GDPR Compliance Statement
Effective Date: August, 2025
Johnson Elborne Ltd is committed to full compliance with the UK General Data Protection Regulation (UL GDPR) and, where applicable, the EU GDPR.
1. Data Processing Principles
We adhere to the data protection principles set out in Article 5 of the GDPR. Personal data shall be:
- Processed lawfully, fairly, and transparently;
- Collected for specified, legitimate purposes and not further processed incompatibly;
- Limited to what is necessary in relation to the purposes for which it is processed;
- Accurate and kept up to date;
- Retained only as long as necessary;
- Processed securely, with appropriate safeguards.
2. Lawful Basis for Processing
All personal data is processed under one or more lawful bases, including:
- The legitimate interests of Johnson Elborne and its clients;
- The performance of a contract;
- Compliance with legal obligations;
- The consent of the data subject, where applicable.
3. Individual Rights
Data subjects are entitled to exercise the following rights:
- Right of access to personal data;
- Right to rectification of inaccurate data;
- Right to erasure (“right to be forgotten”);
- Right to data portability;
- Right to object to processing;
- Right to withdraw consent where applicable;
- Right to lodge a complaint with the Information Commissioner’s Office.
Requests should be directed to: mikayla@johnsonelborne.com
4. Data Breach Notification
We maintain appropriate technical and organisational measures to secure personal data and have procedures in place to detect, report, and investigate data breaches in compliance with Articles 33 and 34 of the GDPR.
5. Data Retention
Personal data is retained only as long as necessary to fulfil contractual, legal, or regulatory obligations. Retention periods are reviewed regularly and minimised where appropriate.
6. Data Transfers
Where personal data is transferred outside of the UK or EEA, appropriate safeguards are implemented to ensure the continued protection of data subjects’ rights, in accordance with Chapter V or the GDPR.