How Pentacept Reporters protects personal information
| Organisation: | Pentacept Enterprises Limited, trading as Pentacept Reporters |
| Location: | London, United Kingdom |
| Policy owner: | Management and Editorial Team |
| Version: | 1.0 |
| Effective date: | 31 July 2026 |
| Next review: | 31 July 2027, or earlier if required |
| Status: | Public-facing governance policy |
| Privacy questions / rights requests: | privacy@pentaceptreporters.com |
1. Purpose and Status
This policy explains the standards Pentacept Enterprises Limited, trading as Pentacept Reporters, follows when it collects, uses, stores, shares or deletes personal information. It supports our accountability under the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable UK privacy law.
This policy is designed for publication on the Pentacept Reporters website. It should be read alongside our Privacy Policy, Cookie Policy, Editorial Standards and Ethics Policy, Corrections Policy, Community Guidelines, contributor terms and any specific privacy notice supplied at the point personal information is collected.
The Privacy Policy tells individuals what happens to their information in particular situations. This Data Protection Policy sets out the wider governance rules we apply across the organisation.
↑ Back to contents2. Scope
This policy applies to directors, employees, volunteers, contributors, freelance journalists, photographers, interviewers, contractors and service providers who handle personal information for Pentacept Reporters. It covers personal information processed through our website, email, editorial and newsgathering work, interviews, photographs, video, events, contributor relationships, recruitment, mailing lists, analytics, audience engagement and business administration.
Everyone acting for Pentacept Reporters must follow this policy, maintain confidentiality and raise concerns promptly. Contractual obligations and role-specific procedures may impose additional requirements.
↑ Back to contents3. Key Terms
| Term | Meaning |
|---|---|
| Personal information | Information relating to an identified or identifiable living person. It includes names, contact details, photographs, recordings, online identifiers and opinions about a person. |
| Processing | Anything done with personal information, including collecting, recording, organising, viewing, using, sharing, publishing, storing, altering or deleting it. |
| Special category data | More sensitive information, including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric identifiers, health, sex life or sexual orientation. |
| Controller | The organisation that decides why and how personal information is processed. |
| Processor | A person or organisation that processes personal information for a controller under instructions. |
4. Our Role and Accountability
Pentacept Enterprises Limited is normally the controller for personal information handled through Pentacept Reporters. Our management team is responsible for approving this policy, providing appropriate resources and making sure data protection risks are addressed.
The Editor-in-Chief and relevant commissioning editors are responsible for ensuring that editorial uses of personal information are lawful, proportionate and consistent with our editorial standards. All personnel must use approved systems, keep information secure, complete any required training and report incidents immediately.
We will maintain records appropriate to the nature, scale and risk of our processing, including records of processing activities where required, retention decisions, lawful basis assessments, consent records, processor contracts, data rights requests, breaches and data protection impact assessments.
↑ Back to contents5. Data Protection Principles
We apply the following principles whenever we process personal information:
- Lawfulness, fairness and transparency: we identify a lawful basis, treat people fairly and explain our use of information clearly.
- Purpose limitation: we collect information for specified, explicit and legitimate purposes and do not reuse it incompatibly.
- Data minimisation: we collect only information that is adequate, relevant and necessary.
- Accuracy: we take reasonable steps to keep information accurate and to correct or qualify material inaccuracies.
- Storage limitation: we keep identifiable information only for as long as it is needed, unless lawful archiving or public-interest reasons justify longer retention.
- Integrity and confidentiality: we protect information with security appropriate to the risks.
- Accountability: we must be able to demonstrate how we comply.
6. Lawful Bases and Fair Processing
Before processing begins, we identify and record an appropriate lawful basis. Depending on the activity, this may be:
- Consent, where a person has made a freely given, specific, informed and unambiguous choice;
- Contract, where processing is necessary to enter into or perform an agreement;
- Legal obligation, where the law requires the processing;
- Legitimate interests, where our or another party's legitimate purpose is not overridden by the person's interests, rights and freedoms;
- Vital interests, in rare cases involving protection of life; or
- A public task, only where a relevant legal basis applies.
Where we rely on legitimate interests, we will document the purpose, necessity and balancing assessment where appropriate. We will not switch lawful basis merely because the original basis becomes inconvenient.
↑ Back to contents7. Sensitive and Criminal Offence Information
Special category information and criminal offence information require additional protection. We will process them only where an Article 6 lawful basis and any further condition required by Article 9 of the UK GDPR or the Data Protection Act 2018 apply. Where explicit consent is used, the request will be clear, specific and recorded.
Editorial teams must consider whether sensitive details are genuinely necessary to the story, whether publication is proportionate, and whether additional safeguards such as redaction, restricted access or stronger source protection are required. Information that is publicly available is not automatically free of privacy obligations.
↑ Back to contents8. Journalism and the Public Interest
UK data protection law recognises the importance of journalism and freedom of expression. The journalism exemption in the Data Protection Act 2018 may disapply specified requirements, but only where its legal conditions are met. It is not a blanket exemption for Pentacept Reporters or for everything held by a newsroom.
Before relying on the exemption, the responsible editor must be able to show that:
- the personal information is being processed for a journalistic purpose;
- the processing is carried out with a view to publishing journalistic material;
- there is a reasonable belief that publication would be in the public interest; and
- there is a reasonable belief that complying with the particular data protection requirement would be incompatible with the journalistic purpose.
The assessment must be made case by case and should be recorded, especially where the material is sensitive, intrusive, disputed or likely to create a significant risk to an individual. Relevant editorial codes, the nature of the story, the person's reasonable expectations, accuracy, necessity, proportionality and possible harm should be considered. Security and accountability remain central even where an exemption applies.
↑ Back to contents9. Transparency and Collection
We provide privacy information in a clear and accessible form at or near the point of collection unless a lawful exception or exemption applies. Notices will explain who we are, what information we use, why we use it, the lawful basis, recipients, international transfers, retention, rights and how to complain.
We may collect information directly from individuals, public records, event organisers, interviewees, contributors, correspondents, tip-offs, social media, publicly available sources, analytics providers and other legitimate sources. Editorial staff must consider source reliability, accuracy and the privacy impact of collection methods.
↑ Back to contents10. Consent, Interviews, Images and Recordings
Where consent is the chosen lawful basis, we keep evidence of what was agreed, when and how. People must be able to withdraw consent as easily as they gave it. Withdrawal does not make earlier lawful processing unlawful, and it may not require removal of material where another lawful basis or a valid journalism exemption applies.
For interviews, photographs, audio and video, we will explain the intended use and publication context as clearly as practicable. We will preserve interview and media consent records in line with the retention schedule. Consent to be interviewed does not remove our obligations concerning accuracy, fairness, safeguarding and responsible editing.
Children and adults at risk require particular care. We will assess age, understanding, risk, parental responsibility, safeguarding and the public interest before collecting or publishing identifying material. We will apply higher protection where children are likely to access an online service or be affected by processing.
↑ Back to contents11. Individual Rights
Subject to applicable legal limits and exemptions, individuals may have the right to:
- be informed about how their personal information is used;
- request access to their personal information;
- ask for inaccurate or incomplete information to be corrected;
- ask for erasure in certain circumstances;
- ask for processing to be restricted;
- object to processing, including certain direct marketing;
- receive certain information in a portable format; and
- seek safeguards in relation to solely automated decisions with legal or similarly significant effects.
Requests should be sent to privacy@pentaceptreporters.com. We may ask for proportionate information to verify identity and clarify the request. We will respond within the period required by law, normally one month, subject to any lawful extension or pause. We normally do not charge a fee, but the law permits limited exceptions.
Where a request concerns unpublished or published journalistic material, confidential sources or third-party rights, we will assess any applicable exemption carefully. A refusal or limitation will be explained unless the law prevents us from doing so.
↑ Back to contents12. Accuracy, Corrections and Editorial Records
We take reasonable steps to verify facts and distinguish fact from comment. A data protection request is not a substitute for our Corrections Policy, and an editorial correction request is not automatically a request under data protection law. We will route each matter appropriately and may deal with both processes where needed.
Editorial records may include source material, notes, recordings, drafts, legal review, correspondence and public-interest assessments. Access will be limited according to role and sensitivity. We may retain an accurate audit trail of corrections and complaints where this is necessary for accountability, legal claims or journalistic integrity.
↑ Back to contents13. Data Protection by Design and Impact Assessments
Privacy and data protection must be considered when a project, tool, supplier, form, campaign or editorial workflow is designed and throughout its lifecycle. Default settings should limit the collection, visibility and retention of personal information to what is necessary.
We will carry out a Data Protection Impact Assessment before processing likely to result in a high risk to individuals. Examples may include systematic monitoring, large-scale sensitive information, new intrusive technologies, extensive profiling, or a project with a substantial risk to children, vulnerable people, sources or contributors. High residual risks will be escalated and, where required, referred to the Information Commissioner before processing begins.
↑ Back to contents14. Security and Confidentiality
We use risk-based technical and organisational safeguards. Depending on the information and activity, these may include:
- role-based access and least-privilege permissions;
- multi-factor authentication, strong passwords and secure account recovery;
- encryption in transit and, where appropriate, at rest;
- managed devices, timely updates, malware protection and secure backups;
- secure sharing methods and controls on downloads or local copies;
- confidentiality duties for staff, volunteers, contributors and suppliers;
- separation or pseudonymisation of identifying information where appropriate;
- secure disposal of paper and electronic records; and
- regular review of access, suppliers, incidents and known risks.
Highly sensitive source material must not be placed in personal email, consumer messaging accounts or unapproved storage. Anyone who suspects loss, unauthorised disclosure, account compromise or another security incident must report it immediately to privacy@pentaceptreporters.com.
↑ Back to contents15. Service Providers and Data Sharing
We share personal information only where there is a lawful and necessary reason. Recipients may include hosting, email, analytics, security, payment, professional advisory and publishing service providers, as well as public authorities where legally required. We do not sell personal information.
Before appointing a processor, we assess its security and data protection arrangements. Required written terms will cover instructions, confidentiality, security, assistance with rights and breaches, deletion or return, audit information and sub-processors. We remain responsible for choosing and supervising processors appropriately.
↑ Back to contents16. International Transfers
Our reporting, contributors, readers and suppliers may be located outside the United Kingdom. A restricted transfer of personal information will take place only where a lawful transfer mechanism applies. Depending on the destination and circumstances, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or a limited statutory exception.
Where required, we will assess the destination laws and practical risks, adopt supplementary safeguards and keep the transfer under review. Access from outside the UK can itself amount to an international transfer.
↑ Back to contents17. Retention and Deletion
We do not keep personal information for longer than necessary. Retention depends on purpose, legal requirements, limitation periods, risk, public-interest archiving and the need to protect journalistic records or confidential sources. At the end of the applicable period, information will be securely deleted, anonymised or reviewed for justified continued retention.
| Record Category | Normal Period | Notes |
|---|---|---|
| General enquiries and routine correspondence | 12 months after closure | Longer only where needed for an active matter, complaint, legal requirement or documented business need. |
| Contributor and contractual records | 6 years after the relationship ends | May be longer for deeds, active disputes, tax requirements or another legal obligation. |
| Interview and media consent records | 6 years after last use or end of relationship | Review alongside the associated publication and any continuing legal or public-interest need. |
| Unsuccessful recruitment records | Normally 6 months | May be extended with consent or where needed for a live dispute or legal obligation. |
| Financial, tax and accounting records | At least 6 years from the relevant financial period | Longer where required by HMRC, an audit, a transaction spanning periods or a compliance check. |
| Newsletter and marketing records | Until opt-out or purpose ends | A minimal suppression record may be retained to respect a do-not-contact request. |
| Cookie and analytics information | As stated in the Cookie Policy and consent tool | Settings are reviewed and unnecessary identifiers are minimised. |
| Complaints, corrections and rights requests | Normally 6 years after closure | A shorter or longer period may be justified by sensitivity, risk and legal limitation periods. |
| Published journalism and public-interest archives | Long-term where justified | Retention is reviewed against journalistic, historical, accountability and public-interest value. |
These periods are working standards, not automatic guarantees. A legal hold, investigation, safeguarding need, confidential-source obligation or documented public-interest assessment may suspend deletion. Conversely, unnecessary information may be deleted sooner.
↑ Back to contents18. Personal Data Breaches
All suspected personal data breaches must be reported immediately to privacy@pentaceptreporters.com. We will contain the incident, preserve relevant evidence, assess the facts and risks, document decisions and take remedial action.
Where a breach is likely to result in a risk to people's rights and freedoms, we will notify the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, we will also inform affected individuals without undue delay unless a lawful exception applies. We will keep a record of all personal data breaches, including those not reported externally.
↑ Back to contents19. Training, Compliance and Review
People who handle personal information for Pentacept Reporters will receive guidance or training appropriate to their duties. Access to sensitive editorial information may require enhanced confidentiality and security instruction. Compliance may be reviewed through access checks, supplier reviews, incident lessons, spot checks and periodic policy audits.
A serious or repeated breach of this policy may result in removal of access, termination of a volunteer or contributor assignment, contractual action or disciplinary action, as applicable. Suspected unlawful conduct may be reported to the appropriate authority.
This policy will be reviewed at least annually and sooner following a material legal change, significant incident, new high-risk activity or substantial change to our services.
↑ Back to contents20. Contact and Complaints
Questions, rights requests and privacy complaints should be sent to:
| Privacy email: | privacy@pentaceptreporters.com |
| General enquiries: | hello@pentaceptreporters.com |
| Organisation: | Pentacept Enterprises Limited, trading as Pentacept Reporters |
| Location: | London, United Kingdom |
We will try to resolve concerns fairly and promptly. Individuals also have the right to complain to the Information Commissioner's Office. Current contact and complaint routes are available at ico.org.uk/make-a-complaint.
↑ Back to contents21. Legal Framework and Official Guidance
This policy is informed by the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and subsequent amendments. Official guidance used in preparing this policy includes:
- ICO: Data protection principles
- ICO: Data protection and journalism code of practice
- ICO: Individual rights
- ICO: Data protection by design and default
- ICO: Personal data breaches
- ICO: International transfers
- GOV.UK: Company and accounting records
Implementation Note
This policy is a governance template prepared for Pentacept Reporters. It should be checked against the organisation's actual systems, suppliers, editorial workflows and regulatory status, and reviewed by a qualified UK data protection professional before formal adoption.
↑ Back to contents