Vellinx.

Data Protection Impact Assessment

Where handling personal information is likely to be high risk to people, the law requires an assessment of that risk and of what reduces it. This page summarises ours, for the research Vellinx carries out on organisations and the roles in them. It sits beside our privacy notice, which says what we do; this page says what could go wrong for the people concerned, and what we do about it.

The full assessment is a working document that we keep up to date. This summary is of version 2, dated 29 September 2026, which replaced version 1 of 14 June 2026. We have left out detail that is commercially sensitive or could weaken our security. If you would like to know more, contact us at privacy@vellinx.com.

What the assessment covers

It covers the research described in our privacy notice under "People at the organisations we research": researching an organisation, and the roles in it, for a user with a genuine business reason to approach that organisation. Our own marketing, running the service for the people who use it, this website's logs and the handling of complaints are described in the notice too; none of them is high risk on its own, and the assessment refers to them only where they meet the research.

Why we carried out an assessment

The research meets more than one of the conditions that the Information Commissioner's Office (ICO), the UK's data protection regulator, lists as needing an assessment:

Describing roles rather than naming people reduces what we hold. It does not take the research outside data protection law, and it does not remove the need for this assessment.

How the research works

Is it necessary and proportionate?

Our lawful basis is legitimate interests, which we have weighed against the interests and rights of the people concerned in a separate assessment. The research exists to make an approach relevant to what an organisation is dealing with and to the right role, and it reads the same public, professional sources a person preparing the approach would read. What we hold is kept to what that needs: roles rather than names, no contact details for the people researched, no research into anyone's private life, and one six-month limit on everything a run produces. An objection to the research is final: we stop, and delete what names the person.

On that basis, and with the measures below, the assessment concludes that the research is necessary and proportionate.

The risks, and what reduces them

Each risk is rated as it stands after the measures that reduce it, on a scale of low, medium and high.

Our conclusion

With these measures, no risk to the people we research is rated high, and once the open measures below are complete the overall risk is low to medium. The assessment therefore concludes that consulting the ICO before processing is not required. If a test shows a high risk that we cannot reduce, we will consult the ICO first.

Some of these conclusions, this one among them, are of a kind that only a qualified lawyer can confirm. That review has not yet taken place.

What is still open

Each test is recorded, with its date and result, in a verification log that forms part of the assessment, and is run again when something it depends on changes.

How we keep it up to date

We review the assessment at least once a year, when the law changes, and whenever the research gains a capability that affects personal information. We update this summary when the assessment's conclusions change.

Summary of version 2 of the assessment, dated 29 September 2026 · Published 29 September 2026.