Privacy Policy and Intellectual Property Policy 

Introduction

On 25th May 2018, new data protection legislation came into force: the General Data Protection Regulation (“GDPR”). GDPR replaced previous legislation and created significant obligations which WCoMC and its Associated Organisations, including the Centre for Management Consulting Excellence (“CMCE”), a separate entity that is an integral part of WCoMC, must fulfil. It also gave numerous rights to Members, Registered Event Account Holders and their Associated Contacts, CMCE newsletter subscribers and event attendees, and external organisations that have directly or indirectly provided images to The Company (“You”). Many of the rules are the same as under previous legislation, but several new elements were introduced. GDPR was an EU Regulation directly applicable in EU Member States without the need for local legislation.

The UK implemented GDPR through the Data Protection Act 2018 (DPA 2018) and decided that the substance of GDPR should continue to apply after the UK left the EU. To all intents and purposes, UK GDPR achieves this objective. The provisions of the EU GDPR were incorporated directly into UK law at the end of the transition period. The UK GDPR sits alongside the DPA 2018 with technical amendments so that it works in a UK-only context. The legislation was updated by the Data (Use and Access) Act 2025 and this policy now reflects the current prevailing legislation.

If You have any queries do please contact us at gdpr@wcomc.org.

This Privacy Policy deals with the following points:

  • What is Lawful Processing?
  • What data does The Company acquire and keep about Members, Registered Event Account Holders, CMCE newsletter subscribers and other associated contacts?

  • Where does The Company obtain the data from and how is the data stored?
  • How does The Company process data that includes images?
  • Does The Company transfer such data elsewhere?
  • How long does The Company retain such data?
  • Your rights

GDPR changes the relationship between The Company and You in relation to the information (data) which The Company collects from You and then processes and stores. Some data is necessarily provided to or accessed by a third party, such as an event venue, caterer or The Company bookkeeper. Much of the requirements of GDPR are mandatory, but where there are options we will identify and explain the option The Company is using. Many of the terms are technical, but You need to be aware of the terms in order to understand what GDPR stipulates. The Company’s first task is to be a lawful processor of Your data.

Lawful Processing

Membership of The Company is a form of contract where Members pay a fine and quarterage in return for which Members receive benefits and services provided by The Company; being a Registered Event Account Holder is a similar form of contract. The Company asserts that it is a lawful processor by virtue of these relationships and therefore does not need to obtain specific consent to process data required for membership administration, event administration and related services. Where The Company processes personal data for CMCE newsletter or other consent-based communications, it does so on the basis of the consent given by the individual concerned. The Company also considers that it is exempt from any obligation to appoint a Senior Responsible Officer under Data (Use and Access) Act 2025, but it does accept its obligation to carry out processing in ways which are lawful, fair and transparent.

Types of Data Collected and Stored

Members

The Company is committed to recording accurate personal data which primarily consists of the information on the Connection and Membership Application Forms and the banking information on the Direct Debit Mandate. Date of birth is recorded because subscription rates may vary with the Member’s age. The Company does not collect sensitive personal data (special category data) such as genetic, biometric or health data nor information on race, ethnicity, religion, political persuasion, or sexual orientation. 

The Company may use the data You have provided to enhance your experience of Company Membership and events by recording your personal preferences, interests, dietary and access requirements and geographical location. Similarly, The Company may use the information you provide summarising your professional skills to assist in the resourcing of ProBono support to Not-for-Profit organisations as part of our philanthropic activities.

The Company may verify the information supplied in the Membership Application Form but does not seek additional information when considering an application. If information is published (i.e. in the public domain) about a Member, e.g. personal, professional or civic honour, award, achievement, etc., The Company is likely to add such information to Your Membership record.

The Company’s database (civiCRM) allows Members to access and update their personal and professional data and to book events online for themselves and their guests. Members are able to correct errors or request rectification of errors. Access is password protected. In the event of a data breach, The Company undertakes to inform You, and any relevant authority where required, within the timescales required by applicable data protection law. Any paper records are also held securely.

Non-Members

The Company’s database (civiCRM) similarly allows non-Members to book events online for themselves (by creating a Registered Event Account) and their guests, including events organised by or on behalf of CMCE through the WCoMC website. Limited information is required and stored, typically name, primary email contact, personal seating preferences, dietary and access requirements. Where a non-Member books a CMCE event and expressly agrees on the civiCRM booking form to receive communications from The Company, that person may also be added to the CMCE mailing list. Registered Event Account holders are able to correct specific errors in their data or request rectification of others if such data is read only. Access is password protected. In the event of a data breach, The Company undertakes to inform You, and any relevant authority where required, within the timescales required by applicable data protection law.

CMCE also maintains a database of subscribers to the CMCE newsletter, typically including names, email addresses, subscription preferences and records of consent or unsubscribe requests. Subscribers are added only where they have requested the newsletter, requested a CMCE report and agreed to receive CMCE communications, or booked to attend a CMCE event and agreed to receive communications from The Company on the civiCRM booking form. Subscribers may unsubscribe at any time.

Images

The Company receives and may publish information from Members and Other Parties that may include personal data and images. Such information is received in Good Faith and The Company cannot be held responsible for ensuring its provenance. Any Privacy or Intellectual Property issues arising from this will be handled through our procedures described below.

In addition to images received from Members and Other Parties, the Company and its appointed photographers may take photographs and video at Company events for use in the Company's newsletter, website and social media channels. Where this processing relies on the Company's legitimate interests rather than a Membership or event contract, attendees are given notice before or at the event and may object to being photographed, or ask for a published image of themselves to be removed, at any time, in accordance with Your Rights below. Identifiable images of under-18s are published only in accordance with the Company's Social Media Policy, which requires both consent and Governance Committee approval before publication.

Transfer and Sharing of Data

The Clerk (which includes any assistant), who is an employee of the Company, is the principal processor of Your data. Book-keeping may be undertaken by an independent sub-contractor on whom required legal obligations will be imposed in relation to processing Member data. The Company’s IT hosting and support providers are our data processors operating under defined data processing agreements.

The Company’s Officers and Committees may also wish to look at Member data from time to time, for example in relation to the provision of our philanthropic ProBono activities.

When You attend functions or events organised by the Company, including CMCE events booked through the WCoMC website, the venue will normally, for security and practical reasons, require a list of attendees’ names, which may include Members, Registered Event Account Holders, guests and non-Member attendees. The Company also provides limited data to our landlord when Members attend meetings and access the building.

For the time being The Company intends to continue its current practice of providing Members’ names and contact details to the publishers of The City of London Directory and Livery Companies Annual Guide and the White Book. Liverymen’s details will also continue to be provided to the City of London for inclusion in the Common Hall Register.

The Data (Use and Access) Act 2025 introduced a revised 'data protection test' for international transfers, which came into force in February 2026.  In accordance with this test the Company does not knowingly transfer data about Members internationally and requires all its suppliers not to make such transfers unless an adequacy agreement is in place.

Retention of Data

The Company intends to hold Your data indefinitely where this is necessary for membership, event administration, archival purposes or institutional memory. Personal data held solely for CMCE newsletter or other consent-based communications will be retained only while You remain subscribed or until You withdraw consent, unsubscribe or request erasure, subject to any legal or administrative need to retain a limited record of that request.

In the case of a Member’s resignation, all data will be held unless requested otherwise, when we reserve the right to keep your name, membership dates and the date of resignation.

In the case of a Member’s exclusion, all data will be held for eight years, in order that appropriate institutional memory exists. At the end of this period your name, membership dates and date of exclusion will be retained.

In the case of death, we will keep your data indefinitely for archival purposes only. The Company will consider requests for erasure received from immediate family and/or executors, in which case your name, membership dates and date of death will be retained.

Your Rights

  • To Complain:  Ideally The Company would wish to try and deal with complaints itself before recourse to any external authority and asks You to submit complaints to us via email at gdpr@wcomc.org but we are open to You submitting a complaint at any time to the Office of the Information Commissioner.
  • To have correct data recorded by The Company:  The Company will be happy to correct errors; Members and Registered Account Holders are reminded that You are able to access, amend and correct any errors Yourself.
  • To require The Company to erase data or images, or to withdraw consent to receive CMCE or other Company communications:  The Company will fully respect the appropriate legislation but reminds You that the low-level information gathered is perceived to be the minimum needed to provide You with the benefits of Membership and Your attendance at events. You may unsubscribe from the CMCE newsletter or withdraw consent to CMCE communications at any time. The Company also notes that in relation to any information passed to a third party, e.g. names and contact details given to The City of London Directory and Livery Companies Annual Guide, this cannot, once given, be retrieved or erased. Any changes may only be made when the publications are reprinted. Similarly, should any data, information or image prove to be the property of a Third Party, then best endeavours will be made to erase it, but historical instances may be impossible to retrieve or erase.

  • To object to processing based on legitimate interests: Where the Company processes Your image or other data on the basis of its legitimate interests (for example, event photography), You have the right to object. The Company will stop such processing unless it can demonstrate compelling legitimate grounds which override Your interests, rights and freedoms.

Company Websites

This policy applies when You use any of The Company's websites, including when You book CMCE events through the WCoMC website, request CMCE reports, subscribe to the CMCE newsletter or interact with the Company's official social media channels. It should be read alongside the Company's Social Media Policy, which sets out further detail on photography, consent and publication at events.

Review and Updates

This policy will be reviewed in September 2027 and annually thereafter, unless changes in the law require an interim review. Whenever this policy is updated or amended, You will be advised.

Dated: Originally May 2018 and reviewed and revised in 2019 and 2020 and 2021 and 2026.

Version 2.6.1 - 25th September 2026

© 2012-2026   The Worshipful Company of Management Consultants (WCoMC)
Plaisterers' Hall, One London Wall, Barbican, London   EC2Y 5JU
Tel:  07761 647811             GDPR:  Our Privacy and IPR Policy
WCoMC is a Chartered Charitable Organisation (Privy Council Reference C877) and a Company Incorporated by Royal Charter (Company No. RC000819)