{"schema_version":"1","generated_at":"2026-09-24T23:20:32+01:00","expires":"2026-10-08T23:20:32+01:00","canonical":"https://compliance.radicaltechteam.co.uk/.well-known/compliance.json","application":{"name":"Compliance Hub","purpose":"The Liberal Democrats' data-rights hub: it shows you what every application we run holds about you, lets you exercise your data protection rights in one place, and keeps the party honest about both.","data_description":"Your hub account (name and email from your Lib Dem sign-in), the rights requests and complaints you make, a one-way fingerprint of every address on the do-not-contact list, and an append-only audit trail of how we handled it all.","url":"https://compliance.radicaltechteam.co.uk"},"controller":{"name":"The Liberal Democrats","address":"1 Vincent Square, London SW1P 2PN","email":"data.protection@libdems.org.uk"},"privacy_contact":{"name":"Data Protection Officer","email":"data.protection@libdems.org.uk","is_dpo":true},"privacy":{"privacy_policy_url":"https://compliance.radicaltechteam.co.uk/privacy","cookies_policy_url":"https://compliance.radicaltechteam.co.uk/cookies","accessibility_statement_url":"https://compliance.radicaltechteam.co.uk/accessibility"},"processing_activities":[{"id":"rights_handling","name":"Subject rights handling","purpose":"Receiving access, rectification, erasure, portability, restriction, objection and marketing opt-out requests and fulfilling them across every application in the suite (UK GDPR Articles 15–21).","lawful_basis":"legal_obligation","lawful_basis_explanation":"UK GDPR Article 12 obliges the controller to facilitate the exercise of data subject rights; operating the shared rights-handling infrastructure is also a legitimate interest (Article 6(1)(f)) of the party and its members.","data_subject_categories":["members","supporters","members of the public"],"retention":{"summary":"Request records are reduced to a statistical shell (kind, dates, outcome) 12 months after closure — the personal payload is scrubbed.","period_months":12},"source":"data_subject"},{"id":"complaints_register","name":"Data protection complaints register","purpose":"Receiving, acknowledging within 30 days, and investigating data protection complaints, which controllers must facilitate under DPA 2018 s.164A (inserted by the Data (Use and Access) Act 2025).","lawful_basis":"legal_obligation","data_subject_categories":["complainants"],"retention":{"summary":"Complaint records are scrubbed of personal content 12 months after closure, keeping only the statistical shell of the register.","period_months":12},"source":"data_subject"},{"id":"suppression_list","name":"Central do-not-contact (suppression) list","purpose":"Honouring objections to direct marketing everywhere, permanently (UK GDPR Article 21(2)–(3)). We store only a one-way SHA-256 hash of each suppressed address — never the address itself — so the list can say \"do not contact\" without being a mailing list.","lawful_basis":"legal_obligation","data_subject_categories":["anyone who has asked us not to contact them"],"retention":{"summary":"Kept until removal is requested — a suppression must outlive the data it suppresses.","criteria":"An entry is removed only at the explicit, verified request of the person it protects."},"source":"data_subject"},{"id":"audit_trail","name":"Append-only audit trail","purpose":"Recording every meaningful action taken in the hub — who did what, when — so that our compliance work is itself accountable.","lawful_basis":"legitimate_interests","lawful_basis_explanation":"It is in our legitimate interest, and that of the people whose rights we handle, to keep tamper-evident receipts of how requests, complaints and suppressions were dealt with. The trail stores actor labels and categorical metadata only, never request content, so the intrusion is minimal and the balance favours keeping it.","legitimate_interests_assessment_url":"https://compliance.radicaltechteam.co.uk/privacy","data_subject_categories":["hub users","compliance officers","application owners"],"retention":{"summary":"Audit events are kept for 6 years, matching the limitation period for statutory claims.","period_months":72},"source":"derived"}],"personal_data_inventory":[{"category":"Account details","description":"Your name and email address from your Lib Dem single sign-on, used to sign you in and show you your own requests.","fields":["users.email","users.email_sha256","users.oidc_sub","users.name"],"activity_ids":["rights_handling"],"source":"data_subject"},{"category":"Sign-in sessions","description":"While you are signed in we keep the session itself on our own server — who you are signed in as, and the token your sign-in provider gave us so we can sign you out there too. Your browser holds only a random identifier pointing at it. Signing out deletes the record; one left idle is deleted within a fortnight.","fields":["sessions.session_id","sessions.data"],"activity_ids":["rights_handling"],"source":"derived"},{"category":"Rights request records","description":"The requests you make, and the email addresses you ask us to search for across our applications, held only while we fulfil them.","fields":["subject_requests.details","subject_requests.identities","subject_identities.email","subject_identities.email_sha256"],"activity_ids":["rights_handling"],"source":"data_subject"},{"category":"Complaint records","description":"What you told us when you complained, and how to reach you about it.","fields":["complaints.name","complaints.email","complaints.email_sha256","complaints.body","complaints.outcome"],"activity_ids":["complaints_register"],"source":"data_subject"},{"category":"Suppressed address fingerprints","description":"A one-way SHA-256 hash of each address on the do-not-contact list, plus a heavily redacted hint for our compliance officers. The hash cannot be reversed to reveal the address.","fields":["suppressions.email_sha256","suppressions.email_redacted"],"activity_ids":["suppression_list"],"source":"data_subject"},{"category":"Audit trail entries","description":"Who did what and when: actor labels and categorical metadata only — never emails or request content.","fields":["audit_events.action","audit_events.actor_label","audit_events.metadata"],"activity_ids":["audit_trail"],"source":"derived"}],"processors":[],"security_measures":["TLS for every connection in transit","Encryption at rest for application credentials and export bundles","Append-only audit trail enforced by a database trigger","Role-based access control (subject, application owner, admin)","Sessions held server-side, so signing out ends the session everywhere rather than asking the browser to forget a credential it still holds","Content Security Policy permitting only our own origin — no third-party scripts, styles or fonts","Rate limiting on public endpoints"],"cookies":[{"name":"_compliance_session","purpose":"Keeps you signed in as you move between pages. It holds a random identifier and nothing else — the session itself is kept on our server, not in your browser. The cookie disappears when you close your browser.","category":"strictly_necessary","first_party":true,"duration":"session","requires_consent":false}],"marketing":{"performs_direct_marketing":false},"automated_decision_making":{"used":false,"description":"No decision in the hub is taken solely by automated means — a compliance officer reviews and closes every request, complaint and finding."},"complaints":{"electronic_form_url":"https://compliance.radicaltechteam.co.uk/complaints/new","contact_email":"data.protection@libdems.org.uk"},"data_subject_rights":{"native_portal":true,"portal_url":"https://compliance.radicaltechteam.co.uk/portal"}}