GDPR Information Governance & Data Protection
Protecting your information is fundamental to how we work.
At Carswell Gould, we understand that our clients trust us with commercially sensitive information, intellectual property and personal data. We take that responsibility seriously.
Our approach goes beyond simply complying with the UK General Data Protection Regulation (UK GDPR). We have established a broader Information Governance framework that helps ensure information is handled securely, responsibly and transparently throughout every client relationship.
Whether we’re developing a brand strategy, managing a PR campaign, producing creative content or delivering digital solutions, safeguarding your information is embedded into the way we work.
Our Commitment
We are committed to:
- Complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Protecting personal data and commercially sensitive information entrusted to us.
- Maintaining appropriate technical and organisational security measures.
- Using Artificial Intelligence responsibly, securely and with meaningful human oversight.
- Working transparently with our clients on information governance and compliance.
- Continually reviewing our policies and working practices to reflect changes in legislation, technology and industry best practice.
Information Security
We operate a secure, cloud-first technology environment using trusted commercial platforms and recognised industry best practices.
Our security measures include, where appropriate:
- Role-based access controls
- Multi-factor authentication
- Secure cloud storage
- Password management
- Encryption where appropriate
- Endpoint protection
- Secure backup and recovery procedures
- Regular software updates
- Staff security awareness training
Our systems and working practices are reviewed periodically to ensure they remain appropriate to the services we provide.
Data Protection
Where Carswell Gould processes Personal Data on behalf of a client, we act as a Data Processor under the UK GDPR.
We will only process personal data:
- under documented client instructions;
- for the agreed purpose;
- using appropriate security measures;
- for no longer than necessary.
We apply the principle of data minimisation and only request information that is reasonably required to deliver the agreed services.
Responsible Artificial Intelligence
Artificial Intelligence has become an important tool in modern marketing, communications and creative services. Carswell Gould uses approved commercial AI technologies responsibly to improve productivity, research, content development and creative workflows.
Our principles are straightforward:
- AI supports our peopleāit does not replace professional expertise.
- Every AI-assisted output is reviewed by experienced members of our team before being delivered to a client.
- We do not knowingly use client or tenant information to train public AI models.
- We only use commercially approved AI platforms that meet appropriate security and governance standards.
- Confidentiality, intellectual property and data protection remain central to every project.
Working With Clients
Every organisation has different governance, security and procurement requirements.
Where clients require:
- a Data Processing Agreement (DPA);
- supplier assurance documentation;
- information security responses;
- AI governance information; or
- bespoke contractual data protection provisions,
we are happy to review and work collaboratively to agree appropriate arrangements wherever they are reasonable, proportionate and consistent with applicable legislation.
Our aim is always to make working with Carswell Gould straightforward, transparent and secure.
Our Governance Framework
Our Information Governance framework is supported by a number of policies and procedures, including:
- Information Governance & Data Processing Policy
- Privacy Policy
- Cookie Policy
- Terms & Conditions
- Responsible AI Policy and Procedures
- Internal Information Security Procedures
Copies of relevant documents are available upon request where appropriate.
Have a Question?
If you would like to discuss how Carswell Gould protects your information, or if your organisation has specific information governance or supplier assurance requirements, we’d be happy to help.
Email: [email protected]
Need a Data Processing Agreement?
Many organisations require suppliers to complete information governance or data protection checks before work begins. If your organisation requires a Data Processing Agreement (DPA), supplier questionnaire or information security documentation, please get in touch. We’ll be happy to provide our standard documentation or review your own requirements as part of the onboarding process.