This Policy sets out the obligations of ComponentSource Limited, a company registered in England under number 2890788, whose registered office is at The White Building, 33 Kings Road, Reading, Berkshire RG1 3AR (“the Company”) regarding data subject access requests under the Data Protection Legislation (defined below).
This Policy also provides guidance on the handling of data subject access requests. The procedures and principles set out in this Policy should be followed at all times by the Company, its employees, agents, contractors, or other parties working on behalf of the Company.
“data controller” means the person or organisation which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Policy, the Company is the data controller of all personal data used in our business;
“data processor” means a person or organisation which processes personal data on behalf of a data controller;
“Data Protection Legislation” means all applicable data protection and privacy laws including, but not limited to, the UK GDPR, the Data Protection Act 2018, and any other applicable national laws, regulations, and secondary legislation in England and Wales concerning the processing of personal data or the privacy of electronic communications, as amended, replaced, or updated from time to time;
“data subject” means a living, identified, or identifiable individual about whom the Company holds personal data;
“ICO” means the Information Commissioner’s Office, a part of the UK Government with a website at ico.org.uk;
“personal data” means any information relating to a data subject who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that data subject;
“processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; and
“special category personal data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sexual life, sexual orientation, biometric, or genetic data.
It is important to note that data subjects are only entitled to access personal data that the Company holds about them. If information located in the process of responding to a SAR does not meet the definition of “personal data” (see Clause 1), the Data Protection Legislation does not entitle the data subject to access it. In certain cases, it may be necessary to separate personal data from non-personal data when responding to a SAR.
This Policy will be reviewed at least annually. The Company’s Data Protection Manager will be responsible for reviewing this Policy.
This Policy will be deemed effective on and from 1st November 2025. No part of this Policy will have retroactive effect and will apply only to matters occurring on or after this date.
CSDARP 01/2026