Privacy policy

We respect your right to privacy.

This privacy policy sets out and details the information that we may collect from you during your use of the DWP Authenticate (The Service) and how we may use this information.

When you register on the Service, the information you give us will be used so that:

  • you can access a DWP Service
  • you can assist other users to access a DWP service
  • DWP can administer your account, e.g. changes to your access rights to a DWP service

The privacy policy should be read alongside the Acceptable Use Policy and the Cookie Policy as well as the DWP personal information charter.

About us

In this privacy policy, the Service is owned by the Department for Work and Pensions (DWP).

DWP is the Data Controller of any personal data processed by the Service and described in this privacy policy. DWP is also the Data Processor, alongside Amazon Web Services.

Use of the Service

The Service is available to DWP Staff, Partners and authorised employees of contracted service organisations, who are required to access DWP services as part of their contract, 24 hours a day, 7 days a week.

This privacy policy applies only to individual use of the Service.

In your use of the Service, we will:

  • keep a record of when you log into and log out of the Service

This is, for example, for dealing with technical queries and to provide, maintain, protect and improve the quality of the Service.

Collection and use of your information

When you access the Service via any means we may collect, store and use certain of your personal information in line with this policy, (specifically your email address and staff number if available)

We may also ask you for additional information when you report a problem with the Service, (e.g. your name or telephone number to ring you)

To register on the Service, we will ask for your email address and a telephone number.

If you contact us with a query or support request, we may also keep a record of that correspondence. This is so we can link it to any similar correspondence from other users to assist us in identifying service improvements.

We may also collect data relating to your visits to the Service that cannot identify you but record your use of our Service including, for example, details of how long you have used the Service and which pages are used most.

We may also collect your computer’s IP address in order to help us improve the delivery, and protect the integrity, of the Service. This will not identify you as an individual to us.

Storage of information

All information is stored on our secure servers. When you register, we will ask you to choose a password which enables you to access your account. You are responsible for keeping this password confidential. We ask you not to share this password with anyone.

In addition, we or our data processors acting on our behalf may also store or process information that we collect about you in countries inside the European Economic Area.

The hosting provider for the website and the data associated with the functional delivery of the service is processed within the UK and Ireland. Some technical operational and support data resides within the EEA for monitoring and administration purposes.

We have put in place technical and organisational security measures to prevent the loss or unauthorised access of your personal information. However, whilst we have used our best efforts to ensure the security of your data, please be aware that we cannot guarantee the security of information transmitted over the Internet.

Legal basis for processing your Information

Our legal basis for collecting and using the personal information described within this privacy policy is contained within GDPR Article 6(1)(e). Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller DWP will collect and use your information. The data processors are not permitted to use the data for any other purpose than enabling people to Authenticate themselves and login to DWP services that Authenticate supports.

For more information see the DWP personal information charter.

Disclosure of your information

We will only disclose your information where we are permitted or required to do so by law, or where necessary to deliver the service. We will not sell or share your data with third parties for marketing purposes.

Data Retention

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with the Service you have requested)

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

Your Authenticate account can be closed at any time by DWP service administrators, either at the request of DWP, or at the request of your employer. A procedure is in place to do this.

If you do not access a DWP service through Authenticate for a specific period of time your account will be deleted. This period is set by the DWP service you access (e.g. 30 days from the last successful authentication) and you will be contacted beforehand by the service administrators to ensure the account is no longer needed.

Closing your account deletes all the personal information held in the Service.

If you have contacted us with a service query, we will delete the records of that contact twelve months after that communication exchange is over.

Your rights

  • The right of access and right to rectification:

You can see and edit your personal details via your profile page whenever you wish.

  • Right to erasure

You can erase your Personal Data at any time by closing your account. A procedure is in place to do this through your employer.

The Service connects users to other DWP services and websites. If you follow a link within any of these websites, please note that these websites have their own privacy policies. Please check these policies before you submit any personal information to these websites, because your rights may be different.

Children

We strongly believe in protecting the privacy of children. In line with this belief, we do not knowingly collect or maintain personal information from persons under 13 years of age, and no part of the Service is directed to persons under 13 years of age. If you are under 13 years of age, then please do not use or access the Service at any time or in any manner. We will take appropriate steps to delete any personal information of persons less than 13 years of age.

Updating this privacy policy

We may update or amend this privacy policy from time to time, to comply with law or to meet our changing business requirements. When we update our privacy policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. Any updates or amendments will be posted on the Service. By continuing to access the Service your access and use will be subject to these updates and amendments.

The privacy policy terms were last updated on (date)

Contacting DWP

If you have any questions, comments or complaints about this privacy policy, please contact us using the information provided in the DWP Personal Information Charter.