Policy No: DP3
Topic: Data Protection
Policy Owner: Ryan Yeoman, Managing Director
Approved by: Board of Directors
Date adopted: 03/09/2026
Version: 1.0
Next review: September 2027, or sooner if required
1. Introduction
Thrive Recruitment Group Plymouth Ltd (“Thrive” or “the Company”) is committed to protecting personal data and complying with the Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and other applicable data protection legislation (together, the “Data Protection Laws”).
As a recruitment business, Thrive processes personal data relating to employees, workers, work-seekers, referees, client contacts, suppliers and other individuals. This may include special category data and criminal offence data where there is an appropriate lawful basis and condition for processing.
This policy explains the principles Thrive follows when collecting, using, sharing, storing and deleting personal data. It applies to directors, employees, temporary workers and anyone processing personal data on Thrive’s behalf.
Registered office: C3 Apollo Court, Neptune Park, Plymouth, England, PL4 0SJ. Telephone: 01752 423450.
2. Definitions
Consent: a freely given, specific, informed and unambiguous indication of an individual’s wishes, given by a statement or clear affirmative action.
Data controller: the person or organisation that determines the purposes and means of processing personal data.
Data processor: a person or organisation that processes personal data on behalf of a controller.
Data subject / individual: an identified or identifiable living individual to whom personal data relates.
Personal data: information relating to an identified or identifiable living individual.
Personal data breach: a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Processing: any operation performed on personal data, including collection, recording, organisation, storage, use, disclosure, restriction, erasure or destruction.
Special category data: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data used for identification, health data, or data concerning a person’s sex life or sexual orientation.
3. Data processing under the Data Protection Laws
Thrive acts as a data controller for much of the personal data it processes and may also act as a data processor where it processes information on behalf of a client or other controller. Where registration with the Information Commissioner’s Office (ICO) is required, Thrive will maintain the appropriate registration and data protection fee.
Thrive may process personal data for:
- staff and worker administration;
- recruitment, registration, compliance and work-finding services;
- identity, right-to-work, DBS/safeguarding, qualification and reference checks where appropriate;
- matching and introducing work-seekers to schools, SEND settings, alternative provision, colleges and other clients;
- administering assignments, placements, payroll information and related records;
- client and supplier administration, accounts and records;
- responding to enquiries, complaints, safeguarding matters and legal or regulatory obligations;
- appropriate business communications and marketing, subject to applicable privacy and electronic marketing rules;
- use of recruitment software, payroll/umbrella providers, professional advisers and other service providers where necessary and appropriately safeguarded.
4. Data protection principles
Thrive will ensure that personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes;
- adequate, relevant and limited to what is necessary;
- accurate and, where necessary, kept up to date;
- kept in identifiable form for no longer than necessary;
- processed securely using appropriate technical and organisational measures; and
- managed in a way that enables Thrive to demonstrate accountability and compliance.
5. Lawful bases for processing
Thrive will only process personal data where a lawful basis applies. Depending on the activity, this may include consent, performance of or steps toward a contract, compliance with a legal obligation, protection of vital interests, performance of a public task where applicable, or legitimate interests where those interests are not overridden by the individual’s rights and freedoms.
Special category data and criminal offence data will only be processed where the additional conditions required by law are met. Thrive will document and review its lawful bases as appropriate and will stop processing where no lawful basis exists.
Before disclosing personal data to third parties such as prospective or current clients, former employers/referees, payroll or umbrella providers, software providers, professional advisers or regulators, Thrive will establish an appropriate lawful basis and apply proportionate safeguards.
6. Privacy by design and by default
Data protection will be considered throughout the lifecycle of Thrive’s processing activities. Appropriate measures may include:
- collecting only information that is necessary for the stated purpose;
- role-appropriate access controls and secure passwords;
- secure electronic storage and transmission;
- appropriate use of encryption, pseudonymisation or anonymisation where proportionate;
- regular review and deletion of information that is no longer required;
- careful selection and management of processors and service providers;
- staff awareness of confidentiality, phishing, cyber security and data breach reporting;
- consideration of privacy risks when introducing new systems, suppliers or processing activities.
7. Privacy notices and transparency
Where Thrive collects personal data directly from an individual, it will provide appropriate privacy information at or around the time of collection. Where data is obtained from another source, Thrive will provide the required information within the applicable legal timeframe, subject to any lawful exemption.
If Thrive intends to use personal data for a materially different purpose, it will provide relevant information before carrying out that further processing where required.
8. Rights of individuals
Subject to the conditions and exemptions in Data Protection Laws, individuals may have rights to:
- be informed about how their personal data is used;
- access their personal data;
- have inaccurate or incomplete data rectified;
- request erasure of personal data;
- request restriction of processing;
- receive or transfer certain data in a portable format;
- object to certain processing, including an absolute right to object to direct marketing;
- withdraw consent where consent is the lawful basis; and
- seek safeguards in relation to qualifying automated decision-making.
Requests should be sent to Ryan Yeoman, Managing Director, via Thrive Recruitment Group Plymouth Ltd at C3 Apollo Court, Neptune Park, Plymouth, England, PL4 0SJ or by telephone on 01752 423450. Thrive will respond within the statutory timeframe, normally one month, and will only extend, refuse or charge for a request where the law permits.
9. Automated decision-making and profiling
Thrive will not make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing is permitted by law and appropriate safeguards are in place. Thrive does not use solely automated decision-making or profiling involving children for recruitment decisions.
10. Data accuracy, retention and deletion
Thrive will take reasonable steps to keep personal data accurate and up to date. Personal data will be retained only for as long as necessary for the purpose for which it was collected, including applicable legal, regulatory, contractual, safeguarding and evidential requirements. When information is no longer required, it will be securely deleted, destroyed or anonymised as appropriate.
11. Data sharing and processors
Personal data will only be shared where there is a lawful and legitimate reason. Recipients may include clients, prospective employers, referees, payroll or umbrella companies, recruitment and compliance software providers, professional advisers, insurers, auditors, regulators, law-enforcement bodies and other parties where required or permitted by law.
Where Thrive appoints a processor, it will take reasonable steps to ensure appropriate data protection terms and security arrangements are in place. International transfers will only be made where an appropriate lawful transfer mechanism and safeguards apply.
12. Personal data breaches
All suspected or actual personal data breaches must be reported immediately to Ryan Yeoman, Managing Director, on 01752 423450. Individuals should preserve relevant evidence and must not attempt to conceal a breach.
Where Thrive is the controller, it will investigate, contain and recover the breach, assess the risk to individuals and document the incident. Where a breach is likely to result in a risk to individuals’ rights and freedoms, Thrive will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, affected individuals will also be informed without undue delay unless an exemption applies.
Where Thrive is acting as a processor, it will notify the relevant controller without undue delay and comply with applicable contractual and legal requirements.
13. Confidentiality and security
Anyone handling personal data for Thrive must keep it confidential, access only the information required for their role, use approved systems and processes, and take reasonable precautions against loss, unauthorised access or disclosure. Personal data must not be sent to personal accounts, left unsecured, or disclosed to unauthorised persons.
Suspected phishing, lost devices or documents, misdirected emails, unauthorised access, accidental disclosures and similar incidents must be reported promptly.
14. Recruitment and safeguarding information
Because Thrive recruits into education and SEND settings, it may process information required for safer recruitment and safeguarding, including identity documents, right-to-work evidence, employment history, references, qualifications, DBS-related information and relevant health or adjustment information. Such information will be processed only where lawful, necessary and proportionate, with access limited appropriately.
15. Complaints
Anyone with a concern or complaint about Thrive’s handling of personal data should contact Ryan Yeoman, Managing Director, on 01752 423450 or write to the registered office. Thrive will investigate concerns fairly and without undue delay.
Individuals also have the right to complain to the Information Commissioner’s Office (ICO). Current contact information is available from the ICO’s official website.
16. Responsibilities
The Board of Directors has overall responsibility for data protection governance. Ryan Yeoman, Managing Director, is the principal contact responsible for coordinating data protection matters, individual rights requests, data breach management and complaints. Thrive has not designated this role as a statutory Data Protection Officer unless and until the legal criteria requiring a DPO apply.
All directors, employees, workers and others processing data on Thrive’s behalf are responsible for following this policy and reporting concerns promptly.
17. Lawful processing conditions – Annex A
The lawful bases for ordinary personal data are consent, contract, legal obligation, vital interests, public task and legitimate interests, where the relevant statutory conditions are satisfied.
Special category data requires both a lawful basis under Article 6 UK GDPR and an additional condition under Article 9 UK GDPR and, where applicable, the Data Protection Act 2018.
Relevant conditions may include explicit consent, employment/social protection law, vital interests, legal claims, substantial public interest, occupational medicine or other conditions provided by law. Criminal offence data will only be processed where Article 10 UK GDPR and the Data Protection Act 2018 permit it.
18. Approval and review
This policy was adopted by the Board of Directors of Thrive Recruitment Group Plymouth Ltd on 03/09/2026. It will be reviewed annually and sooner where legislation, regulatory guidance, systems, suppliers or business activities materially change.
Signed: R.Yeoman
Name: Ryan Yeoman
Position: Managing Director
Date: 03/09/2026