Data Protection Policy

1. Purpose And Commitment

CC33 Global Limited (CC33) is committed to protecting personal data, respecting privacy rights and handling information lawfully, fairly and securely. This public policy explains the standards and principles that guide our approach to data protection.

This policy is a high-level statement of our data protection commitments. It does not replace our privacy notices, which provide more detailed information about how we collect and use personal data in particular circumstances.

2. Scope

This policy applies to personal data CC33 processes in connection with our business activities and services. CC33 may act as a data controller for its own business activities and, where we provide services for clients, may also act as a data processor acting on the client’s documented instructions.

Our internal policies, standards and procedures provide more detailed requirements for employees, contractors and others who process personal data on behalf of CC33.

3. Legal And Regulatory Framework

CC33 processes personal data in accordance with applicable data protection and privacy law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR), where relevant.

Where we process or transfer personal data internationally, we also consider applicable overseas requirements and any contractual obligations that apply to the processing.

4. Our Data Protection Principles

CC33 applies the core data protection principles to the personal data we handle. We aim to ensure that personal data is:

  • processed lawfully, fairly and transparently;
  • collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes;
  • adequate, relevant and limited to what is necessary;
  • accurate and kept up to date where required;
  • kept for no longer than necessary;
  • protected through appropriate technical and organisational measures; and
  • managed in a way that enables CC33 to demonstrate accountability.

5. Lawful, Fair And Transparent Processing

Before processing personal data, CC33 identifies and documents an appropriate lawful basis and any additional condition required for special category or criminal offence data. We provide appropriate privacy information so that individuals can understand how and why their personal data is being used.

Where CC33 undertakes direct marketing or uses electronic communications for marketing purposes, we apply applicable data protection and PECR requirements, including relevant consent, preference and opt-out requirements.

6. Data Protection By Design And Risk Management

We consider privacy and data protection when new systems, services, campaigns, technologies, or processing activities are designed or materially changed. We use risk assessments and Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals.

We apply data minimisation, appropriate access controls and other safeguards by design and by default. Where processing is likely to be accessed by children, we consider the higher level of protection that children require.

Where CC33 makes a significant decision based solely on automated processing, including profiling, we apply the safeguards and individual rights required by applicable data protection law.

7. Information Security And Confidentiality

CC33 maintains technical and organisational measures designed to protect personal data against unauthorised or unlawful access, use, disclosure, alteration, loss or destruction. Measures are selected according to the sensitivity of the information and the risks associated with the processing.

These measures include appropriate access controls, secure storage and transmission, information classification, monitoring, incident management, staff awareness and regular review of security controls.

8. Individual Rights

CC33 respects the rights available to individuals under data protection law. Depending on the circumstances, these may include rights to:

  • be informed about how personal data is used;
  • access personal data;
  • have inaccurate or incomplete personal data corrected;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing, including direct marketing;
  • receive personal data in a portable format where the right applies; and
  • exercise rights relating to automated decision-making and profiling where applicable.

You can make requests by contacting privacy@cc33.co.uk. We will respond without undue delay and within the applicable statutory timeframe, which is normally one calendar month, subject to any permitted extension or other provision of the law.

Where CC33 processes personal data solely on behalf of a client acting as the data controller, we may refer a rights request to that client and support them in responding as required.

9. Data Protection Complaints

Individuals have the right to complain to CC33 if they believe we have not handled personal data in accordance with data protection law. Complaints can be submitted to privacy@cc33.co.uk or through any other published CC33 complaints route.

We will acknowledge a data protection complaint within 30 days of receipt, take appropriate steps to investigate it without undue delay, keep the complainant appropriately informed and communicate the outcome.

Where CC33 acts solely as a processor for a client, we may refer the complaint to the relevant client acting as data controller and provide reasonable assistance with their investigation.

If an individual remains dissatisfied, they may complain to the Information Commissioner’s Office (ICO). Further information is available at www.ico.org.uk.

10. Personal Data Breaches

Suspected or actual personal data breaches are assessed and managed promptly. CC33 maintains incident response arrangements to contain incidents, investigate causes and impact, take remedial action and meet applicable legal and contractual notification requirements.

Where notification to the ICO, another supervisory authority, an affected individual or a client is required, this will be managed in accordance with the circumstances and applicable law or contract.

11. Suppliers, Data Sharing And Processors

CC33 only shares personal data where there is an appropriate purpose, lawful basis, or other legal authority to do so. Where third parties process personal data on our behalf, we apply appropriate due diligence, contractual requirements and proportionate oversight.

Processors and sub-processors are required to protect personal data, maintain confidentiality and security, assist with relevant data protection obligations and notify CC33 of personal data breaches without undue delay and within any shorter contractual timeframe.

12. International Data Transfers

Where personal data is transferred outside the United Kingdom, CC33 assesses the transfer and uses an appropriate lawful transfer mechanism where required. This may include reliance on adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.

Where required, we also assess whether additional measures are needed to protect personal data in the destination country.

13. Retention And Secure Disposal

Personal data is retained only for as long as it is needed for the purpose for which it was collected, or to meet applicable legal, regulatory, contractual or legitimate business requirements. CC33 maintains retention arrangements and securely deletes, destroys or anonymises information when it is no longer required.

14. Governance, Training And Accountability

Senior management is responsible for ensuring that appropriate resources and oversight are available for data protection. CC33’s Data Protection Officer provides independent advice, monitoring and guidance and reports on significant data protection matters through the organisation’s governance arrangements.

Employees and relevant contractors receive appropriate data protection and information security training. Compliance is monitored through governance, assurance, risk management and audit activities, and our policies and controls are reviewed when legal requirements, processing activities or organisational risks materially change.

15. Contact And Review

Questions about this policy, requests to exercise data protection rights and data protection complaints can be directed to:

Email: privacy@cc33.co.uk

CC33 will keep this policy under review and update the public version where necessary to reflect material changes in law, regulatory guidance, our processing activities or our data protection arrangements.

Last updated: 28 August 2026