Our site uses cookies

This site uses optional cookies for performance and quality purposes in line with out Cookie Policy.

Cyber Essentials Certification Body Data Protection Register

This register describes the personal data processed by us when administering Cyber Essentials.

    1. Purpose of this register
    2. We (Cannon Tomlinson Mansley Ltd, trading as ctm Information Technology) are an authorised Cyber Essentials Certification Body.
    3. This register describes the personal data processed by us when administering Cyber Essentials. It explains whose information is processed, why it is processed, the types of information involved and the applicable retention periods.
    4. This register relates specifically to personal data processed as part of our Cyber Essentials Certification Body activities. It should be read alongside our general privacy information and terms.
    1. Categories of data subject
    2. Personal data may be processed about the following categories of individual:
    3. Business contacts representing organisations applying for Cyber Essentials certification
    4. Business contacts involved in the administration, payment or management of a certification application
    5. Individuals communicating with us about a Cyber Essentials assessment
    1. Purpose of the processing
    2. Personal data is processed where necessary for the performance and administration of contracts relating to Cyber Essentials certification services.
    3. The processing supports the following activities:
    4. Receiving and managing certification enquiries
    5. Managing Cyber Essentials certification applications
    6. Administering assessments and certification decisions
    7. Communicating with applicants and their authorised representatives
    8. Producing assessment reports and certification records
    9. Managing invoices and payments
    10. Managing Certification Body and assessor licences
    11. Supporting quality assurance, moderation, complaints and appeals
    12. Meeting contractual, regulatory and Cyber Essentials scheme requirements
    1. How personal data is processed
    2. Processing may include:
    3. Receiving information through email, telephone, online forms or direct customer communication
    4. Creating and maintaining customer and certification case records
    5. Entering and reviewing information within the approved Cyber Essentials assessment platform
    6. Reviewing assessment responses, supporting evidence and technical information
    7. Communicating assessment questions, clarification requests, decisions and feedback
    8. Generating reports, certificates, invoices and management information
    9. Maintaining records needed for quality assurance, audit and compliance purposes
    10. Securely deleting information when the applicable retention period expires
    1. Categories of personal data
    2. The personal data processed may include:
    3. Name
    4. Job title or business role
    5. Organisation name
    6. Business postal address
    7. Business telephone number
    8. Business email address
    9. Internet Protocol address details
    10. Information contained in certification applications, assessment responses and supporting attachments
    11. Records of communications relating to an enquiry, application or assessment
    12. Invoice, payment and transaction administration information
    13. Certification, assessor and Certification Body licence information
    14. Applicants should not provide special-category personal data, criminal-offence data or unrelated personal information unless it is specifically required and there is a lawful and authorised reason for doing so.
    1. Data storage
    2. Formal Cyber Essentials assessment information is processed through the approved Cyber Essentials assessment platform.
    3. Where we needs to retain information outside the assessment platform, it is held within access-controlled business systems used for Cyber Essentials Certification Body records.
    4. Access is limited to authorised personnel who require the information to administer, assess, quality-assure or manage the certification service.
    1. Retention periods
    2. Personal data is retained only for the period applicable to the relevant type of record. At the end of the applicable retention period, copies held by us will be securely deleted unless continued retention is required by law, an investigation, a complaint, an appeal, a legal hold or another authorised requirement.
    3. Assessment answers, comments and attachments before submission

      Before submission, assessment answers, comments and attachments are retained online in the approved assessment platform for up to six months from the application date.

      They may be retained for longer where this is requested by the applicant or Certification Body.

    4. Assessment answers and comments after submission

      After submission, assessment answers and comments are retained in the approved assessment platform for 18 months from the date on which the last report was run.

    5. Cyber Essentials feedback reports

      Copies of Cyber Essentials feedback reports held by us are retained for 18 months from the date of the final report, whether the assessment resulted in a pass or fail.

    6. Supporting assessment evidence

      Supporting evidence held by us is retained only for as long as necessary to complete and support the assessment.

    7. Where the evidence is retained as part of the formal assessment record, it will normally be deleted no later than 18 months after the final report unless another authorised retention requirement applies.
    8. Declarations and branding agreements

      Declarations and branding agreements held by us are retained for 18 months from the date of the final report, whether the assessment resulted in a pass or fail.

    9. Certificate data

      Certificate data, including the applicant contact email address, is stored within the applicable certificate registry and customer relationship management systems indefinitely.

    10. Invoice and payment data

      Invoice and payment data is retained for six years plus the current financial year, in accordance with applicable financial record-keeping requirements.

    11. Certification Body licence data

      Certification Body licence data is retained for two years after the end of the applicable Certification Body contract.

    1. Information sharing
    2. Information may be shared where necessary with the organisations responsible for administering, assuring or overseeing the Cyber Essentials scheme.
    3. This may include IASME, the National Cyber Security Centre and organisations operating approved assessment, certification, registry or quality-assurance systems.
    4. Information may also be disclosed where required by law, a competent regulatory authority or a valid legal process.
    5. We do not permit personal data obtained through the certification process to be used for unrelated purposes.
    1. Data security
    2. We apply appropriate organisational and technical controls to protect Cyber Essentials certification information.
    3. These controls include access restrictions, identity and access management, audit logging, encryption, secure configuration, information classification, incident management and controlled data deletion.
    4. Suspected loss, unauthorised access, disclosure or misuse of Cyber Essentials information is managed through our formal information security incident management process.
    1. Accuracy of information
    2. Applicants and their authorised representatives are responsible for ensuring that information submitted as part of a certification application is accurate, complete and up to date.
    3. If a business contact becomes aware that their personal information is incorrect, they should contact us so that the record can be reviewed and, where appropriate, corrected.
    1. Data protection enquiries
    2. Questions about personal data processed by us in connection with Cyber Essentials certification should be directed to: privacy@ctm-it.com
    3. Please include sufficient information to identify the relevant certification application or enquiry.
    4. Sensitive assessment evidence should not be sent by email unless it has been specifically requested and an approved secure transfer method has been agreed.
    1. Changes to this register
    2. This register may be updated when our processing activities change or when the Cyber Essentials scheme, contractual requirements or applicable data protection requirements are revised.