PRODUCT STEWARDSHIP Scientific rigour. Practical assurance.
LEGAL

GDPR & Data Protection Policy

How we govern data protection within our own organisation.

Last updated: 5 August 2026

This policy sets out Product Stewardship Ltd’s commitment to protecting personal data and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025. It applies to all personal data we process, whether relating to clients, prospective clients, suppliers, or our own personnel, and to everyone who processes personal data on our behalf. We publish this policy so that clients and partners who need to assess our data governance as part of their own supplier due diligence can do so directly.

1. Our commitment

We are committed to processing personal data lawfully, fairly and transparently, and to respecting the rights of everyone whose data we hold. This is a standing commitment across the business, applied with the same rigour we bring to our clients’ own regulatory positions.

2. Data protection principles

We process personal data in accordance with the data protection principles set out in Article 5 of UK GDPR. Personal data must be:

  • Processed lawfully, fairly and in a transparent manner
  • Collected for specified, explicit and legitimate purposes, and not further processed in a manner incompatible with those purposes
  • Adequate, relevant and limited to what is necessary
  • Accurate and kept up to date
  • Kept for no longer than necessary
  • Processed in a manner that ensures appropriate security

We are also accountable for being able to demonstrate compliance with these principles.

3. Roles and responsibilities

Product Stewardship Ltd has no employees; overall responsibility for data protection compliance sits with our director. Where we engage subcontractors or advisers who handle personal data on our behalf, they are required to follow this policy and our related procedures, and to raise any data handling concerns promptly.

4. Lawful basis for processing

Before we process personal data, we identify an appropriate lawful basis under Article 6 of UK GDPR — most commonly legitimate interests (for responding to enquiries and maintaining client relationships), legal obligation (for accounting and regulatory record-keeping), or consent (where required, for example for certain cookies).

5. Data subject rights

We have procedures in place to recognise and respond to individuals exercising their rights under UK GDPR, including the right of access, rectification, erasure, restriction, portability, objection, and the right to complain, whether made to us directly or to the Information Commissioner’s Office. We aim to respond to any request within one calendar month.

6. Data Protection Impact Assessments

Where we introduce a new process, system or service likely to result in a high risk to individuals’ rights and freedoms, we carry out a Data Protection Impact Assessment (DPIA) before processing begins, to identify and mitigate risks.

7. Data security

We maintain appropriate technical and organisational measures to protect personal data, including access controls, secure storage, and regular review of the systems and third parties we use to process data on our behalf.

8. Data breach reporting

We have a procedure in place to identify, assess, contain and report any personal data breach. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and will notify affected individuals directly where the breach is likely to result in a high risk to them.

9. Third-party processors and due diligence

Where we use third-party suppliers to process personal data on our behalf, we carry out appropriate due diligence and put a data processing agreement in place, so that data is handled to the same standard we apply ourselves.

10. International transfers

Where personal data is transferred outside the UK, we ensure an appropriate transfer mechanism is in place, such as the UK’s International Data Transfer Agreement or an applicable adequacy decision.

11. Training and awareness

We keep our own understanding of data protection requirements current as part of the same discipline we apply to regulatory change more broadly, and review our practices periodically to ensure they remain appropriate to how the business operates.

12. Review of this policy

This policy is reviewed periodically and updated where necessary to reflect changes in law, guidance from the Information Commissioner’s Office, or our own practices.

13. Contact us

Questions about this policy, or about how we handle personal data, can be sent to support@ps-ltd.co.uk or 07584 073 768.

Product Stewardship

Need help with REACH, CLP or material compliance?

Get specialist regulatory and material assurance support across the UK, EU, industry and defence sectors — REACH, CLP, BPR, DSEAR and the evidence to back it up.

Call 07584 073 768 Contact Us
Email queries: support@ps-ltd.co.uk

Product Stewardship Ltd provides specialist regulatory support, material assurance and compliance training for organisations operating across the UK, EU, industry and defence sectors.

Coverage: UK, EU & Defence sectors
Regulators: HSE & ECHA
Contact & Help

Speak to us about REACH, CLP, defence material assurance, training or workplace compliance.

© 2026 Product Stewardship Ltd
Product Stewardship Ltd · Registered in England & Wales, Company No. 12143264 · Registered office: 140 Lee Lane, Horwich, BL6 7AF · VAT No. GB430 9538 93