The North Sea Transition Authority (‘NSTA’) is a business name of the Oil and Gas Authority (‘OGA’), a limited company registered in England and Wales.


The NSTA respects your privacy and is committed to protecting your personal information. This Privacy Statement (‘the Statement’) will tell you how we look after your personal information and your rights in relation to your personal information and how the law protects you.

When we talk about personal information in this Statement, we mean any data which identifies you or which could be used to identify you such as your name or contact details. Your personal information may also include information about how you use the NSTA or National Data Repository (‘NDR’) websites or the Energy Portal.


  1. Important information and who we are
  2. The personal information we collect about you
  3. How your personal information is collected
  4. How we use your personal information
  5. Data Retention
  6. Disclosures of your personal information
  7. Data Security
  8. International Transfers
  9. Your Rights
  10. Complaints

1. Important information and who we are

1.1 The NSTA is the data controller and responsible for your personal information. Our registered address is Sanctuary Buildings, 20 Great Smith Street,
London, SW1P 3BT. We are registered as a company in England and Wales and our company number is 09666504. Our Headquarters is at 3rd Floor, 1 Marischal Square, Broad Street, Aberdeen, AB10 1BL.

1.2 We have appointed a Data Protection Officer (‘DPO’) who is responsible for overseeing our compliance with data protection laws and answering any questions about this Statement. If you have any questions about this Statement or any requests to exercise your legal rights, please contact the DPO using the details set out below:

Data Protection Officer
North Sea Transition Authority
Sanctuary Buildings
20 Great Smith Street


Tel: 0300 020 1010 or 0300 020 1090


1.3 Changes to the Statement and informing us of changes    

The Statement was last updated on 21st March 2022. 

It is important that the personal information we hold about you is accurate and up to date. Please let us know if your personal information changes while we hold information about you.


2. The personal information we collect about you

2.1 Personal information means any information about an individual from which that person can be identified. It does not include data where your identity has been removed (anonymous data).

2.2 For example, when you submit an application in the Energy Portal, register as a user of the NDR, register to receive information from us or engage with the NSTA or NDR website we may collect certain personal information from you. We may collect, use, store and transfer different kinds of personal information which we have grouped together as follows:

  • Identity data which includes your first, middle and/or surname, username or similar identifier and title
  • Contact data which includes your postal and/or email address, telephone numbers and date of birth
  • Transaction data which includes payments you have made for applications;
  • Technical data which includes internet protocol (IP) address, log in details, operating system and platform and other technology on devices you use to access the NSTA or NDR website
  • Profile data which includes your username and password, applications submitted by you, preferences, feedback and consultation responses
  • Usage data which includes information about how you use the NSTA or NDR website;
  • Communication data which includes information on emails and updates you have subscribed to receive from us.

2.3 We do not collect any special categories of personal information such as details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, genetic or biometric data. We may process limited information in relation to criminal convictions and offences being investigated.


3. How your personal information is collected

3.1 We use different methods to collect personal information from and about you through:

  • Direct Interactions such as corresponding with us by post, phone, emails or otherwise. Providing identity and contact details by creating an account in the Energy Portal or the NDR, subscribing to receiving information from us, responding to consultations.
  • Automated technologies or interactions. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this information by using cookies. Further information on our cookie policy can be found here cookie policy.
  • Technical data from Google Analytics.
  • Contact and transaction data from providers of payment services.

4. How we use your personal information

4.1 We will only use your personal information when the law allows us to. Most commonly we will use your personal information in the following circumstances:

  • For the purposes of discharging our statutory functions including:-
  1. Licensing activities including granting a licence and other applications in respect of a licence;
  2. Undertaking stewardship and other surveys;
  • Undertaking regulatory investigations;
  1. Gathering and publishing evidence and opinions including through consultations and carrying out research;
  2. When you provide information to the NSTA in the NDR as a Relevant Person or former licensee.
  • Where we need to comply with a legal or other regulatory obligation;
  • To establish, exercise or defend legal rights;
  • To improve our services;
  • To send communications about the NSTA which you have subscribed to (some communications may be sent using the Government Digital Service's GOV.UK Notify service).


4.2 Consent 

We may rely on consent as the legal basis for processing your personal information. You have the right to withdraw your consent as the basis on which we process your personal information. If you wish to withdraw your consent for processing for a particular purpose, please contact the DPO. The withdrawal of consent will not affect the lawfulness of the data processing before your consent was withdrawn.

4.3. Purposes for which we will use your personal information 

We have set out below, in a table format, a non-exhaustive description of the most common ways we may process your personal information. We may process your personal information for one or more lawful ground depending on the specific purpose for which we are using your data. Please contact the DPO if you need details about the specific legal ground we are relying on to process your personal information where more than one ground is set out in the table below.

Purpose/activity Type of data Lawful basis for processing 
To create an Energy Portal or NDR account
  • Identity
  • Contact
  • Discharge of our statutory functions
  • In the exercise of our lawful authority 

To manage our relationships with you, including:·       

  • Considering applications submitted in the Energy Portal
  • Managing NDR accounts and services to NDR users
  • Notifying you of changes to any of our policies
  • Asking you to complete a survey (such as the stewardship survey)
  • Considering/evaluating/publishing consultation responses
  • Asking you to leave a review
  • Identity
  • Contact        Transactional   
  • Profile    Communications
  • Discharge of our statutory functions
  • Keep our records accurate and up to date
  • In the exercise of our lawful authority
To administer and protect the NSTA and NDR websites, the NDR and the Energy Portal (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of personal information). 
  • Identity
  • Contact       
  • Technical 
  • Consent
  • Discharge of our statutory functions
  • In the exercise of our lawful authority
To deliver relevant NSTA and NDR website content and the NDR.
  • Identity     
  • Contact     
  • Transaction        Technical     
  • Profile
  • Usage 
  • Consent
  • Discharge of our statutory functions
  • In the exercise of our lawful authority
To use data analytics to improve the NSTA and NDR websites.
  • Technical
  • Usage 
  • Keep the NSTA and NDR websites updated and relevant
  • Discharge of our statutory functions
  • In the exercise of our lawful authority 


4.4 Cookies 

The NSTA and NDR websites use cookies to improve the quality of each website. Further information on our cookie policy and how to remove or disable cookies can be found in our cookie policy.


4.5 Change of purpose   

We will only use your personal information for the purposes for which we collect it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact the DPO.

If we need to use your personal information for an unrelated purpose, we will tell you and explain the legal basis which we consider allows us to do so.

We may process your personal information without your knowledge or consent in compliance where required to do so by law.

5. Data Retention

We will only keep your information as long as we need it. How long we need it for will depend on the purposes for which is was collected, our statutory duties and other legal, accounting or reporting requirements.

In determining how long we will keep your personal data we will consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those processes through other means.


6Disclosure of your personal information

We may need to share your personal information with third parties including:

  • Government departments and other regulatory bodies for the purposes of enabling them and us to carry out our respective legal and statutory functions;
  • Third parties who we may engage to process personal information on our behalf. We require all third parties to respect the privacy or your personal information and to treat it in accordance with the law. We do not allow third parties to use your personal information for their own purposes and only permit them to process your personal information for a specified purpose and in accordance with our instructions.

7. Data Security

We protect your personal information against unauthorised access, unlawful use, accidental loss, corruption or destruction.

We use technical measures such as firewalls and password protection to protect your data and the systems they are held in.

We limit access to your personal information to employees, agents, contractors and other third parties with a business need to know. They will only process your personal information in accordance with our instructions and are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data breach and will notify you and the Information Commissioner’s Office as required.

8. International Transfers

From time to time we may need to transfer your personal information to other countries, for example where personal information is being stored securely in the cloud and the servers are located in another country.

If we send your personal information outside the European Economic Area (EEA), we will ensure the country your personal information is transferred to affords a similar degree of protection by ensuring one of the following safeguards is implemented:

  • Transferring your personal information to countries that have been deemed to provide an adequate level of protection for personal information by the European Commission1.
  • Where we use providers based in the United States, we may transfer personal information to them if they are part of the Privacy Shield which requires them to provide similar protection to personal information shared between Europe and the United States2

9. Your rights

9.1 You have the right to access your personal information. In certain circumstances, you have the right to:

  • Request correction of your personal information
  • Request erasure of your personal information
  • Object to the processing of your personal information
  • Request restriction of processing your personal information
  • Request a transfer of your personal information
  • Withdraw consent you have provided for the processing of your personal information.

To request your personal information or exercise any of your other rights, contact the DPO.

9.2 Fees 

You will not normally have to pay a fee to access your personal information (or to exercise any of the rights at 9.1 above).

9.3 Information we may need from you  

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that your personal information is not disclosed to a third party who has no right to receive it.

We may also request further information in relation to your request to help us deal with it as quickly as possible.

9.4 Time Limit to Respond 

We will try to respond to all requests for personal information within 30 days. Occasionally it may take us longer than 30 days if your request is particularly complex or if you have made a number of requests. In these cases, we will notify you and keep you updated on the time scale for responding to your request.

10. Complaints

If you have any complaints about the way we process your personal information, please contact the DPO.

You also have the right to make a complaint to the Information Commissioner’s Office, which can be contacted at:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, by visiting the official ICO website or calling 0303 123 1113 or 01625 545 745.

  1. For further information see The EU's statement on the adequacy of the protection of personal data in non-EU countries
  2. For further information see information on the EU-US Privacy Shield