Success Stories

Verne Success Story — Privacy Programme and DPMS

How Up Secure established Verne's privacy programme by building a full Data Protection Management System covering UK and EU GDPR across multi-site data centre operations.

Verne operates low-carbon data centre campuses across Iceland, Finland and the United Kingdom, with further sites in development in France and Norway. This footprint places the company under UK GDPR and EU GDPR simultaneously, with personal data flowing between group entities, colocation customers, contractors and site security systems. Up Secure was engaged to establish the privacy programme from the ground up by designing and implementing a full Data Protection Management System (DPMS) — a documented, operational framework that makes data protection an ongoing business process rather than a one-off compliance exercise.

Data Mapping and Records of Processing

The programme began with a structured mapping of processing activities across HR, commercial, customer operations and physical site security. Each activity was documented with its purpose, legal basis, categories of data subjects and data, retention period, recipients and transfer mechanism, producing Article 30 records for both controller and processor roles.

Particular attention was given to processing that is characteristic of data centre operations: CCTV and access control at secure facilities, visitor and contractor logs, and identity verification for customer engineers attending site. These were assessed for necessity and proportionality, with retention periods shortened where the original justification did not hold.

DPMS Documentation and Governance

A complete documentation set was built and put into operation: the privacy policy framework, a retention schedule, a data subject rights procedure, a personal data breach procedure, a DPIA methodology with threshold assessment, an international transfer procedure, and privacy by design requirements for new systems and projects. Roles and responsibilities were defined across the group, with escalation paths and a governance cadence that ties privacy decisions back to management review.

Data Subject Rights and Breach Response

Rights request handling was implemented as an end-to-end workflow with identity verification, defined response timelines and a record of the decisions taken. The breach procedure was aligned to the 72-hour notification requirement and exercised against realistic scenarios drawn from data centre operations, ensuring that the security incident and privacy response paths work together rather than in parallel.

International Transfers and Vendor Governance

Group and third-party data flows were assessed against the applicable transfer mechanisms, with standard contractual clauses, the UK addendum and transfer risk assessments applied where required. Processor and sub-processor arrangements were brought under a consistent contractual standard, and customer-facing data processing terms were reviewed so that commitments made in colocation agreements match what the organisation can operationally deliver.

What was the business impact?

Verne now has a privacy programme that is documented, assigned and demonstrable. Accountability under Article 5(2) can be evidenced rather than asserted, privacy questions arising in customer and investor due diligence are answered from a maintained record set, and new projects enter a defined privacy by design path instead of being assessed retrospectively. Because the DPMS was designed around how the business actually runs across jurisdictions, it scales with each new site rather than requiring rework. These outcomes were delivered by Up Secure.

Who did benefit from the service?

  • Compliance and Legal Officers focusing on GDPR readiness and risk management
  • Teams building products in regulated industries or processing sensitive data
  • Data Protection Officers and Privacy Specialists leading data governance efforts
  • Executives and Business Owners interested in strategic security and compliance maturity

What our customers say?

David Llewellyn
Head of Compliance and Security @Verne

[DRAFT — proposed wording, pending David’s review and approval. Not to be published as attributed until confirmed.]

Establishing our privacy programme meant building it properly from the ground up across several jurisdictions at once. Up Secure combined the legal grounding and the operational understanding to design a management system that our teams can actually run, rather than a set of documents that sit unused. We can now demonstrate accountability rather than assert it, which matters considerably in customer and investor due diligence.