Travel UpdatesLast updated:
We advice you check your journey before traveling with us today
There is a good service across our network
Last updated: 18 April 2019
But just in case you’re on the move or do not have time to read it in full we have summarised the key points for you in our 'speed read' section below.
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited. We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
This section sets out who we are. It provides some useful information about us including our company number, registered address and data controller registration number (provided by the information commissioner’s office).
This section informs you of exactly what personal data we collect about you and why. This includes information that is provided to us directly by you as well as information that we gather from your visits to our website and information that we receive from other sources.
This section explains to you the different ways in which we will collect the personal data that you provide to us.
This section explains the purposes for which we will use your personal data we hold. We also set out what we consider to be the legal basis for processing your personal data for each purpose, this is to ensure that you have all the information that we are required to provide you by law.
This section explains how we will ensure that you only receive communications that you wish to receive. We will ensure that you have total control over the information that you receive.
This section explains which of our employees will have access to your personal data. It also explains the reason for our employees accessing your personal data.
This section informs you of who we share your personal data with. It also explains the reason for sharing; this is largely so that we can provide our services to you.
This section explains how we keep your personal data safe and where it will be held. It also explains how we may process your personal data outside of the European Economic Area, but that we will only do so using recognised mechanisms which offer an adequate level of protection.
This section explains the length of time that we will retain your personal data. It also explains why we would hold your personal data for such time periods.
This section explains that you have rights in relation to your personal data. It also explains what these rights are and how you can go about exercising them.
This section provides you with contact information should you have any questions or concerns about the way we handle your personal data. It also explains how you can contact the data protection regulator should you be unsatisfied with our response to your data protection issues.
Great Western Railway (GWR, we, our or us) is a trading name of First Greater Western Limited, a company registered in England and Wales under company number 05113733 whose registered office is at Milford House, 1 Milford Street, Swindon, Wiltshire, SN1 1HL.
We are registered as a data controller with the Information Commissioner's Office and our registration number is Z9382315.
This section informs you of what information we collect about you and why. Personal data means any information about an individual from which that individual can be identified.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Special Category Data includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We do not seek to collect or otherwise process your Special Category Data, except where:
We use different methods to collect data from and about you including through:
We collect personal data about you if you fill in forms on the Website or correspond with us by telephone, email or otherwise. This includes information you provide when you:
We may also ask you to share your personal data with us if it is necessary for us to provide our services to you – for example, we may ask if you require mobility assistance when travelling.
We may process personal data that you manifestly choose to make public, including via social media (e.g. we may collect information from your social media profile(s), to the extent that you choose to make your profile visible).
If you use our Website, we automatically collect the following information:
Where we collect information about you in the ways described above, we do so on the basis that it is in our legitimate interests to collect and process this data. In most situations this will be anonymised but we collect and process this data to ensure that our site is functioning properly and that our customer experience is to the standard that you and we expect.
The Website may, from time to time, contain links to and from the websites of advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
No automated decision-making or profiling will take place using your personal data.
We may receive information about you if you use any other website we operate or the other services we provide. We are also working closely with third parties, (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them, in particular where you purchase any of our products or services through such third parties. In addition, we may receive information about you from third parties who provide it to us (e.g. your employer, our customers and law enforcement authorities).
When we receive information from other sources, we rely on them having the appropriate provisions in place telling you how they collect data and who they may share it with. We carefully check our sources to ensure that we only receive your information when it is lawful for us to do so.
We employ CCTV, on-demand audio recording and body worn video (BWV) cameras to capture, record and monitor what takes place at our offices, stations, car parks and on our trains in order to help provide a safe environment for both our employees and customers, reduce the number of assaults on our employees and prevent, deter and detect crime.
BWV will only be activated when absolutely necessary. Prior to the record mode being activated, our employees will give notice that the camera is being activated and that it will make both a video and audio recording. For further information on CCTV and retention periods, please contact us using the details provided in section 13 below.
This section explains how we will use personal data you provide to us in order to carry out the activities relevant to the provision of our services to you.
We must have a legal basis for processing your personal data. We consider that we have a legal basis where:
Where we process your personal data on the basis of our legitimate interests, these are our (or our third party’s) interests in providing our services to you in an efficient and secure manner.
We have set out below a list of all the ways we may use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are, where appropriate.
In some cases we may use more than one legal basis for processing your personal data; this will depend on the specific purpose for which we are using your personal data. Please contact us in section 13 if you have any queries about the specific legal basis that we rely on for processing your personal data.
|What we use your personal data for (purpose)
||Type of data
||Legal basis for processing (including basis of legitimate interest)
|To register you as a new customer
|Performance of a contract with you
To carry out our obligations arising from any contracts entered into between you and us including:(a) managing payments, paying refunds or compensation, fees and charges;
(b) collecting and recovering money owed to us;
(c) running fraud checks if we have reasonable suspicions;
(d) provide you with the information, products and services that you request from us including, but not limited to, contacting you about your journey;
(f) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us, to pay refunds or compensation owed to you and to prevent us facilitating fraud)
|To respond to your enquiries or to process your requests in relation to your information
|Performance of a contract with you
|To maintain a suppression list should you opt-out of receiving communications
||Necessary for our legitimate interests (to ensure that we are not at risk of breaching data protection laws by communicating with you where you have asked us not to)
(b) asking you to leave a review or take a survey
(d) Marketing Communications
(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to recover debts due to us)
|To help provide a safe environment for our employees and customers; to reduce the number of assaults on our employees during revenue enforcement duties; and to improve the quality of evidence available for submission to the authorities
(a) Necessary for our legitimate interests (to protect employee and customer safety and assist with the verification of claim)
|To enable you to partake in a prize draw, competition or complete a survey
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
|To administer and protect our business and the Website (including training our employees, troubleshooting, data analysis, testing, system maintenance, security audits, support, reporting and hosting of data)
|To conduct health and safety assessments and record keeping; and compliance with related legal obligations
|To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
(e) Marketing Communications
|Necessary for our legitimate interest (to study how you use our products/services, to develop them, to grow our business and to inform our marketing strategy)
|To use data analytics to improve the Website, products/services, marketing, customer relationships and experiences
||Necessary for our legitimate interests (to define types of customers for our products and services, to keep the Website updated and relevant, to develop our business and to inform our marketing strategy)
|To make suggestions and recommendations to you about goods or services that we feel may interest you
(f) Marketing Communications
Necessary for our legitimate interest (to develop our products/services and grow our business)
|To establish, exercise and defend our legal rights
This section is to explain how we will ensure that you only receive communications that you wish to receive:
We can only use your personal information to send you marketing messages if we have either your consent or a ‘legitimate interest’. A ‘legitimate interest’ is when we have a business or commercial reason to use your information. It must not unfairly go against what is right and best for you.
The personal data we have for you is made up of what you tell us, and the data we collect about you when you use our services, or data provided to us from third parties we work with. We study this to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you.
If you have provided your consent to receive marketing communications from us and you change your mind, you can change your preferences and unsubscribe at any time by unsubscribing from the relevant communication channel, changing your preferences in the preference centre or by contacting us at GWR-DPO@gwr.com. If you choose not to receive this information we will be unable to keep you informed of new products, services and promotions that may interest you.
Whatever you choose, you'll still receive booking confirmations and other important information, for example service updates.
As detailed in the table at section 6, we may send you communications such as those which relate to any service updates (e.g. service disruption) or provide customer satisfaction surveys. We consider that we can lawfully send these communications to you as we have a legitimate interest to do so, namely to effectively provide you with the best service we can and to grow our business.
We take your privacy seriously and have implemented appropriate physical, technical and organisational security measures designed to secure your personal data against accidental loss, destruction or damage and unauthorised access, use, alteration or disclosure.
We may share your personal data with you, and where appropriate, your family, your associates and your representatives.
We may share your personal data with any member of our group which means our subsidiaries, our ultimate holding company (FirstGroup plc) and its subsidiaries as defined in section 1159 of the UK Companies Act 2006. For example, where we facilitate the ability to book corporate travel through our Business Direct platform, your personal data may be accessible by another member of our group which also makes use of the platform.
We may disclose your personal data to the British Transport Police or any other law enforcement agency or court to the extent necessary for purposes including preventing, investigating, detecting, and prosecuting criminal offences; preventing threats to public security in accordance with applicable law; or validating a claim.
We may share your personal data with the following third-parties who assist us with administering the provision of our services to you:
We may also pass Aggregated Data on the usage of our site (e.g. we might disclose the median ages of visitors to our site, or the numbers of visitors to our site that come from different geographic areas) to third parties but this will not include information that can be used to identify you personally.
If a business transfer or change of business ownership takes place or is envisaged or if our rail franchise is awarded to another company in the future, we may transfer your personal data to the Secretary of Statement for Transport and/or the new owner (or a prospective new owner) or the new franchisee. If this happens, you will be informed of this transfer.
This section explains how we keep your personal data safe and where it will be held.
We take your privacy seriously and are committed to maintaining the privacy and security of the personal data you provide to us, and the choices you have regarding our collection and use of your personal data.
Once we have received your personal data, we follow strict security procedures as to how your personal data is stored and used, and who sees it, to help stop any unauthorised access.
Any payment transactions will be encrypted. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. You should not share this information with anyone.
The information that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA). When we transfer and store your personal data outside of the EEA we will ensure that it is adequately protected by using appropriate safeguards as further detailed below.
Staff operating outside the EEA who work for us, or one of our suppliers, may process the information. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services;
Where your personal data is transferred from the EEA to a recipient outside the EEA in a country not recognised by the European Commission as providing an adequate level of protection for personal data, such transfer shall be covered by a framework recognised by the relevant authorities or courts as providing an adequate level of protection for personal data including but not limited to:
Unfortunately, the transmission of your personal data via the internet is not completely secure and although we do our best to protect your personal data, we cannot guarantee the security of your data transmitted to us over the internet and you acknowledge that any transmission is at your own risk.
This section explains the length of time that we will retain your personal data.
We will keep your personal data for no longer than is necessary for the purposes for which it was obtained. The criteria for determining the duration for which we will retain your personal data are as follows:
(1) we will retain your personal data in a form that permits identification only for as long as:
(2) the duration of:
(3) in addition, if any relevant legal claims are brought, we may continue to process your personal data for such additional periods as are necessary in connection with that claim.
During the periods in paragraphs (2)a and (2)b above, we will restrict our processing of your personal data to the storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim or obligation under applicable law.
After this period your personal data will be anonymised so that you are no longer identified or identifiable from such information, or securely deleted/destroyed.
Any third parties that we engage will keep your data stored on their systems for as long as is necessary to provide the relevant services to you or us. If we end our relationship with any third party providers, we will make sure that they securely delete or return your personal data to us.
The retention periods for CCTV and BWV vary depending on the location and system in use. Such periods tend not to exceed 30 days and will always be reasonable or as long as is required by law. For more information please contact us using the details provided in section 13.
We may retain personal data about you for statistical purposes (for example, to help us better advertise our services). Where data is retained for statistical purposes it will always be anonymised, meaning that you will not be identifiable from that data.
This section explains that you have a number of rights in relation to your personal data. There are circumstances in which your rights may not apply. You have the right to request that we:
For more information on your rights and how to use them, or if you would like to make any of the requests set out above, please contact us using the details provided in section 13. We will respond to all such requests within the time period required by law. Occasionally it may take us longer, if your request is particularly complex, you have made a number of requests or you have not supplied the information we need to respond to you. In this case, we will notify you and keep you updated.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
As explained in the section on Communications above, even if you consented to the processing of your personal data for marketing purposes (by ticking the relevant box or by requesting information about services), you have the right to ask us to stop processing your personal data for such purposes. You can exercise this right at any time by unsubscribing from the relevant communication channel, changing your preferences in the preference centre or by contacting us at GWR-DPO@gwr.com.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
If you have any questions or concerns about how we handle your personal data, you can contact us using any one (or more) of the following:
Post: MH101, GWR, Milford House, Swindon, SN1 1HL
Telephone number: 0345 7000 125
Alternatively, you can contact us through the Contact Us section of the Website.
We have appointed a Data Protection Officer. They are responsible for our approach to data protection and protecting your privacy. You can contact them at DPO@firstgroup.com.
If you are unsatisfied with our response to any data protection issues you raise with us or our DPO, you have the right to make a complaint to the Information Commissioner’s Office (ICO). The ICO is the authority in the UK which is tasked with the protection of personal data and privacy.
Last updated: 22 November 2019
Cookies are text files containing small amounts of information which are downloaded to your personal computer, mobile or other device when you visit a website.
Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognises that cookie. Cookies are useful because they allow a website to recognise a user's device.
Cookies in themselves do not identify you, just the computer or device you are using. Cookies do lots of different jobs, like making it easier for you to log onto, and use, our site during future visits, letting you navigate between pages efficiently, remembering your preferences, and generally improving your experience. They also allow us to monitor traffic on our site and can also help to ensure that advertising you see online is more relevant to you and your interests.
Cookies themselves only record which areas of our site have been visited by your computer or device and for how long. Allowing us to create a cookie does not give us access to the rest of your computer, and does not allow us to see any personally identifiable data about you.
We've arranged the cookies we use into four groups:
a) Analytics/performance cookies: Every time someone visits our site, software that we have selected and which is provided by one or more other organisations generates an 'anonymous analytics cookie' which tell us whether or not you have visited our site before. Your browser will tell us if you have these cookies and, if you don't, we generate new ones. This allows us to track how many users we have, and how often they visit our site. We use these cookies to gather statistics such as the number of visits to any page on our site.
b) Functionality cookies: These cookies enable us to remember choices you make and provide enhanced, more personal features. For example, remembering your email address and preferences on our website, so you don't have to choose them each time you visit.
c) Strictly necessary cookies: These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website or make a purchase.
d) Targeting cookies: We use these anonymous cookies to determine the content of advertisements that we show on other websites. When you visit other sites on the web, such as news or information sites, this cookie lets our re-targeting providers know when to serve advertisements and what content to show you. These cookies also allow us to know whether or not you've seen an advertisement, and how long it has been since you've seen it.
You can find more information about the individual cookies we use and the purposes for which we use them in the table below:
Category - First-party performance cookies
Category - Third-party performance cookies