Enigma Partners Global

Governance

Data Protection Policy

Enigma Partners Global Limited — SC893958 — ICO registration C1969786 — Version 1.0, 26 July 2026

1. Policy statement

Enigma Partners Global Limited (“Enigma”) is committed to processing personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any successor legislation. This policy sets out our obligations as a data controller and, where applicable, as a data processor acting on behalf of clients.

Enigma is registered with the Information Commissioner’s Office (ICO) under registration reference C1969786.

2. Scope

This policy applies to:

  • →All personal data processed by Enigma in the course of its business activities
  • →All Enigma personnel, including employees and associate consultants
  • →All systems, tools, and third-party services used to process personal data

It covers data held in digital and physical formats, including email, cloud storage (Microsoft OneDrive/SharePoint), AI-assisted tools, and any client deliverables containing personal data.

3. Data protection principles

We process personal data in accordance with the six principles set out in Article 5 UK GDPR:

Principle What this means for Enigma
Lawfulness, fairness, transparency We identify a lawful basis before processing. We are transparent with data subjects about how their data is used.
Purpose limitation Personal data is collected for specified, explicit purposes and not processed in incompatible ways.
Data minimisation We collect only the personal data necessary for the stated purpose.
Accuracy Personal data is kept accurate and up to date. Inaccurate data is corrected or deleted promptly.
Storage limitation Data is not kept longer than necessary. See section 7 for our retention schedule.
Integrity and confidentiality Personal data is protected by appropriate technical and organisational security measures.

4. Lawful basis for processing

Contract — processing necessary for the performance of a contract, or to take steps before entering one (e.g. client contact data, consultant engagement records).

Legitimate interests — processing necessary for Enigma’s legitimate business interests where not overridden by data subject rights (e.g. business development records, prospect contact data). Legitimate interest assessments are documented and available on request.

Legal obligation — processing required to comply with a legal or regulatory obligation (e.g. HMRC records, Companies House filings).

Consent — where none of the above bases applies, we will seek explicit consent before processing. Consent records are maintained and consent can be withdrawn at any time.

5. Special category data

Enigma does not routinely process special category data in the course of its advisory activities. Where client engagement requires access to special category data processed by the client (for example, as part of a DPIA or governance audit), we will identify the appropriate Schedule 1 condition under DPA 2018, ensure our Data Protection Lead reviews and approves the arrangement, and record the processing in our Records of Processing Activities (ROPA).

6. Individual rights

Right How Enigma responds
Access (SAR) Responded to within one calendar month. Verified via email from the requestor’s registered address.
Rectification Inaccurate data corrected within one calendar month of notification.
Erasure Data erased where no overriding legal obligation to retain exists, within one calendar month.
Restriction Processing restricted on request where the legal basis for restriction applies.
Portability Data provided in machine-readable format where processing is by automated means and based on consent or contract.
Object Objections to legitimate interest processing considered promptly; processing stopped unless compelling grounds override.
Automated decisions Enigma does not make solely automated decisions with significant individual effects. Where AI tools are used, a human review step is maintained.

All rights requests: douglas.trainer@enigmapartnersglobal.com

7. Data retention

Data category Retention period Basis
Client contact and engagement records 6 years from end of engagement Limitation Act 1980; professional liability
Financial and invoicing records 6 years from end of tax year HMRC requirement
Prospect and BD contact records 2 years from last contact Legitimate interest; reviewed annually
Associate records 6 years from end of engagement Employment and contract law
Incident and breach records 5 years from date of incident ICO accountability requirement
Email correspondence 3 years (routine) / 6 years (contentious) Proportionality / Limitation Act

8. Data security

Technical and organisational measures in place:

  • →Microsoft 365 Business Premium — all data encrypted in transit and at rest
  • →Multi-factor authentication (MFA) enforced on all accounts
  • →Device encryption on all working devices
  • →Access controls limiting personal data access to those with a business need
  • →Secure deletion procedures for data no longer required

Douglas Trainer holds ISO/IEC 27001:2013 Lead Auditor qualification. ISO 27001 information security management principles are applied to Enigma’s internal operations. Cyber Essentials Plus certification is in progress (anticipated Q4 2026).

9. Data breach management

In the event of a personal data breach, Enigma will:

  • →Identify and contain the breach as a priority
  • →Assess the risk to affected individuals
  • →Notify the ICO within 72 hours where the breach is likely to result in a risk to individual rights and freedoms
  • →Notify affected individuals without undue delay where there is a high risk to their rights and freedoms
  • →Record all breaches in our breach register regardless of whether notification is required

10. International data transfers

Enigma’s primary data processing occurs within the UK and EEA. Where personal data is transferred outside the UK/EEA (for example, through cloud services with non-UK/EEA data centres), we ensure an appropriate transfer mechanism is in place: an adequacy decision, International Data Transfer Agreement (IDTA), or equivalent. Microsoft 365 processes data under IDTAs and the EU-US Data Privacy Framework.

11. AI and automated processing

Enigma uses AI-assisted tools internally and in service delivery. Our AI governance policy ensures:

  • →All AI tools processing personal data are assessed for GDPR compliance before deployment
  • →AI-generated outputs that may affect individuals are subject to human review
  • →EU AI Act Article 50 transparency obligations are met for AI-generated client-facing content
  • →Clients are informed where AI tools are used in delivering their engagement

Enigma Comply, our internal governance platform, is operated under a published AI System Card (EPG-COMPLY-AISC-001) aligned to ISO 42001 and EU AI Act Article 13 transparency requirements.

12. Framework compliance

Our data protection practices are aligned to:

  • →UK GDPR and Data Protection Act 2018
  • →ISO/IEC 27001:2013 Information Security Management
  • →ISO/IEC 42001:2023 AI Management System
  • →NIST AI Risk Management Framework
  • →NIST Cybersecurity Framework
  • →EU AI Act (Article 50 and Annex III obligations)
  • →ICO guidance on privacy by design, DPIAs, and automated decision-making

Data protection contact

Glenn Hunter

Data Protection Lead — Certified DPO

gwphunter@outlook.com

+44 7494 792453

Douglas Trainer

Managing Partner

douglas.trainer@enigmapartnersglobal.com

+44 7863 787 968

Policy review

This policy is reviewed annually by the Managing Partner, or following any significant data breach, material change to our data processing activities, or change in applicable legislation. Next scheduled review: July 2027.

Douglas Trainer

Managing Partner, Enigma Partners Global Limited

SC893958 — Registered in Scotland

Version 1.0 — Published 26 July 2026