Trust & Compliance / GDPR

Data protection begins with a defined role.

How WDL approaches GDPR and UK GDPR responsibilities when those laws apply.

Resource
Operational overview
Last updated
25 August 2026
01

Define the processing role

MSM may act as a controller for its website and business administration, or as a processor/service provider under a research client’s documented instructions. The facts and contract determine the role.

02

Use an applicable legal basis

Controller processing may rely on contract steps, legitimate interests, legal obligations or consent where required. When acting for a client, WDL follows documented instructions and the client determines the project legal basis.

03

Minimize project information

Project identifiers and pseudonymous respondent IDs are preferred over unnecessary direct identifiers. Data categories depend on the study and source.

04

Support rights requests

Access, correction, deletion, restriction, objection, portability, consent withdrawal and regulator complaints may apply. Requests are verified and may be referred to a client when WDL acts only for that client.

05

Protect international transfers

Appropriate contractual and organizational measures are used where required, which may include data-processing terms and approved contractual clauses.

06

Review suppliers and processors

Privacy practices and contractual responsibilities form part of supplier and service-provider review appropriate to the relationship.

Vendor onboarding

Need additional vendor documentation?

Prospective clients, procurement teams and research partners may request supporting information for due diligence. Documentation is provided by request and subject to availability, confidentiality and appropriate review.

Request documentation