DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy

Size: px
Start display at page:

Download "DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy"

Transcription

1 DATA PROTECTION POLICY WINCHESTER CITY COUNCIL

2 Document Title: Author: Fiona Sutherland Revision History Version Revision Date Summary of Change Distribution /03/16 Internet Intranet

3 WINCHESTER CITY COUNCIL DATA PROTECTION POLICY 1.0 INTRODUCTION 1.1 This is the of Winchester City Council and applies to all employees, elected members, public representatives, business partners, agents and third parties acting on the Council s behalf. 1.2 The Council needs to collect, use and store certain types of information about the people we deal with in order to carry out our business as a local authority. These people include current, past and prospective employees, suppliers, clients/customers and others. In addition, the Council may sometimes be required by law to collect and use certain types of personal information to comply with Government requirements. Personal information must be dealt with properly however it is collected, recorded and used whether on paper, in a computer or recorded on other material such as CCTV. 1.3 The Council regards the lawful and correct treatment of personal information as very important in order to maintain confidence between us and the people we deal with. We ensure that the Council treats personal information lawfully and correctly. 1.4 The Council is therefore fully committed to the eight Data Protection principles, set out in Schedule 1 of the Data Protection Act 1998 (DPA). 2.0 DATA PROTECTION PRINCIPLES The Data Protection Principles are as follows: Principle 1 - Personal data shall be processed fairly and lawfully, and, in particular, shall not be processed unless specific conditions for processing are met. Principle 2 - Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes. Principle 3 - Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. Principle 4 - Personal data shall be accurate, and, where necessary, kept up to date.

4 Principle 5 - Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. Principle 6 - Personal data shall be processed in accordance with the rights of individuals under this Act. Principle 7 - Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss, or destruction of, or damage to, personal data. Principle 8 - Personal data shall not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection for the rights and freedoms of individuals in relation to the processing of personal data. 3.0 WHAT THE COUNCIL WILL DO 3.1 Winchester City Council will: Observe fully the conditions regarding the fair collection and use of personal information. Meet its legal obligations to specify the purposes for which information is used. Collect and process personal information, only to the extent that it is needed to enable us to carry out our business as a local authority or to comply with any legal requirements. Ensure the quality of information we use is accurate and kept up to date. Ensure that we do not keep personal information for any longer than we need to (and in accordance with our Retention Schedule). Guarantee that when we hold information about people, they can exercise their rights under the DPA (these include the right to be informed that processing is being undertaken, the right to access information that we hold about them, the right to prevent processing in certain circumstances and the right to correct, rectify, block or erase information which is not correct. Ensure that appropriate security measures are taken, both technically & organisationally, to protect against damage, loss or abuse of personal data. Ensure that personal information is not transferred abroad without suitable safeguards. Maintain a central log of data protection breaches, investigate all breaches that are reported, and take appropriate steps to prevent recurrence. Ensure that Winchester City Council s Data Protection Registration is kept up to date ( the Registration number is Z ). Regularly review this policy and safeguards that relate to it, to ensure that the contents are still relevant, efficient and effective.

5 Ensure CCTV systems are used in compliance with the DPA. Ensure the privacy of our employees and customers and people that we deal with. 3.2 In addition Winchester City Council will ensure that: There is someone with specific responsibility for data protection in the Council. This is the Head of Legal and Democratic Services. Everyone managing and handling personal information understands that they are responsible for following good data protection practice. Everyone managing and handling personal information is appropriately trained to do so. Everyone managing and handling personal information is appropriately supervised. Anybody wanting to make enquiries about handling personal information knows what to do. Queries about handling personal information are promptly and courteously dealt with. A regular review and audit is made of the way personal information is managed. Methods of handling personal information are regularly assessed. 4.0 SUMMARY 4.1 When we ask you for information, Winchester City Council will: Ensure you know why we need it. Protect it and make sure nobody has access to it that should not have. Ensure you know if you have a choice about giving us information. Let you know if we need to share the information with other organisations to give you better public services and whether you can say no. Make sure we do not keep the information longer than necessary. 4.2 In return we ask you to: Give us accurate information. Tell us as soon as possible of any changes.

6 Tell us as soon as possible if you notice mistakes in the information we hold about you, as this helps us keep our information reliable and up to date. 5.0 FURTHER INFORMATION 5.1 If you wish to be supplied with personal information we hold about you (a subject access request), or if you have any queries or complaints please write to the Head of Legal and Democratic Services, Winchester City Council, City Offices, Colebrook Street, Winchester, Hampshire SO23 9LJ. You can also contact Legal Services by If you would like to see Winchester City Council s Data Protection Registration details, as notified to the Information Commissioner, you can visit the Information Commissioner s website ( and simply enter the Council s registration number Z in the appropriate box. 5.3 For independent advice about data protection, please contact the Information Commissioner, By Post: The Information Commissioner s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF By Phone: (local rate) By casework@ico.org.uk

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Data Protection/ Information Security Policy

Data Protection/ Information Security Policy Data Protection/ Information Security Policy Date Policy Reviewed 27 th April 2016 Date Passed to Governors: 27 th April 2016 Approved by Governors: 7 th June 2016 Date of Next Review: June 2018 Data Protection

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

Data Protection Policy

Data Protection Policy Preston and District Data Protection Policy The University of the Third Age Scope of the policy This policy applies to the work of Preston & District U3A (hereafter the U3A ). The policy sets out the requirements

More information

Data Protection Policy

Data Protection Policy Data Protection Policy University of London Data Protection UoL website link: http://www.london.ac.uk/238.html Email: records.managament@london.ac.uk Contents 1 Policy statement... 3 2 Introduction and

More information

General Data Protection Regulation. What should community energy organisations be doing to prepare?

General Data Protection Regulation. What should community energy organisations be doing to prepare? General Data Protection Regulation What should community energy organisations be doing to prepare? The implementation date of 25 May 2018 for the General Data Protection Regulation (GDPR) is fast approaching.

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients TECHNICAL RELEASE TECH 05/14BL Data Protection Handling information provided by clients ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over

More information

PARK HIGH SCHOOL FREEDOM OF INFORMATION POLICY PUBLICATION SCHEME GUIDANCE. (Please also refer to the Schools Management of Records Policy)

PARK HIGH SCHOOL FREEDOM OF INFORMATION POLICY PUBLICATION SCHEME GUIDANCE. (Please also refer to the Schools Management of Records Policy) PARK HIGH SCHOOL FREEDOM OF INFORMATION POLICY PUBLICATION SCHEME & GUIDANCE (Please also refer to the Schools Management of Records Policy) UPATED January 2017 AUTHOR DOCUMENT OWNER Business Manager Headteacher

More information

Data Protection Policy

Data Protection Policy Data Protection Policy for The Astor Bannerman Group of Companies Issue Date: 3 rd January 2014 Version: 01 Approval History Name Department Role/Position Date approved Signature James Stuart- Smith Director

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY 1. Introduction This policy sets out how The Robert Gordon University shall comply with the requirements of the Data Protection Act 1998 and was created with reference to the JISC

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title: Data Protection Policy Ref:CP005 Version:2 Approval Body: Corporation via Audit & Risk Committee Date:24th March 2015 Review Date: 24th March 2018 Lead Person: Director, Institutional Effectiveness

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

Data Protection Audit Self-assessment toolkit

Data Protection Audit Self-assessment toolkit Data Protection Audit Self-assessment toolkit online preferences security passport details emergency contact details blood group email account number accuracy CCTV images tax records rights payroll number

More information

UK Research and Innovation (UKRI) Data Protection Policy

UK Research and Innovation (UKRI) Data Protection Policy UK Research and Innovation (UKRI) Data Protection Policy Document Information Revision History Version Comment Date By 0.1 Draft Policy created July 2017 DH 0.2 Revision post review by information manager

More information

Quick guide to the employment practices code

Quick guide to the employment practices code Data protection Quick guide to the employment practices code Ideal for the small business Contents 3 Contents Section 1 About this guidance 4 Section 2 What is the Data Protection Act? 5 Section 3 Recruitment

More information

THE HEATH ACADEMY TRUST DATA PROTECTION POLICY

THE HEATH ACADEMY TRUST DATA PROTECTION POLICY THE HEATH ACADEMY TRUST DATA PROTECTION POLICY inspire transform together Summary Policy Reference Number: 024 Category: Authorised By: Committee Responsible: Data Protection Board Of Directors Board Of

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice ICO lo Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 About this code... 3 Chapter 1 - Introduction to PIAs... 5 What the ICO means by PIA...

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1. Introduction This policy is intended to provide information about how the School will use (or process ) personal data about individuals including: Current, past and prospective pupils; Parents, carers

More information

The Information Commissioner s response to the Competition and Market Authority s Energy market investigation: notice of possible remedies paper.

The Information Commissioner s response to the Competition and Market Authority s Energy market investigation: notice of possible remedies paper. The Information Commissioner s response to the Competition and Market Authority s Energy market investigation: notice of possible remedies paper. The Information Commissioner s role The Information Commissioner

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

Park Hall Academy FOI Policy & Publication Scheme

Park Hall Academy FOI Policy & Publication Scheme 1. INTRODUCTION Park Hall Academy FOI Policy & Publication Scheme Park Hall Academy is committed to the Freedom of Information Act 2000 (FOIA), the principles of accountability and the general right to

More information

Comments, Complaints & Compliments policy

Comments, Complaints & Compliments policy Comments, Complaints & Compliments policy Version EKH#2 Last reviewed July 2013 Responsible officer Jonathan Hicks Approved by Board 12 Sept 2011 Next review date May 2015 Related documents Mission Statement

More information

Customer Advocacy. Complaints Management Policy

Customer Advocacy. Complaints Management Policy Customer Advocacy Complaints Management Policy Complaints Management Policy Page 2 1. Purpose 1.1 The purpose of this policy is to provide customers and stakeholders with an overview and understanding

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

Data Protection Policy and General Data Protection Regulations (GDPR)

Data Protection Policy and General Data Protection Regulations (GDPR) Data Protection Policy and General Data Protection Regulations (GDPR) Daryl Martin Revised September 2017 AFVS Policies & Templates are intended as general guides in relation to the topics covered, and

More information

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?... Data Protection Guidance for Volunteers Last update 26/11/17 Contents Introduction... 2 1. Why is data protection important?... 2 2. How does it apply to volunteers?... 2 3. What volunteers need to do?...

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe,

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the processing of personal data in the context of employment (Adopted by the Committee of Ministers on 1 April 2015, at the

More information

SIGBI DATA PROTECTION PROTOCOLS 2018

SIGBI DATA PROTECTION PROTOCOLS 2018 SIGBI DATA PROTECTION PROTOCOLS 2018 For the purpose of this document, references to Soroptimist International Great Britain and Ireland (SIGBI) Limited and Soroptimist International may be written as

More information

Data Protection Policy

Data Protection Policy HOLY TRINITY CE (VA) PRIMARY SCHOOL Data Protection Policy Learning and caring together, building a firm foundation for the future. FOUNDED 1865 Date of Last Review: July 2015 Date to be Revisited: July

More information

A Parish Guide to the General Data Protection Regulation (GDPR)

A Parish Guide to the General Data Protection Regulation (GDPR) A Parish Guide to the General Data Protection Regulation (GDPR) What s happening and why is it important? The law is changing. Currently, the Data Protection Act 1998 governs how you process personal data

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

Regulates the way data controllers process personal data

Regulates the way data controllers process personal data GUIDANCE NOTE ON THE DATA PROTECTION ACT 1998 This guidance note gives an overview of how the Data Protection Act 1998 (the Act ) applies to clubs (including class associations) and recognised training

More information

Thank you for your request under the Freedom of Information Act 2000 (the Act) received on 16 February 2011, seeking the following information:

Thank you for your request under the Freedom of Information Act 2000 (the Act) received on 16 February 2011, seeking the following information: 16 th March 2011 Freedom of Information Request - RFI20110210 Thank you for your request under the Freedom of Information Act 2000 (the Act) received on 16 February 2011, seeking the following information:

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

Ewyas Harold Group Parish Council. Freedom of Information Policy

Ewyas Harold Group Parish Council. Freedom of Information Policy Ewyas Harold Group Parish Council Freedom of Information Policy The Parish Council Model Publication Scheme follows this policy. This scheme will enable members of the public to view and access information

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

COUNCIL OF EUROPE COMMITTEE OF MINISTERS. RECOMMENDATION No. R (89) 2 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES

COUNCIL OF EUROPE COMMITTEE OF MINISTERS. RECOMMENDATION No. R (89) 2 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES COUNCIL OF EUROPE COMMITTEE OF MINISTERS RECOMMENDATION No. R (89) 2 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES ON THE PROTECTION OF PERSONAL DATA USED FOR EMPLOYMENT PURPOSES 1 (Adopted by the Committee

More information

Code of Conduct. Integral Diagnostics Limited ACN

Code of Conduct. Integral Diagnostics Limited ACN Code of Conduct Integral Diagnostics Limited ACN 130 832 816 Date: 1 October 2015 Code of Conduct Part A Scope and application 1 Purpose of the Code The Company is committed to a high level of integrity

More information

The. Code of Practice

The. Code of Practice The Code of Practice 1 SEPTEMBER 2015 adma.com.au Introduction ADMA sets leading industry standards that are relevant to the sector, set appropriate benchmarks and allow for future growth. The ADMA Code

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY Version: 1.4 Approved by: Date approved: 19 January 2017 Name of Originator/Author: Name of Responsible Committee/Individual: Date issued: Information

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector TABLE OF CONTENTS INTRODUCTION... 2 Accountable privacy management 2 Getting started 3 A.

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved Gwybodaeth Dan Reolaeth Gwynedd Council DATA PROTECTION POLICY FINAL 2.0 September 2015 Information Management Service 1. Introduction The Council makes considerable use of personal information in all

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey www.nascenta.com GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey Introduction GDPR Key Points GDPR/DPA Differences Start Up, Tech Business Professional Practice?

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

Positioning Technology in Working Life

Positioning Technology in Working Life Check-list Positioning Technology in Working Life It has become more and more common for employers to use positioning systems of various kinds to check where their vehicles and employees are. When such

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

Whistle Blowing Policy

Whistle Blowing Policy Whistle Blowing Policy Introduction The Code is intended to help employees in or working with or assisting Schools in Lambeth who have major concerns over any wrong-doing within such Schools relating to

More information

This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling Databases.

This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling Databases. The Data Protection Act 1998 & Market Research: Guidance for MRS Members September 2003 This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 Information Commissioner s foreword... 2 About this code... 3 Chapter 1 Introduction to PIAs...

More information

Equality, diversity and inclusion policy

Equality, diversity and inclusion policy Equality, diversity and inclusion policy Valid from 26 September 2013 Aims Action to promote equality, diversity and inclusion is an integral part of DCH s strategy and business objectives. We can only

More information

EDINBURGH NAPIER UNIVERSITY A GUIDE TO PRIVACY IMPACT ASSESSMENTS

EDINBURGH NAPIER UNIVERSITY A GUIDE TO PRIVACY IMPACT ASSESSMENTS EDINBURGH NAPIER UNIVERSITY A GUIDE TO PRIVACY IMPACT ASSESSMENTS PART ONE ABOUT PIAs... 2 What is this guide for?... 2 What is a PIA and what does it do?... 2 What are the risks of not carrying out a

More information

Customer Services Charter

Customer Services Charter Customer Services Charter Promotion for the public benefit of the science and practice of building and construction About the Chartered Institute of Building Our Guiding Principles Our Commitment Customer

More information

LEISURE VOUCHERS TERMS AND CONDITIONS

LEISURE VOUCHERS TERMS AND CONDITIONS LEISURE VOUCHERS TERMS AND CONDITIONS Your Balance can be checked by clicking Here This card expires 24 months after the last use Can be used online and in store Maximum load 500 Please enter 10 digit

More information

General Data Protection Regulation. The changes in data protection law and what this means for your church.

General Data Protection Regulation. The changes in data protection law and what this means for your church. General Data Protection Regulation The changes in data protection law and what this means for your church. 1 Contents Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 18 Page 20 Page 23

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

College Policy. Freedom of Information Act Publication Scheme

College Policy. Freedom of Information Act Publication Scheme College Policy Freedom of Information Act Publication Scheme Lead Responsible Vice Principal Finance and Resources Effective from January 2011 Approved by Corporation EIA Date Approval Date January 2011

More information

Privacy Policy PURPOSE SCOPE POLICY. Data Collection

Privacy Policy PURPOSE SCOPE POLICY. Data Collection Privacy Policy PURPOSE 1. To ensure Training & Assessment Mentor maintains the privacy of personal information provided to Training & Assessment Mentor from Staff and Students. SCOPE 2. This document describes

More information

closer look at Definitions The General Data Protection Regulation

closer look at Definitions The General Data Protection Regulation A closer look at Definitions The General Data Protection Regulation September 2017 V1 www.inforights.im Important This document is part of a series, produced purely for guidance, and does not constitute

More information

IQ Data Protection Policy

IQ Data Protection Policy IQ Data Protection Policy Statement of purpose IQ Ltd is registered on the Data Protection register as a statutory requirement for organisations that hold personal data. Registration was first completed

More information

Tetney Primary School. Policy for Whistleblowing

Tetney Primary School. Policy for Whistleblowing Tetney Primary School Policy for Whistleblowing This is the Lincolnshire Policy which we have adopted. AGREED BY GOVERNORS ON SIGNED BY CHAIR TO BE REVIEWED REVIEWED ON.. REVIEWED ON.. Whistleblowing Policy

More information

PUBLIC WIFI FROM EE SOLUTION TERMS

PUBLIC WIFI FROM EE SOLUTION TERMS 1. Interpretation 1.1 The Public WiFi from EE Solution (referred to in these Solution Terms as "Public WiFi" or the "Solution") is provided in accordance with the Customer s Agreement with EE. 1.2 Solution

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

12 STEPS TO PREPARE FOR THE GDPR

12 STEPS TO PREPARE FOR THE GDPR 12 STEPS TO PREPARE FOR THE GDPR Presented by Henshalls Insurance Brokers On 25 May 2018, the General Data Protection Regulation (GDPR) comes into effect in the EU and across the United Kingdom. The GDPR

More information

Appointment of GCC Education Visitors. Information Pack for Applicants. Closing date: 11 th August 2017 at noon

Appointment of GCC Education Visitors. Information Pack for Applicants. Closing date: 11 th August 2017 at noon Appointment of GCC Education Visitors Information Pack for Applicants Closing date: 11 th August 2017 at noon Interviews: 12 th and 14 th September 2017 Contents Page Overview of Recruitment Process 3

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 05/EN WP108 Working Document Establishing a Model Checklist Application for Approval of Binding Corporate Rules Adopted on April 14 th, 2005 This Working Party

More information

MRS Guidelines for MRS Company Partners: Qualitative Recruitment

MRS Guidelines for MRS Company Partners: Qualitative Recruitment MRS Guidelines for MRS Company Partners: Qualitative Recruitment CONSULTATION DRAFT 1 Introduction Over the years, questions have been asked about whether all qualitative recruiter practices are fully

More information

INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified)

INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified) Disciplinary Policy INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified) Consultation Staff Forum August 2014

More information

Operating procedure. Managing customer contacts

Operating procedure. Managing customer contacts Operating procedure Managing customer contacts Contents 1. Introduction 2. Staff welfare 3. Application and context of this procedure 4. Defining and dealing with challenging customer behaviour 5. Equality

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

Policy and Procedure Manual HR01 Effective Date: 7 February 2014 Rev 1: 7 February 2014 CODE OF CONDUCT AND ETHICS POLICY

Policy and Procedure Manual HR01 Effective Date: 7 February 2014 Rev 1: 7 February 2014 CODE OF CONDUCT AND ETHICS POLICY EFFICIENT GROUP & SUBSIDIARIES Policy and Procedure Manual HR01 Effective Date: 7 February 2014 Rev 1: 7 February 2014 CODE OF CONDUCT AND ETHICS POLICY 1 CODE OF CONDUCT AND EHTICS POLICY 1.1 Background

More information

Doncaster Council Data Quality Strategy

Doncaster Council Data Quality Strategy Doncaster Council Data Quality Strategy 2016/17-2020/21 Better Data, Better Services Approving Body Date of Approval Date of Implementation Next Review Date Review Responsibility Version Doncaster Council

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

WHISTLE BLOWING POLICY

WHISTLE BLOWING POLICY WHISTLE BLOWING POLICY Introduction The Tandridge Learning Trust is committed to the highest possible standards of honesty, openness, probity and accountability. It seeks to conduct its affairs in a responsible

More information

LinkMeUp Personal Assistant (PA) Register & Recruitment Support Terms & Conditions

LinkMeUp Personal Assistant (PA) Register & Recruitment Support Terms & Conditions LinkMeUp Personal Assistant (PA) Register & Recruitment Support Terms & Conditions Contents 1. About Us... 2 2. About the Service... 2 3. Cost of the Service... 2 4. Signing up to use LinkMeUp... 2 5.

More information

SSCL Recruitment Service Implementation Environment Agency. Data Protection

SSCL Recruitment Service Implementation Environment Agency. Data Protection SSCL Recruitment Service Implementation Environment Agency Data Protection TABLE OF CONTENTS 1. INTRODUCTION... 3 2. REGISTRATION INFORMATION... 3 3. APPLICATION FORM... 3 3.1. Eligibility... 3 3.2. Personal

More information

Code of Practice Date of last update: 26th April 2017

Code of Practice Date of last update: 26th April 2017 Code of Practice Date of last update: 26 th April 2017 1 CODE OF PRACTICE The purpose of this code of practice is to inform you in clear and helpful terms about our products, services, customer care policies

More information

Processing of personal data in a trust network for electronic identification

Processing of personal data in a trust network for electronic identification Recommendation Processing of personal data in a trust network for electronic identification Annex to FICORA Regulation Recommendation 1 (10) Contents 1 Introduction... 3 2 TRUST NETWORK AND ITS OPERATION...

More information

WHISTLE-BLOWING POLICY Guidance for Managers

WHISTLE-BLOWING POLICY Guidance for Managers WHISTLE-BLOWING POLICY Guidance for Managers Whistle-Blowing Policy Guidance for Managers Whistle-blowing is the term used when someone who works within or for an organisation raises a concern about a

More information

1. Have you translated principle 1 into clear objectives? Yes No If so what are they?

1. Have you translated principle 1 into clear objectives? Yes No If so what are they? Self assessment tool How well does your organisation comply with the 12 guiding principles of the surveillance camera code of practice? Complete this easy to use self assessment tool to find out if you

More information