Framework hub
GDPR
EU / UK ICO
General Data Protection Regulation for organizations handling EU and UK personal data.
HLD Group maintains policies and controls mapped to this framework as part of our security and compliance programme. This hub describes programme alignment — not a third-party certification or attestation unless separately agreed in your contract.
Programme focus areas
- Lawful basis
- Data subject rights
- DPIAs
- Cross-border transfers
Policies meeting this framework
The following published policies and programme documents are mapped to GDPR. Status: published and under periodic review.
- Privacy PolicyPublished
How personal data is collected, used, stored, and shared.
v2.0 · review every 365 days
- Data classification policyPublished
Classification levels and handling requirements for information assets.
v1.3 · review every 365 days
- Data retention & disposal policyPublished
Retention schedules and secure destruction of information.
v1.0 · review every 365 days
- Data processing & DPA standardsPublished
Processor obligations, subprocessors, and data subject rights.
v1.0 · review every 365 days
- Breach notification policyPublished
Notifying regulators, customers, and individuals of data breaches.
v1.0 · review every 365 days
- Vendor & third-party risk policyPublished
Assessment and ongoing management of suppliers and subprocessors.
v1.4 · review every 365 days
- Risk management policyPublished
Identifying, assessing, and treating organizational risks.
v1.5 · review every 365 days
Assurance note
Programme alignment means HLD maintains controls, policies, and monitoring mapped to GDPR requirements appropriate to our services and risk profile. It does not by itself constitute certification, authorization, or a SOC/ISO audit report. Customers requiring formal attestations should contact [email protected].