Internal Access privacy notice
Last update: 10 July 2026
Internal Access is a single sign on service for the public sector. In order to make the service secure and available, we need to collect, process and store some personal data.
- What data we collect
- Our legal basis for processing your data
- Who we share your data with
- Where your data is processed and stored
- How long we store your data
- How we protect your data and keep it secure
- Data subject rights
- International transfers
- Cookies
- Questions and complaints
- Changes to this notice
What data we collect
Internal Access is only used to authenticate users through authorised email addresses. We do not collect or store any data except that which is needed for this purpose, or for maintaining the performance of this service.
We collect:
- active session state
- token metadata (not token values)
- structured logs which include client ID, endpoint, event type and email addresses
Our legal basis for processing your data
Legitimate interests (UK GDPR Article (6)(1)(f))
When we process your personal data for security monitoring and reporting purposes, the legal basis we rely on is that the processing is necessary for the Department of Science, Innovation and Technology’s (DSIT) legitimate interests, which is to protect Public Sector Sign in and its users against security threats, and to ensure the ongoing performance of the service.
Who we share your data with
Your personal data may be shared with security teams in your organisation in relation to security incidents, such as if malicious behaviour is detected.
We may also share some data for reporting purposes, such as which organisations currently use Internal Access. Personal data will only be shared internally within DSIT.
Where your data is processed and stored
All processing is based in the UK on DSIT-managed cloud infrastructure using Amazon Web Services.
How long we store your data
Your personal data is retained so long as you are an active user of this service, and for one year for security purposes. IP addresses, browser and connection details are retained for one year for security purposes.
Logs are retained for at least 90 days to support deprecation monitoring and incident review.
How we protect your data and keep it secure
We are committed to doing all that we can to keep your information secure. This is why we store and process only the information required for Internal Access to work, and for security monitoring and reporting purposes.
Log data is accessible only to the team operating the service and is not shared with third parties.
All data is encrypted both at rest and in transit.
Data subject rights
You have the right to:
- request information about how your personal data are processed, and to request a copy of that personal data.
- request that any incomplete personal data are completed, including by means of a supplementary statement.
- request that your personal data are erased if there is no longer a justification for them to be processed.
- request, in certain circumstances (for example, where accuracy is contested), that the processing of your personal data is restricted.
- object to the processing of your personal data where it is processed for direct marketing purposes.
- object to the processing of your personal data.
- withdraw consent to the processing of your personal data at any time.
- request a copy of any personal data you have provided, and for this to be provided in a structured, commonly used and machine-readable format.
Questions and complaints
The contact details for our Data Protection Officer are:
Department for Science, Innovation and Technology
22-26 Whitehall
London
SW1A 2EG
dataprotection@dsit.gov.uk
You may also make a complaint to the Information Commissioner, who is an independent regulator set up to uphold information rights.
Wycliffe House
Water Lane
Wilmslow
SK9 5AF
casework@ico.org.uk
0303 123 1113
Changes to this notice
We may change this privacy notice. In that case the ‘last updated’ date at the top of this page will also change. Any changes to this privacy notice will apply to you and your data immediately. If these changes affect how your personal data is processed, the Department for Science, Innovation and Technology (DSIT) will take reasonable steps to make sure you know.