GDPR Information
Information about NXT Workforce processes where the General Data Protection Regulation applies.
Data protection
Last updated: 26 September 2026
The GDPR may apply to certain NXT Workforce activities depending on the people, clients, locations and processing involved. This page explains how we approach GDPR-related responsibilities when the regulation applies.
Controller and processor roles
For website enquiries and NXT Workforce's own business administration, NXT Workforce may act as a controller. When processing personal data only on a client's documented instructions as part of a contracted service, NXT Workforce may act as a processor. The exact role depends on the activity.
Lawful processing
Where NXT Workforce acts as a controller, we identify an appropriate lawful basis for the processing. Where we act as a processor, the client is responsible for determining the lawful basis and providing lawful documented instructions.
Data processing agreements
A data processing agreement may be used where required. It can address processing instructions, confidentiality, security, sub-processors, assistance with data-subject requests, incident notification, deletion or return of data and international transfers.
Data minimisation and purpose limitation
Personal data should be limited to what is relevant for the defined business purpose. We do not intend to use client-controlled personal data for unrelated purposes.
Data-subject rights
Where applicable, individuals may have rights including access, correction, erasure, restriction, objection and portability. Requests should be verified and handled according to the role NXT Workforce has in the processing. If we act as a processor, requests relating to client-controlled data may need to be referred to the client.
International transfers
If GDPR-covered personal data is transferred to a country that does not have an applicable adequacy decision, an appropriate safeguard may be required. The correct mechanism depends on the processing arrangement and should be documented before transfer where required.
Sub-processors
Service delivery may use hosting, communications, CRM, form-processing, cloud or other approved service providers. Where GDPR requires sub-processor controls, those requirements should be addressed in the client agreement or data processing terms.
Retention and deletion
Retention should be based on the purpose, client instructions, contractual needs and legal obligations. Processor-held client data should be returned or deleted at the end of the service where required by the agreement and subject to lawful retention obligations.
Contact
For GDPR-related questions, email hello@nxt-workforce.com.
This page provides general operational information. Client-specific data protection requirements should be documented in the applicable contract or data processing agreement.
