NODE · LON-01|LONDON --:--:--
DC-Services — Digital Claims Services Limited
Legal Documentation

DC-Services UK Lawful Basis for Processing

Article 6 UK GDPR grounds applied across DC-SERVICES UK documentation engagements.

This page sets out the lawful bases on which Digital Claims Services Limited (trading as DC-SERVICES UK) processes personal data in the course of its documentation work. It sits alongside the Privacy Policy and is informational only — it is not financial, investment, legal or tax advice.

Last reviewed: February 2026 · 20 sections

lawful-basis-for-processing.pdf · A4 · brandedAll documents
01

Purpose of the page

  1. 1.1DC-SERVICES UK publishes this page so every category of personal data processing is matched to a specific, named lawful basis under the UK GDPR.
  2. 1.2A lawful basis is the legal ground that permits a controller to process personal data; processing without one is unlawful.
  3. 1.3Internally each processing activity is mapped to a basis in our Record of Processing Activities before processing begins.
  4. 1.4Anyone may consult this page to understand why DC-SERVICES UK holds or handles information about them.
02

Role of DC-SERVICES UK

  1. 2.1DC-SERVICES UK acts as a data controller for its own website, marketing and onboarding data, and may act as a processor for client-supplied documentation.
  2. 2.2A controller decides why and how data is processed; a processor acts only on documented instructions from a controller.
  3. 2.3The role is decided per engagement and recorded in the engagement letter or applicable Data Processing Agreement.
  4. 2.4Each client is told in writing whether DC-SERVICES UK is acting as controller or processor for the data they entrust to us.
03

Relationship to Digital Claims Services Limited

  1. 3.1DC-SERVICES UK is the trading style of Digital Claims Services Limited, a company registered in England & Wales under company number 08948101.
  2. 3.2All data-protection obligations referenced on this page are obligations of Digital Claims Services Limited under UK law.
  3. 3.3Contracts, notices and records of processing are issued in the name of Digital Claims Services Limited.
  4. 3.4The trading name is used for public-facing communications; the legal entity remains the responsible controller or processor.
04

Categories of personal data processed

  1. 4.1We process identification, contact, engagement, billing, communications and technical data — and only the categories actually needed for the work.
  2. 4.2Personal data is any information relating to an identified or identifiable natural person.
  3. 4.3Each category is recorded in our Record of Processing Activities together with its source, purpose and retention period.
  4. 4.4Where the engagement does not require a category, it is not collected and is rejected if offered.
05

Client materials and submitted records

  1. 5.1Client materials submitted for documentation work are processed strictly to perform the engagement and for no other purpose.
  2. 5.2Submitted records may contain personal data about the client and, where relevant, third parties named in those records.
  3. 5.3Materials are stored in restricted client folders, indexed and accessible only to the assigned case team.
  4. 5.4Clients are responsible for the lawfulness of their disclosure to us; we do not solicit data beyond engagement scope.
06

Contractual necessity (UK GDPR Art. 6(1)(b))

  1. 6.1Where data is processed to take steps requested by the client before entering a contract, or to perform the engagement itself, we rely on contractual necessity.
  2. 6.2Article 6(1)(b) permits processing necessary for the performance of a contract with the data subject.
  3. 6.3This basis applies to onboarding, scoping, deliverable preparation, invoicing and engagement correspondence.
  4. 6.4If the client objects, the basis no longer holds and the engagement cannot be performed.
07

Legal obligation (UK GDPR Art. 6(1)(c))

  1. 7.1Where processing is required by UK statute or by regulatory or court order, we rely on legal obligation as the lawful basis.
  2. 7.2Article 6(1)(c) permits processing necessary for compliance with a legal obligation to which the controller is subject.
  3. 7.3Examples include record retention under tax law, MLR 2017 obligations and responses to lawful disclosure requests.
  4. 7.4Where this basis is relied upon, the specific legal obligation can be disclosed on request to the data subject.
08

Legitimate interests (UK GDPR Art. 6(1)(f))

  1. 8.1Where we rely on legitimate interests, we have first carried out and recorded a balancing assessment between our interest and the data subject's rights.
  2. 8.2Article 6(1)(f) permits processing necessary for legitimate interests, unless overridden by the data subject's interests, rights or freedoms.
  3. 8.3Examples include site security logging, fraud prevention and handling unsolicited business enquiries.
  4. 8.4Data subjects may object at any time; objections are reviewed against the recorded balancing test.
09

Consent where applicable (UK GDPR Art. 6(1)(a))

  1. 9.1Consent is used only where required and is collected by clear affirmative action, separately from other terms.
  2. 9.2Consent under the UK GDPR must be freely given, specific, informed and unambiguous, and capable of being withdrawn at any time.
  3. 9.3Non-essential cookies, electronic marketing communications and certain optional analytics rely on consent.
  4. 9.4Withdrawal is as easy as giving consent; withdrawal does not affect the lawfulness of past processing.
10

Special category data handling (UK GDPR Art. 9)

  1. 10.1Special category data is not actively collected; if such data appears in client materials, we apply an Article 9 condition before further processing.
  2. 10.2Special category data includes data revealing racial origin, political opinions, religion, health, sex life and biometric data used for identification.
  3. 10.3Where engagement scope unavoidably touches such data, the controller condition is recorded and the data is minimised.
  4. 10.4Clients are asked not to send special category data unless strictly necessary for the engagement.
11

Criminal offence data position (UK GDPR Art. 10)

  1. 11.1Criminal offence data is processed only where a UK statutory authority or a Schedule 1 condition under the Data Protection Act 2018 permits it.
  2. 11.2Article 10 restricts processing of personal data relating to criminal convictions and offences.
  3. 11.3Where it is incidental to the engagement, it is segregated, access-restricted and reviewed by a senior preparer.
  4. 11.4Clients are told if criminal offence data identified in their materials affects the conduct of the engagement.
12

Data minimisation

  1. 12.1We process the minimum personal data needed to perform the engagement and decline data that is excessive.
  2. 12.2Data minimisation is the UK GDPR principle that data must be adequate, relevant and limited to what is necessary.
  3. 12.3Onboarding forms, intake checklists and deliverable templates are reviewed periodically to remove unneeded fields.
  4. 12.4If data was supplied that is not needed, it is deleted promptly and the deletion is recorded.
13

Purpose limitation

  1. 13.1Personal data collected for one purpose is not re-used for an incompatible purpose without a fresh lawful basis.
  2. 13.2Purpose limitation under the UK GDPR requires data to be collected for specified, explicit and legitimate purposes.
  3. 13.3Internal staff cannot repurpose client data for analytics, marketing or unrelated engagements.
  4. 13.4Where a compatible secondary purpose is identified, the data subject is informed before processing begins.
14

Retention connection

  1. 14.1Retention periods are set by reference to the lawful basis on which data was collected and statutory requirements that apply afterwards.
  2. 14.2Retention rules are recorded separately in our Data Retention Policy.
  3. 14.3On expiry of the retention window, data is either deleted or anonymised, and the deletion event is logged.
  4. 14.4Data subjects can request our retention schedule for the categories of data we hold about them.
15

User rights connection

  1. 15.1All UK GDPR data subject rights apply to data we process about identified individuals.
  2. 15.2Those rights include access, rectification, erasure, restriction, portability and objection, subject to legal exceptions.
  3. 15.3Requests are routed to the Data Protection Officer and responded to within one calendar month.
  4. 15.4Where a right is limited, the data subject is told which exception applies and is given a route to challenge it.
16

Withdrawal of consent

  1. 16.1Where consent is the lawful basis, the data subject may withdraw it at any time without giving reasons.
  2. 16.2Withdrawal stops further processing on that basis but does not affect prior, lawful processing.
  3. 16.3Withdrawal mechanisms are provided in the same channel that collected the consent (for example unsubscribe links and the cookie panel).
  4. 16.4Withdrawal is acknowledged in writing and the change is reflected in our records.
17

Objection to processing

  1. 17.1Data subjects may object to processing based on legitimate interests, public interest or direct marketing.
  2. 17.2Article 21 UK GDPR requires the controller to stop processing unless it can show compelling, overriding grounds.
  3. 17.3Objections are reviewed by the Data Protection Officer and decided in writing, with reasoning recorded.
  4. 17.4Where the objection succeeds, the affected processing stops and the data subject is informed.
18

Data protection contact route

  1. 18.1The Data Protection Officer is the single contact point for all data-protection questions, requests and complaints.
  2. 18.2Contact is by email to dataprotection@dc-service.uk or by post to our registered office in the United Kingdom.
  3. 18.3All data-protection correspondence is logged with an internal reference number and audit trail.
  4. 18.4Data subjects may also complain to the Information Commissioner's Office (ICO) at any time.
19

Review and update process

  1. 19.1This page is reviewed at least annually and whenever processing activities materially change.
  2. 19.2Reviews are owned by the Data Protection Officer and approved by the Compliance Office.
  3. 19.3Changes are version-controlled and a change log is retained internally.
  4. 19.4Material changes are notified to active clients and published with a new 'Last reviewed' date.
20

Limitations and transparency statement

  1. 20.1This page is an informational statement of lawful bases — it is not financial, investment, legal or tax advice.
  2. 20.2Reliance on this page does not create a regulated services relationship between DC-SERVICES UK and the reader.
  3. 20.3Specific data-protection questions about an active engagement should be raised with the engagement team.
  4. 20.4If there is a conflict between this page and a signed engagement letter, the engagement letter prevails.
Frequently Asked Questions

Questions about this page

Which lawful basis is used most often?
Contractual necessity (Article 6(1)(b)) — most processing is required to perform the documentation engagement the client has asked us to undertake.
Do you process special category data?
Not by default. If special category data appears in client materials, we minimise it, segregate it and apply an Article 9 condition before further processing.
Can I withdraw consent at any time?
Yes, where consent is the lawful basis. Withdrawal stops further processing on that basis but does not affect prior, lawful processing.
How do I exercise my UK GDPR rights?
Write to the Data Protection Officer at dataprotection@dc-service.uk. We respond within one calendar month and explain any applicable exception.