Privacy Policy

Privacy policy for Screening Services

Document Owner: Data Protection Officer (DPO)

Approval Date: 26th September, 2025

Review Date: 26th September, 2025

Version: 2.0

This Privacy Policy ("Policy") describes how Get Licensed ("we," "us," or "our") collects, uses, and discloses personal information when you use our screening service platform ("Get Licensed"). By accessing or using Get Licensed, you consent to the collection, use, and disclosure of your personal information as described in this Policy.

a. Get Licensed, a company registered in England and Wales, provides background screening service. This Privacy Policy outlines how we collect, process, store, and protect personal data, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable international data transfer requirements.

b. Get Licensed is used by employers to carry out BS7858 and NSI NCP 111-compliant vetting. This process requires the collection and processing of highly sensitive personal data. We are committed to handling this data lawfully, transparently, and securely.

a. Data Controller: Get Licensed Ltd.

b. Registered Address: 20-22 Wenlock Road, London, England, N1 7GU

c. DPO Contact: Shahab Ali, shahab@get-licensed.co.uk

a. This is our privacy policy, written in accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. It explains what personal data we collect, how we use it, and what rights you have.

a. To carry out background screening under BS7858 and NSI NCP 111, we collect and process the following data:

  • Full name, date of birth, contact details
  • Current and previous addresses (last 5 years)
  • Employment history (last 5 years)
  • Education and training records
  • Proof of right to work (e.g., passport, visa)
  • Identification documents (passport, driving licence)
  • Criminal record history (DBS)
  • Financial records (credit checks)
  • References (character and employment)
  • SIA licence number
  • National insurance number
  • Biometric data (selfie for ID verification)

a. We are Get Licensed Limited, trading as Get Licensed, providing BS7858-compliant background screening for UK organisations.

b. Company Number: 07154333

  • Address: 36 Scotts Road, Bromley, England, BR1 3QD

c. Data Protection Officer (DPO): Shahab Ali

a. Candidate: The individual being screened.

b. Client: The employer or organisation requesting the screening.

c. Personal Data: Any data relating to an identified or identifiable person.

d. Data Controller: The Client.

e. Data Processor: Get Licensed.

f. Special Category Data: Sensitive data like criminal history or biometric information.

g. Third-Party Verifiers: Yoti, Credit Safe, Care Check, and similar partners who support verification.

a. Data Processor/Controller

Get Licensed generally acts as a Data Processor on behalf of Clients. In limited cases where Get Licensed determines the technical means of processing for fraud prevention, security monitoring, or compliance purposes, it acts as an independent Data Controller for that specific activity.

a. We collect this data solely to fulfil employment vetting obligations under:

  • UK GDPR Article 6(1)(b): Processing necessary for the performance of a contract
  • UK GDPR Article 9(2)(b): Processing necessary for carrying out obligations in the field of employment
  • UK GDPR Article 9(2)(g): Processing necessary for reasons of substantial public interest

Processing is done to:

  • Comply with BS7858 and NSI NCP 111 requirements
  • Conduct identity verification
  • Confirm employment and address history
  • Complete criminal and financial background checks

a. We collect your data through:

  • Get Licensed/GuardCheck App
  • Authorised third-party sources (Yoti, Care Check, Credit Safe)
  • Automated monitoring systems (IP logs, login tracking)
  • Regulatory and public databases

a. Your data is used to:

  • Conduct BS7858-compliant vetting
  • Verify identity, career history, address history, and criminal/financial standing
  • Deliver screening reports to Clients
  • Meet obligations under NSI NCP 111 and SIA licensing requirements
  • Monitor internal platform usage, investigate anomalies, and maintain system integrity

b. We do not use your data for profiling, automated decision-making, or marketing.

a. We share your data only with:

Authorised third-party verifiers:

  • Yoti – Identity verification, PEP and sanctions screening
  • Care Check – DBS criminal background checks
  • Credit Safe – Credit and financial verification
  • Respond.io – Candidate messaging platform (WhatsApp / SMS) used to communicate with candidates during the screening process.
  • Our internal vetting admins (under NDA and strict access control)
  • Clients (your employer or contractor) as part of the completed vetting report
  • UK regulators or law enforcement where legally required (e.g. ICO, SIA, Police)

b. We do not sell your data.

c. Credit Reference and Affordability Checks

As part of the BS7858 screening process, we carry out a consumer credit reference search to assess financial probity. This search is conducted through Creditsafe Business Solutions Limited (FCA registration number 742313), which acts as a credit broker and sources credit data from TransUnion (FCA registration number 737740), a licensed credit reference agency.

When a credit reference search is carried out:

  • Your personal data (full name, date of birth, and current address) is shared with Creditsafe and TransUnion for the purpose of obtaining a consumer credit report.
  • TransUnion will place a soft search footprint on your credit file. This is visible only to you and does not affect your credit score or your ability to obtain credit.
  • The credit report may contain information about county court judgements (CCJs), bankruptcies, individual voluntary arrangements (IVAs), insolvency orders, and other public financial records.
  • The results of the credit reference search are reviewed by a trained human vetting administrator as part of the screening assessment. No automated decisions are made based on your credit data (see Section 21).
  • The credit data obtained is used solely for the purpose of employment vetting under BS7858 and is not used for any lending, insurance, or affordability decision.

For more information about how these organisations process your data, please refer to their privacy notices:

a. UK Storage

  • All data is stored in encrypted cloud environments hosted in the UK (e.g. AWS S3).
  • Backups are encrypted and retention-controlled in line with UK GDPR.

b. International Transfers to Pakistan

As part of our vetting process, some candidate information is viewed by our authorised vetting staff in Pakistan. This includes:

  • Basic details (name, date of birth, gender, nationality)
  • Identity documents (passport, driving licence)
  • Photographs and facial scan results
  • Address history (covering 5 years)
  • Employment history and references
  • Right-to-work and SIA licence details
  • DBS check results
  • Credit check reports
  • App activity logs (IP, login records)

c. Legal Basis

These transfers are necessary to perform BS7858-compliant screening and are carried out under:

  • UK GDPR Article 6(1)(b) (contractual necessity with clients), and
  • Article 9(2)(b) & (g) (processing of special category data where necessary for employment law and substantial public interest in the UK security industry).

a. Get Licensed operates a secure, UK-hosted vetting system. However, to deliver the screening service efficiently and cost-effectively, certain personal data is accessed by our in-house vetting team based in Pakistan.

b. This access is conducted under strict compliance with UK GDPR, using:

  • UK International Data Transfer Agreement (IDTA)
  • Standard Contractual Clauses (SCCs)
  • Data Transfer Impact Assessment (DTIA)

The following data is accessed in Pakistan:

  • Candidate identity documents
  • Employment and address history
  • Right to work documents
  • DBS and credit check results
  • Any additional documentation required for vetting

Safeguards include:

  • Data is accessed remotely only via secure, UK-based systems
  • No data is downloaded, printed, or stored locally in Pakistan
  • Systems are protected by AES-256 encryption and full endpoint monitoring
  • All access is restricted via biometric login and secured by CCTV-monitored facilities
  • No subcontractors are used in Pakistan; all personnel are direct Get Licensed employees vetted and trained internally

c. These transfers are essential for performing the contract and are legally justified under Articles 44-49 of the UK GDPR.

a. Transfers are governed by the UK International Data Transfer Agreement (IDTA) and our Data Transfer Impact Assessment (DTIA).

b. Clients and candidates may request a copy of our DTIA by emailing info@get-licensed.co.uk.

c. Strict technical, legal, and organisational measures apply, including:

  • AES-256 encryption at rest / TLS 1.2+ in transit
  • DLP systems to prevent data extraction
  • No download, printing, or screen capture permissions
  • VPN-only, role-based access for Pakistan staff
  • CCTV-monitored, fingerprint-secured rooms
  • Staff police-verified and trained in UK GDPR

a. Data is retained for 60 days after completion of the vetting file for employer review.

b. After 90 days, all personal data is automatically and securely deleted from our systems.

c. An audit trail of vetting actions (not containing personal data) is maintained for compliance purposes.

a. Under UK GDPR, you have the following rights:

  • Right to access your data
  • Right to rectify inaccuracies
  • Right to erasure (where applicable)
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Right to lodge a complaint with the ICO

b. Requests can be made by emailing shahab@get-licensed.co.uk.

c. Making a data protection complaint. If you are unhappy with how your personal data has been handled, you can raise a complaint with us — by email to info@get-licensed.co.uk or by post to the Data Protection Officer, Get Licensed Ltd, 36 Scotts Road, Bromley, BR1 3QD. We will acknowledge your complaint within 30 days and look into it without undue delay, keeping you informed of progress and of the outcome. You also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk/make-a-complaint or on 0303 123 1113. Full details are in our Data Protection Complaints Handling Policy (GP-POL-071).

a. We implement robust physical, technical, and organisational measures including:

  • UK-hosted cloud infrastructure (ISO 27001 certified)
  • AES-256 encrypted data transmission and storage
  • Data Loss Prevention (DLP) tools
  • Access restrictions with role-based permissions
  • Endpoint monitoring, biometric logins, and CCTV surveillance

a. Your personal data is never stored locally in Pakistan; it is only accessed through secure, monitored UK systems.

b. Clients and candidates may request a copy of our DTIA by emailing info@get-licensed.co.uk.

a. All incidents are investigated by our DPO and security team.

b. Breaches are logged, contained, and reported within 72 hours to affected parties and the ICO (if applicable).

c. Clients and Candidates will be notified without undue delay if a personal data breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 UK GDPR.

a. We use minimal analytics tools solely to:

  • Monitor system uptime and error rates
  • Detect fraud, misuse, or anomalous behaviour
  • Improve platform performance

b. We do not use personal data for targeted advertising or third-party profiling.

a. Get Licensed does not make any solely automated decisions that produce legal effects or similarly significantly affect individuals.

b. All screening assessments, including the review of credit reference data obtained from Creditsafe and TransUnion, are carried out by trained human vetting administrators. Credit data is reviewed manually as one component of the BS7858 screening process and is not used to make automated decisions about a candidate's suitability.

c. No profiling, automated scoring, or algorithmic decision-making is applied to candidate data at any stage of the vetting process.

a. We may update this policy to reflect changes in law or service models. You will be notified via:

  • Email (if a user or Client)
  • Website notices

b. Material changes will include a clear version history and take effect 30 days after publication.

Top Rated Downloads
Get GuardPass

Find work, try mock tests and book courses from
the UK’s #1 app for security professionals

Apps Store Play Store
download guard app
Do you need help?

Our team’s got your back.

Help centre
image image image image image