Insights & News page
Capita privacy controls and assurance
Ensuring governance and compliance, including in AI implementations
We take privacy matters very seriously. We are committed to respecting and protecting the privacy of colleagues, our clients and their customers.
This page explains how Capita handles personal data and what we expect from all colleagues.
Our privacy principles
Our assurance model
Shared responsibility in data protection
Trust is built on shared responsibility – everyone must protect what matters.
Our operational privacy controls
Sub-processor compliance
All sub-processors are subject to our due diligence process to ensure compliance with relevant legislation, regulations and contractual terms.
Notifications of changes
Clients are promptly notified about any changes involving sub-processors to maintain transparency.
Rights request assistance
Technology is designed to always support individual rights requests.
Incident response process
Our colleagues are trained to respond immediately in the event of a breach and to work with stakeholders to mitigate impact wherever possible.
Embedded privacy controls – always
Data location and sovereignty
Compliance with data location
Our hyperscaler hosting partners give us full control over the geographic regions we select to host client data, enabling us to ensure our client’s sovereignty requirements are met.
Use of safeguard mechanisms
Appropriate safeguards like UK IDTA and Standard Contractual Clauses (SCCs) are applied for international data transfers.
Protection Outside UK/EEA
Access to data outside the UK/EEA is only permitted in strict alignment with client-specified contractual terms.
Our hyperscaler partners- privacy first
Our partners
Discover how we’re leveraging the expertise of technology hyperscalers to deliver impactful solutions.
Capita’s Privacy Control Framework
Framework alignment
Our framework complies with GDPR and other data privacy regulations to ensure legal adherence.
Regular monitoring
Continuous monitoring is conducted to verify controls are effective and meet regulatory requirements.
Adaptive assurance
Our framework adapts to regulatory changes through ongoing assurance and updates.


