Data Protection
The intended handling of client data within software engineering engagements.
Working draft pending legal review
This document has not yet been reviewed by a lawyer and is not yet a binding statement. Bracketed details remain to be completed before publication as a final policy.
Scope of this statement
This working statement complements the website privacy policy by describing how [LEGAL ENTITY NAME], of [REGISTERED ADDRESS], expects to handle client data inside software engineering engagements. It is intended to take effect on [EFFECTIVE DATE], subject to completion and legal review.
It concerns data made available by a client for discovery, development, migration, testing, deployment or support. The role of each party, permitted purposes and instructions must be defined in the relevant contract and any required data processing terms under [GOVERNING JURISDICTION].
Minimisation and access
Engagement teams should request and use only the data reasonably needed for the agreed work. Where practical, development and testing should use reduced, anonymised, pseudonymised or synthetic datasets rather than unnecessary production records.
Access should be limited on a need-to-know basis to people assigned to the engagement and removed when no longer required. Client credentials and data should not be placed in public repositories, examples or unrelated internal material. Specific access methods and client approval requirements should be agreed for each environment.
Client environment separation
Client repositories, workspaces, credentials and deployment environments should be kept logically separate from those of other clients. Transfers between environments should be deliberate, authorised and limited to what the engagement requires. Client instructions and the applicable agreement determine where data may be stored and processed.
The final statement must identify any standard service providers or sub-processors, their roles, approved locations and safeguards for international transfers. These arrangements are not established by this draft and should be answered for the particular engagement before protected data is supplied.
End of an engagement and questions
At the end of an engagement, access should be withdrawn and client data returned, transferred or deleted as the contract and client instructions require. Copies needed for legal obligations, dispute records or agreed support should be identified, access-restricted and retained only for the applicable period. Backup treatment and deletion verification must be confirmed for each relevant system.
Questions about instructions, access, sub-processors, transfers, retention or deletion should be directed to [DATA PROTECTION CONTACT]. The final statement must confirm responsibilities, retention schedules, escalation routes and the requirements of [GOVERNING JURISDICTION].
