Data Processing & Privacy Statement
Data Processing & Privacy Statement
Last updated: September 2026
CRG Diagnostics is committed to protecting personal information and processing data responsibly, securely and transparently.
As a specialist provider of vehicle diagnostics, ADAS calibration, coding, programming and associated technical services, we may receive and process information from our customers and business partners to carry out services on their behalf.
This statement explains how CRG Diagnostics handles that information.
Our Role
In many cases, CRG Diagnostics operates as a Data Processor on behalf of another organisation acting as the Data Controller.
These organisations may include:
- Accident repair centres and bodyshops
- Vehicle manufacturers and dealer networks
- Insurance companies and claims management organisations
- Windscreen and automotive glazing companies
- Vehicle rental and fleet operators
- Vehicle repair and servicing organisations
- Other automotive businesses and service providers
Where a vehicle is referred to CRG by one of these organisations, the referring organisation will normally determine the purpose for which personal information is being processed.
CRG processes the information necessary to provide the requested service.
In certain circumstances, CRG may act as a Data Controller in its own right, for example in relation to our own customer, supplier, employee, accounting and regulatory records.
Information We May Process
The information processed will depend upon the service being provided.
It may include:
- Vehicle registration number
- Vehicle Identification Number (VIN)
- Vehicle make, model and specification
- Customer or vehicle keeper details where supplied to us
- Contact details
- Repair and accident information
- Insurance claim or repair references
- Diagnostic information and fault codes
- Vehicle configuration and programming information
- ADAS calibration information
- Photographs relating to the vehicle or repair
- Diagnostic reports and calibration certificates
- Location of the repair facility or vehicle
- Information required by vehicle manufacturers or OEM diagnostic systems
We aim to process only the information reasonably necessary to provide the requested service.
Why We Process Information
CRG may process information for purposes including:
- Carrying out vehicle diagnostic scans
- Completing pre-repair and post-repair diagnostics
- Performing ADAS calibration and recalibration
- Vehicle coding and programming
- Component initialisation and configuration
- Accessing OEM diagnostic and technical information
- Providing remote diagnostic support
- Producing diagnostic reports and calibration certificates
- Confirming that requested work has been completed
- Managing bookings and technician attendance
- Providing technical support to our customers
- Quality assurance and audit purposes
- Meeting manufacturer, regulatory, accreditation and legal requirements
- Responding to queries relating to work previously completed
Vehicle and Diagnostic Data
Modern vehicles contain significant amounts of electronic information.
When CRG connects diagnostic or calibration equipment to a vehicle, information may be obtained from the vehicle's electronic control units and associated systems.
This can include diagnostic trouble codes, vehicle configuration, mileage information, software information, VIN and information relating to vehicle safety systems.
CRG accesses this information only where reasonably necessary to diagnose, calibrate, code, programme or otherwise perform the service requested.
OEM and Manufacturer Systems
Some diagnostic, programming and calibration procedures require CRG to access systems operated by vehicle manufacturers or their authorised technology providers.
Where required to complete the requested service, relevant vehicle information may therefore be transmitted to these systems.
This may include:
- VIN
- Vehicle registration
- Vehicle specification
- Diagnostic information
- Fault codes
- Programming information
- Calibration information
We only provide information reasonably necessary to perform the relevant procedure.
Vehicle manufacturers and technology providers may process information in accordance with their own privacy policies and legal obligations.
SERMI and Vehicle Security Information
Certain vehicle security-related procedures require access to security-related repair and maintenance information.
Where applicable, CRG operates in accordance with SERMI requirements and applicable manufacturer security procedures.
Access to security-related information is restricted to appropriately authorised personnel and is used only for legitimate vehicle repair, diagnostic, coding or programming purposes.
Additional information or evidence may be required before CRG can undertake certain security-related procedures.
Sharing Information
CRG does not sell personal information.
Information may be shared where reasonably necessary with organisations involved in delivering the requested service, including:
- Vehicle manufacturers and OEM systems
- Diagnostic equipment and software providers
- Approved technology providers
- Authorised CRG personnel and technicians
- IT, cloud and communications providers
- Professional advisers
- Regulatory, accreditation or law enforcement organisations where legally required
Where organisations process personal information on our behalf, we take reasonable steps to ensure appropriate data protection arrangements are in place.
Data Security
CRG takes appropriate technical and organisational measures to protect information against unauthorised access, accidental loss, alteration, disclosure or destruction.
Measures include appropriate access controls, password-protected systems, security software, controlled access to company systems, staff confidentiality requirements and data protection procedures.
Access to information is restricted to personnel who reasonably require it to perform their duties.
How Long We Keep Information
We retain information only for as long as reasonably necessary for the purpose for which it was collected and to meet relevant legal, contractual, technical, audit and regulatory requirements.
Certain diagnostic reports, calibration certificates and vehicle service records may need to be retained to provide evidence of work completed, respond to future technical queries or demonstrate compliance with applicable standards.
Once information is no longer reasonably required, it will be securely deleted, anonymised or otherwise disposed of where appropriate.
International Data Processing
Some vehicle manufacturer, OEM, diagnostic or technology systems may process or store information outside the United Kingdom.
Where CRG is responsible for an international transfer of personal data, appropriate safeguards will be used where required by UK data protection legislation.
Your Data Protection Rights
Under UK data protection legislation, individuals may have rights concerning their personal information, including rights relating to:
- Access
- Correction
- Erasure
- Restriction of processing
- Objection to processing
- Data portability
The rights available will depend upon the circumstances and the lawful basis under which the information is being processed.
Where CRG processes information solely on behalf of one of our customers, requests may need to be referred to that organisation as the relevant Data Controller.
CRG will provide reasonable assistance to our customers in responding to legitimate Data Subject requests.
Data Breaches
CRG maintains procedures for identifying and responding to suspected personal data breaches.
Where a breach affects information that CRG processes on behalf of another organisation, we will notify the relevant Data Controller without undue delay where required and provide reasonable assistance with investigation and response.
Our Commitment
CRG Diagnostics recognises the importance of data protection within the modern automotive repair industry.
Our approach is based on three principles:
Only access what we need.
Only use it for the purpose for which it was provided.
Protect it appropriately while it is in our possession.
We continually review our processes as vehicle technology, manufacturer systems and data protection requirements evolve.
Contact Us
If you have a question about how CRG Diagnostics processes personal information, or wish to raise a data protection enquiry, please contact:
CRG Diagnostics
Data Protection Enquiries
- Email: contact@crgadas.solutions
- Address: Unit 7 Marina Ct, Maple Dr, Hinckley LE10 3BF
If you are unhappy with how your personal information has been handled, you also have the right to raise a concern with the Information Commissioner's Office (ICO).
CRG Diagnostics | Vehicle Diagnostics • ADAS Calibration • Coding & Programming