1. Purpose
This policy sets out how Full Colour Leadership Ltd (“Full Colour”) complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It explains how we handle personal data, defines roles and responsibilities, and confirms our commitment to protecting the privacy rights of individuals whose data we process.
2. Scope
This policy applies to:
- Full Colour’s Founder and CEO
- All associates and sub-contractors engaged by Full Colour
- All personal data collected, stored, processed, or shared by Full Colour in the course of delivering consultancy and training services.
Personal data means any information that identifies or could identify an individual (e.g. names, email addresses, feedback forms, participant data).
3. Roles and Responsibilities
- Founder and CEO (Data Protection Lead): The Founder and CEO is responsible for ensuring Full Colour complies with data protection legislation. This includes maintaining policies, ensuring associates are aware of their responsibilities, responding to data subject rights requests, and reporting breaches if they occur.
- Associates/Sub-contractors: Each associate must handle personal data in line with this policy, sign confidentiality agreements, and complete GDPR briefings provided or arranged by Full Colour.
- Clients: Clients remain the data controllers for any personal data they supply to us. Full Colour acts as a data processor unless otherwise agreed in writing.
4. Data Protection Principles
We follow the six principles of data protection law. Personal data must be:
- Lawful, fair, and transparent – we process data based on a clear legal basis and explain how it will be used.
- Limited to the purpose collected – data will only be used for consultancy and training purposes.
- Data minimised – we only collect the minimum data required.
- Accurate and up to date – inaccurate data will be corrected or deleted promptly.
- Storage limited – personal data is kept only as long as necessary.
- Secure – we protect data through appropriate technical and organisational measures.
5. Lawful Basis for Processing
We will only process personal data when there is a lawful basis, such as:
- Contract – delivering agreed consultancy or training services.
- Consent – for optional communications, surveys, or events.
- Legitimate interest – where processing is minimal, low-risk, and necessary for business purposes.
6. Data Security
We protect personal data through the following measures:
- Use of encrypted devices and secure cloud storage where appropriate.
- Password protection.
- Sharing data with associates only where necessary, and via secure methods (e.g. encrypted email attachments or secure portals).
- Physical documents (if any) stored securely and destroyed by shredding when no longer required.
7. Working with Associates
- All associates are required to sign confidentiality and data protection agreements.
- Associates must not download, store, or share client personal data outside secure systems authorised by Full Colour.
- Associates are only given access to personal data relevant to the projects they are delivering.
8. Data Retention
- Client project data: retained for up to six months after project completion, unless agreed otherwise.
- Training participant lists and evaluations: retained for 18 months for reporting and quality assurance, then anonymised or deleted.
- Contact details for associates: retained while the associate works with Full Colour, and deleted within 12 months of ending the relationship.
9. Data Subject Rights
Individuals have the right to:
- Access their personal data
- Request correction of inaccurate data
- Request erasure (when legally permitted)
- Restrict or object to processing
- Request data portability (where applicable)
Requests will be acknowledged and responded to within one month (two months for complex requests).
10. Data Breach Procedure
All associates must immediately report any suspected data breach to the Founder and CEO. The Founder and CEO will:
- Investigate and assess the severity.
- Contain and mitigate the breach.
- Notify the Information Commissioner’s Office (ICO) within 72 hours if there is a risk to individuals’ rights and freedoms.
- Inform affected individuals if necessary.
- Keep a record of all breaches, regardless of severity.
11. Training and Awareness
- All associates will receive GDPR briefings when they begin working with Full Colour.
- The Founder and CEO will review this policy regularly and update it as required.
12. Compliance Commitment
Full Colour is committed to:
- Upholding the rights of individuals under UK GDPR.
- Ensuring associates understand and comply with this policy.
- Working transparently with clients, who remain the data controllers in most cases.
- Reviewing and improving our practices to maintain compliance.
13. Complaints process
If you wish to raise a complaint, please email us at [email protected]. We will acknowledge receipt of the complaint as soon as possible and within 30 days of receipt of the complaint at the latest.
Full Colour will investigate the complaint thoroughly. If the investigation identifies steps that Full Colour needs to take we will implement within a reasonable timeframe.
We will keep the complainant informed during the process and let them know the outcome.
Signed:
Srabani
Founder and CEO, Full Colour Ltd
Date: 11 June 2026
Appendix 1: Data Breach Procedure
Purpose
This procedure sets out the steps all subcontractors and associates must follow if they suspect or identify a personal data breach.
1. What is a Data Breach?
A data breach is any event where personal data is:
- Lost, stolen, or accidentally deleted
- Accessed by someone without permission
- Shared in error (e.g. wrong recipient in an email)
- Damaged or corrupted so it cannot be used
2. Immediate Actions (All Staff & Associates)
- Identify – If you think a breach has happened, stop what you are doing and record what has occurred.
- Report – Inform the Director (Data Protection Lead) immediately by phone or email.
- Contain – Take steps to reduce further risk, e.g.:
- Recall mis-sent emails
- Change compromised passwords
- Secure physical files
- Disconnect affected devices from the internet if hacked
3. Role of the Director (Data Protection Lead)
The Director will:
- Assess – Decide whether the breach poses a risk to individuals’ rights and freedoms.
- Record – Log the breach in the Breach Register, even if minor.
- Mitigate – Take corrective actions (e.g. recover data, update security measures).
- Notify ICO – If risk is significant, report to the Information Commissioner’s Office within 72 hours.
- Notify Individuals – If there is a high risk of harm (e.g. identity theft, financial loss), affected individuals will be informed promptly.
4. Follow-up
- Review what caused the breach.
- Implement improvements to prevent recurrence.
- Provide additional guidance/training to associates if needed.
5. Key Contact
Data Protection Lead:
Srabani Sen
Email: [email protected]
Phone: 07802 790634
Appendix 2: Testing procedures
1. Annual “Policy to Practice” Check (Internal Audit Lite)
- Once a year, Full Colour will take our GDPR policy and walk through each section.
- We ask: “Are we actually doing this? Can we show evidence?”
- We will record findings in a short review log (this shows a track record of monitoring).
2. Spot-Check Data Handling by Associates
- On occasion Full Colour will choose one or two projects and check:
- Was personal data (e.g. delegate names/emails) handled securely?
- Was data deleted or anonymised after the agreed retention period?
- Was transfer of data (e.g. by email, file sharing) done securely?
- This ensures subcontractors are applying our standards.
3. Test a “Subject Access Request” (SAR) Drill
- On occasion we will simulate a client or participant asking: “Please provide me with all the data you hold on me.”
- We will Test how quickly and easily we can gather, review, and (hypothetically) respond.
4. Check Full Colour’s Data Inventory
- We will review your data register (what personal data you hold, why, where it’s stored, how long it’s kept).
5. Test Security Measures
- Check whether devices used for work (laptops, phones) have:
- Password protection, up-to-date antivirus, and encrypted storage where possible.
- Associates using secure file-sharing methods
6. Review Retention and Deletion
- Once a year, check whether old files/emails containing personal data have been securely deleted in line with your retention rules.
- This is one of the areas regulators often look at.