Close

Capita Web Assist CapitaWebAssist


Hello! I’m CapitaWebAssist, your AI Virtual Assistant.

Please ask me anything about Capita - our expertise and solutions, what it's like to work here, news or our latest thinking.

I’m sorry, I do not know the answer to your question. You may be able to find your answer at www.capita.com.

Potentially abusive, vulgar, or irreverent language detected. Please accept our apologies if this is an incorrect detection. Try asking again using different words.

CapitaWebAssist can make mistakes. The more specific your questions, the more accurate the responses are likely to be. Any important information should be separately verified.
CapitaWebAssist is powered by Black Sun Global

Access to the microphone has been blocked by your web browser.

You can configure your web browser to allow access to the microphone.

Capita privacy controls and assurance 

Ensuring governance and compliance, including in AI implementations

We take privacy matters very seriously. We are committed to respecting and protecting the privacy of colleagues, our clients and their customers.

This page explains how Capita handles personal data and what we expect from all colleagues.



Our privacy principles

We are committed to collecting and using personal data fairly, transparently and lawfully.

We will ensure the integrity, confidentiality and availability of personal data and respect an individual's rights in respect of their data. 

We will comply with all applicable data protection laws and will adapt out controls to meet evolving regulatory requirements.


Our assurance model

1

First line of defence

Our Operational teams embed privacy controls within daily activities to manage risks effectively.

2

Second line of defence

Our Data Privacy Team offers guidance, monitors processes and ensures privacy compliance.

3

Third line of defence

Our Group Audit Team validates compliance and promotes continuous improvement initiatives.


Shared responsibility in data protection

Trust is built on shared responsibility – everyone must protect what matters.


Our operational privacy controls


Sub-processor compliance

All sub-processors are subject to our due diligence process to ensure compliance with relevant legislation, regulations and contractual terms.

Notifications of changes

Clients are promptly notified about any changes involving sub-processors to maintain transparency.

Rights request assistance

Technology is designed to always support individual rights requests.

Incident response process

Our colleagues are trained to respond immediately in the event of a breach and to work with stakeholders to mitigate impact wherever possible.


Embedded privacy controls – always

Privacy by design and default

Privacy by design and default

Our solutions embed privacy principles from the outset, ensuring comprehensive data protection by design and default.

Anonymisation and pseudonymisation

Anonymisation and pseudonymisation

At every opportunity, we apply anonymisation and pseudonymisation to strengthen data protection and maintain confidentiality.

Encryption and data segregation

Encryption and data segregation

Encryption secures data in transit and at rest, while data segregation isolates client information for added security.

Strict role-based access controls

Strict role-based access controls

Access to data is tightly controlled and limited based on strict role-based access controls to ensure confidentiality and Privileged Access Management (PAM).


Data location and sovereignty

Compliance with data location

Our hyperscaler hosting partners give us full control over the geographic regions we select to host client data, enabling us to ensure our client’s sovereignty requirements are met.

Use of safeguard mechanisms

Appropriate safeguards like UK IDTA and Standard Contractual Clauses (SCCs) are applied for international data transfers.

Protection Outside UK/EEA

Access to data outside the UK/EEA is only permitted in strict alignment with client-specified contractual terms.

Planet Earth Seen From Space

Our hyperscaler partners- privacy first

Secure and scalable infrastructure

Hyperscaler partners offer advanced infrastructure ensuring secure and scalable data processing.

Data privacy principles

Partners uphold strict data confidentiality, availability and integrity in compliance with privacy principles.

Robust controls and efficiency

Following instructions and robust controls, partners process personal data securely and efficiently.


Our partners

Discover how we’re leveraging the expertise of technology hyperscalers to deliver impactful solutions.



Capita’s Privacy Control Framework

Two office employees studying during training

Framework alignment

Our framework complies with GDPR and other data privacy regulations to ensure legal adherence.

Regular monitoring

Continuous monitoring is conducted to verify controls are effective and meet regulatory requirements.

Adaptive assurance

Our framework adapts to regulatory changes through ongoing assurance and updates.