Data Protection Policy

Policy summary

Delta Housing Association, hereafter referred to as Delta, needs to collect and process personal information about people to carry out our business and provide services. Everyone who interacts with Delta has a right to privacy and to expect that all personal information about them will be handled sensitively and with due regard to its confidentiality. This policy sets out how we safeguard your personal information and data protection rights.

Delta’s nominated Data Protection Officer (DPO) is responsible for overseeing questions in relation to this policy. If you have any questions about this policy, including any requests to exercise your legal rights, please contact the DPO.  

How to contact the DPO

If you live in a former CHP home, were a CHP employee, or were employed by Delta Housing Association after 1 April 2026:  

 

If you live in a former Estuary Housing Association home or were an Estuary employee:

  • email dpo@estuary.co.uk
  • call 0300 304 5000. If you’re unsure, please contact any of the options above, and we’ll direct your query to the right team. 

1. Policy Purpose

1.1 Delta needs to collect and process personal information about people to carry out our business and provide services. Everyone who interacts with Delta has a right to privacy and to expect that all personal information about them will be handled sensitively and with due regard to its confidentiality.  

1.2 This policy sets out our commitment to protecting personal data, safeguarding individuals’ privacy and ensuring compliance with their rights. It explains the data protection principles that we will adhere to and the rights of individuals in relation to their personal data. It covers how we ensure we’ll integrate privacy considerations into our data processing activities, ensuring we act in line with the requirements in data protection legislation in the work we do.  

2. Scope

2.1 This policy applies to all personal data and special categories of personal data held and processed by Delta Housing Association, hereafter referred to as Delta, that relates to living identifiable individuals, regardless of the category of data. It applies to all personal data we process, regardless of the media on which that data is stored.

2.2 It includes data of customers, employees (permanent and temporary), Board members, housing applicants, volunteers, homebuyers, Homebuy equity loan customers, contractors and third parties, where appropriate. This includes data relating to former CHP and Estuary Housing Association customers, employees and other stakeholders. It also includes data processed by subsidiaries of Delta, and if we manage homes on behalf of other partners.

2.3 This policy should be followed by anyone who has access to the personal data Delta processes or systems which process personal data. This includes Board members, employees, volunteers, and other third parties.  

2.4 Some key terms used in this policy include: 

Key Terms
Term Definition
Data subject Any natural person who is the subject of personal data held by an organisation. 
Data controller The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Delta is a data controller and is responsible for your personal data (collectively referred to as ‘we’, ‘us’ or ‘our’ in this policy). 
Data processor An entity or individual that processes personal data on behalf of the controller. 
Personal data

Data which relates to a living individual which:

  • directly identifies a person (e.g. name, address or contact information);
  • indirectly identifies a person when combined with other data (e.g. a unique ID number, IP address or an expression of opinion in respect of a person). 
Special categories of personal data

Some of the personal data we process can be more sensitive in nature and therefore requires a higher level of protection. The UK GDPR refers to the processing of these data as ‘special categories of personal data’.

This means personal data relating or inferring to an individual’s:

  • race;
  • ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data (if this is used for identification purposes);
  • health data;
  • sex life;
  • sexual orientation. 

 

2.5 For more details about the regulatory and corporate context, refer to Appendix 1.

3. Data Protection Principles

3.1 The seven principles

3.1.1 Delta needs to collect, process and store personal data about individuals to operate as a registered and regulated, not-for-profit social landlord. As a responsible landlord, and to meet regulatory obligations, we may collect personal data about tenancy holders, occupants, including children, and other stakeholders who have a relationship with us.

3.1.2 When personal data is supplied to us via a third party, we will accept the data under the assumption that the data subject is made fully aware and gave their full consent.

3.1.3 The UK GDPR and Data Protection Act 2018 provide a framework for protecting personal data, emphasising the importance of data protection principles. For all data, we’ll adhere to the seven principles for data processing:

  1. Lawfulness, fairness and transparency 
  2. Purpose limitation 
  3. Data minimisation 
  4. Accuracy 
  5. Storage limitation 
  6. Integrity and confidentiality (security) 
  7. Accountability

3.2 Lawfulness, fairness and transparency

3.2.1 We’ll ensure that transparency is engrained in processing by being clear, open and honest with data subjects. This is captured within our privacy notices.

3.3 Purpose limitation

3.3.1 We’ll only collect data for specific, explicit and legitimate purposes, and ensure it’s not further processed in ways incompatible with those purposes.

3.4 Data minimisation

3.4.1 The data we collect will be adequate, relevant and limited to what’s necessary for the purposes it serves. We’ll strive to collect and use the minimum amount of personal data in processing activities and will periodically review the relevance of the information we collect, in line with legislation. 

3.4.2 Employees and data process owners are responsible for ensuring that no unnecessary, irrelevant or unjustifiable personal data is kept, collected or created.

3.5 Accuracy

3.5.1 Data will be accurate, and we’ll ensure it is kept up to date as needed. We’ll erase or correct inaccurate data without delay. We’re committed to implementing, improving and monitoring data quality across the organisation. 3.6 Storage limitation

3.6 Storage

3.6.1 We won’t store data in an identifiable form for longer than necessary for the purposes it was collected. See section 5.2 to read more about data retention.  

3.7 Integrity and confidentiality (security)

3.7.1 We’ll process data securely, protecting it against unauthorised or unlawful processing and against accidental loss, destruction or damage through appropriate technical and organisational measures.

3.8 Accountability

3.8.1 As the data controller, we’re responsible for overall compliance. This means that we must demonstrate that the principles outlined above are met for all personal data for which we’re responsible. This includes having clear responsibilities for data protection, as set out in this policy. 

4. Data Subject Rights

4.1 Your rights

4.1.1 Data protection legislation is designed with the data subject in mind, ensuring that personal information in handled responsibly and with respect for individual rights. Under GDPR, data subjects have rights that enhance their control over personal data.

These are:

  1. Right to be informed
  2. Right of access 
  3. Right to rectification 
  4. Right to erasure 
  5. Right to restriction of processing 
  6. Right to data portability 
  7. Right to object 
  8. Rights related to automated decision-making including profiling 

4.1.2 We have procedures setting out how we’ll handle information rights requests. We’ll ensure that all relevant people are made aware of how to make requests and how to process these in line with legislation.

4.1.3 More detail about the individual rights is shown below. 

4.2 The right to be informed  

4.2.1 We’ll ensure individuals are informed of the reasons for processing their data in a clear, transparent and easily accessible form and will inform them of all their rights.

4.2.2 We will do this through privacy notices, which will set out when, how and what personal data we are collecting and processing.  

4.3 The right of access  

4.3.1 We’ll ensure that individuals are aware of their right to obtain confirmation that their data is being processed, access to copies of their personal data and other information, such as a privacy notice, and how to execute this right.

4.3.2 We’ll be clear about our procedures to ensure that individuals and their authorised representatives know how to make an application for information held about them. This is known as a ‘subject access request’.

4.4 The right to rectification

4.4.1 You have the right to have your personal data rectified if it is inaccurate or incomplete.  

4.4.2 If we’ve disclosed this to third parties, we’ll tell you if this is appropriate and will inform them of the rectification where possible.  

4.5 The right to erasure  

4.5.1 The right to erasure is also known as the ‘right to be forgotten’ and allows an individual to request that we delete or remove their personal information if there is no compelling reason to continuing processing it.

4.6 The right to restrict processing  

4.6.1 Under certain circumstances, you have a right to ‘block’ or suppress processing of personal data. When processing is restricted, we’re permitted to store the personal data, but not further process it. We can retain just enough information about you to ensure that the restriction is respected in future.  

4.7 The right to data portability  

4.7.1 The right to data portability allows you to obtain your personal information from Delta and reuse it for your own purposes.  

4.8 The right to object  

4.8.1 You have the right to object to our processing of your personal information. You have an absolute right to stop your data being used for direct marketing. In other cases where the right to object applies, we may be able to continue processing if we can demonstrate we have a compelling reason for doing so. 

4.9 Rights related to automated decision-making including profiling

4.9.1 The UK GDPR has provisions on:

  • automated individual decision-making (making a decision solely by automated means without any human involvement); and 
  • profiling (automated processing of personal data to evaluate certain things about an individual). Profiling can be part of an automated decision-making process. 

5. How We Process and Manage Data

5.1 Data protection by design 

5.1.1 The concept of data protection by design requires organisations to integrate privacy considerations into data processing activities from the design stage. This is the approach Delta takes.

5.2 Data retention

5.2.1 We’ll not retain personal data any longer than required. We’ll comply with legal or regulatory requirements or best practice when determining how long to store data.  

5.2.2 We’ll maintain our own data retention schedule so that documentation isn’t retained and stored longer than legally required and to ensure compliance with the Data Protection Act. We will review our data retention periods regularly.  

5.2.3 After the relevant retention period has expired, the information will be securely destroyed or retained in a manner which prevents the identification of data subjects (anonymisation).  

5.2.4 In exceptional cases we may hold data for longer than specified in our retention schedule, where required to do so by law or under contract with a data subject.  

5.3 Data sharing

5.3.1 We’ll only share personal data if we have a lawful basis, and if it’s necessary to do so. If we share personal data with third parties/processors, we will carry out robust and appropriate checks and ensure there’s an adequate Data Processor and Controller Agreement (including Data Sharing Agreements) in place before any sharing takes place. 5.4 Data protection impact assessments

5.4.1 We’ll adopt a risk-based approach to processing personal data, ensuring that we assess any risks to privacy or people’s rights and freedoms before commencing, commissioning or changing data processing activities.  

5.4.2 We’ll do this through Data Protection Impact Assessments.

5.5 International transfers  

5.5.1 The UK GDPR restricts data transfers to countries outside of the UK to ensure that the level of data protection afforded to individuals by the UK GDPR is not undermined.  

5.5.2 We’ll only transfer data outside of the UK where it is strictly necessary to do so and if certain conditions apply. Before transferring any personal data outside of the UK, we’ll take steps to ensure there are appropriate data transfer mechanisms in place to safeguard the data.

5.6 Data breaches 

5.6.1 The GDPR defines personal data breach as “a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”. If there is a data breach, we’ll manage this in line with our Data Breach Procedure.

5.6.2 Employees must report any breach, potential breach, incident or data protection concern to the DPO immediately.

5.6.3 We’ll log all data breaches and will investigate each incident immediately.

5.6.4 We’ll take appropriate remedial action as soon as possible to isolate and contain the breach, evaluate and minimise its impact, and to recover from the effects of the breach.  5.6.5 We will record and investigate data protection ‘near misses’.  

5.6.6 The Data Breach Procedure sets out responsibilities, decision-making criteria and timescales for notifying data subjects, and where relevant the Information Commissioner’s Office (ICO), the Audit and Risk Committee, and Board.

5.7 Data quality

5.7.1 We acknowledge that good data quality is essential to providing a positive customer experience, maintaining trust and ensures that we can meet our obligations to customers, employees, stakeholders and the Regulator of Social Housing.

5.7.2 Committed to improving data quality, and we insist that all Delta employees have a responsibility for data quality.

5.7.3 We take appropriate measures to detect and mitigate risks to data quality across our systems and processes. 

6. Support

6.1 We will support customers, employees and other individuals to exercise their rights in relation to data protection legislation.

6.2 This includes clearly communicating their rights, providing information in the format they need and signposting them to external agencies such as the ICO. 

7. If You're Unhappy

7.1 If you’re unhappy If you have any concerns about the way we have handled your data or dealt with your subject access requests, you should contact our Data Protection Officer to make a complaint, as detailed in our policy summary.

7.2 If you’re unhappy If you have any concerns about the way we have handled your data or dealt with your subject access requests, you should contact our Data Protection Officer to make a complaint, as detailed in our policy summary.

7.3 We’ll log and acknowledge your complaint within 30 calendar days of receiving it.

7.4 After investigating, we’ll provide a full response without undue delay. If additional issues arise in pursuing our enquiries which mean the investigation may take longer than we’d expect, we’ll let you know; we’ll explain the reason for the delay and provide you with a timeline for when you can expect our response.

7.5 You may also contact the Information Commissioner’s Office. Information on how to do this is available online at https://ico.org.uk/. We would, however, welcome the opportunity to deal with your concerns and/or complaints at the first instance. If you’re unhappy about the service we provide as a housing provider or employer, we’ll refer you to our Complaints and Feedback or HR Team, as appropriate. Please see our Complaints and Feedback Policy, or our HR policies for more information. 

8. Responsibilities

8.1 Delta’s nominated Data Protection Officer (DPO) is responsible for development and implementation of this policy to ensure that we comply with our legal and regulatory duties. The DPO will:

  • ensure that the Board are updated data protection risks, issues and their responsibilities;
  • monitor compliance with data protection legislation and this policy;
  • review this policy and data protection procedures at regular intervals;
  • ensure that appropriate data protection training is in place for all those who require it, including more specific or in-depth training where necessary;
  •  be the central point of contact for all data-protection-related queries, providing advice based on skills, experience and the ICO’s guidance;
  • be the central point of contact for the ICO;
  • coordinate responses to requests made by individuals to exercise their rights;
  • check and approve data processing agreements, data-protection-related contractual clauses, and any other data processing activity undertaken by third parties on Delta’s behalf;
  • approve data protection statements issued anywhere in the organisation;
  • consider all breaches of data security and recommend appropriate action; 
  • report as necessary to the Audit and Risk Committee and Board.  

8.2 It’s the responsibility of the Board to review, adopt and approve this policy.

8.3 Delta’s Chief Executive is the accountable officer and has ultimate responsibility for the management of the organisation and ensuring appropriate mechanisms, including compliance with the Data Protection legislation, are in place to support service delivery and continuity. Protecting data and thus maintaining confidentiality is pivotal to the organisation being able to operate and for enforcing compliance in relation to this policy. 

8.4 Members of the Executive Team have overall responsibility for compliance with the Data Protection Principles within their business areas.  

8.5 It’s the responsibility of everyone, including all managers and employees, to embrace and adhere to this policy at all times. All employees must:

  • achieve and demonstrate an adequate level of general awareness of information security and confidentiality; 
  • fully understand and ensure compliance with their obligations under the data protection legislation;
  • familiarise themselves with and adhere to the key procedures, practices and guidance;
  • ensure that the data they are processing complies with Delta’s policies and procedures and is lawful and justified;
  • raise any concerns, notify any breaches or errors, and report anything actually or potentially contradictory to Delta’s policies and procedures without delay to the DPO; and
  • participate actively in information security and exercises, including training, when required. 

8.6 All employees will be notified of this policy through organisational communication channels and all new starters will be made aware of this policy as part of their induction process. We will carry out data protection training for all relevant employees. Managers will be responsible for keeping employees up to date with any changes to this policy.

8.7 All partners, contractors, sub-contractors and other third-party organisations will comply with data protection legislation when they process personal information on Delta’s behalf.

8.8 Engaged customers will be provided with training on their data protection responsibilities where relevant. 

9. Compliance and Monitoring

9.1 We’ll report regularly to the Executive Team, Audit and Risk Committee, and Board on key indicators relating to data protection. This will include an annual report on data protection.

9.2 We will carry out periodic checks to test whether this policy is being adhered to and to check the effectiveness of control measures. We’ll keep records of all such audits and compliance checks, including corrective actions taken.  

9.3 We will learn from feedback, data breaches and subject access requests, and continually improve how we work and embed learning. 

10. Equity, Diversity and Inclusion

10.1 Our policy recognises the importance of holding sensitive information securely, in line with this policy.  

10.2 We will support customers as needed to exercise their rights in line with this policy. This will include making reasonable adjustments considering an individual’s support needs.

10.3 We know that trust is essential when we ask customers, employees and other stakeholders to consider sharing their personal information with us, especially when that data is special category.

10.4 One of the aims of this policy is to provide assurance to people that when they share their personal information with Delta, we’ll treat their data with respect and in line with best practice.

10.5 Giving people confidence to share special category data with us enables us to further monitor our service to ensure equitable access and quality of service for all customers, driving improvements, where appropriate. 

11. Review

11.1 We’ll review this policy every three years. A policy review may also be required earlier in response to internal or external changes, for example, changes in legislation or following feedback from customers or employees.

12. Version History

Version History
Version Number Approval Date Summary of Changes Approval by
1 April 2026 First policy for Delta Board
1.1 August 2026 Updates to section 7 to clarify process for complaints relating to this policy  Executive Management Team

Appendix 1 - Policy Context

Policy context
Our data protection registration Delta is registered as a Community Benefit Society, under the Co-operative and Community Benefit Societies Act 2014 under registration number 8112. Our registered address is Delta Housing, Myriad House, 33 Springfield Lyons Approach, Springfield, Chelmsford, CM2 5LB.  
Regulatory standards This policy supports the Regulatory Standards, which registered providers of social housing must meet. The Governance and Financial Viability Standard requires all registered providers of social housing to adhere to all relevant law. This includes GDPR.
Legislation

This policy supports the following legislation:

  • Data Protection Act 2018; 
  • Data (Use and Access) Act 2025; 
  • Retained General Data Protection Regulations (EU) 2016/679; 
  • Privacy and Electronic Communications Regulations 2003; 
  • UK General Data Protection Regulation 2018 (UKGDPR).