National Space Innovation Programme (NSIP) - Privacy Notice
Updated 20 July 2026
Data Protection
In the course of engaging with the National Space Innovation Programme, you may provide information about yourself (‘personal data’). We (the Department for Science, Innovation and Technology (DSIT)) are the ‘data controller’ for this information, which means we decide how to use it and are responsible for looking after it. This notice sets out how we will process your personal data, and your rights. It is made under Articles 13 and/or 14 of the UK General Data Protection Regulation (UK GDPR).
The type of personal information we collect
Depending on the nature of the interaction, we may collect and process some or all of the following personal data:
-
Personal identifiers and contact information (for example, name, postal / email address, telephone number).
-
Personal characteristics (age, gender).
-
Profession-related information (profession, qualifications, job role title, organisation name, seniority/grade/position within organisation, security clearance level).
-
Geographic-related information.
Where required, we may also collect and process the following special category data:
-
Accessibility requirements (which may indicate your health data);
-
Dietary requirements (which may indicate your religious beliefs or health data);
-
Nationality (which may indicate your religious beliefs or ethnic origin when combined with other data such as name and title);
-
Images and video (which may indicate your racial or ethnic origin, religious or philosophical beliefs, or health data).
There is limited automated processing of personal data for administrative purposes.
How we will use your data
We will use your data to ensure that National Space Innovation Programme is able to:
-
receive and process grant applications from you, and administer and manage your funding award, if successful
-
evaluate and analyse the impact and effectiveness of our grant portfolio
-
prevent and detect fraud
-
facilitate administration activity where you request to attend an event, for purposes directly related to the safe and secure running of the event, including making reasonable adjustments for accessibility purposes
-
monitor equality of opportunity and diversity where protected characteristics are captured – this will be anonymised and aggregated beyond an individual level for statistical purposes only, and will not be used for individual decisions
-
maintain a reviewer pool, allocate proposals for review and pay assessor fees
-
Communicate NSIP updates, funding opportunities and relevant information through a mailing list
We will only use your data for the purposes for which we collect it, unless we reasonably consider that we need to use it for another related reason and that reason is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will seek your consent separately to use it for that new purpose.
Depending on the nature of your engagement, the lawful basis for processing your personal data under Article 6 of the UK GDPR will be one of the following:
-
1(e) Public task: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller; in this case, the proper management and governance of the grant funding process.
-
1(f) Legitimate interests: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
The legal basis for processing your special category data under Article 9 of the UK GDPR is:
- 2(a) Because you have provided your explicit consent to the processing of your data for one or more specified purposes
Who has access to your data?
Access to your data held by DSIT will be provided to staff within the organisation who need to view it as part of their work in carrying out the purposes described above.
We may share your data with third parties who are contracted in support and administration of tasks directly related to NSIP who will act as data processors. These bodies are required to take appropriate security measures to protect your data in line with our policies and this privacy notice. We do not allow them to use your data for their own purposes. We permit them to process your data only for specified purposes and in accordance with our instructions.
Retaining your data
Personal data will be retained to the following schedule:
-
Information within proposals (successful and unsuccessful) will be retained for seven years following scheme closure.
-
Your contact data will be retained for no longer than 10 years following the scheme closure for monitoring and evaluation purposes.
-
Sensitive personal data collected to facilitate event attendance will be destroyed one month after the event.
-
Anonymised and non-personal data may be kept for up to 15 years for statistical purposes.
Where we store and use your data
Your personal data will be processed in the UK within secure UK government systems which use the Government Microsoft 365 environment and are hosted in UK-based data centres. As your personal data will be stored on our IT infrastructure it will be shared with our data processors Microsoft and may be transferred and stored securely outside the UK. Where that is the case it will be subject to equivalent legal protection through an adequacy decision, the use of Standard Contractual Clauses or a UK International Data Transfer Agreement. We will not make additional copies of personal data to store outside of this environment.
Where your personal data is processed outside of the UK, one or more of the following safeguards will be in place:
-
UK Adequacy Regulations (this includes EEA and all countries covered by an adequacy decision in respect of a third country by the European Commission)
-
An International Data Transfer Agreement
-
The EU’s Standard Contractual Clauses together with an international data transfer addendum.
Such transfers will only take place if one of the following applies:
-
the country receiving the data is considered by the EU to provide an adequate level of data protection;
-
the organisation receiving the data is covered by an arrangement recognised by the EU as providing an adequate standard of data protection e.g. transfers to companies that are certified under the EU US Privacy Shield;
-
the transfer is governed by approved contractual clauses;
-
the transfer has your consent;
-
the transfer is necessary for the performance of a contract with you or to take steps requested by you prior to entering into that contract; or
-
the transfer is necessary for the performance of a contract with another person, which is in your interests.
Your data protection rights
You have the right to request information about how your personal data are processed, and to request a copy of that personal data.
You have the right to request that any inaccuracies in your personal data are rectified without delay.
You have the right to request that any incomplete personal data are completed, including by means of a supplementary statement.
You have the right to request that your personal data are erased if there is no longer a justification for them to be processed.
You have the right in certain circumstances (for example, where accuracy is contested) to request that the processing of your personal data is restricted.
You have the right to object to the processing of your personal data where it is processed for direct marketing purposes.
You have the right to withdraw consent to the processing of your personal data at any time.
You have the right to object to the processing of your personal data.
To exercise your rights please contact the Data Protection Officer using the contact details below.
How to contact us
If you have any questions or concerns about our use of your personal information, you can contact us the department’s Data Protection Officer in the first instance using the details below.
DSIT Data Protection Officer,
Department for Science, Innovation and Technology,
22-26 Whitehall,
London, SW1A 2EG.
Email: dataprotection@DSIT.gov.uk