Governance
Data Protection Policy
Enigma Partners Global Limited — SC893958 — ICO registration C1969786 — Version 1.0, 26 July 2026
1. Policy statement
Enigma Partners Global Limited (“Enigma”) is committed to processing personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any successor legislation. This policy sets out our obligations as a data controller and, where applicable, as a data processor acting on behalf of clients.
Enigma is registered with the Information Commissioner’s Office (ICO) under registration reference C1969786.
2. Scope
This policy applies to:
- →All personal data processed by Enigma in the course of its business activities
- →All Enigma personnel, including employees and associate consultants
- →All systems, tools, and third-party services used to process personal data
It covers data held in digital and physical formats, including email, cloud storage (Microsoft OneDrive/SharePoint), AI-assisted tools, and any client deliverables containing personal data.
3. Data protection principles
We process personal data in accordance with the six principles set out in Article 5 UK GDPR:
| Principle | What this means for Enigma |
|---|---|
| Lawfulness, fairness, transparency | We identify a lawful basis before processing. We are transparent with data subjects about how their data is used. |
| Purpose limitation | Personal data is collected for specified, explicit purposes and not processed in incompatible ways. |
| Data minimisation | We collect only the personal data necessary for the stated purpose. |
| Accuracy | Personal data is kept accurate and up to date. Inaccurate data is corrected or deleted promptly. |
| Storage limitation | Data is not kept longer than necessary. See section 7 for our retention schedule. |
| Integrity and confidentiality | Personal data is protected by appropriate technical and organisational security measures. |
4. Lawful basis for processing
Contract — processing necessary for the performance of a contract, or to take steps before entering one (e.g. client contact data, consultant engagement records).
Legitimate interests — processing necessary for Enigma’s legitimate business interests where not overridden by data subject rights (e.g. business development records, prospect contact data). Legitimate interest assessments are documented and available on request.
Legal obligation — processing required to comply with a legal or regulatory obligation (e.g. HMRC records, Companies House filings).
Consent — where none of the above bases applies, we will seek explicit consent before processing. Consent records are maintained and consent can be withdrawn at any time.
5. Special category data
Enigma does not routinely process special category data in the course of its advisory activities. Where client engagement requires access to special category data processed by the client (for example, as part of a DPIA or governance audit), we will identify the appropriate Schedule 1 condition under DPA 2018, ensure our Data Protection Lead reviews and approves the arrangement, and record the processing in our Records of Processing Activities (ROPA).
6. Individual rights
| Right | How Enigma responds |
|---|---|
| Access (SAR) | Responded to within one calendar month. Verified via email from the requestor’s registered address. |
| Rectification | Inaccurate data corrected within one calendar month of notification. |
| Erasure | Data erased where no overriding legal obligation to retain exists, within one calendar month. |
| Restriction | Processing restricted on request where the legal basis for restriction applies. |
| Portability | Data provided in machine-readable format where processing is by automated means and based on consent or contract. |
| Object | Objections to legitimate interest processing considered promptly; processing stopped unless compelling grounds override. |
| Automated decisions | Enigma does not make solely automated decisions with significant individual effects. Where AI tools are used, a human review step is maintained. |
All rights requests: douglas.trainer@enigmapartnersglobal.com
7. Data retention
| Data category | Retention period | Basis |
|---|---|---|
| Client contact and engagement records | 6 years from end of engagement | Limitation Act 1980; professional liability |
| Financial and invoicing records | 6 years from end of tax year | HMRC requirement |
| Prospect and BD contact records | 2 years from last contact | Legitimate interest; reviewed annually |
| Associate records | 6 years from end of engagement | Employment and contract law |
| Incident and breach records | 5 years from date of incident | ICO accountability requirement |
| Email correspondence | 3 years (routine) / 6 years (contentious) | Proportionality / Limitation Act |
8. Data security
Technical and organisational measures in place:
- →Microsoft 365 Business Premium — all data encrypted in transit and at rest
- →Multi-factor authentication (MFA) enforced on all accounts
- →Device encryption on all working devices
- →Access controls limiting personal data access to those with a business need
- →Secure deletion procedures for data no longer required
Douglas Trainer holds ISO/IEC 27001:2013 Lead Auditor qualification. ISO 27001 information security management principles are applied to Enigma’s internal operations. Cyber Essentials Plus certification is in progress (anticipated Q4 2026).
9. Data breach management
In the event of a personal data breach, Enigma will:
- →Identify and contain the breach as a priority
- →Assess the risk to affected individuals
- →Notify the ICO within 72 hours where the breach is likely to result in a risk to individual rights and freedoms
- →Notify affected individuals without undue delay where there is a high risk to their rights and freedoms
- →Record all breaches in our breach register regardless of whether notification is required
10. International data transfers
Enigma’s primary data processing occurs within the UK and EEA. Where personal data is transferred outside the UK/EEA (for example, through cloud services with non-UK/EEA data centres), we ensure an appropriate transfer mechanism is in place: an adequacy decision, International Data Transfer Agreement (IDTA), or equivalent. Microsoft 365 processes data under IDTAs and the EU-US Data Privacy Framework.
11. AI and automated processing
Enigma uses AI-assisted tools internally and in service delivery. Our AI governance policy ensures:
- →All AI tools processing personal data are assessed for GDPR compliance before deployment
- →AI-generated outputs that may affect individuals are subject to human review
- →EU AI Act Article 50 transparency obligations are met for AI-generated client-facing content
- →Clients are informed where AI tools are used in delivering their engagement
Enigma Comply, our internal governance platform, is operated under a published AI System Card (EPG-COMPLY-AISC-001) aligned to ISO 42001 and EU AI Act Article 13 transparency requirements.
12. Framework compliance
Our data protection practices are aligned to:
- →UK GDPR and Data Protection Act 2018
- →ISO/IEC 27001:2013 Information Security Management
- →ISO/IEC 42001:2023 AI Management System
- →NIST AI Risk Management Framework
- →NIST Cybersecurity Framework
- →EU AI Act (Article 50 and Annex III obligations)
- →ICO guidance on privacy by design, DPIAs, and automated decision-making
Data protection contact
Policy review
This policy is reviewed annually by the Managing Partner, or following any significant data breach, material change to our data processing activities, or change in applicable legislation. Next scheduled review: July 2027.
Douglas Trainer
Managing Partner, Enigma Partners Global Limited
SC893958 — Registered in Scotland
Version 1.0 — Published 26 July 2026