- Ethical Technology
- The data the group will hold
Ethical Technology · Data
The data the group will hold
Every dataset in the group has a documented origin, a lawful basis, a purpose and a deletion date before anyone works with it. The processing register held 84 activities at 30 June 2026. A dataset whose origin cannot be stated is not admitted, and a dataset whose purpose has ended is deleted rather than kept in case it becomes useful.

Commitments
- Every dataset carries a documented origin and a lawful basis before its first use.
- The group buys no bulk personal data, scrapes no networks and sells no client data.
- Data given for one mandate or one transaction is never used to serve another.
- A new purpose for existing data is a new activity and needs its own assessment.
- Deletion runs on a schedule and produces a certificate, not a promise.
Where a dataset comes from
The origin field in the processing register is the provenance principle made concrete. It states whether the data came from the individual, from a public register, from a screening provider under contract, from a counterparty in a transaction or from a licensed commercial source. It names the date of receipt and the person who accepted it into the group.
The Information & Data division builds sector datasets on pharmaceutical, animal-health, aquaculture and agri-science markets. Those datasets are assembled from licensed feeds, public filings, published research and the direct reporting of portfolio companies. Each source is recorded at the level of the individual feed, and a feed whose own provenance is unclear is dropped rather than blended into the whole.
An origin statement is tested when the dataset is admitted and again at each annual review of the register entry. Where a supplier changes its collection method, the dataset is reassessed before the next use. Fifteen sector datasets were reviewed in the twelve months to 30 June 2026 and one was retired because the supplier could no longer evidence consent for a subset of its records.
Data the group declines
The group does not buy personal data in bulk. It does not collect data from public social networks. It does not accept a dataset from a vendor that cannot say where the records came from, and it does not accept one assembled from another firm client base. These refusals cost the group information that competitors hold, and the Board has accepted that cost twice on the record.
Data received from a counterparty under a confidentiality undertaking is used for the transaction it was given for and for nothing else. It is never used to train, tune or ground a system. Data collected under one client mandate is never used to serve another client, and no client data is sold, exchanged or contributed to a pooled dataset outside the group.
- Bulk purchases of personal data from data brokers.
- Records collected from public social networks or scraped from websites.
- Datasets whose supplier cannot evidence the origin of every record.
- Client or counterparty data used to train any system that serves someone else.
- Any contribution of group or client data to a pooled industry dataset.
Purpose, and the edge of a mandate
The group processes personal data to identify its clients, to run their mandates and to meet its legal obligations. There is no fourth purpose. Every item held must trace to one of those three, and the trace is a field in the register rather than an argument made after the fact. Marketing to eligible counterparties is addressed to firms and to roles, never to inferred interests.
Where a client volunteers information the mandate does not need, it is recorded only if the client asks for it to be recorded, and it is never an input to a decision. Where a division wants to use existing data for a new purpose, that is a new processing activity: it needs its own entry, its own basis and its own privacy assessment before a single query is run.
Nineteen privacy assessments were completed in the twelve months to 30 June 2026 and two proposals were declined. Both refusals concerned the reuse of client due diligence records for an analytical purpose that no mandate required. The Information Governance Committee heard each case and the Group Data Protection Officer position was upheld.
Deletion as a discipline
Personal data relating to a client relationship is kept for seven years after the relationship ends and is then deleted, unless the law of the booking jurisdiction requires longer, in which case the longer period is recorded in the register and applied. Data gathered for a prospective relationship that does not proceed is deleted after twelve months. Candidate records from an unsuccessful recruitment go six months after the decision.
Deletion is a scheduled system action rather than an instruction to a person. Records reach their date, the deletion job runs, and the job produces a certificate that the Group Data Protection Officer reviews. A record held past its date without a documented legal reason is a finding, and findings on retention are reported to the Information Governance Committee each quarter.
Who decides
The Group Data Protection Officer owns the register and reports to the Information Governance Committee, chaired by an independent director, with a direct line to the Chair of the Board. Local data protection officers in Singapore, Luxembourg, London, Dubai and Toronto report to the Group Data Protection Officer on this subject and to their entity boards on everything else.
Disputes between the Group Data Protection Officer and a business division go to the Information Governance Committee rather than to the division head. That structure exists because a data judgement made inside a revenue line is not an independent judgement. In the twelve months to 30 June 2026 the Committee heard three such disputes and decided two in favour of the data protection position.
Also on ethical technology