GDPR STATEMENT
We are currently auditing our suppliers and third-party providers and requesting that they pass on their statements around GDPR, and inform us of any anticipated major changes to their working practices. These include organisations such as job boards, LinkedIn, our CRM provider and our payroll provider. We are also following advice from the REC. For further information, please email wework@rubiconpeople.co.uk or call 01202 680 311.
GENERAL DATA PROTECTION REGULATIONS (GDPR) STATEMENT
The EU General Data Protection Regulations (GDPR) came into effect on the 25th May 2018, replacing the 1995 EU Data Protection Directive. The regulation is used to strengthen and unify data protection for all individuals within the EU and be enforced by the Information Commissioner’s Office (ICO).
GDPR still applies to the UK, even post-Brexit, as the UK has adopted GDPR into domestic law through the UK Data Protection Act 2018.
Whilst we are confident that most of our current processes already fall in line with the GDPR expectations, we are:
· Reviewing the purposes of our processing activities, and will select the most appropriate lawful basis for each activity.
· Checking that the processing is necessary for the relevant purpose and document this to demonstrate compliance.
· Including information about both the purposes of the processing and the lawful basis for the processing in our privacy notice.
· Briefing all staff on GDPR and what their personal responsibilities are. Training will be given on any changes to process.
· Not transferring any personal data outside of the UK or EU.
When processing data we undertake the following:
· The processing is lawful, fair and transparent
· Transparent about what the data is being used for
· Data is collected for a specific purpose
· The data is necessary for the purpose
· The data must be accurate and kept up to date
· Data is not kept for longer than necessary
· The data is kept safe and secure
· Individuals can request that we stop processing their data at any time
· Individuals can request for their data to be erased
LEGAL UPDATES UNDER THE DATA (USE AND ACCESS) ACT 2025
SUBJECT ACCESS REQUESTS
We respond to data access requests within the legal timeframe, applying the ‘stop the clock’ provision where clarification is needed. We ensure that searches are reasonable and proportionate.
RECOGNISED LEGITIMATE INTERESTS
We may process personal data under recognised legitimate interests without conducting a full assessment where permitted by law. This includes crime prevention, safeguarding and emergency response.
COOKIES AND LOW-RISK TECHNOLOGIES
We use certain low-risk cookies such as those for service improvement, without requiring user consent, in accordance with current UK regulations.
COMPLAINTS HANDLING
Individuals may submit complaints electronically by contacting wework@rubiconpeople.co.uk. We aim to acknowledge and resolve complaints within 30 days. Please note that the ICO may not handle all complaints directly under the current framework.

