1. Purpose
ProMediate (UK) Limited is committed to protecting the confidentiality, integrity and availability of all information entrusted to us by consumers, traders, ADR Officials, staff and other stakeholders.
This Policy sets out the measures taken to safeguard information, reduce the risk of unauthorised access and ensure compliance with applicable legal and regulatory obligations.
2. Scope
This Policy applies to:
- Directors;
- ADR Officials;
- employees;
- consultants;
- contractors; and
- any person handling information on behalf of ProMediate.
It applies to both electronic and paper records.
3. Information Security Principles
ProMediate will:
Protect confidential information.
Restrict access to authorised persons only.
Maintain secure systems and procedures.
Minimise the collection of personal information where appropriate.
Regularly review security arrangements.
Comply with applicable data protection legislation.
4. Access Controls
Access to case information and personal data will only be granted where necessary for the performance of an individual's role.
User accounts, passwords and permissions will be managed to minimise unauthorised access.
Access will be removed promptly when no longer required.
5. Password Security
Users must:
- use strong passwords;
- keep passwords confidential;
- avoid sharing passwords;
- change passwords where compromise is suspected; and
- enable multi-factor authentication where available.
6. Secure Storage
Electronic and paper records
Electronic records will be stored using secure systems with appropriate technical safeguards.
Paper files containing confidential information will be stored securely and access restricted.
7. Remote Working
Where information is accessed remotely:
- secure internet connections should be used;
- devices should be password protected;
- confidential information should not be left unattended; and
- appropriate care should be taken when working in public locations.
Working away from the office
These requirements apply equally to ADR Officials, consultants and contractors accessing case information from any location.
8. Email and Electronic Communications
Care should be taken to ensure that emails are sent to the correct recipients.
Confidential information should only be shared where necessary and appropriate.
Sensitive documents
Sensitive documents should be password protected or encrypted where appropriate.
9. Data Breaches
Any suspected loss, unauthorised disclosure or security incident must be reported to the Directors immediately.
Appropriate steps will be taken to:
- investigate the incident;
- minimise any risk;
- comply with legal reporting obligations where applicable; and
- prevent recurrence.
10. Business Continuity
ProMediate will take reasonable steps to ensure that information remains available in the event of system failure or other disruption.
Appropriate backup arrangements and recovery procedures will be maintained where reasonably practicable.
11. Disposal of Information
Information will be securely disposed of in accordance with the Data Retention Policy.
Electronic records will be securely deleted.
Paper records will be confidentially shredded or otherwise securely destroyed.
12. Responsibilities
All Directors, ADR Officials, employees and contractors are responsible for protecting confidential information.
The Directors have overall responsibility for maintaining appropriate information security arrangements.
Related Policies
This Policy should be read together with:
13. Review
This Policy will be reviewed annually or sooner if required by changes in legislation, regulatory guidance or operational requirements.
Contact
To report a security concern or ask about how we protect your information, please contact us.
Post
ProMediate (UK) LimitedBrow Farm
Top Road
Frodsham
WA6 6SP
Version History
| Version | Effective date | Review date | Summary of changes |
|---|---|---|---|
| 1.0 | August 2026 | August 2027 | First issue. |
This policy is reviewed at least annually.