Data Protection Policy

JOHN BANKS GROUP

Data Protection Policy

UK GDPR compatible • Updated July 2026

Document reference

BS.DAT.0.02.26

Policy owner

Chief Executive / Data Protection Lead

Approved by

Melanie Banks-Browne, Chief Executive

Effective date

24 July 2026

Next review

July 2027, or earlier following legal or operational change

Applies to

All John Banks Group companies, sites, workers and relevant third parties

Policy status: This policy reflects the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and the Data (Use and Access) Act 2025 as in force at 24 July 2026.

1. Purpose and scope

John Banks Group (“the Group”) is committed to handling personal data lawfully, fairly, transparently and securely. This policy sets the standards that apply when the Group collects, uses, shares, stores, accesses, changes, transfers or disposes of personal data.

It applies to directors, employees, workers, apprentices, agency staff, contractors, consultants and any other person processing personal data for or on behalf of the Group. It covers customer, prospective customer, employee, candidate, supplier, business contact, website user, CCTV, telematics and other personal data processed in paper or electronic form.

2. Legal framework

The Group will comply with applicable UK data protection and privacy law, including:

the UK General Data Protection Regulation (“UK GDPR”);

the Data Protection Act 2018 (“DPA 2018”);

the Data (Use and Access) Act 2025 (“DUAA”), which amends but does not replace the UK GDPR, DPA 2018 and PECR;

the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”); and

relevant guidance, codes and decisions issued by the Information Commissioner’s Office (“ICO”).

Where the Group processes personal data connected with another jurisdiction, it will also assess whether additional local requirements apply.

3. Key definitions

Term

Meaning

Personal data

Information relating to an identified or identifiable living individual.

Special category data

Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data used for identification; health data; or data concerning sex life or sexual orientation.

Criminal offence data

Personal data relating to criminal allegations, proceedings, convictions or related security measures.

Processing

Any operation performed on personal data, including collection, recording, use, disclosure, storage, alteration, retrieval, restriction or deletion.

Controller

The organisation that decides why and how personal data is processed.

Processor

An organisation that processes personal data on a controller’s behalf.

Personal data breach

A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

4. Data protection principles

Personal data must be:

processed lawfully, fairly and transparently;

collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes;

adequate, relevant and limited to what is necessary;

accurate and, where necessary, kept up to date;

kept in identifiable form for no longer than necessary;

protected by appropriate technical and organisational security; and

processed in a way that enables the Group to demonstrate compliance (accountability).

5. Governance and responsibilities
5.1 The Group

The Group will maintain proportionate governance, including records of processing, privacy notices, retention rules, security controls, processor contracts, training, breach records, legitimate interests assessments and data protection impact assessments where required.

5.2 Data Protection Lead

The Data Protection Lead oversees this policy, advises on compliance, coordinates rights requests and complaints, maintains relevant records and liaises with the ICO. The current contact is Olivia Tombs at [email protected] or John Banks Group, Kempson Way, Moreton Hall, Bury St Edmunds, Suffolk, IP32 7AR.

The title “Data Protection Lead” is used unless and until the Group determines that appointment of a statutory Data Protection Officer is required. The Board retains overall accountability.

5.3 Managers and IT

Managers must embed this policy in their teams, restrict access appropriately and escalate incidents. IT is responsible for proportionate technical controls, access management, monitoring, backups, patching and incident support.

5.4 Everyone

All persons covered by this policy must complete required training, follow approved processes, keep data confidential, use only authorised systems and immediately report suspected loss, misuse, unauthorised access or disclosure.

6. Lawful processing

Before processing personal data, the Group must identify and document an appropriate lawful basis:

Lawful basis

Typical Group examples

Contract / pre-contract steps

Vehicle or service enquiries, sales, repairs, bookings, warranties and related customer administration.

Legal obligation

Tax, accounting, employment, vehicle registration, regulatory and health and safety duties.

Legitimate interests

Operating and improving the business, customer service, fraud prevention, network and information security, proportionate CCTV, debt recovery and relevant direct marketing, subject to an assessment where required.

Consent

Optional marketing or another activity where consent is the appropriate basis. Consent must be freely given, specific, informed, unambiguous and easy to withdraw.

Vital interests

Protecting life or physical safety where another lawful basis is unavailable.

Public task

Limited circumstances where the processing is necessary for an applicable public function.

Recognised legitimate interests

Specific purposes listed in UK law, such as certain public security or safeguarding activities, where the statutory conditions are met.

Direct marketing may be a legitimate interest, but the Group must still comply with PECR, respect objections and complete a legitimate interests assessment where appropriate. Safety recalls and essential service, MOT or contract communications must not be presented as marketing.

7. Special category and criminal offence data

Special category data requires both an Article 6 lawful basis and an Article 9 condition. Criminal offence data requires an Article 6 basis plus lawful authority or an appropriate DPA 2018 condition. Where required, the Group will maintain an Appropriate Policy Document.

Examples include employee health and occupational health information, equality monitoring, reasonable adjustments, driving-licence information and criminal record information for eligible roles. Access must be strictly limited.

8. Transparency and privacy information

The Group will provide clear privacy information when personal data is collected and, where it is obtained from another source, within the applicable legal timeframe. Notices will explain the controller’s identity, purposes, lawful bases, legitimate interests, recipients, international transfers, retention, individual rights, complaint routes and any significant automated decision-making.

If the Group intends to use personal data for a materially different purpose, compatibility and transparency requirements must be assessed before that use begins. Any statutory exemption must be documented.

9. Individual rights

Subject to legal conditions and exemptions, individuals have rights to:

be informed about processing;

access their personal data;

rectify inaccurate or incomplete data;

erase personal data in certain circumstances;

restrict processing in certain circumstances;

receive and transmit eligible data (data portability);

object to processing based on legitimate interests and to direct marketing; and

receive safeguards in relation to solely automated decisions producing legal or similarly significant effects.

Requests may be made verbally or in writing and do not need to mention the UK GDPR. Staff must forward any request immediately to the Data Protection Lead. The Group may request proportionate identity information and clarification where genuinely required.

The usual response period is one month, beginning in accordance with the applicable rules. It may be extended by up to two further months for complex or numerous requests, with the individual informed within the first month. A fee may be charged, or a request refused, only where legally permitted, including where it is manifestly unfounded or excessive.

Subject access searches: The Group will make searches that are reasonable and proportionate. Decisions about search scope, exemptions, redaction and third-party information must be documented.

10. Data protection complaints

The Group will make it straightforward for an individual to complain about how their personal data has been handled, including through an accessible electronic route. Complaints must be sent immediately to the Data Protection Lead.

The Group will:

acknowledge the complaint within 30 days of receipt;

take appropriate steps to investigate it;

respond without undue delay, explaining the outcome and any action taken; and

tell the complainant that they may complain to the ICO and, where appropriate, seek a judicial remedy.

Complaint records and relevant correspondence will be retained in accordance with the Group’s retention schedule.

11. Data minimisation, accuracy and retention

Only the minimum personal data reasonably required for an approved purpose may be collected or retained. Data should be checked for accuracy at collection and corrected when inaccuracies are identified. The Group will operate and periodically review a retention schedule covering customer, finance, vehicle, employment, CCTV, call-recording, marketing, complaint, legal and supplier records.

Data subject to a legal hold, complaint, regulatory matter, litigation or investigation must not be deleted until the hold is lifted. When retention expires, data must be securely deleted, anonymised or destroyed using an approved method.

12. Security and acceptable handling

The Group applies security proportionate to the nature, volume and risk of the processing. Everyone must:

use only approved Group devices, accounts, applications and storage locations;

use unique strong passwords and multi-factor authentication where enabled; never share credentials;

lock screens when unattended and protect devices from loss, theft and unauthorised viewing;

send personal data only to verified recipients, using approved encryption or secure transfer methods where appropriate;

apply least-privilege access and promptly remove access when it is no longer required;

keep software supported and patched and comply with IT controls relating to malware protection, backups, logging and monitoring;

avoid removable media unless authorised and encrypted;

keep paper records secure, operate a clear-desk approach and use confidential waste or cross-cut shredding;

not upload Group personal data to personal email, consumer cloud storage, messaging accounts, unapproved AI tools or personal devices; and

report misdirected emails, phishing, lost devices, unusual system behaviour and any other suspected incident immediately.

Personal data may be accessed remotely only through approved devices and secure connections. Staff must take particular care when working in public places, travelling or discussing customer or employee matters.

13. Dealership systems and operational data

Approved systems may include Pinewood Pinnacle, manufacturer systems, Keyloop services, finance-house platforms, AFRL/DVLA services, PeopleHR, Microsoft 365, CitNOW, payment providers, customer contact and booking systems, CCTV and other authorised business applications.

Access must be role-based. Customer and prospect records must not be exported, photographed, copied or used outside approved business processes. Finance, identity, health, payroll and employee-relations information requires enhanced care. Payment card data must be handled only through approved payment processes and must not be recorded in free-text notes, email or paper files unless expressly authorised.

14. Direct marketing and communications

Marketing must comply with UK GDPR and PECR. The Group will record the applicable lawful basis and, for electronic marketing, whether consent or a valid soft opt-in applies. Purchased or manufacturer-supplied lists must not be used until their provenance, transparency and permissions have been checked.

Every marketing communication must provide a clear opt-out. Suppression records should be retained so that objections continue to be respected. Objections to direct marketing must be actioned promptly across relevant systems and channels. Telephone marketing must be screened against the TPS/CTPS where required.

15. CCTV, call recording, vehicle and location data

CCTV, call recordings, ANPR, demonstrator or courtesy-car telematics, dashcams and location data may be used only for specified, necessary and proportionate purposes with appropriate notices, restricted access and defined retention. Covert monitoring is prohibited unless exceptionally justified, lawful, authorised at senior level and supported by a documented assessment.

Monitoring must not be repurposed for routine employee performance management without prior legal, privacy and employee-relations assessment.

16. Children and vulnerable individuals

Where services are likely to be accessed by children, the Group will take their needs and best interests into account when designing processing and privacy information. Additional care must also be taken with vulnerable customers, while avoiding unnecessary collection of sensitive information.

17. Automated decision-making, profiling and AI

The Group may use automation or profiling to assist with lead handling, fraud prevention, finance eligibility, recruitment, customer contact, stock or service activity. No solely automated decision producing a legal or similarly significant effect may be introduced without prior assessment, an appropriate lawful basis and required safeguards.

Safeguards include meaningful information about the processing, the ability to make representations, obtain human intervention and challenge the decision. Stricter conditions apply to special category data. Staff must not place personal data into public or unapproved generative-AI services. New AI uses require approval, supplier due diligence and, where indicated, a DPIA.

18. Data protection by design and DPIAs

Privacy must be considered at the start of, and throughout, any new system, supplier, campaign, monitoring activity, data-sharing arrangement, AI use or material change to processing. Default settings should minimise collection, access, disclosure and retention.

A Data Protection Impact Assessment must be completed before high-risk processing begins, including where there is systematic monitoring, large-scale sensitive data, significant automated decision-making, novel technology or substantial combining of datasets. Unmitigated high risk must be escalated and, where required, referred to the ICO before processing.

19. Suppliers, processors and data sharing

Before appointing a processor, the Group will carry out risk-based due diligence and put in place a written contract containing the required data protection terms. Processors may act only on documented instructions, maintain appropriate security, assist with rights and breaches, control sub-processors, return or delete data at the end of the service and permit relevant assurance.

Data sharing with manufacturers, finance providers, insurers, regulators, police, professional advisers and other controllers must have a lawful basis, be necessary and proportionate, and be covered by appropriate transparency and, where appropriate, a data-sharing agreement.

20. International transfers

Personal data may be transferred or made remotely accessible outside the UK only after the transfer has been approved and an appropriate legal mechanism is in place. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, binding corporate rules or a limited statutory exception.

Where required, the Group will document the applicable UK data-protection test and any supplementary safeguards. Supplier location, hosting, support access and onward transfers must be checked; references to the EEA alone are not sufficient.

21. Personal data breaches

Report immediately: Any actual or suspected loss, misdirection, unauthorised access, disclosure, alteration, deletion, ransomware, phishing compromise or security weakness involving personal data must be reported at once to the Data Protection Lead and IT. Staff must not investigate independently or conceal an incident.

The Group will contain and investigate the incident, preserve evidence, assess risk and document the decision. Where a breach is likely to result in a risk to individuals’ rights and freedoms, the ICO must be notified without undue delay and, where feasible, within 72 hours of awareness. If complete information is unavailable, an initial report may be made and updated without undue delay.

Where a breach is likely to create a high risk, affected individuals will be informed without undue delay unless a legal exception applies. The Group will also consider notification to insurers, law enforcement, the National Cyber Security Centre, manufacturers, finance providers or other regulators where appropriate.

22. Training, assurance and audit

Data protection and information-security training is mandatory on induction and periodically thereafter, with additional role-based training for higher-risk functions. The Group may carry out compliance reviews, access audits, supplier reviews, phishing exercises and other proportionate assurance.

Suspected non-compliance will be investigated. Breach of this policy may result in removal of access, disciplinary action up to and including dismissal, termination of contract and/or referral to regulators or law enforcement.

23. Records and related documents

This policy should be read with the Group’s:

privacy notices and cookie notice;

Data Retention Policy and retention schedule;

Information Security, IT Acceptable Use and Cyber Incident procedures;

Subject Access Request and Individual Rights procedure;

Personal Data Breach Response procedure;

CCTV and monitoring arrangements;

Direct Marketing procedures and suppression controls;

Data Protection Impact Assessment and Legitimate Interests Assessment templates; and

employment policies dealing with confidentiality, records and monitoring.

24. Review and approval

This policy will be reviewed at least annually and earlier if legislation, ICO guidance, Group systems, business activities or risk materially changes. Operational contact details and supporting procedures may be updated between formal reviews where this does not reduce protection.