← Policies

Data protection policy

FourWinds Digital · Version 1.0 · 20 August 2026 Owner: Oscar Cobbe · Review due: 20 February 2027


1. Who this covers and in what role

FourWinds Digital builds and runs websites, automations, integrations, dashboards and compliance tooling for Irish businesses. It is established in Ireland, so the GDPR applies through Article 3(1) and no Article 27 representative is required.

FourWinds is currently a sole trader. On incorporation the company, not the founder personally, becomes the controller and processor, and this policy is reissued naming the company.

We act in two different roles and the duties differ. Every processing activity is recorded against one of them.

WhatOur role
Our own clients, enquiries, prospects, staff, contractors, accountsController
Client data inside the sites, dashboards and automations we build and hostProcessor
Portal account and billing dataController

Where we host a system and also decide its retention, security design, sub-processors and analytics, the substance may make us a joint controller under Article 26 regardless of what a contract calls us. That is decided per product and written down, not assumed globally.

2. Principles

Article 5(1) binds everything below: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Article 5(2) requires us to demonstrate it, which in practice means the records named in this policy exist and are current.

3. Lawful basis

Recorded per purpose, not per person.

PurposeBasis
Delivering work to a clientArticle 6(1)(b), contract
Enquiries and prospectsArticle 6(1)(f), legitimate interests, with a written assessment
Tax, company and employment recordsArticle 6(1)(c), legal obligation
Electronic marketingConsent under SI 336/2011 Regulation 13, with Article 6(1)(a) or (f) underneath
Staff health informationArticle 9(2)(b) with Data Protection Act 2018 s.46, and the suitable and specific measures required by s.36

4. Records of processing

We keep two records, and the small-company exemption does not apply.

Article 30(5) removes the obligation for organisations under 250 people unless the processing is likely to risk rights and freedoms, or is not occasional, or includes special category data. Those are alternatives, so any one of them brings the duty back. The Article 29 Working Party position paper, endorsed by the EDPB, holds that HR processing can never be "occasional" because it is continuous. Ongoing client hosting is not occasional either.

So we maintain:

  1. An Article 30(1) controller record of our own processing.
  2. An Article 30(2) processor record, listing each client we act for, the categories of processing, transfers, and a general description of the Article 32 measures.

The second is the one agencies typically do not have, and it is the one a client's procurement team and the Data Protection Commission ask for first. Under Article 30(4) the DPC can demand either on request.

5. Who is accountable

FourWinds does not require a Data Protection Officer. Article 37(1) is exhaustive for private companies: we are not a public authority, our core activity is not regular and systematic monitoring of people on a large scale, and we do not process special category data at scale.

We deliberately do not appoint one voluntarily. A voluntary DPO attracts the full Article 37 to 39 regime, including independence and freedom from conflict of interest. A sole founder who also decides the purposes of processing cannot satisfy Article 38(6). Calling the role a DPO would create the conflict rather than the protection.

Instead there is a named Data Protection Contact: Oscar Cobbe, oscar@fourwindsdigital.com. This is the contact point referred to in Article 33(3)(b).

If our work moves toward behavioural analytics, tracking or scoring as the product rather than as a support function, Article 37(1)(b) becomes arguable and this decision is reassessed in writing.

6. Irish law on top of the GDPR

The Data Protection Act 2018 adds duties the GDPR does not, and two of them carry personal exposure:

  • s.144 makes it a criminal offence for a processor, or its employee or agent, to disclose personal data without the prior authority of the controller. On indictment: a fine up to €50,000 and up to five years.
  • s.146 makes directors and managers personally liable where an offence is committed with their consent, connivance or neglect.

Because we hold client data as a processor, an unauthorised disclosure by us or a contractor is a crime in Ireland, not only a GDPR infringement. No client data leaves our systems without a documented instruction from that client. That rule exists because of s.144.

Also relevant: s.31 sets the digital age of consent at 16; s.30 makes it an offence to process a child's data for direct marketing, profiling or micro-targeting; s.36 requires "suitable and specific measures" wherever we rely on a DPA 2018 condition.

The supervisory authority is the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963.

7. Rights requests

One month to respond, under Article 12(3). Extendable by two further months for complexity, but only if the person is told within the first month. Free, unless the request is manifestly unfounded or excessive, and the burden of showing that is ours.

Access requests were 42% of all complaints to the DPC in 2025, on a caseload up 45%. This is statistically the most likely way we meet the regulator, so the procedure has an owner and a clock rather than a paragraph.

As a processor we never answer a data subject directly about client data. Article 28(3)(e) requires us to assist the client, not to substitute for them. Requests are forwarded to the client controller within three working days.

8. When we act as a processor

Every client engagement carries a written agreement meeting Article 28(3): processing only on documented instructions, confidentiality commitments, Article 32 measures, sub-processor conditions, assistance with rights requests, assistance with Articles 32 to 36, deletion or return at the client's choice at the end, and submitting to audits.

We also tell the client immediately if an instruction appears to breach data protection law. That is a standalone duty in the final subparagraph of Article 28(3).

Sub-processors. Vercel, Supabase, Stripe, Google and Anthropic are sub-processors when used inside a client system. We maintain a published sub-processor list, notify clients before adding or replacing one, and give them an opportunity to object. We stay fully liable for them under Article 28(4).

9. Security

Article 32 requires measures proportionate to the risk. Ours, and the evidence for each, are:

Technical. Devices patched and running current operating systems. Full-disk encryption on every laptop and phone. Two-factor authentication on every account that touches client data, without exception. TLS on everything. Vendor default credentials changed. Backups held separately and restore-tested, with the test recorded.

Organisational. This policy and the retention schedule, both written and reviewed. A password policy. A breach response plan, tested. An asset register. Leaver procedures applied to files and permissions. Periodic review of third-party contracts.

Cloud. Documented access privileges, reviewed periodically to confirm each one is still necessary. Provider defaults are reviewed and hardened rather than accepted.

A one-person company is not expected to run a security operations centre. It is expected to have written this down, to have tested a restore, and to have multi-factor authentication everywhere.

10. Assessing risk before we build

Before any new product, integration or AI feature touching personal data, we write a short screening note and record the outcome, including when the answer is that no assessment is needed.

A full Data Protection Impact Assessment is mandatory where the Irish Article 35(4) list applies. Three items on that list are live risks for what we build:

  • systematically monitoring, tracking or observing people's location or behaviour
  • profiling people on a large scale
  • combining or cross-referencing separate datasets where that contributes to profiling or behavioural analysis

Where a DPIA shows a high risk we cannot mitigate, Article 36 requires prior consultation with the DPC before proceeding.

11. Breaches

Governed by the Breach response plan, which is a separate document because it has to be usable at two in the morning. Two points belong here:

  • The 72-hour clock in Article 33(1) runs in calendar hours.
  • Every breach is written into the register under Article 33(5), including the ones we decide not to notify. The reasoning for a decision not to notify is the entry that discharges accountability. The DPC has an open initiative examining compliance with this obligation specifically.

12. Marketing

Electronic marketing is governed by SI 336/2011 Regulation 13, and the burden of proving consent sits on the sender under Regulation 13(14).

The business-to-business carve-out in Regulation 13(2) is narrower than commonly assumed: the address must reasonably appear to be used mainly in the recipient's commercial capacity, and the message must relate solely to that commercial activity.

The existing-customer soft opt-in in Regulation 13(11) requires all four conditions: our own product, similar to what was supplied, a free and easy objection route offered at collection and in every message, and a sale within the preceding 12 months.

Opt-outs are honoured for business contacts too. Suppression records are kept indefinitely, because deleting one so that we re-market to that person is itself the offence. Each message is a separate offence under Regulation 13(15)(b). On indictment the fine is up to €250,000 for a body corporate and up to €50,000 for a natural person. FourWinds is a sole trader, so €50,000 per message is our exposure today and the €250,000 figure applies from incorporation.

13. Transfers outside the EEA

We rely on the EU-US Data Privacy Framework where a vendor is certified, and keep Standard Contractual Clauses as a documented fallback in every US vendor contract.

That belt-and-braces position is deliberate. The Framework survived its first challenge in September 2025, but that decision is under appeal, and in June 2026 the US Supreme Court held that Federal Trade Commission commissioners may be removed without cause. FTC independence is one of the pillars the adequacy decision rests on, and the EDPB has formally asked the Commission to reassess. If the Framework is suspended, we re-paper on SCCs rather than start from nothing.

Current position of our stack:

VendorRouteTransfer assessment
VercelFramework certifiedNot required while adequacy holds
StripeFramework certifiedNot required while adequacy holds
GoogleFramework certified, verify per entity and serviceNot required while adequacy holds
SupabaseSCCsRequired
AnthropicSCCs, EU contracting entity, Irish governing lawRequired

Transfer impact assessments follow the EDPB's six-step method and are re-evaluated, not written once.

Sending client personal data to an AI service is a disclosure to a sub-processor. If the client has not authorised it, that is a breach of Article 28(3)(a) and potentially an offence under DPA 2018 s.144. AI vendors appear on the client-facing sub-processor list like any other.

14. Review

Reviewed annually or on any material change. Next review 20 February 2027, brought forward if the Data Privacy Framework position changes or if the proposed GDPR reforms are adopted.

Two items are moving and are deliberately not presented as settled: the Framework's survival, and the anonymisation standard pending the EDPB's draft guidelines, which are in consultation until 30 October 2026.