Privacy and Cookies
Last updated: 15 February 2024
At a glance this is what you need to know:
We always recommend that our customers read this privacy policy in full. It explains who we are, how and why we collect personal data from you, how and why it will be processed by us and our commitment to protecting your data.
But just in case you’re on the move or do not have time to read it in full we have summarised the key points for you in our 'speed read' section below.
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited. We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
This section sets out who we are. It provides some useful information about us including our company number, registered address and data controller registration number (provided by the information commissioner’s office).
2. About this privacy policy
This section tells you when this privacy policy applies (e.g. When you use our website or communicate with us). It also lets you know how and when we will communicate updates of this privacy policy to you.
3. What personal data do we collect about you?
This section informs you of exactly what personal data we collect about you and why. This includes information that is provided to us directly by you as well as information that we gather from your visits to our website and information that we receive from other sources.
4. How is your personal data collected?
This section explains to you the different ways in which we will collect the personal data that you provide to us.
5. Purposes for which we will use your personal data
This section explains the purposes for which we will use your personal data we hold. We also set out what we consider to be the legal basis for processing your personal data for each purpose, this is to ensure that you have all the information that we are required to provide you by law.
6. Communications
This section explains how we will ensure that you only receive communications that you wish to receive. We will ensure that you have total control over the information that you receive.
7. Who will have access to your personal data?
This section explains which of our employees will have access to your personal data. It also explains the reason for our employees accessing your personal data.
8. Who else might we share your personal data with?
This section informs you of who we share your personal data with. It also explains the reason for sharing; this is largely so that we can provide our services to you.
9. How do we protect your personal data?
This section explains how we keep your personal data safe and where it will be held. It also explains how we may process your personal data outside of the United Kingdom, but that we will only do so using recognised mechanisms which offer an adequate level of protection.
10. How long do we keep your personal data?
This section explains the length of time that we will retain your personal data. It also explains why we would hold your personal data for such time periods.
11. What are your rights?
This section explains that you have rights in relation to your personal data. It also explains what these rights are and how you can go about exercising them.
12.Cookies
This section explains that our website uses cookies and where you can find further information about the cookies used.
13. Who can you ask for more information?
This section provides you with contact information should you have any questions or concerns about the way we handle your personal data. It also explains how you can contact the data protection regulator should you be unsatisfied with our response to your data protection issues.
Section expanded
1. About Great Western Railway
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited, a company registered in England and Wales under company number 05113733 whose registered office is at Milford House, 1 Milford Street, Swindon, Wiltshire, SN1 1HL.
We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
2. About this privacy policy
This privacy policy applies to the personal data we collect about you through our website (www.gwr.com) (Website), by post, by telephone, in person (for example in stations and on board), through our apps and when you otherwise communicate with us.
This privacy policy may change from time to time and, if it does, the up-to-date version will always be available on our Website. We will also tell you about any important changes to our privacy policy.
3. What personal data do we collect about you?
This section informs you of what information we collect about you and why. Personal data means any information about an individual from which that individual can be identified.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Special Category Data includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We do not seek to collect or otherwise process your Special Category Data, except where:
We use different methods to collect data from and about you including through:
Direct interactions:
We collect personal data about you if you fill in forms on the Website or correspond with us by telephone, email or otherwise. This includes information you provide when you:
We may process personal data that you manifestly choose to make public, including via social media (e.g. we may collect information from your social media profile(s), to the extent that you choose to make your profile visible).
Automated technologies or interactions:
If you use our Website, we automatically collect the following information:
The Website may, from time to time, contain links to and from the websites of advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
We also use cookies on our Website. Please see section 13 for more information.
No automated decision-making or profiling will take place using your personal data.
Information we receive from other sources:
We may receive information about you if you use any other website we operate or the other services we provide. We are also working closely with third parties, (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them, in particular where you purchase any of our products or services through such third parties. In addition, we may receive information about you from third parties who provide it to us (e.g. your employer, our customers and law enforcement authorities).
When we receive information from other sources, we rely on them having the appropriate provisions in place telling you how they collect data and who they may share it with. We carefully check our sources to ensure that we only receive your information when it is lawful for us to do so.
CCTV and Body Worn Video:
We employ CCTV and Body Worn Video (BWC) cameras (BWC include audio recording capabilities) to capture, record and monitor what takes place at our offices, stations, car parks and on our trains in order to help provide a safe environment for both our employees and customers, reduce the number of assaults on our employees, provide an accurate record of certain interactions and prevent, deter and detect crime.
BWC will only be activated when absolutely necessary. Prior to the record mode being activated, our employees will give notice that the camera is being activated and that it will make both a video and audio recording. For further information on CCTV and retention periods, please contact us using the details provided in section 13 below.
5. Purposes for which we will use your personal data
This section explains how we will use personal data you provide to us in order to carry out the activities relevant to the provision of our services to you.
We must have a legal basis for processing your personal data. We consider that we have a legal basis where:
We have set out below a list of all the ways we may use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are, where appropriate.
In some cases we may use more than one legal basis for processing your personal data; this will depend on the specific purpose for which we are using your personal data. Please contact us in section 13 if you have any queries about the specific legal basis that we rely on for processing your personal data.
At a glance this is what you need to know:
We always recommend that our customers read this privacy policy in full. It explains who we are, how and why we collect personal data from you, how and why it will be processed by us and our commitment to protecting your data.
But just in case you’re on the move or do not have time to read it in full we have summarised the key points for you in our 'speed read' section below.
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited. We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
- We have appointed a Data Protection Officer. They are responsible for our approach to data protection and protecting your privacy. You can contact them at GWR.DPO@firstgroup.co.uk.
- We process (i.e. handle) your personal data to provide our services to you. Under data protection laws, we are only permitted to process your personal data where we have a legal basis for doing so. We will only ever process your personal data in compliance with applicable law.
- We may share your personal data with our third-party suppliers, including payment processors and data analysts, to enable the efficient and secure provision of services to you. Except as explained in this privacy policy, we will not share your data with third parties without your consent unless required to do so by law.
- We will keep your personal data for as long as we need it. How long we need your personal data depends on what we are using it for, whether that is to provide services to you, for our own legitimate interests (described below) or so that we can comply with the law. We will actively review the information we hold and when there is no longer a customer, legal or business need for us to hold it, we will either delete it securely or in some cases anonymise it.
- We may transfer your personal data to a recipient located outside of the United Kingdom (UK). If we do this, we will ensure that the transfer mechanism provides an adequate level of protection, which has been recognised by the United Kingdom.
- You have important rights under laws aimed at protecting your personal data. This policy sets out your rights and how you can exercise them. For more information, read section 12. You also have the right to make a complaint to the Information Commissioner's Office if you are unhappy with how we have handled your personal data. For more information read section 13.
Contents
1. About Great Western RailwayThis section sets out who we are. It provides some useful information about us including our company number, registered address and data controller registration number (provided by the information commissioner’s office).
2. About this privacy policy
This section tells you when this privacy policy applies (e.g. When you use our website or communicate with us). It also lets you know how and when we will communicate updates of this privacy policy to you.
3. What personal data do we collect about you?
This section informs you of exactly what personal data we collect about you and why. This includes information that is provided to us directly by you as well as information that we gather from your visits to our website and information that we receive from other sources.
4. How is your personal data collected?
This section explains to you the different ways in which we will collect the personal data that you provide to us.
5. Purposes for which we will use your personal data
This section explains the purposes for which we will use your personal data we hold. We also set out what we consider to be the legal basis for processing your personal data for each purpose, this is to ensure that you have all the information that we are required to provide you by law.
6. Communications
This section explains how we will ensure that you only receive communications that you wish to receive. We will ensure that you have total control over the information that you receive.
7. Who will have access to your personal data?
This section explains which of our employees will have access to your personal data. It also explains the reason for our employees accessing your personal data.
8. Who else might we share your personal data with?
This section informs you of who we share your personal data with. It also explains the reason for sharing; this is largely so that we can provide our services to you.
9. How do we protect your personal data?
This section explains how we keep your personal data safe and where it will be held. It also explains how we may process your personal data outside of the United Kingdom, but that we will only do so using recognised mechanisms which offer an adequate level of protection.
10. How long do we keep your personal data?
This section explains the length of time that we will retain your personal data. It also explains why we would hold your personal data for such time periods.
11. What are your rights?
This section explains that you have rights in relation to your personal data. It also explains what these rights are and how you can go about exercising them.
12.Cookies
This section explains that our website uses cookies and where you can find further information about the cookies used.
13. Who can you ask for more information?
This section provides you with contact information should you have any questions or concerns about the way we handle your personal data. It also explains how you can contact the data protection regulator should you be unsatisfied with our response to your data protection issues.
Section expanded
1. About Great Western Railway
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited, a company registered in England and Wales under company number 05113733 whose registered office is at Milford House, 1 Milford Street, Swindon, Wiltshire, SN1 1HL.
We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
2. About this privacy policy
This privacy policy applies to the personal data we collect about you through our website (www.gwr.com) (Website), by post, by telephone, in person (for example in stations and on board), through our apps and when you otherwise communicate with us.
This privacy policy may change from time to time and, if it does, the up-to-date version will always be available on our Website. We will also tell you about any important changes to our privacy policy.
3. What personal data do we collect about you?
This section informs you of what information we collect about you and why. Personal data means any information about an individual from which that individual can be identified.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes first name, surname, username or similar identifier, marital status, title, date of birth, gender and CCTV footage.
- Contact Data includes billing address, delivery address, postcode, email address and telephone numbers.
- Financial Data includes bank account and payment card details.
- Transaction Data includes details as to your journeys, details about payments to and from you and other details of products and services you have purchased from us.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
- Profile Data includes your username and password, purchases or orders made by you, any interests communicated to us to enable the personalisation of services, travel preferences, feedback and survey responses.
- Usage Data includes information about how you use the Website, products and services.
- Health Data includes information relating to your mobility and disability status to enable us to provide assisted travel and ensure that you receive the correct pricing and any information detailed within any accident reports that relates to personal injury or receipt of medical attention.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
Special Category Data includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We do not seek to collect or otherwise process your Special Category Data, except where:
- we have obtained your explicit consent prior to processing your Special Category Data (e.g. you consent to us processing your Health Data to provide travel assistance services to you);
- the processing is necessary for compliance with a legal obligation;
- the processing is necessary for the detection or prevention of crime (including the prevention of fraud) to the extent permitted by applicable law;
- you have manifestly made those Special Category Data public;
- the processing is necessary for the establishment, exercise or defence of legal rights; or
- processing is necessary for reasons of substantial public interest and occurs on the basis of an applicable law that is proportionate to the aim pursued and provides for suitable and specific measures to safeguard your fundamental rights and interests.
We use different methods to collect data from and about you including through:
Direct interactions:
We collect personal data about you if you fill in forms on the Website or correspond with us by telephone, email or otherwise. This includes information you provide when you:
- register to use our Website or app;
- buy train tickets or other products or services;
- enter a competition, promotion or survey; or
- report a problem with our Website or give us feedback.
We may process personal data that you manifestly choose to make public, including via social media (e.g. we may collect information from your social media profile(s), to the extent that you choose to make your profile visible).
Automated technologies or interactions:
If you use our Website, we automatically collect the following information:
- web usage information (e.g. IP address), your login information, browser type and version, time zone setting, operating system and platform; and
- information about your visit, including the full Uniform Resource Locators (URLs) clickstream to, through and from our Website (including date and time); time on page, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks and mouse-overs).
The Website may, from time to time, contain links to and from the websites of advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
We also use cookies on our Website. Please see section 13 for more information.
No automated decision-making or profiling will take place using your personal data.
Information we receive from other sources:
We may receive information about you if you use any other website we operate or the other services we provide. We are also working closely with third parties, (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them, in particular where you purchase any of our products or services through such third parties. In addition, we may receive information about you from third parties who provide it to us (e.g. your employer, our customers and law enforcement authorities).
When we receive information from other sources, we rely on them having the appropriate provisions in place telling you how they collect data and who they may share it with. We carefully check our sources to ensure that we only receive your information when it is lawful for us to do so.
CCTV and Body Worn Video:
We employ CCTV and Body Worn Video (BWC) cameras (BWC include audio recording capabilities) to capture, record and monitor what takes place at our offices, stations, car parks and on our trains in order to help provide a safe environment for both our employees and customers, reduce the number of assaults on our employees, provide an accurate record of certain interactions and prevent, deter and detect crime.
BWC will only be activated when absolutely necessary. Prior to the record mode being activated, our employees will give notice that the camera is being activated and that it will make both a video and audio recording. For further information on CCTV and retention periods, please contact us using the details provided in section 13 below.
5. Purposes for which we will use your personal data
This section explains how we will use personal data you provide to us in order to carry out the activities relevant to the provision of our services to you.
We must have a legal basis for processing your personal data. We consider that we have a legal basis where:
- you have given us consent to do so for the specific purposes which we have told you about - for example, we will need your consent to process any health information you provide to us, such as information relating to mobility;
- it is necessary for us to do so to enable us to provide you with the services that you have requested from us - for example, contacting you about your journey;
- it is necessary in order to fulfil our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests; or
- the law otherwise permits or requires it.
We have set out below a list of all the ways we may use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are, where appropriate.
In some cases we may use more than one legal basis for processing your personal data; this will depend on the specific purpose for which we are using your personal data. Please contact us in section 13 if you have any queries about the specific legal basis that we rely on for processing your personal data.
Personal data: how and what it is used for: