Version 1.2
Effective date: 18 August 2026
Mission Diverse CIC is committed to processing personal information lawfully, fairly, transparently and securely in accordance with applicable UK data protection legislation.
This policy explains how Mission Diverse may collect, use, retain, share, protect and otherwise process personal information, together with the approach we take to individual information rights.
It applies to individuals whose personal information we process, including clients, prospective clients, website visitors, training participants, employees, former employees, workers, consultants, contractors, suppliers, professional contacts, partners and other individuals who interact or have interacted with Mission Diverse.
This policy sets out Mission Diverse’s general approach. It does not create rights or obligations beyond those arising under applicable law.
Mission Diverse processes personal information in accordance with applicable legislation, including, where relevant:
References to legislation include amendments, replacements, re-enactments and corresponding provisions in force from time to time.
Where legislation and this policy are inconsistent, applicable legislation will prevail.
Personal data
Personal data is information relating to an identified or identifiable individual within the meaning of Article 4(1) UK GDPR.
Whether information constitutes personal data depends on its content, purpose and context.
A document, email, record or system does not become personal data in its entirety merely because an individual’s name or other identifier appears within it.
Business records may contain a combination of personal data relating to one or more individuals, confidential business information, client information, commercial information, intellectual property, operational information and information which is not personal data.
Mission Diverse will determine what information falls within the scope of applicable data protection rights in accordance with the legislation.
Depending on the nature of our relationship with an individual, we may process information including, but not limited to:
We may process special category personal data or criminal offence information where necessary and where the applicable additional legal conditions are satisfied.
Mission Diverse may process personal information for purposes including, but not limited to:
Mission Diverse will identify an appropriate lawful basis for processing personal data.
Depending on the circumstances, this may include:
Consent is not required for every processing activity.
Where processing is undertaken on another lawful basis, an individual’s refusal or withdrawal of consent does not necessarily require that processing to cease.
Under Article 6(1)(f) UK GDPR, Mission Diverse may process personal data where processing is necessary for legitimate interests pursued by Mission Diverse or another person, except where those interests are overridden by the individual’s interests or fundamental rights and freedoms.
Our legitimate interests may include, but are not limited to:
This list is illustrative and not exhaustive.
Where legitimate interests is relied upon, Mission Diverse will apply the requirements of Article 6(1)(f) and other applicable data protection legislation.
Materials created, commissioned or contributed to through Mission Diverse’s activities may form part of our intellectual property, organisational records or service-delivery resources.
These may include training materials, presentations, written resources, methodologies, templates, photographs, audio or video recordings, recorded training, digital resources, professional materials and other works or deliverables.
Where an appropriate lawful basis exists, Mission Diverse may retain and continue to use such materials for the purpose for which they were created or another lawful and compatible purpose.
The ending of an employment, consultancy, contracting or other professional relationship does not, by itself, require Mission Diverse to delete, destroy, withdraw or cease using materials lawfully created during that relationship.
Where such materials contain identifiable personal information, Mission Diverse will consider applicable data protection obligations separately from any contractual or intellectual property rights.
The UK GDPR distinguishes between a data controller and a data processor.
A controller determines the purposes and means of processing personal data.
A processor processes personal data on behalf of, and ordinarily on the documented instructions of, a controller.
Mission Diverse may act as controller for some processing activities and processor for others. Our status will depend on the particular processing activity and circumstances.
Where Mission Diverse is the controller
Where Mission Diverse determines the purposes and means of processing, it will ordinarily act as data controller and will be responsible for considering applicable individual rights requests.
Mission Diverse will determine, in accordance with the law:
Acting as controller does not create an entitlement to unrestricted access to Mission Diverse’s documents, systems or business records.
Where Mission Diverse is the processor
Where Mission Diverse processes personal data solely on behalf of another organisation and under that organisation’s documented instructions, the relevant controller will ordinarily remain responsible for determining and responding to individual rights requests.
If Mission Diverse receives a request relating to information for which another organisation is controller, Mission Diverse may:
Mission Diverse will not ordinarily make the substantive decision about whether another controller’s information should be disclosed, withheld, rectified, restricted or erased unless authorised or legally required to do so.
Individual rights and statutory limitations
Mission Diverse recognises the rights available under Articles 12 to 22 UK GDPR and the Data Protection Act 2018.
These rights are subject to the conditions, qualifications, restrictions and exemptions contained within applicable legislation.
Nothing in this policy creates a right of access, disclosure, deletion, objection, rectification or restriction beyond that required by law.
Mission Diverse may rely upon any applicable statutory exemption, restriction, qualification or other protection where its legal requirements are satisfied.
Article 15 UK GDPR provides individuals with a right to confirmation of whether their personal data is being processed, access to that personal data and specified supplementary information.
It is a right to personal data.
It is not a general right to obtain or inspect all documents, emails, messages, records, systems or business information in which an individual may be mentioned.
A requester cannot expand the statutory right simply by identifying particular documents, systems, people, accounts or categories of records.
Requests for information including emails, messages, meeting records, board papers, drafts, reports, system logs, website records, project files, version histories, working documents or other organisational records will be considered to the extent that they contain personal data falling within Article 15.
The fact that an individual created a document, performed the work recorded in it, sent or received a communication, was copied into a communication, is named or referred to within it, participated in a meeting, used a particular system, worked on a project or considers information relevant to a dispute does not by itself make the entire document or record that individual’s personal data.
Where a wider document contains relevant personal data, Mission Diverse may provide the personal data through an extract, compilation, transcript, redacted copy or another appropriate form where this satisfies Article 15.
Mission Diverse will undertake searches that are reasonable and proportionate in the circumstances.
In determining appropriate search activity, Mission Diverse may consider matters including, but not limited to:
A subject access request does not automatically require searches of every account, device, communication platform, archive or storage location capable of containing information.
Where private devices or informal messaging systems have been used for Mission Diverse business, Mission Diverse will consider whether there is a reasonable basis for believing relevant personal data controlled by Mission Diverse is held there.
Where Mission Diverse processes a large amount of information relating to an individual, or where a request cannot reasonably be actioned without further information, Mission Diverse may ask the requester to clarify the information or processing activities concerned where permitted by law.
Where the statutory conditions are satisfied, the applicable response period may be paused while necessary clarification is awaited.
Seeking clarification does not mean that a requester can be compelled to narrow an otherwise valid request. Mission Diverse will undertake reasonable and proportionate searches as required by law.
Repeated, overlapping and successive requests
Mission Diverse will consider each request on its individual circumstances.
Where an individual submits repeated, overlapping or successive requests, Mission Diverse may consider whether all or part of a request is manifestly unfounded or excessive under Article 12 UK GDPR.
Relevant factors may include, but are not limited to:
Where permitted by law, Mission Diverse may refuse all or part of a manifestly unfounded or excessive request or charge a reasonable fee reflecting the administrative cost of responding.
A request will not be treated as manifestly unfounded or excessive merely because it is large, inconvenient, critical of Mission Diverse or connected with a dispute.
Where a subsequent request seeks personal data that has already been supplied, Mission Diverse may take this into account when considering the appropriate response.
Where no material change has occurred and a request substantially repeats a recent request, Mission Diverse may consider whether the request or relevant part of it is excessive under Article 12.
New or materially changed personal data will be considered separately.
Information does not become personal data in its entirety merely because an employee, consultant, contractor or other individual created it, received it, was copied into it or is named within it.
Ordinary business records may include information concerning clients, projects, operational instructions, training and consultancy work, proposals, commercial discussions, organisational decisions, financial matters, business strategy, intellectual property, internal processes, system administration and other individuals.
Where only part of a record constitutes the individual’s personal data, Mission Diverse will assess the individual’s statutory rights in relation to that personal data rather than treating the complete record as belonging to, or automatically accessible by, the individual.
Draft documents, version histories, internal comments, annotations, metadata, system logs, access records, security logs and other technical information are not automatically subject to disclosure in their entirety.
Where information within such records constitutes the requester’s personal data, Mission Diverse will consider it in accordance with Article 15 and applicable exemptions or restrictions.
Mission Diverse is not required under Article 15 to disclose technical, operational or administrative information which does not constitute personal data relating to the requester.
Data protection rights are not a general right of disclosure
Data protection rights do not create a general right of discovery, disclosure or inspection of Mission Diverse’s records.
A subject access request does not provide a general mechanism for obtaining evidence for a dispute, investigating Mission Diverse’s internal decision-making, obtaining documents for actual or contemplated litigation, reviewing confidential management discussions, obtaining company records generally or accessing information belonging to Mission Diverse or another person.
The fact that information may be relevant to a grievance, complaint, negotiation, employment dispute or legal proceeding does not itself bring the whole document within Article 15.
Mission Diverse will provide personal data that falls within the statutory right, subject to applicable exemptions, restrictions and third-party rights.
Article 15 and other data protection rights are subject to exemptions and restrictions, including those contained within the Data Protection Act 2018.
Where permitted by law, Mission Diverse may withhold, restrict or redact information in whole or in part.
This may include, but is not limited to, circumstances involving:
The applicability of any exemption will depend on its statutory conditions.
Mission Diverse may provide part of a record while redacting or withholding other information.
An individual’s right of access does not automatically entitle them to obtain personal information relating to another identifiable person.
Where a record contains personal data relating to the requester and another individual, Mission Diverse will consider applicable statutory requirements, including whether consent has been obtained, whether disclosure without consent would be reasonable, whether information can appropriately be redacted and whether the rights and interests of another individual require information to be withheld.
Where personal data is protected by legal professional privilege, Mission Diverse may rely upon the applicable exemption under Schedule 2 of the Data Protection Act 2018.
This may include confidential communications made for the purpose of obtaining or providing legal advice and information protected by litigation privilege where the legal requirements are satisfied.
Mission Diverse will not waive legal professional privilege merely because an information-rights request has been made.
Where the applicable statutory requirements are satisfied, Mission Diverse may rely on exemptions relating to management forecasting or planning and negotiations with the requester.
This may include information concerning future organisational arrangements, staffing, restructuring, financial or operational planning, or Mission Diverse’s intentions during negotiations where disclosure would create the prejudice required by the relevant statutory provision.
Article 21 UK GDPR provides individuals with a right to object to certain processing carried out under Article 6(1)(e) or Article 6(1)(f).
An objection does not automatically require all processing to cease.
Where permitted under Article 21, Mission Diverse may continue processing where compelling legitimate grounds override the individual’s interests, rights and freedoms or where processing is necessary for the establishment, exercise or defence of legal claims.
Different rules apply to direct marketing.
Article 17 UK GDPR provides a right to erasure in specified circumstances.
The right is not absolute.
Mission Diverse may retain personal information where continued processing is permitted or required under applicable law, including where necessary to comply with a legal obligation, for the establishment, exercise or defence of legal claims, where another statutory exemption applies or where the legal conditions giving rise to erasure have not been satisfied.
Article 16 UK GDPR provides a right to rectification of inaccurate personal data.
This does not ordinarily require Mission Diverse to alter an honestly recorded opinion, assessment, statement, decision or historical record merely because an individual disagrees with it.
Where appropriate, Mission Diverse may retain the original record while recording that the individual disputes the information.
Mission Diverse will retain personal information for as long as reasonably necessary for lawful purposes.
Relevant considerations may include contractual requirements, operational requirements, statutory or regulatory obligations, financial and taxation requirements, insurance requirements, safeguarding, governance, limitation periods, complaints or disputes, actual or anticipated legal proceedings, evidential value, historical records, intellectual property protection and the establishment, exercise or defence of legal rights.
Where an actual or anticipated complaint, dispute, investigation, legal proceeding or regulatory matter exists, Mission Diverse may suspend normal deletion arrangements where reasonably necessary to preserve relevant information.
Mission Diverse will take appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing, accidental loss, destruction, alteration or disclosure.
Access will be restricted according to legitimate organisational need.
Mission Diverse may restrict or withdraw access to its systems, accounts, records or information where reasonably necessary for security, operational, contractual or legal reasons.
Mission Diverse may undertake proportionate monitoring of its systems, accounts, information and communications where lawful and reasonably necessary for purposes including:
Where monitoring involves personal data, applicable data protection requirements will apply.
Mission Diverse may disclose personal information where lawful and reasonably necessary.
Recipients may include authorised employees and contractors, clients or delivery partners where appropriate, technology and cloud-service providers, professional advisers, accountants and auditors, insurers, banks and payment providers, regulatory and statutory bodies, legal representatives, courts and tribunals and law enforcement agencies.
Mission Diverse does not sell personal information.
Where personal information is transferred outside the United Kingdom, Mission Diverse will apply an appropriate transfer mechanism or safeguard where required by law.
Mission Diverse may use digital and artificial intelligence tools to support administrative, analytical, transcription, summarisation, document-management, search or other organisational activities.
Where these activities involve personal data, they will be subject to applicable data protection requirements.
Mission Diverse will not make a decision producing significant legal or similarly significant effects solely through automated processing unless permitted by law and appropriate safeguards apply.
Individuals wishing to exercise a statutory data protection right or raise a concern about Mission Diverse’s use of personal information should contact Mission Diverse using the contact information published on our website.
Mission Diverse may ask for information reasonably necessary to confirm identity or clarify a request where legally appropriate.
Individuals may also complain to the Information Commissioner’s Office.
This policy sets out Mission Diverse CIC’s current overarching approach to privacy, data protection and information rights from its stated effective date.
It should be read alongside relevant contracts, privacy notices, employee handbook provisions, information-security arrangements, records-management procedures and other applicable Mission Diverse policies.
Where an earlier privacy or data protection policy addresses the same subject matter, this policy represents Mission Diverse’s current position from its effective date to the extent that the provisions are inconsistent.
Earlier policies may remain relevant to processing undertaken during the period in which they were in force and may be retained as part of Mission Diverse’s compliance records.
Nothing in this policy retrospectively changes the legal status or lawful basis of earlier processing. It may, however, describe or clarify processing activities, lawful bases or organisational practices which already existed.
Nothing in this policy limits Mission Diverse’s ability to rely upon any right, exemption, restriction, qualification, defence or other protection available under:
References to particular statutory provisions or examples within this policy are not exhaustive.
Mission Diverse may update this policy to reflect changes in legislation, regulatory guidance, technology, services or organisational practices.
The current version applies from its stated effective date.
| Version | Effective Date | Amendments | Approved By |
| 1.0 | 2 August 2022 | Policy effective | Data Protection Officer |
| 1.1 | 11 October 2023 | Section added: “Sharing information” | Data Protection Officer |
| 1.2 | 18 August 2026 | Section added: “International transfers” | Data Protection Officer |