Cyber Essentials Certification Body Data Protection Register
This register describes the personal data processed by us when administering Cyber Essentials.
Purpose of this register
We (Cannon Tomlinson Mansley Ltd, trading as ctm Information Technology) are an authorised Cyber Essentials Certification Body.
This register describes the personal data processed by us when administering Cyber Essentials. It explains whose information is processed, why it is processed, the types of information involved and the applicable retention periods.
This register relates specifically to personal data processed as part of our Cyber Essentials Certification Body activities. It should be read alongside our general privacy information and terms.
Categories of data subject
Personal data may be processed about the following categories of individual:
Business contacts representing organisations applying for Cyber Essentials certification
Business contacts involved in the administration, payment or management of a certification application
Individuals communicating with us about a Cyber Essentials assessment
Purpose of the processing
Personal data is processed where necessary for the performance and administration of contracts relating to Cyber Essentials certification services.
Administering assessments and certification decisions
Communicating with applicants and their authorised representatives
Producing assessment reports and certification records
Managing invoices and payments
Managing Certification Body and assessor licences
Supporting quality assurance, moderation, complaints and appeals
Meeting contractual, regulatory and Cyber Essentials scheme requirements
How personal data is processed
Processing may include:
Receiving information through email, telephone, online forms or direct customer communication
Creating and maintaining customer and certification case records
Entering and reviewing information within the approved Cyber Essentials assessment platform
Reviewing assessment responses, supporting evidence and technical information
Communicating assessment questions, clarification requests, decisions and feedback
Generating reports, certificates, invoices and management information
Maintaining records needed for quality assurance, audit and compliance purposes
Securely deleting information when the applicable retention period expires
Categories of personal data
The personal data processed may include:
Name
Job title or business role
Organisation name
Business postal address
Business telephone number
Business email address
Internet Protocol address details
Information contained in certification applications, assessment responses and supporting attachments
Records of communications relating to an enquiry, application or assessment
Invoice, payment and transaction administration information
Certification, assessor and Certification Body licence information
Applicants should not provide special-category personal data, criminal-offence data or unrelated personal information unless it is specifically required and there is a lawful and authorised reason for doing so.
Data storage
Formal Cyber Essentials assessment information is processed through the approved Cyber Essentials assessment platform.
Where we needs to retain information outside the assessment platform, it is held within access-controlled business systems used for Cyber Essentials Certification Body records.
Access is limited to authorised personnel who require the information to administer, assess, quality-assure or manage the certification service.
Retention periods
Personal data is retained only for the period applicable to the relevant type of record. At the end of the applicable retention period, copies held by us will be securely deleted unless continued retention is required by law, an investigation, a complaint, an appeal, a legal hold or another authorised requirement.
Assessment answers, comments and attachments before submission
Before submission, assessment answers, comments and attachments are retained online in the approved assessment platform for up to six months from the application date.
They may be retained for longer where this is requested by the applicant or Certification Body.
Assessment answers and comments after submission
After submission, assessment answers and comments are retained in the approved assessment platform for 18 months from the date on which the last report was run.
Cyber Essentials feedback reports
Copies of Cyber Essentials feedback reports held by us are retained for 18 months from the date of the final report, whether the assessment resulted in a pass or fail.
Supporting assessment evidence
Supporting evidence held by us is retained only for as long as necessary to complete and support the assessment.
Where the evidence is retained as part of the formal assessment record, it will normally be deleted no later than 18 months after the final report unless another authorised retention requirement applies.
Declarations and branding agreements
Declarations and branding agreements held by us are retained for 18 months from the date of the final report, whether the assessment resulted in a pass or fail.
Certificate data
Certificate data, including the applicant contact email address, is stored within the applicable certificate registry and customer relationship management systems indefinitely.
Invoice and payment data
Invoice and payment data is retained for six years plus the current financial year, in accordance with applicable financial record-keeping requirements.
Certification Body licence data
Certification Body licence data is retained for two years after the end of the applicable Certification Body contract.
Information sharing
Information may be shared where necessary with the organisations responsible for administering, assuring or overseeing the Cyber Essentials scheme.
This may include IASME, the National Cyber Security Centre and organisations operating approved assessment, certification, registry or quality-assurance systems.
Information may also be disclosed where required by law, a competent regulatory authority or a valid legal process.
We do not permit personal data obtained through the certification process to be used for unrelated purposes.
Data security
We apply appropriate organisational and technical controls to protect Cyber Essentials certification information.
These controls include access restrictions, identity and access management, audit logging, encryption, secure configuration, information classification, incident management and controlled data deletion.
Suspected loss, unauthorised access, disclosure or misuse of Cyber Essentials information is managed through our formal information security incident management process.
Accuracy of information
Applicants and their authorised representatives are responsible for ensuring that information submitted as part of a certification application is accurate, complete and up to date.
If a business contact becomes aware that their personal information is incorrect, they should contact us so that the record can be reviewed and, where appropriate, corrected.
Data protection enquiries
Questions about personal data processed by us in connection with Cyber Essentials certification should be directed to: privacy@ctm-it.com
Please include sufficient information to identify the relevant certification application or enquiry.
Sensitive assessment evidence should not be sent by email unless it has been specifically requested and an approved secure transfer method has been agreed.
Changes to this register
This register may be updated when our processing activities change or when the Cyber Essentials scheme, contractual requirements or applicable data protection requirements are revised.