CEDR's Privacy Policy

Centre for Effective Dispute Resolution and its group companies ("CEDR", "we", "us", or "our") are committed to protecting and respecting the personal data that we hold. This Privacy Notice explains why and how we collect and use personal data and provides information about individuals' rights. It applies to personal data provided to us both directly and indirectly.

CEDR Cust Service MJ 1

Personal data

Personal data is any information relating to an identified or identifiable living person.

When collecting and using personal data, we are committed to being transparent about the reasons for processing and how information is used.

Personal data may be obtained:

  • Directly from the individual concerned.

  • From another individual acting on their behalf.

  • From an organisation connected with the individual.

  • From publicly available sources such as Companies House and publicly accessible websites.

Data that we hold

CEDR processes personal data for a variety of purposes:

  • Providing Services to Clients
    Where CEDR provides mediation, adjudication, complaint handling, consultancy, training or dispute resolution services, personal data may be processed to fulfil contractual and operational requirements. Information may be provided directly by the individual concerned or by another party involved in a dispute, complaint or matter being handled by CEDR.
  • Client Management
    Personal data may be processed to communicate with clients and prospective clients and to ensure that services provided remain appropriate to their requirements.
  • Promoting Our Services
    We may use business contact details to provide information about dispute resolution, conflict management and related services.
    We do not use personal data obtained through consumer-facing services for marketing purposes without appropriate consent.
  • Administration
    Personal data may be processed to support business operations, including:
    - Internal business records.
    - Client and supplier management.
    - Event administration.
    - Financial administration.
    - Personnel administration.
  • Regulatory and Legal Requirements
    Personal data may be processed where necessary to comply with legal, regulatory or professional obligations, including identity verification and fraud prevention. The personal data processed may include contact details, correspondence, employee information, customer details, supplier details, financial information and other information relevant to the services being provided. Where necessary and relevant, we may also process special category personal data, including information relating to health, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sex life or sexual orientation, and criminal offence information.

Lawful Basis for Processing

We only process personal data where we have identified a lawful basis under UK GDPR.

Depending upon the circumstances, this may include:

  • Performance of a contract.

  • Compliance with a legal obligation.

  • Legitimate business interests.

  • Consent.

  • Protection of vital interests.

  • Performance of a task carried out in the public interest.

Complaints – Data Protection

If you have concerns about how we have handled your personal data, you have the right to make a formal complaint.
CEDR operates a dedicated Data Protection Complaints Process which explains how complaints can be submitted, investigated and resolved.

You can access our complaints process here. If you remain dissatisfied following the outcome of our internal process, you also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.

Security

We take the security of personal data seriously.  Staff receive training in:

  • Data protection.

  • Information security.

  • Confidentiality.

 

CEDR maintains a framework of information security policies, procedures and technical controls designed to protect information against unauthorised access, disclosure, alteration, misuse or loss.

Access to personal data is restricted to employees, agents, contractors and third parties who have a legitimate business need to know.

We maintain procedures for identifying, investigating and managing information security incidents and personal data breaches and will notify affected individuals and regulators where required by law.

We have also implemented safeguards to ensure that transfers of personal data outside the United Kingdom are carried out lawfully and subject to appropriate protections recognised under UK GDPR.

Retention period

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to meet legal, regulatory, contractual and operational requirements.

CEDR maintains a documented Data Retention & Disposal Policy and retention schedule which defines retention periods for different categories of information.

Examples include:

  • Case files, adjudications, mediation records and complaint files – 6 years after closure

  • Case management system records – 6 years after closure

  • Subject Access Requests and other rights requests – 3 years after closure

  • Data protection complaints – 6 years after closure

  • Data breach records and information security incident records – 6 years after closure

  • Telephone recordings – 6 months

  • Website enquiries – 2 years

  • Recruitment records for unsuccessful applicants – 12 months

  • Marketing contacts – 2 years after last engagement or withdrawal of consent


In some circumstances information may be retained beyond standard retention periods where required for:

  • Legal proceedings.

  • Regulatory investigations.

  • Complaints handling.

  • Audits.

  • Insurance claims.

  • Law enforcement requests.

  • Other legal or regulatory obligations.


When personal data is no longer required and any applicable retention period has expired, it will be securely deleted, destroyed or anonymised.

Information sharing and disclosure

CEDR does not sell, rent or trade personal information.

We may share personal data with trusted third-party service providers that help us deliver services and operate our business, including providers of:

  • Information technology services.

  • Cloud-based software.

  • Website hosting.

  • Data analysis.

  • Data backup.

  • Information security services.

  • Identity verification services.

 

We may also share information with mediators, adjudicators, consultants and trainers where necessary to deliver our services.  Appropriate contractual and security controls are implemented with all third parties processing personal data on our behalf.

We may also disclose personal data where required by law or where necessary to establish, exercise or defend legal rights.

Automated Decision-Making

CEDR does not generally make decisions about individuals solely through automated processing or profiling that produce legal or similarly significant effects. Where automated processing is used in connection with a particular service, appropriate information will be provided.

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

  • Be informed about how your personal data is used.

  • Access your personal data.

  • Correct inaccurate information.

  • Request erasure of personal data where appropriate.

  • Restrict processing in certain circumstances.

  • Object to processing in certain circumstances.

  • Request portability of your personal data where applicable.

  • Withdraw consent where processing relies on consent.

  • Complain about the handling of your personal data.

 

Further information is available from the Information Commissioner's Office.

The ICO's contact details are:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk

Telephone: 0303 123 1113

If you wish to exercise any of your rights or have any questions regarding your personal data, please contact:

Douglas O'Neil
Head of Operations & Data Protection Lead
Email: dpl@cedr.com

We will respond as soon as possible and, in most circumstances, within one calendar month.

Changes to this privacy notice

We may update this Privacy Notice from time to time to reflect changes in legislation, regulatory guidance, business activities or processing practices. The latest version will always be available on our website.

Company information

CEDR Services Limited (Company Number 03271988) is a wholly owned subsidiary of Centre for Effective Dispute Resolution Limited (Charity Number 1060369).
 
CEDR acts as a Data Controller under UK GDPR and the Data Protection Act 2018 and is registered with the Information Commissioner's Office under registration number Z7486946.

For the Independent Complaints Adjudication Service for Ofsted (ICASO), CEDR acts as a Data Processor on behalf of the Department for Education (DfE), which is the Data Controller.