Information security policy for suppliers
1. Introduction
At ELE, we are trusted with highly sensitive and confidential client information. This responsibility extends to all third-party suppliers who provide services that involve access to our data, systems, or infrastructure.
This policy sets out the minimum information security standards expected of all suppliers who process, store, transmit, or otherwise handle ELE information. It complements ELE’s internal Information Security Policy and IT Security Checklist.
2. Purpose
The aims of this policy are to:
- Protect ELE’s business information and client data from unauthorised access, loss, or disclosure
- Ensure compliance with data protection laws including the UK GDPR
- Clarify the information security responsibilities of suppliers
- Promote consistent and appropriate handling of confidential data across the supply chain
3. Scope
This policy applies to all third parties engaged by ELE who may access or process:
- ELE’s business information
- Client documents or personal data
- ELE systems or cloud platforms
It applies regardless of the medium or format of information (e.g. paper, digital, verbal), and includes suppliers such as:
- Freelance contractors and subcontractors
- IT service providers and SaaS platforms
- Virtual assistants and external consultants
- Hosted service providers (including those using cloud infrastructure)
4. Key Definitions
Business Information: Internal information generated by or for ELE in the course of business.
Personal Data: Information relating to an identifiable individual, including client, employee or candidate data.
Confidential Information: Trade secrets or sensitive data disclosed in the course of work with ELE.
Sensitive Personal Data: As defined in the UK GDPR, includes health data, racial or ethnic origin, sexual orientation, and similar categories.
5. General Security Principles
Suppliers must:
- Treat all ELE and client data as confidential by default
- Process personal data only where necessary and lawful
- Implement appropriate technical and organisational measures to protect information
- Ensure staff or subcontractors working on ELE matters are trained and bound by equivalent confidentiality and security standards
6. Data Handling and Storage
Suppliers must:
- Store ELE data securely (e.g. encrypted cloud storage or secured drives)
- Never store ELE data on unsecured local drives or personal cloud services
- Avoid using removable media (e.g. USB sticks) unless explicitly authorised
- Apply strong password protection and two-factor authentication where supported
- Ensure all devices used for ELE work are password-protected and locked when unattended
7. Access Control
Suppliers must:
- Restrict access to ELE data on a need-to-know basis
- Immediately remove access rights when a member of staff or subcontractor no longer requires access
- Notify ELE of any subcontractor who will access ELE data or systems
8. Communications and Data Transfer
When transferring ELE data, suppliers must:
- Use encrypted email or secure file-sharing platforms (e.g. Google Workspace)
- Never send confidential information via unencrypted or unauthorised channels
- Verify recipient details before sending
- Label sensitive files clearly (e.g. “Strictly Private and Confidential”)
9. Working Remotely
Suppliers working from home or co-working spaces must:
- Ensure confidential ELE data is not accessible to others in the household or shared space
- Avoid printing ELE data unless necessary and with secure disposal
- Use secure WiFi with encryption and change default router passwords
10. AI Tools and Cloud Platforms
Suppliers must:
- Not use public generative AI tools (e.g. ChatGPT, Gemini) to process client or ELE data unless express written consent is provided
- Avoid uploading ELE or client content to platforms without appropriate data protection compliance (e.g. UK GDPR adequacy or DPA agreement)
- Pay careful attention to and apply all elements of our AI policy
11. Data Retention and Deletion
Suppliers must:
- Retain ELE data only for as long as necessary to fulfil their obligations
- Securely delete or return data once work is completed, in line with ELE’s instructions
- Confirm deletion of all copies (including backups) when required
12. Subprocessors and Third Parties
Suppliers must:
- Not engage subprocessors or third-party platforms to process ELE data without prior written approval
- Ensure any approved subprocessors meet the same security obligations
13. International Data Transfers
Suppliers must:
- Not transfer ELE or client data outside the UK without prior written authorisation
- Ensure that any such transfer meets UK GDPR requirements (e.g. adequacy decision or standard contractual clauses)
14. Breach Notification
Suppliers must:
- Notify ELE immediately of any suspected or actual data breach or security incident affecting ELE data
- Provide timely cooperation with any required investigations or notifications
15. Compliance and Monitoring
ELE reserves the right to:
- Request evidence of a supplier’s security practices and compliance
- Conduct due diligence and regular reviews
- Terminate relationships where security obligations are not met
16. Contact
Any questions about this policy or information security obligations should be directed to:
Data Protection Officer
Helen Foord
helen@ele.team