Web Analytics

Data Protection Compliance Framework

This Data Protection Compliance Framework explains how Orfid meets its obligations under the UK GDPR, the Data Protection Act 2018, and applicable journalistic exemptions when handling personal data, sensitive information, evidence submissions, and regulator-accessible audit records.

1. Data protection governance

Orfid maintains a multi-layer governance model to ensure lawful and ethical processing of data, including:

Data protection and compliance queries may be directed to support@orfid.co.uk.

2. Lawful bases for processing

Orfid processes personal and special-category data under the following lawful bases:

3. Special category data

Orfid may receive special category data (including health, political, or criminal information) within reports or evidence submissions. Processing occurs only where:

Access to such data is strictly controlled and fully logged via THOTH.

4. Automated compliance processing

ISIS and NUT deploy automated systems to identify and mitigate legal risks, including:

Automated controls may restrict or delay publication. Manual review is available where required by law or context.

5. Data security standards

Infrastructure adheres to recognised ISO 27001 and SOC 2 security standards.

6. Regulator access and audit trails

Regulators may be granted limited read-only “Ghost Tier” access for oversight. All access is:

Regulators are never permitted to modify platform data.

7. Incident response and breach handling

8. Law-enforcement requests

All disclosures are logged within THOTH.

9. User rights

Users may exercise UK GDPR rights subject to journalistic exemptions, including:

Requests may be submitted to support@orfid.co.uk.

10. Record-keeping and documentation

11. Retention and deletion

Secure deletion processes apply once data is no longer required.