Controller
Who is responsible for the data described here.
Lyre Group is a partnership registered in the UK and is the data controller for the personal data described in this notice. VAT registration number GB 497 2036 68.
Enquiries about this notice, and requests to exercise the rights set out below, should be sent to enquiries@lyre.group, marked "Data Protection". A postal address is available on request.
Scope
Two distinct groups, governed differently.
Lyre processes personal data about two groups, and the sections that follow are marked accordingly.
- Clients and enquirers. Individuals who make contact, who instruct Lyre, or who work for an organisation that does.
- Subjects of an engagement. Individuals whose information is processed in the course of instructed work, including due diligence, vetting, corporate intelligence, threat analysis and protective monitoring.
If this notice has been provided because you are the subject of an engagement, the relevant section is "Data processed during an engagement".
Clients and enquirers
Data held about those who instruct Lyre.
What is held
- Name, job title, employer and contact details
- The content of enquiries and subsequent correspondence
- Engagement records, instructions, scoping documents and deliverables
- Billing and payment records
- Technical data arising from use of this website, as described below
Purpose and lawful basis
- Responding to an enquiry
- Legitimate interests: responding to a request made to Lyre.
- Delivering an engagement
- Contract, or legitimate interests where the contract is with an employer rather than the individual.
- Invoicing, accounting and tax records
- Legal obligation.
- Retaining a record of advice given and work performed
- Legitimate interests: establishing and defending Lyre's position in the event of a dispute.
- Client due diligence checks
- Legitimate interests, and legal obligation where applicable.
Retention
Data protection law sets no fixed retention periods. It requires that personal data is kept no longer than is necessary for the purpose it was obtained for. The periods below are set against that standard and against the other obligations that apply.
- Engagement records
- Six years from the conclusion of the engagement, reflecting the limitation period for contractual claims and professional indemnity requirements.
- Financial and billing records
- Six years, in line with HMRC record-keeping requirements.
- Enquiries that do not proceed
- Twelve months from the last contact.
Data processed during an engagement
Where the subject is not the client.
Lyre is instructed to research, assess and monitor risk. This involves processing personal data about individuals who are not Lyre's clients. This section explains that processing.
Sources
Information is generally not collected from the individual concerned. Sources include:
- Publicly available material, including websites, social media, press and broadcast media
- Public registers and official records, including company registries, court records, insolvency registers, land registers, and sanctions and enforcement lists
- Information supplied by the instructing client
- Licensed commercial databases and, where instructed, third-party correspondents
Categories
Identity and contact details; employment and directorship history; corporate and financial interests; litigation and regulatory history; media coverage; publicly expressed views and affiliations; and information about connected persons and entities where relevant to the instruction.
Depending on the instruction, this may include special category data, such as information revealing political opinions, religious beliefs, trade union membership or health, and information relating to alleged or actual criminal offences.
Lawful basis
For personal data generally, Lyre relies on legitimate interests: the client's interest in making an informed and defensible decision about a material risk, and Lyre's interest in delivering the service it has been instructed to provide. This has been assessed against the interests and rights of the individuals concerned in a documented Legitimate Interests Assessment, available on request.
For special category data, Lyre relies on the substantial public interest conditions in Part 2 of Schedule 1 to the Data Protection Act 2018: paragraph 10, preventing or detecting unlawful acts, and paragraph 11, protecting the public against dishonesty, malpractice or other seriously improper conduct. Lyre maintains the Appropriate Policy Document those conditions require.
For criminal offence data, Lyre relies on the same conditions, as permitted by section 10(5) of that Act.
Where an engagement concerns actual or prospective legal proceedings, Lyre may also rely on the establishment, exercise or defence of legal claims.
Automated decision-making
Lyre does not make decisions about individuals by automated means and does not profile individuals for the purpose of producing legal effects. Assessments are prepared by human analysts. Decisions that follow are taken by the client.
Retention
Research material is retained for the duration of the engagement and for six years afterwards, matching the engagement record it supports, so that findings remain auditable and defensible. Material that proves irrelevant to the instruction is discarded during the engagement rather than retained.
Notification
Data protection law ordinarily requires that an individual is told their data is being processed. In some engagements this is not possible, because notification would prejudice the purpose of the work, for example where the instruction concerns the prevention or detection of unlawful acts, or where legal proceedings are in prospect. In those cases Lyre relies on the exemptions in Schedule 2 of the Data Protection Act 2018.
Those exemptions are applied to the specific engagement and only for as long as the prejudice would arise. They are not treated as a general exclusion from Lyre's obligations. The same applies to requests to exercise the rights set out below. Where information is withheld on that basis, the reason is recorded.
Rights
What individuals may ask for, and where those rights are qualified.
Individuals have the right to request:
- Access to the personal data held about them
- Correction of inaccurate data
- Erasure of their data
- Restriction of processing
- Transfer of their data to another controller, where that right applies
- An objection to processing carried out on the basis of legitimate interests
Requests should be sent to enquiries@lyre.group, marked "Data Protection". A response will be provided within one month. Verification of identity may be required before a request is actioned, to avoid disclosing data to the wrong person.
Several of these rights are qualified. As set out above, they may lawfully be restricted in the context of a particular engagement. Where that occurs, the individual will be informed that a restriction has been applied, unless doing so would itself cause the prejudice the exemption exists to prevent.
Disclosure and transfers
Who receives data, and where it goes.
Personal data is shared with:
- The client who instructed the engagement
- Lyre's professional advisers, including its accountant and, where necessary, its solicitors and insurers
- Service providers processing data on Lyre’s behalf under written agreement
- Law enforcement, regulators or courts, where disclosure is legally required
Personal data is not sold and is not shared for marketing purposes.
International transfers
Personal data held by Lyre is stored in the United Kingdom. It is not transferred to, or stored in, any other country.
Security and this website
Technical measures, and what the site itself collects.
Lyre applies technical and organisational measures appropriate to the sensitivity of the material it holds, including encryption of data at rest and in transit, access control on a need-to-know basis, and secure disposal at the end of the retention period.
This website sets no cookies and runs no analytics. The hosting provider records server logs, including IP addresses, for security and diagnostic purposes, retained for 90 days. The lawful basis for that processing is legitimate interests, specifically the security of Lyre's infrastructure.
Complaints
Escalation.
Concerns about how Lyre has handled personal data should be raised directly in the first instance, so that they can be addressed. There is also a right to lodge a complaint with the relevant supervisory authority for data protection.
This notice is updated when Lyre's processing changes.
Last updated: 20 September 2026