Idle Shark
Start a project

LegalIdle Shark Limited

GDPR Guidelines

Operational Compliance Policy & Client Governance Standard

Company Name
Idle Shark Limited
Company Registration Number
17214821
Registered Office Address
70 St Stephens Road, London, E6 1AW, United Kingdom
Effective Date
5 August 2026
Contact Email
info@idleshark.com

011. Overview & Operational Scope

This document outlines the data protection compliance framework maintained by Idle Shark Limited. It governs internal data practices across our UX/UI design, software engineering, branding, digital marketing, and ongoing maintenance services, assuring commercial clients that our development and marketing workflows satisfy UK GDPR obligations.

022. Operational Roles: Controller vs. Processor

  • Data Controller Role: Idle Shark Limited acts as Data Controller for personal data gathered directly for agency sales, website traffic analytics, client invoicing, and business administration.
  • Data Processor Role: Idle Shark Limited acts as a Data Processor when building, hosting, configuring, or engineering digital systems that handle personal data belonging to our client's end-users.

033. Service Compliance Integration

A. UX/UI Design (Privacy by Design & Default)

  • Data Minimisation: Form layouts and user interface components must restrict inputs to data fields strictly necessary for the core interaction.
  • Explicit Consents: UI mockups must incorporate unchecked consent boxes for marketing or analytics. Pre-ticked checkboxes are strictly prohibited.

B. High-Performance Product Engineering

  • Credential Protection: Authentication architecture must deploy industry-standard hashing algorithms (e.g., Argon2, bcrypt).
  • Environment Isolation: Testing, staging, and development environments must never use unanonymized production user databases.

C. Digital Marketing & SEO Services

  • PECR Direct Email Rules: Marketing emails sent on behalf of clients must rely on verified explicit consent or satisfy strict "soft opt-in" conditions.
  • Unsubscribe Mechanics: Commercial emails must feature a functional, one-click unsubscribe link.
  • Analytics Consent Management: Tracking tags and pixels must be integrated via a compliant Consent Management Platform (CMP).

D. Maintenance & Ongoing Support

  • Patch Management: Core platform dependencies, frameworks, and CMS engines must be systematically updated to patch security vulnerabilities.
  • Encrypted Backups: Automated system backups are encrypted both in transit and at rest with restricted access logging.

044. Article 28 Data Processing Agreement (DPA) Summary

When Idle Shark Limited acts as a Data Processor for a client, our client contracts incorporate standard UK GDPR Article 28 DPA terms:

  • Documented Instructions: We process end-user personal data solely on documented instructions from the Client (Data Controller).
  • Staff Confidentiality: All developers, engineers, and personnel handling client databases are bound by strict non-disclosure obligations.
  • Sub-Processor Governance: We engage vetted sub-processors and notify clients prior to modifying infrastructure partners.
  • 48-Hour Incident SLA: In the event of a confirmed personal data security breach affecting client systems under our management, Idle Shark Limited will notify the Client within 48 hours of confirmation to facilitate ICO compliance.
  • Data Deletion/Return: Upon project completion or contract termination, all client personal data assets will be securely deleted or returned in accordance with contract terms.

055. Governance Contact & Compliance Enquiries

To execute a formal Data Processing Agreement (DPA) or submit a data protection inquiry: