Data Protection Controls

Henson Franklyn implements comprehensive internal controls to safeguard customer and client data from unauthorised access, aligning with the UK General Data Protection Regulation (GDPR) and the Data Protection Act. Their measures encompass both physical and digital security protocols.

1. Physical Security Measures:

  • Controlled Access: Data is stored on secured systems accessible only to authorised personnel.
  • Secure Storage: Physical documents containing personal data are kept in locked cabinets or secure areas to prevent unauthorised access.

2. Digital Security Measures:

  • Encryption: Utilisation of standard commercial encryption technologies, such as Secure Socket Layer (SSL), to protect data during transmission and storage.
  • Access Controls: Implementation of role-based access to personal data, ensuring that employees can only access information necessary for their role.
  • Password Policies: Enforcement of strong password policies, including the use of complex passwords and secure password managers.
  • Firewalls and Intrusion Detection: Deployment of firewalls and intrusion detection systems to monitor and protect against unauthorized access attempts.
  • Regular Updates and Backups: Conducting monthly software and hardware updates, along with regular backups, to maintain system integrity and data availability.

3. Organisational Measures:

  • Data Protection Policies: Adoption of comprehensive data protection policies and procedures that address all aspects of data handling, including collection, use, storage, and disclosure.
  • Employee Training: Implementation of ongoing employee training programs to promote awareness of data protection responsibilities and ensure compliance with internal policies.
  • Data Breach Procedures: Establishment of robust procedures to identify, assess, investigate, and respond to any personal data breaches promptly.

4. Third-Party Management:

  • Due Diligence: Conducting strict due diligence checks on third-party service providers to ensure they have appropriate safeguards in place to protect personal data.
  • Data Processing Agreements: Entering into data processing agreements with third parties, outlining their obligations to comply with data protection laws and internal policies.
  • International Data Transfers: Implementing safeguards for data transferred outside the UK, such as standard data protection clauses and regular reviews of destination countries’ data protection adequacy.

These measures collectively ensure that Henson Franklyn maintains a high standard of data security, restricting access to customer and client data to authorised individuals only, and protecting against unauthorised access by employees or third parties.


Tim Henson

Managing Director
Henson Franklyn Ltd

January 2026