Privacy policy for Business.gov.uk user research panel
Purpose of this document
The Department for Business and Trade (DBT) is committed to protecting the privacy and security of your information.
This privacy policy describes how we collect and use personal information about you in accordance with UK Data Protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are required under data protection legislation to notify you of the information contained in this privacy policy. It is important that you read this policy so that you are aware of how and why we are using your information.
What data we collect
Personal data we collect includes your:
- name
- job title
- business email address
- business telephone number
- company name
- business type
Why we need your data
The information you provide will be processed by DBT and selected third parties in order to make our websites and services better by learning from the people who use them. You can view the privacy policy for other government departments, agencies, public bodies and third party service providers.
The information or data you share with us will only be used for improving government websites and services. Your answers will help ensure that you participate in user research that is relevant to you.
Other purposes which may be relevant (to be considered on a case-by-case basis) are to:
- gather feedback to improve our services
- respond to any feedback you send us, if you have asked us to
Lawful basis for processing
Our lawful basis for processing your personal data is that the processing is necessary:
- to perform a task in the public interest (Article 6(1)(e) of the UK GDPR and section 8 of the Data Protection Act 2018
- for the exercise of our functions as a government department
How we share your information
We will, in some circumstances and where the law allows, share your data with other government departments, agencies, public bodies, and third-party service providers which may include, but are not limited to:
- Government Digital Service (GDS)
- Foreign and Commonwealth Development Office (FCDO)
- other UK government departments
You will be notified if your information is shared with other third parties not included in this list.
Aggregated analysis of responses may also be shared with:
- Information Commissioner’s Office (ICO)
- Government Internal Audit Agency (GIAA)
- National Audit Office (NAO)
We will not:
- sell or rent your data to third parties
- share your data with third parties for their marketing purposes
We will also share your data if we are required to do so by law or regulation, for example, by court order or to prevent fraud or other crime.
How long we keep your data
In line with our records management and retention and disposal policy, we will only retain your personal information for as long as:
- you agree
- it is needed for the purposes set out in this document
- the law requires us to
We will email you annually to reconfirm your agreement. Contact us at any time if you would like us to remove your data. We will retain your personal data until you unsubscribe or withdraw your agreement to process your personal data.
How we protect your data and keep it secure
We are committed to doing all that we can to keep your data secure. We have set up systems and processes to prevent unauthorised access or disclosure of your data. For example, we protect your data using varying levels of encryption. All personal data is stored in the European Economic Area (EEA).
We also ensure that any third parties keep all personal data they process on our behalf secure.
Contacting you
We will use the personal information you provide to contact you to about taking part in user research activities to make our services better. You can choose which activities you wish to take part in. You can also choose to unsubscribe at any time.
If you unsubscribe, we will not send research participation offers. We will also delete your information from our system.
You can find a link to unsubscribe in any of the emails from us.
We rely on the ‘public task’ lawful basis when sending promotional messages to carry out DBT’s public tasks or functions (Article 6(1)(e) of the UK GDPR and section 8 of the Data Protection Act 2018). This is without prejudice to your right to object and to exercise other applicable rights available under the regulation. The full details of data subjects’ rights and how to contact us are provided below.
Your rights
When processing personal data under the public task lawful basis, you have the following rights:
- Right to be informed: you have the right to be informed about the collection and use of your personal data
- Right of access: you can request access to your personal data
- Right to rectification: you can request correction of inaccurate or incomplete personal data
- Right to restrict processing: you can request the restriction of processing of your personal data in certain circumstances
- Right to object: you have the right to object to the processing of your personal data
Please note that the right to erasure and right to data portability do not apply when processing is based on public task.
Contact us
If you have any requests relating to your rights or have questions about this privacy policy and how we handle your personal information, you can contact:
Data Protection Officer
Department for Business and Trade
Old Admiralty Building
Whitehall
LONDON
SW1A 2DY
Email: data.protection@businessandtrade.gov.uk
Information Commissioner’s Office
Contact the Information Commissioner for independent advice about data protection, privacy, and data-sharing issues.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Textphone: 01625 545860
Email: casework@ico.org.uk
Changes to this privacy policy
We reserve the right to update this privacy policy at any time and we will provide you with a new privacy policy when we make any substantial updates.
Confidentiality
Information provided whilst using this service, including personal information, may be disclosed in accordance with access to information regimes, primarily the Freedom of Information Act 2000 (FOIA).
If you want the information you provide to be treated confidentially, please be aware that, in accordance with the FOIA, public authorities are required to comply with a statutory code of practice that addresses obligations of confidence, among other things.