Data Protection Policy.
GDPR 2018 Compliance Statement
It is a legal requirement for the company to comply with the Data Protection Act 1998 and as amended the GDPR 2018. It is also company policy to ensure that every employee maintains the confidentiality of any personal data held by the company in whatever form.
Data protection principles
The company needs to keep certain information about its employees, customers, candidates and suppliers for financial and commercial reasons and to enable us to monitor performance, to ensure legal compliance and for health and safety purposes. To comply with the law, information must be collected and used fairly, stored safely and not disclosed to any other person unlawfully. This means that we must comply with the Data Protection Principles set out in the GDPR 2018.
These principles require that personal data must be:
· Obtained fairly and lawfully and shall not be processed unless certain conditions are met:
· Obtained for specified and lawful purpose and not further processed in a manner incompatible with that purpose:
· Adequate, relevant and not excessive
· Accurate and up to date
· Kept for no longer than necessary
· Processed in accordance with data subjects’ rights
· Protected by appropriate security
· Not transferred to a country outside the European Union without adequate protection.
In processing or using any personal information Gary W Allen Roofing and Exteriorswill ensure that they will follow these principles at all times.
To ensure the implementation of this policy the company has designated the Office Manager as the company’s data protection coordinator. All enquiries relating to the holding of personal data should be referred to the Manager in the first instance.
Notification of data held
You are entitled to know:
· What personal information the company holds about you and the purpose for which it is used
· How to gain access to it
· How it is kept up to date
· What the company is doing to comply with its obligations under the 1998 Act.
This information is available from the office manager.
Individual Responsibility
As an employee you are responsible for:
· Checking that any information that you provide in connection with your employment is accurate and up to date.
· Notifying the company of any changes to information that you have provided, for example changes of address
· Ensuring that you are familiar with and follow the data protection policy
Any breach of the data protection policy, either deliberate or through negligence, may lead to disciplinary action being taken and could in some cases result in criminal prosecution.
Data Security
Gary W Allen Roofing and Exteriors LTD are responsible for ensuring that:
· Any personal data that we hold, whether in electronic or paper format, is kept securely:
· Any personal information is not disclosed either verbally or in writing, accidentally or otherwise, to any unauthorised third party.
· Items that are marked “personal” or “private and confidential”, or appear to be of a personal nature, are opened by the addressee only.