Privacy notice
Lloyd’s Register Foundation takes the security of your personal information very seriously and is committed to ensuring that your personal information is protected at all times.
Summary
This summary is intended for the Foundation’s global audience, where English may not be the reader’s first language and readers may not be familiar with data protection or privacy practices. This notice explains how the Foundation collects, uses, stores and shares your personal information. It applies when you apply for or receive funding, work with us, use our websites or Funding Portal, attend our events, visit the Heritage Centre, provide services or otherwise interact with the Foundation. You have rights over your personal information, including the right to ask for a copy, correct inaccurate information and raise concerns or make a complaint about how it is used. For questions or to exercise your rights, contact dataprotection@lr.org.
About this notice
Lloyd’s Register Foundation (known as the Foundation, we, us or our) respects your privacy and is committed to protecting your personal data. This privacy notice explains how we collect, use, store and share your personal data through our websites, online portals, customer relationship management and grant management systems, events, correspondence and other interactions with the Foundation. It also explains your privacy rights under applicable data protection laws including the Data Protection Act 2018, the UK General Data Protection Regulation, the Data (Use and Access) Act 2025 and where applicable the EU General Data Protection Regulation.
Who controls your personal data?
A controller is a person or organisation that, alone or jointly with others, determines why and how personal data is processed. Unless we notify you otherwise, the Foundation is the controller of personal data collected and processed through our websites, online portals, customer relationship management and grant management systems, events, correspondence and other interactions with the Foundation.
Who does this notice apply to?
This privacy notice applies to personal data we process in connection with:
Grant applicants: Individuals who apply for grants, funding or other support from the Foundation and individuals named in applications or supporting documents.
Grantees: Individuals who receive grants, funding or other support directly from the Foundation.
Representatives of applicant, grantee and partner organisations: Employees, project team members, consultants, trustees, directors, authorised signatories, referees and other individuals working for or associated with organisations that apply for funding, receive funding, collaborate with or otherwise engage with the Foundation.
Prospective applicants and partners: Individuals and representatives of organisations that may be eligible for or interested in funding, collaboration or other support from the Foundation.
Peer reviewers: Individuals who review grant applications, funded activities or project outputs to help assess their quality, suitability, progress or impact.
Expert panel members and expert comment authors: Individuals who participate in expert panels, provide expert comments or otherwise contribute specialist knowledge to support the Foundation’s work and decision-making.
Suppliers and service providers: Individuals who supply products or services to the Foundation, including employees, contractors and representatives of supplier organisations.
Event participants and contributors: Individuals who register for, attend, speak at or otherwise contribute to our events, webinars, workshops or activities including events held at our premises.
Newsletter subscribers: Individuals who subscribe to receive newsletters, updates, invitations or other communications from the Foundation.
Website and portal users: Individuals who browse or interact with our websites, use our online services, create or manage a Funding Portal account, submit information through online forms or access information and resources we provide.
Research participants and contributors: Individuals who participate in research, surveys, consultations, interviews, case studies or evaluations conducted or commissioned by the Foundation.
Heritage Centre visitors and users: Individuals who visit the Heritage Centre at 71 Fenchurch Street, London, EC3M 4BS or access its collections, resources, events, training or services.
What personal data do we collect?
Personal data means any information relating to an individual who can be identified directly or indirectly. It does not include information where an individual’s identity has been permanently removed so that the individual can no longer be identified. This is known as anonymised data. Anonymised data falls outside the scope of data protection laws.
Identity Data: Name, title, job title, username or similar identifier, organisation, role and current or previous professional affiliation.
Contact Data: Email address, telephone number, postal correspondence address, billing address and delivery address.
Financial Data: Bank account details and other financial information needed to administer grants, payments, expenses or supplier arrangements.
Transaction Data: Payment details, payment history and information about grants, fees, expenses, reimbursements and other transactions.
Technical Data: Internet Protocol address, approximate location, browser type and version, operating system, device information, login information and other technical information generated when accessing our websites, portals or online services.
Usage Data: Information about how you use our websites, portals, online services, resources and Heritage Centre services.
ID and Verification Data: Information used to confirm your identity or authority. This may include photographic identification, a passport, national identity document, personal photograph or other verification information where necessary and lawful.
Professional and Background Data: Employment information, professional biography, qualifications, expertise, publications, organisational roles, references and relevant information obtained from professional or publicly available sources.
Relationship and Engagement Data: Information about your relationship and interactions with the Foundation, including your organisation, role, professional affiliations, areas of interest and participation in Foundation activities.
Application, Assessment and Grant Management Data: Information contained in applications, supporting documents, assessments, peer reviews, funding agreements, budgets, reports, project outputs and grant-related correspondence.
Due Diligence and Compliance Data: Information used to assess eligibility, governance, financial controls, conflicts of interest, sanctions, fraud, safeguarding and compliance with legal, regulatory or grant requirements.
Portal and Account Data: Portal username, account registration and verification information, account status, access history, authentication information and account administration records.
Communications and Interaction Data: Emails, letters, enquiries, feedback, survey responses, complaints, meeting notes and other communications or interactions with the Foundation.
Marketing and Communications Data: Preferences for receiving newsletters, event invitations, marketing and other communications from the Foundation.
Administrative and Audit Data: Record creation and amendment history, approvals, status changes, system notifications, access records and audit trails.
Image and Recording Data: Photographs and audio or video recordings collected through events, interviews, research or other Foundation activities.
Peer Review and Conflict of Interest Data: Expertise, availability, reviews, assessments, recommendations, financial or professional interests and relationships with applicants or grantees.
Special Category Data: Sensitive information requiring additional protection, including relevant health or accessibility information, and dietary requirements where these reveal health information or religious or philosophical beliefs. This applies only where an additional legal condition under applicable data protection laws is met, along with your explicit consent.
Criminal Offence Data: Information relating to criminal allegations, proceedings, offences or convictions where processing is necessary and lawful.
Why do we use your personal data?
The processing tables across provide further information about why we use your personal data and
the lawful bases on which we rely.
We may use your personal data in the following circumstances:
Consent: Where you have given us consent for a specific purpose. You may withdraw consent at any time by contacting dataprotection@lr.org.
Performance of a contract: Where processing is necessary to enter into or perform a contract with you.
Legal obligation: Where processing is necessary for us to comply with a legal or regulatory obligation.
Vital interests: Where processing is necessary to protect your life or the life of another person.
Public obligation: Where processing is necessary for us to comply with a public obligation, for example in matters of public health or public interest.
Legitimate interests: Where processing is necessary for our legitimate interests or those of a third party and your interests and fundamental rights do not override those interests.
Where do we get your personal data from?
We collect personal data from a range of sources, depending on your relationship and interactions
with the Foundation:
Directly from you: You may provide personal data when you complete an application or other form, create or manage a Funding Portal account, register for a grant, newsletter or event, submit reports or supporting documents, participate in research or surveys, visit the Heritage Centre or communicate with us by email, post, telephone, online meeting or in person.
From organisations associated with you: Applicant, grantee, partner, supplier or other organisations may provide information about their employees, trustees, directors, project team members, consultants, authorised signatories, referees or other representatives as part of an application, funded project, contract or other interaction with the Foundation.
From other individuals: We may receive information about you from referees, peer reviewers, expert panel members, project partners, collaborators or other individuals involved in our grant-making, research, events or other activities.
From our employees and contractors: Our employees, contractors and authorised representatives may create or add information to our customer relationship management and grant management systems. This may include correspondence, meeting notes, application assessments, due diligence findings, relationship-management information, project monitoring information, decisions and other administrative records.
From previous systems and records: We may transfer information from previous grant management systems, customer relationship management systems, databases, spreadsheets, documents or other records into our current systems where it remains necessary for grant administration, relationship management, audit, reporting or other lawful purposes.
From publicly available sources: We may collect professional and organisational information from public websites, registers, publications, news sources, professional profiles and research databases. This may include information from services such as ORCID, the Research Organisation Registry and 360Giving.
From service providers and other third parties: We may receive personal data from organisations that support our websites, Funding Portal, customer relationship management and grant management systems, events, communications, due diligence, identity or sanctions checks, payment processing, analytics and other Foundation activities.
From payment providers: Banks, payment processors and other financial service providers may provide payment and transaction information needed to administer grants, fees, expenses, reimbursements or payments for products and services.
Automatically through our websites and online services: When you visit our websites or portals, interact with our online services, or open or select links in communications we send, we and our service providers may automatically collect Technical Data and Usage Data through cookies, pixels, web beacons, software development kits, server logs and similar technologies. Further information is available in our Cookies Policy.
Why do we process your personal data?
The processing tables below explain why we process your personal data, the categories of personal data involved and the lawful bases on which we rely. Depending on your relationship and interactions with the Foundation, more than one processing table may apply to you.
This table applies where you apply for funding or support, receive funding, work for or with an applicant, grantee or partner organisation, are named in an application or supporting document or otherwise participate in a funded project or activity.
Processing activities | Categories of personal data | Lawful basis |
| To create and manage contact, organisational, relationship, portal and system records | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Portal and Account Data; Technical Data; Administrative and Audit Data | Legitimate interests, including maintaining accurate records, managing relationships and administering our activities; Performance of a contract where applicable |
| To receive, process, assess and decide applications for funding or support, including obtaining references, conducting peer or expert review and communicating decisions | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Application, Assessment and Grant Management Data; Peer Review and Conflict of Interest Data; Communications and Interaction Data | Legitimate interests, including making fair and informed funding decisions; Performance of a contract or taking steps before entering into a contract where applicable; Legal obligation where applicable |
| To carry out due diligence, eligibility, governance, financial, fraud, sanctions, safeguarding, conflict of interest and other compliance checks | Identity Data; Contact Data; Professional and Background Data; Financial Data; ID and Verification Data; Relationship and Engagement Data; Due Diligence and Compliance Data; Special Category Data or Criminal Offence Data where necessary and lawful | Legal obligation where applicable; Legitimate interests, including protecting individuals, charitable funds and the Foundation. |
| To enter into, administer and manage funding, grant, collaboration or other agreements, including budgets, payments, expenses and reporting requirements | Identity Data; Contact Data; Financial Data; Transaction Data; Relationship and Engagement Data; Application, Assessment and Grant Management Data; Communications and Interaction Data; Administrative and Audit Data | Performance of a contract where the agreement is with you; Legitimate interests where the agreement is with an organisation you represent; Legal obligation where applicable |
| To manage relationships and communicate about applications, grants, projects, policies, guidance, opportunities, enquiries, feedback, complaints or concerns | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Application, Assessment and Grant Management Data; Communications and Interaction Data | Legitimate interests; Performance of a contract where applicable; Legal obligation where applicable |
| To monitor, evaluate, audit and report on funded activities, expenditure, performance, outcomes and impact | Identity Data; Contact Data; Professional and Background Data; Financial Data; Transaction Data; Relationship and Engagement Data; Application, Assessment and Grant Management Data; Due Diligence and Compliance Data; Communications and Interaction Data | Performance of a contract where applicable; Legitimate interests, including monitoring funding, assessing impact and improving our activities; Legal obligation where applicable |
| To analyse and improve our funding, systems, services, relationships and strategy | Relationship and Engagement Data; Application, Assessment and Grant Management Data; Financial Data; Transaction Data; Usage Data; Technical Data; Administrative and Audit Data | Legitimate interests, including evaluating impact, improving our work and using charitable resources effectively. |
| To publish and share information about funding, funded activities, outcomes and impact, including through reports, websites, public grant databases and other communications | Identity Data where relevant; Professional and Background Data; Relationship and Engagement Data; Application, Assessment and Grant Management Data; Financial Data; Transaction Data; Image and Recording Data | Legitimate interests, including transparency, accountability and communicating our charitable work; Consent where required; Legal obligation where applicable |
| To maintain security, prevent misuse, manage access, troubleshoot systems and retain appropriate records for legal, regulatory, audit, accounting, research, archiving and statistical purposes | Identity Data; Contact Data; Portal and Account Data; Technical Data; Usage Data; Communications and Interaction Data; Application, Assessment and Grant Management Data; Due Diligence and Compliance Data; Administrative and Audit Data | Legitimate interests, including protecting our systems, maintaining appropriate records and demonstrating accountability. Legal obligation where applicable |
This table applies where you supply products or services to the Foundation, work for or represent a supplier or service provider, or otherwise engage with us in connection with the procurement or delivery of products and services.
Processing activities | Categories of personal data | Lawful basis |
| To assess, appoint and manage suppliers and service providers, including appropriate due diligence and compliance checks | Identity Data; Contact Data; Professional and Background Data; ID and Verification Data; Relationship and Engagement Data; Due Diligence and Compliance Data; Communications and Interaction Data | Legitimate interests, including selecting suitable suppliers, managing risk and protecting the Foundation; Legal obligation where applicable |
| To enter into, administer and manage contracts and the provision of products or services | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Communications and Interaction Data; Administrative and Audit Data | Performance of a contract where the contract is with you; Legitimate interests where you represent a supplier organisation; Legal obligation where applicable |
| To manage payments, fees, charges, expenses and related financial records | Identity Data; Contact Data; Financial Data; Transaction Data; Administrative and Audit Data | Performance of a contract where applicable; Legitimate interests; Legal obligation, including applicable accounting, tax and reporting requirements |
This table applies where you register for, attend, speak at or contribute to an event, webinar, workshop or other activity, or subscribe to receive newsletters, updates or invitations from the Foundation.
Processing activities | Categories of personal data | Lawful basis |
| To register and administer your participation, including communications, attendance, access and event arrangements | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Communications and Interaction Data | Performance of a contract where applicable; Legitimate interests, including administering events and activities |
| To manage accessibility, dietary, health, safety, emergency or other participation requirements | Identity Data; Contact Data; Special Category Data; Communications and Interaction Data | Consent or explicit consent where required; Performance of a contract; Legal obligation or vital interests where applicable. |
| To manage payments, expenses, travel, accommodation or reimbursements | Identity Data; Contact Data; Financial Data; Transaction Data; Administrative and Audit Data | Performance of a contract where applicable; Legal obligation including accounting and tax requirements |
| To collect feedback and evaluate or improve events, activities and communications | Identity Data; Contact Data; Relationship and Engagement Data; Usage Data; Communications and Interaction Data | Legitimate interests, including evaluating impact and improving our activities |
| To take and use photographs, audio or video recordings for reporting, communications or publicity | Identity Data; Professional and Background Data; Image and Recording Data | Legitimate interests where the use is proportionate and reasonably expected; Consent where required |
| To send newsletters, updates, invitations and other communications and manage your preferences | Identity Data; Contact Data; Relationship and Engagement Data; Marketing and Communications Data | Consent where required; Legitimate interests where permitted by law |
| To maintain security and retain appropriate event, communication, legal and audit records | Identity Data; Contact Data; Technical Data; Usage Data; Communications and Interaction Data; Administrative and Audit Data | Legitimate interests, including protecting people, premises, systems and information and maintaining appropriate records; Legal obligation where applicable |
This table applies where you participate in research, surveys, consultations, interviews, case studies or evaluations conducted or commissioned by the Foundation.
Processing activities | Categories of personal data | Lawful basis |
| To recruit participants and administer research, surveys, consultations, interviews, case studies or evaluations | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Communications and Interaction Data | Consent where required; Legitimate interests, including conducting research and evaluating or improving our work; Performance of a contract where applicable |
| To collect, analyse and report research findings, views, experiences and contributions | Identity Data where necessary; Relationship and Engagement Data; Usage Data; Communications and Interaction Data; Special Category Data where relevant and lawful; Image and Recording Data where applicable | Legitimate interest to collect, analyse, report research findings, views, experiences, contributions. Consent where required for publications |
| To manage participation payments, incentives, expenses or reimbursements | Identity Data; Contact Data; Financial Data; Transaction Data; Administrative and Audit Data | Performance of a contract where applicable; Legal obligation, including accounting and tax requirements |
| To publish or share findings, quotations, case studies, photographs or recordings | Identity Data where agreed; Professional and Background Data; Communications and Interaction Data; Image and Recording Data | Consent where required; Legitimate interests where use of information is proportionate and reasonably expected |
| To retain appropriate research, consent, legal, archiving and audit records | Identity Data where necessary; Relationship and Engagement Data; Communications and Interaction Data; Special Category Data where relevant and lawful; Administrative and Audit Data | Legitimate interests, including research integrity, archiving and demonstrating accountability; Legal obligation where applicable. |
This table applies where you visit our Heritage Centre, including as part of a university or membership group, in order to access our historic collections, libraries, photographs or historical assets or to receive training.
Processing activities | Categories of personal data | Lawful basis |
| To register and administer visits, enquiries, appointments, research access, events, training and use of collections or resources | Identity Data; Contact Data; Professional and Background Data; Relationship and Engagement Data; Usage Data; Communications and Interaction Data | Performance of a contract where applicable; Legitimate interests, including providing and managing Heritage Centre services |
| To manage access, security, health and safety, emergencies and any accessibility or participation requirements | Identity Data; Contact Data; Usage Data; Special Category Data; Image and Recording Data where security systems are used | Legitimate interests, including protecting visitors, premises and collections; Legal obligation or vital interests where applicable; Consent or explicit consent where required. |
| To manage and preserve collections, including recording the use, reproduction or contribution of collection material | Identity Data; Contact Data; Professional and Background Data; Usage Data; Communications and Interaction Data; Administrative and Audit Data | Legitimate interests, including managing, protecting and understanding the use of our collections; Performance of a contract where applicable |
| To collect feedback, evaluate and improve Heritage Centre services and activities | Identity Data; Contact Data; Relationship and Engagement Data; Usage Data; Communications and Interaction Data | Legitimate interests, including evaluating impact and improving our services |
| To retain appropriate visitor, collection, security, legal, research, archiving and audit records | Identity Data; Contact Data; Usage Data; Communications and Interaction Data; Administrative and Audit Data | Legitimate interests, including preserving records, protecting collections and demonstrating accountability; Legal obligation where applicable |
Cookies and similar technologies
The Foundation gathers information and statistics about visitors to our websites, portals and other online services. Analysis of this information helps us understand how our digital services are used and assists us in improving their accessibility, content, performance and effectiveness. Where required by law, we will obtain your consent before using non-essential cookies or similar technologies. Please refer to our Cookies Policy for more information about the cookies and similar technologies we use.
Providing personal data
Where we need to collect personal data by law, under the terms of a contract, or to consider entering into a contract with you or an organisation you represent, and you do not provide that information when requested, we may not be able to consider an application, provide funding or services, administer our relationship, or perform the relevant contract. In this case, we may need to decline or withdraw an application, suspend access to a service or cancel the relevant service or agreement, but we will notify you where appropriate.
Marketing communications
The Foundation may send you marketing communications, newsletters, updates or event invitations where you have consented or where otherwise permitted by law. You have the right to object to the processing of your personal data for direct marketing purposes. You can unsubscribe from receiving marketing communications from us by using the unsubscribe method contained in our communications or by contacting us. Please see the Contact us section below.
Where you opt out of receiving marketing communications, this will not affect our use of personal data provided to us in connection with an application, grant, contract, event, service, account or other operational interaction with the Foundation. We may continue to send you non-marketing communications where necessary to administer our relationship with you or an organisation you represent.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for contract
fulfilment, grant administration, legal and regulatory compliance, our legitimate interests or the
other purposes described in this privacy notice.
Such circumstances may include:
Internally: Your personal data may be accessed by our employees, contractors and authorised representatives where they have a legitimate business need to use it for the purposes described in this privacy notice.
With our affiliates: We may share personal data within the Lloyd’s Register group where necessary to operate and manage our activities, provide services or support your request.
Our service partners: We may share personal data with vendors and other third parties that perform services on our behalf, including providers supporting our websites, Funding Portal, customer relationship management and grant management systems, IT services, event administration, communications, cloud storage, research, evaluation, due diligence and data analysis.
Reviewers, experts and programme partners: We may share relevant information with peer reviewers, panel members, experts, co-funders, delivery partners, evaluators or other parties involved in assessing, administering, monitoring or evaluating applications and funded activities.
Marketing partners: We may share personal data with business or marketing partners where necessary to provide information to you. We will obtain your consent before sharing your contact details with third parties for their own marketing purposes where required by law.
Legal advisers: We may share personal data with legal advisers where necessary to obtain advice, enforce applicable terms, establish or defend legal claims, or protect the Foundation or the rights of other people.
Professional advisers: We may share personal data with auditors, bankers, insurers and other professional advisers that provide consultancy, banking, insurance, accounting or related services.
Payment intermediaries: We may share relevant information with banks, payment processors and other organisations that facilitate payments to and from us.
Analytics providers: We may share information with providers that support the operation, security and analysis of our websites, portals and other online services, subject to applicable consent requirements.
Public reporting: We may publish or share relevant information about grant awards and funded activities through our websites, reports, publications, public grant databases and transparency initiatives. Personal data will only be included where appropriate and lawful.
Legal and regulatory bodies: We may disclose personal data to regulators, law enforcement agencies, public authorities or other organisations where required by law or where necessary to protect individuals, charitable funds or the Foundation.
Business transactions: We may share personal data in connection with a reorganisation, merger, transfer or acquisition involving all or part of the Foundation’s activities. Personal data will continue to be protected and processed in accordance with applicable data protection law.
International transfers for UK/EU
We may transfer or process your personal data outside the United Kingdom or European Economic Area, including where our service providers, systems, support services, reviewers or partners are located in other countries. Data protection laws in these countries may differ from those in the United Kingdom or European Economic Area.
Where personal data is transferred internationally, we will ensure that an appropriate transfer mechanism or safeguard is in place. This may include transferring information to a country recognised as providing an adequate level of protection or using contractual safeguards approved for use in the United Kingdom or European Union, such as the UK International Data Transfer Agreement, the UK Addendum or the European Commission’s Standard Contractual Clauses.
Where required, we will assess the risks associated with the transfer and implement additional safeguards. To find out more about the safeguards used for international transfers, please contact us at dataprotection@lr.org.
Data security
We have put in place appropriate technical and organisational security measures designed to prevent your personal data from being accidentally lost, used, accessed, altered or disclosed without authorisation. We limit access to personal data to employees, agents, contractors and other third parties who have a legitimate business need to access it. Third parties processing personal data on our behalf are required to follow our instructions, protect the information appropriately and comply with applicable confidentiality and data protection obligations.
The transmission of information over the internet is not completely secure. Although we take appropriate measures to protect personal data, no internet transmission or information system can be guaranteed to be completely secure.
Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which it was collected, including satisfying applicable legal, regulatory, tax, accounting, audit, reporting, research or archiving requirements. We may retain personal data for longer where there is an ongoing complaint, investigation or legal claim, or where we reasonably believe that legal proceedings may arise from our relationship with you or an organisation you represent.
Retention periods may differ depending on the type of information and the purpose for which it is processed. This includes information relating to applications, grants, agreements, payments, due diligence, monitoring, peer review, portal accounts, communications, marketing preferences, complaints and system audit records.
When determining an appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which the information is processed, whether those purposes can be achieved through other means and applicable legal, regulatory, tax, accounting and reporting requirements. When personal data is no longer required, we will securely delete or anonymise it in accordance with our applicable retention policies and procedures.
Further information about our retention periods for specific categories of personal data is available on request by contacting us at dataprotection@lr.org.
Data Subject Rights
Under certain circumstances, you have rights under applicable data protection laws. These rights are
not absolute and may vary depending on your location and the circumstances in which we process
your personal data. You may have the right to:
Request access to your personal data: This is commonly known as a subject access request and enables you to request a copy of the personal data we hold about you and information about how it is processed.
Request correction of your personal data: This enables you to request that incomplete or inaccurate personal data we hold about you is corrected.
Request erasure of your personal data: This enables you to ask us to delete personal data where there is no lawful reason for us to continue processing it. We may not always be able to comply with a request for erasure where we need to retain the information for legal, regulatory, contractual, archiving or other lawful purposes. Where applicable, we will explain this to you.
Object to processing of your personal data: You may object where we process your personal data on the basis of our legitimate interests or those of a third party. We may be entitled to continue processing where we can demonstrate compelling legitimate grounds or where the information is needed to establish, exercise or defend legal claims. You have an absolute right to object to processing for direct marketing purposes. Please also see Marketing communications.
Request restriction of processing your personal data: This enables you to ask us to suspend or limit processing where you dispute the information’s accuracy, believe the processing is unlawful but do not want the information erased, need us to retain the information to establish, exercise or defend legal claims, or have objected to our processing while we consider whether we have overriding legitimate grounds to continue.
Request transfer of your personal data, known as data portability: In certain circumstances, you may ask us to provide personal data that you supplied to us in a structured, commonly used and machine-readable format, or to transfer it to another organisation where technically feasible.
Withdraw consent: Where we rely on consent to process your personal data, you may withdraw that consent at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn. Depending on the processing activity, we may not be able to provide a particular service or activity after consent is withdrawn. We will explain any relevant consequences at the time.
Automated decision-making: We may use automated workflows and rules to administer applications, grants, accounts and communications, including to validate information, calculate values, route records or generate notifications. We do not make decisions that have legal or similarly significant effects on individuals solely by automated means. Material funding and grant management decisions involve human review.
Carrying out your data subject rights
You will not normally have to pay a fee to access your personal data or exercise any of your other rights. However, we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, taking into account whether the request is repetitive.
We may request specific information from you to confirm your identity and verify your entitlement to exercise the relevant right. This is a security measure intended to ensure that personal data is not disclosed to anyone who is not entitled to receive it. We may also contact you for further information where this is necessary to clarify or respond to your request.
We aim to respond to legitimate requests within one month. It may take longer where a request is particularly complex or you have made several requests. Where this applies, we will notify you and keep you informed.
If you wish to exercise any of the rights set out above, please contact us at dataprotection@lr.org.
Keeping personal information accurate and current
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us or an organisation you represent. Please contact us if you wish to update your personal data. Where available, you may also update certain information through your Funding Portal or other online account.
Concerns and complaints
We welcome any comments, inquiries or concerns regarding your personal data and our privacy practices. You may submit them to the details under the Contact us section below.
If you consider that we have handled your personal data in a way that infringes data protection law, you have the right to complain directly to us by contacting us using the details in the Contact us section below. We will acknowledge your complaints promptly and take appropriate steps to investigate and respond. We will keep you informed of the progress and outcome of your complaint.
If you are not satisfied with our response, or wish to raise your concerns directly to a supervisory authority, you also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data protection supervisory authority. If you live or work outside the United Kingdom, or your complaint concerns processing in another country, you may also have the right to complain to the relevant local data protection supervisory authority.
Changes to our privacy notice
We may update this privacy notice from time to time in response to legal, regulatory, technical or operational developments, including changes to our systems, services and processing activities. We will take appropriate steps to make you aware of significant changes and will obtain consent where this is required by applicable data protection law.
Contact us
The Foundation has designated a Data Protection Officer. If you would like more information about how we manage your personal data, wish to exercise your data protection rights, or wish to raise a concern or complaint, please contact us at:
- Email address: dataprotection@lr.org
- Postal address: Data Protection Officer, c/o Lloyd’s Register, 71 Fenchurch Street, London, EC3M 4BS, UK
- Phone: +44 20 7423 1724
Version control
This version was last updated in September 2026.