Transparency data: Privacy Notice for Cabinet Office Security Management Processing

Imported from official source

This notice sets out how we will use your personal data, and your rights. It is made under Articles 13 and/or 14 of the UK General Data Protection Regulation (UK GDPR). 

The purposes for which we are processing your personal data are: 

Dealing with security incidents and queries as they arrive in the dedicated security email inbox. These can range from adding colleagues to security inductions, through to managing security incidents/breaches.

Where an incident has occurred, the team may request specific follow-up information from an individual, or relevant stakeholders, to better understand the nature of the incident, with progress logged and managed via a tracker.

  • For cyber security, for example detecting and analysing unusual IT usage
  • For dealing with security breaches or concerns
  • For vetting purposes, e.g. updating the vetting team with security incident information
  • For ensuring legal obligations and implications of overseas travel are managed
  • We will process the following personal data in the course of security investigations: 

  • Name of person reporting incident & any other individuals named
  • Audio or video recordings from on site security teams
  • We do not see vetting records, but we update the vetting team with relevant security incident information
  • The legal basis for processing your personal data is: 

    It is necessary for a public function, which is to ensure the security and integrity of Cabinet Office Assets, People and Estate.  

    Sensitive personal data is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, or criminal convictions. The legal basis for processing your sensitive personal data is:

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.gov.uk/government/publications/privacy-notice-for-cabinet-office-security-management-processing

    Officially imported this from Cabinet Office’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Cabinet Office — imported from official source
    Official source
    https://www.gov.uk/government/organisations/cabinet-office.atom ATOM
    Imported
    September 18, 2026 11:35
    Versions
    1 recorded
    Identity
    https://www.gov.uk/government/publications/privacy-notice-for-cabinet-office-security-m...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.