Now taking new clients  ·  hire@joannablack.co.uk
Privacy Cookies Data Protection Anti-Slavery Diversity Complaints
Legal · Internal Policy · UK GDPR

Data Protection Policy

Version 1.1 Pegaz Recruitment Ltd t/a Joanna Black Recruitment · Co. No. 09521939 Last updated: June 2026

1. Purpose and scope


Pegaz Recruitment Ltd, trading as Joanna Black Recruitment, processes personal data about candidates, clients and business partners in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to all employees, contractors and suppliers who access personal data held by or on behalf of the agency. It sets out our commitments, responsibilities and procedures.

2. The six UK GDPR principles


We commit to processing all personal data in accordance with the six data protection principles:

3. Roles and responsibilities


Data Controller

Pegaz Recruitment Ltd t/a Joanna Black Recruitment is the Data Controller and is fully responsible for compliance with UK GDPR. The Data Controller determines the purposes and means of processing personal data.

Responsible person

Joanna Black, Director  ·  hire@joannablack.co.uk

Note on DPO: An agency of this size is not legally required under UK GDPR to appoint a formal Data Protection Officer (DPO). However, a designated responsible person is in place internally and is the first point of contact for all data protection matters.

4. ICO registration


The agency is registered with the Information Commissioner's Office (ICO) as required under UK data protection law. Our ICO registration number is available on request. Registration is renewed annually (current fee: £40–60/year). Person responsible for renewal: Joanna Black.

The ICO register can be searched at: ico.org.uk.

5. Collecting and processing candidate data


6. Data security measures


Technical safeguards

Organisational safeguards

7. Data breach procedure


  1. The person who discovers a breach immediately informs Joanna Black (the designated responsible person)
  2. We assess the nature, scope and likely risk to the rights and freedoms of affected individuals
  3. If the breach is likely to result in a risk to individuals — we report to the ICO within 72 hours of becoming aware
  4. If the breach carries a high risk to individuals — we notify those affected directly and without undue delay
  5. Every breach, regardless of severity, is documented in our internal breach register
ICO breach reporting:
Phone: 0303 123 1113  ·  Online: ico.org.uk/report-a-breach
Deadline: 72 hours from the point of becoming aware of the breach

8. International data transfers


9. Third-party data processors


All suppliers who process personal data on our behalf must:

10. Individual rights


Individuals whose data we hold have the following rights under UK GDPR. All requests should be directed to hire@joannablack.co.uk and will be responded to within 30 calendar days.

11. Policy review


This policy is reviewed at least annually and updated promptly following any material change in legislation, agency processes or data processing activities.

Last reviewed: June 2026  ·  Next review: June 2027  ·  Approved by: Joanna Black, Director