Legal & compliance centre

HLD Group

Data processing & DPA standards

Processor obligations, subprocessors, and data subject rights.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines how HLD Group processes personal data lawfully, fairly, and securely, both as a controller of our own data and as a processor acting on behalf of customers. It establishes the privacy principles and obligations that govern all handling of personal data across our operations.

2. Scope

This policy applies to all processing of personal data by HLD Group, in any jurisdiction, whether we determine the purposes of processing (as controller) or process on documented instructions from a customer (as processor).

3. Definitions

  • Personal data / personal information — information about an identified or reasonably identifiable individual
  • Processing — any operation performed on personal data, from collection to deletion
  • Controller — the party that determines the purposes and means of processing
  • Processor — the party that processes personal data on behalf of a controller
  • Data subject — the individual to whom personal data relates
  • Cross-border transfer — a transfer of personal data to another country or international organisation

4. Data protection principles

  • Lawfulness, fairness, and transparency in how personal data is handled
  • Purpose limitation — data is collected for specified purposes and not used incompatibly
  • Data minimisation — only data that is adequate, relevant, and necessary is processed
  • Accuracy — data is kept accurate and up to date
  • Storage limitation — data is retained only as long as necessary, under the Data Retention Policy
  • Integrity and confidentiality — data is protected by appropriate security
  • Accountability — we can demonstrate compliance with these principles
  • Privacy Act 1988 (Cth) and the Australian Privacy Principles
  • Regulation (EU) 2016/679 (GDPR) and applicable member-state law; UK GDPR and the Data Protection Act 2018
  • California Consumer Privacy Act as amended by the CPRA, and other applicable US state privacy laws
  • Sector-specific privacy requirements applicable to particular engagements

6. Lawful basis and transparency

As a controller, HLD Group identifies and records a lawful basis for each processing activity and provides clear privacy information to individuals. Consent, where relied upon, is freely given, specific, informed, and revocable. Special category and sensitive data receive additional protection and are processed only where a valid condition applies.

7. Processing as a processor

Where HLD Group processes customer personal data as a processor, we act only on the customer’s documented instructions under a data processing agreement, assist the customer with data subject requests and security obligations, and do not engage subprocessors without authorisation.

  • Processing is limited to the documented purposes of the engagement
  • Subprocessors are assessed and bound to equivalent obligations, and disclosed to the customer
  • We assist customers with data subject requests, breach notification, and impact assessments
  • Data is returned or deleted at the end of the engagement as instructed

8. Data subject rights

  • Access to their personal data and information about its processing
  • Correction of inaccurate or incomplete data
  • Erasure where a legal basis for retention no longer exists
  • Restriction of and objection to certain processing
  • Data portability where applicable
  • Not to be subject to solely automated decisions with legal or similarly significant effect, without safeguards

9. Cross-border transfers

Personal data is transferred across borders only where a lawful transfer mechanism is in place, such as an adequacy decision, standard contractual clauses, or another approved safeguard, together with any transfer risk assessment required. Australian Privacy Principle 8 obligations regarding overseas disclosure are met where applicable.

10. Security, breaches, and impact assessments

Personal data is protected by the security controls set out in our information security policies. Data breaches are handled under the Breach Notification Policy. Data protection impact assessments are conducted for high-risk processing, including certain AI uses under the AI Governance Policy.

11. Roles, exceptions, and review

A privacy officer owns this policy with the CISO. Exceptions require documented approval; statutory rights and obligations cannot be waived internally. This policy is reviewed at least annually and on any material change to privacy law.

Related frameworks

For contractual attestations or audit packs, contact [email protected].