Need Support? Call us (9am - 5pm): UK  0121 663 6110  

Mission Diverse

Making Diversity Our Mission

Data Protection & Information Rights Policy

Version 1.2

Effective date: 18 August 2026

Mission Diverse CIC is committed to processing personal information lawfully, fairly, transparently and securely in accordance with applicable UK data protection legislation.

This policy explains how Mission Diverse may collect, use, retain, share, protect and otherwise process personal information, together with the approach we take to individual information rights.

It applies to individuals whose personal information we process, including clients, prospective clients, website visitors, training participants, employees, former employees, workers, consultants, contractors, suppliers, professional contacts, partners and other individuals who interact or have interacted with Mission Diverse.

This policy sets out Mission Diverse’s general approach. It does not create rights or obligations beyond those arising under applicable law.

Data protection legislation

Mission Diverse processes personal information in accordance with applicable legislation, including, where relevant:

  • the UK General Data Protection Regulation;
  • the Data Protection Act 2018;
  • the Data (Use and Access) Act 2025;
  • the Privacy and Electronic Communications Regulations 2003; and
  • other applicable legislation and common law principles.

References to legislation include amendments, replacements, re-enactments and corresponding provisions in force from time to time.

Where legislation and this policy are inconsistent, applicable legislation will prevail.

Personal data

Personal data is information relating to an identified or identifiable individual within the meaning of Article 4(1) UK GDPR.

Whether information constitutes personal data depends on its content, purpose and context.

A document, email, record or system does not become personal data in its entirety merely because an individual’s name or other identifier appears within it.

Business records may contain a combination of personal data relating to one or more individuals, confidential business information, client information, commercial information, intellectual property, operational information and information which is not personal data.

Mission Diverse will determine what information falls within the scope of applicable data protection rights in accordance with the legislation.

Information we may process

Depending on the nature of our relationship with an individual, we may process information including, but not limited to:

  • names and contact details;
  • employment and professional information;
  • qualifications, experience and professional credentials;
  • contractual information;
  • financial and payment information;
  • correspondence and communications;
  • training, attendance and participation information;
  • photographs, audio and video recordings;
  • information contained within meetings and recordings;
  • website and technical information;
  • account and system information;
  • project and service-delivery records;
  • information created during consultancy, employment or another professional engagement;
  • complaints, grievances, safeguarding or investigation information;
  • information required to protect legal or contractual interests; and
  • other information reasonably required for lawful organisational purposes.

We may process special category personal data or criminal offence information where necessary and where the applicable additional legal conditions are satisfied.

How we use personal information

Mission Diverse may process personal information for purposes including, but not limited to:

  • providing consultancy, training and other services;
  • managing enquiries, bookings and client relationships;
  • administering contracts and payments;
  • managing employment and professional relationships;
  • communicating with individuals and organisations;
  • maintaining appropriate business and governance records;
  • operating and improving our systems, website and services;
  • maintaining organisational knowledge and business continuity;
  • developing and delivering training and professional resources;
  • protecting confidential information and intellectual property;
  • protecting information and cyber security;
  • managing risk;
  • investigating complaints, concerns or suspected misconduct;
  • obtaining professional or legal advice;
  • establishing, exercising or defending legal rights;
  • complying with regulatory, legal and insurance requirements; and
  • other compatible and lawful organisational purposes.

Lawful bases

Mission Diverse will identify an appropriate lawful basis for processing personal data.

Depending on the circumstances, this may include:

  • performance of a contract;
  • compliance with a legal obligation;
  • legitimate interests;
  • consent;
  • protection of vital interests; or
  • another lawful basis recognised under applicable legislation.

Consent is not required for every processing activity.

Where processing is undertaken on another lawful basis, an individual’s refusal or withdrawal of consent does not necessarily require that processing to cease.

Legitimate interests

Under Article 6(1)(f) UK GDPR, Mission Diverse may process personal data where processing is necessary for legitimate interests pursued by Mission Diverse or another person, except where those interests are overridden by the individual’s interests or fundamental rights and freedoms.

Our legitimate interests may include, but are not limited to:

  • operating, managing and protecting Mission Diverse;
  • delivering and improving services;
  • maintaining organisational knowledge and business continuity;
  • protecting confidential information;
  • protecting intellectual property and business assets;
  • maintaining operational, governance, audit and historical records;
  • information and cyber security;
  • risk management;
  • managing employment and professional relationships;
  • investigating complaints, concerns or suspected misconduct;
  • protecting employees, clients and other individuals;
  • obtaining professional or legal advice;
  • preserving evidence;
  • establishing, exercising or defending legal rights;
  • maintaining information relating to actual or anticipated disputes;
  • meeting contractual, insurance and professional requirements; and
  • making appropriate continued use of materials, resources and intellectual property created or contributed to during employment, consultancy, contracting or another professional engagement.

This list is illustrative and not exhaustive.

Where legitimate interests is relied upon, Mission Diverse will apply the requirements of Article 6(1)(f) and other applicable data protection legislation.

Materials, resources and intellectual property

Materials created, commissioned or contributed to through Mission Diverse’s activities may form part of our intellectual property, organisational records or service-delivery resources.

These may include training materials, presentations, written resources, methodologies, templates, photographs, audio or video recordings, recorded training, digital resources, professional materials and other works or deliverables.

Where an appropriate lawful basis exists, Mission Diverse may retain and continue to use such materials for the purpose for which they were created or another lawful and compatible purpose.

The ending of an employment, consultancy, contracting or other professional relationship does not, by itself, require Mission Diverse to delete, destroy, withdraw or cease using materials lawfully created during that relationship.

Where such materials contain identifiable personal information, Mission Diverse will consider applicable data protection obligations separately from any contractual or intellectual property rights.

Data controllers and processors

The UK GDPR distinguishes between a data controller and a data processor.

A controller determines the purposes and means of processing personal data.

A processor processes personal data on behalf of, and ordinarily on the documented instructions of, a controller.

Mission Diverse may act as controller for some processing activities and processor for others. Our status will depend on the particular processing activity and circumstances.

Where Mission Diverse is the controller

Where Mission Diverse determines the purposes and means of processing, it will ordinarily act as data controller and will be responsible for considering applicable individual rights requests.

Mission Diverse will determine, in accordance with the law:

  • whether information constitutes the requester’s personal data;
  • the appropriate searches required;
  • whether clarification is necessary;
  • whether information should be disclosed, redacted or withheld;
  • whether the rights of other individuals are affected;
  • whether an exemption, restriction or qualification applies; and
  • the appropriate manner in which personal data should be supplied.

Acting as controller does not create an entitlement to unrestricted access to Mission Diverse’s documents, systems or business records.

Where Mission Diverse is the processor

Where Mission Diverse processes personal data solely on behalf of another organisation and under that organisation’s documented instructions, the relevant controller will ordinarily remain responsible for determining and responding to individual rights requests.

If Mission Diverse receives a request relating to information for which another organisation is controller, Mission Diverse may:

  • notify or forward the request to the controller;
  • provide reasonable assistance to the controller;
  • undertake searches or technical steps where instructed; and
  • act in accordance with the relevant data processing agreement and Article 28 UK GDPR.

Mission Diverse will not ordinarily make the substantive decision about whether another controller’s information should be disclosed, withheld, rectified, restricted or erased unless authorised or legally required to do so.

Individual rights and statutory limitations

Mission Diverse recognises the rights available under Articles 12 to 22 UK GDPR and the Data Protection Act 2018.

These rights are subject to the conditions, qualifications, restrictions and exemptions contained within applicable legislation.

Nothing in this policy creates a right of access, disclosure, deletion, objection, rectification or restriction beyond that required by law.

Mission Diverse may rely upon any applicable statutory exemption, restriction, qualification or other protection where its legal requirements are satisfied.

Subject access requests

Article 15 UK GDPR provides individuals with a right to confirmation of whether their personal data is being processed, access to that personal data and specified supplementary information.

It is a right to personal data.

It is not a general right to obtain or inspect all documents, emails, messages, records, systems or business information in which an individual may be mentioned.

A requester cannot expand the statutory right simply by identifying particular documents, systems, people, accounts or categories of records.

Requests for information including emails, messages, meeting records, board papers, drafts, reports, system logs, website records, project files, version histories, working documents or other organisational records will be considered to the extent that they contain personal data falling within Article 15.

The fact that an individual created a document, performed the work recorded in it, sent or received a communication, was copied into a communication, is named or referred to within it, participated in a meeting, used a particular system, worked on a project or considers information relevant to a dispute does not by itself make the entire document or record that individual’s personal data.

Where a wider document contains relevant personal data, Mission Diverse may provide the personal data through an extract, compilation, transcript, redacted copy or another appropriate form where this satisfies Article 15.

Reasonable and proportionate searches

Mission Diverse will undertake searches that are reasonable and proportionate in the circumstances.

In determining appropriate search activity, Mission Diverse may consider matters including, but not limited to:

  • the wording and scope of the request;
  • the nature and importance of the information;
  • the volume and age of potentially relevant records;
  • the systems reasonably likely to contain relevant personal data;
  • the accessibility of the information;
  • the likelihood that particular searches will identify relevant information;
  • information previously supplied;
  • whether equivalent information exists elsewhere; and
  • whether further searches would be reasonable and proportionate.

A subject access request does not automatically require searches of every account, device, communication platform, archive or storage location capable of containing information.

Where private devices or informal messaging systems have been used for Mission Diverse business, Mission Diverse will consider whether there is a reasonable basis for believing relevant personal data controlled by Mission Diverse is held there.

Clarification of requests

Where Mission Diverse processes a large amount of information relating to an individual, or where a request cannot reasonably be actioned without further information, Mission Diverse may ask the requester to clarify the information or processing activities concerned where permitted by law.

Where the statutory conditions are satisfied, the applicable response period may be paused while necessary clarification is awaited.

Seeking clarification does not mean that a requester can be compelled to narrow an otherwise valid request. Mission Diverse will undertake reasonable and proportionate searches as required by law.

Repeated, overlapping and successive requests

Mission Diverse will consider each request on its individual circumstances.

Where an individual submits repeated, overlapping or successive requests, Mission Diverse may consider whether all or part of a request is manifestly unfounded or excessive under Article 12 UK GDPR.

Relevant factors may include, but are not limited to:

  • whether substantially the same information was recently requested or supplied;
  • whether a reasonable interval has elapsed;
  • whether the information is likely to have materially changed;
  • whether a new request substantially overlaps another request;
  • whether information has already been provided by another appropriate means;
  • the nature and importance of the information;
  • the burden and administrative cost of responding;
  • the resources reasonably available to Mission Diverse; and
  • the wider context and pattern of requests.

Where permitted by law, Mission Diverse may refuse all or part of a manifestly unfounded or excessive request or charge a reasonable fee reflecting the administrative cost of responding.

A request will not be treated as manifestly unfounded or excessive merely because it is large, inconvenient, critical of Mission Diverse or connected with a dispute.

Information previously supplied

Where a subsequent request seeks personal data that has already been supplied, Mission Diverse may take this into account when considering the appropriate response.

Where no material change has occurred and a request substantially repeats a recent request, Mission Diverse may consider whether the request or relevant part of it is excessive under Article 12.

New or materially changed personal data will be considered separately.

Business information and ordinary working activity

Information does not become personal data in its entirety merely because an employee, consultant, contractor or other individual created it, received it, was copied into it or is named within it.

Ordinary business records may include information concerning clients, projects, operational instructions, training and consultancy work, proposals, commercial discussions, organisational decisions, financial matters, business strategy, intellectual property, internal processes, system administration and other individuals.

Where only part of a record constitutes the individual’s personal data, Mission Diverse will assess the individual’s statutory rights in relation to that personal data rather than treating the complete record as belonging to, or automatically accessible by, the individual.

Drafts, metadata, technical and system records

Draft documents, version histories, internal comments, annotations, metadata, system logs, access records, security logs and other technical information are not automatically subject to disclosure in their entirety.

Where information within such records constitutes the requester’s personal data, Mission Diverse will consider it in accordance with Article 15 and applicable exemptions or restrictions.

Mission Diverse is not required under Article 15 to disclose technical, operational or administrative information which does not constitute personal data relating to the requester.

Data protection rights are not a general right of disclosure

Data protection rights do not create a general right of discovery, disclosure or inspection of Mission Diverse’s records.

A subject access request does not provide a general mechanism for obtaining evidence for a dispute, investigating Mission Diverse’s internal decision-making, obtaining documents for actual or contemplated litigation, reviewing confidential management discussions, obtaining company records generally or accessing information belonging to Mission Diverse or another person.

The fact that information may be relevant to a grievance, complaint, negotiation, employment dispute or legal proceeding does not itself bring the whole document within Article 15.

Mission Diverse will provide personal data that falls within the statutory right, subject to applicable exemptions, restrictions and third-party rights.

Exemptions, withholding and redaction

Article 15 and other data protection rights are subject to exemptions and restrictions, including those contained within the Data Protection Act 2018.

Where permitted by law, Mission Diverse may withhold, restrict or redact information in whole or in part.

This may include, but is not limited to, circumstances involving:

  • personal data or rights of other individuals;
  • legal professional privilege;
  • confidential legal advice;
  • management forecasting or planning;
  • negotiations with the requester;
  • confidential references;
  • crime prevention, detection, investigation or taxation;
  • regulatory or safeguarding functions;
  • qualifying research, statistical or archiving activities;
  • information whose disclosure is prohibited or restricted by legislation;
  • confidential or commercially sensitive information where an applicable legal protection applies;
  • information outside the scope of the requester’s personal data; and
  • any other statutory exemption, restriction or qualification.

The applicability of any exemption will depend on its statutory conditions.

Mission Diverse may provide part of a record while redacting or withholding other information.

Information relating to other people

An individual’s right of access does not automatically entitle them to obtain personal information relating to another identifiable person.

Where a record contains personal data relating to the requester and another individual, Mission Diverse will consider applicable statutory requirements, including whether consent has been obtained, whether disclosure without consent would be reasonable, whether information can appropriately be redacted and whether the rights and interests of another individual require information to be withheld.

Where personal data is protected by legal professional privilege, Mission Diverse may rely upon the applicable exemption under Schedule 2 of the Data Protection Act 2018.

This may include confidential communications made for the purpose of obtaining or providing legal advice and information protected by litigation privilege where the legal requirements are satisfied.

Mission Diverse will not waive legal professional privilege merely because an information-rights request has been made.

Management information and negotiations

Where the applicable statutory requirements are satisfied, Mission Diverse may rely on exemptions relating to management forecasting or planning and negotiations with the requester.

This may include information concerning future organisational arrangements, staffing, restructuring, financial or operational planning, or Mission Diverse’s intentions during negotiations where disclosure would create the prejudice required by the relevant statutory provision.

Right to object

Article 21 UK GDPR provides individuals with a right to object to certain processing carried out under Article 6(1)(e) or Article 6(1)(f).

An objection does not automatically require all processing to cease.

Where permitted under Article 21, Mission Diverse may continue processing where compelling legitimate grounds override the individual’s interests, rights and freedoms or where processing is necessary for the establishment, exercise or defence of legal claims.

Different rules apply to direct marketing.

Erasure

Article 17 UK GDPR provides a right to erasure in specified circumstances.

The right is not absolute.

Mission Diverse may retain personal information where continued processing is permitted or required under applicable law, including where necessary to comply with a legal obligation, for the establishment, exercise or defence of legal claims, where another statutory exemption applies or where the legal conditions giving rise to erasure have not been satisfied.

Rectification and disputed information

Article 16 UK GDPR provides a right to rectification of inaccurate personal data.

This does not ordinarily require Mission Diverse to alter an honestly recorded opinion, assessment, statement, decision or historical record merely because an individual disagrees with it.

Where appropriate, Mission Diverse may retain the original record while recording that the individual disputes the information.

Retention

Mission Diverse will retain personal information for as long as reasonably necessary for lawful purposes.

Relevant considerations may include contractual requirements, operational requirements, statutory or regulatory obligations, financial and taxation requirements, insurance requirements, safeguarding, governance, limitation periods, complaints or disputes, actual or anticipated legal proceedings, evidential value, historical records, intellectual property protection and the establishment, exercise or defence of legal rights.

Where an actual or anticipated complaint, dispute, investigation, legal proceeding or regulatory matter exists, Mission Diverse may suspend normal deletion arrangements where reasonably necessary to preserve relevant information.

Information security

Mission Diverse will take appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing, accidental loss, destruction, alteration or disclosure.

Access will be restricted according to legitimate organisational need.

Mission Diverse may restrict or withdraw access to its systems, accounts, records or information where reasonably necessary for security, operational, contractual or legal reasons.

Monitoring and organisational systems

Mission Diverse may undertake proportionate monitoring of its systems, accounts, information and communications where lawful and reasonably necessary for purposes including:

  • information and cyber security;
  • protecting confidential information;
  • protecting intellectual property;
  • preventing unauthorised use;
  • maintaining business continuity;
  • safeguarding;
  • investigating suspected misconduct;
  • maintaining audit trails;
  • protecting organisational reputation; and
  • establishing or defending legal rights.

Where monitoring involves personal data, applicable data protection requirements will apply.

Sharing information

Mission Diverse may disclose personal information where lawful and reasonably necessary.

Recipients may include authorised employees and contractors, clients or delivery partners where appropriate, technology and cloud-service providers, professional advisers, accountants and auditors, insurers, banks and payment providers, regulatory and statutory bodies, legal representatives, courts and tribunals and law enforcement agencies.

Mission Diverse does not sell personal information.

International transfers

Where personal information is transferred outside the United Kingdom, Mission Diverse will apply an appropriate transfer mechanism or safeguard where required by law.

Automated systems and artificial intelligence

Mission Diverse may use digital and artificial intelligence tools to support administrative, analytical, transcription, summarisation, document-management, search or other organisational activities.

Where these activities involve personal data, they will be subject to applicable data protection requirements.

Mission Diverse will not make a decision producing significant legal or similarly significant effects solely through automated processing unless permitted by law and appropriate safeguards apply.

Complaints and exercising rights

Individuals wishing to exercise a statutory data protection right or raise a concern about Mission Diverse’s use of personal information should contact Mission Diverse using the contact information published on our website.

Mission Diverse may ask for information reasonably necessary to confirm identity or clarify a request where legally appropriate.

Individuals may also complain to the Information Commissioner’s Office.

Status and relationship with other policies

This policy sets out Mission Diverse CIC’s current overarching approach to privacy, data protection and information rights from its stated effective date.

It should be read alongside relevant contracts, privacy notices, employee handbook provisions, information-security arrangements, records-management procedures and other applicable Mission Diverse policies.

Where an earlier privacy or data protection policy addresses the same subject matter, this policy represents Mission Diverse’s current position from its effective date to the extent that the provisions are inconsistent.

Earlier policies may remain relevant to processing undertaken during the period in which they were in force and may be retained as part of Mission Diverse’s compliance records.

Nothing in this policy retrospectively changes the legal status or lawful basis of earlier processing. It may, however, describe or clarify processing activities, lawful bases or organisational practices which already existed.

General reservation of statutory protections

Nothing in this policy limits Mission Diverse’s ability to rely upon any right, exemption, restriction, qualification, defence or other protection available under:

  • the UK GDPR;
  • the Data Protection Act 2018;
  • the Data (Use and Access) Act 2025;
  • the Privacy and Electronic Communications Regulations 2003, where applicable;
  • other applicable legislation; or
  • common law principles including legal professional privilege and confidentiality.

References to particular statutory provisions or examples within this policy are not exhaustive.

Changes to this policy

Mission Diverse may update this policy to reflect changes in legislation, regulatory guidance, technology, services or organisational practices.

The current version applies from its stated effective date.

VersionEffective DateAmendmentsApproved By
1.02 August 2022Policy effectiveData Protection Officer
1.111 October 2023Section added:  “Sharing information”Data Protection Officer
1.218 August 2026Section added: “International transfers”Data Protection Officer
    
    
    
    
    
    



Scroll to top
error: HELLO COPYCAT! THIS CONTENT IS PROTECTED!