1. Who is responsible for your personal data
The controller is the Responsible Markets Conduct Association ("RMCA"), a private company limited by guarantee without share capital, incorporated in England and Wales under Company No. 17408187.
Registered office: First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.
Privacy contact: privacy@rmca.org.uk
2. What this notice covers
This notice describes the personal data RMCA actually processes today through its current public websites, including https://www.rmca.org.uk, https://www.fdrc.org.uk and https://www.pscr.org.uk.
RMCA's current public websites are publishing, reference and explanatory websites. They do not operate user accounts, logins, payment processing, marketing lists or optional analytics. This notice is deliberately limited to that current reality.
3. What this notice does not cover
Several RMCA programmes are described publicly as planned or in development. Those services are not operational, and this notice does not describe them as if they were. They include participant applications and onboarding, institutional evidence rooms, FDRC case and complaint handling, and private PSCR evidence access.
When any of those services becomes live, the processing will be governed by an additional layered privacy notice published before that service begins operating. This notice will be updated at the same time.
4. Personal data currently processed
4.1 Technical and delivery data
When you visit a page, our hosting platform automatically processes technical request data so the site can be delivered and kept secure. This ordinarily includes your IP address, user-agent string, the URL requested, the referring URL where sent by your browser, and the date and time of the request.
This data is generated by the platform layer as an unavoidable part of serving a website over the internet. RMCA does not combine it with any other data to build a profile of you, and does not use it for advertising or behavioural tracking.
4.2 Correspondence data
If you choose to contact RMCA by email, we process the information you send. Depending on which route you use, this may include your name, your email address, your employer or professional role where you supply it, and the content of your message and any attachments.
Published contact routes are privacy@rmca.org.uk, legal@rmca.org.uk, complaints@rmca.org.uk, corrections@rmca.org.uk, security@rmca.org.uk and secretariat@rmca.org.uk. Email is not a secure channel; please do not send sensitive or special-category information unless it is strictly necessary.
4.3 Search terms you type
The public register pages include a search and filter control. That control runs entirely in your browser against material already delivered to the page. Your search terms are not submitted to RMCA as a form and are not stored by RMCA.
Because search terms are placed in the page URL so results can be shared and bookmarked, a term you type may appear in the platform request logs described at 4.1. Please do not enter personal or confidential information into that field.
4.4 Register and demonstration content
The RMCA Public Register is still in development. The register and demonstration pages currently published contain illustrative and synthetic material only. The entities, records and dates shown are fictional examples created to demonstrate record structure, and they are not statements about real people or real organisations.
Where RMCA later publishes information drawn from public sources, it will be published because it is already publicly available from an identified source, and the relevant public-source explanation and correction route will apply.
5. Current retention
The table below covers only the categories actually in use today. Where a fixed period is set by a third-party platform rather than by RMCA, or where retention necessarily depends on the subject matter of your correspondence, we state the documented criterion instead of an invented number.
| Data category | Purpose | Retention period or criterion | Trigger / start point | Reason |
|---|---|---|---|---|
| Technical and delivery data (4.1) | Site delivery, availability, security and abuse prevention | Retained for the standard log-retention window operated by our hosting platform; RMCA does not extend it or copy logs into separate long-term storage | Date the request is made | Short operational retention is sufficient to investigate faults, outages and abuse; longer retention would serve no purpose |
| Correspondence data (4.2) — general enquiries | Reading, routing and answering the enquiry | Kept while the enquiry is open, then deleted once the matter is closed and no follow-up is reasonably expected | Date the message is received | The data has no further purpose once the enquiry is resolved |
| Correspondence data (4.2) — legal, complaint, correction and security reports | Handling the matter and keeping a defensible record of what was reported and how it was dealt with | Kept for as long as needed to handle the matter and to evidence the decision, and for any period required by a limitation, regulatory or legal-obligation requirement that applies to that matter | Date the matter is closed | Accountability requires that a complaint, correction or security report can be evidenced after closure |
| Privacy rights requests (4.2 via privacy@) | Verifying and answering the request and demonstrating compliance | Kept for the period necessary to demonstrate that the request was handled correctly | Date the response is issued | RMCA must be able to show it met its UK GDPR obligations |
RMCA has not set an arbitrary fixed period where none is justified. Where a specific numeric period is later approved through RMCA governance, this table will be updated to state it.
6. Lawful bases
| Processing | Lawful basis |
|---|---|
| Technical and delivery data | Legitimate interests — operating a secure, available website. Our interest is limited to delivery and security, and the processing is the minimum inherent in serving a page |
| Correspondence and enquiry handling | Legitimate interests — responding to a person who has chosen to contact us about our work |
| Complaints, corrections and security reports | Legitimate interests in accountable handling; and legal obligation where a specific duty applies to the matter reported |
| Privacy rights requests | Legal obligation — compliance with the UK GDPR |
Where we rely on legitimate interests, you may object as described at section 10.
7. Recipients and processors
RMCA does not sell personal data, does not share it for advertising, and does not disclose it to third parties for their own marketing.
The current categories of recipient are:
- Our hosting and content-delivery platform, which processes technical request data on our behalf in order to serve the websites. The current production sites are deployed on the Vercel platform.
- Our email service provider, which processes correspondence sent to our published addresses on our behalf.
- Professional advisers, such as legal advisers, where a matter requires advice, and only to the extent necessary.
- Public authorities, regulators or courts, where disclosure is required by law or is necessary to establish, exercise or defend legal claims.
No optional analytics, advertising, profiling or data-broker recipient is involved, because no such technology is deployed. See the Cookies and Storage Technologies Notice for the verified technical inventory.
8. International transfers
RMCA is established in the United Kingdom and intends that personal data associated with its current websites is processed in the UK or the European Economic Area wherever reasonably practicable.
Some hosting, content-delivery and email infrastructure is operated by providers with facilities or support functions outside the UK and EEA. Where personal data is transferred outside the UK, RMCA relies on a transfer mechanism recognised under UK data protection law — ordinarily UK adequacy regulations, or the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with any additional safeguards required following a transfer risk assessment.
You may request further information about the transfer mechanism applicable to a specific category of processing by contacting privacy@rmca.org.uk.
9. Security and data zones
RMCA operates a deliberate separation between its public publishing zone and any non-public zone.
The public zone is the material published on the websites, which is intended to be read by anyone and is served as static content. There is currently no public login, user account, upload route or public database write path on these websites.
Any non-public material, including correspondence about complaints, corrections and security reports, is handled separately from the public publishing zone and is restricted to the people who need it to handle the matter. Future case, participant and evidence-room services will be operated in a controlled non-public zone with their own access controls and their own layered privacy notice.
Technical and organisational measures include HTTPS transport security, hardened HTTP response headers, least-privilege access to publishing and correspondence systems, and separation of published output from working material.
10. Your rights
Subject to the conditions and exemptions in UK data protection law, you have the right to:
- be informed about how your personal data is used, which is the purpose of this notice;
- request access to a copy of your personal data;
- request rectification of inaccurate or incomplete personal data;
- request erasure where the data is no longer necessary or was processed unlawfully;
- request restriction of processing while a dispute is resolved;
- object to processing carried out on the basis of legitimate interests;
- data portability, where the processing is based on consent or contract and is automated.
RMCA does not carry out automated decision-making producing legal effects, and does not carry out profiling, on its current public websites.
To exercise any right, contact privacy@rmca.org.uk. We will respond within one month of receiving a valid request, and will tell you if that period needs to be extended because the request is complex.
A request to correct a published factual record is handled through the factual correction and right-of-reply route at corrections@rmca.org.uk rather than as a data-protection rectification request, because it concerns the accuracy of a publication rather than personal data held about you. Where a request engages both, RMCA will handle both aspects.
11. Complaining to the Information Commissioner's Office
If you are unhappy with how RMCA has handled your personal data, you may complain to the UK supervisory authority:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Helpline 0303 123 1113. Website https://ico.org.uk.
We would prefer the opportunity to resolve the matter first, but you are not required to contact us before complaining to the ICO.
A complaint about RMCA's services, governance or conduct that does not concern personal data is handled through the separate complaints process.
12. Changes to this notice
This notice describes current processing. It will be updated when processing changes, and in particular before any new service that involves additional personal data begins operating. The version and effective date shown alongside this document record the current published version.
13. Contact
Privacy enquiries and rights requests: privacy@rmca.org.uk. General enquiries: secretariat@rmca.org.uk. Legal enquiries: legal@rmca.org.uk. Factual corrections and right of reply: corrections@rmca.org.uk. Security reports: security@rmca.org.uk.
Responsible Markets Conduct Association — Company No. 17408187; incorporated in England and Wales; registered office: First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.