GDPR and Data Protection Policy

Last updated: 28 August 2026

1. Purpose of this policy

This policy explains how Megri.co.uk approaches data protection and complies with applicable privacy law when operating https://www.megri.co.uk.

It is intended both as:

  • a public statement of our data-protection commitments; and
  • an operational framework for anyone who handles personal information on behalf of Megri.co.uk.

Our separate Privacy Policy explains in more detail what personal information we collect from website visitors, why we use it, who receives it, how long it is kept and the rights available to individuals. If this policy and the Privacy Policy address the same matter, the more specific information in the Privacy Policy should be followed for that processing activity.

Megri.co.uk is currently a free-to-access online publication. It does not operate an online shop or sell products, subscriptions or magazine issues through the website.

2. Who is responsible for data protection

The operator of Megri.co.uk is responsible for deciding why and how personal information is processed and is therefore the data controller for that processing.

Data-protection enquiries and complaints should be sent to:

Legal Adviser, Megri.co.uk
133 Creek Road
Greenwich
London SE8 3BU
United Kingdom

Email: [email protected]
Telephone: 07443 813 186

Where another organisation independently decides why and how it uses personal information, that organisation may be a separate controller. Where a supplier processes information only on our documented instructions, it acts as our processor.

3. Laws covered

Our principal data-protection framework is:

  • the UK General Data Protection Regulation (UK GDPR);
  • the Data Protection Act 2018;
  • the Data (Use and Access) Act 2025, including amendments brought into force from time to time; and
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) where electronic communications, cookies or similar technologies are involved.

The EU GDPR may apply to particular activities if we offer relevant services to people in the European Economic Area or monitor their behaviour there. The fact that a person in the EEA can simply read a publicly available article does not, by itself, mean that every EU GDPR requirement necessarily applies. We will assess territorial scope when introducing targeted services, campaigns or tracking.

4. Our data-protection principles

Anyone handling personal information for Megri.co.uk must follow these principles:

  1. Lawfulness, fairness and transparency: use personal information lawfully, fairly and in a way people can reasonably understand.
  2. Purpose limitation: collect information for clear purposes and do not use it incompatibly without a lawful justification.
  3. Data minimisation: collect only information that is adequate, relevant and necessary.
  4. Accuracy: take reasonable steps to keep information accurate and correct or delete inaccurate information where appropriate.
  5. Storage limitation: retain identifiable information only for as long as necessary.
  6. Integrity and confidentiality: protect information with security appropriate to the risks.
  7. Accountability: maintain appropriate policies, decisions and records to demonstrate compliance.

5. Personal information within scope

This policy applies to any information relating to an identified or identifiable living person. In the context of Megri.co.uk, this may include:

  • names, email addresses, telephone numbers and postal addresses;
  • correspondence, enquiries, complaints and correction requests;
  • contributor, author, photographer and source information;
  • comments or other material submitted for publication;
  • IP addresses, browser details, server logs and security records;
  • cookie identifiers, consent choices and analytics information where used;
  • information about suppliers, professional contacts and representatives; and
  • information appearing in editorial research or published material where data-protection law applies.

Anonymous information that cannot reasonably identify a person is not personal information. Pseudonymised information remains personal information where it can be linked back to an individual using additional information.

6. Special category and criminal-offence information

Information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, biometrics used for identification, sex life or sexual orientation receives additional protection.

We will process special category information only where:

  • an Article 6 lawful basis applies;
  • an additional condition under Article 9 of the UK GDPR and, where necessary, the Data Protection Act 2018 applies; and
  • appropriate safeguards and documentation are in place.

Criminal-offence information will be processed only where authorised by law and subject to appropriate safeguards.

Editorial, journalistic or public-interest activity may engage specific legal provisions. Such processing must be assessed case by case and must not be treated as automatically exempt from data-protection requirements.

7. Lawful bases

Before collecting or using personal information, we will identify and document an appropriate lawful basis. Depending on the activity, this may be:

  • consent, where a person has made a freely given, specific, informed and unambiguous choice;
  • contract, where processing is necessary to enter into or perform a contract with the individual;
  • legal obligation, where processing is necessary to comply with the law;
  • vital interests, in a genuine life-or-death situation;
  • public task, where a qualifying task in the public interest or official function applies; or
  • legitimate interests, where the processing is necessary for a legitimate purpose and is not overridden by the individual’s interests, rights or freedoms.

Where we rely on legitimate interests, we will identify the purpose, consider necessity and balance it against the likely effect on individuals. A legitimate-interests assessment should be recorded where the balance is not obvious or the processing presents more than minimal risk.

Consent will not be used merely because it appears convenient. Where consent is used, it must be as easy to withdraw as to give, and withdrawal must not affect processing carried out lawfully before withdrawal.

8. Transparency and privacy information

We will provide privacy information in a concise, accessible and understandable form at or before the point personal information is collected, unless a lawful exception applies.

The information provided will be proportionate to the activity and will normally identify:

  • the controller and contact details;
  • the categories and sources of personal information;
  • the purposes and lawful bases;
  • the legitimate interests pursued, where relevant;
  • recipients or categories of recipients;
  • international transfers and applicable safeguards;
  • retention periods or the criteria used to set them;
  • relevant individual rights;
  • whether information is required and the possible consequences of not providing it;
  • any qualifying automated decision-making; and
  • the right to complain to the Information Commissioner’s Office.

We will review the Privacy Policy and collection notices when our practices or legal obligations change.

9. Data minimisation, accuracy and retention

Forms and operational processes must request only information reasonably needed for their stated purpose. Optional information should be clearly distinguished from required information.

Reasonable steps must be taken to correct or remove inaccurate information, taking account of the context, source and significance of the information. Editorial disputes about accuracy should also be handled under the applicable corrections or complaints procedure.

Personal information must not be retained indefinitely merely because storage is available. We will maintain proportionate retention rules covering at least:

  • routine enquiries and correspondence;
  • complaints, corrections and legal notices;
  • contributor and contractual records;
  • website, security and server logs;
  • consent and preference records;
  • backups; and
  • published material and its supporting editorial records.

At the end of the relevant retention period, information should be securely deleted, anonymised or retained only where a documented legal, editorial, archival, security or dispute-related reason applies.

10. Privacy by design and default

Data protection must be considered when planning a new form, plugin, analytics tool, advertising service, editorial workflow, contributor system or other activity involving personal information.

Default settings should collect and expose the least personal information reasonably necessary. Access must be limited according to role and business need.

Before implementation, the responsible person should consider:

  • what information will be collected and why;
  • the lawful basis;
  • whether the purpose can be achieved with less information;
  • access, storage, deletion and security;
  • processor contracts and international transfers;
  • cookie or marketing consent;
  • risks to children or vulnerable people; and
  • what privacy information must be provided.

A Data Protection Impact Assessment (DPIA) must be completed before processing likely to result in a high risk to individuals. A DPIA is also good practice for major new or materially changed projects involving personal information.

11. Cookies and electronic communications

Cookies and similar technologies must be classified and documented. Users must receive clear information about what these technologies do and why they are used.

Technologies that are not strictly necessary must not be activated before valid consent where PECR requires it. Consent choices must be specific enough for the relevant purposes, recorded and capable of being changed or withdrawn. Rejecting optional technologies should be as easy as accepting them.

Any future email marketing must comply with both data-protection law and PECR. Marketing lists must not be purchased, scraped or used without confirming a lawful basis and any required consent. Objections and unsubscribe requests must be respected promptly, although minimal suppression records may be retained to prevent further marketing.

12. Suppliers, processors and data sharing

Before giving a supplier access to personal information, we will assess the service, data involved, security, location of processing and applicable contractual protections.

A processor must be engaged under written terms meeting applicable legal requirements. These terms should address, as relevant:

  • documented processing instructions;
  • confidentiality;
  • security;
  • use of sub-processors;
  • help with individual rights, DPIAs and breaches;
  • deletion or return of information at the end of the service; and
  • audits and information needed to demonstrate compliance.

We will keep a current record of material processors and review them periodically. Personal information must not be shared merely because another person or organisation requests it. The purpose, lawful basis, necessity, proportionality and security of a proposed disclosure must be considered first.

13. International transfers

Before making a restricted transfer of personal information outside the United Kingdom, we will identify a lawful transfer mechanism. This may include UK adequacy regulations, an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum, or a specific legal exception.

Where safeguards are used, we will carry out and document any required transfer risk assessment and adopt supplementary protections where necessary. Supplier claims about hosting location must be checked rather than assumed.

14. Information security

We will use technical and organisational security measures proportionate to the nature of the information and the risks. Depending on the system, these may include:

  • individual accounts and role-based access;
  • strong passwords and multi-factor authentication;
  • timely WordPress, theme, plugin and server updates;
  • secure hosting, firewalls and malware protection;
  • encryption in transit and, where appropriate, at rest;
  • protected backups and tested recovery procedures;
  • restrictions on downloading or sharing personal information;
  • logging, monitoring and incident response; and
  • secure deletion and disposal.

People with access to personal information must keep it confidential, use it only for authorised purposes and report suspected loss, disclosure or misuse immediately.

15. Personal data breaches

A personal data breach includes accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to personal information. Examples include sending information to the wrong recipient, compromised login details, malware, loss of a device, unauthorised publication or improper deletion.

Anyone who becomes aware of a suspected breach must immediately notify the person responsible for data protection at [email protected]. They must not delay reporting while attempting to investigate alone.

We will:

  1. contain the incident and preserve relevant evidence;
  2. record the facts, affected information, likely consequences and remedial action;
  3. assess the risk to individuals;
  4. notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach;
  5. notify affected individuals without undue delay where the law requires it; and
  6. document the decision whether or not to notify.

All personal data breaches must be recorded, including those that do not meet the reporting threshold.

16. Individual rights requests

Individuals may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent, as well as rights concerning qualifying automated decisions.

Requests may be made verbally or in writing and do not need to mention the UK GDPR. Anyone receiving a request must forward it promptly to [email protected].

We will:

  • record the request and calculate the applicable deadline;
  • verify identity proportionately where needed;
  • conduct reasonable and proportionate searches;
  • consider the particular right, lawful basis and any applicable exemption;
  • protect the rights of other people when preparing a response; and
  • respond within the legally required period, normally one month, unless a lawful extension applies.

A request will normally be handled free of charge. A fee or refusal will be considered only where permitted by law, and the reasons will be documented and explained.

17. Data-protection complaints

Anyone may raise a complaint about our use of personal information by emailing [email protected], calling 07443 813 186, or writing to the address in section 2.

We will provide a clear way to complain and will:

  • acknowledge a data-protection complaint within 30 days;
  • take appropriate steps to investigate it;
  • keep the complainant appropriately informed; and
  • communicate the outcome without undue delay.

Complaint records will be kept securely and retained only as long as needed for resolution, accountability and legal purposes.

An individual also has the right to complain to the Information Commissioner’s Office (ICO). Information is available at https://ico.org.uk/make-a-complaint/. We would appreciate an opportunity to address the concern first, but this does not restrict the right to approach the ICO.

18. Children

Megri.co.uk is a general-audience publication and is not designed specifically for children. We do not knowingly ask children to create accounts, buy services or provide personal information through the website.

Before introducing a service likely to be accessed by children, we will assess the best interests and needs of children, apply privacy-protective defaults, provide age-appropriate information and consider whether the ICO’s Children’s Code applies.

19. Automated decision-making and artificial intelligence

We do not use solely automated decision-making through the Website to make decisions that produce legal or similarly significant effects on visitors.

If artificial-intelligence tools are used in editorial or administrative work, personal information must not be entered into such a tool unless:

  • the use is necessary and has a documented lawful basis;
  • the provider, contractual terms, retention, training use and international transfers have been assessed;
  • confidential, special category and source-identifying information are protected;
  • appropriate human oversight is maintained; and
  • affected individuals receive any transparency information required by law.

20. Records, training and responsibility

We will maintain records proportionate to our processing and risk. These may include:

  • a data and processing inventory;
  • lawful-basis and legitimate-interests assessments;
  • processor contracts and supplier reviews;
  • DPIAs;
  • consent and objection records;
  • rights-request and complaint logs;
  • retention rules;
  • international-transfer assessments; and
  • a personal data breach register.

Anyone with regular access to personal information must receive appropriate instructions or training. Responsibility for compliance remains with the controller even where work is delegated to a supplier or contractor.

We will assess whether appointment of a formal Data Protection Officer is legally required. A contact person described as the Legal Adviser or privacy contact is not automatically a statutory Data Protection Officer.

21. Review and approval

This policy will be reviewed at least annually and sooner following a significant change to the Website, a material incident, a new high-risk activity or a relevant legal or regulatory development.

Operational records should show:

Policy owner: Legal Adviser
Approved by: Legal Adviser
Approval date: Legal Adviser
Next scheduled review: 28 August 2027