Internal Access privacy notice

Last update: 10 July 2026

Internal Access is a single sign on service for the public sector. In order to make the service secure and available, we need to collect, process and store some personal data.

What data we collect

Internal Access is only used to authenticate users through authorised email addresses. We do not collect or store any data except that which is needed for this purpose, or for maintaining the performance of this service.

We collect:

  • active session state
  • token metadata (not token values)
  • structured logs which include client ID, endpoint, event type and email addresses

Legitimate interests (UK GDPR Article (6)(1)(f))

When we process your personal data for security monitoring and reporting purposes, the legal basis we rely on is that the processing is necessary for the Department of Science, Innovation and Technology’s (DSIT) legitimate interests, which is to protect Public Sector Sign in and its users against security threats, and to ensure the ongoing performance of the service.

Who we share your data with

Your personal data may be shared with security teams in your organisation in relation to security incidents, such as if malicious behaviour is detected.

We may also share some data for reporting purposes, such as which organisations currently use Internal Access. Personal data will only be shared internally within DSIT.

Where your data is processed and stored

All processing is based in the UK on DSIT-managed cloud infrastructure using Amazon Web Services.

How long we store your data

Your personal data is retained so long as you are an active user of this service, and for one year for security purposes. IP addresses, browser and connection details are retained for one year for security purposes.

Logs are retained for at least 90 days to support deprecation monitoring and incident review.

How we protect your data and keep it secure

We are committed to doing all that we can to keep your information secure. This is why we store and process only the information required for Internal Access to work, and for security monitoring and reporting purposes.

Log data is accessible only to the team operating the service and is not shared with third parties.

All data is encrypted both at rest and in transit.

Data subject rights

You have the right to:

  • request information about how your personal data are processed, and to request a copy of that personal data.
  • request that any incomplete personal data are completed, including by means of a supplementary statement.
  • request that your personal data are erased if there is no longer a justification for them to be processed.
  • request, in certain circumstances (for example, where accuracy is contested), that the processing of your personal data is restricted.
  • object to the processing of your personal data where it is processed for direct marketing purposes.
  • object to the processing of your personal data.
  • withdraw consent to the processing of your personal data at any time.
  • request a copy of any personal data you have provided, and for this to be provided in a structured, commonly used and machine-readable format.

Questions and complaints

The contact details for our Data Protection Officer are:

DSIT Data Protection Officer
Department for Science, Innovation and Technology
22-26 Whitehall
London
SW1A 2EG
dataprotection@dsit.gov.uk

You may also make a complaint to the Information Commissioner, who is an independent regulator set up to uphold information rights.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
SK9 5AF
casework@ico.org.uk
0303 123 1113

Changes to this notice

We may change this privacy notice. In that case the ‘last updated’ date at the top of this page will also change. Any changes to this privacy notice will apply to you and your data immediately. If these changes affect how your personal data is processed, the Department for Science, Innovation and Technology (DSIT) will take reasonable steps to make sure you know.