Skip to content
Human transcription and translation services for Ireland +353 1 960 9195   ·   anna@tptranscription.co.uk
TP Transcription Ireland Ireland

Data Protection and GDPR \u2014 Ireland and EU

Company policy: View the current companywide policy on tptranscription.co.uk. The linked page is the controlling company policy if a later revision differs from this Irish-site copy.

Irish/EU version — last reviewed 23 September 2026.

This policy explains how TP Transcription Limited manages personal data when serving customers and data subjects in Ireland and the European Economic Area.

1. Organisation and scope

TP Transcription Limited (“TP Transcription”, “we”, “us”) is registered in England and Wales under company number 04946815. Its registered office is Ty Brith, Llandegla Road, Llanarmon-yn-Ial, Mold CH7 4QX. The Irish contact office is Bracken Road No 51, Carlisle Offices, Sandyford, Dublin 18, D18 CV48, Ireland. Contact anna@tptranscription.co.uk or telephone +353 1 960 9195.

This policy applies to the Irish website, enquiries, quotations, client administration and personal data processed while providing transcription, translation, subtitling, copy-typing and related services.

2. Roles and responsibilities

For recordings, videos, documents and instructions supplied by a client, the client will normally be the controller and TP Transcription the processor. We process that material on documented instructions and under the contract or data-processing agreement. We are a controller for our own contact, account, supplier, personnel, website-security and statutory business records.

The directors are responsible for data-protection governance. All staff, contractors and associate transcribers with access to personal data are subject to confidentiality and security requirements.

3. Principles

Personal data must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; accurate where required; kept no longer than needed; protected against unauthorised or unlawful use, loss or damage; and handled in a way that demonstrates accountability.

4. Information processed

Depending on the service, this may include contact and organisation details, correspondence, quotation and billing data, upload metadata, IP and security logs, recordings, transcripts, translations, photographs, video, research material and special-category or criminal-offence data contained in client material. We do not require clients to provide more data than the assignment needs.

5. Purposes and lawful bases

  • Answering enquiries and taking steps towards a contract.
  • Providing and administering contracted services.
  • Maintaining accounts, tax records and evidence of instructions to comply with legal obligations and legitimate business interests.
  • Protecting systems, preventing misuse and managing incidents in our legitimate interests and to meet legal duties.
  • Sending marketing only where consent or another lawful basis permits it, with an unsubscribe route.

Where a client is controller, the client is responsible for the Article 6 lawful basis and, where applicable, an Article 9 or Article 10 condition for the underlying content.

6. Processor commitments

When acting as processor we will process data only on documented instructions unless law requires otherwise; ensure authorised people are bound by confidentiality; use appropriate technical and organisational measures; control subprocessors; assist reasonably with data-subject requests, impact assessments and breach duties; and return or delete data at the end of the service subject to legal retention requirements.

7. Security

Controls include secure transfer, access restriction, confidentiality agreements, endpoint and account protection, encrypted transmission, documented incident handling, supplier assessment, backups and secure deletion. Sensitive client recordings should not be sent by ordinary email. Our information-security management system is aligned with the company’s ISO 27001 controls.

8. AI and automated processing

Client audio, video, text and metadata must not be placed into AI tools. Transcription is completed and checked by people. We do not make decisions producing legal or similarly significant effects about website users by solely automated means. See the full AI policy.

9. Recipients and subprocessors

Data may be available, only as necessary, to authorised directors, staff, associate transcribers or translators and vetted providers of hosting, secure transfer, email, workflow, IT support, accounting or professional advice. It may also be disclosed where required by law. Appropriate written terms and access controls are used for processors.

10. EEA–UK and other international transfers

The company is established in the United Kingdom and Irish/EEA client data may be transferred to or accessed from the UK. The European Commission renewed the UK’s GDPR adequacy decision on 19 December 2025, so covered transfers can currently proceed on that basis. We monitor the position. If adequacy does not cover a transfer or ceases to apply, we will use an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses, together with any required assessment and supplementary measures. A transfer outside the EEA or UK for a particular language or supplier will be disclosed and authorised where required.

11. Retention and deletion

Project material is kept only for the period agreed with the client or required for delivery, quality control, dispute management and legal obligations, then securely deleted or returned. Different periods apply to invoices, contracts, security logs and statutory company records. Clients can request a project-specific retention schedule before work begins.

12. Individual rights

Subject to the GDPR and applicable exemptions, individuals may request access, correction, erasure, restriction, portability, or object to processing. They may withdraw consent where consent is the basis. When we act only as processor, we will pass the request to the relevant client/controller and assist it as required. We may verify identity before releasing information.

13. Personal-data breaches

Suspected loss, unauthorised access, disclosure or misuse must be reported immediately to a director. We record, investigate and contain incidents. When acting as processor we notify the controller without undue delay. Where we are controller, we assess whether notification to a supervisory authority and affected individuals is legally required.

14. Complaints and contact

Questions and rights requests can be sent to anna@tptranscription.co.uk. Please contact us first so we can investigate. You may also complain to the Irish Data Protection Commission at dataprotection.ie, the UK Information Commissioner’s Office, or another competent EEA supervisory authority.

15. Review

This policy is reviewed at least annually and when services, suppliers or relevant law change. Material revisions will be dated on this page.

Talk to a real person

Need a transcription quote?

Tell us about your recordings and we will recommend the right service and turnaround.