Skip to main content
Transparency data

Fraud Risk Assessment Accelerator Privacy Notice

Published 7 October 2026

This notice sets out how we will use your personal data, and your rights. It is made under Articles 13 and/or 14 of the UK General Data Protection Regulation (UK GDPR). 

Your data

Purpose

The purpose for which we are processing your personal data is: 

To provide access to the Fraud Risk Assessment Accelerator in order to enhance cyber security, and prevent/detect fraud. The nature and scope of personal data processing are strictly limited to administrative data necessary for user authentication, access control, and application security. Specifically, the system processes user profile credentials, including the full name, work or business email address, job role, and organisation or department name of authorised counter-fraud professionals. This data is collected directly from individuals and public bodies during the onboarding process via secure corporate email. A subset of personal data (names, departments, work or business emails) is retained to conduct user research and direct user feedback which is anonymised on a quarterly basis.

Additionally, the system processes residual personal data that may be incidentally contained within the policy scheme documents uploaded by users. This processing is strictly limited to passing the documents through an automated redaction tool to identify and permanently remove personally identifiable information (PII) before the source documents are analysed by the underlying AI model.

We will process the following personal data: 

• Name
• Email address
• Job title or grade
• Organisation name

• Usage audit logs

• Incidental personal data contained within uploaded policy scheme  documents (prior to automated redaction)

The legal basis for processing your personal data is that it is in our legitimate interest to:

  1. to enable access to the FRA, 
  2. audit FRA usage for security purposes, and
  3. to conduct user research.
  4. redact and remove incidental personal data from uploaded documents to ensure data minimisation and security.

Recipients

Your personal data will be shared by us with Department for Energy Security and Net Zero (DESNZ) and CBAS, Microsoft (official IT platform) 

Retention 

Your personal data will be kept by us for as long a user needs access to the FRA. Personal data  is subject to a quarterly review and purge cycle for inactive users.The specific retention timeframe for the application audit and access logs is 30 days. Any personal data identified and redacted from uploaded source documents is masked instantly during the ingestion process and is not retained or stored.

Your Rights

You have the right to request information about how your personal data are processed, and to request a copy of that personal data. 

You have the right to request that any inaccuracies in your personal data are rectified without delay. 

You have the right to request that any incomplete personal data are completed, including by means of a supplementary statement. 

You have the right to request that your personal data are erased if there is no longer a justification for them to be processed. 

You have the right in certain circumstances (for example, where accuracy is contested) to request that the processing of your personal data is restricted. 

You have the right to object to the processing of your personal information in certain circumstances.

International Transfers

Documents are processed within a private Azure environment; the underlying OpenAI large language model operates from a Sweden-based core model. Data transfers to Sweden are covered under the UK’s Adequacy Decision for the EU.

Complaints 

If you consider that your personal data has been misused or mishandled, you may make a complaint to the Information Commissioner, who is an independent regulator.  The Information Commissioner can be contacted at:  

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

or 0303 123 1113, or icocasework@ico.org.uk.  Any complaint to the Information Commissioner is without prejudice to your right to seek redress through the courts. 

Contact Details

The data controller for your personal data is the Cabinet Office. The contact details for the data controller are: 

Cabinet Office
70 Whitehall
London
SW1A 2AS

or 0207 276 1234, or you can use this webform. 

The contact details for the data controller’s Data Protection Officer are: dpo@cabinetoffice.gov.uk. 

The Data Protection Officer provides independent advice and monitoring of Cabinet Office’s use of personal information.