Skip to main content

How we protect you

Good data protection isn't a policy document in a drawer — it's a set of habits, built into how our systems work, that you can check for yourself. Here are ours.

We declare everything

Every application the party runs must publish a machine-readable declaration of the personal data it holds — what, why, on what legal basis, for how long, and who else touches it. This hub polls each declaration daily, checks it against a strict schema, grades it, and publishes the results on the applications page.

A declaration that goes stale or stops validating becomes a compliance finding — and we publish the count of open findings too. No quiet drift.

Your rights work here

You shouldn't need to know which of our systems holds your details. Make one request in the portal — access, correction, erasure, export, restriction or objection — and the hub fans it out to every application on your behalf, tracks the statutory deadline, and brings the answers back to one place. Your rights, explained.

The do-not-contact list is absolute

When you object to direct marketing — and for a political party that includes campaigning and fundraising messages — the objection is absolute. UK GDPR Article 21 gives us no balancing test, no discretion, no "but this one's important". We stop. Everywhere. Permanently.

Technically: your address goes onto a central suppression list as a one-way fingerprint, and every application must check that list before every send. A suppression outlives the data it suppresses.

We keep receipts

Every meaningful action in the hub — a request opened, a deadline extended, a suppression added, a complaint closed — is written to an append-only audit trail that a database trigger prevents anyone from editing or deleting, administrators included. Changes to records are versioned as well. When we say we did something, we can prove when and by whom.

We keep only what we need

Fulfilled requests are scrubbed of personal content after 12 months, keeping only the statistics — kind, dates, outcome. Export downloads expire after 30 days. The suppression list never stores your address at all — only a hash that cannot be reversed. Retention rules are declared per application, in public, and the details are in our privacy notice.

Running an efficient democratic service

Here's the part that surprises people: doing this properly makes our campaigning better. Volunteers don't waste an evening calling people who asked us not to. Donated money isn't spent mailing stale addresses. Data that's accurate, current and wanted is simply more useful than data that isn't.

Compliance done as an afterthought is a cost. Built in from the start, it's just running a good service — and a party that wants to run the country ought to be able to run its own database honestly.

Want the detail? Read your rights, the privacy notice, or browse every application's declaration. Think we've fallen short? Make a complaint — we're required to make that easy, and we want it easy.