Trident Management Ltd

Trading as Trident Parking

Privacy Policy

Trident Management Ltd | Version 1.1 | Last Reviewed: July 2026

Trident Management Ltd, trading as Trident Parking, is committed to protecting the privacy of everyone whose personal data we process. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have in relation to it.

We have written this policy in plain language because we want you to understand it. If anything is unclear, or if you have a question that this policy does not answer, please contact our Data Protection Officer using the details at Section 15.

This policy was last reviewed and updated in July 2026. We review it at least annually and whenever there is a significant change to how we operate or to the law. The current version is always published at www.tridentparking.co.uk/privacy and www.tridentmanagement.uk/privacy

1. Who We Are

Trident Management Ltd, trading as Trident Parking, is a private parking management company operating as an Approved Operator under the British Parking Association (BPA) Approved Operator Scheme. We manage parking facilities on private land on behalf of landowners and site operators across our operational areas.

About Us Details
Company name Trident Management Ltd
Trading name Trident Parking — our parking enforcement activities are carried out under this brand
Registered address Suite 17, 4 Spring Bridge Road, Ealing, London, W5 2AA
Websites www.tridentparking.co.uk and www.tridentmanagement.uk
ICO registration Registered with the Information Commissioner’s Office for parking management purposes, including enforcement and associated data processing
BPA membership BPA Approved Operator — Accredited Trade Association member
Data Protection Officer Contact via dpo@tridentmanagement.uk or at the registered address above

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Trident Management Ltd is the data controller in respect of all personal data described in this policy — meaning that we determine the purposes and means of processing that data. This applies equally to processing carried out under the Trident Parking trading name.

2. What This Policy Covers

This policy covers all personal data that Trident Management Ltd processes in connection with our operations, whether under our registered name or the Trident Parking brand. We have organised it by the type of person whose data is involved, because different people interact with us in different ways and their data is handled differently as a result.

Section Who It Covers
Section 3 Motorists — people who park in car parks we manage, whether or not a Parking Charge Notice is issued
Section 4 ANPR and camera data — how we collect and use footage and vehicle data
Section 5 Appeals and complaints — people who challenge a charge or raise a concern
Section 6 Debt recovery — what happens when a charge remains unpaid
Section 7 Website visitors — people who visit www.tridentparking.co.uk or www.tridentmanagement.uk
Section 8 Landowners and client contacts — people at organisations that engage our services
Section 9 Permit holders and authorised users — people who have been granted parking entitlements
Section 10 Staff and contractors — a signpost to our internal staff privacy notice
Sections 11–15 Your rights, cookies, retention, security, and how to contact us

3. Motorists — Parking Enforcement

When you park in a car park managed by Trident Management Ltd (operating as Trident Parking), you enter into a contract with the landowner or site operator. The terms of that contract are displayed on signage at the entrance and throughout the site. By parking on the site, you accept those terms. Trident Management Ltd manages the enforcement of those terms on behalf of the landowner.

3.1 What Data We Collect

The data we collect about motorists depends on the circumstances. In all cases where a vehicle parks on a site we manage, we will capture the vehicle registration mark (VRM). If a Parking Charge Notice (PCN) or Notice of Parking Charge (NPC) is issued, or if we seek to enforce a charge, we will collect and process additional data including:

  • Vehicle registration mark (VRM) and vehicle details.
  • Date, time, and duration of parking — including entry and exit times where ANPR is in use.
  • Photographs of the vehicle, including images showing the vehicle’s position in relation to any signage, bay markings, or restrictions.
  • Registered keeper name and address — obtained from the Driver and Vehicle Licensing Agency (DVLA) or, where the vehicle is a hire or fleet vehicle, from the relevant hire or fleet company.
  • Details of the alleged contravention — the specific term or condition that was not complied with.
  • Payment records, where a charge is paid.
  • Correspondence relating to the charge, including any representations, appeals, or communications exchanged between us and the motorist or their representative.

3.2 How We Collect It

We collect motorist data through the following means:

  • ANPR cameras installed at car park entry and exit points, which automatically capture VRMs and associated timestamps.
  • On-site observation by parking attendants, who may photograph vehicles and record details manually or using handheld devices.
  • The DVLA, via the KADOE service, which provides registered keeper information in connection with a specific vehicle and a specific alleged contravention. We may only request DVLA keeper data where we have a legitimate reason to enforce a parking charge. We cannot and do not make bulk or speculative enquiries.
  • Hire and fleet companies, where a vehicle is confirmed to have been on hire at the relevant time.
  • Third-party credit reference agencies, where we need to verify or update an address in connection with recovery of an unpaid charge.
  • The motorist or their representative directly, where they contact us in connection with a charge.

3.3 Why We Process It and Our Lawful Basis

We process motorist data for the following purposes, each of which has a documented lawful basis under the UK GDPR.

Purpose Lawful Basis
Issuing a Parking Charge Notice where the terms of parking have not been complied with Performance of a contract — when you parked on our site you entered into a contract with the landowner, and we enforce the terms of that contract on their behalf
Contacting the registered keeper of the vehicle in connection with an unpaid charge Legitimate interests — our legitimate interest and that of the landowner in recovering an unpaid contractual debt
Pursuing payment of an unpaid charge, including through debt recovery agents and legal proceedings Legitimate interests — recovery of a contractual debt
Managing appeals and representations against a charge Legitimate interests — fairly determining whether a charge was correctly issued
Preventing and detecting crime, and ensuring the safety and security of the site and its users Legitimate interests — protecting the site and its users
Fulfilling our reporting and compliance obligations to the BPA, DVLA, and other regulatory bodies Legitimate interests and legal obligation — meeting the requirements of our DVLA KADOE Agreement and our contractual obligations as a BPA Approved Operator

We do not use consent as our lawful basis for processing enforcement-related data. This is deliberate — consent is not an appropriate basis where processing is necessary for a legitimate contractual or enforcement purpose, and relying on consent would create a misleading impression that motorists can simply withdraw it and avoid enforcement.

3.4 DVLA Data

We access registered keeper data from the DVLA under the terms of our KADOE Agreement — a formal agreement with the DVLA that governs when and how we may request keeper information. We are permitted to request this data only in connection with a specific vehicle and a specific alleged contravention where we intend to issue or pursue a parking charge. The data is used solely for that purpose and is not shared with any party not involved in the enforcement process.

We are required by the DVLA to notify motorists — through this privacy policy and through our on-site signage — that keeper data may be requested in connection with the enforcement of parking charges. The DVLA’s own privacy notice explains how it handles data requests from parking operators and is available at www.gov.uk/government/organisations/driver-and-vehicle-licensing-agency.

4. ANPR and Camera Systems

A number of the car parks we manage operate Automatic Number Plate Recognition (ANPR) systems. Where ANPR is in use, this will be clearly indicated on signage at the car park entrance. That signage is required by the Private Parking Sector Single Code of Practice and forms part of the information displayed to motorists before they decide whether to park.

4.1 What ANPR Captures

ANPR cameras capture the vehicle registration mark and a timestamp as a vehicle enters and exits the car park. The system uses this data to calculate the duration of stay and to compare it against the permitted parking period or tariff applicable to that site. The system does not capture or process biometric data and does not recognise or record the faces of vehicle occupants.

4.2 Retention of ANPR Data

Where a vehicle’s stay does not result in an alleged contravention, ANPR data is retained for a maximum of 28 days and then permanently deleted. This period allows time for any late-flagged issues to be identified before data is destroyed.

Where a vehicle’s ANPR data is linked to the issuance of a Parking Charge Notice, that data is retained for the duration of the enforcement process and thereafter in accordance with the retention periods described in Section 12 of this policy.

4.3 Lawful Basis

The lawful basis for processing ANPR data is Legitimate Interests — specifically, the legitimate interest of Trident Management Ltd and the relevant landowner in managing the car park effectively and enforcing the terms on which parking is offered. We have assessed this processing against the three-part legitimate interests test and are satisfied that it is necessary, proportionate, and does not override the rights and interests of motorists, who are notified of the ANPR system before they choose to park.

5. Appeals and Complaints

When you appeal against a Parking Charge Notice, or submit a complaint about our service, you will typically provide us with personal information as part of that process. This may include your name, contact details, vehicle details, and any supporting evidence — which in some cases may include sensitive personal data such as medical information submitted in support of a mitigation-based appeal.

5.1 How We Use It

We use information submitted in connection with an appeal or complaint solely for the purpose of investigating and determining that appeal or complaint. We will not use it for any other purpose. Information submitted in appeals that are escalated to POPLA (the Parking on Private Land Appeals service) will be shared with POPLA as part of the case file — POPLA operates as an independent adjudication service and has its own privacy notice, available at www.popla.co.uk.

5.2 Sensitive Personal Data

Where you provide sensitive personal data — such as medical information or information about a disability — in support of an appeal or complaint, we will handle it with additional care. We will use it only to assess the specific ground of appeal or complaint to which it relates, and we will not retain it beyond the period necessary for that purpose.

5.3 Lawful Basis

The lawful basis for processing appeal and complaint data is Legitimate Interests — the legitimate interest of Trident Management Ltd in fairly determining whether a charge was correctly issued, and the legitimate interest of the individual in having their challenge properly considered. Where sensitive personal data is involved, the additional condition relied upon under Schedule 1 of the Data Protection Act 2018 is that processing is necessary for the purposes of establishing, exercising, or defending legal claims.

6. Debt Recovery

Where a Parking Charge Notice remains unpaid following the conclusion of our internal process — including any appeal — we may refer the matter to a debt recovery agent, a solicitor, or, ultimately, a court for enforcement. When we do so, we will share the personal data necessary for that process with the relevant third party.

Any debt recovery agent or solicitor acting on our behalf is subject to a data processing agreement with Trident Management Ltd, which requires them to handle personal data in accordance with our instructions and the UK GDPR. They may not use data received from us for any purpose other than the recovery of the specific debt in question.

Where a debt recovery agent pursues a debt on our behalf, they will contact you directly. If you are in financial difficulty or in a vulnerable situation, you are entitled to be treated with appropriate sensitivity and care — please refer to Section 6.1 below.

6.1 Vulnerable People and Financial Difficulty

Trident Management Ltd is committed to treating people in vulnerable circumstances fairly. If you are struggling financially, if you are experiencing a mental health crisis, or if there are other personal circumstances that make it difficult for you to engage with the debt recovery process, please contact us at the address in Section 15. We will do our best to help.

If you enter a Breathing Space period under the Debt Respite Scheme (Breathing Space Regulations 2020) — whether Standard Breathing Space or Mental Health Crisis Breathing Space — all recovery activity will be suspended for the duration of that period. Please ensure Trident Management Ltd is notified through the appropriate channel so we can act immediately.

6.2 Lawful Basis

The lawful basis for processing data in connection with debt recovery is Legitimate Interests — the legitimate interest of Trident Management Ltd and the relevant landowner in recovering a contractual debt that remains outstanding after the conclusion of the appeals process.

7. Website Visitors

When you visit either of our websites — www.tridentparking.co.uk or www.tridentmanagement.uk — we may collect certain data about your visit. This section explains what we collect, why, and how, and applies equally to both sites.

7.1 Data Collected Automatically

Like most websites, ours automatically collect certain technical information when you visit. This includes:

  • Your IP address — a numerical identifier assigned to your device by your internet service provider.
  • The type of browser and device you are using.
  • The pages you visit on our websites and the time you spend on each.
  • The website that referred you to ours, if any.

This data is collected through cookies and similar technologies. Please see Section 13 of this policy for full details of the cookies we use and how to manage them.

7.2 Data You Provide to Us

If you use a contact form, submit an online complaint or appeal, or otherwise communicate with us through either of our websites, you will provide us with personal data — typically your name, contact details, and the substance of your enquiry. We use this data solely to respond to your enquiry and to handle the matter you have raised. It will be treated in accordance with the relevant section of this policy depending on the nature of the enquiry (for example, Section 5 if it relates to an appeal or complaint).

7.3 Lawful Basis

The lawful basis for processing automatically collected website data is Legitimate Interests — the legitimate interest of Trident Management Ltd in operating functioning websites, understanding how they are used, and maintaining their security. The lawful basis for processing data submitted through our contact forms is either Legitimate Interests (for general enquiries) or Performance of a Contract (where the enquiry relates to an existing enforcement matter).

8. Landowners, Clients, and Their Representatives

Where Trident Management Ltd provides parking management services to a landowner or site operator, we will process personal data relating to the individuals at that organisation who are our points of contact — for example, the property manager, facilities manager, or managing agent responsible for the site.

The data we hold about client contacts typically includes name, job title, email address, telephone number, and correspondence exchanged in connection with the contract between us. We use this data solely to manage our contractual relationship, to provide the services agreed, and to communicate with the relevant contacts about site-related matters.

The lawful basis for this processing is Performance of a Contract (where the individual is a party to the agreement with us) or Legitimate Interests (where the individual is a contact at an organisation that is the contracting party).

9. Permit Holders and Authorised Parking Users

Where Trident Management Ltd administers a permit scheme on behalf of a landowner or managing agent — for example, a residents’ permit scheme or a staff permit scheme — we will process personal data relating to the individuals who hold or apply for those permits.

This data typically includes name, address, vehicle registration mark, and the type of permit held. We use it solely for the purpose of administering the permit scheme — issuing and renewing permits, maintaining exemption lists that enable enforcement systems to recognise authorised vehicles, and communicating with permit holders about changes to the scheme.

The lawful basis for this processing is Performance of a Contract — we issue permits on the basis of an agreement between the permit holder and the landowner, and the administration of that agreement requires us to hold the relevant data. Permit data is retained for six years from the date the permit expires or is revoked, unless the landowner’s contract with us requires a different period.

10. Staff and Contractors

Trident Management Ltd processes personal data about its employees, contractors, and agents in connection with their employment or engagement. This processing is governed by our internal Staff Privacy Notice, which is provided to all staff at the point of induction and is available on request from the Data Protection Officer.

This public-facing Privacy Policy does not cover staff data in detail — if you are a member of staff or a contractor and have a question about how your personal data is handled, please refer to the Staff Privacy Notice or contact the DPO directly.

11. Who We Share Your Data With

We do not sell personal data. We do not share personal data with any third party for marketing purposes. We share personal data only where necessary for the purposes described in this policy and only with organisations that are bound by appropriate data protection obligations.

Recipient Why We Share and Basis for Sharing
The DVLA We provide VRM data to the DVLA when making registered keeper enquiries. This is a two-way exchange — we provide the VRM and receive keeper details — governed by our KADOE Agreement.
POPLA (Parking on Private Land Appeals) Where an appeal is escalated to POPLA, we share the relevant case file — including enforcement records and any evidence submitted by the motorist — with POPLA as the independent adjudicator.
The British Parking Association (BPA) We may share data with the BPA in connection with our membership obligations, compliance monitoring, and — where relevant — the investigation of complaints escalated to them.
Landowners and site operators We share enforcement and site data with the landowner or site operator responsible for the relevant car park, as part of our management reporting obligations to them.
Debt recovery agents and solicitors Where a charge remains unpaid, we may pass the relevant personal data to a debt recovery agent or solicitor acting on our behalf. They operate under a data processing agreement with us.
Court and enforcement services Where legal proceedings are commenced in respect of an unpaid charge, relevant personal data will be included in court documentation and shared with any relevant enforcement officer.
IT and systems providers We use third-party providers for case management systems, ANPR technology, and other operational tools. These providers act as data processors under Article 28 UK GDPR agreements with us.
Payment processors Where a charge is paid online, payment data is handled by our payment processor. We do not store card details on our own systems.
Credit reference agencies Where we need to verify or update an address in connection with recovery of a charge, we may use a credit reference agency. We do not use credit reference agencies for any other purpose.
Law enforcement and regulatory bodies We may be required by law to share personal data with the police, the ICO, HMRC, or other statutory bodies. We will only do so where we are legally required or authorised to.

We do not transfer personal data outside the United Kingdom unless we have confirmed that appropriate safeguards are in place — for example, where an IT service provider operates servers outside the UK, we will ensure an Article 46 UK GDPR-compliant transfer mechanism is in place before any such transfer occurs.

12. How Long We Keep Your Data

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. The following table summarises our main retention periods. Our full Data Retention and Destruction Policy is available on request.

Category of Data Retention Period
ANPR data — vehicle not subject to a charge 28 days from date of capture, then permanent deletion
PCN / NPC — cancelled charges 60 days from date of cancellation
PCN / NPC — paid charges 6 years from date of payment (financial record requirement)
PCN / NPC — unpaid / enforcement ongoing 6 years from date of case closure
DVLA registered keeper data — no charge pursued 14 days from decision not to pursue, then deletion
DVLA registered keeper data — charge issued For the duration of the enforcement lifecycle, then 6 years
Appeal and complaint records 6 years for appeals; 36 months for complaints (Code of Practice requirement)
Website enquiry data 12 months from last contact, unless the enquiry led to an enforcement matter
Permit holder data 6 years from date permit expires or is revoked

Where a legal claim, regulatory investigation, or formal dispute is pending or reasonably anticipated, we may retain relevant data beyond the standard period until that matter is resolved. The six-year maximum in most categories reflects the statutory limitation period for contractual claims under the Limitation Act 1980.

13. Cookies and Our Websites

Cookies are small text files placed on your device when you visit a website. They help the website work properly, remember your preferences, and — in some cases — collect information about how the site is used. This section explains the cookies used on www.tridentparking.co.uk and www.tridentmanagement.uk.

Type of Cookie Purpose and Details
Strictly necessary cookies These are essential for the website to function. They enable core features such as navigation and access to secure areas. These cookies cannot be switched off. No personal data is stored beyond what is strictly required.
Analytical / performance cookies These help us understand how visitors use our websites — which pages are visited most, how long people spend on each page, and where visitors come from. This data is collected anonymously and used to improve the websites. We use analytics services for this purpose.
Functional cookies These cookies remember choices you make — for example, your language preference or whether you have accepted our cookie notice — so that we can provide a more personalised experience.
Third-party cookies Where our websites include embedded content or links to third-party services, those services may set their own cookies. We have no control over the cookies set by third parties. Please refer to the relevant third party’s privacy policy for details.

When you first visit either of our websites, you will be shown a cookie notice that allows you to accept or decline non-essential cookies. You can update your cookie preferences at any time through the cookie settings link in the footer of the website. You can also manage cookies through your browser settings — your browser’s help function will tell you how.

14. Your Data Protection Rights

The UK GDPR gives you a number of important rights in relation to the personal data we hold about you. We take these rights seriously and will always respond to a request to exercise them within the statutory timescale — one calendar month from the date we receive your request.

Your Right What It Means
Right to be informed You have the right to be told how your personal data is being used. This Privacy Policy is how we meet that obligation.
Right of access (Subject Access Request) You have the right to request a copy of all personal data we hold about you, along with information about why we hold it, who we share it with, and how long we keep it. This right is free to exercise. Our Subject Access Request Policy explains how to make a request.
Right to rectification You have the right to ask us to correct any personal data about you that is inaccurate or incomplete. If you believe there is an error in a record we hold — for example, an incorrect vehicle registration — please contact us.
Right to erasure You have the right to ask us to delete your personal data in certain circumstances — for example, where it is no longer necessary for the purpose for which it was collected. This right is not absolute: we may be entitled to retain data where we have a legal obligation or legitimate interest that overrides your request. We will always explain our reasoning if we are unable to comply.
Right to restrict processing You have the right to ask us to limit how we use your data — for example, if you dispute the accuracy of the data or have objected to its processing and we are considering that objection.
Right to data portability Where we process your data by automated means on the basis of a contract or consent, you have the right to receive that data in a structured, machine-readable format and to have it transferred to another organisation where technically feasible.
Right to object You have the right to object to processing that is based on our legitimate interests. We will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests. Note that this right does not override our ability to process data for the purpose of establishing, exercising, or defending legal claims.
Rights related to automated decision-making We do not make fully automated decisions about individuals that have legal or similarly significant effects. Where ANPR systems flag a potential contravention, a human review takes place before any enforcement decision is made.

To exercise any of these rights, please contact our Data Protection Officer using the details in Section 15. We may ask you to verify your identity before we process your request. We will respond within one calendar month; if we need longer (up to three months in complex cases), we will let you know within the first month and explain why.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at any time. The ICO is the UK’s independent data protection supervisory authority. You do not need to contact us first before going to the ICO, although we would always encourage you to raise concerns with us first so that we have the opportunity to put things right.

Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

15. How to Contact Us

If you have a question about this Privacy Policy, want to exercise any of your data protection rights, or have a concern about how we have handled your personal data, please contact our Data Protection Officer. We will always try to resolve concerns informally in the first instance.

How to Contact Our DPO Details
Email dpo@tridentmanagement.uk
Post Data Protection Officer, Trident Management Ltd (trading as Trident Parking), Suite 17, 4 Spring Bridge Road, Ealing, London, W5 2AA
Online www.tridentparking.co.uk/privacy or www.tridentmanagement.uk/privacy

For Subject Access Requests specifically, please follow the process described in our Subject Access Request Policy, which is available at either of the web addresses above. You will need to provide sufficient information to allow us to identify the records you are seeking and to verify your identity before we release any personal data.

16. Changes to This Policy

We review this Privacy Policy at least annually and whenever there is a significant change to our operations, to the law, or to the way we process personal data. When we make material changes, we will update the ‘last reviewed’ date at the top of this policy and — where the changes are significant — we will take reasonable steps to draw them to your attention.

The current version of this policy is always available at www.tridentparking.co.uk/privacy and www.tridentmanagement.uk/privacy. Previous versions are available on request from the Data Protection Officer.

Document Information
Policy Owner Head of Compliance / Data Protection Officer, Trident Management Ltd (trading as Trident Parking)
Version 1.1
Last Reviewed July 2026
Next Scheduled Review July 2027, or earlier if required by regulatory change (including the introduction of the Government’s statutory Code of Practice)
Governing Framework UK General Data Protection Regulation (UK GDPR); Data Protection Act 2018; Private Parking Sector Single Code of Practice (BPA/IPC); DVLA KADOE Agreement; Privacy and Electronic Communications Regulations (PECR); Debt Respite Scheme (Breathing Space) Regulations 2020
Published at www.tridentparking.co.uk/privacy and www.tridentmanagement.uk/privacy