Information Security Policy

Avalon Surveyors Ltd holds information entrusted to us by clients and by others connected with the buildings we work on. This policy explains how we protect that information and keep it confidential, accurate and available when it is needed.

Scope

The policy applies to all information held by the practice in any form, including paper files, email, electronic documents, photographs, site records and information held in cloud services or on laptops and mobile devices. It applies to everyone who works for or on behalf of the practice, and to suppliers who handle information for us.

Our commitments

  • We keep client information confidential and use it only for the purpose for which it was provided, as the RICS Rules of Conduct require.
  • We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our Privacy Policy explains how we handle personal data and the rights people have.
  • We are registered with the Information Commissioner’s Office (registration reference ZA013524).
  • We apply appropriate technical and organisational measures to protect information against loss, misuse and unauthorised access or disclosure.
  • We limit access to information to those who need it for their work.
  • We use service providers who offer appropriate security safeguards and who process information only on our instructions.
  • We keep information only for as long as it is needed, and dispose of it securely.

How we put this into practice

Our arrangements are proportionate to the size of the practice and the information we hold. This policy requires:

  • access controls on our systems, accounts and devices;
  • software and devices to be kept up to date;
  • regular back-up of electronic records;
  • care with email, including checking any request to change payment details by telephone before acting on it (see our Email Disclaimer);
  • paper records and site notes to be kept securely and disposed of confidentially; and
  • the return or secure deletion of client information when it is no longer needed, in line with our retention arrangements.

Reporting incidents

Anyone who suspects that information has been lost, sent to the wrong person or accessed without authority must tell the Director immediately. We will act to contain the incident and assess the risk. Where the law requires it, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of a personal data breach, and inform the people affected.

Responsibilities

The Director is responsible for this policy and for the practice’s data protection arrangements. Everyone who works for or on behalf of the practice is responsible for handling information in line with it.

Monitoring and review

We review this policy every year, and sooner after any significant incident or change in the law or our systems.

Related policies


Approved by the Director of Avalon Surveyors Ltd. Last reviewed: October 2026. Next review: October 2027.