Grant Ledger

Rules and ethics

Part of Small business grants: rules and ethics from application to award

Data protection for a grant application or funded project, from purpose to retention

Plan data protection for an England business grant application or funded project by defining purpose, lawful basis, access, sharing and retention.

A grant application may use personal data about directors, employees, customers, research participants or delivery partners. Start by listing the information, purpose and organisations involved. Do not collect extra data merely because a form or funder might ask for it later.

This is general guidance. The UK GDPR and Data Protection Act require case-specific decisions, and a qualified adviser or data-protection officer should review higher-risk processing.

What to take away

  • List the personal data, purpose and organisations involved before you collect anything.
  • Decide controller, joint controller or processor roles for each activity, not by contract labels.
  • Choose and document a lawful basis before processing, and do not assume consent is correct.
  • Give access only to people who need the data for an authorised task.
  • Set a retention period based on the agreement, legal need and project purpose.

Map the data

Create a record containing the data field, person concerned, source, purpose, lawful basis, recipient, storage location, access, retention and deletion method. Separate company information from personal data about identifiable people.

The ICO's UK GDPR guidance and resources provide the primary framework for organisational compliance. A grant agreement may add security or reporting duties but does not remove statutory responsibilities.

Define roles

Decide whether the funder, applicant, adviser and delivery supplier act as controllers, joint controllers or processors for each activity. The answer depends on who decides the purpose and means of processing. A label in a template contract does not settle it.

Put necessary terms in contracts and explain responsibility to staff. Do not send an applicant list to a supplier until the role and permitted use are clear.

Choose and document a lawful basis

Identify a lawful basis before processing. Consent is not automatically the right choice. The basis depends on the purpose, organisation and relationship. Special-category or criminal-offence data needs further conditions and controls.

Where research is involved, the ICO's research-processing guidance distinguishes ethical participation consent from UK GDPR consent as a lawful basis.

Tell people what happens

Provide a clear privacy notice covering identity, purposes, lawful basis, recipients, retention, rights and complaint route. Give it when the information is collected, or as required when data comes from another source.

Avoid vague wording that permits unrelated future marketing. If an adviser plans to contact applicants for commercial purposes, explain that purpose and assess the marketing rules separately.

Limit access and sharing

Give access only to people who need the data for an authorised task. Use approved systems, strong account controls and secure transfer. Check whether a funder genuinely needs raw personal data or can accept an aggregate report.

Set a retention period based on the agreement, legal need and project purpose. Preserve required grant evidence, but do not keep every interview recording or contact list indefinitely.

Assess suppliers

Before using an application portal, consultant, survey tool or cloud service, record what personal data it receives and under whose instructions. Review security, subprocessors, international transfers, deletion and support for individual rights. Put required terms in a signed contract before sharing data.

Do not assume that a well-known supplier settles the assessment. The relevant question is how the chosen service, plan and configuration handle this project's information.

Consider a DPIA

Screen the project for high-risk processing before launch. New technology, large-scale monitoring, sensitive information or vulnerable people may require a data-protection impact assessment. Record the decision even when the full assessment is not required.

Separate grant administration and marketing

Contact needed to administer an application does not automatically permit later promotion of advisory services. Define each purpose, assess the relevant data and electronic-marketing rules, and make objection or withdrawal routes work in practice.

Respond to change and incidents

Review the data map when the project adds a supplier, new reporting field or different use. Complete a data-protection impact assessment where required. Maintain an incident route so staff can report loss, misdirection or unauthorised access quickly.

Publication checks

Remove personal details from public case studies unless the intended use is properly authorised. A publicity clause in a grant agreement does not automatically provide consent to publish an employee's story or photograph.

This draft contains no live internal links and remains on hold for a qualified UK data-protection review.

Before you act

  • List data fields, purposes and organisations involved.
  • Decide controller, joint controller or processor roles for each activity.
  • Choose and document a lawful basis before processing.
  • Provide a clear privacy notice when collecting data.
  • Limit access to people who need the data.
  • Assess suppliers before sharing any personal data.

Common questions

How do I decide whether the funder, applicant, adviser or supplier is a controller or processor?

The answer depends on who decides the purpose and means of processing. A label in a template contract does not settle it. Put necessary terms in contracts and explain responsibility to staff. Do not send an applicant list to a supplier until the role and permitted use are clear.

When do I need a data-protection impact assessment for a grant project?

Screen the project for high-risk processing before launch. New technology, large-scale monitoring, sensitive information or vulnerable people may require a data-protection impact assessment. Record the decision even when the full assessment is not required. Review the data map when the project adds a supplier, new reporting field or different use.

Can I use contact details from a grant application to market advisory services later?

No. Contact needed to administer an application does not automatically permit later promotion of advisory services. Define each purpose, assess the relevant data and electronic-marketing rules, and make objection or withdrawal routes work in practice. Avoid vague wording that permits unrelated future marketing.

More in Rules and ethics

Rules and ethics

Small business grants: rules and ethics from application to award

Understand the principal UK rules and practical compliance checks affecting small business grant applications, funded projects and awards in England.

Rules and ethics

Small business grants advertising rules: what an advert must prove

Check advertising for business grants and grant services in England for evidence, clear qualifications, sponsorship labels and accurate deadlines.

Rules and ethics

Small business grants: contract points to settle with advisers and suppliers

Twelve contract points to review when a small business uses grant advisers or project suppliers, from scope and fees to evidence and termination.

Rules and ethics

Small business grants disclosure policy for a grant-information website

Write a disclosure policy for an England grant-information website covering advertising, affiliate links, advisers, sources, reviews and corrections.