GovSecure Portal crest
GOVERNMENT SECUREPORTAL
OFFICIAL
Back to Portal

Privacy Notice

GovSecure Portal — Data Protection Statement

1. Who We Are

The GovSecure Portal is operated by thegovernement.uk. The data controller for personal information processed through this portal is the relevant government department or agency responsible for your account. This portal is classified as an OFFICIAL system under the Government Security Classifications Policy.

2. What Personal Data We Collect

We collect and process the following categories of personal data:

  • Identity data: Full name, job title, department, and government email address.
  • Authentication data: Hashed passphrase credentials and session tokens. Passphrases are never stored in plain text.
  • Usage data: Login timestamps, IP addresses, pages accessed, and actions performed within the portal.
  • Communications data: Secure messages sent and received through the portal's internal email system.
  • Audit data: A complete audit log of all significant system actions, retained for security and accountability purposes.

3. How We Use Your Data

Your personal data is used for the following purposes:

  • Authenticating your identity and managing your access to the portal.
  • Enabling secure internal communications between authorised personnel.
  • Maintaining an audit trail for security, accountability, and legal compliance.
  • Detecting and investigating unauthorised access or misuse of the system.
  • Administering your account, including password resets and role management.

4. Legal Basis for Processing

Processing is carried out under Article 6(1)(e) of the UK GDPR — the exercise of official authority vested in the controller. Where processing relates to special category data, the basis is Article 9(2)(g) — substantial public interest. All processing is conducted in accordance with the Data Protection Act 2018.

5. Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Audit logs are retained for a minimum of 7 years in accordance with government records management policy. Account data is deleted within 90 days of account closure.

6. Data Security

All data transmitted through this portal is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256. Access is restricted to authorised personnel only, and all access is subject to administrator approval. This system is monitored continuously; all activity is logged and may be reviewed by security personnel.

7. Your Rights

Subject to applicable exemptions under the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you (Subject Access Request).
  • Request correction of inaccurate personal data.
  • Request erasure of your personal data where there is no lawful basis for continued processing.
  • Object to processing of your personal data.
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Contact

To exercise your rights or raise a data protection concern, please contact the Security Team using the Contact Security Team form. For complaints, you may also contact the ICO directly at ico.org.uk.

Last reviewed: June 2026 — © Crown Copyright 2026