Contact us 02920 799 133
t2 group is committed to protecting and respecting the privacy of individuals and handling personal data responsibly, securely, and transparently in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations (PECR), and other applicable data protection legislation.
This policy explains how t2 group collects, uses, stores, shares, retains, and safeguards personal data and demonstrates the organisation’s commitment to accountability through appropriate governance, policies, technical and organisational measures, staff training, and ongoing monitoring.
The UK GDPR sets out the following key principles which t2 group will comply with:
Personal data will only be processed where there is a clear lawful basis and where individuals would reasonably expect such processing to occur.
All personal data processing at t2 group will be conducted in compliance with applicable data protection legislation. This includes implementing appropriate technical and organisational measures to ensure personal data is processed securely, lawfully and fairly.
This includes:
All employees, contractors, consultants, and temporary staff are expected to comply with this policy and associated procedures.
t2 group processes personal data under one of the six legal bases set out under Article 6 UK GDPR.
Processing where a clear and freely given opt-in is required, including certain electronic marketing communications and optional activities.
Individuals may withdraw consent at any time where consent is relied upon.
Processing necessary:
Processing required to comply with statutory, regulatory, safeguarding, employment, taxation, funding body or other legal obligations.
Processing necessary to protect the vital interests of an individual or another person, including emergency situations involving health or safety.
Where applicable, processing may be undertaken in connection with activities carried out in the public interest or under statutory authority, including publicly funded educational or training activities.
Processing necessary for legitimate organisational or business interests, except where overridden by rights and freedoms of individuals.
Where legitimate interests are relied upon, t2 group will assess:
Examples may include:
t2 group may process special category data where permitted under Article 9 UK GDPR and Schedule 1 of the Data Protection 2018.
This may include:
Processing will only occur where:
Criminal offence data will only be processed where authorised by law and subject to appropriate confidentiality and security measures.
t2 group maintains an Appropriate Policy Document (APD) where required under the Data Protection Act 2018.
Personal data will only be retained for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, safeguarding, contractual, funding, and operational requirements.
Data will be securely deleted, anonymised, archived, or disposed of I accordance with the organisation’s Data Retention Policy and records management procedures.
Under UK GDPR, individuals have the following rights regarding their personal data.
Individuals have the right to receive clear and transparent information about how their personal data is processed.
Individuals may request access to their personal data.
Requests should be submitted to dataprotection@t2group.co.uk
t2 group will respond within one month of receipt or applicable statutory timeframe.
Where requests are complex or numerous, or where clarification or identity verification is required, the response timeframe may be extended in accordance with applicable data protection law.
Individuals may request correction of inaccurate data or incomplete personal data.
Where appropriate and feasible, relevant third parties will be informed of corrections.
Individuals can request deletion of their data where there is no compelling reason for continued processing.
Requests will be assessed against applicable legal, contractual, safeguarding, funding, regulatory, and organisational purposes.
Individuals can request that processing of their personal data be limited in certain circumstances.
Individuals may object to processing based on legitimate interest or direct marketing purposes.
Objection requests can be submitted to dataprotection@t2group.co.uk
Where applicable, individuals can request their personal data in a structured, commonly used, and machine-readable format.
t2 group does not currently undertake solely automated decision-making producing legal or similarly significant effects without human involvement.
Where automated processing is used, appropriate safeguards and human oversight will be implemented where required.
Individuals have the right to raise concerns directly with t2 group and may also lodge a complaint with the Information Commissioner’s Office (ICO)
t2 group follows a Data Breach Response Plan to identify, assess, manage, and record personal data breaches.
This includes:
All staff must report suspected personal data breaches immediately.
t2 group implements Privacy by Design and Default principles when implementing systems, processes and business activities.
Appropriate technical and organisational security measures may include:
Data Protection Impact Assessments (DPIAs) will be undertaken where processing is likely to result in a high risk to individuals.
Where personal data is transferred outside the UK, t2 group will ensure appropriate safeguards are implemented in accordance with Chapter V UK GDPR.
Safeguards may include:
Data Protection Impact Assessments (DPIAs) will be undertaken where processing is likely to result in a high risk to individuals.
t2 group will comply with the Privacy and Electronic Communications Regulations (PECR) when undertaking electronic marketing activities or using cookies and similar technologies.
This includes:
Further details are available within the organisation’s Cookie Notice and Privacy Notices.
Where third-party suppliers process personal data on behalf of t2 group, appropriate due diligence and contractual safeguards will be implemented.
This includes:
All staff are responsible for protecting personal data and complying with this policy.
t2 group will provide appropriate data protection, privacy, cybersecurity, and information governance training to staff on a periodic basis
Failure to comply with this policy may result in disciplinary action.
t2 group reserves the right to amend this policy as needed.
For any questions or concerns, contact our Data Protection Officer:
Email: dataprotection@t2group.co.uk
Address: t2 group, Fern House, Unit 1, Links Court, Fortran Road, St. Mellons, CARDIFF CF3 0LT
This policy is reviewed annually to ensure continued compliance with UK GDPR and Data Protection Act 2018.
t2 group
Head Office - Fern House, Unit 1 Links Court,
Fortran Road, St.Mellons,
Cardiff CF3 0LT
02920 799 133
Need to report a Safeguarding concern? Click here.
Acumen Coaching is a specialist Leadership and Management Division of the t2 group.
t2 group and Acumen Coaching are part of the Marr Corporation Ltd.