1. Policy Statement
Lonsite is committed to protecting the privacy and personal data of individuals whose information it processes, including employees, agency workers, candidates, clients, suppliers, and other business contacts.
This policy explains how Lonsite collects, uses, stores, and protects personal data in accordance with UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Legal Framework
This policy supports compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- ICO guidance and applicable data protection law
3. Scope
This policy applies to:
- All personal data processed by Lonsite
- All employees and persons working on behalf of Lonsite
- All systems, records, and processes involving personal data
4. Roles and Responsibilities
Data Controller
Lonsite acts as the Data Controller for the personal data it processes.
Data Protection Lead
Lonsite has appointed a designated Data Protection Lead responsible for overseeing data protection compliance and responding to data protection enquiries.
All staff are responsible for protecting personal data they handle.
5. Types of Personal Data We Process
As a labour-only recruitment agency and provider of labour subcontract packages, Lonsite may process:
- Identification and contact details
- CVs, qualifications, training records
- Right-to-work documentation
- Employment history and references
- Payroll and payment information
- Client and supplier contact details
- Health and safety or compliance information (where required)
6. Lawful Bases for Processing
Lonsite processes personal data only where there is a lawful basis, including:
- Contractual necessity – to place or employ workers
- Legal obligation – e.g. right-to-work checks, tax requirements
- Legitimate interests – recruitment, business operations, client service
- Consent – where required, and only when freely given
Consent may be withdrawn at any time.
7. Data Protection Principles
Lonsite processes personal data in accordance with the seven UK GDPR principles:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
8. Data Subject Rights
Individuals have rights under UK GDPR, including the right to:
- Access their personal data
- Rectify inaccurate data
- Erase data where applicable
- Restrict or object to processing
- Data portability (where applicable)
Requests should be made in writing and will be handled in accordance with legal timescales.
9. Data Security
Lonsite implements appropriate technical and organisational measures to protect personal data, including:
- Access controls and password protection
- Secure storage of electronic and paper records
- Encryption where appropriate
- Secure disposal of data when no longer required
- Incident reporting and response procedures
10. Data Sharing and Third Parties
Personal data may be shared with clients, suppliers, or service providers where necessary and lawful.
Appropriate contractual safeguards are in place to protect data shared with third parties.
11. International Data Transfers
Where personal data is transferred outside the UK, Lonsite ensures appropriate safeguards are in place in line with UK GDPR requirements.
12. Data Retention
Personal data is retained only for as long as necessary to fulfil its purpose and comply with legal obligations.
Retention periods are reviewed regularly.
13. Data Breaches
Any actual or suspected personal data breach must be reported immediately.
Where required, breaches will be reported to the Information Commissioner’s Office (ICO) and affected individuals.
14. Policy Review
This policy will be reviewed annually or sooner where required by changes in legislation, guidance, or business activities.
This policy has been approved by the Managing Managing Director.
Brian Harris
1st March 2026
Managing Director
