Privacy Policy

We're committed to respecting your privacy on our website

Carter Brown is a registered Limited Company (Company Number: 04547728) that provides independent expert witness assessments for solicitors, courts, local authorities and organisations. Our registered address is 2nd Floor, c/o The Antser Group, 122 Colmore Row, Birmingham, B3 3BD, United Kingdom.

At Carter Brown, we are committed to ensuring that the privacy and personal information we handle is protected .Therefore, we strictly adhere to the provisions of the Data Protection Act 2018 and are compliant with the UK General Data Protection Regulation (GDPR) (together “the Data Protections Laws”) 2021.

This Privacy Notice sets out how we use and protect any information you give us including when you use this website. If we ask you to provide any information by which you can be identified, be rest assured that it will only be used in accordance with the terms of this Privacy Notice.

We have appointed a Data Protection Officer who shall oversee questions in relation to this Privacy Notice. If you have any questions about this Privacy Notice including any requests to exercise your legal rights, please contact the Data Protection Officer by emailing DPO@antser.com or alternatively referrals@carterbrownexperts.co.uk

You may also contact our Carter Brown team on 01623 661089.

Please note that we may change this Privacy Notice from time to time by updating this page. You should check this page to ensure you are satisfied with any changes.

How do we collect information?

This notice outlines what information we collect, where we get it from, what we use it for, and how we store it.

For assessment work, we are provided with the personal information from the instructing parties on a case and/or from the independent expert witnesses registered with Carter Brown who undertake the assessments and provide the report.

Carter Brown is therefore a Data Processor/Joint Data Processor for this information. The Data Controllers will be the individuals or organisations (I.e. solicitor, local authority, court) who gather the information to be supplied to Carter Brown and its associate experts to undertake the work on its behalf. We therefore recommend that you understand or contact the Data Controller of your personal information with any queries related to their handling of your personal data.

Personal information is provided to us from respective Data Controllers via the following routes:

  • Assessments completed within family law proceedings: The information is provided to our service via the lead solicitor and / or other instructed parties, including the Local Authority.
  • Assessments completed within criminal law proceedings: The information is provided to our service by the instructing party solicitor or the Crown Prosecution Service.
  • Assessments completed within pre-proceedings: The information is provided to our service via the Local Authority.
  • Assessments completed for the purpose of assessing alternative carers i.e. Form F assessments, Adoption assessments, Connected Persons assessments and Special Guardianship assessments: The information is provided to our service via the Local Authority.
  • For any other assessments the information is either received via the instructing service or via the data subject.

All information is obtained either electronically (via secure email or passworded documentation) or sent via the postal or a recognised courier service.

What type of information is collected?

The personal information collected for the purpose of the assessment process may include:

  • Identifying information i.e. names
  • Contact information i.e. address and telephone number
  • Social services records
  • Criminal records
  • Medical records
  • Family history
  • Culturally specific information
  • Educational and employment information
  • Information regarding physical or mental health conditions
  • Lifestyle information
  • Results of relevant tests

Marketing

  • Basic technical information about your visits to and use of this website which is automatically collated (including your IP address, geographical location, browser type and version, operating system type and version, referral source, length of visit, page views, website navigation paths and service usage).
  • Information collected for relevant marketing purposes, including data that helps us tailor our advertising and promotional communications.
  • Marketing and communications data is your preferences in receiving marketing from us and our third parties and your communication preferences.

Employees, contractors or associates – we may collect and process the following further information about you:

  • Date of birth
  • Gender
  • Marital status and dependents
  • National insurance number
  • Bank account details, payroll records, and tax status information
  • Salary, annual leave, pension, and benefits information
  • Criminal conviction history via a DBS check
  • Professional registration numbers/details
  • Previous employment history
  • Professional references from individuals you nominate

We will not share your personal information with organisations, so that they can contact you for any marketing activities.

Why and how is your information used?

We will only use personal information when the law allows us to. These are known as the legal bases for processing. We will use personal information in one or more of the following circumstances:

  • Where we need to do so to perform the contract or agreement we have entered 
  • When consent has been obtained
  • To comply with a Legal obligation
  • In the interest of a Public task

We use the personal information collected in order undertake the requested assessment or assignment; the information is triangulated with other information to form an evidenced based recommendation within the substantive report provided to the relevant instructing party or person.

We will not share your personal information with organisations, so that they can contact you for any marketing activities. Nor do we share any information about your web browsing activity.

Legal Disclosures: We may disclose your information if required to do so by law (for example, to comply with applicable laws, regulations and codes of practice or in response to a valid request from a competent authority).

Employees, contractors or associates

We collect your personal data via the application and recruitment process, either directly from you or sometimes via an employment agency or background check provider. We process your data in the following circumstances:

  1. Where we need to fulfil our contractual obligations with you. 
  2. Where we need to comply with a legal obligation.
  3. Where it is necessary for legitimate interests pursued by us or a third party and your interests and fundamental rights do not override those interests.

We may also under specific circumstances use your personal information in the following situations:

  1. Where we need to protect your interests (or someone else’s interests).
  2. Where it is needed in the public interest or for official purposes.

We will use your data for the following purposes:

  • Submitting you through our application or formal recruitment procedures
  • Checking you are legally entitled to work in the UK
  • Verifying references and your identity
  • Determining the terms and conditions on which you work for us.
  • Conducting routine compliance checks to ensure that you are still able to work with us (i.e. updated DBS, professional indemnity insurance, professional registration)
  • Paying you and, if you are an employee or deemed employee for tax purposes, deducting tax and national insurance contributions (NICs).
  • Providing your payroll details to our Payroll provider (employees only)
  • Setting up and paying your pension through a nominated pension provider as per your contract.
  • Complying with our contract with you.

To support our recruitment screening and compliance checks we use third party HR software through Zincwork.com. Further information will be provided to you during the recruitment process regarding this before proceeding.

Marketing Communications

With your consent or where we have a legitimate interest, we may use your personal information to contact you with relevant marketing material, including:

  • Updates about upcoming events and promotions
  • Exclusive offers and discounts
  • Newsletters containing industry insights, company news, or product updates
  • Other marketing content that we believe may be of interest to you

You can opt out of receiving marketing communications at any time by following the unsubscribe link in our emails or by contacting us directly.

Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are your consent and where we have a legitimate interest.

How do we store the personal information?

We store the personal information provided to us on a number of systems used by the company to operationally manage the services we provide. This includes the following:

  • Our secure cloud based (password- and firewall- protected) servers to which only contracted employees or approved contractors/associates/clinicians have specific and restricted access to – this hosts email accounts, calendars, clinical records, reports.
  • Lockable filing cabinets – to store handwritten clinical records and assessment booklets.
  • Secure cloud-based accounting software to process invoices and payment records

We take all reasonable technical and organisational precautions to prevent the loss, misuse or alteration of personal information.

How long do we hold information for?

We will only process and keep personal data for as long as we need to in order to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, account or reporting requirements.

Unless we notify you otherwise on this privacy notice, we will retain personal information based on the following criteria:

i. For as long as we are required to do so by law (if it is mandatory for us to retain the data).

ii. If we believe that the personal data is or may become relevant to any ongoing or prospective legal proceedings we may need to keep the data for longer.

iii. For as long as necessary in order to exercise, defend or establish our legal rights (including providing our information to others for the purpose of fraud prevention or reducing credit risk).

For associates / clinicians – In line with the legal basis on retaining details of individual linked to children’s data (via the assessment work undertaken) we will retain data of recruited associates (those successfully completing the recruitment process) for a minimum of 75 years following completion of the last assessment with Antser Group companies. This is to enable us to undertake any assignment work requested and for us to fulfil our legal obligations and for the establishment, exercise or defence of legal claims.

For applicants to be Self Employed Contractors (Associates/Assessors) with Antser Group companies who are unsuccessful, any information provided will be deleted. A record of your name and reason for not progressing will be logged on our central spreadsheet for future reference and will not be kept for any longer than is necessary.

Please let us know if the personal information that we hold about you needs to be corrected or updated, including when your contact details change. You can contact DPO@antser.com any time with updates.

Details of how long we keep personal data is available in our retention policy which can be provided upon request.

Change of purpose

We will only use the information provided for the purposes for which we collected it. If we need to use the information for a purpose other than that for which it was collected, we will provide you, prior to that further processing, with information about the new purpose, we will explain the legal basis which allows us to process such information for the new purpose and we will provide you with any relevant further information. We may also issue a new privacy notice.

Who has access to your information?

Relevant employed individuals within the service have access to personal information for the purpose of processing the assessment. These include personnel from the following teams:

  • The referrals team: this team initially allocate the assessment based on the information received to a relevant and experienced assessor.
  • The case handling team: This team ensure that the information is processed securely, sent securely to the relevant assessor, deal with any specific queries throughout the assessment process and ensure the assessment is filed on time.
  • The quality assurance team: Reads the assessment to ensure the report is of a quality standard, they provide feedback to the assessor regarding spelling, grammar and content. 
  • Management: to monitor the processing of all assessments and to ensure any issue is dealt with in line with policy and procedure.

Each employee has been fully trained to adhere to our policies and procedures regarding data protection and confidentiality when dealing with any personal data.

Third Party Service Providers we work in association with

Following approval from the instructing client (solicitor, local authority, court etc.) that Carter Brown and their assessor are approved to proceed with the case, we pass your information to our third party subcontractors (assessors) for the purposes of completing the assessments. We disclose only the personal information that is necessary to deliver the service i.e. assessment (as provided to us by the instructing lead party – i.e. solicitor or local authority).

We have a contract in place that requires them to keep your information secure and not to use it for any other purpose than the assessment. In addition to a contract, all providers are subject to rigorous checks including an enhanced DBS check, provision of professional indemnity insurance, receipt of references, evidence of qualifications and professional registrations, completion of an interview and provision of a full CV and application form.

We may also need to share personal information with a regulator or to otherwise comply with the law.

We will not sell or rent your information to third parties.

We will not share your information with third parties for marketing purposes.

Security of personal information

We are committed to ensuring that your personal information is secure and have in place measures to protect the security of your information. In this respect, we have put in place, all appropriate internal policies, procedures and controls, for implementing reasonable technical and organisational precautions to, prevent your information from being accidentally lost or destroyed, altered, disclosed or used/ accessed in an unauthorised way.

The technical and organisational precautions include, (but are not limited to) the following:

(i) We limit access to information to those employees, workers in order to perform their job duties and responsibilities.

(ii) Where information is shared with third party service providers, we require them to take appropriate technical and organisational security measures to protect information and to treat it to a duty of confidentiality in accordance with the relevant Data Protection Laws and Guidance.

(iii) We have in place procedures to deal with a suspected data security breach, in which case we notify the ICO (or any applicable supervisory authority or regulator) and the data subject of the suspected breach (where we are legally required to do so).

The security measures that we have in place include:

  • Staff training in general security awareness and cyber security
  • Policies concerning the use of email and company equipment, and mobile working
  • Staff can only access our servers through company laptops
  • Company laptops have encryption, multi factor authentication and anti-virus software installed, and this software is kept up-to-date
  • Use of cloud-based software that is secure
  • Backup system for personal data
  • Secure disposal of personal data

Whilst these security measures will help to protect your personal data, we cannot guarantee that the information shared with us is 100% secure.

International transfers

We use an approved third party contractor based outside of the United Kingdom to support financial processing of your data. This is solely for the purpose of financial and payment transactions. For example, they will supply invoices, remittances, arrange and process payments and record transactional data for the services we undertake. 

The contractor is contractually bound to comply and uphold all UK GDPR relating to the processing of personal data. This is in addition to being required to meet company policy, procedure and training requirements prior to processing any data on our behalf. 

These transfers are managed entirely through secure VPN access to our cloud based servers where the information is securely held and not transferred via email or other online data transfers.

Access is approved by senior management and certified by our IT team. It is reviewed frequently to ensure proper use and revoke access where necessary.

  • Data protection rights

Under data protection law, you have rights including:

  • Your right of access – You have the right to ask us for copies of your personal information.
  • Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
  • Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
  • Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances.
  • Your right to object to processing – You have the right to object to the processing of your personal information in certain circumstances.
  • Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

Please note that they do not apply in all circumstances, and we will explain in writing if you exercise a right that in our view does not apply. If the request is deemed manifestly unfounded or excessive, we may also exercise our rights to deny your request in these circumstances.

If we receive a request from you to exercise your rights under Data Protection Legislation, we will ensure the following:

  1. A response to your request is normally provided within One (01) Month of the date we receive your request. The date count will start on a later date if we ask you to clarify your request, or for proof of your identity, or if you act on behalf of someone else and we ask for proof of your authorisation.
  1. Our response will be jargon free and in plain English.
  1. You will not normally be charged for our response to your requests. We can lawfully charge a reasonable fee (or refuse to comply) if your request access is unfounded or excessive.

If you have provided us with your contact details, we may send you information about our work. However, you may instruct us at any time not to process your personal information for marketing purposes. In practice, we will usually either ask for your consent to our use of your personal data for stated marketing purposes, or we will provide you with an opportunity to opt out of the use of your personal data for stated marketing purposes.

If you would like to make a request in line with the above rights, please contact us on the number and/or email address provided within this notice.

How to contact us or to make a complaint

You also have the right to make a complaint at any time to the Information Commissioner. We would however, appreciate the chance to deal with your concerns, before you approach the ICO, so please contact us in the first instance.

If you have any queries or concerns about our use of your personal information, please contact us and we’ll do everything we can to address your concerns. Please address your email to our Data Protection Officer:

Amy Callaghan – Data Protection Officer

referrals@carterbrownexperts.co.uk / DPO@antser.com 

Alternatively, you can also complain to the ICO if you are unhappy with how we have used your data.

The ICO’s Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Helpline Number: 03031 231 113ICO website: ico.org.uk


Last updated 12th March 2026

Have a question for our team? We're here to help

Contact Us Ready to make a Referral?