Legal · Internal Policy · UK GDPR
Data Protection Policy
Version 1.1
Pegaz Recruitment Ltd t/a Joanna Black Recruitment · Co. No. 09521939
Last updated: June 2026
1. Purpose and scope
Pegaz Recruitment Ltd, trading as Joanna Black Recruitment, processes personal data about candidates, clients and business partners in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all employees, contractors and suppliers who access personal data held by or on behalf of the agency. It sets out our commitments, responsibilities and procedures.
2. The six UK GDPR principles
We commit to processing all personal data in accordance with the six data protection principles:
- Lawfulness, fairness and transparency — we process data lawfully and inform individuals clearly how and why
- Purpose limitation — data is collected for specified, explicit, legitimate purposes only and not processed beyond those purposes
- Data minimisation — we collect only what is strictly necessary for the stated purpose
- Accuracy — data is kept accurate and up to date; inaccuracies are corrected promptly
- Storage limitation — data is not kept for longer than necessary; retention schedules are followed
- Integrity and confidentiality — data is protected against unauthorised access, loss, destruction or damage through appropriate technical and organisational measures
3. Roles and responsibilities
Data Controller
Pegaz Recruitment Ltd t/a Joanna Black Recruitment is the Data Controller and is fully responsible for compliance with UK GDPR. The Data Controller determines the purposes and means of processing personal data.
Responsible person
Joanna Black, Director · hire@joannablack.co.uk
Note on DPO: An agency of this size is not legally required under UK GDPR to appoint a formal Data Protection Officer (DPO). However, a designated responsible person is in place internally and is the first point of contact for all data protection matters.
4. ICO registration
The agency is registered with the Information Commissioner's Office (ICO) as required under UK data protection law. Our ICO registration number is available on request. Registration is renewed annually (current fee: £40–60/year). Person responsible for renewal: Joanna Black.
The ICO register can be searched at: ico.org.uk.
5. Collecting and processing candidate data
- We collect CVs and candidate data only when a candidate voluntarily submits them, or when we have found them on a public platform (LinkedIn, job board) and are contacting them about a suitable role
- On first contact with a sourced candidate (i.e. one who has not applied directly), we identify ourselves, explain where we found their data and how we intend to process it
- A candidate's CV is never shared with a client without the candidate's explicit consent
- A candidate may withdraw consent at any time; their data will be removed from our active database within 30 days of the request
- We do not use automated decision-making or profiling that has a legal or similarly significant effect on candidates
6. Data security measures
Technical safeguards
- Data stored on encrypted cloud platforms (e.g. Microsoft 365, Google Workspace)
- Access controlled by strong, unique passwords and mandatory two-factor authentication (2FA)
- Regular automated data backups with tested recovery procedures
- Emails containing CVs or sensitive personal data transmitted via encrypted connections (TLS)
Organisational safeguards
- Candidate and client data accessible only to authorised personnel
- All new staff and contractors with data access complete data protection awareness training before being granted system access
- Work devices are locked when unattended
- Physical documents containing personal data are destroyed by cross-cut shredder
- Third-party suppliers with access to personal data are subject to a Data Processing Agreement (DPA)
7. Data breach procedure
- The person who discovers a breach immediately informs Joanna Black (the designated responsible person)
- We assess the nature, scope and likely risk to the rights and freedoms of affected individuals
- If the breach is likely to result in a risk to individuals — we report to the ICO within 72 hours of becoming aware
- If the breach carries a high risk to individuals — we notify those affected directly and without undue delay
- Every breach, regardless of severity, is documented in our internal breach register
ICO breach reporting:
Phone: 0303 123 1113 · Online:
ico.org.uk/report-a-breach
Deadline: 72 hours from the point of becoming aware of the breach
8. International data transfers
- UK → EU/EEA: The UK recognises all EU/EEA countries as providing adequate data protection (UK adequacy regulations). No additional safeguards are required.
- UK → other third countries: Appropriate safeguards must be in place, such as UK International Data Transfer Agreements (IDTAs) or UK Standard Contractual Clauses (UK SCCs).
- All transfers of personal data outside the UK are documented in our data processing records.
9. Third-party data processors
All suppliers who process personal data on our behalf must:
- Sign a Data Processing Agreement (DPA) before processing begins
- Demonstrate an adequate level of data security (e.g. ISO 27001, SOC 2, or equivalent)
- Process personal data solely in accordance with our documented instructions
- Notify us promptly of any data breach or security incident involving our data
10. Individual rights
Individuals whose data we hold have the following rights under UK GDPR. All requests should be directed to hire@joannablack.co.uk and will be responded to within 30 calendar days.
- Right of access (Subject Access Request)
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to object to processing based on legitimate interest
- Right to restrict processing
- Right to data portability
- Right to withdraw consent at any time
11. Policy review
This policy is reviewed at least annually and updated promptly following any material change in legislation, agency processes or data processing activities.
Last reviewed: June 2026 · Next review: June 2027 · Approved by: Joanna Black, Director