Data Privacy Policy
A. Preamble
I. Purpose and scope
Protecting personal information of customers, employees and other individuals associated with Radial Equity Partners / the Motorsport Products Group (referred to as “Personal Data”) is a top priority for all affiliated companies within the group (the “Company”). Our success is dependent not only on global networking of information flows, but above all on trustworthy and safe handling of Personal Data. The Company is committed to process Personal Data only in a fair, lawful, and transparent manner and to use such Personal Data for legitimate purposes only.
As part of this commitment, the Company has established this Data Privacy Policy (the “Policy”) reflecting the Company’s global principles and standards on handling Personal Data.
II. Application and relevance
This Policy applies to all Company entities and extends to all jurisdictions in which the Company operates and does business. All Company entities are required to always implement and observe this Policy and are accountable to ensure that business is conducted in compliance with all applicable laws and regulations, including applicable data protection laws.
This Policy applies to the members of the management, all executives and all employees of the Company, and of any Company subsidiaries worldwide (altogether the “Employees”). It is every Employees’ responsibility to understand and follow this Policy and the laws and regulations that apply to the business of the Company. The Company will provide appropriate tools to assist employees, officers and directors with complying with this Policy.
This Policy is intended to ensure compliance with but does not take the place of applicable laws and regulations. If there is any inconsistency among these laws, regulations and this Policy, the highest standard should be applied. If this Policy conflicts with any local laws or legislation, the GDPR@mpgworks.com should be informed in writing immediately.
III. Related regulations and policies
This Policy describes specific rules and instructions as described in section I above, which may be supplemented by other Company policies. In the event of any conflict between this Policy and other Company policies, the relevant policy owners must be informed in writing.
This Policy is one of several policies that set out the Company’s approach to the handling of Personal Data and other information, including the following, as may be amended from time to time:
-
the MPG Intra-Group Data Processing and Transfer Agreement, including its Standard Contractual Clauses and UK Addendum;
-
the MPG IT Security Policy;
-
the MPG AI Usage Guidelines;
-
the Job Applicant Privacy Notice;
-
The HR Retention Records Policy;
-
The Employee Privacy Policy; and
-
any applicable data retention schedule and records of processing activities (ROPA).
B. Data privacy governance
Each Company entity is responsible for establishing a data privacy governance framework to ensure compliance with and accountability for applicable privacy laws. This includes implementing data protection measures in accordance with the legal requirements of the relevant jurisdiction and the requirements set out in this Policy.
Such measures include, but are not limited to:
-
Defining privacy roles and responsibilities and ensuring that the individuals understand them;
-
Raising privacy awareness among employees; and
-
Reviewing privacy framework and controls at regular intervals to incorporate latest legal and regulatory requirements and industry best practices.
Where required by applicable data protection laws, Company entities must appoint a data protection officer and notify the relevant supervisory authority of their contact details.
Based on the Company’s current activities and structure, a mandatory data protection officer appointment is not considered to be required under Article 37 GDPR, and this position shall be kept under review as the business evolves. Overall accountability for data protection sits with the person responsible for GDPR compliance at Group level, supported by the individuals responsible for the EU/UK region and for the USA region respectively. Contact for all data protection matters is GDPR@mpgworks.com.
Where a Company entity determines that specific requirements of this Policy are not applicable under local data protection laws, the Company entity may deviate from such requirements, if it documents the legal rationale for such deviation in accordance with the “comply or explain” principle. The justification must demonstrate that the local legal framework does not impose equivalent or higher standards and must be retained by the Company entity to evidence compliance, for example in the event of an internal or external audit.
C. General principles of processing personal data
I. Processing of Personal Data
Personal Data includes any information relating to an identified or identifiable living individual from which that living individual can be identified, either from that data alone or from other information.
Examples of Personal Data include names, dates of birth, addresses or contact details (both professional and private), signatures, identification numbers (such as for social security purposes, passports, or identity cards). It also includes personnel file numbers, user credentials, IP addresses of personal devices, individual real-time location data, health, economic, cultural, or social information about individuals, as well as expressions of opinion (such as in an HR appraisal record) if it relates to specific individuals. Personal Data may relate to individuals such as Employees, job applicants, consumers (such as website visitors) or individual contacts at suppliers, service partners and customers.
Processing is any activity that involves use or retention of the data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.
Pseudonymized data does not contain information which clearly identifies a person (e.g. by name or job title). It qualifies as Personal Data if the Data subject can be (re-)identified by using additional information (e.g. address, date of birth, photo etc.). Only if such re-identification is impossible, the data will be considered as being “anonymized”, and this Policy will not apply.
II. Data privacy principles
All processing of personal data within the Company must comply with to the following key principles:
-
Processing shall be fair and transparent (Fairness and Transparency). Fairness is typically achieved through transparency. This means that individuals are informed about how their data is collected, used, and shared, and that such processing is conducted in ways that respect their rights and expectations.
-
Processing shall be lawful (Lawfulness). Subject to local law requirements, any data processing activity generally requires a valid legal basis. This may include obtaining the individual’s consent, fulfilling contractual obligations, complying with legal requirements, or pursuing legitimate interests that do not override the rights of the data subject.
-
Processing shall be for limited purposes and shall be done in an appropriate way (Purpose Limitation). Personal data is collected for specified, explicit, and legitimate purposes and is not further processed in a manner that is incompatible with those purposes.
-
Processing shall be limited to what is necessary for the intended purpose (Data Minimization). The collection of personal data must be limited to what is necessary for the intended processing activity. Access should follow a strict “need-to-know” principle, meaning only Employees whose roles require access to specific data should be permitted to view or handle it. No Employee should access personal data without a clear, legitimate business reason.
-
Personal Data shall always be accurate and kept up to date (Accuracy). Reasonable measures shall be taken to ensure that Personal Data is accurate, complete, and kept up to date. Incorrect data shall be corrected.
-
Personal Data shall not be kept longer than necessary for the purpose it was collected (Storage Limitation). Personal Data is retained only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations. Once data is no longer needed, it is securely deleted or anonymized to prevent unauthorized access or use.
-
Personal Data shall always be kept secure (Integrity and Confidentiality). ROPA (“TOMs”) to protect the security, confidentiality, and integrity of Personal Data shall be taken against unlawful or unauthorized processing of Personal Data, and against the accidental loss of, or damage to Personal Data.
-
Processing and compliance with Data Privacy Laws shall be documented (Accountability). The Company needs to be able to demonstrate compliance with data privacy laws at all times.
III. Processing of sensitive personal data
Subject to local law requirements, sensitive Personal Data may include information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition (including, for example, information on pregnancy, maternity, reintegration post illness or disability) or sexual life, genetic or biometric identifiers, or information relating to criminal convictions and offences.
Company entities shall implement measures to ensure compliance with stricter rules that may apply under applicable data privacy laws for processing sensitive personal data including, where required, obtaining consent and/or limiting data processing to what is necessary to fulfil obligations under employment and social security laws.
D. Data sharing and data transfer
At times Company entities may share Personal Data with third parties outside the Company such as professional advisers (including auditors, lawyers, accountants etc.), service providers or regulators (“Third Parties”) or other Company entities where necessary and in compliance with applicable data privacy laws and this Policy.
I. Data sharing with Third Parties
Personal Data will only be disclosed to Third Parties for specific purposes and to the extent permitted by applicable data protection laws and in accordance with this Policy, in particular the Data Privacy Principles set out in section C.II above.
Company entities shall only appoint Third Parties that guarantee to implement appropriate technical and organisational measures in order to ensure that their processing activities meet the requirements of data privacy laws and ensure the protection of the rights of data subjects to carry out processing of personal data on its behalf.
When engaging an external organization or individual to process personal data on behalf of the Company (a so-called ‘third-party data processor’), the relevant Company entity shall enter into a written agreement with that third-party data processor, as required under applicable data protection laws.
A Company entity and a third party who jointly determine the purposes for which, and the manner in which, Personal Data is processed, might be considered joint data controllers under data privacy laws. If this is the case, the Company entity should consider whether the relevant agreement with the third party needs to determine each party’s respective responsibilities for compliance with data privacy laws.
Any cross-border Personal Data transfers, particularly outside the EU/EEA shall be made in accordance with section D.III of this Policy.
II. Data sharing within the Company
Personal Data may be shared within the Company if required for specific purposes and in accordance with applicable data privacy laws and this Policy, in particular the Data Privacy Principles set out in section C.II above.
To the extent required by applicable data protection laws, Company entities shall enter into the required data protection agreements (e.g. data processing agreements, joint control agreements).
Any cross-border Personal Data transfers, particularly outside the EU/EEA shall be made in accordance with section D.III of this Policy.
III. Cross-border Personal Data transfers
Personal Data shall only be transferred across borders (i.e. to a recipient in another country) if required for specific purposes and if appropriate safeguards as required by applicable law are in place. The Company entity transferring Personal Data to another country shall implement appropriate data transfer mechanisms to ensure safe third country data transfer (e.g., standard contractual clauses), where necessary.
E. Data retention / deletion
Each Company entity shall ensure that measures are in place to ensure that personal data is not retained for longer than permitted by applicable law. Personal Data should be destroyed or erased from Company IT systems when it is no longer required for the relevant specified purpose that it was collected for, provided that the Company may retain personal data in order to comply with applicable laws.
F. Data subject Rights
Data subjects are often granted certain rights under applicable data privacy laws. Each Company entity shall ensure to implement procedures and internal processes to be able to respond to data subject rights with due consideration of relevant legal requirements, in particular responding within the applicable statutory deadline (generally within one month of receipt under UK and EU GDPR, which may be extended by up to two further months for complex or numerous requests, and which may be paused to “stop the clock” where the Company reasonably requires further information to clarify or verify the request, as permitted under the Data (Use and Access) Act 2025). Typical data subject rights include (often subject to further conditions) the right to:
-
request access to Personal Data held about them by the Company and be provided information in relation to that data (including the purposes for which the data is processed, the recipients to whom that Personal Data have been or will be disclosed, how long it will be stored for, details of any automated decision-making and their right to lodge a complaint with a supervisory authority);
-
have inaccurate Personal Data amended or erased, and to have incomplete Personal Data completed;
-
request the erasure of their Personal Data (the so-called ‘right to be forgotten’);
-
object to or restrict the processing of their Personal Data (including where their personal data is processed for direct marketing purposes);
-
request that their Personal Data be transferred to another data controller or provided in a format that will permit this transfer (the so-called ‘right to portability’); and
-
object to any decision that affects them being taken solely by a computer or other automated process (including profiling).
G. Complaints handling
Each Company entity shall establish, maintain and publish a clear procedure enabling data subjects to make a complaint about how their Personal Data is handled. Where required by applicable data privacy laws – and in particular for Company entities operating in the UK under the Data (Use and Access) Act 2025 – the Company entity shall acknowledge such complaints within 30 days of receipt, take appropriate steps to respond without undue delay, and maintain a log of complaints received and how they were resolved. Any complaints should be sent to GDPR@mpgworks.com immediately so that they can be logged and assistance provided with acknowledgement and procedure.
H. Data security
The Company must ensure a level of security appropriate to the risks associated with data processing. Each Company entity shall implement appropriate technical and organisational measures to protect Personal Data from unauthorized access, disclosure, alteration, or destruction. These measures may include encryption, access controls, regular security assessments, and incident response protocols.
I. Cyber incidents
A cyber incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. Typical examples of cyber incidents include hacking and phishing attacks, malware infections, and other forms of data theft.
Each Company entity shall implement appropriate technical and organizational measures to detect, respond to, and recover from cyber incidents in accordance with applicable data privacy laws. This includes notifying the relevant data protection authorities without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach (unless the breach is unlikely to result in a risk to the rights and freedoms of individuals), and notifying affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, and providing them with the information required by applicable privacy laws, where required.
In the event of a cyber incident with potential cross-Company or Company-wide impact, all affected Company entities shall make best efforts to cooperate in a timely and coordinated manner. This includes sharing relevant information, aligning on necessary containment and mitigation measures, and supporting each other in fulfilling respective legal obligations. Such cooperation should be aimed at minimizing harm, ensuring consistent communication, and safeguarding the rights and freedoms of affected individuals.
J. Documentation / Accountability
I. General accountability
Each Company entity shall ensure that it is able to properly demonstrate its compliance with applicable data privacy laws. This includes maintaining accurate and detailed records of the following:
-
mandatory documentation under applicable data privacy laws (e.g., records of processing activities, data protection impact assessments, legitimate interest assessments etc.);
-
any consents provided by data subjects to the processing of their personal data; and
-
all data protection related policies and procedures.
II. Records of processing activities
Where required by applicable data privacy laws, each Company entity shall document all commencing and ongoing processing activities (including as part of projects, business processes and procedures) in a records of processing activities (“ROPA”).
A ROPA shall typically include the following information for each processing activity:
-
Controller (i.e. Company entity);
-
Personal Data categories processed and affected data subjects;
-
Purposes and justification for the processing activity;
-
IT-assets or other technical means relied on for that processing activity;
-
Recipients of Personal Data (including joint controllers or processors);
-
Data transfers to other countries or organizations, including (contractual or other) safeguards;
-
Applicable retention periods; and
-
Description of TOMs.
III. Data protection impact assessment
Where required by applicable data privacy laws, Company entities shall conduct a data protection impact assessment (“DPIA”) before carrying out certain types of processing activities which are likely to result in an increased privacy risk to data subjects’ interests (the High-Risk Activities). A DPIA is basically a well-documented assessment of a specific processing activity designed to identify risks arising out of this processing activity and describe the technical and organizational measures necessary to mitigate those risks as far and as early as possible.
K. Enforcement
All Employees are required to comply with this Policy. Non-compliance with this Policy is a ground for enforcement action which may include termination of employment.
L. Final provision
The MPG Executive Team shall examine this Policy at regular intervals, but at least once a year, and shall make any necessary adjustments. The MPG Executive Team shall inform all relevant Company entities of the amended content.
Each Company entity shall be required to examine whether amendments to this Policy have any implications for legal compliance in their own country or whether they conflict with the legal provisions in their respective country. They should report any findings to GDPR@mpgworks.com which should review those reports and consult with MPG Executive Team on necessary actions. If the Company entity is unable to implement the amendments for legal reasons, it shall inform GDPR@mpgworks.com immediately.