Data Management Policy and Procedures
First approved: 8 August 2023 · Review cycle: annual · Approved by Tim Li, Managing Director, Mutus Tech Ltd.
1. Introduction
Mutus Tech Ltd recognises that data is one of our most valuable assets. Proper management of data is essential to ensure it is accurate, secure, accessible and used effectively in line with business objectives and legal requirements. This policy sets out how data is collected, maintained, stored, shared and disposed of.
2. Purpose
The purpose of this policy is to:
- ensure data is managed as a corporate asset;
- establish clear responsibilities for data governance;
- maintain data accuracy, quality and security;
- comply with applicable legislation, including UK GDPR and the Data Protection Act 2018;
- support business efficiency and informed decision-making.
3. Scope
This policy applies to all data held by Mutus Tech, in both digital and hardcopy form, including customer data, employee data, operational data, financial records and any other information processed in the course of business. It applies to all employees, contractors and authorised third parties.
4. Data management principles
- Ownership — all data created or collected in the course of Mutus Tech's business is owned by the company.
- Accountability — every dataset has a designated custodian responsible for its management.
- Accuracy — data is accurate, complete and kept up to date.
- Purpose limitation — data is collected for specific, legitimate business purposes.
- Single source — data is collected once and reused to avoid duplication.
- Change control — amendments to data are controlled and documented.
- Compliance — data is processed in accordance with legal and regulatory requirements.
- Standards — data conforms to recognised standards and formats where possible.
5. Roles and responsibilities
- Managing Director (Custodian) — overall accountability for data governance and compliance.
- Data Steward — assigned by management to oversee day-to-day data management, ensure quality and act as a point of contact.
- IT Administrator — responsible for technical systems that store and protect data, implementing security measures and providing access controls.
- Users — all staff and contractors who access or process data must follow this policy and report issues or breaches.
6. Data quality
- Data is regularly validated to ensure accuracy and completeness.
- Errors are corrected promptly.
- Outdated or duplicate records are identified and removed in a controlled manner.
7. Data security
- Data is protected from unauthorised access, alteration, disclosure or destruction.
- Sensitive or personal data is encrypted where appropriate.
- Data access is role-based and approved by management.
- Disposal of data follows secure destruction methods (e.g. secure shredding of hardcopies, cryptographic erasure of digital files).
Detailed access control and incident response procedures are covered in our Data Security Policy.
8. Data sharing
- Data is only shared externally where necessary for business purposes, subject to appropriate agreements and controls.
- Data sharing complies with Mutus Tech's Data Sharing Policy and Data Security Policy.
9. Data retention and disposal
- Data is retained only for as long as necessary to fulfil business or legal requirements.
- Retention schedules are applied to different categories of data.
- Secure disposal methods are used once data is no longer required.
10. Monitoring and review
- The management team reviews data management practices annually.
- This policy is updated as required to reflect changes in law, regulation or business practice.
Related: Data Security Policy · Data Sharing Policy · Trust & compliance overview