LegalIdle Shark Limited
GDPR Guidelines
Operational Compliance Policy & Client Governance Standard
011. Overview & Operational Scope
This document outlines the data protection compliance framework maintained by Idle Shark Limited. It governs internal data practices across our UX/UI design, software engineering, branding, digital marketing, and ongoing maintenance services, assuring commercial clients that our development and marketing workflows satisfy UK GDPR obligations.
022. Operational Roles: Controller vs. Processor
- Data Controller Role: Idle Shark Limited acts as Data Controller for personal data gathered directly for agency sales, website traffic analytics, client invoicing, and business administration.
- Data Processor Role: Idle Shark Limited acts as a Data Processor when building, hosting, configuring, or engineering digital systems that handle personal data belonging to our client's end-users.
033. Service Compliance Integration
A. UX/UI Design (Privacy by Design & Default)
- Data Minimisation: Form layouts and user interface components must restrict inputs to data fields strictly necessary for the core interaction.
- Explicit Consents: UI mockups must incorporate unchecked consent boxes for marketing or analytics. Pre-ticked checkboxes are strictly prohibited.
B. High-Performance Product Engineering
- Credential Protection: Authentication architecture must deploy industry-standard hashing algorithms (e.g., Argon2, bcrypt).
- Environment Isolation: Testing, staging, and development environments must never use unanonymized production user databases.
C. Digital Marketing & SEO Services
- PECR Direct Email Rules: Marketing emails sent on behalf of clients must rely on verified explicit consent or satisfy strict "soft opt-in" conditions.
- Unsubscribe Mechanics: Commercial emails must feature a functional, one-click unsubscribe link.
- Analytics Consent Management: Tracking tags and pixels must be integrated via a compliant Consent Management Platform (CMP).
D. Maintenance & Ongoing Support
- Patch Management: Core platform dependencies, frameworks, and CMS engines must be systematically updated to patch security vulnerabilities.
- Encrypted Backups: Automated system backups are encrypted both in transit and at rest with restricted access logging.
044. Article 28 Data Processing Agreement (DPA) Summary
When Idle Shark Limited acts as a Data Processor for a client, our client contracts incorporate standard UK GDPR Article 28 DPA terms:
- Documented Instructions: We process end-user personal data solely on documented instructions from the Client (Data Controller).
- Staff Confidentiality: All developers, engineers, and personnel handling client databases are bound by strict non-disclosure obligations.
- Sub-Processor Governance: We engage vetted sub-processors and notify clients prior to modifying infrastructure partners.
- 48-Hour Incident SLA: In the event of a confirmed personal data security breach affecting client systems under our management, Idle Shark Limited will notify the Client within 48 hours of confirmation to facilitate ICO compliance.
- Data Deletion/Return: Upon project completion or contract termination, all client personal data assets will be securely deleted or returned in accordance with contract terms.
055. Governance Contact & Compliance Enquiries
To execute a formal Data Processing Agreement (DPA) or submit a data protection inquiry:
- Company Name: Idle Shark Limited
- Email: info@idleshark.com
- Subject Line: Attn: Data Compliance Coordinator
- Website: https://idleshark.com/