
Version: 2.0
Policy Owner: Operations Manager / Data Protection Lead
Approved by: Board of Directors
Review Date: Annually or sooner where legislation or business practices change
Arthur Financial Limited ("Arthur", "we", "our" or "us") is committed to protecting your privacy and ensuring that your personal information is handled responsibly, securely and transparently.
This Privacy Notice explains how we collect, use, store, share and protect your personal data when you interact with us, whether as a candidate, client, supplier, referee, website visitor, employee or other individual whose personal information we process.
We process personal information in accordance with:
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Data (Use and Access) Act 2025 (where applicable)
Privacy and Electronic Communications Regulations (PECR)
Arthur maintains a comprehensive Data Protection Governance Framework comprising policies and procedures covering lawful processing, retention, security, data subject rights, complaints handling, personal data breaches and accountability. These measures help ensure that personal data is processed lawfully, fairly and transparently.
Arthur is committed to ensuring that all personal data is:
Processed lawfully, fairly and transparently.
Collected for specified, explicit and legitimate purposes.
Limited to what is necessary for those purposes.
Accurate and kept up to date.
Retained only for as long as necessary.
Protected using appropriate technical and organisational security measures.
Processed in a way that enables individuals to exercise their rights.
We regularly review our data protection practices to ensure continued compliance with applicable legislation and guidance issued by the Information Commissioner's Office (ICO).
Before processing personal information, Arthur determines the appropriate lawful basis under UK GDPR.
Depending on the circumstances, we rely on one or more of the following lawful bases:
Performance of a contract
Compliance with a legal obligation
Legitimate interests
Consent
Where we rely on Legitimate Interests, we undertake a documented Legitimate Interest Assessment (LIA) where appropriate. This assessment considers:
The purpose of the processing.
Whether the processing is necessary.
The impact on individuals.
Safeguards implemented to minimise privacy risks.
These assessments are reviewed periodically to ensure they remain appropriate.
Depending upon your relationship with Arthur, we may collect:
Candidate Information
Name and contact details
Curriculum Vitae (CV)
Employment history
Education and qualifications
Skills and professional experience
References
Interview notes
Salary expectations
Right to work documentation
Diversity information (where provided)
Criminal convictions (where legally required)
Call recordings
Website usage information
Client Information
Contact details
Job vacancies
Recruitment requirements
Feedback on candidates
Contractual information
Marketing preferences
Supplier Information
Contact details
Business information
Payment details
Contract information
Website Information
IP address
Browser information
Device information
Cookie preferences
Website usage data
We use personal data to:
Provide recruitment services.
Match candidates to employment opportunities.
Introduce suitable candidates to clients.
Manage client relationships.
Communicate with candidates and clients.
Comply with legal and regulatory obligations.
Improve our services.
Send relevant marketing communications (where permitted).
Protect our legal rights.
Prevent fraud and maintain information security.
Sharing Your Personal Information
We may share personal information with:
Prospective employers and clients.
Technology providers supporting our recruitment services.
Payroll providers.
Professional advisers.
Regulatory authorities.
Law enforcement agencies where required.
Service providers acting on our behalf.
All third parties processing personal information on our behalf are required to implement appropriate technical and organisational security measures and process information only in accordance with our instructions.
Arthur takes the security of personal information seriously and implements appropriate technical and organisational measures to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Our security measures include, where appropriate:
Encrypted systems and communications.
Secure cloud hosting.
Role-based access controls.
Multi-factor authentication.
Regular security monitoring.
Vulnerability assessments.
Secure disposal of confidential information.
Staff training.
Confidentiality obligations.
Supplier due diligence.
Access to personal data is restricted to authorised personnel who require access for legitimate business purposes.
Arthur retains personal information only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, contractual and business requirements.
Retention periods are determined by considering:
Legal obligations.
Regulatory requirements.
Business necessity.
Contractual obligations.
The sensitivity of the personal information.
Arthur maintains a formal Data Retention Policy and reviews retention periods regularly.
When information is no longer required, it is securely deleted, anonymised or destroyed using appropriate technical and organisational measures.
Where personal information is transferred outside the United Kingdom, Arthur ensures that appropriate safeguards are implemented in accordance with UK GDPR.
These safeguards may include:
UK International Data Transfer Agreements (IDTAs).
UK Addendum to the Standard Contractual Clauses.
Transfers to countries benefiting from UK adequacy regulations.
Other lawful transfer mechanisms recognised under UK GDPR.
We regularly assess international transfers to ensure personal information receives an equivalent level of protection.
Under UK GDPR, you have the right to:
Be informed.
Access your personal information.
Request correction of inaccurate information.
Request deletion of your personal information where appropriate.
Restrict processing.
Object to processing.
Receive your data in a portable format.
Withdraw consent where processing relies on consent.
Object to automated decision making and profiling.
Arthur maintains documented procedures to ensure requests are handled promptly and within the statutory timescales.
Where the requirements of UK GDPR are met, individuals may request that Arthur erase their personal information.
Upon receiving a request we will:
Verify your identity.
Assess whether the request meets the legal requirements.
Consider whether any exemptions apply.
Securely erase personal information where appropriate.
Notify relevant processors where required.
Maintain a record of the request for compliance purposes.
Where we are unable to erase information because we have a legal or regulatory obligation to retain it, we will explain our reasons.
Arthur maintains documented procedures for identifying, investigating and managing personal data breaches.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within the required statutory timeframe and, where appropriate, notify affected individuals without undue delay.
All suspected breaches are investigated, documented and reviewed to identify lessons learned and support continual improvement.
Our website uses cookies to improve user experience, monitor website performance and support marketing activities.
Where required by law, we will seek your consent before placing non-essential cookies on your device.
Further information is available within our Cookie Policy.
Arthur is committed to handling concerns regarding personal data fairly, consistently and transparently.
If you are dissatisfied with how we have handled your personal information or exercised your data protection rights, please contact our Data Protection Lead:
Email: privacy@arthur.co.uk
We will:
Acknowledge your complaint promptly.
Investigate the matter thoroughly.
Keep you informed where appropriate.
Explain our findings.
Identify any corrective action taken.
Arthur maintains a formal Data Protection Complaints Policy which governs how complaints relating to personal information are investigated, recorded, resolved and reviewed.
If you remain dissatisfied following our response, you have the right to complain to the Information Commissioner's Office (ICO).
Arthur is committed to demonstrating accountability under UK GDPR by maintaining a comprehensive privacy governance framework.
This includes documented policies covering:
Data Protection Governance
Privacy Notices
Data Processing
Legitimate Interests
Data Retention
Data Erasure
Data Subject Rights
Personal Data Breaches
Data Protection Complaints
Staff Training
Regular Compliance Reviews
These policies are reviewed periodically to ensure they remain effective and aligned with current legislation and business practices.
If you have any questions regarding this Privacy Notice or wish to exercise your rights, please contact:
Data Protection Lead
Arthur Financial Limited
80 Leadenhall Street
London
EC3A 3DH
Email: privacy@arthur.co.uk
Telephone: 0203 5877 234
This Privacy Notice will be reviewed at least annually, or sooner where there are significant changes to legislation, regulatory guidance, business operations or data processing activities.