Skip to content
Mutus Tech

Data Sharing Policy

First approved: 8 August 2023 · Review cycle: annual · Approved by Tim Li, Managing Director, Mutus Tech Ltd.

1. Introduction

Mutus Tech Ltd ("we" or "the Company") often needs to share information between staff and external third parties. This policy aims to minimise the risk of loss, unauthorised disclosure, modification or removal of company information, while enabling legitimate business collaboration.

2. Scope

This policy covers all forms of information sharing, whether in hardcopy or electronic format. It applies to sharing with clients, suppliers, service providers, commercial partners, universities and other relevant organisations.

The policy applies to all staff, contractors and partners who handle or share company data.

3. Definitions

3.1 Data Controller

A Data Controller determines the purposes and means of processing personal data and is responsible for ensuring appropriate contracts are in place where processors are used.

3.2 Data Processor

A Data Processor processes personal data on behalf of the Data Controller and is legally liable for breaches where they are responsible. Processors must maintain records of processing activities and comply with all contractual and legal obligations.

3.3 Joint Controller

Where two or more organisations jointly determine the purposes and means of processing, they are Joint Controllers. Responsibilities must be defined clearly in a contract or agreement, particularly with respect to data subject rights and compliance with UK GDPR.

4. Responsibilities

4.1 Mutus Tech Ltd

Mutus Tech is the primary Data Controller and is ultimately responsible for compliance with current data protection legislation.

4.2 Data users

All employees and contractors comply with this policy and relevant legislation. When sharing data, they ensure recipients understand confidentiality obligations and comply with any data sharing agreement.

4.3 Managers and supervisors

Managers ensure information is only shared with authorised individuals or organisations and that data sharing agreements are in place where required.

4.4 Information Asset Owners (IAO)

IAOs are responsible for their data assets and for authorising data sharing. They ensure appropriate controls such as contracts or data sharing agreements are in place.

4.5 System owners

System owners and administrators are responsible for implementing appropriate access controls so information is only shared with authorised parties.

5. Policy

  • Mutus Tech, as a Data Controller, is accountable for ensuring compliance with relevant legislation whenever data is shared.
  • Where Mutus Tech uses a Data Processor, a written contract is in place setting out each party's responsibilities and liabilities.
  • Contracts require processors to:
    • implement appropriate security measures;
    • assist Mutus Tech in enabling data subject rights under UK GDPR;
    • incorporate Standard Contractual Clauses (SCCs) or ICO-approved clauses where required;
    • demonstrate sufficient guarantees for UK GDPR compliance and data subject protection.
  • Processors only act on documented instructions from Mutus Tech.
  • Whenever information is shared outside the UK or EEA, appropriate safeguards are applied (see Section 6).

6. International transfers

  • Personal data may only be transferred outside the UK or EEA in compliance with UK GDPR Chapter V.
  • Transfers are permitted where the receiving country or organisation is subject to a UK or EU adequacy decision.
  • Where adequacy does not apply, transfers are supported by safeguards such as:
    • Standard Contractual Clauses (SCCs);
    • ICO-approved contractual clauses;
    • legally binding agreements between public authorities;
    • approved codes of conduct or certification schemes;
    • authorised contractual arrangements approved by the ICO.
  • Individuals' rights remain enforceable, and effective legal remedies are available following the transfer.

7. Data Use Agreement template

Mutus Tech maintains a standard Data Use Agreement (DUA) template used when sharing data with project partners, research collaborators or commercial customers. The DUA covers permitted purpose, data security expectations, subject rights, retention, audit, breach notification and termination. The current template is available on request under an active engagement or NDA — please contact contact@mutus.co.uk.

8. Relationship to other policies

This policy should be read in conjunction with other Mutus Tech policies, including the Data Security Policy, Data Management Policy, Website Privacy Policy and Pezego App Privacy Policy.

9. Review

This policy is reviewed annually, or earlier if required by changes in law or business practice.


Related: Data Security Policy · Data Management Policy · Trust & compliance overview