Data Protection & GDPR Policy
| Policy owner | SuperSubBetting (sole trader) |
| Effective date | 1 January 2025 |
| Version | 1.0 |
| Review frequency | Annually, or following a significant change in processing activities or applicable law |
1. Purpose
This policy sets out how SuperSubBetting collects, uses, stores and protects personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). It also documents the procedure for identifying and reporting personal-data breaches. The policy is proportionate to the activities of a small digital publisher and sole trader.
2. Scope
This policy applies to all personal data processed by SuperSubBetting in the operation of the supersubbetting.com website, including:
- Website visitor analytics data (e.g. IP addresses, page views, session duration via Google Analytics or equivalent).
- Cookie data placed on visitor devices for analytics and site functionality.
- Contact-form submissions (name, email address, message content).
- Limited technical event data associated with outbound links.
Not in scope: SuperSubBetting does not collect betting account details, payment card data, gambling deposits, withdrawals or any financial balances belonging to end users. Those data are processed exclusively by the licensed operators to whom users are referred.
3. Legal basis and applicable law
- Legal requirement: SuperSubBetting is subject to UK GDPR and DPA 2018 as a UK-established data controller processing personal data of UK and EEA residents.
- SuperSubBetting is not required to register with the Information Commissioner's Office (ICO) as a data controller solely because it is a small business, but does maintain a record of processing activities as good practice and will register if processing activities change to require it.
- SuperSubBetting is not regulated by the UK Gambling Commission. Digital publishers are not licensed gambling operators under the Gambling Act 2005.
4. Responsibilities
- The sole trader is the data controller and is personally responsible for all data protection compliance.
- Any third-party tools or services used (e.g. analytics platforms, email providers) are data processors and are subject to data processing agreements where required.
5. Practical controls
- Cookie consent: A consent management banner is shown to new visitors. Analytics and non-essential cookies are activated only after explicit consent.
- Privacy notice: A publicly accessible cookie and privacy notice explains what data is collected, why, and users' rights.
- Data minimisation: Only data necessary for the stated purpose is collected. Contact-form data is not used for marketing without separate consent.
- Access controls: Website admin access is protected by strong passwords and two-factor authentication (2FA).
- Third-party processors: Tools such as Google Analytics are configured to anonymise IP addresses where possible. Data processing agreements are accepted before use.
- Retention: Analytics data is subject to the retention periods in the Records Management Policy. Contact-form emails are deleted when no longer needed.
- Subject rights: Requests to access, correct, delete or port personal data are handled within one calendar month. Contact: info@supersubbetting.com.
6. Personal-data breach reporting procedure
Definition: A personal-data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- Identify: On discovering or suspecting a breach, document the date, time, nature and likely scope immediately.
- Assess risk: Determine whether the breach is likely to result in a risk to the rights and freedoms of natural persons (e.g. financial loss, discrimination, reputational harm).
- Report to ICO: If the breach is likely to result in a risk to individuals, report to the ICO at ico.org.uk/report-a-breach within 72 hours of becoming aware.
- Notify individuals: If the breach is likely to result in a high risk to individuals, notify affected individuals without undue delay.
- Record: Log all breaches (including those not reported to the ICO) in the breach register, noting nature, effects and remedial actions taken.
- Remediate: Take steps to contain the breach and prevent recurrence.
Legal requirement: Reporting to the ICO within 72 hours is a legal requirement under Article 33 UK GDPR where there is a risk to individuals. Failure to report is a breach of the DPA 2018 and may result in ICO enforcement action.
7. Record-keeping requirements
- Record of processing activities (ROPA) — maintained and updated when processing changes.
- Breach register — all breaches recorded regardless of ICO reporting threshold.
- Consent records — where consent is the lawful basis, evidence of consent is retained.
- Subject-rights request log — record of requests received and responses provided.
8. Reporting and escalation
The sole trader is the single point of escalation. For breaches requiring ICO notification, report via the ICO self-service portal within 72 hours. For concerns raised by third parties, respond within five working days.