This policy explains how the Trade & Customs Standards Association (TCSA) collects, uses, discloses, retains and protects personal data of members, applicants, verification subjects, buyers, suppliers, website visitors and other individuals we interact with. It is published in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018.
1. Introduction and Scope
TCSA is committed to protecting the privacy and personal data of everyone it interacts with, including members, membership applicants, verified organisations, procurement buyers and suppliers, training providers, event attendees, newsletter subscribers, enquiry contacts and website visitors.
This policy applies to all personal data processed by TCSA, regardless of whether that data is collected through this website, by email, by telephone, through application forms, or through our procurement, verification and advisory services.
This document should be read alongside the TCSA Privacy Policy, which provides a plain-language summary of how personal data is handled. In the event of any conflict, this GDPR Policy prevails.
2. Data Controller
For the purposes of the UK GDPR and EU GDPR, TCSA acts as a data controller for the personal data it processes in the course of its activities.
Data controller details:
- Name: Trade & Customs Standards Association (TCSA)
- Contact email: members@tcsa.org.uk
- Established: 1999
- Nature of organisation: Independent, non-governmental international standards body
TCSA is not a public authority and does not carry out large-scale processing of special category data.
3. Personal Data We Collect
The categories of personal data TCSA may process include:
- Identity data: full name, job title, role, and digital signature data.
- Contact data: email address, telephone number, postal address, and LinkedIn or other professional profile URLs.
- Organisational data: company name, trading name, company registration number, VAT number, registered and trading addresses, website, employee count, years trading, and countries of operation.
- Application and assessment data: membership application responses, verification submissions, declarations, trade references, compliance statements, and supporting documents.
- Procurement data: tender and requirement submissions, buyer brief details, supplier capability information, and bid responses.
- Advisory data: advisory request details, uploaded files, and correspondence relating to advisory support.
- Financial data: billing name, invoice details, and payment references where a purchase is made. TCSA does not store full card numbers; card payments are handled by our payment processor.
- Technical data: IP address, browser type, device information, and website usage data collected through cookies and analytics.
- Communications data: the content of emails, messages, forms and enquiries you send to us.
- Marketing data: newsletter subscription preferences and engagement with TCSA communications.
TCSA does not knowingly process special category personal data (such as data revealing health, ethnicity, religious beliefs or biometric data) except where an individual voluntarily provides it as part of a declaration, in which case it is handled in accordance with the additional conditions in Article 9 of the UK GDPR and EU GDPR.
4. How We Collect Your Data
We collect personal data through the following methods:
- Information you provide directly: via membership application forms, verification submissions, procurement or tender forms, advisory requests, course approval submissions, enquiry forms, event registrations, job applications, and email or written correspondence.
- Information collected automatically: via cookies, analytics tools and server logs when you visit our website or interact with our digital communications.
- Information from third parties: where a third party (such as a buyer, referral source, or a member organisation) provides contact details for the purpose of a specific procurement, referral or advisory activity.
- Information from public sources: such as company registers, professional directories, and LinkedIn, used to verify organisational legitimacy and professional relevance during assessment.
We only collect personal data for specified, explicit and legitimate purposes and do not process it in a manner incompatible with those purposes.
5. Lawful Basis for Processing
TCSA relies on the following lawful bases when processing personal data, as set out in Article 6 of the UK GDPR and EU GDPR:
- Consent: where you have given clear consent to the processing (for example, newsletter subscriptions and marketing communications).
- Contractual necessity: where processing is necessary to take steps before entering into a contract, or to perform a contract with you (for example, processing membership applications, delivering advisory services, and administering procurement activity).
- Legal obligation: where processing is necessary to comply with a legal obligation (for example, accounting, tax, and record-keeping requirements).
- Legitimate interests: where processing is necessary for TCSA's legitimate interests, or those of a third party, and is not overridden by your rights and freedoms (for example, maintaining the integrity of the verification framework, fraud prevention, network administration, and responding to enquiries).
Where TCSA relies on legitimate interests as the lawful basis, we carry out a balancing test to ensure your rights, interests and freedoms are not disproportionately affected. A summary of the legitimate interests assessment can be requested using the contact details in Section 18.
For special category data (where applicable), we rely on the explicit consent of the data subject, as set out in Article 9 of the UK GDPR and EU GDPR.
6. How We Use Your Personal Data
We use personal data for the following purposes:
- Assessing and administering membership applications and ongoing membership status.
- Conducting verification and accreditation assessments of organisations.
- Operating the procurement and tender matching service, including publishing requirements and managing supplier responses.
- Providing advisory support, including customs, compliance and operational guidance.
- Communicating with you about your application, membership, verification, advisory request or enquiry.
- Processing payments and issuing invoices and certificates.
- Administering training course approvals and listing approved courses.
- Organising and administering events and recording attendance.
- Sending newsletters, updates and marketing communications where you have consented.
- Maintaining the security and integrity of the website, services and TCSA network.
- Complying with legal, regulatory and accounting obligations.
- Responding to complaints and carrying out investigations under the Code of Ethics.
TCSA does not use personal data to make solely automated decisions that have a legal or similarly significant effect on you, except where this is necessary to enter into or perform a contract, is authorised by law, or is based on your explicit consent.
7. Data Sharing and Recipients
TCSA may share personal data with the following categories of recipient, where necessary and proportionate:
- Members and verified organisations, where you have submitted a procurement requirement, tender, advisory request, or application that requires responses or matching.
- Procurement buyers and their nominated representatives, where you have submitted a requirement or bid.
- Service providers and processors acting on TCSA's behalf: for example hosting, email delivery, payment processing, analytics, document generation, CRM, and marketing tools. These processors act under contract and are bound by confidentiality and data protection obligations.
- Professional advisers: such as legal, accounting and insurance advisers, where necessary for advice or compliance.
- Regulators and public authorities: where required by law, court order, or to assist with a legitimate investigation.
- Successors or transferees: in the event of a restructuring, merger or transfer of TCSA's activities, personal data may be transferred subject to the protections in this policy.
TCSA does not sell personal data to third parties.
8. International Data Transfers
TCSA operates internationally and personal data may be transferred to, stored in, or processed in countries outside the United Kingdom and the European Economic Area (EEA).
Where TCSA transfers personal data outside the UK or EEA, it ensures that one or more of the following safeguards is in place:
- The destination country has been recognised as providing an adequate level of data protection.
- Appropriate safeguards are in place, such as standard contractual clauses adopted under the UK GDPR or EU GDPR.
- An exemption or derogation under Article 49 of the UK GDPR or EU GDPR applies (for example, explicit consent or contract necessity).
If you would like a copy of the safeguards used for a particular transfer, or further information, please contact us using the details in Section 18.
9. Data Retention
TCSA retains personal data only for as long as necessary to fulfil the purposes set out in this policy, and in accordance with legal, accounting and regulatory requirements.
Indicative retention periods are:
- Membership application data: retained for the duration of membership, plus 6 years after membership ends.
- Verification and accreditation records: retained for the duration of accredited status, plus 6 years after expiry or withdrawal.
- Procurement and tender data: retained for 2 years after the requirement is closed, or longer where a contractual relationship continues.
- Advisory request data: retained for 2 years after the request is completed, or longer where required for billing or disputes.
- Newsletter and marketing data: retained until you withdraw consent or request deletion.
- Website and analytics data: retained for up to 26 months, subject to the relevant analytics tool's configuration.
- Job application data: retained for up to 12 months after a recruitment process ends, or longer where required by law.
Where retention is no longer necessary, personal data is securely deleted or anonymised.
10. Data Security
TCSA implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure. These measures include:
- Access controls limiting personal data to authorised personnel who require it to perform their role.
- Encryption of data in transit and at rest where technically feasible.
- Secure, access-controlled storage of application, verification and advisory documents.
- Regular review of access permissions and system security.
- Staff and contractor awareness of data protection obligations.
- Contracts with processors that require equivalent security standards.
Despite these measures, no system can be guaranteed to be fully secure. TCSA continuously reviews and improves its security posture.
11. Your Rights Under GDPR
Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
- Right to be informed: to receive clear information about how we use your data (this policy).
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure: in certain circumstances, to have your personal data deleted.
- Right to restrict processing: in certain circumstances, to limit how we use your data.
- Right to data portability: to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller.
- Right to object: to object to processing based on legitimate interests, direct marketing, or processing for research or statistical purposes.
- Rights in relation to automated decision-making and profiling.
- Right to withdraw consent: where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us using the details in Section 18. We will respond within one month, and may extend this by two further months where requests are complex or numerous. We will explain any extension and the reasons for it.
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk).
12. Cookies and Analytics
The TCSA website uses cookies and similar technologies to operate the site, understand how it is used, and improve the user experience. Cookies are small files stored on your device.
The types of cookies we use include:
- Strictly necessary cookies: required for the website to function and cannot be switched off.
- Analytics cookies: allow us to measure and improve website performance and content.
- Preference cookies: remember choices you make such as region or language preferences.
- Marketing cookies: used, where consented, to measure the effectiveness of communications and show relevant content.
Where cookies are not strictly necessary, we will only place them with your consent. You can manage or withdraw cookie consent at any time through your browser settings or our cookie controls.
13. Marketing and Communications
Where you have consented, TCSA may send you newsletters, updates, procurement opportunities and other communications about its activities and the trade sector.
You can opt out of marketing communications at any time by using the unsubscribe link in any email, by updating your preferences, or by contacting members@tcsa.org.uk. Opting out of marketing does not affect service-related communications connected to your membership, application, verification, advisory request or procurement activity.
14. Children's Privacy
TCSA's services are intended for organisations and professionals operating in the trade, customs, freight, logistics and compliance sectors. We do not knowingly collect personal data from children under 16.
If you believe a child has provided personal data to TCSA, please contact us and we will take steps to delete that data.
15. Data Breach Notification
TCSA has procedures to identify, assess and respond to personal data breaches in line with the UK GDPR and EU GDPR.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, TCSA will notify the relevant supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to individuals, we will also notify affected individuals without undue delay.
16. Third-Party and Member Processing
TCSA members, verified organisations and procurement participants may act as data controllers or processors in their own right in connection with procurement, advisory or verification activity. TCSA is not responsible for the data protection practices of such independent organisations.
Members and participants are expected to comply with the UK GDPR and EU GDPR in respect of any personal data they process, and to have appropriate policies and safeguards in place. Where TCSA acts as a processor on behalf of a member or buyer, it will do so under a written agreement setting out the respective obligations.
17. Changes to This Policy
TCSA may update this GDPR Policy from time to time to reflect changes in its practices, legal requirements or the services it provides. The version and review date shown at the top of this policy indicate when it was last reviewed.
Material changes will be reflected on this page and, where appropriate, communicated to affected individuals. Continued use of TCSA's services or website after a change indicates acceptance of the updated policy.
18. Contact Us
If you have any questions about this GDPR Policy, wish to exercise any of your data protection rights, or wish to make a complaint about how we handle your personal data, please contact us:
Contact details:
- Email: members@tcsa.org.uk
- Organisation: Trade & Customs Standards Association (TCSA)
- Subject line: Data Protection Enquiry
We will acknowledge your enquiry promptly and respond in accordance with the timescales set out in the UK GDPR and EU GDPR.
