Data Protection/Security & Privacy Policy Ver 1 Data Protection and Data Security Policy Page 1 of 8
TABLE OF CONTENTS 1 |
PURPOSE OF POLICY |
2 |
RESPONSIBILITIES |
3 |
WHY WE PROCESS YOUR DATA |
4 |
HOW WE USE YOUR INFORMATION |
5 |
PERSONNAL INFORMATION |
6 |
INFORMATION PROCESSED |
7 |
PURPOSE |
8 |
DATA SHARING |
9 |
DATA PROTECTION PRINCIPLES |
10 |
DATA SECURITY |
11 |
BREACH NOTIFICATION |
12 |
RETENTION |
13 |
METHODS OF DISPOSAL |
14 |
EMPLOYEE RIGHTS |
15 |
SUBJECT ACCESS REQUESTS |
16 |
YOUR RESPNSIBILITIES |
17 |
REFERENCES AND POST EMPLOYMENT |
18 |
COOKIES |
19 |
CHANGES TO THIS POLICY |
Ver 1 Data Protection and Data Security Policy Page 2 of 8
1. PURPOSE OF POLICY
LJF Powder Coating Ltd (the Employer) is committed to ensuring that all personal information handled by us will be processed accordingly to legally compliant standards of data protection and data security.
The purpose of this policy is to help us achieve our data protection and data security aims by:
This is a statement of policy only and does not form part of your contract of employment. We may amend this policy at any time, at our absolute discretion.
2. RESPONSIBLITIES
The Company is the “Data Controller” and is responsible for maintaining appropriate standards of data protection and data security is a collective task shared between the Company and Employees. This policy and the rules contained in it apply to all Employees of the Company, irrespective of seniority, tenure and working hours, including all Employees, Directors and Officers, Consultants and Contractors, casual or agency staff, trainees, homeworkers and fixed term staff and any volunteers.
The Managing Director has overall responsibility for ensuring that all personal information is handled in compliance with the law and has an appointed Data Protection Officer with day to day responsibility for data processing and data security.
All Employees have personal responsibility to ensure compliance with this policy, to handle all personal information consistently with the principles set out here and to ensure that measures are taken to protect the data security.
Managers also have a responsibility to lead by example and for monitoring and enforcing compliance.
Any breach of this policy will be taken seriously and may result in disciplinary action.
3. WHY WE PROCESS YOUR DATA
• We process your personal data primarily on the basis of legitimate interest as a business but only if necessary for the purpose we collected it for. We will also process data on the basis of contractual and transactional obligation where necessary. We may process your data for;
• Sales and marketing activities such as calls, emails and other types of communications
• Understanding how you interact with the website and social media
• Account activity such as, email, written and verbal communications and agreements Ver 1 Data Protection and Data Security Policy Page 3 of 8
• To perform obligations under a contract with you or a business you may work for
• We will only store your data, for as long as we need it to undertake any of the processes listed above.
4. HOW WE USE YOUR INFORMATION
• About you: when you use our website, send us an email or communicate with us in any way, you are voluntarily giving us information that we collect.
• That information may include either your name, email address, ip address, phone number, as well as details including occupation, location, survey responses and feedback. By giving us this information, you agree to this information being collected, used, disclosed, transferred within the eu (our main data storage centre is located in scotland) and stored by us as described in this privacy policy.
• automatically: when you browse our website we may collect usage information about your visit to our website and your web browsing. that information may include your ip address, your operating system, your browser id, your browsing activity, and other information about how you interacted with our website or service. we may collect this information as a part of log files as well as through the use of cookies or other tracking technologies. our use of cookies and other tracking technologies is discussed more below, and in more detail in our cookie policy
• Website cookies and link tracking: cookies allow us to provide important site functionality, so you don’t have to re-enter lots of information. They also allow us to remember what links and pages have been clicked or viewed during a session. If you have provided us with personal data, completing a contact form for example, we may associate this personal data with other information. This will allow us to identify and record what is most relevant to you. By using your browser controls, you are always in control of the cookies we store and access on your computer. More information on how to control cookies and limit personal data processing can be found at youronlinechoices.com/uk/five-top-tips. For comprehensive information on how to change your cookie settings in a wide variety of different web browsers, visit www.aboutcookies.org.
• Google analytics cookies: google analytics is a website monitoring tool that allows users to see volumes of website visitors, their source, and to analyse how the content of their website is viewed and navigated. This in turn allows optimisation of the content and pages and the marketing programmes that drive traffic to the website. Google analytics does not store any personal information about website visitors, but does use persistent cookies to identify repeat visitors. You may universally opt-out of all google analytics tracking used by all websites by visiting the following url – https://tools.google.com/dlpage/gaoptout
5. PERSONAL INFORMATION
This policy covers personal information: Ver 1 Data Protection and Data Security Policy Page 4 of 8
6. INFORMATION PROCESSED
The Company collects personal information about its Employees which:
The types of personal information that the Company may collect, store and use about its Employees include records relating to the Employees:
The Company may also collect, store and use the following “special categories” of more sensitive personal information.
By Employees providing the Company with their personal information, Employees agree to the use of their personal information (including any sensitive personal data) in accordance with this Policy. Ver 1 Data Protection and Data Security Policy Page 5 of 8
If you fail to provide certain information when requested, we may not be able to perform the contract we have entered into with you (such as paying you or providing a benefit), or we may be prevented from complying with our legal obligations (such as health and safety of our Employees). Any failure may result in a contract with you being terminated or disciplinary action.
7. PURPOSE
The Company will use information to carry out Business, to administer Employees employment or engagement. We will only use your personal information when the law allows us to. Most commonly, we will use your personal information in the following circumstances: –
In particular, the situations in which we may process your personal information are as follows: –
Some personal information needs even more careful handling “Special Categories” of particularly sensitive personal information require a higher level of protection. We need to have further justification for collecting, storing and using this type of information.
This includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition or sexual life or about criminal offences. Strict conditions apply to processing this sensitive personal information and the Employee must normally have given specific and express consent to each way in which the information is used. Ver 1 Data Protection and Data Security Policy Page 6 of 8
We may process special categories of personal information in the following circumstances: –
We will only use employee’s information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If the Company needs to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
8. DATA SHARING
The Company confirms that for the purposes of the Data Protection Act 1998, the Finance Manager has been appointed as the Data Protection Officer and shall act for the Company and is responsible for the personal information in connection with the Employees employment. This means that the Company determines the purposes for which, and the manner in which Employees personal information is processed.
The Company will take all reasonable steps to ensure that Employees information is kept secure, and as described later in the Policy.
The Company. will have to share your data with third parties.
The Company will share your data with third parties where it is necessary to administer the working relationship with you or where we have another legitimate interest in doing so.
Third parties will only process your personal information on our instructions and where they have agreed to treat the information confidentially and to keep it secure.
We require third parties to respect the security of your data and to treat it in accordance with the law.
The Company may need to share your personal information to a third party for the following reasons:
9. DATA PROTECTION PRINCIPLES
Employees whose work involves using personal data relating to the Employees or others must comply with this Policy and with the eight legal Data Protection Principles which require that personal information is: Ver 1 Data Protection and Data Security Policy Page 7 of 8
10. DATA SECURITY
The Company must protect all personal information in our possession from being accessed, lost, deleted or damaged unlawfully or without proper authorisation through the use of Data Security measures.
Maintaining Data Security means making sure that:
By law, the Company must use procedures and technology to secure personal information through the period that the Company holds or controls it, from obtaining to destroying the information.
Personal information must not be transferred to any individual to process (eg while performing service for the Company or on the Company’s behalf), unless that individual has agreed to comply with the Company’s Data Security procedures or the Company is satisfied that other adequate measures exist.
Security procedures include:
Ver 1 Data Protection and Data Security Policy Page 8 of 8
11. BREACH NOTIFICATION
12. RETENTION
13. METHODS OF DISPOSAL
14. EMPLOYEE RIGHTS
Ver 1 Data Protection and Data Security Policy Page 9 of 8
15. SUBJECT ACCESS REQUESTS
16. YOUR RESPONSIBILITIES
number or change bank details.
17. REFERENCES AND POST EMPLOYMENT
Ver 1 Data Protection and Data Security Policy Page 10 of 8
18. COOKIES
• Cookies are small text files that are placed on to your computer by websites that you visit. They are used to make websites work, to improve efficiency of websites, to improve the user’s experience and to provide usage information on websites. This information should make your website visits more productive by storing and using information on your website preferences and habits.
• Your web browser can choose whether or not to accept cookies. Most web browser software is initially set up to accept them.
• Our website uses cookies and you should ensure that your web browser is set up to not accept cookies if you do not wish to receive them. Please note that if you disable cookies, some services or website functionality may not be available. For further information about cookies and how to disable them please go to aboutcookies.org. We use the following cookies:
• Essential cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, and to use online forms.
• Analytical cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
• Marketing cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences. These cookies also record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website, the advertising displayed on it and communications sent more relevant to your interests.
19. CHANGES TO THIS POLICY