Data Protection Policy
1.1 Introduction
Quayside Technical Services Ltd needs to collect personal information to effectively and compliantly carry out our everyday business functions and activities and to provide the products and services defined by our business type. Such data is collected from employees, customers, suppliers and clients and includes (but is not limited to), Name, address, date of birth, IP address, identification numbers, private and confidential information & documents, and other sensitive information.
In addition, we may be required to collect and use certain types of personal information to comply with the requirements of the law and/or regulations, however we are committed to collecting, processing, storing and destroying all information in accordance with the General Data Protection Regulation, UK data protection laws and specific data protection codes of conduct (herein collectively referred to as ‘the GDPR’).
Quayside Technical Services Ltd has developed policies, procedures, controls and measures to ensure maximum and continued compliance with the GDPR and its principles, including staff training, procedure documents, audit measures and customer data, accounts and other data. Ensuring and maintaining the security and safety of personal and/or special category data belonging to the individuals and businesses with whom we deal is paramount to our company ethos. Quayside Technical Services Ltd adheres to the GDPR and its associated principles in every process and function.
We are proud to operate a ‘Privacy by Design’ approach and aim to be proactive not reactive; assessing changes and their impact from the start, and designing systems and processes to protect data privacy is at the core of our business.
In summary our policies state that personal data shall:
- Be processed fairly and lawfully.
- Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with the purpose.
- Be adequate, relevant and not excessive for the purpose.
- Be accurate and up-to-date.
- Not be kept for longer than necessary for the purpose.
- Be processed in accordance with the data subject’s rights.
- Be kept safe from unauthorised processing, and accidental loss, damage or destruction.
- Not be transferred to a country outside the European Economic Area, unless that country has equivalent levels of protection for personal data, except in specified circumstances.
1.2 Definitions
“Staff”, “clients” and “other data subjects” may include past, present and potential members of those groups including other terms including ‘customer’, ‘supplier’, ‘consultant’, ‘representative’, etc.
“Other data subjects” and “third parties” may include contractors, suppliers, contacts, referees, monitoring and regulatory organisations and bodies etc.
“Processing” refers to any action involving personal information, including obtaining, viewing, copying, amending, adding, deleting, extracting, storing, disclosing or destroying information.
- Notification of Data Held
Quayside Technical Services Ltd shall notify all staff, customers, and other relevant data subjects of the types of data held and processed by Quayside Technical Services Ltd concerning them, and the reasons for which it is processed. The information which is currently held by Quayside Technical Services Ltd and the purposes for which it is processed will be amended when processing for a new or different purpose.
- Responsibilities
3.1 Clients and all people on which information is held.
- Ensure that all information which they provide to Quayside Technical Services Ltd is accurate and up-to-date.
- Inform Quayside Technical Services Ltd of any changes to information, for example, changes of address.
- Check the information which Quayside Technical Services Ltd shall make available from time to time, in written or automated form, and inform Quayside Technical Services Ltd of any errors or, where appropriate, follow procedures for up-dating entries on computer forms. Quayside Technical Services Ltd shall not be held responsible for errors of which it has not been informed.
3.2 Staff shall ensure that:
- All personal information is kept securely.
- Personal information is not disclosed either orally or in writing, accidentally or otherwise to any unauthorised third party. Unauthorised disclosure may be a disciplinary matter, and may be considered gross misconduct in some cases.
- Rights to Access Information
4.1 Staff, Clients, and other data subjects have the right to access any personal data that is being kept about them either on computer or in structured and accessible manual files. Any person may exercise this right by submitting a request in writing to Quayside Technical Services Ltd.
4.2 Quayside Technical Services Ltd will make a charge of £10 for each official Subject Access Request under the Act.
4.3 Quayside Technical Services Ltd aims to comply with requests for access to personal information from Staff, Clients, and other data subjects, as quickly as possible, but will ensure that it is provided within 40 days unless there is good reason for delay. In such cases, the reason for the delay will be explained in writing by the Information Security Officer to the data subject making the request.
- Specific subject Consent – medical history and/or conditions.
Quayside Technical Services Ltd will ask staff and possibly other data subjects for information about particular health needs, such as allergies to particular forms of medication, or conditions such as asthma, arthritis. Quayside Technical Services Ltd will only use such information to protect the health and safety of the individual, for example, in the event of a medical emergency or in carrying out physical activities.
- The Data Controller and the Designated Data Controllers
Ms. Claire Salter is the data controller under the Act, and is ultimately responsible for implementation.
- Retention of Data
Quayside Technical Services Ltd will keep different types of information for differing lengths of time, depending on legal, and operational requirements.
- Compliance
8.1 Compliance with the Act is the responsibility of all learners and members of staff. Any deliberate or reckless breach of this Policy may lead to disciplinary, and where appropriate, legal proceedings.
8.2 Any individual, who considers that the policy has not been followed in respect of personal data about him- or herself, should raise the matter with Quayside Technical Services.