Data Protection

1. Purpose

The purpose of this policy is to ensure that CASEwork complies with its legal obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in the handling of personal data.

2. Scope

This policy applies to all employees, contractors, and partners of CASEwork who process personal data in the course of providing our services.

3. Key Principles

We are committed to complying with the data protection principles. Personal data will be:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as necessary
  • Processed securely

4. Lawful Basis for Processing

We process personal data under one or more of the following lawful bases:

  • Contractual necessity (e.g., to provide bookkeeping or payroll services)
  • Legal obligation (e.g., for tax compliance)
  • Consent (where applicable)
  • Legitimate interests (e.g., internal record-keeping)

5. Data Subjects’ Rights

Data subjects have the following rights:

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making (not used by us)

Requests to exercise these rights can be made via: accounts@casework.org.uk

6. Data Security

We implement appropriate technical and organisational measures to ensure data is:

  • Stored securely (e.g., encrypted cloud-based systems)
  • Accessed only by authorised personnel
  • Regularly backed up
  • Protected against loss, misuse, and unauthorised access

7. Data Sharing

We only share data with:

  • HMRC (where required)
  • Accountants or other professionals (with client consent)
  • Software providers under contract and with proper safeguards

We never sell or rent personal data.

8. Data Retention

We retain financial records and related personal data for 6 years from the end of the financial year, or longer where required by law.

9. Data Breaches

In the event of a data breach, we will assess the risk and, where necessary, report it to the ICO within 72 hours. Affected individuals will be informed if the breach is likely to result in a high risk to their rights and freedoms.

10. Policy Review

This policy is reviewed every two years or following any significant regulatory change or data breach.

×