Data Protection Policy

Congruent means the Congruent Group consisting of Congruent Holdings Limited and its subsidiary companies. Congruent takes it obligations under the Data Protection Act 2018 very seriously and strives for the highest standards. Congruent’s lead data protection supervisory authority is the Information Commissioner’s Office (ICO) in the United Kingdom.

This Data Protection Policy also includes our Privacy Policy.


  • Consent – Consent is given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement.
  • Data Controller – The organisation or individual that determines the purpose and means of data processing.
  • Data Processor – An organisation or individual that processes data on behalf of a data controller.
  • Data Subject – An identified or identifiable natural (living) person.
    Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
  • Personal Data – Any data relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Processing – Any operation/set of operations which performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, and ‘process’ and ‘processed’ shall be construed accordingly.

Data Protection Act

Congruent companies that are Data Controllers are registered under the Data Protection Act. Congruent is responsible for compliance with the Data Protection Principles contained within the Data Protection Act.

The six principles of the Data Protection Act for personal data are as follows.

  1. Processed lawfully, fairly and in a transparent manner in relation to individuals.
  2. Collected for specified, explicit and legitimate purposes and not processed beyond those.
  3. Adequate, relevant and limited to what’s necessary in relation to the purposes for which they are processed.
  4. Accurate and, where necessary, kept up-to-date.
  5. Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  6. Processed in a manner that ensures appropriate security of the personal data.

The Data Protection Act includes the following rights for individuals.

  • The right to be informed (which is the right to be provided with clear, transparent and easily understandable information about how Congruent uses your information and your rights relating to the information).
  • The right of access to the personal data which is processed and information about how it is being used.
  • The right to rectification if personal data is inaccurate or incomplete.
  • The right to erasure in certain circumstances where there is no reason for Congruent to continue to process the data.
  • The right to restrict further processing of personal data.
  • The right to data portability of personal data between different service providers.
  • The right to object to certain types of processing, such as direct marketing.
  • The right not to be subject to decisions based solely on automated decision-making, including profiling.

The six legal grounds personal data can be processed are as follows.

  1. The data subject has given consent for a specific purpose.
  2. It’s necessary for the performance of a contract with the data subject.
  3. It’s necessary for the controller to comply with a legal obligation.
  4. It’s necessary to protect the vital interest of the data subject or other natural person.
  5. It’s necessary to perform a task in the public interest or for official functions.
  6. It’s necessary for the purpose of the legitimate interest pursued by the controller or third party except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

Congruent principles

Congruent focuses pro-actively on compliance with data protection regulations and in addition, adheres to its own principles:

  • Congruent staff are kept up-to-date and trained on data protection regulations and best practices for the safe handling of personal data.
  • Congruent only deals with reputable organisations, and where there might be any grounds for suspicion it is alert to avoid being involved in what might be improper use of personal data.
  • Congruent adopts best practice in the administration and security of its computer systems, and keeps up-to-date with technical developments and emerging risks to network integrity.
  • Congruent monitors its computers systems and the personal data that they hold, which includes the access to and use of that data by its staff in order to ensure that only relevant data is accessible for the roles of individual staff, there is no misuse and that data is not put at risk.
  • Congruent has a continuous data protection programme to ensure compliance and safeguards within all operations, which include activities such as privacy impact assessments, regular audits, policy reviews and updates, and training.

Personal data

Personal data covers both facts and opinions about an individual where that data identifies an individual. The personal data held by Congruent falls into three categories:

  • Staff and associates of Congruent, as well as possible recruits and past staff.
  • Individuals with whom Congruent has a business relationship, such as clients, trade bodies, professional advisers, regulatory organisations and suppliers:
  • Individuals whose investment and insurance needs are analysed by Congruent in the course of its business as a professional firm.

Processing of personal data

Congruent will only process personal data when a legal basis has been clearly identified above.

  • Staff, associates, potential recruits: Congruent processes employment details and other employment-related data for potential recruits, and current and former staff. Congruent carries out this processing in order to prepare for and carry out employment contracts, and to comply with legal obligations as an employer. Further details are available to employees in the staff handbook.
  • Individuals with whom Congruent has a business relationship: Congruent processes contact details of these individuals, such as names, addresses, email addresses and professional interests. If the individual has specifically opted-in, Congruent uses this information to send out communications related to Congruent’s business. Other business contact information is used by Congruent for its legitimate business interests. This involves contacting specific people in connection with current business or future business issues. The information may be passed to third parties that provide services to Congruent to enable Congruent to carry out the purposes referred to above.
  • Individuals who hold financial products or have received financial services: When Congruent provides a service to an individual who holds financial products or has received financial services, or to an individual whose financial investment and insurance needs are analysed by Congruent as part of a service contract, the only data Congruent obtains is that required to provide the service. The data will be obtained from the individual directly or from elsewhere at the specific request of the individual via the relevant data controller. Upon the evaluation of data obtained for the performance of contracts, if Congruent becomes exposed to information that is in addition to the information required to performing the required service, Congruent will only use the information that is required to provide the service and will take measures, where possible, to limit such exposure. Congruent has written contracts with the clients for whom Congruent processes this information and Congruent complies with their written instructions for how the information may be used.

Sensitive personal data

Congruent may hold sensitive data about its staff which will have been provided to facilitate employment duties and information which would be relevant to their employment and relationships with other members of staff. Information relating to Congruent’s use of personal information relating to staff is set out in the staff handbook (which is available to all Congruent staff). Due to the nature of the services which Congruent provides, Congruent can hold sensitive personal data about individuals. This data may contain a variety of information including financial details (including historic), family details and health information. The situation arises because Congruent provides services to independent financial advisers, insurance companies, regulators, solicitors, courts of law and others who in the course of their business need to consider the holdings of investments and investment and insurance needs of individuals, sometimes on the instructions of the individual but sometimes in an adversarial, monitoring or other capacity. Congruent processes this information to comply with the service contracts that relate to the individuals.


Congruent will only accept consent as any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

For further information about how Congruent collects, looks after and uses personal data for its marketing, please read our privacy policy. Consent for these types of communications can be changed and withdrawn at any time through options available within these communications.

Retention of data

Congruent will not retain personal data for longer than it is needed for its authorised purpose. Where Congruent processes data on the basis of an individual’s consent, once consent has been withdrawn, our systems will be updated immediately and the personal data will be removed from use (as defined within the request for the withdrawal of consent) and will be deleted. For the performance of contracts, a defined period for the retention of data will be agreed with the data controller.

Congruent periodically reviews the data held about individuals with whom Congruent maintains a business relationship to ensure that it is still relevant to Congruent’s business needs.

Subject access requests

Congruent will provide access to personal data which it holds, upon request, subject to checking that the personal data may legally be provided and with agreement from the Data controller (either Congruent or client; whichever is the data controller). There will be no charge for providing this information unless they are manifestly unfounded or excessive. Congruent will ensure that the information is made available within 30 days. Congruent may require further time (up to a maximum of 2 further months) if the request for information is complex – in this case we will inform the data subject accordingly. If Congruent refuses a request for personal data, it will inform the individual with the reasons why and that they have the right to complain to the supervisory authority and to a judicial remedy. To make a formal request to access personal data that we hold about you, please contact us. Congruent’s marketing communications will contain links to access and update the data subject’s core contact details and mailing and subscription preferences.

Data security

Congruent provides highly secure computer systems, applications and devices for its staff. It also hosts a range of computer applications and services to organisations as part of a contract. Large volumes of data pass over this network of computers, applications and devices which contain adequate controls for the separation and management of data. Congruent monitors the data and traffic in the capacity of a network administrator as well as in the capacity of operator of its own business and as an employer. Congruent makes it clear to all those individuals and organisations affected what roles it carries out in the operation of the network. Congruent staff will only have access to personal data that is relevant to fulfil their roles and for the performance of contracts. Congruent has strict policies and procedures for its staff around the use of computer systems, applications and devices to minimise the risks to personal data, which includes the use of personal data within external communications and systems outside the control and monitoring of Congruent. Congruent policies and procedures extend to all other methods for containing personal data, which includes printed documents and all paper files.

Personal data breaches

Congruent has procedures to effectively detect, report and investigate a personal data breach. If a personal data breach has been verified, then Congruent will take immediate action by informing the data controller (if not Congruent), and where appropriate informing affected data subjects (in liaison with the data controller), and the supervisory authority.

Further information

For all data protection matters, please contact us.