When does GDPR apply?
An EU/EEA establishment may bring processing within GDPR. A business outside the EU/EEA may also fall within its territorial scope when offering goods or services to people in the EU/EEA or monitoring their behaviour there, subject to the regulation’s conditions. A globally accessible website alone does not automatically establish that scope.
The UK GDPR is a separate regime with its own territorial rules. Applicable UAE federal, free-zone, and sector-specific data-protection laws also need assessment. This page is not a claim that TMJ is GDPR-certified or that a full compliance assessment has been completed.
Rights where GDPR applies
Rights depend on the processing, lawful basis, and applicable exceptions. They can include:
- Information about the controller, purposes, legal bases, recipients, retention, and transfers.
- Access to personal data and correction of inaccurate or incomplete data.
- Erasure and restriction in the circumstances provided by law.
- Portability for qualifying automated processing based on consent or contract.
- Objection to processing based on legitimate interests or public tasks, and objection to direct marketing at any time.
- Withdrawal of consent without affecting the lawfulness of earlier processing.
- Safeguards for solely automated decisions with legal or similarly significant effects, and a complaint to a competent supervisory authority.
Making a request
The controller and a verified rights-request channel must be confirmed before live operation. The site currently configures hello@tmgitsolutions.com as its enquiry address, not a verified DPO mailbox. You may prepare an email asking which entity holds your data and requesting the action you need.
Explain the right you want to exercise and enough context to locate the relevant correspondence. A controller may reasonably verify identity and request clarification. Avoid sending passports, passwords, or sensitive documents through an ordinary initial email.
Where GDPR applies, a controller normally responds without undue delay and within one month. The period may be extended by up to two further months for complexity or number of requests, with notice and reasons within the first month. Requests are generally free; legally permitted exceptions must be justified. This describes the legal standard, not evidence that an operational request workflow has already been verified.
Marketing and automated decisions
The current application does not run profiling, behavioural advertising, or automated decisions with legal or similarly significant effects. An AI service listing is not an AI decision system acting on website visitors.
The launch-offer checkbox indicates interest in discussing a proposed quote. It does not subscribe you to a mailing list or provide consent to unrelated marketing. Any future marketing or tracking requires separate assessment and appropriate controls.
Operational work required before a compliance claim
Publishing these pages alone does not achieve compliance. The operator still needs to:
- Confirm controller identity, verified contact details, and whether a DPO or EU/UK representative is required.
- Inventory real data flows, purposes, lawful bases, recipients, international transfers, and retention periods.
- Put suitable supplier/processor agreements and any required transfer safeguards in place.
- Validate security, access control, deletion, breach response, and rights-request procedures.
- Assess whether any high-risk processing needs a DPIA and maintain required records.
- Audit the deployed site for cookies, optional scripts, logs, and consent requirements; keep the notices aligned with actual operations.
Complaints and official guidance
Where GDPR applies, you may complain to a competent supervisory authority, including in the member state of your habitual residence, workplace, or alleged infringement. UK-related matters may fall to the ICO; UAE matters depend on the applicable regime and competent authority. You do not need to surrender statutory complaint rights to use this website.
Use the official resources below for the legal text and further guidance. A qualified adviser should review the actual business structure and processing before these drafts are adopted.