B2B mobile wholesaleBelfast, Northern IrelandUK & Europe served

ORGANISATION-WIDE DATA GOVERNANCE

GDPR Data
Protection.

How BMW embeds lawful, secure and accountable personal-data handling across its people, systems, trade relationships and device operations.

CURRENT PUBLISHED VERSION
LAST UPDATED5 August 2026

Applies across BMW’s organisational processing, business relationships and supporting operational controls from this publication date.

PRIMARY ROLEData ControllerUK FRAMEWORKUK GDPR & DPA 2018EU FRAMEWORKWhere applicableACCOUNTABILITYPolicy, controls & records
01

Introduction and commitment

This GDPR Data Protection Policy explains the organisation-wide approach taken by UL Mobiles Ltd trading as Bulk Mobile Wholesalers, referred to in this policy as BMW, we, us or our, to the responsible handling of personal data. It applies across our website, employment and contractor relationships, trade accounts, supplier relationships, commercial transactions, services and supporting business systems.

BMW treats data protection as a fundamental business responsibility, not simply a compliance exercise. Respect for personal data supports lawful trading, protects the people behind every business relationship and gives buyers, suppliers, institutions and public-sector bodies confidence in the way we operate.

This policy sets the standards by which BMW meets its obligations under UK data protection law and, where its territorial-scope rules apply, the EU GDPR. It is supported by more detailed notices, procedures, contractual controls and operational records where a particular activity requires them.

This is the current published version, last updated on 5 August 2026. It is an organisational policy and should be read with the BMW Privacy Policy and Cookie Policy.

02

Scope and who must follow this policy

This policy applies to personal data handled by BMW in any format, whether held electronically, on paper, within a device, in correspondence or in an approved business system. Everyone working for or on behalf of BMW is expected to protect personal data and follow the controls relevant to their role.

  1. 02.1

    BMW personnel. All employees, directors, contractors, temporary workers, consultants, agents and authorised representatives.

  2. 02.2

    Trade relationships. Trade buyers, account applicants, buyers' representatives, suppliers, potential suppliers and the individual contacts acting for those organisations.

  3. 02.3

    Website and enquiry contacts. Individuals who submit enquiries, applications, quotation requests, subscriptions, service requests or other information through the website or an agreed communication channel.

  4. 02.4

    Service programmes. Individuals whose data may be associated with devices, logistics, diagnostics, RMA, warranty, buy-back, refurbishment, repair or erasure activity.

  5. 02.5

    Third parties. Processors, sub-processors and professional or operational suppliers that process personal data for BMW under an appropriate agreement.

03

BMW's role as Data Controller

UL Mobiles Ltd is the Data Controller for personal data processed for BMW's own website, workforce, account management, commercial relationships, orders, supplier management, compliance, security and business administration. As controller, BMW determines why and how that data is processed and is responsible for demonstrating that the processing is lawful, fair, secure and transparent.

For a defined client service in which BMW handles personal data only on the documented instructions of a trade client, BMW may act as a Data Processor rather than controller for that specific processing. The roles, instructions, security measures, assistance duties and end-of-service arrangements are then set out in the relevant service terms or data processing agreement. BMW remains controller for its own billing, security, legal and relationship records.

  1. 03.1

    Legal entity. UL Mobiles Ltd trading as Bulk Mobile Wholesalers.

  2. 03.2

    Company number. NI721693, registered in Northern Ireland.

  3. 03.3

    VAT number. XI 478420863.

  4. 03.4

    Registered address. 37a Upper Dunmurry Lane, Dunmurry, Belfast, Northern Ireland, BT17 0AA.

  5. 03.5

    Data protection contact. [email protected]. Use Data Protection in the subject line for formal matters.

  6. 03.6

    ICO position. BMW assesses its data protection fee obligations and maintains the registration required for its processing. A registration reference is not published in this policy unless and until the current public entry has been independently verified.

04

Legal and regulatory framework

BMW's principal framework is the UK General Data Protection Regulation, the Data Protection Act 2018 and relevant electronic-communications rules, each as amended. This includes applicable changes introduced by the Data (Use and Access) Act 2025.

The EU General Data Protection Regulation applies to particular processing where its territorial-scope requirements are met. Trading with an EU organisation or holding an XI VAT number does not by itself determine that scope, so BMW assesses the actual activity, establishment, offering and monitoring involved.

Where both UK and EU requirements apply, BMW aims to satisfy each applicable framework. This policy does not claim that every legal rule applies to every record. It establishes a consistent minimum standard and requires any additional local obligation to be identified and followed.

05

Governance, ownership and responsibility

BMW's directors retain overall responsibility for data protection governance. Operational responsibility is assigned to appropriate people within the business, with a clear route for staff, suppliers and data subjects to escalate questions, incidents and complaints. Access to personal data is based on business need and role, not seniority alone.

BMW reviews whether the nature or scale of its processing creates a legal requirement to appoint a Data Protection Officer. This policy does not present BMW as having appointed a statutory DPO where that threshold has not been established. Data protection enquiries are coordinated through [email protected] and escalated internally as appropriate.

  1. 05.1

    Leadership. Approves the policy, provides proportionate resources and receives material risk or incident escalations.

  2. 05.2

    Process owners. Identify purposes, lawful bases, data fields, recipients, retention needs and security controls for the activities they manage.

  3. 05.3

    Personnel and agents. Follow authorised procedures, protect credentials, avoid unnecessary collection and report concerns immediately.

  4. 05.4

    Suppliers and processors. Meet agreed confidentiality, security, deletion, audit and incident-notification duties.

06

The seven data protection principles

The following principles sit at the centre of every BMW processing activity. They apply from the first decision to collect personal data through to secure deletion or anonymisation.

  1. 06.1

    Lawfulness, fairness and transparency. BMW identifies a lawful basis, uses personal data in a fair way and gives people clear information about what is happening.

  2. 06.2

    Purpose limitation. Personal data is collected for specified, explicit and legitimate purposes and is not reused incompatibly without a proper assessment and legal basis.

  3. 06.3

    Data minimisation. BMW collects and makes available only the personal data reasonably necessary for the stated purpose.

  4. 06.4

    Accuracy. Reasonable steps are taken to keep personal data accurate and current, and inaccurate records are corrected or marked appropriately.

  5. 06.5

    Storage limitation. Identifiable personal data is retained only for as long as its business, legal, regulatory or evidential purpose requires.

  6. 06.6

    Integrity and confidentiality. Proportionate technical and organisational measures protect personal data against unauthorised access, misuse, loss, alteration, disclosure or destruction.

  7. 06.7

    Accountability. BMW takes responsibility for compliance and maintains appropriate policies, contracts, decisions and records to demonstrate the measures it has taken.

07

Categories of personal data

The exact information depends on the relationship and purpose. Company data is not personal data by itself, but details connected with directors, employees, sole traders, beneficial owners or business contacts can be personal data.

  1. 07.1

    Business contact data. Names, job titles, company names, business addresses, email addresses, telephone and WhatsApp numbers, professional roles and contact preferences.

  2. 07.2

    Workforce data. Recruitment, employment, contractor, payroll, attendance, access, performance, training and emergency-contact information where applicable and governed by more specific internal notices.

  3. 07.3

    Transaction and commercial data. Trade applications, quotations, orders, invoices, payment references, currency, VAT route, stock enquiries, purchase records, trading history and correspondence.

  4. 07.4

    Website and technical data. IP addresses, browser and device details, security logs, referring source, pages viewed and consent records. Optional analytics data is processed only if a consent-based analytics service is introduced and activated.

  5. 07.5

    Operational data. Delivery and collection details, RMA files, warranty claims, support records, diagnostic outcomes, repair or refurbishment records and service instructions.

  6. 07.6

    Device-related data. IMEI and serial numbers, model and grade, CheckMend or blacklist results, data-erasure status, Blancco outcome records, device identity and relevant provenance evidence.

  7. 07.7

    Due-diligence and compliance data. Company, VAT, ownership, beneficial-owner, sanctions, fraud, trade-reference, source-of-stock and destination checks where proportionate.

  8. 07.8

    Marketing and preference data. Stock-offer subscriptions, consent evidence, opt-out status and areas of professional interest.

08

Purposes for which data is used

  1. 08.1

    Enquiries and applications. To understand a request, assess a trade or supplier application, prepare a quotation and continue a relevant business conversation.

  2. 08.2

    Accounts and transactions. To open and manage trade relationships, confirm orders, issue invoices, reconcile payments, arrange delivery and administer returns, warranties and RMA cases.

  3. 08.3

    Device and stock operations. To identify devices, verify status and provenance, manage diagnostics, repair, refurbishment, buy-back or recycling, document agreed erasure and maintain an auditable stock record.

  4. 08.4

    Due diligence and fraud prevention. To verify prospective and existing buyers and suppliers, detect unlawful or suspicious activity, protect funds and stock and support responsible supply-chain decisions.

  5. 08.5

    Legal and regulatory duties. To meet company, tax, VAT, accounting, customs, data protection, sanctions and other lawful reporting or record-keeping obligations.

  6. 08.6

    Business communications. To provide service and transaction updates and, where the relevant electronic-marketing rules are met, send stock offers, new-arrival notices and BMW commercial news.

  7. 08.7

    Security and improvement. To secure systems, investigate incidents, maintain business continuity, diagnose website faults and improve processes and services.

  8. 08.8

    Legal and professional administration. To obtain advice, manage insurance, audit, disputes, debt recovery, claims and genuine corporate transactions.

09

Lawful bases for processing

BMW identifies and records an appropriate lawful basis before processing personal data. More than one basis may be relevant to a connected activity, but BMW does not use consent where the person has no genuine choice. When an individual acts for a limited company, legitimate interests will often be more appropriate than contract because the organisation, rather than the contact, is the contracting party.

  1. 09.1

    Contract or pre-contract steps. For trade account administration, enquiry handling, order processing, invoicing, payment, delivery and agreed services where the individual is party to the contract or asks BMW to take steps before entering it.

  2. 09.2

    Legitimate interests. For proportionate B2B relationship management, business development, operational improvement, record keeping, security, fraud prevention, debt recovery and due diligence, after balancing BMW's need against individual rights.

  3. 09.3

    Legal obligation. For financial, tax and VAT records, company administration, customs obligations, data protection duties and lawful requests from courts, regulators or public authorities.

  4. 09.4

    Consent. For email marketing, stock-offer subscriptions, optional cookies or analytics where specific consent is legally required. Consent may be withdrawn at any time without affecting earlier lawful processing.

  5. 09.5

    Legal claims and vital interests. Where processing is necessary to establish, exercise or defend legal claims, or in a genuine emergency to protect a person's life. These bases are used only when their legal conditions are met.

10

Sensitive data, criminal-offence data and children

BMW does not ordinarily need special category data or criminal-offence data for general B2B enquiries. Where such information is genuinely necessary for employment, legal claims, safeguarding, sanctions, fraud prevention or another lawful purpose, BMW identifies both the Article 6 basis and the additional condition required by applicable law and limits access accordingly.

Free-text forms should not be used to send health information, identity documents or other sensitive material unless BMW has requested it through an appropriate channel. BMW's trade services are not directed to children, and the business does not knowingly open trade accounts for anyone under 18.

11

Processing records, data mapping and transparency

BMW maintains documentation proportionate to its processing, which may include records of processing activities, data maps, system and supplier registers, lawful-basis assessments, legitimate-interest assessments, consent records, retention decisions, data-sharing records, incident logs and relevant policy approvals.

Privacy information is provided at the appropriate point through the BMW Privacy Policy, forms, contracts, workforce notices, service documents or direct communication. If BMW receives personal data from another source, it provides the required information within the legal timeframe unless a valid exemption applies.

12

Data subject rights

Rights apply according to the facts, lawful basis and legal framework involved. They are important but not always absolute, and BMW may need to retain or continue using certain information to meet a legal obligation, protect another person's rights or establish, exercise or defend legal claims.

  1. 12.1

    Access. To receive confirmation of processing and a copy of personal data, together with the information required by law.

  2. 12.2

    Rectification. To have inaccurate personal data corrected and incomplete information completed where appropriate.

  3. 12.3

    Erasure. To request deletion in the circumstances provided by law, subject to BMW's lawful retention duties and exemptions.

  4. 12.4

    Restriction. To ask BMW to limit use of personal data in defined circumstances while an issue is resolved.

  5. 12.5

    Data portability. To receive eligible data in a structured, commonly used and machine-readable format where processing is automated and based on consent or contract.

  6. 12.6

    Object. To object to processing based on legitimate interests. BMW will assess the objection and stop unless compelling legitimate grounds or legal-claims needs justify continuation.

  7. 12.7

    Direct marketing. To object to direct marketing at any time. BMW will stop that marketing without requiring the person to explain why.

  8. 12.8

    Withdraw consent. To withdraw consent at any time for future processing based on that consent, without affecting the lawfulness of processing before withdrawal.

  9. 12.9

    Automated decisions. To receive the protections required for a solely automated decision producing legal or similarly significant effects. BMW does not currently make such decisions about trade applicants or business contacts.

  10. 12.10

    Complain. To raise a concern with BMW and to lodge a complaint with the ICO or, where EU GDPR applies, the competent EU supervisory authority.

Read the Privacy Policy
13

How BMW handles rights requests

A rights request can be made by emailing [email protected] or writing to the registered address. The request does not need to quote GDPR or use a specific form. It should explain the right being exercised and provide enough information to help BMW identify the relevant person and records.

BMW responds without undue delay and ordinarily within one calendar month after receiving a valid request or any information reasonably required to confirm identity or authority. Where the law permits an extension for a complex request or several requests, BMW will explain this within the first month. BMW may ask for proportionate identification and clarification, but will not request more personal data than necessary.

Requests are normally free. A reasonable fee may be charged, or a request may be refused, only where the law allows this, such as where a request is manifestly unfounded or excessive. Any refusal will be explained with information about the right to complain.

Use the subject line Data Protection Rights Request. BMW aims to make the process practical, accessible and appropriately documented.

14

Data security and organisational controls

BMW applies technical and organisational measures proportionate to the volume, sensitivity, context and risk of the personal data involved. No system can be guaranteed completely secure, so controls are reviewed and improved as technology, threats and business activities change.

  1. 14.1

    Access control. Personal data is available only to authorised people who need it for a defined role, using appropriate authentication and account-management practices.

  2. 14.2

    Secure communications. Approved business channels are used for correspondence, and sensitive material is moved to a more suitable route where ordinary email or messaging is not appropriate.

  3. 14.3

    System and record control. Business systems, devices, records, backups and disposal routes are selected and managed with confidentiality, integrity, availability and recovery in mind.

  4. 14.4

    Data minimisation. Forms, exports, shared files and staff access are limited to the information reasonably necessary for the task.

  5. 14.5

    Supplier assurance. Security, confidentiality, processing locations, sub-processors, retention and incident duties are considered before a provider receives personal data.

  6. 14.6

    Review and response. Security practices, permissions, supplier arrangements and incident procedures are reviewed periodically and after relevant changes or events.

15

Device erasure, IMEI verification and evidence

Devices can contain employee, customer and operational information even after they leave their original owner. Where data erasure forms part of an agreed BMW workflow and the device is technically capable of completing it, BMW uses Blancco-certified data-erasure technology to support controlled deletion and produce tamper-resistant, auditable outcome records. Failures and exceptions follow the agreed holding, escalation or return route rather than being treated as successful erasures.

IMEI and serial information is used for device identification, stock reconciliation, provenance checks and CheckMend verification. This supports BMW's commitment to handling legitimate, clean and compliant stock. An IMEI is not used to inspect unrelated device content or track an end user.

Sealed new stock and devices outside an agreed erasure service are not opened merely to create an erasure record. The exact controller and processor roles, erasure standard, evidence pack, exception route and retention period are confirmed for institutional or corporate programmes where required.

16

Personal data breaches

A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. BMW maintains procedures to identify, contain, assess, document, investigate and learn from suspected breaches. Personnel and processors must report concerns promptly through the agreed escalation route and must not attempt to conceal an incident.

Where a breach is likely to result in a risk to people's rights and freedoms, BMW will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where EU GDPR applies, the competent EU supervisory authority will be notified in accordance with the applicable rules.

Where a breach is likely to result in a high risk to affected individuals, BMW will also communicate with those individuals without undue delay unless a lawful exception applies. Every breach is recorded with the facts, effects, assessment and remedial action, including where BMW decides that regulatory notification is not required.

17

Data processors and third-party suppliers

BMW shares personal data only where there is a clear purpose and lawful basis. A processor handling personal data for BMW must be able to provide sufficient guarantees and must be bound by terms covering documented instructions, confidentiality, security, sub-processing, rights assistance, breaches, deletion or return and information needed to demonstrate compliance.

  1. 17.1

    Couriers and logistics. DHL, FedEx, UPS, Royal Mail, GLS and other appropriate providers for collection, delivery, tracking, customs and transit investigations.

  2. 17.2

    IT and website providers. Hosting, cloud, communications, CRM, accounting, support, security, erasure and maintenance providers needed to operate BMW's digital infrastructure.

  3. 17.3

    Banks and payment providers. For invoice, payment, reconciliation, fraud prevention, return and transaction management.

  4. 17.4

    Verification providers. Company, VAT, sanctions, fraud, CheckMend, device-status and trade-reference sources used for proportionate due diligence.

  5. 17.5

    Professional advisers. Legal, accounting, audit, insurance, consulting and debt-recovery professionals where their work requires relevant information.

  6. 17.6

    Authorities. Courts, regulators, HMRC, customs and law-enforcement bodies where disclosure is required or permitted by law.

BMW does not sell personal data and does not share personal data with another organisation for that organisation's independent marketing.

18

International data transfers

BMW operates from Northern Ireland and trades across the UK, European Economic Area and wider markets. Personal data may be accessed or processed in another country through logistics, cloud, communication, verification or professional services.

Transfers from the UK to the EEA can currently rely on UK adequacy regulations where their conditions are met. Transfers from the EEA to the UK can currently rely on the European Commission's UK adequacy decision where it covers the processing. BMW monitors the continuing availability and scope of those arrangements.

For a restricted transfer not covered by adequacy, BMW uses an appropriate mechanism such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses or another lawful safeguard. Transfer risk assessments and supplementary measures are used where required. A legal exception is relied on only where its conditions are genuinely met.

19

Retention and secure disposal

BMW keeps personal data for no longer than is reasonably necessary for its purpose, taking account of legal requirements, limitation periods, warranties, disputes, audit needs and the value of the record to business continuity. Retention periods may be paused where a complaint, investigation, legal hold or claim requires relevant information to be preserved.

  1. 19.1

    Financial and transaction records. Normally seven years to support HMRC, VAT, accounting, audit and legal requirements.

  2. 19.2

    Trade account and relationship records. For the active relationship and a reasonable period afterwards, based on legal, risk, continuity and limitation needs.

  3. 19.3

    Warranty and RMA records. For the claim lifecycle and a suitable period afterwards to evidence the decision, resolution and connected transaction.

  4. 19.4

    Enquiries and correspondence. For a period proportionate to the enquiry, whether a relationship followed and any legal or complaint risk.

  5. 19.5

    IMEI, CheckMend and erasure records. For long enough to support stock legitimacy, service evidence, audit, dispute and applicable legal or regulatory obligations.

  6. 19.6

    Workforce records. According to the purpose and applicable employment, tax, health and safety, limitation and record-keeping rules.

  7. 19.7

    Marketing records. Active subscription data until unsubscribe, with a limited suppression record retained afterwards so the opt-out continues to be respected.

  8. 19.8

    Website and security data. According to the relevant security, hosting, consent and analytics setting. The current website does not activate optional analytics without consent.

When retention ends, information is securely deleted, destroyed or irreversibly anonymised using a method appropriate to the record and system.

20

Data protection by design and impact assessment

BMW considers privacy at the start of a new system, form, service, supplier arrangement or material change, rather than after personal data has already been collected. Default settings should minimise collection, access, visibility and retention while still allowing the business purpose to be achieved.

A Data Protection Impact Assessment is carried out before processing that is likely to create a high risk to individuals. The assessment describes the activity, tests necessity and proportionality, identifies risk and records measures to reduce it. BMW consults the ICO before starting the processing if a high residual risk cannot be reduced to an acceptable level where the law requires consultation.

21

Accountability, awareness and review

BMW must be able to demonstrate its compliance. The evidence maintained is proportionate to the scale and risk of the business and may include policies, processing records, training records, supplier assessments, contracts, consent records, rights-request logs, breach logs, retention decisions, security reviews and impact assessments.

  1. 21.1

    Awareness. Relevant employees, contractors and agents receive data protection information appropriate to their responsibilities and are reminded how to escalate concerns.

  2. 21.2

    Processor due diligence. BMW reviews a supplier's role, access, safeguards, location, sub-processors and incident arrangements before appointment and during the relationship where appropriate.

  3. 21.3

    Policy review. This policy and the procedures supporting it are reviewed regularly and after significant legal, operational, technical or incident-driven change.

  4. 21.4

    Evidence and assurance. Material decisions are recorded so BMW can explain what was decided, why it was lawful and which controls were applied.

  5. 21.5

    Continuous improvement. Incidents, complaints, audits, rights requests, supplier reviews and staff feedback are used to strengthen controls.

22

Questions, complaints and regulatory contact

Anyone wishing to exercise a right, raise a concern or ask how BMW handles personal data should contact [email protected] or write to UL Mobiles Ltd at the registered address below. Include a name, company, contact route and enough detail for BMW to identify the matter. Do not send unnecessary identity documents until BMW requests them through an appropriate channel.

BMW aims to acknowledge and handle data protection complaints in accordance with the timeframes required by current UK law, to investigate without undue delay, keep the complainant appropriately informed and explain the outcome. Rights requests are handled under section 13 and ordinarily receive a response within one calendar month.

If the individual is not satisfied with BMW's response, they may complain to the Information Commissioner's Office at ico.org.uk. Where EU GDPR applies, they may also complain to the competent supervisory authority in the EEA country connected with the processing. BMW cooperates with competent supervisory authorities and complies with lawful regulatory requirements.

Visit the ICO website
DATA PROTECTION EMAIL[email protected]WHATSAPP+44 7425 299682
REGISTERED ADDRESS37a Upper Dunmurry Lane, Dunmurry, Belfast, Northern Ireland, BT17 0AA
REQUEST SUBJECTData Protection Rights Request or Complaint
23

Changes to this policy

BMW reviews this GDPR Data Protection Policy regularly to keep it accurate, practical and aligned with applicable law and business operations. Changes may be made when legislation, guidance, systems, services, processing activities or organisational responsibilities change.

The last-updated date at the top of this page identifies the current published version. Material changes will be highlighted or communicated through an appropriate business channel where the nature of the change makes this necessary.

DATA PROTECTION ENQUIRY

Accountability begins
with a clear answer.

Tell us the person, company, transaction or service involved and the BMW team will route the matter through the appropriate data protection process.

WRITE TO THE DATA CONTACT[email protected]INDEPENDENT UK REGULATORInformation Commissioner’s Office