LEX NEGATA Logo

GDPR & Data Protection Statement

Our framework for processing enquiries and managing sensitive files under UK data protection laws.

1. Our Commitment

LEX NEGATA LTD is committed to protecting the privacy and security of all personal data we process. As a consultancy regularly auditing public sector social care files, we maintain the highest standards of data protection, aligning fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

2. Audited Files & Anonymisation

When performing Care Act or Judicial Review audits, LEX NEGATA LTD acts as a **Data Processor** or joint controller under strict Data Processing Agreements (DPAs) with local authorities and NHS bodies. To protect vulnerable adults:

  • We advise client authorities to fully anonymise all care files (removing names, exact addresses, NHS numbers) before sharing them with our audit portals.
  • Where direct system access is required, our audits occur via secure, encrypted VPN channels inside the client's own IT infrastructure. No client files are downloaded to local devices.

3. Data Security Measures

We implement robust technical and organisational controls, including:

  • Multifactor Authentication (MFA) on all communications and scheduling tools.
  • End-to-end encryption for files in transit and at rest.
  • Regular data protection impact assessments (DPIAs) for new consulting tools.

4. Contact & Inquiries

If you have any questions regarding how we process your enquiry details or handle data during audits, please contact our Data Protection Officer at info@lexnegata.com.

Last Updated: June 2026