privacy policy

Our Data Protection and Privacy Policy


Privacy Policy & Data Protection Statement

Change Underground enforces strict data protection standards across our global publication. This Privacy Policy details how we collect, store, and secure personal information under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We respect user data, guarantee zero unauthorized third-party sales, and ensure total structural transparency for readers.

Context & Overview

Key Details:
Policy originally prepared by: Mark Betteridge
Initially published: 18 May 2018
Last systematically reviewed and updated: 8 July 2026 at 19:56
Policy operational lead: Jamie Reed (Editor-in-Chief)

Introduction to Data Protection

Change Underground needs to gather and use certain information about individuals. This can include customers, suppliers, business contacts, contributors, readers and other people the organisation has a relationship with or may need to contact.

This policy describes how this personal data must be collected, handled and stored to meet the publication’s data protection standards and to comply fully with UK and international law.

Why This Privacy Policy Exists

This data protection policy ensures Change Underground complies with data protection law and follows definitive journalistic best practice regarding user data. It protects the rights and data of staff, customers, readers and partners. It guarantees transparency about how the company stores and processes data. It protects the organisation from the risks of data security breaches.

Data Protection Law
The UK GDPR and the Data Protection Act 2018 describe how organisations including Change Underground must collect, handle and store personal information. These rules apply regardless of whether data is stored electronically, on paper or via secure cloud systems.

To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully. Core principles dictate that personal data must be processed fairly, lawfully and transparently. It must be obtained only for specific, explicit and legitimate purposes. It must be adequate, relevant and limited to what is necessary.

Data must be accurate and kept up to date. It must not be kept in a form which permits identification of data subjects for longer than is necessary. It must be processed in a manner that ensures appropriate security of the personal data.

The Right to be Forgotten: You hold the absolute right to request that your personal data is permanently deleted or restricted from our operational systems.

People, Risks and Responsibilities

Policy Scope
This policy applies to the main operations of Change Underground, including all editorial desks, staff, volunteers, contractors, suppliers and any persons working on behalf of the publication.

It applies to all data the company holds relating to identifiable individuals, including names of individuals, postal and billing addresses, email addresses, and telephone numbers. It also covers IP addresses, device tracking identifiers and automated metadata attributes.

Responsibilities
Everyone who works for or with Change Underground carries individual responsibility for ensuring data is handled appropriately in accordance with compliance frameworks.

The Owner (Mark Betteridge) is ultimately responsible for ensuring that Change Underground meets its overarching structural and legal obligations.

The Data Protection Officer (Jamie Reed) is responsible for the daily execution of our compliance mandate. This includes handling data protection queries from staff or readers, dealing with formal Subject Access Requests (SARs), and reviewing editorial compliance schedules.

The IT Infrastructure Lead (Mark Betteridge) is responsible for ensuring all servers, databases, security hard points, firewalls and encryption protocols meet high-tier industry safety standards.

The Data Marketing Lead (Jamie Reed) is responsible for approving data protection statements attached to promotional communications, ensuring all marketing footprints strictly abide by opt-in mechanisms.

General Staff Guidelines

The only people authorised to access data covered by this policy are those who strictly require it to execute their professional workflows. Data must never be shared informally. Employees must use complex passwords and multi-factor authentication where available, and screens must be locked immediately when workstations are left unattended.

How We Use Your Personal Data

Change Underground processes data across distinctly defined user categories. Subscribers and newsletter readers are only contacted via email if they have actively and explicitly completed a double-opt-in tracking action. Customers and business clients agree to be contacted with transactional data, invoicing requirements, and crucial project milestones relevant to their commercial campaigns.

Voters participating in our public charts or tracking polls must consent to the collection of verification data to protect our editorial metrics from structural manipulation or automated botanical infiltration.

Corporate Transitions and Asset Sales: In the event Change Underground undergoes a business transition, such as a merger, acquisition by another operator, or the sale of all or a portion of its digital assets, user data and subscriber lists will be securely transferred as a core operational asset. The acquiring entity will assume the rights and obligations regarding your personal data as defined in this specific policy.

Data Storage and Security Protocols

When data is stored electronically, it is protected against unauthorised access, malicious hacking attempts, and accidental corruption. We implement secure transport pathways alongside rigorous database firewalls. Anonymisation and pseudonymisation protocols are deployed across reader datasets wherever applicable. Data is never saved locally to unencrypted mobile devices or laptops.

Cookies and Tracking Architecture

This website utilises cookies and analytical software to tracking usage patterns and enhance on-site user experiences. Cookies can be removed or rejected via your individual browser architecture without losing access to primary editorial content.

Necessary Cookies are required for fundamental site operations, user logins, and core interface rendering. Functionality Cookies are used to recognise your preferences, such as auto-filling name and email credentials on comment sheets. Analytics Cookies track baseline traffic volume, reading footprints, and technical execution metrics to help us optimize server distribution. Advertising Cookies are managed alongside third-party ad networks to ensure displayed commercial campaigns are contextually relevant to our underground music audience.

Data Accuracy and Subject Access Requests (SAR)

We keep central records clean and limited to minimal, essential datasets. Data sets are primarily contained within our direct secure WordPress database, alongside verified campaign distribution partners.

Your Explicit Rights Under GDPR:
You maintain the right to information, access, rectification, erasure, restriction of processing, data portability, and the right to object to processing or automated decision-making.

If you wish to invoke a formal Subject Access Request or exercise your Right to be Forgotten, requests must be submitted directly to our Data Protection Desk at data@change-underground.com. Our desk processes verified requests within 14 business days without administrative charge.

Contact Information

Data Protection Officer & Newsroom Lead
For questions regarding your personal data rights, processing parameters, or policy details, direct communications to Jamie Reed at data@change-underground.com.

Editorial Infrastructure & Ownership
For structural corporate compliance issues, direct queries to Mark Betteridge at mark@change-underground.com.

Supervisory Authority Coordination
If you are located in the UK, your data rights are overseen by the Information Commissioner’s Office (ICO). For European territories, complaints can be registered alongside the relevant regulatory framework via info@dataprotection.ie.

Changes to This Privacy Policy

We reserve the right to apply operational modifications to this policy framework as technology and editorial infrastructure demands shift over time. Document initially published: 18 May 2018. Last modified and authenticated: 8 July 2026 at 19:56.

Change Underground remains fully committed to safeguarding user privacy through rigorous, legally compliant data architectures.

Key Takeaways

Change Underground processes subscriber data in strict compliance with the General Data Protection Regulation and the UK Data Protection Act 2018.
Data Protection Officer Jamie Reed oversees all Subject Access Requests and data security frameworks for Change Underground.
Change Underground transfers proprietary data exclusively under strict operational service agreements or during formal corporate transitions.

Change Underground Privacy Policy FAQ

What data does the Change Underground Privacy Policy cover?

The Change Underground Privacy Policy covers names, email addresses, billing addresses, telephone numbers, and automated metadata attributes. Change Underground collects this data to fulfill legitimate publication purposes.

Who manages the Change Underground Privacy Policy compliance?

Jamie Reed acts as the Data Protection Officer for Change Underground. Mark Betteridge oversees the overarching structural and IT infrastructure obligations.

How does Change Underground handle third-party data sales?

Change Underground never sells personal data to third parties for independent marketing purposes. Data transfers only occur under strict operational agreements or formal corporate transitions.

What are the individual rights under the Change Underground Privacy Policy?

Individuals maintain the right to information, access, rectification, erasure, and restriction of processing under the General Data Protection Regulation. Change Underground processes Subject Access Requests within 14 business days.

How does Change Underground secure electronic data?

Change Underground secures data using secure transport pathways, database firewalls, and pseudonymisation protocols. The publication never saves data locally to unencrypted mobile devices.

Where can readers direct Change Underground Privacy Policy inquiries?

Readers must direct all data protection inquiries and Subject Access Requests to the official Change Underground data protection desk email address. The Information Commissioner’s Office oversees data rights for users located in the UK.


Related Post