Skip to main content

Last updated: 17th June 2026

Introduction

House of Fisher (“we”, “us”, “our”) is committed to protecting the privacy, security and lawful processing of personal information.

Since the introduction of the General Data Protection Regulation (GDPR) in May 2018 and following the implementation of the UK General Data Protection Regulation (“UK GDPR”) together with the Data Protection Act 2018, we have maintained and continuously developed our data protection framework to ensure compliance with applicable data protection legislation and recognised good practice.

We recognise that protecting personal information is an ongoing responsibility. Our approach is based on accountability, privacy by design, risk management and continuous improvement to ensure personal information is handled securely, transparently and lawfully.


Our Commitment

House of Fisher is committed to maintaining a robust and effective data protection programme that supports compliance with applicable privacy and data protection laws.

We continue to review and enhance our governance arrangements, policies, procedures and technical and organisational measures to ensure personal information remains protected throughout its lifecycle.

Our objectives are to:

  • process personal information lawfully, fairly and transparently;
  • collect and retain only data that is necessary and proportionate;
  • maintain appropriate security measures;
  • support individuals in exercising their rights; and
  • demonstrate accountability through documented policies, procedures and records.

Our Data Protection Framework

To maintain compliance and good governance standards, House of Fisher operates a structured data protection programme which includes:

Information Governance and Records Management:

We maintain processes to identify and manage the personal information we hold, including understanding:

  • what personal information is collected;
  • where it originates from;
  • how and why it is processed;
  • who it is shared with; and
  • how long it is retained.

We maintain appropriate records of processing activities where required by applicable legislation.

Policies and Procedures:

Our internal policies and procedures support compliance with UK GDPR and applicable data protection requirements and include:

Data Protection Governance:

We maintain documented data protection policies and governance controls designed to embed accountability, privacy by design and data protection by default into our operations.

Data Retention and Erasure:

We operate retention schedules and disposal procedures to support the principles of data minimisation and storage limitation. Personal information is retained only for as long as necessary and securely archived or deleted in accordance with legal, operational and regulatory requirements.

Personal Data Breach Management:

We maintain incident response and breach management procedures to identify, assess, investigate and respond appropriately to actual or suspected personal data breaches, including notification procedures where legally required.

International Data Transfers and Third Parties:

Where personal information is transferred internationally or processed by third parties, appropriate safeguards and contractual measures are implemented to protect personal information and support compliance with applicable legislation.

Subject Access Requests and Individual Rights:

We maintain procedures for managing requests from individuals and responding within applicable statutory timescales. Processes are in place to verify identity, assess requests and apply relevant exemptions where permitted by law.

Lawful Basis for Processing

House of Fisher identifies and documents an appropriate lawful basis for processing personal information under Article 6 UK GDPR and, where applicable, additional conditions for processing special category data under Article 9 and Schedule 1 of the Data Protection Act 2018.

Privacy Information

We maintain privacy notices designed to provide clear and transparent information about:

  • the personal information we collect;
  • the purposes for which it is processed;
  • lawful bases for processing;
  • how information is shared;
  • retention periods;
  • individual rights; and
  • how to contact us regarding privacy matters.

Privacy notices are reviewed periodically to ensure they remain accurate and up to date.

Consent and Marketing Communications

Where consent is relied upon as a lawful basis, we maintain processes to ensure consent is:

  • freely given;
  • specific;
  • informed;
  • unambiguous; and
  • capable of being withdrawn at any time.

Our direct marketing practices include appropriate opt-in and opt-out mechanisms and comply with applicable privacy and electronic communications requirements.

Data Protection Impact Assessments (DPIAs)

Where processing activities present a higher risk to individuals’ rights and freedoms, we undertake Data Protection Impact Assessments (DPIAs) to identify, assess and mitigate privacy risks before processing begins.

Third-Party Processors

Where third parties process personal information on our behalf, we carry out appropriate due diligence and maintain contractual arrangements that define responsibilities and require appropriate technical and organisational security measures.

Special Category Data

Where special category personal data is processed, House of Fisher applies enhanced safeguards and processes such information only where a lawful condition under applicable legislation has been identified.
Additional controls may include restricted access, encryption, monitoring and minimisation measures.

Data Subject Rights

House of Fisher supports individuals in exercising their rights under applicable data protection laws, including the right to:

  • be informed;
  • access personal information;
  • request rectification;
  • request erasure (where applicable);
  • restrict processing;
  • object to processing;
  • data portability (where applicable);
  • withdraw consent where consent is relied upon; and
  • raise concerns with the relevant supervisory authority.

Information Security

Protecting personal information remains a core business priority.

We maintain technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration, disclosure or destruction. These measures are reviewed periodically and updated where appropriate to respond to changes in technology, business operations and emerging risks.


Governance, Roles and Training

House of Fisher maintains responsibility for data protection governance across the organisation.

Appropriate personnel and internal responsibilities have been assigned to support privacy compliance, policy oversight, employee awareness and ongoing monitoring.

Employees receive data protection and information security training appropriate to their role as part of induction and ongoing learning programmes.


Contact Us

If you have any questions regarding this statement or our approach to data protection, please contact:

Trine Oestergaard Stafford
Data Protection Officer (DPO)
House of Fisher

Email: Datarequest@houseoffisher.com

Address: House of Fisher, Theale Court, 11-13 High Street, Theale RG7 5AH, UK