DATA PROTECTION

DATA PROTECTION

Policy · Data Protection & Privacy

Data Protection & Privacy Policy

How Britannia Elite collects, uses, stores, shares and protects personal data — and the rights available to the individuals whose data we hold, under United Kingdom and Ugandan law.

CoveringUnited Kingdom & Uganda
Updated24 June 2026
Approving BodyBoard of Directors, Britannia Elite Ltd
ReviewAnnual
Introduction

1. Introduction

Britannia Elite Ltd (“we”, “us”, “our”) is committed to protecting the privacy, confidentiality and security of all personal data entrusted to us. This policy explains how we collect, use, store, share and protect personal data, and the rights of the individuals whose data we hold. It is written to comply with:

  • the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018; and
  • Uganda’s Data Protection and Privacy Act 2019 and the Data Protection and Privacy Regulations 2021.

It applies to everyone whose data we process, including clients, trainees, employees, instructors, contractors and website users. Britannia Elite Ltd owns and governs the standard from the United Kingdom; training is delivered at an approved centre in Uganda. Personal data is therefore handled across both jurisdictions, and we apply the higher standard where they differ.

Who We Are

2. Who we are and how to contact us

Company nameBritannia Elite Ltd
Company number14855565 (registered in England & Wales)
Registered address86–90 Paul Street, London, England, EC2A 4NE, United Kingdom
Data protection contactinfo@britannia-elite.com (monitored by the Chief Executive Officer)

For the purposes of this policy, Britannia Elite Ltd is the data controller for personal data collected through its websites, enquiries, enrolment and certification. Where a third party processes personal data on our instructions — for example IT or payment providers — that party acts as a data processor under a written agreement.

Definitions

3. Definitions

Personal data

Any information that identifies, or can identify, a living individual.

Processing

Any operation performed on personal data — collection, storage, use, transfer or deletion.

Data subject

An individual whose personal data is processed.

Controller / processor

The controller decides why and how data is processed; a processor acts on the controller’s instructions.

Data We Collect

4. The data we collect

4.1 Identity

  • Full name, date of birth and nationality
  • Identification documents (passport, national ID, certificates)

4.2 Contact

  • Email address and telephone number
  • Residential or business address

4.3 Professional

  • Employment details and qualifications
  • Training records and compliance documentation

4.4 Technical

  • IP address, device information and website usage data
  • Cookies (see our Cookie Policy)

4.5 Sensitive (special category) data, where applicable

  • Health information relevant to training fitness and safety
  • Security clearance information
  • Criminal-record checks, only where lawfully permitted and necessary
Lawful Basis

5. Our lawful basis for processing

We process personal data only where we have a lawful basis to do so. Under both the UK GDPR and Uganda’s Data Protection and Privacy Act 2019 these include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, and our legitimate interests (where these are not overridden by the rights of the individual). Special-category and sensitive data are processed only where an additional condition applies, such as explicit consent or a legal obligation.

Use

6. How we use personal data

  • Delivering training, assessment and certification
  • Managing enrolments, attendance and records
  • Verifying identity and qualifications
  • Meeting regulatory, safeguarding and audit requirements
  • Communicating operational updates and notices
  • Improving our services and website

We do not sell personal data.

Regulatory Compliance

7. Regulatory compliance

Britannia Elite handles personal data in accordance with the requirements of the data protection authorities in the jurisdictions in which it operates — the Information Commissioner’s Office (ICO) in the United Kingdom, and the Personal Data Protection Office (PDPO) within NITA-U in Uganda — and meets the registration and compliance obligations applicable to its processing activities.

Impact Assessments

8. Data protection impact assessments

Where processing is likely to result in a high risk to individuals — for example processing of sensitive data or large-scale monitoring — we carry out a data protection impact assessment before processing begins, consistent with the UK GDPR and Regulation 12 of Uganda’s 2021 Regulations.

International Transfers

9. International data transfers

Because the standard is governed in the UK and training is delivered in Uganda, personal data may be transferred between the two countries. We make such transfers only where appropriate safeguards are in place.

United Kingdom

  • Adequacy decisions, Standard Contractual Clauses (SCCs) and transfer risk assessments

Uganda

  • Compliance with Section 19 of the Data Protection and Privacy Act 2019, which restricts transfers of personal data outside Uganda unless adequate protection or consent is in place

All transfers are lawful, documented and subject to review.

Retention

10. How long we keep data

We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law.

Record typeRetention period
Training & certification records10 years
Compliance documentationAs required by law
Financial records6 years (UK requirement)
Website analyticsUp to 24 months

Data is securely deleted or anonymised when it is no longer required.

Your Rights

11. Your rights

United Kingdom (UK GDPR)Uganda (DPPA 2019)
Be informed; access; rectification; erasure; restriction; data portability; objection; withdraw consentAccess; correction; deletion of inaccurate or unlawfully held data; prevention of processing in certain circumstances; withdraw consent

Requests are handled within the statutory timeframes applicable in each jurisdiction. To exercise any right, contact us using the details in section 2.

Security

12. How we protect data

  • Encryption and secure servers
  • Access controls on a need-to-know basis
  • Staff and instructor confidentiality agreements
  • Regular audits and secure disposal procedures

13. Data breaches

We maintain a breach response procedure. Where a personal data breach occurs, we assess it without delay and notify the relevant regulator and affected individuals where required.

United Kingdom: notifiable breaches are reported to the ICO within 72 hours of our becoming aware of them.

Uganda: where there is reason to believe personal data has been accessed or acquired by an unauthorised person, we notify the PDPO as soon as the breach is discovered, together with the remedial action taken.

Sharing

14. Sharing personal data

We may share personal data, under confidentiality and data protection obligations, with: regulatory authorities; training and accreditation bodies; security vetting agencies; IT service providers; payment processors; and legal or compliance advisors.

Cookies & Marketing

15. Cookies, tracking and marketing

Non-essential cookies are used only with consent, and may be rejected; full detail is in our Cookie Policy. We send marketing communications only where we have a lawful basis to do so, and every such message includes a means to opt out. We do not use solely automated decision-making that produces legal or similarly significant effects on individuals.

Children

16. Children’s data

Our services are directed at adults. We do not knowingly collect personal data from children under 13 (the age of consent for online services under the UK Data Protection Act 2018) without parental or guardian consent, and we apply additional safeguarding protections to anyone under 18 in line with our Safeguarding Policy.

Complaints

17. Complaints

You may contact us first using the details in section 2. You also have the right to complain to a regulator:

  • United Kingdom: the Information Commissioner’s Office (ICO) — ico.org.uk
  • Uganda: the Personal Data Protection Office (PDPO) within NITA-U — pdpo.go.ug
Updates

18. Policy updates

This policy may be updated to reflect legal, operational or regulatory change. The current version is always available on our website.

PolicyData Protection & Privacy
CoveringUnited Kingdom & Uganda
Approving BodyBoard of Directors, Britannia Elite Ltd
ReviewAnnual

Data Protection Officer / contact: Britannia Elite Ltd, 86–90 Paul Street, London EC2A 4NE — info@britannia-elite.com.