B&PBulca & PartnersDiligence & Integrity
Overview / Data protection

Data protection

The safeguards and responsibilities that sensitive research requires.

Purpose and scope

This page explains the data-handling principles in our Code of Conduct and the arrangements to discuss when commissioning research. It complements the Privacy notice and Code of Conduct. It is not a certification, a security audit or a substitute for the terms applicable to a particular assignment.

Establish responsibilities

An engagement needs a defined purpose, applicable legal requirements, controller and processor roles, permitted recipients and appropriate notices. Roles follow the actual decisions and activities involved; they are not determined solely by the label used in a contract.

Limit collection

Our Code requires collection to be limited to the research question, with additional scrutiny for sensitive and criminal-record information. Irrelevant private details and unsupported inferences about relatives or associates have no place in an assessment. The provenance and permitted use of records matter alongside their content.

Control access and sharing

Access is governed by the assignment and the need to know. Delivery methods, authorised recipients and any provider involvement are matters to settle before transferring subject documents. Our Code requires scrutiny of providers, confidentiality, permitted processing and further subcontracting.

Review international transfers

International research requires an assessment of where providers and recipients process information and which transfer safeguards apply. Changes to an assignment or its providers can change those requirements. Contact us to discuss the arrangements relevant to your jurisdiction.

Keep evidence accurate and bounded

Our Code requires identity checks, source dates, relevant context and material contrary evidence to inform an assessment. Allegations and uncertainty must remain visible. Substantive conclusions require human review, and material errors must be corrected.

Retention and incidents

Retention is determined by record category, purpose, applicable obligations and lawful preservation needs. Our Code calls for secure deletion or return when retention is no longer justified.

Suspected loss, unauthorised access or disclosure should be reported promptly. Our Code requires appropriate protective action and assessment of any notification obligations. Reports can be sent to info@bulcapartners.com without attaching sensitive evidence to the initial message.

Requests and supplier discussions

For privacy requests, security concerns or questions about an engagement’s handling arrangements, contact info@bulcapartners.com. Describe the issue without attaching sensitive records initially. A general email address is not an anonymous reporting channel. Further verification and an appropriate exchange method may be needed.

Back to top ↑