Data Handling and Confidentiality Policy

Last updated: July 2026

Version 6

© Nadine Powrie Consultancy Limited. All rights reserved.


Policy owner Nadine Powrie, Director

Data Protection Officer Phil Powrie philpowrie@nadinepowrie.com

Company registration 10279740 (registered in England and Wales)

Registered office The Old Bakery, 90 Camden Road, Tunbridge Wells, Kent, TN1 2QP

Next review September 2026


Purpose

This policy sets the minimum requirements followed by Nadine Powrie Consultancy Limited (the Company) when receiving, being granted access to, viewing, using, storing, sharing, returning or deleting confidential information and personal data. It is designed to give clients clear assurance about how information entrusted to us is handled.

It should be read alongside the relevant engagement contract, any non-disclosure or data-processing agreement, the client's security instructions and our Privacy Policy. Where a client requirement is more stringent, the client requirement takes priority. This policy does not govern website cookies or direct marketing, which are addressed in our Privacy Policy.


Scope

This policy applies to every director, employee, contractor or other person authorised to act for the Company. Unless the client agrees otherwise in writing, access to client confidential material is limited to the lead consultant, Nadine Powrie.

It covers information in any form, including documents sent directly to the Company and documents made available through shared drives, collaborative platforms, data rooms or client portals, as well as emails, messages, meeting content, images, recordings, handwritten notes, system access and verbal disclosures. Examples include:

  • personal data and special category data, including health, equality, disciplinary or other sensitive information;

  • information relating to staff, pupils or students, clients, leaders, service users and other identifiable individuals;

  • safeguarding, human resources, complaints, performance, governance, inspection, legal and regulatory material;

  • financial, strategic, operational and commercially sensitive information;

  • passwords, access credentials and information about client systems or security arrangements.

The confidentiality requirements in this policy apply whether or not the information is personal data and continue after an engagement ends.


Definitions

  • Personal data — information relating to an identified or identifiable living individual.

  • Special category data — personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health, sex life or sexual orientation. Criminal offence data is subject to equivalent safeguards.

  • Controller — the party that determines the purposes and means of processing.

  • Processor — a party that processes personal data on a controller's documented instructions.

  • Processing — any operation performed on personal data, including collecting, viewing, storing, sharing, altering and deleting.

  • Personal data breach — a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.


Legal and professional framework

Where personal data is involved, the Company handles it in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018, as amended. Our approach reflects the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability.

The Company is the data controller for its own business administration, such as contracts, invoicing, coaching and mediation records and professional correspondence. When the Company handles personal data solely on a client's documented instructions, the client will normally be the controller and the Company the processor. The precise roles and responsibilities will be confirmed in the contract or data-processing agreement for the engagement.


Lawful bases (controller activities). Where the Company acts as controller it relies on: performance of a contract, for delivering agreed services and administering engagements; legal obligation, for accounting, tax and regulatory record-keeping; and legitimate interests, for professional correspondence, service improvement and the security of its systems, subject to a balancing assessment.


Special category and criminal offence data. Where such data is processed in a controller capacity, the Company relies on explicit consent, on the establishment, exercise or defence of legal claims, or on the safeguarding of children and individuals at risk under Schedule 1 to the Data Protection Act 2018, as applicable. Where a Schedule 1 condition requires it, the Company maintains an Appropriate Policy Document, which is available to clients on request.

Where the Company acts as processor, the lawful basis is determined by the client as controller and recorded in the engagement documentation.


Professional standards. Nadine Powrie is a member of the Chartered Institute of Personnel and Development and of the European Mentoring and Coaching Council. The Company's practice is governed by the ethical standards of those bodies alongside its legal obligations, iincluding the CIPD Code of Conduct and Ethics and Professional Standards, and the Global Code of Ethics adopted by the EMCC. The confidentiality commitments in sections 10 and 11 derive from those codes as well as from data protection law. Where a professional code sets a higher standard than this policy, the higher standard applies.


Accountability and responsibilities

Nadine Powrie, as lead director, is accountable for the Company's data protection compliance and for decisions about the organisational and technical controls applied to client information.

The Company is registered with the Information Commissioner's Office under reference ZA791471, and Phil Powrie is recorded on that registration as the Company's Data Protection Officer. The Data Protection Officer monitors compliance with this policy and with applicable data protection law, advises on data protection impact assessments and other obligations, acts as the contact point for the Information Commissioner's Office and for individuals whose personal data is processed, and reports to the Company's directors.

The Data Protection Officer holds no operational role in the Company, receives no salary and takes no part in the delivery of client services. He does not determine the purposes or means of processing, and he is not instructed on how to perform the role. This separation is maintained so that the Data Protection Officer can advise and monitor independently, in accordance with Articles 38 and 39 of the UK GDPR. The appointment is made voluntarily; the Company's processing does not meet the mandatory criteria in Article 37.

The lead consultant is responsible for applying this policy to each engagement, following client instructions and escalating any uncertainty before using or sharing information.

Before accessing confidential material, the Company will clarify, as appropriate:

  • the purpose and expected duration of access;

  • the categories of information and people involved;

  • whether special category, criminal offence, safeguarding or children's data is present;

  • the approved systems and transfer methods;

  • any restrictions on downloading, printing, copying, recording or onward sharing; and

  • the arrangements for return, deletion and incident reporting.

Where the Company considers that a client instruction would breach data protection law, it will inform the client promptly and will not act on the instruction until the position is resolved.


Access control

Access is granted on a need-to-know and least-privilege basis. Client material will be accessed only to the extent necessary to deliver the agreed services.

  • Individual accounts and unique credentials must be used; passwords and accounts must never be shared.

  • Multifactor authentication must be enabled wherever the client or service supports it.

  • Access links, passwords and authentication codes must be protected and must not be forwarded without permission.

  • A second director, contractor or adviser may access client material only where this is necessary, the client has authorised it in writing, and that person is bound by appropriate confidentiality obligations.

  • Access must be removed promptly when it is no longer required or when the engagement ends.


Secure receipt, access and storage

Client-controlled systems are used wherever reasonably available. These may include Google Drive, Microsoft SharePoint or OneDrive, secure data rooms and client portals. Documents may be downloaded where this is necessary to deliver the agreed services and is permitted by the client. Any downloaded copy will be held only on an authorised encrypted device or approved business system, accessible only to authorised users, and deleted as soon as it is no longer required. Where downloading is not necessary or permitted, documents will remain within the client's approved platform.

If temporary Company storage is necessary and authorised:

  • only approved business accounts, the Company's Microsoft 365 environment and authorised devices may be used;

  • devices must be protected by strong authentication, full-disk encryption, supported software, security updates and automatic screen locking;

  • data in transit must be protected by current encryption standards; unencrypted transfer of confidential material is not permitted;

  • confidential material must not be stored in personal email, personal cloud storage, consumer file-sharing accounts or unencrypted removable media;

  • email attachments must be avoided where a secure portal or restricted link is available; where email is necessary, the recipient must be verified and additional protection used according to the risk;

  • confidential material must not be treated as the sole unprotected local copy of any record;

  • temporary downloads and working copies must be removed as soon as their purpose has been completed.

Business systems are backed up so that access to information can be restored in a timely manner following an incident, and restoration arrangements are reviewed periodically.

Printing is avoided. If a paper copy is genuinely necessary and authorised, it must be kept under the direct control of the authorised user or in locked storage, must not be left unattended and must be cross-cut shredded or returned when no longer required.


Shared drives and collaborative platforms

Documents made available through Google Drive, SharePoint, OneDrive or another collaborative platform are covered by this policy even though no file has been emailed or transferred to the Company. Viewing, searching, commenting on, editing, downloading, synchronising, copying or changing access to a shared document are all forms of handling.

  • access must be through the named business account authorised by the client and protected by multifactor authentication wherever available;

  • the Company will access only the folders and documents necessary for the engagement and will not browse unrelated material, even if wider access has been granted inadvertently;

  • documents and folders may be downloaded, copied, printed or made available offline only where this is necessary for the agreed work and permitted by the client; they must not be re-shared, moved or linked publicly without specific authority;

  • the Company will not change sharing permissions, add users or create an 'anyone with the link' access route unless specifically instructed by the client;

  • unexpected, excessive or continuing access will be reported to the client rather than used; and

  • at the end of the engagement, shortcuts, bookmarks, synchronised or offline copies will be removed and the client will be asked to withdraw the Company's access.

If the Company creates a shared folder or collaborative document for an engagement, it will use an approved business account, restrict access to named authorised users, apply the most limited permissions consistent with the work and review access when the purpose changes or the engagement ends.


Use, disclosure and data minimisation

Client information will be used only for the agreed engagement and in accordance with the client's instructions. The Company will access the minimum information required and, where practical, will work with redacted, pseudonymised or aggregated information.

  • Client information will not be used for marketing, case studies, training materials, publications or another client engagement without prior written permission.

  • Confidential content will not be discussed with family members, professional contacts or any unauthorised person.

  • Recipients will be checked carefully before any email, link or attachment is sent. Autofill suggestions will not be relied upon without verification.

  • Client information will not be disclosed to a third party or sub-processor without the authority required by the contract, unless disclosure is required by law.

  • Any accidental receipt of information that appears unnecessary or outside scope will be reported to the client and will not be used.


Limits to confidentiality: safeguarding and serious harm

Confidentiality is not absolute. The Company will disclose information without consent, and where necessary without prior notice, where it believes on reasonable grounds that:

  • a child or young person is at risk of, or is experiencing, harm, abuse or neglect;

  • an adult at risk is being harmed, abused or neglected;

  • there is a risk to the life or serious physical safety of any person, including the individual concerned;

  • a serious criminal offence has been, or is likely to be, committed; or

  • disclosure is otherwise required by law, court order or a regulatory duty.

Disclosure will be limited to what is necessary and will be made promptly to the appropriate route: the client's Designated Safeguarding Lead or safeguarding governor; the Local Authority Designated Officer or equivalent where an allegation concerns an adult working with children; the police or emergency services where there is immediate risk; or the relevant inspection or regulatory body where a duty applies to Company inspection work.

Wherever it is safe and appropriate to do so, the Company will tell the individual concerned what will be shared and with whom. The Company will not do so where this would increase risk to any person, obstruct an investigation or conflict with a legal duty. A record of the concern, the decision, the reasons and the action taken will be kept securely and separately from general working notes.

These limits are explained to coaching and mediation clients at the start of an engagement and are reflected in the engagement contract.


Mediation confidentiality

Workplace mediation carries additional confidentiality protections. Discussions in mediation are conducted on a without prejudice basis and will not be disclosed to the commissioning organisation or used in any grievance, disciplinary, tribunal or court proceedings, except with the agreement of all participants or where the law requires. The mediator will not act as a witness or provide evidence about the content of mediation discussions, save where compelled by a court or where the limits in section 10 apply.

Anything shared privately with the mediator remains private unless the participant agrees it may be shared. Where a written agreement is produced, only that agreement is released, and only to those the participants nominate. Notes taken by the mediator during the process are working notes, are not disclosed and are destroyed on conclusion of the mediation unless the parties agree otherwise or a legal hold applies.


Artificial intelligence, recording and automated tools

Client documents, excerpts, identifiers or confidential information must not be entered into generative AI services, transcription services, automated note-taking tools, meeting assistants, public search tools or other external automated systems unless the client has given prior written permission and the data protection, confidentiality, contractual and security implications have been assessed.

Where a tool is approved, only the minimum necessary information will be used, the agreed retention and access controls will apply, and any setting permitting the provider to use the content for model training or product improvement will be disabled. Client information will not be used to train, fine-tune or evaluate any artificial intelligence model.

Meetings or calls will not be recorded or automatically transcribed without the prior agreement of the client and all relevant participants. Any approved recording will be stored under the controls in this policy and deleted in accordance with the "Retention, return and secure deletion" section below.


Remote working and travel

Confidential work must be undertaken in a setting that prevents unauthorised viewing or hearing. In particular:

  • screens must be positioned away from public view and locked whenever unattended;

  • confidential calls must not take place where they can be overheard;

  • devices and papers must remain under the authorised user's control when travelling;

  • public or shared computers must never be used; and

  • unsecured public Wi-Fi must not be used to access client information unless an appropriately secured connection is in place.

Where the Company works internationally, the requirements in the section "Third-party services and international transfers" below on access from outside the United Kingdom also apply.


Special category, safeguarding and children's information

Information relating to health, safeguarding, equality, disciplinary matters, criminal allegations or children requires particular care. The Company will access such information only where it is necessary for the agreed service and the client has confirmed the appropriate instructions and safeguards.

Where practicable, names and other direct identifiers will be removed before documents are shared with the Company. Such information will remain in the client's secure system wherever possible, will not be copied into general working notes and will not be shared onwards without explicit authority, subject always to the limits in the section "Limits to confidentiality" above.


Data protection impact assessments

A data protection impact assessment is required where processing is likely to result in a high risk to individuals, including large-scale processing of special category data, processing relating to children or vulnerable individuals, systematic monitoring, or the use of new technologies.

Where the Company acts as controller and proposes such processing, it will complete an assessment before processing begins and will consult the Information Commissioner where a high residual risk cannot be mitigated. Where the Company acts as processor, responsibility for the assessment rests with the client; the Company will tell the client where it considers one is needed and will provide reasonable assistance, including information about its own systems, controls and sub-processors.


Vetting and confidentiality undertakings

Nadine Powrie holds an Enhanced Disclosure and Barring Service certificate appropriate to work in educational settings and is registered with the DBS Update Service, so that the certificate's status can be verified at any time. The certificate and the details required to carry out an online status check are provided to clients on request, where the client is entitled to carry out such a check for the role concerned.

Any director, contractor or adviser given access to client confidential information must be bound by a written confidentiality undertaking, must have confirmed that they understand this policy, and must hold any vetting clearance the engagement or the client requires, before access is granted. The Company keeps a record of these confirmations.


Retention, return and secure deletion

Client-supplied confidential documents are not retained as a general Company archive. The contract or client instruction determines the retention period. Unless another period is agreed, copies held by the Company will be returned or securely deleted as soon as they are no longer required and normally within 30 calendar days of the end of the engagement or a valid client request.

Records the Company holds in its own right are retained as follows:

  • coaching records, including session notes, contracting documents and assessment reports — six years from the end of the engagement, reflecting professional indemnity and complaints periods;

  • mediation records — the written agreement and administrative file for six years from conclusion; mediator working notes destroyed on conclusion, as set out in section 11;

  • Strengthscope and other psychometric reports — six years from the end of the engagement, or a shorter period where the assessment provider or the client requires it;

  • inspection working papers — returned or deleted in accordance with the inspectorate's requirements and the terms of the inspection contract;

  • safeguarding concern records — retained securely for the period required by the client's safeguarding policy or applicable statutory guidance, and not deleted while a matter remains open; and

  • administrative, contractual and financial records — up to six years where required for legal, accounting, insurance or regulatory purposes.

Client source documents will not be retained under the administrative category unless there is a documented necessity.

Secure deletion includes, as applicable, removing temporary downloads, local and synchronised copies, email attachments, working notes and items in recycle or deleted-items folders. Copies held solely within resilient system backups will be protected from ordinary access and will expire through the service's normal backup cycle.

Deletion may be suspended where information is subject to a legal hold, dispute, investigation or other lawful requirement; the client will be informed where permitted.


Personal data rights

Where the Company acts as processor. Any request from an individual to access, correct, restrict, object to, erase or otherwise exercise rights over client-controlled personal data will be forwarded to the client without undue delay, normally within one working day. The Company will not respond substantively unless instructed or legally required and will provide reasonable assistance to the client.

Where the Company acts as controller. Individuals may exercise their rights of access, rectification, erasure, restriction, objection, portability and, where relevant, rights relating to automated decision-making, by contacting the Company. The Company will:

  • acknowledge the request and, where there is genuine doubt, verify the requester's identity before disclosing information;

  • respond within one month of receipt of the request, or of the information needed to verify identity or clarify scope;

  • extend that period by up to two further months where a request is complex or where several requests have been made, telling the individual within the first month and explaining why;

  • carry out a reasonable and proportionate search for the information requested;

  • provide the information free of charge, unless a request is manifestly unfounded or excessive, in which case a reasonable fee may be charged or the request refused with reasons; and

  • apply exemptions only where they are available in law, and explain the outcome and the right to complain to the Company and to the Information Commissioner.

Where information concerns more than one individual, or is subject to a confidentiality obligation, the Company will consider carefully what can be released and will redact third-party information where it is not reasonable to disclose it.


Incident and breach response

Any suspected loss, misdirection, unauthorised access, disclosure, alteration, malware event or other compromise must be treated as an information security incident, even if the facts are not yet clear.

The Company will:

act immediately to contain the incident and preserve relevant evidence;

  • notify the client's nominated contact without undue delay and, wherever practicable, within 24 hours of becoming aware of an incident involving client information;

  • record what happened, the information and people affected, the likely consequences and the containment or recovery action taken;

  • co-operate with the client's investigation, risk assessment, notifications and remedial action;

  • review the cause and strengthen controls to reduce the risk of recurrence.

Where the Company is the controller, it will assess whether the breach is likely to result in a risk to individuals and, if so, report it to the Information Commissioner's Office without undue delay and within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to individuals, the Company will also inform those individuals without undue delay, in clear language, describing the likely consequences, the measures taken and the steps they can take to protect themselves, unless a recognised exception applies.

A breach record will be retained whether or not external notification is required.


Third-party services and international transfers

Business services used to handle personal data or confidential information must be subject to proportionate due diligence, appropriate contractual protections and access controls. A sub-processor will not be appointed for client personal data without the authorisation required by the client contract, and any sub-processor will be bound by obligations equivalent to those in this policy.

Personal data will not be transferred to, or accessed from, a country outside the United Kingdom unless the transfer is permitted by law and consistent with the client's instructions. The Company relies on one of the following:

  • UK adequacy regulations, where the destination country is covered;

  • the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, supported by a transfer risk assessment; or

  • another safeguard or exception recognised under UK data protection law.

Access while working overseas. The Company delivers services internationally, including in the United Arab Emirates and Saudi Arabia. Where the lead consultant accesses client information while working outside the United Kingdom, that access is treated as a transfer for the purposes of this policy. The Company will confirm the client's position in advance where the engagement or the client's own policy restricts access by location, will access information only through approved encrypted devices and secured connections, and will not store client information on any device or service located in, or subject to the jurisdiction of, a third country without the client's agreement. Where the client provides the system, the Company will use it in accordance with the client's access and location requirements.


Assurance, training and review

The Company maintains records of its processing activities in accordance with Article 30 of the UK GDPR, together with records of contractual responsibilities, security arrangements, retention decisions, transfer assessments and incidents.

Anyone given access to confidential information must understand this policy and their confidentiality responsibilities before access is granted. Data protection and confidentiality training is completed at induction and refreshed at least annually, and completion is recorded. Additional briefing is provided following a material change in law, systems or client requirements, or following an incident.

This policy is reviewed at least annually and sooner following a material change in services, systems, law, client requirements or an information security incident. Non-compliance may result in immediate withdrawal of access, remedial action and, where relevant, termination of an engagement or contract.


Contact, complaints and related information

Questions about this policy or the handling of personal data should be sent to npowrie@nadinepowrie.com, or to the Data Protection Officer, Phil Powrie, at philpowrie@nadinepowrie.com. Written correspondence may be addressed to either at the registered office above. The Data Protection Officer's contact details are also published on the Information Commissioner's Office register of fee payers.

Complaints to the Company. If you consider that the Company has infringed data protection law in its handling of your personal data, you may complain directly to the Company by email to npowrie@nadinepowrie.com or to the Data Protection Officer at philpowrie@nadinepowrie.com, or in writing to the registered office. Complaints are accepted in any form. The Company will acknowledge receipt within 30 days, will begin enquiring into the complaint without undue delay, will carry out an investigation proportionate to the nature and complexity of the issues raised and the impact on the individual, will keep you informed of progress and of any anticipated delay, and will give you the outcome without undue delay.

If you are not satisfied with how the Company has handled your personal data or a request you have made, you may complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk/make-a-complaint. You may complain to the Information Commissioner at any time, whether or not you have complained to the Company first.


Approved by Nadine Powrie, Director.