top of page

UNIVERSAL PRIVACY, DATA GOVERNANCE & PROPRIETARY RIGHTS FRAMEWORK

Platform: www.gmbhinkley.co.uk
Platform Architect & Lead Administrator: Iulian Eduard Vrajitoru
Applicable Framework: UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, Copyright, Designs and Patents Act 1988, and other applicable UK law
Version: 5.0
Updated on date -  Date: 26 August 2026

1. PLATFORM STATUS, OWNERSHIP & PURPOSE

1.1 Independent Platform Status

www.gmbhinkley.co.uk is an independently developed digital platform created to support workplace communication, member information, representative activity and digital services connected with the GMB Hinkley Point C environment.

The Platform is not the national GMB Union website and should not be interpreted as an official corporate publication of GMB nationally unless a particular item is expressly identified as such.

The Platform may contain official GMB information, links, branding, workplace material and branch-related content where its use has been authorised or is otherwise lawfully permitted.

1.2 Intellectual Property

Unless otherwise stated, original software, source code, custom integrations, database structures, user-interface designs, layouts, original written material, technical workflows and other original works created specifically for this Platform are retained by their respective legal owner.

Where original material has been created independently by Iulian Eduard Vrajitoru and has not been assigned or transferred under contract, applicable intellectual-property rights remain with him.

Nothing in this Framework claims ownership over:

  • GMB trademarks, logos or nationally produced materials;

  • employer-owned material;

  • third-party software or intellectual property;

  • member personal data;

  • material where ownership has otherwise been transferred or established by law.

Copyright ownership depends on the circumstances in which a work was created, including any applicable employment, contractual or commissioning arrangements.

1.3 Branch Use of the Platform

The Platform is made available for branch-related and representative purposes subject to appropriate technical, governance, security and data-protection arrangements.

Any future change in administration, licensing, branding, hosting or technical control must be managed separately from the treatment of personal data.

Ownership or control of the technical Platform does not create ownership of personal data held within it.

2. DATA GOVERNANCE & RESPONSIBILITY

2.1 Determining Data-Protection Roles

Data-protection roles are determined by the actual circumstances of processing, including who decides:

  • why personal data is processed;

  • what personal data is collected;

  • how it is used;

  • who receives it;

  • how long it is retained;

  • the essential means by which the processing takes place.

The labels used in this Framework describe the intended operational structure but do not override the legal test under UK data-protection law.

2.2 Intended Operational Structure

For branch-related processing, the intended structure is:

GMB / relevant GMB organisational body
Responsible for determining the legitimate union, membership, representative or organisational purposes for which personal data is processed.

Platform Administrator — Iulian Eduard Vrajitoru
Responsible for technical development, administration, maintenance, security configuration and operation of the Platform within the authority actually granted for the relevant processing activity.

Wix.com and other technology providers
Provide hosting, infrastructure, platform services and other technical processing services subject to their own contractual and data-processing arrangements.

Depending on the particular processing activity, the legal position may be controller, joint controller, processor or another applicable relationship.

Where necessary, the relevant parties should formally document those responsibilities.

3. DATA CATEGORIES

Depending on the service being used, the Platform may process the following categories of information.

Tier 1 — Identity & Workplace Information

Examples may include:

  • name;

  • trade or occupation;

  • employer;

  • workplace;

  • grade or classification;

  • representative status;

  • membership-related identifiers where required.

Tier 2 — Contact & Account Information

Examples may include:

  • email address;

  • telephone number;

  • account identifiers;

  • authentication information;

  • communication preferences.

Passwords or authentication credentials should be protected using appropriate technical controls and should not be stored in plain text.

Tier 3 — Special Category Data

Information revealing trade-union membership constitutes special-category personal data under UK data-protection law.

Other special-category information may arise depending on the service being used and should only be processed where an appropriate legal condition applies.

Tier 4 — Technical & Security Information

Examples may include:

  • IP address;

  • browser information;

  • device information;

  • security logs;

  • access records;

  • referral information;

  • technical telemetry.

Such data may be processed for security, fraud prevention, system integrity, troubleshooting and legitimate operational purposes.

4. PURPOSES OF PROCESSING

Personal data should only be processed for specified, legitimate and proportionate purposes.

Depending on the service, these may include:

  • supporting members and workplace representatives;

  • providing workplace information;

  • managing enquiries and communications;

  • directing requests to appropriate representatives;

  • administering secure member services;

  • monitoring system performance;

  • protecting accounts and systems;

  • preventing unauthorised access or misuse;

  • maintaining appropriate audit and security records;

  • analysing aggregated or appropriately minimised information to improve services.

Personal data must not be repurposed incompatibly with the purpose for which it was originally collected without an appropriate legal basis.

5. SPECIAL CATEGORY & UNION MEMBERSHIP DATA

Trade-union membership data requires additional protection.

Processing must have:

  • an appropriate lawful basis under Article 6 UK GDPR; and

  • an applicable condition for processing special-category data under Article 9 UK GDPR.

Only the minimum information reasonably required for the relevant purpose should be processed.

Access should be restricted according to role and genuine operational need.

6. ACCESS CONTROL & SECURITY

The Platform should operate using a least-privilege access model.

Where technically possible:

  • individual named accounts should be used;

  • administrator access should be limited;

  • multi-factor authentication should be enabled;

  • shared passwords should be avoided;

  • recovery credentials should remain controlled;

  • access changes should be documented;

  • administrator activity should be auditable;

  • unnecessary access should be removed promptly.

No person should be given unrestricted access merely because they hold a senior role where that access is not necessary for the relevant function.

Access to special-category or confidential member information should be separately justified.

7. TECHNOLOGY PROVIDERS & SUB-PROCESSING

The Platform uses third-party technical services, which may include:

  • Wix.com;

  • analytics providers;

  • email and communications services;

  • security services;

  • authentication providers;

  • other integrations necessary for Platform functionality.

These providers may process information in multiple jurisdictions in accordance with their contractual arrangements and applicable transfer safeguards.

The Platform does not guarantee that all data is stored exclusively within the United Kingdom or European Economic Area.

Where international transfers occur, appropriate lawful safeguards should apply.

8. ANALYTICS, AUTOMATION & AI

Automated tools may be used to assist with:

  • routing enquiries;

  • categorising information;

  • analysing aggregated trends;

  • security monitoring;

  • administrative support.

The Platform should not make solely automated decisions producing legal or similarly significant effects on individuals unless the applicable legal requirements and safeguards are satisfied.

Where significant automated processing is used, appropriate transparency, human review and challenge mechanisms should be available where required by law.

Personal data should not be used to train unrelated generative-AI systems unless there is a lawful basis, proper governance and appropriate transparency.

9. DATA MINIMISATION & RETENTION

Only personal data reasonably required for the relevant purpose should be collected and retained.

Data should not be kept indefinitely merely because storage is technically available.

Retention periods should reflect:

  • operational need;

  • legal requirements;

  • dispute or case-management requirements;

  • security requirements;

  • GMB or other applicable organisational policies.

Information that is no longer required should be securely deleted, anonymised or archived where appropriate.

10. INDIVIDUAL RIGHTS

Individuals may have rights under UK data-protection law, including rights relating to:

  • access;

  • rectification;

  • erasure;

  • restriction;

  • objection;

  • portability;

  • automated decision-making;

  • complaints to the Information Commissioner.

These rights are subject to the statutory conditions, limitations and exemptions applying to the particular circumstances.

The right to erasure is not absolute and does not automatically require deletion where information must lawfully be retained.

Requests will be assessed according to the applicable legal framework and the identity of the relevant controller.

11. DATA SHARING

Personal information should only be disclosed where there is:

  • a legitimate operational need;

  • an appropriate lawful basis;

  • proper authority;

  • an applicable legal obligation;

  • or another lawful justification.

Access to or extraction of Platform data does not remove the recipient's responsibility to handle that information lawfully and securely.

No personal information is sold to commercial data brokers.

12. PLATFORM ADMINISTRATION & CONTINUITY

Technical continuity should be managed through documented governance rather than informal transfer of passwords or unrestricted access.

Where administration needs to be shared or transferred, the preferred approach is:

  • named administrator accounts;

  • defined permissions;

  • documented responsibilities;

  • multi-factor authentication;

  • controlled recovery arrangements;

  • access logging;

  • secure backup procedures;

  • removal of obsolete privileges.

The existence of a continuity requirement does not by itself justify unrestricted access to all Platform data.

13. INTELLECTUAL PROPERTY & DATA SEPARATION

Platform intellectual property and personal data are legally distinct.

A person may own or control software, design, source code or other original technical work without owning the personal data processed through that technology.

Similarly, transfer or termination of technical administration does not automatically transfer intellectual-property rights.

Any separation, migration or cessation of Platform services should therefore address separately:

  1. personal data;

  2. software and technical infrastructure;

  3. GMB branding and official content;

  4. account access;

  5. security credentials;

  6. contractual responsibilities;

  7. retention and deletion requirements.

14. LIABILITY & RESPONSIBILITY

Each party remains responsible for complying with the legal duties that apply to it.

Nothing in this Framework excludes or limits liability where such liability cannot lawfully be excluded.

The Platform Administrator is not responsible for independent misuse of information by another person after that person has lawfully received or extracted the information, except to the extent that responsibility continues to arise under applicable law.

Any contractual indemnity or allocation of liability must be separately agreed where legally required and should not be assumed merely from use of this Platform.

15. GOVERNANCE REVIEW

The Platform's data-governance arrangements should be reviewed when there is a material change involving:

  • Platform ownership or administration;

  • GMB branch or regional governance;

  • administrator access;

  • hosting;

  • data categories;

  • new technologies;

  • automation or AI;

  • member services;

  • regulatory requirements;

  • security incidents;

  • changes to controller or processor responsibilities.

Material changes should be documented.

16. SECURITY INCIDENTS

Suspected unauthorised access, disclosure, loss, alteration or misuse of personal data should be reported promptly to the appropriate responsible person.

Where a personal-data breach occurs, the relevant controller must assess whether notification to the Information Commissioner's Office or affected individuals is required.

Technical logs and evidence relating to suspected incidents should be preserved securely.

17. CONTACT & REGULATORY OVERSIGHT

Platform Technical Administration

Iulian Eduard Vrajitoru
Platform Architect & Lead Administrator

Email: iuli675@gmail.com

GMB-Related Data Governance

Questions relating to GMB's use of personal data should be directed to the appropriate GMB branch, regional or national data-protection contact according to the relevant processing activity.

Regulatory Authority

Information Commissioner's Office (ICO)
www.ico.org.uk

18. STATUS OF THIS FRAMEWORK

This document is intended to explain the Platform's governance, privacy and technical operating principles.

It does not by itself:

  • determine legal controller or processor status contrary to the underlying facts;

  • transfer intellectual-property rights;

  • transfer ownership of personal data;

  • create an automatic indemnity;

  • override UK data-protection law;

  • override GMB rules or authorised governance arrangements;

  • override contractual or statutory rights.

Where a conflict exists between this Framework and applicable law, the applicable law prevails.

© 2026 IEV — Original Platform Design & Technical Works.

GMB names, logos and official materials remain subject to the rights of their respective owners.

bottom of page