LEGAL

Privacy Statement

May 12, 2026

Personal Data Privacy Notice

Purpose

Northern Gas Networks (“NGN”) is committed to protecting the privacy and security of your personal data. NGN is a Controller meaning that we are required to register with the Information Commissioner’s Office. Our registration number is Z7620325.

This privacy notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, together “Data Protection Laws”.

It is important that you read this statement, together with any other privacy statement we may provide on specific occasions when we are collecting or processing personal data about you, so that you are aware of how and why we are using such information.

The Type of Information We Hold About You

We will collect, store, and use some or all the following categories of personal data about you:

* Personal contact details such as name, title, addresses, telephone numbers, and personal email addresses.
* Date of birth.
* Gender.
* Details of a secondary contact (name and telephone number).
* Energy usage (e.g., meter readings and units of gas used over time).
* Financial information (bank account or card details).
* Your Meter Point Reference Number (MPRN) that identifies your gas supply.
* Whether you are a homeowner or renter.
* Details of your income and whether you are in receipt of state benefits.
* CCTV footage of you from our offices or our vehicles (dashcam footage).
* Telephone recordings.
* Survey responses.
* Information about you in connection to a legal claim, such as personal injury claims.
* Where you visit our website, your IP address, and your behaviour on our website (e.g., the links you click) – these are referred to as ‘Cookies’.
* If you visit and park at our offices, we may record your vehicle registration number.
* Any other personal data relating to you that you provide to us or that we generate about you in connection with our relationship with you, including records of any consent you have provided.

Special Categories of Data

The following special categories of data may also be processed and therefore require a higher level of protection:

* Information about your health, including medical conditions, disabilities, or vulnerabilities.
* Details relating to a suspected criminal offence, such as tampering with gas meters.

How Is Your Personal Data Collected?

We collect personal data that you provide directly to us in relation to any of our services where you:

* Communicate with us by phone, email, forms, letter, social media or in person.
* Agree to participate in surveys, questionnaires, and other research activities.
* Request to join schemes that you may be eligible for.
* Visit our website and agree to the use of cookies which track information about your activity on the website.

Information Collected From Third Parties

We may also receive personal data about you from third parties who are essential to the services we provide, such as:

* Xoserve for Meter Point Reference Numbers (MPRN) and other associated data.
* Other utility companies to receive information relating to individuals on the Priority Services Register (PSR), to obtain your contact details to carry out essential work on the utility company’s behalf, to notify you of any planned or unplanned interruptions to your gas supply or where a member of the public has contacted them to report a suspected gas leak.
* Local authorities, councils, housing associations and other landlords to provide us with contact details to arrange for work to be carried out.
* The Courts in relation to any legal claims that we are a party to.
* Our regulators, such as Ofgem regarding any complaints or enquiries directed to NGN.

In addition, we may collect personal data from other publicly available sources (e.g., the Land Registry).

If You Don’t Provide Your Personal Data to Us

If you fail to provide certain information when requested, we may not be able to carry out essential services, such as providing you with a gas connection, or we may be prevented from complying with our legal and regulatory obligations (such as the health and safety of our customers).

How We Use Your Personal Data

All the processing carried out by us falls into one of the permitted reasons set out under our lawful bases for processing your personal data.

We may process your personal data to:

* Respond to a gas emergency at your property or where we receive a report of an emergency from you.
* Notify you of any work that NGN may be carrying out in your area.
* Consult with you when our work may affect your property.
* Provide or maintain gas connections to your premises.
* Effectively deal with any communications you send to us.
* Monitor and/or record conversations for staff training and/or audit purposes.
* Obtain your views on NGN’s services, projects, and proposals.
* Investigate, respond to and/or process any complaints, claims for loss, damage and/or injury.
* Process data that is required or requested by regulatory bodies or law enforcement agencies.
* Manage attendance at NGN events or workshops.
* Arrange access to our on-site facilities.
* Sign you up to the Priority Services Register.
* Collect personal data during home visits.
* Process requests made in connection to your data rights or environmental information held by NGN.
* Process payments made to you.
* Send you industry relevant communications.

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the lawful basis which allows us to do so.

Our Lawful Bases for Processing Your Personal Data

We will only process your personal data where Data Protection Laws allow us to. Most commonly, we will use your personal information in the following circumstances:

1. Where you have provided your consent (which can be withdrawn at any time).
2. Where we need to perform the contract that we have entered with you.
3. Where we need to comply with a legal obligation.
4. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

Examples of legitimate interests include:

* Monitoring and securing our systems to prevent unauthorised access.
* Detecting and preventing fraud.
* Managing relationships with third parties such as suppliers and contractors.
* Researching, developing and making improvements for the benefit of our customers.
* Sending relevant email communications.

Although uncommon, we may also use your personal information where we need to protect your vital interests or where it is needed in the public interest (or for official purposes).

Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal data.

Our Lawful Bases for Processing Your Special Category Data

Special categories of data require a higher level of protection and so we must process it in accordance with more stringent guidelines.

Most commonly, we will process special categories of data when:

1. You have given explicit consent to the processing.
2. It is needed for reasons of substantial public interest, such as equal opportunities monitoring and safeguarding of individuals at risk.

Less commonly, we may process this type of information where it is needed in relation to legal claims, to protect your interests (or someone else’s interests) and you are not capable of giving consent, or where you have already made the information public.

Who We Share Your Personal Data With

We may share your personal data with third parties where required by law or where we have a legitimate interest in doing so.

Recipients of your personal data may include:

* Suppliers and contractors working on NGN’s behalf.
* Your registered utilities company in order to process a request.
* Emergency services such as police, fire and ambulance.
* Local authorities, courts and tribunals, regulatory bodies such as Ofgem and HSE, and/or law enforcement agencies.
* Other utility companies where we register you on the Priority Services Register.
* Relevant partners to assess your eligibility for financial support schemes, where we have your consent.
* Other entities in our group for reporting activities, business reorganisation, system maintenance support and data hosting.

How Secure Is My Personal Data With Third Parties?

All parties we share personal data with are required to take appropriate technical and organisational measures to protect your information in line with our policies.

We do not allow third-party service providers to use your personal data for their own purposes. We put legally binding contracts in place to ensure they only process your personal information on our instructions and are subject to confidentiality obligations.

Transferring Personal Data Outside the EEA

There is not a requirement to transfer the personal information we collect about you to countries outside the EU.

Data Security

We have put in place appropriate technical and organisational measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

Measures include, but are not limited to:

* Encryption.
* Auditing procedures.
* Data integrity checks.

We also limit access to your personal information to employees, agents, contractors and other third parties who have a business need to know.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator where legally required.

Data Retention

In line with data protection principles, we only keep your data for as long as necessary to fulfil the purposes we collected it for, including legal, accounting or reporting requirements.

Typical retention periods include:

Data Category                                                                     Retention Period 
Queries, complaints, correspondence and claims       6 years
Recruitment data                                                               At least 6 months after application
Legal and regulatory requirements                                Varies depending on the requirement

When it is no longer necessary to retain your data, it will be securely destroyed in accordance with our Data Retention Policy.

In limited cases, the law permits us to keep your personal information indefinitely provided appropriate protections are in place.

Automated Decision-Making

No decision will be made about you solely on the basis of automated decision-making which has a significant impact on you.

Your Data Subject Rights

Data Protection Laws provide you with certain rights in respect of your personal data, including the right to:

* Request information about the collection and use of your personal data.
* Request access to your personal data.
* Request correction or completion of your personal data.
* Request erasure of your personal data.
* Object to processing of your personal data in certain circumstances.
* Request restriction of processing your personal data.
* Request transfer of your personal data to another party in certain circumstances.
* Not be subject to automated decision-making and profiling.

Where you have provided consent to our use of your data, you also have the unrestricted right to withdraw that consent at any time.

To exercise any of your rights, contact: GDPR@northerngas.co.uk

Once requested, we will have one calendar month to provide a response.

No Fee Usually Required

You will not usually have to pay a fee to access your personal data or exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, excessive, or repetitive.

What We May Need From You

We may need to request specific information from you to confirm your identity before processing your request.

Third Party Links

Our website may contain links to third-party websites. This privacy notice does not apply to those organisations and we are not responsible for their privacy statements.

When leaving our website, we recommend reading the privacy notice of each website you visit.

Cookies

Like other websites, our website uses digital cookies to enhance your browsing experience.

Cookies are small text files placed on your computer by websites that you visit. They allow the website to recognise your device and store information about your preferences or past actions.

Our website provides you with the option to reject non-essential cookies.

For more information about how we use cookies, please visit our Cookies Policy.

Marketing

You will only receive emails from NGN where you have provided consent or where we believe it is in your interests to receive the communication.

This may include where you have:

* Previously attended events or workshops hosted by, or with, NGN.
* Taken part in research or stakeholder engagement activity hosted by or with NGN.
* Had your details added to our database by an employee due to an existing relationship.

From time to time, we may contact you to confirm your consent to continue receiving emails from us.

You also have the right to opt out of receiving communications from NGN every time we contact you.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee compliance with this privacy notice.

If you have any questions about this privacy notice or how we handle your personal information, please contact the DPO at:

GDPR@northerngas.co.uk

Complaints

If you are not satisfied with the response to any query you raise with NGN, or you believe we are processing your personal data in a way which is inconsistent with the law, you can complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Changes to This Privacy Notice

We reserve the right to update this privacy notice at any time and will provide you with a new privacy notice when we make substantial updates.

We may also notify you in other ways from time to time about the processing of your personal information.