Rules and ethics
Part of Small business grants: rules and ethics from application to award
Data protection for a grant application or funded project, from purpose to retention
Plan data protection for an England business grant application or funded project by defining purpose, lawful basis, access, sharing and retention.
A grant application may use personal data about directors, employees, customers, research participants or delivery partners. Start by listing the information, purpose and organisations involved. Do not collect extra data merely because a form or funder might ask for it later.
This is general guidance. The UK GDPR and Data Protection Act require case-specific decisions, and a qualified adviser or data-protection officer should review higher-risk processing.
What to take away
- List the personal data, purpose and organisations involved before you collect anything.
- Decide controller, joint controller or processor roles for each activity, not by contract labels.
- Choose and document a lawful basis before processing, and do not assume consent is correct.
- Give access only to people who need the data for an authorised task.
- Set a retention period based on the agreement, legal need and project purpose.
Map the data
Create a record containing the data field, person concerned, source, purpose, lawful basis, recipient, storage location, access, retention and deletion method. Separate company information from personal data about identifiable people.
The ICO's UK GDPR guidance and resources provide the primary framework for organisational compliance. A grant agreement may add security or reporting duties but does not remove statutory responsibilities.
Define roles
Decide whether the funder, applicant, adviser and delivery supplier act as controllers, joint controllers or processors for each activity. The answer depends on who decides the purpose and means of processing. A label in a template contract does not settle it.
Put necessary terms in contracts and explain responsibility to staff. Do not send an applicant list to a supplier until the role and permitted use are clear.
Choose and document a lawful basis
Identify a lawful basis before processing. Consent is not automatically the right choice. The basis depends on the purpose, organisation and relationship. Special-category or criminal-offence data needs further conditions and controls.
Where research is involved, the ICO's research-processing guidance distinguishes ethical participation consent from UK GDPR consent as a lawful basis.
Tell people what happens
Provide a clear privacy notice covering identity, purposes, lawful basis, recipients, retention, rights and complaint route. Give it when the information is collected, or as required when data comes from another source.
Avoid vague wording that permits unrelated future marketing. If an adviser plans to contact applicants for commercial purposes, explain that purpose and assess the marketing rules separately.
Limit access and sharing
Give access only to people who need the data for an authorised task. Use approved systems, strong account controls and secure transfer. Check whether a funder genuinely needs raw personal data or can accept an aggregate report.
Set a retention period based on the agreement, legal need and project purpose. Preserve required grant evidence, but do not keep every interview recording or contact list indefinitely.
Assess suppliers
Before using an application portal, consultant, survey tool or cloud service, record what personal data it receives and under whose instructions. Review security, subprocessors, international transfers, deletion and support for individual rights. Put required terms in a signed contract before sharing data.
Do not assume that a well-known supplier settles the assessment. The relevant question is how the chosen service, plan and configuration handle this project's information.
Consider a DPIA
Screen the project for high-risk processing before launch. New technology, large-scale monitoring, sensitive information or vulnerable people may require a data-protection impact assessment. Record the decision even when the full assessment is not required.
Separate grant administration and marketing
Contact needed to administer an application does not automatically permit later promotion of advisory services. Define each purpose, assess the relevant data and electronic-marketing rules, and make objection or withdrawal routes work in practice.
Respond to change and incidents
Review the data map when the project adds a supplier, new reporting field or different use. Complete a data-protection impact assessment where required. Maintain an incident route so staff can report loss, misdirection or unauthorised access quickly.
Publication checks
Remove personal details from public case studies unless the intended use is properly authorised. A publicity clause in a grant agreement does not automatically provide consent to publish an employee's story or photograph.
This draft contains no live internal links and remains on hold for a qualified UK data-protection review.
Before you act
- List data fields, purposes and organisations involved.
- Decide controller, joint controller or processor roles for each activity.
- Choose and document a lawful basis before processing.
- Provide a clear privacy notice when collecting data.
- Limit access to people who need the data.
- Assess suppliers before sharing any personal data.
Common questions
How do I decide whether the funder, applicant, adviser or supplier is a controller or processor?
The answer depends on who decides the purpose and means of processing. A label in a template contract does not settle it. Put necessary terms in contracts and explain responsibility to staff. Do not send an applicant list to a supplier until the role and permitted use are clear.
When do I need a data-protection impact assessment for a grant project?
Screen the project for high-risk processing before launch. New technology, large-scale monitoring, sensitive information or vulnerable people may require a data-protection impact assessment. Record the decision even when the full assessment is not required. Review the data map when the project adds a supplier, new reporting field or different use.
Can I use contact details from a grant application to market advisory services later?
No. Contact needed to administer an application does not automatically permit later promotion of advisory services. Define each purpose, assess the relevant data and electronic-marketing rules, and make objection or withdrawal routes work in practice. Avoid vague wording that permits unrelated future marketing.