POPULAR COURSES
ALL COURSES
POPULAR LICENCES
ALL LICENCES
POPULAR COURSES
ALL LOCATIONS
ALL CAREERS
Document Owner: Data Protection Officer (DPO)
Approval Date: 26th September, 2025
Review Date: 26th September, 2025
Version: 2.0
This Privacy Policy ("Policy") describes how Get Licensed ("we," "us," or "our") collects, uses, and discloses personal information when you use our screening service platform ("Get Licensed"). By accessing or using Get Licensed, you consent to the collection, use, and disclosure of your personal information as described in this Policy.
a. Get Licensed, a company registered in England and Wales, provides background screening service. This Privacy Policy outlines how we collect, process, store, and protect personal data, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable international data transfer requirements.
b. Get Licensed is used by employers to carry out BS7858 and NSI NCP 111-compliant vetting. This process requires the collection and processing of highly sensitive personal data. We are committed to handling this data lawfully, transparently, and securely.
a. Data Controller: Get Licensed Ltd.
b. Registered Address: 20-22 Wenlock Road, London, England, N1 7GU
c. DPO Contact: Shahab Ali, shahab@get-licensed.co.uk
a. This is our privacy policy, written in accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. It explains what personal data we collect, how we use it, and what rights you have.
a. To carry out background screening under BS7858 and NSI NCP 111, we collect and process the following data:
a. We are Get Licensed Limited, trading as Get Licensed, providing BS7858-compliant background screening for UK organisations.
b. Company Number: 07154333
c. Data Protection Officer (DPO): Shahab Ali
a. Candidate: The individual being screened.
b. Client: The employer or organisation requesting the screening.
c. Personal Data: Any data relating to an identified or identifiable person.
d. Data Controller: The Client.
e. Data Processor: Get Licensed.
f. Special Category Data: Sensitive data like criminal history or biometric information.
g. Third-Party Verifiers: Yoti, Credit Safe, Care Check, and similar partners who support verification.
a. Data Processor/Controller
Get Licensed generally acts as a Data Processor on behalf of Clients. In limited cases where Get Licensed determines the technical means of processing for fraud prevention, security monitoring, or compliance purposes, it acts as an independent Data Controller for that specific activity.
a. We collect this data solely to fulfil employment vetting obligations under:
Processing is done to:
a. We collect your data through:
a. Your data is used to:
b. We do not use your data for profiling, automated decision-making, or marketing.
a. We share your data only with:
Authorised third-party verifiers:
b. We do not sell your data.
c. Credit Reference and Affordability Checks
As part of the BS7858 screening process, we carry out a consumer credit reference search to assess financial probity. This search is conducted through Creditsafe Business Solutions Limited (FCA registration number 742313), which acts as a credit broker and sources credit data from TransUnion (FCA registration number 737740), a licensed credit reference agency.
When a credit reference search is carried out:
For more information about how these organisations process your data, please refer to their privacy notices:
a. UK Storage
b. International Transfers to Pakistan
As part of our vetting process, some candidate information is viewed by our authorised vetting staff in Pakistan. This includes:
c. Legal Basis
These transfers are necessary to perform BS7858-compliant screening and are carried out under:
a. Get Licensed operates a secure, UK-hosted vetting system. However, to deliver the screening service efficiently and cost-effectively, certain personal data is accessed by our in-house vetting team based in Pakistan.
b. This access is conducted under strict compliance with UK GDPR, using:
The following data is accessed in Pakistan:
Safeguards include:
c. These transfers are essential for performing the contract and are legally justified under Articles 44-49 of the UK GDPR.
a. Transfers are governed by the UK International Data Transfer Agreement (IDTA) and our Data Transfer Impact Assessment (DTIA).
b. Clients and candidates may request a copy of our DTIA by emailing info@get-licensed.co.uk.
c. Strict technical, legal, and organisational measures apply, including:
a. Data is retained for 60 days after completion of the vetting file for employer review.
b. After 90 days, all personal data is automatically and securely deleted from our systems.
c. An audit trail of vetting actions (not containing personal data) is maintained for compliance purposes.
a. Under UK GDPR, you have the following rights:
b. Requests can be made by emailing shahab@get-licensed.co.uk.
c. Making a data protection complaint. If you are unhappy with how your personal data has been handled, you can raise a complaint with us — by email to info@get-licensed.co.uk or by post to the Data Protection Officer, Get Licensed Ltd, 36 Scotts Road, Bromley, BR1 3QD. We will acknowledge your complaint within 30 days and look into it without undue delay, keeping you informed of progress and of the outcome. You also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk/make-a-complaint or on 0303 123 1113. Full details are in our Data Protection Complaints Handling Policy (GP-POL-071).
a. We implement robust physical, technical, and organisational measures including:
a. Your personal data is never stored locally in Pakistan; it is only accessed through secure, monitored UK systems.
b. Clients and candidates may request a copy of our DTIA by emailing info@get-licensed.co.uk.
a. All incidents are investigated by our DPO and security team.
b. Breaches are logged, contained, and reported within 72 hours to affected parties and the ICO (if applicable).
c. Clients and Candidates will be notified without undue delay if a personal data breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 UK GDPR.
a. We use minimal analytics tools solely to:
b. We do not use personal data for targeted advertising or third-party profiling.
a. Get Licensed does not make any solely automated decisions that produce legal effects or similarly significantly affect individuals.
b. All screening assessments, including the review of credit reference data obtained from Creditsafe and TransUnion, are carried out by trained human vetting administrators. Credit data is reviewed manually as one component of the BS7858 screening process and is not used to make automated decisions about a candidate's suitability.
c. No profiling, automated scoring, or algorithmic decision-making is applied to candidate data at any stage of the vetting process.
a. We may update this policy to reflect changes in law or service models. You will be notified via:
b. Material changes will include a clear version history and take effect 30 days after publication.
Enter your details below to instantly download the career guide PDF
Get Licensed helps you get SIA trained, licensed, and ready for real security jobs — trusted by 450,000+ people across the UK.
We use cookies to enhance your experience on our website. By continuing to use our website, you consent to the use of cookies.
For more information, please see our Cookie Policy.