Ipsos privacy notice: cyber security breaches survey (charities and education institutions)
Updated 13 August 2026
This privacy notice explains who we are, the personal data we collect, how we use it, who we share it with, and what your legal rights are.
About Ipsos UK and this study
Ipsos UK is a specialist research agency, commonly known as “Ipsos”. Ipsos is part of the Ipsos worldwide group of companies, and a member of the Market Research Society. As such we abide by the Market Research Society Code of Conduct and associated regulations and guidelines.
Ipsos has been asked by the Department Digital, Culture, Media, and Sport (DCMS) and the Home Office (HO) to carry out research on their behalf, looking at organisations’ approaches to cyber security and whether they have experienced cyber security breaches or attacks. This research was previously commissioned by the former Department for Science, Innovation and Technology (DSIT). In July 2026, the parts of DSIT responsible for cyber security policy moved to DCMS.
This is an annual study, called the Cyber Security Breaches Survey. The research includes:
- a telephone and online survey of charities and education institutions
- follow-up qualitative interviews with those taking part in the survey
DCMS is the data controller of this survey, which was initially conceived by DSIT and HO. Ipsos provides DCMS and HO with fully anonymised reports and notes. This Ipsos privacy notice applies to all these aspects of the research with charities and education institutions.
What information does Ipsos UK have on you?
If you are registered on one of the following websites as a charity or education institution, we have collected your personal data from one of these websites in order to invite your organisation to take part in the cyber security breaches survey:
- The Charity Commission for England and Wales
- The Office of the Scottish Charity Regulator
- The Charity Commission for Northern Ireland
- all institutions in England from the Get Information About Schools database
- schools in Scotland from the Scottish Government School contact details
- further education colleges in Scotland from the Colleges Scotland directory
- schools in Wales from the Welsh Government address list of schools
- further education colleges in Wales from the Welsh Government Further Education Institutions contact details
- schools in Northern Ireland from the Northern Ireland Department of Education database
- further education colleges in Northern Ireland from the NI Direct FE College directory
- online lists of all UK universities, e.g. the Universities UK website, cross-referenced against the comprehensive list of recognised bodies on GOV.UK (which also includes, for example, degree-awarding arts institutes).
The data (including personal data) Ipsos has received from these sources includes:
- organisation registered and trading names
- organisation address and postcode
- organisation telephone number
- contact name within the organisation where available – for an individual likely to be responsible for cyber security
- contact email within the organisation where available
In some cases, we have supplemented the above organisation details with contact details sourced from business websites and publicly available LinkedIn data, via another research partner, Sample Solutions. Information on how Sample Solutions collects this data can be found on their website.
What is Ipsos’s legal basis for processing personal data?
Ipsos UK requires a legal basis to process your personal data. Ipsos’ legal basis for processing personal data for this research study is your consent to take part. If you wish to withdraw your consent at any time, please see the section below covering “Your Rights”.
How will Ipsos use any personal data, including survey answers provided by participants?
Responding to the survey, or follow-up qualitative interview is voluntary and any answers are given with your consent.
Ipsos will use your personal data and answers solely for statistical research purposes. This includes producing anonymous, aggregated statistical research findings for DCMS and the Home Office. Ipsos will provide DCMS and the Home Office with a de-identified data file of responses for them to carry out their own analysis and quality assurance of the results. This de-identified file may be made available to other approved government departments, partner organisations or researchers for statistical research purposes only. Your personal data (including any contact information) will not be included in this data file.
Ipsos will only share what is discussed during an interview in an anonymised format i.e. we will not share any identifiable, personal data with the Home Office. This could take the form of an anonymised transcript. Any recorded materials will be used for research purposes only.
Ipsos will therefore keep your personal data in confidence, in accordance with this Privacy Notice. Ipsos can further assure you that you will not be identifiable in any published results.
Who will Ipsos share your data with?
Ipsos will use the supplier organisation Paton Williamson Consultancy and Recruitment (PWL) for recruitment of qualitative interviews. We will therefore be sharing the contact details of those who agree to be recontacted for this research strand with PWL.
How will Ipsos ensure personal information is secure?
Ipsos takes its information security responsibilities seriously. We apply various precautions to ensure your information is protected from loss, theft or misuse. Security precautions include appropriate physical security of offices, and controlled and limited access to computer systems.
Ipsos is accredited to the International Standard for Information Security, ISO 27001. In line with this, we have regular internal and external audits of our information security controls and working practices.
How long will Ipsos retain personal data and identifiable answers?
Ipsos will only retain any personal data and identifiable answers for as long as is necessary to support this research. In practice, this means that once we have reported the final anonymous research findings to DCMS or the Home Office, we will securely remove any personal data from our systems.
For this project, we will securely remove your personal data from our systems by the end of March 2027. This is unless you give your consent to be recontacted to take part in follow-up research on this topic up to 12 months after your interview. In this case, Ipsos will securely remove your personal data from our systems by 9 November 2027.
Your rights
This section sets out your rights to the personal data that Ipsos holds about you, and the contact information you need to exercise your rights.
-
You have the right to access your personal data within the limited period that Ipsos holds it.
-
Providing responses to this survey is entirely voluntary and is done so with your consent. You have the right to withdraw your consent.
-
You also have the right to rectify any incorrect or out-of-date personal data about you which we may hold.
-
If you want to exercise your rights, please contact us at the Ipsos address below.
-
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), if you have concerns on how we have processed your personal data. You can find details about how to contact the Information Commissioner’s Office at https://ico.org.uk/global/contact-us/ or by sending an email to: casework@ico.org.uk.
-
If instead you want to contact DCMS and the Home Office, who commission the research, to exercise your rights about any data they may hold about you, please contact them using the details provided below.
Where will personal data be held and processed?
All of your personal data used and collected for this survey will be stored by Ipsos in data centres and servers within the United Kingdom and European Economic Area (EEA).
Contacting Ipsos and DCMS/the Home Office about this survey and/or your personal data
Contact the relevant Ipsos research team
Email Eva Radukic at UK-PA-DSIT-CyberSecurityBreaches@ipsosresearch.com.
Contact the Ipsos compliance team
Email compliance@ipsos.com with “26-020358-02 Cyber-Security Breaches Survey 2026 to 2027” in the subject line.
Post:
Subject: 26-020358-02 Cyber-Security Breaches Survey 2026 to 2027
Compliance Department Ipsos (market research)Limited
3 Thomas More Square
London
E1W 1YW
Contact the relevant DCMS research team
Email Saman Rizvi at cybersurveys@dsit.gov.uk.
Contact the DCMS data protection officer
Email dpo@dcms.gov.uk with “26-020358-02 Cyber-Security Breaches Survey 2026 to 2027” in the subject line.
Post:
Subject: 26-020358-02 Cyber-Security Breaches Survey 2026 to 2027
DCMS Data Protection Officer
The Department for Culture, Media & Sport
100 Parliament Street
London
SW1A 2BQ
Contact the relevant Home Office research team
Email CyberCrimeResearch@homeoffice.gov.uk.
Contact the Home Office data protection officer
Email dpo@homeoffice.gov.uk with “26-020358-02 Cyber-Security Breaches Survey 2026 to 2027” in the subject line.
Post:
Subject: 26-020358-02 Cyber-Security Breaches Survey 2026 to 2027
Office of the DPO
Home Office
Peel Building
2 Marsham Street
London
SW1P 4DF