Verne operates low-carbon data centre campuses across Iceland, Finland and the United Kingdom, with further sites in development in France and Norway. This footprint places the company under UK GDPR and EU GDPR simultaneously, with personal data flowing between group entities, colocation customers, contractors and site security systems. Up Secure was engaged to establish the privacy programme from the ground up by designing and implementing a full Data Protection Management System (DPMS) — a documented, operational framework that makes data protection an ongoing business process rather than a one-off compliance exercise.
Data Mapping and Records of Processing
The programme began with a structured mapping of processing activities across HR, commercial, customer operations and physical site security. Each activity was documented with its purpose, legal basis, categories of data subjects and data, retention period, recipients and transfer mechanism, producing Article 30 records for both controller and processor roles.
Particular attention was given to processing that is characteristic of data centre operations: CCTV and access control at secure facilities, visitor and contractor logs, and identity verification for customer engineers attending site. These were assessed for necessity and proportionality, with retention periods shortened where the original justification did not hold.
DPMS Documentation and Governance
A complete documentation set was built and put into operation: the privacy policy framework, a retention schedule, a data subject rights procedure, a personal data breach procedure, a DPIA methodology with threshold assessment, an international transfer procedure, and privacy by design requirements for new systems and projects. Roles and responsibilities were defined across the group, with escalation paths and a governance cadence that ties privacy decisions back to management review.
Data Subject Rights and Breach Response
Rights request handling was implemented as an end-to-end workflow with identity verification, defined response timelines and a record of the decisions taken. The breach procedure was aligned to the 72-hour notification requirement and exercised against realistic scenarios drawn from data centre operations, ensuring that the security incident and privacy response paths work together rather than in parallel.
International Transfers and Vendor Governance
Group and third-party data flows were assessed against the applicable transfer mechanisms, with standard contractual clauses, the UK addendum and transfer risk assessments applied where required. Processor and sub-processor arrangements were brought under a consistent contractual standard, and customer-facing data processing terms were reviewed so that commitments made in colocation agreements match what the organisation can operationally deliver.
What was the business impact?
Verne now has a privacy programme that is documented, assigned and demonstrable. Accountability under Article 5(2) can be evidenced rather than asserted, privacy questions arising in customer and investor due diligence are answered from a maintained record set, and new projects enter a defined privacy by design path instead of being assessed retrospectively. Because the DPMS was designed around how the business actually runs across jurisdictions, it scales with each new site rather than requiring rework. These outcomes were delivered by Up Secure.