Nexus and PM-Ops platforms are hosted on servers located in the United Kingdom. Email, files and collaboration services run on Microsoft 365 in Microsoft's UK region. Accounting records are held in Zoho Books in Zoho's European Union data centres, a location covered by UK adequacy regulations. Subject to that, the Company's default position is that personal data is held in the United Kingdom (section 13), and any further exception requires the prior approval of the Data Protection Lead.

12.6

Personal and mobile devices, including subcontractor devices. Where staff or subcontractor operatives use personal or mobile devices to access Company systems, access is permitted only through approved applications or browser sessions. Personal data must not be stored locally on the device, including by downloading files or saving screenshots. Sessions time out after 15 minutes of inactivity. The Company can revoke a device's access remotely and will do so when an engagement ends or a device is lost, stolen or compromised. Devices used for access must be protected by a passcode or biometric lock and kept up to date with security updates. Lost or stolen devices must be reported immediately under section 14.

12.7

Audit logging. Access to systems holding personal data is logged. Logs are reviewed following any incident and periodically by the Data Protection Lead or a nominated administrator.

12.8

Backup and recovery. Backups of the Company's internally hosted systems, including the Nexus and PM-Ops platforms, are taken daily, encrypted, stored separately from live systems, and protected to the same standard as live data. Restoration is tested weekly.

12.9

Secure disposal. Paper records containing personal data are cross-cut shredded or placed in secure confidential waste for destruction, never in general waste or recycling. Digital records are deleted so that they cannot reasonably be recovered, and hardware is securely wiped or destroyed before disposal or reuse. Disposal of client data is certified in writing under section 6.2(h).

12.10

Joiners, movers and leavers. No one is given access to personal data before agreeing confidentiality terms and completing induction data protection training. Access rights are adjusted promptly when someone changes role, and removed no later than the last day of employment or engagement, including for subcontractor operatives leaving a project. Equipment, keys, passes and records are returned on or before the last day.

12.11

Training. Everyone within the scope of this policy completes data protection training on induction, before handling personal data, and refresher training at least annually. Site briefings and toolbox talks cover the site rules in section 10 for operatives. Training completion is recorded.

12.12

Confidentiality clauses. Employment contracts and subcontract and supplier terms include confidentiality and data protection obligations. No one handles personal data on the Company's behalf without such terms in place.

12.13

Physical security. Paper records containing personal data are kept in lockable storage and locked away when unattended. Works orders and other site documents containing personal data must be kept secure on site and in vehicles, never left on display, and returned for secure disposal when the job is complete. Visitors must not be left unattended in areas where personal data is accessible.

13. International transfers

13.1

The Company's default position is that personal data is held in the United Kingdom. The one standing exception is accounting data held in Zoho Books in the European Union, which is covered by UK adequacy regulations. Beyond that, personal data must not be transferred to, or accessed from, a country outside the UK without the prior approval of the Data Protection Lead.

13.2

Where a transfer outside the UK does occur, it takes place only if the destination is covered by UK adequacy regulations, or appropriate safeguards are in place: the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, in each case with a transfer risk assessment completed and approved before the transfer begins.

13.3

Where the Company acts as processor, no international transfer of a client's personal data is made without the client's documented instructions or prior authorisation, in addition to the safeguards above.

13.4

Working outside the UK while accessing Company systems counts as a transfer consideration. Obtain the Data Protection Lead's approval before doing so.

14. Personal data breaches

14.1

A personal data breach is defined in section 2.8. Examples include a lost or stolen phone, laptop or site folder; an email or works order sent to the wrong recipient; papers containing occupant details left at a property; ransomware or unauthorised access to a system; and accidental deletion of records without backup.

14.2

Report immediately. If you discover or suspect a breach, including one caused by your own mistake, report it to the Data Protection Lead by phone and email immediately, and in any event the same working day. Do not investigate on your own, do not delete evidence, and do not notify anyone outside the Company. Prompt, honest reporting will never be held against you; concealment will be treated as a serious matter.

14.3

The Data Protection Lead assesses each report, leads containment and recovery, and records every breach, whether or not it is notifiable, in the Company's breach register, including the facts, effects, remedial action taken and, where the ICO is not notified, the reasons why.

14.4

Where the Company is the controller and the breach is likely to result in a risk to individuals' rights and freedoms, the Data Protection Lead notifies the ICO without undue delay and, where feasible, within 72 hours of the Company becoming aware of the breach. If notification is made later than 72 hours, it is accompanied by the reasons for the delay.

14.5

Where the breach is likely to result in a high risk to individuals, the Company also informs the affected individuals without undue delay, in clear language, describing the likely consequences, the measures taken and the steps they can take to protect themselves.

14.6

Where the breach affects personal data the Company processes for a client, the Company notifies the client without undue delay after becoming aware of it, provides the information the client needs for its own notification decisions, and assists the client. In that situation the client, as controller, decides whether to notify the ICO and individuals, and the Company does not do so for the client's data unless the client instructs it.

14.7

After every breach, the Data Protection Lead reviews the causes and any changes needed to systems, training or this policy, and reports significant breaches to the Board.

15. Sub-processors and the supply chain

15.1

Due diligence before appointment. Before any subcontractor, supplier or service provider handles personal data on the Company's behalf, the Data Protection Lead assesses its data protection and security arrangements, proportionate to the risk and sensitivity of the data involved. No access is granted until the assessment is satisfactory and contract terms are in place.

15.2

Written terms. Every such appointment is documented in a written contract containing confidentiality obligations and, where the party processes personal data on the Company's behalf, terms meeting Article 28(3) of the UK GDPR.

15.3

Flow-down. Where the Company acts as processor for a client, it does not engage a sub-processor on that client's data without the client's prior written authorisation, and it flows down obligations equivalent to those it owes the client, in writing, remaining fully responsible to the client for the sub-processor's performance.

15.4

Register. The Data Protection Lead maintains a list of all sub-processors and of suppliers with access to personal data. The current entries are: Microsoft (Microsoft 365, for email, files and collaboration), Zoho (Zoho Books, for accounting and invoicing), the hosting provider for the Nexus and PM-Ops platforms, and the Company's external accountants. Where any of these handles a client's personal data, the authorisation and flow-down requirements in this section apply.

15.5

Access review and revocation. Supply chain access to systems and data is reviewed under section 12.2 and revoked promptly at the end of an engagement, at the end of a project, or where a concern arises. Sub-processors and suppliers must cooperate with the Company in the event of an incident, request or audit.

16. Accountability and governance

16.1

Records of processing. The Data Protection Lead maintains the Company's records of processing activities under Article 30 of the UK GDPR, covering both its controller activities (Article 30(1)) and its processor activities for each client (Article 30(2)), and keeps them up to date. The limited exemption in Article 30(5) for small organisations does not apply to the Company, because the Company processes special category data on a non-occasional basis.

16.2

Data protection impact assessments. Before starting any new or significantly changed processing likely to result in a high risk to individuals, a data protection impact assessment is carried out under Article 35 of the UK GDPR. Triggers include new technology, large-scale processing of special category data, systematic monitoring, and processing concerning vulnerable individuals, such as occupants of client properties. The Data Protection Lead advises on and reviews each assessment. Where a high residual risk cannot be mitigated, the ICO is consulted before processing begins.

16.3

Training. Training is delivered and recorded as set out in section 12.11.

16.4

Audit and monitoring. The Data Protection Lead carries out periodic compliance checks, including spot checks on site document handling, works order content, access rights and retention, and reports findings to the Board. The Data Protection Lead reports to the Board at least annually on breaches, complaints, rights requests, training completion, supply chain assurance and the status of the ICO registration.

16.5

ICO registration. The Data Protection Lead renews the Company's ICO registration ZB854904 before its expiry on 19 January 2027 and on each renewal date thereafter.

17. Review and version control

17.1

The Board owns this policy. The Data Protection Lead reviews it at least every 12 months from the effective date, and sooner where there is a relevant change in the law or in ICO guidance, a significant incident, or a material change in the Company's activities. The Board approves all changes.

17.2

Version history:

VersionEffective dateApproved bySummary
1.025 June 2026The BoardInitial policy, drafted to reflect the Data (Use and Access) Act 2025, including the complaints procedure under section 164A of the DPA 2018 and request timescales under Article 12A of the UK GDPR

17.3

Approval. Signed for and on behalf of the Board of Property Momentum Limited:

Chirag Sachdev

Chirag Sachdev, Director

Signed for and on behalf of the Board of Property Momentum Limited

Date: 25 June 2026