DATA PROTECTION POLICY

Size: px
Start display at page:

Download "DATA PROTECTION POLICY"

Transcription

1 Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection Officer Target audience All staff DATA PROTECTION POLICY After the Review Date has expired, this document may not be up-to-date. Please contact the document owner to check the status after the Review Date shown above. If you would like help to understand this document, or would like it in another format or language, please contact the document owner.

2 CONTENTS 1. Introduction 1 2. Background 1 3. Policy Statement Roles and Responsibilities 2 5. Definitions Records Management Consent Databases Containing Personal Data Retention and Disposal of Information Accuracy and Data Quality Subject Access Requests Privacy and Electronic Communications Regulations Privacy Impact Assessments Providers. 15. Complaints Security and Confidentiality Informing Staff of Data Protection Requirements Reporting Monitoring and Audit Offences Under the Act Associated Legislation and Guidance Risks. 9 Appendix 1: Data Protection Principles 10 Appendix 2: Data Protection Act 1998 Schedule Appendix 3: Data Protection Act 1998 Schedule 3. 12

3 1. Introduction Herefordshire Council has a responsibility under the Data Protection Act 1998 to hold, obtain, record, use and store all personally identifiable data in a secure and confidential manner and in accordance with the purpose stated within its Data Protection Notification. This Policy is a statement of what the Council intends to do to ensure its compliance with the Act. The will apply to all Council employees, volunteers, contractors and to staff members of NHS bodies with whom we work who handle council data in joint teams. The Policy will provide a framework within which the Council will ensure compliance with the requirements of the Act and will underpin any operational procedures and activities connected with the implementation of the Act. 2. Background The Data Protection Act 1998 together with a number of related Statutory Instruments governs the handling of personal information relating to living individuals and covers both manual and computerised personal information. It provides a mechanism by which individuals about whom data is held (the data subjects ) can have a certain amount of control over the way in which it is handled. The main features of the Act are: All data covered by the Act must be handled in accordance with the Eight Data Protection Principles of Good Data Handling (see Appendix 1) The person about whom the information is held (the Data Subject) has the right to request access to that information, to request that inaccuracies are rectified and to place restrictions on the sharing of their data with others. In certain circumstances the Data Subject can also object to the processing of their data, however, this is not an absolute right and will only be applicable in certain circumstances. Every organisation that processes personal information must submit a notification to the Information Commissioner, unless they are exempt. The notification includes a description of the data subjects about whom personal information is held, the purpose(s) for which it is held, the classes of data held, a list of the recipients of that data, ie who that data will be shared with. Failure to notify constitutes an offence under the Act. The Information Commissioner is responsible for policing the Act and issues Information and Enforcement Notices to organisations where they are not complying with the requirements of the Act. He also has the ability to prosecute those who commit offences under the Act and to issue Monetary Penalty Notices. The Information Commissioner has powers to levy a penalty of up to 500,000 for each Data Protection Principle breached up to a maximum of 3 Data Protection Principles. This is for the most serious breaches and could therefore result in the potential for up to a 1.5 million in penalty charges being imposed on the Organisation, or where a August Version 1.1

4 Director or Senior Manager has either knowingly breached the Act or where they should have known that they would breach the Act or has pressurised someone within the Organisation to breach the Act, they would then be putting themselves at risk of being personally liable for payment of the penalty charge. A First-Tier Tribunal (Information Rights) - a separate body, hears appeals against decisions made by the Information Commissioner under the Act. 3 Policy Statement The Council is committed to ensuring that personal information is handled in a secure and confidential manner in accordance with its obligations under the Data Protection Act 1998 and professional guidelines. The Council will use all appropriate and necessary means at its disposal to comply with the Data Protection Act and associated guidance. 4 Roles and Responsibilities 4.1 Data Protection Officer The Data Protection Officer is the Knowledge and Information Service Manager, and they are responsible for ensuring that the organisation complies with its responsibilities under the Act. The Data Protection Officer is also responsible for ensuring that the Data Protection Notification for Herefordshire Council is current and personal data is processed in accordance with that Notification. The Data Protection Officer is responsible for remaining up to date on guidance issued by the Information Commissioner relating to the application of the Act and providing advice and assistance on Data Protection matters as and when required. The Data Protection Officer is also responsible for the oversight of the Information Governance function and related training. 4.2 Information Management and Technology Board The Information Management and Technology Board will be responsible for ensuring that the organisation complies with its responsibilities under the Data Protection Act through monitoring of activities and incidents via regular reporting by the Data Protection Officer. The Board will also ensure that there is adequate resources to support the work outlined in this policy to ensure compliance with the Data Protection Act, and in particular that there is capacity within the Knowledge and Information Service to support compliance. 4.3 Knowledge and Information Steering Group The Group will be responsible for discussing and resolving any Data Protection and Confidentiality issues which may arise. 4.4 Directors/Assistant Directors/Service Managers/Team Leaders All Directors, Assistant Directors, Service Managers and Team Leaders will be fully aware of their responsibility with regard to the Data Protection Act. This will be accomplished through inclusion in staff contracts and job descriptions, coupled with the provision of appropriate awareness training, supported by local policies and procedures detailing organisational and individual responsibilities and action required to ensure compliance with the Act. August Version 1.1

5 They will ensure that: All staff for which they are responsible are provided with appropriate training with regard to the requirements of the Act and their responsibilities under it. Information is created and stored in accordance with the Council s Records Management Policy and Procedures to facilitate easy location should it be required and to ensure that records are retained in line with the Fifth Principle of the Act. Personal information is only used for the purposes specified within the Council s Data Protection Notification. Information is handled in a secure and confidential manner. The Data Protection Officer is informed of all databases created and/or held within their area, in order that the Council can ensure that the Data Protection Notification covers their use. They comply with Data Protection Audits as and when required. 4.5 Knowledge and Information Service The Knowledge and Information Service will:- Produce and maintain up-to-date policies and procedures to ensure compliance with current legislation and guidelines; Produce training packages to ensure staff are fully aware of their responsibilities under the Act; Audit processes and procedures to ensure staff both understand and comply with their responsibilities under the Act. Support members of staff to conduct appropriate Privacy Impact Assessments and reviews. Work with the Data Protection Officer to ensure organisation wide compliance with the Act Work with council departments, and where appropriate with partner organisations, to ensure that appropriate mechanisms are in place to raise staff awareness within the Council. 4.6 Legal Services Legal Services will:- Provide advice and assistance on matters relating to the Data Protection Act as required. August Version 1.1

6 .4.7 Social Care Social Care services for children and for adults will ensure that there is resource available to process subject access requests for files, supported by Legal Services and the Information and Records Management Team. 4.8 All Staff All Staff will ensure that:- Personal information is treated in a confidential manner in accordance with this and any associated policies. Personal information is only used for the stated purpose, unless explicit consent has been given by the Data Subject to use their information for a different purpose. Personal information is only disclosed on a strict need to know basis, to recipients who are entitled to that information. Personal information is recorded accurately and is kept up to date. They create and maintain their own records in accordance with the Council Records Management Policy and associated policies and procedures to facilitate easy location of records as required. They refer any potential or actual Subject Access Requests to the appropriate member of staff (Data Protection Officer or for Social Care, the Assistant Records Manager). They raise actual or potential breaches of the Data Protection Act either to their Line Manager, the Data Protection Officer, The Information Security Monitoring Officer, Legal Services, or the Information and Records Management Team Leader. Consent is obtained before using cookies on web sites. A Privacy Impact Assessment is carried out when initiating projects. It is the responsibility of all staff to ensure that they comply with the requirements of this policy and any associated policies or procedures. Failure to do so may result in disciplinary action being taken. 4.9 Contractors and Employment Agencies Where contractors or employment agencies are used, the contracts between the Council and these third parties should contain mandatory information assurance clauses to ensure that the contract staff are bound by the same code of behaviour as Council members of staff Volunteers August Version 1.1

7 All volunteers are bound by the same code of behaviour as Council members of staff. 5 Definitions 5.1 Personal Data Data which relates to a living individual who can be identified either from those data or from those data in conjunction with any other data which is, or is likely to come into the possession of the Data Controller and includes any expression of opinion and any indication of the intention of the Data Controller or any other person in respect of the individual. Personal data held by the Council and therefore subject to the provisions of the Act includes information about service users, members of staff, contractors and volunteers. 5.2 Data Subject The individual to which the data relates, including individual service users, and members of staff. 5.3 Data Controller An individual or organisation who, either alone, jointly or in common with other persons, decides the purposes for which personal data are, or will be processed and the way in which that data are or will be processed. The Data Controller for the Council is Herefordshire Council, though in some cases Herefordshire Council will be a joint Data Controller with another organisation, in particular when working with partner organisations such as Hoople which service our requirements as a Council (for example, Human Resources functions). 6 Records Management Good records management practice plays a pivotal role in ensuring that the Council is able to meet its obligations to provide information, and to retain it, in a timely and effective manner in order to meet the requirements of the Act. It is necessary to ensure that robust records management practices are in place which are understood and implemented by all staff dealing with records within the Council. It is the responsibility of all staff to ensure that they are familiar with the policies, procedures and schedules relating to records management within the Council, these include: Records Management Policy Corporate Electronic Records Procedure Corporate Paper Records Procedure Retention Schedules Version Control Procedure 7 Consent The Council will take all reasonable steps to ensure that service users, members of staff, volunteers, and contractors are informed of the reasons the Council requires information from them, how that information will be used and who it will be shared with. This will enable the Data Subject to give informed consent to the Council handling their data and where the data is sensitive personal data to give explicit consent. August Version 1.1

8 Should the Council wish to use personal data for any purpose other than that specified when it was originally obtained, the Data Subject s explicit consent should be obtained prior to using the data in the new way unless exceptionally such use is in accordance with other provisions of the Act. Should the Council wish to share personal data with anyone other that those recipients specified at the time the data was originally obtained, the Data Subject s explicit consent should be obtained prior to sharing that data, failure to do so could result in a breach of confidentiality. Failure to obtain explicit consent to either use or share personal data in ways other than those specified when the data was obtained could result in a breach of the First Data Protection Principle, ie that Personal data shall be processed fairly and lawfully. 8 Databases Containing Personal Data A database is any collection of personal information that can be processed by automated means, these could include:- personal details used for providing a service personal information used for research staff records held on an Excel Spreadsheet to monitor annual leave and sickness staff personal details used for monitoring training courses attended etc. It is important that data collected from individuals is both accurate and complete and is justified for the purpose for which it is being collected. All new system developments should be advised to the Data Protection Officer and comply with the Council s Data Protection Notification. 9 Retention and Disposal of Information All records should be retained and disposed of in accordance with the Council s retention schedules. 10 Accuracy and Data Quality It is the right under the Data Protection Act 1998 of any living individual about whom personal information is held, for that information to be accurate, relevant and up to date. In order to ensure compliance with the Act, the Council will ensure that all reasonable steps are taken to confirm the validity of personal information directly with the Data Subject. All members of staff must ensure that service user personal information is checked and kept up to date on a regular basis by checking it with the service user when they attend for appointments in order that the information held can be validated. Staff information should be checked for accuracy on a regular basis by the line manager. 11 Subject Access Requests August Version 1.1

9 All staff must ensure that requests for the personal information of living individuals made under the Data Protection Act 1998 are dealt with in accordance with the Council s procedures for processing subject access requests. 12 Privacy and Electronic Communications Regulations 2003 The Privacy and Electronic Communications Regulations 2003 set out requirements for respecting privacy with electronic communications. The Regulations have been amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations The new rules require in most cases that websites wanting to use cookies get consent, and mat affect the Council if the Council carries out actions that can be defined as marketing within the Regulations. 13 Privacy Impact Assessments A Privacy Impact Assessment is a process which helps to assess privacy risks to individuals in the collection, use and disclosure of information. To be effective, they must be carried out at the early stages of projects. The key elements of a Privacy Impact Assessment are: Initial Assessment Full-Scale Privacy Impact Assessment Small-Scale Privacy Impact Assessment Privacy Law Compliance Check Data Protection Compliance Check Review 14 Providers Contracts made with partner organisations must contain clauses to ensure that there is an adequate Data Protection competence by partners in fulfilling services on the Council s behalf. Where the work is specialised and tied in with Council staff the Council will provide training for partner organisation staff to reduce the risk of a data protection breach. The Council s key providers include: Amey Wye Valley Focsa Halo Hoople 15 Complaints Section 42 of the Data Protection Act 1998 gives an individual the right to complain to the Information Commissioner if they feel that the Act has been breached. The Council s making experiences count Procedure details the procedure to be followed in the case of complaints relating to the way the Council has complied with its obligations under the Data Protection Act In line with the Council s making experiences count procedure, any expression of dissatisfaction from an applicant (written or verbal) with reference to the Council s handling of personal information will be treated as a complaint. August Version 1.1

10 Should the complainant remain dissatisfied with the outcome of their complaint to the Council once the Complaints Procedure has been exhausted, a complaint can be made to the Information Commissioner who will then investigate the complaint and take action where necessary. A Data Protection Complaints form can be obtained either from the Information Commissioner s Website at or by telephoning the helpline on Security and Confidentiality All staff must ensure that information relating to identifiable individuals is kept secure and confidential at all times. The Council will ensure that its holdings of personal data are properly secured from loss or corruption and that no unauthorised disclosures of personal data are made. Further information can be found in the Information Security Policy and Procedure Suite. The Council will ensure that information is not transferred to countries outside the European Economic Area (EEA) unless that country has an adequate level of protection for security and confidentiality of information and this has been confirmed by the Information Commissioner. Information on countries with an adequate level of protection and the US Safe Harbor agreements is detailed on the Information Commissioner s website at: px. 17 Informing Staff of Data Protection Requirements The Council will inform staff of their responsibilities under the Data Protection Act through the normal communication mechanisms within the Council, coupled with induction and refresher training and the cascade of information via Heads of Profession, Departmental Managers and Team Leaders in line with their responsibilities detailed at Section Reporting The Data Protection Officer will be responsible for compiling an annual report for the Information Management and Technology Board, which provides details of subject access requests received and the responses to them. A quarterly report will be produced by Legal Services and the Information and Records Management Service summarising the number of requests, number of refusals, the number of responses which did not meet the response target and the number of complaints. 19 Monitoring and Audit This Policy and associated procedures will be monitored by the Knowledge and Information Expert Forum. Compliance will also be monitored through Internal Audit. August Version 1.1

11 20 Offences Under the Act It is an offence to process personal data without notification, or failure to notify the Commissioner of changes to the notification register entry. It is an offence for a person, knowingly or recklessly, without the consent of the Data Controller to obtain, disclose or procure personal data or the information contained in personal data, unless the person can show that: it was necessary to prevent or detect crime; it was required or authorised by law; they acted in the reasonable belief that they had a legal right to do so; the Data Controller would have consented to if if they had known; in the particular circumstances it was justified as being in the public interest. 21 Associated Legislation and Guidance Access to Health Records Act 1990 Human Rights Act 1998 Freedom of Information Act 2000 Regulation of Investigatory Powers Act 2000 Crime and Disorder Act 1988 Mental Capacity Act 2005 Computer Misuse Act 1990 Police and Criminal Evidence Act 1984 Section and 79: The Adoption and Children Act 2002 Road Traffic Act 1988 Privacy and Electronic Communications Regulations 2003 Privacy and Electronic Communications (EC Directive) (Amendment) Regulations Risks The risks of not ensuring adequate data protection compliance (including when using provider services as data processors on behalf of the Council as data controller) are: incurring of monetary penalties if a breach of the Data Protection Act occurs complaints from the community if their privacy rights are violated loss of reputation through a lack of trust by the community in handling confidential information The Council s corporate risk register will include any specific data protection risks and actions taken to mitigate them. August Version 1.1

12 APPENDIX 1 DATA PROTECTION PRINCIPLES First Principle Personal data shall be processed fairly and lawfully, (in particular shall not be processed unless: At least one of the conditions in Schedule 2 of the Data Protection Act is met (see Appendix 2); and In the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met (see Appendix 3). Sensitive data is information relating to the physical or mental health of the data subject (healthcare records), information relating to the Data Subject s racial or ethnic origin, sexual life, criminal records or offences, political opinions, membership of trade unions or religious beliefs. 2 Second Principle Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose, or those purposes. 3 Third Principle Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. 4 Fourth Principle Personal data shall be accurate and, where necessary, kept up to date. 5 Fifth Principle Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. 6 Sixth Principle Personal data shall be processed in accordance with the rights of the data subjects under this Act. 7 Seventh Principle Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. 8 Eighth Principle Personal data shall not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection of the rights and freedoms of data subjects in relation to the processing of personal data or the data subject has given consent for the transfer to take place. August Version 1.1

13 APPENDIX 2 DATA PROTECTION ACT 1998 SCHEDULE 2 Schedule 2 of the Data Protection Act 1998 specifies conditions Relevant to the Processing of Personal or Sensitive Data: a) The data subject has given his/her consent to the processing b) The processing is necessary for: the performance of a contract to which the data subject is a party, or for the taking of steps at the request of the data subject with a view to entering into a contract. c) The processing is necessary for compliance with any legal obligation to which the data controller is subject, other than an obligation imposed by contract d) The processing is necessary to protect the vital interests of the data subject. e) The processing is necessary for the administration of justice for the exercise of any functions conferred on any person by or under any enactment for the exercise of any functions of the Crown, a Minister of the Crown or a government department for the exercise of any other functions of a public nature exercised in the public interest by any person f) The processing is necessary for the purpose of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except when the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject. The Secretary of State may by order specify particular circumstances in which this condition is, or is not, to be taken to be satisfied. August Version 1.1

14 APPENDIX 3 DATA PROTECTION ACT 1998 SCHEDULE 3 Conditions relevant for the processing of sensitive personal data: 1. That the data subject has given his explicit consent to the processing of the personal data. 2. (1) The processing is necessary for the purposes of exercising or performing any right or obligation which is conferred or imposed by law on the data controller in connection with employment. (2) The Secretary of State may by order (a) exclude the application of sub-paragraph (1) in such cases as may be specified, or (b) provide that, in such cases as may be specified, the condition in sub-paragraph (1) is not to be regarded as satisfied unless such further conditions as may be specified in the order are also satisfied 3. The processing is necessary (a) in order to protect the vital interests of the data subject or another person, in any case where (i) consent cannot be given by or on behalf of the data subject, or (ii) the data controller cannot reasonably be expected to obtain the consent of the data subject, or (b) in order to protect the vital interests of another person, in a case where consent by or on behalf of the data subject has been unreasonably withheld 4. The processing (a) is carried out in the course of its legitimate activities by any body or association which (b) (i) is not established or conducted for profit, and (ii) exists for political, philosophical, religious or trade union purposes is carried out with appropriate safeguards for the rights and freedoms of data subjects (c) relates only to individuals who either are members of the body or association or have regular contact with it in connection with its purposes, and (d) does not involve disclosure of the personal data to a third party without the consent of the data subject. 5. The information contained in the personal data has been made public as a result of steps deliberately taken by the data subject. August Version 1.1

15 6. The processing (a) is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings) (b) is necessary for the purpose of obtaining legal advice, or (c) is otherwise necessary for the purposes of establishing, exercising or defending legal rights 7. (1) The processing is necessary (a) for the administration of justice (b) for the exercise of any functions conferred on any person by or under an enactment, or (c) for the exercise of any functions of the Crown, a Minister of the Crown or a government department. (2) the Secretary of State may by order (a) exclude the application of sub-paragraph (1) in such cases as may be specified, or (b) provide that, in such cases as may be specified, the condition in sub-paragraph (1) is not to be regarded as satisfied unless such further conditions as may be specified in the order are also satisfied. 8. (1) The processing is necessary for medical purposes and is undertaken by (a) a health professional, or a person who in the circumstances owes a duty of confidentiality which is equivalent to that which would arise if that person were a health professional (2) In this paragraph 'medical purposes' includes the purposes of preventative medicine, medical diagnosis, medical research, the provision of care and treatment and the management of health care services. 9. (1) The processing (a) is of sensitive personal data consisting of information as to racial or ethnic origin, (b) is necessary for the purpose of identifying or keeping under review the existence of absence of equality of opportunity or treatment between persons of different racial or ethnic origins, with a view to enabling such equality to be promoted or maintained. (c) is carried out with appropriate safeguards for the rights and freedoms of data subjects. 10. The personal data are processed in circumstances specified in an order made by the Secretary of State for the purposes of this paragraph. August Version 1.1

Corporate ICT & Data Management. Data Protection Policy

Corporate ICT & Data Management. Data Protection Policy 90 Corporate ICT & Data Management Data Protection Policy Classification: Unclassified Date Created: January 2012 Date Reviewed January Version: 2.0 Author: Owner: Data Protection Policy V2 1 Version Control

More information

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data;

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; OBJECTS AND REASONS This Bill would provide for (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; (b) the protection of the privacy of individuals in relation

More information

Data Protection Policy

Data Protection Policy 1 Data Protection Policy Version 1: June 2014 1 2 Contents 1. Introduction 3 2. Policy Statement 3 3. Purpose of the Data Protection Act 1998 3 4. The principles of the Data Protection Act 1998 4 5 The

More information

Data Protection Policy

Data Protection Policy Data Protection Policy CONTENTS Introduction...2 1. Statement of Intent...2 2. Fair Processing or Privacy Statement...3 3. Data Uses and Processes...4 4. Data Quality and Integrity...4 5. Technical and

More information

Information Governance Policy

Information Governance Policy Information Governance Policy 1 Introduction Healthwatch Rutland (HWR) needs to collect and use certain types of information about the Data Subjects who come into contact with it in order to carry on its

More information

HERTSMERE BOROUGH COUNCIL

HERTSMERE BOROUGH COUNCIL HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act

More information

GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT. CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4

GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT. CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4 GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4 PREFACE The following provides general guidance on data protection

More information

Data Protection Policy

Data Protection Policy Data Protection Policy September 2015 Contents 1. Scope 2. Purpose 3. Data protection roles 4. Staff training and guidance 5. About the Data Protection Act 1998 6. Policy 7. The Information Commissioner's

More information

DATA PROTECTION ACT 1998 COUNCIL POLICY

DATA PROTECTION ACT 1998 COUNCIL POLICY DATA PROTECTION ACT 1998 COUNCIL POLICY Page 1 of 5 POLICY STATEMENT Blackpool Council recognises the need to fully comply with the requirements of the Data Protection Act 1998 (DPA) and the obligations

More information

Little Marlow Parish Council Registration Number for ICO Z3112320

Little Marlow Parish Council Registration Number for ICO Z3112320 Data Protection Policy Little Marlow Parish Council Registration Number for ICO Z3112320 Adopted 2012 Reviewed 23 rd February 2016 Introduction The Parish Council is fully committed to compliance with

More information

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk Data Protection Act 1998 The for the Borough Council of King's Lynn & West Norfolk 1 Contents Introduction 3 1. Statement of Intent 4 2. Fair Obtaining I Processing 5 3. Data Uses and Processes 6 4. Data

More information

Human Resources and Data Protection

Human Resources and Data Protection Human Resources and Data Protection Contents 1. Policy Statement... 1 2. Scope... 2 3. What is personal data?... 2 4. Processing data... 3 5. The eight principles of the Data Protection Act... 4 6. Council

More information

Data Protection Policy June 2014

Data Protection Policy June 2014 Data Protection Policy June 2014 Approving authority: Consultation via: Court Audit and Risk Committee, University Executive, Secretary's Board, Information Governance and Security Group Approval date:

More information

CORK INSTITUTE OF TECHNOLOGY

CORK INSTITUTE OF TECHNOLOGY CORK INSTITUTE OF TECHNOLOGY DATA PROTECTION POLICY APPROVED BY GOVERNING BODY ON 30 APRIL 2009 INTRODUCTION Cork Institute of Technology is committed to a policy of protecting the rights and privacy of

More information

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers Office of the Data Protection Commissioner of The Bahamas Data Protection (Privacy of Personal Information) Act, 2003 A Guide for Data Controllers 1 Acknowledgement Some of the information contained in

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title Author Approved By and Date Review Date Mike Pilling Latest Update- Corporation May 2008 1 Aug 2013 DATA PROTECTION ACT 1998 POLICY FOR ALL STAFF AND STUDENTS 1.0 Introduction 1.1 The Data Protection

More information

Dublin City University

Dublin City University Dublin City University Data Protection Policy Data Protection Policy Contents Purpose... 1 Scope... 1 Data Protection Principles... 1 Disclosure of Personal Data... 2 Summary of Responsibilities... 3 Rights

More information

technical factsheet 176

technical factsheet 176 technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection

More information

Merthyr Tydfil County Borough Council. Data Protection Policy

Merthyr Tydfil County Borough Council. Data Protection Policy Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Data Protection Policy Version: 3 Reference Number: CO59 Keywords: Data, access, principles, protection, Act. Data Subject, Information Supersedes Supersedes:

More information

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY Originated by: Data Protection Working Group: November 2008 Impact Assessment: (to be confirmed) Recommended by Senate: 28 January 2009 Approved by Council:

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY DATA PROTECTION POLICY Document Control Information Title Data Protection Policy Version V1.0 Author Diana Watt Date Approved 21 February 2013 Review Date Annually, on the anniversary

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Version 1.3 April 2014 Contents 1 POLICY STATEMENT...2 2 PURPOSE....2 3 LEGAL CONTEXT AND DEFINITIONS...2 3.1 Data Protection Act 1998...2 3.2 Other related legislation.....4 3.3

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Document Ref: DPA20100608-001 Version: 1.3 Classification: UNCLASSIFIED (IL 0) Status: ISSUED Prepared By: Ian Mason Effective From: 4 th January 2011 Contact: Governance Team ICT

More information

2. Scope 2.1 This policy covers all the activities and processes of the University that uses personal information in whatever format.

2. Scope 2.1 This policy covers all the activities and processes of the University that uses personal information in whatever format. University of Westminster Personal Data Protection Policy For Compliance with the Data Protection Act 1998 1. Background 1.1 The Data Protection Act 1998 (DPA) defines personal data as data and information

More information

DATA PROTECTION AUDIT GUIDANCE

DATA PROTECTION AUDIT GUIDANCE DATA PROTECTION AUDIT GUIDANCE CONTENTS Section I: Section II: Audit of Processing of Personal Data Audit Procedure Appendices: A B C D E Audit Form List of Purposes List of data subjects List of data

More information

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Controller Policy Contents INTRODUCTION 3 PART I: BACKGROUND AND ACTIONS 4 PART II: CONTROLLER OBLIGATIONS 6 PART III: APPENDICES 13 2 P a g e INTRODUCTION

More information

Personal Data Act (1998:204);

Personal Data Act (1998:204); Personal Data Act (1998:204); issued 29 April 1998. Be it enacted as follows. General provisions Purpose of this Act Section 1 The purpose of this Act is to protect people against the violation of their

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Prepared By: Malkiat Thiarai Head of Corporate Information Management Date of Publication: 23/01/2013 Version: 5.0 Classification: Not Protectively Marked Page 1 Table of Contents

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Approval date: June 2014 Approved by: Board Responsible Manager: Executive Director of Resources Next Review June 2016 Data Protection Policy 1. Introduction Data Protection Policy

More information

Data Protection. Policy and Application July 2009

Data Protection. Policy and Application July 2009 Data Protection Policy and Application July 2009 Produced for staff of the House of Commons Service by the Department of Resources Information Rights and Information Security (IRIS) Service Data Policy:

More information

Data Protection in Ireland

Data Protection in Ireland Data Protection in Ireland 0 Contents Data Protection in Ireland Introduction Page 2 Appointment of a Data Processor Page 2 Security Measures (onus on a data controller) Page 3 8 Principles Page 3 Fair

More information

Data Protection Act. Privacy & Security in the Information Age. April 26, 2013. Ministry of Communications, Ghana

Data Protection Act. Privacy & Security in the Information Age. April 26, 2013. Ministry of Communications, Ghana Data Protection Act Privacy & Security in the Information Age April 26, 2013 Agenda Privacy in The Information Age The right to privacy Why We Need Legislation Purpose of the Act The Data Protection Act

More information

An overview of UK data protection law

An overview of UK data protection law An overview of UK data protection law Our team Vinod Bange Partner +44 (0)20 7300 4600 v.bange@taylorwessing.com Graham Hann Partner +44 (0)20 7300 4839 g.hann@taylorwessing.com Chris Jeffery Partner +44

More information

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY Page 1 of 16 Contents Policy Information 3 Introduction 4 Responsibilities 7 Confidentiality 9 Data recording and storage 11 Subject Access 12 Transparency

More information

QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN 18 085 048 237. better health cover shouldn t hurt

QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN 18 085 048 237. better health cover shouldn t hurt QUEENSLAND COUNTRY HEALTH FUND privacy policy Queensland Country Health Fund Ltd ABN 18 085 048 237 better health cover shouldn t hurt 1 2 contents 1. Introduction 4 2. National Privacy Principles 5 3.

More information

The Manitowoc Company, Inc.

The Manitowoc Company, Inc. The Manitowoc Company, Inc. DATA PROTECTION POLICY 11FitzPatrick & Associates 4/5/04 1 Proprietary Material Version 4.0 CONTENTS PART 1 - Policy Statement PART 2 - Processing Personal Data PART 3 - Organisational

More information

Index. Definitions. What is Data Protection? Rights of Individuals. The 8 Principles of Data Protection

Index. Definitions. What is Data Protection? Rights of Individuals. The 8 Principles of Data Protection Data Protection Awareness Based on DIT s Data Protection Policy, the Data Protection Acts, 1988 & 2003 and guidance from the Office of the Data Protection Commissioner Index Definitions What is Data Protection?

More information

AlixPartners, LLP. General Data Protection Statement

AlixPartners, LLP. General Data Protection Statement AlixPartners, LLP General Data Protection Statement GENERAL DATA PROTECTION STATEMENT 1. INTRODUCTION 1.1 AlixPartners, LLP ( AlixPartners ) is committed to fulfilling its obligations under the data protection

More information

Data Protection and Community Councils Briefing Note

Data Protection and Community Councils Briefing Note Data Protection and Community Councils Briefing Note This briefing note has been prepared in response to specific queries raised by Community Councils in Marr in relation to their Data Protection requirements.

More information

DATA PROTECTION AND DATA STORAGE POLICY

DATA PROTECTION AND DATA STORAGE POLICY DATA PROTECTION AND DATA STORAGE POLICY 1. Purpose and Scope 1.1 This Data Protection and Data Storage Policy (the Policy ) applies to all personal data collected and dealt with by Centre 404, whether

More information

DATA PROTECTION ACT 2002 The Basics

DATA PROTECTION ACT 2002 The Basics DATA PROTECTION ACT 2002 The Basics Purpose of the Act Balance the rights of an individual with an organisation s legitimate need to process personal data Promote openness and transparency Establish and

More information

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS As a world leader in electronic commerce and payment services, First Data Corporation and its subsidiaries ( First Data entity or entities ),

More information

Data Protection Act a more detailed guide

Data Protection Act a more detailed guide Data Protection Act a more detailed guide What does the Act do? The Data Protection Act 1998 places considerable duties on organisations which process personal data; increases the rights of access by data

More information

UNIVERSITY OF ABERDEEN POLICY ON DATA PROTECTION

UNIVERSITY OF ABERDEEN POLICY ON DATA PROTECTION UNIVERSITY OF ABERDEEN POLICY ON DATA PROTECTION The Data Protection Act 1998 (DPA) was passed in order to implement the EU Data Protection Directive (95/46/EC) and applies to all data relating to, and

More information

Data Protection Procedures

Data Protection Procedures Data Protection Procedures PROCEDURE OVERVIEW: This Procedure outlines Down District Council s ( the Council ) commitment to the Data Protection Act 1998 ( the Act ) and provides a framework for the Council

More information

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document Data Protection Processing and Transfer of Personal Data in Kvaerner Binding Corporate Rules Public Document 1 of 19 1 / 19 Table of contents 1 Introduction... 4 1.1 Scope... 4 1.2 Definitions... 4 1.2.1

More information

DATA PROTECTION MANUAL

DATA PROTECTION MANUAL DATA PROTECTION MANUAL VERSION TABLE Version Date Published CO Circular 1 September 2008 3 July 2015 July 2015 2 CONTENTS Part A: General Guidance 1 Introduction to the Data Protection Act 1998 5 2 The

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY The information and guidelines within this Policy are important and apply to all members, Fellows and staff of the College 1. INTRODUCTION Like all educational establishments, the

More information

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT 2300 Pursuant to its authority from Article 59 of the Rules of Procedure of the Croatian Parliament, the Legislation Committee determined the revised text

More information

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 EUROPEAN COMMUNITIES (ELECTRONIC COMMUNICATIONS NETWORKS AND SERVICES) (PRIVACY AND ELECTRONIC COMMUNICATIONS) REGULATIONS 2011 (Prn. A11/1165) 2 [336] S.I.

More information

Human Resources Policy documents. Data Protection Policy

Human Resources Policy documents. Data Protection Policy Policy documents Aims of the Policy apetito is committed to meeting its obligations under data protection law. As a business, apetito handles a range of Personal Data relating to its customers, staff and

More information

Rick Parsons Information Governance Officer County Hall 01865 323593 rick.parsons@oxfordshire.gov.uk

Rick Parsons Information Governance Officer County Hall 01865 323593 rick.parsons@oxfordshire.gov.uk Rick Parsons Information Governance Officer County Hall 01865 323593 rick.parsons@oxfordshire.gov.uk 1 THE DATA PROTECTION ACT 1998 2 Requirements of the Act Roles & Responsibilities Best Practice 3 The

More information

Scottish Rowing Data Protection Policy

Scottish Rowing Data Protection Policy Revision Approved by the Board August 2010 1. Introduction As individuals, we want to know that personal information about ourselves is handled properly, and we and others have specific rights in this

More information

The Manchester College

The Manchester College The Manchester College The Manchester College Produced by TMC Prin DataProtect pol v1 11/2010 All rights reserved; no part of this publication may be photocopied, recorded or otherwise reproduced, stored

More information

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS Mat Wright www.britishcouncil.org CONTENTS Purpose of the code 1 Scope of the code 1 The British Council s data protection commitment and

More information

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy) PRESIDENT S DECISION No. 40 of 27 August 2013 Regarding Data Protection at the European University Institute (EUI Data Protection Policy) THE PRESIDENT OF THE EUROPEAN UNIVERSITY INSTITUTE, Having regard

More information

Data Protection Policy.

Data Protection Policy. Data Protection Policy. Data Protection Policy Foreword 2 Foreword Ladies and Gentlemen, In the information age, we offer customers the means to be always connected, even in their cars. This requires data

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY MILNBANK HOUSING ASSOCIATION DATA PROTECTION POLICY LS/NOV.2011/REF.P14 1) INTRODUCTION Milnbank Housing Association recognises that the Data Protection Act 1998 is an important piece of legislation to

More information

Privacy Policy. Board for Lutheran Education Australia. Policy. Purpose. Exclusion

Privacy Policy. Board for Lutheran Education Australia. Policy. Purpose. Exclusion Policy Relevant to Responsible officer Contact officer Authorisation Date introduced March 2014 Effective date of latest version March 2014 Next review date March 2017 Relevant legislation or source Board

More information

1.2 Scope This policy and guidance applies to all University staff, students and others who use or process any personal information.

1.2 Scope This policy and guidance applies to all University staff, students and others who use or process any personal information. MANCHESTER METROPOLITAN UNIVERSITY DATA PROTECTION POLICY This policy should be read in conjunction with the Data Protection Guidance, which is attached as: Appendix A Dealing with Personal Data Appendix

More information

Policy and Procedure Title: Maintaining Secure Learner Records Policy No: CCTP1001 Version: 1.0

Policy and Procedure Title: Maintaining Secure Learner Records Policy No: CCTP1001 Version: 1.0 PROVIDER NAME: POLICY AREA: College of Computing Technology (CCT) Standard 10: Information Management, Student Information System & Data Protection Policy and Procedure Title: Maintaining Secure Learner

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages

More information

Data Protection Guidance

Data Protection Guidance 53 September 2010 Management Circular No. 53 Glasgow City Council Education Services Wheatley House 25 Cochrane Street Merchant City GLASGOW G1 1HL To Heads of all Educational Establishments Data Protection

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19 Protection of Personal Data RPC001147_EN_D_19 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Rules Responsibility

More information

Data Protection Policy

Data Protection Policy Internal Ref: NELC 16.60 Review date December 2016 Version No. V04 Data Protection Policy 1 Data Protection Statement Data Protection Policy 1.1 North East Lincolnshire Council recognises that in order

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version: V1 Ratified by: Operational Management Executive Committee Date ratified: 26 September 2013 Name and Title of originator/author(s): Chris Brady, FOI, Data Protection and

More information

DATA PROTECTION POLICY. Examples of personal data which TWM may require from clients include the following and for the reasons ascribed to each;

DATA PROTECTION POLICY. Examples of personal data which TWM may require from clients include the following and for the reasons ascribed to each; DATA PROTECTION POLICY Introduction TWM Solicitors maintain certain personal data about individuals for the purposes of satisfying operational and legal obligations. The Data Protection Act sets rules

More information

Guidelines on Data Protection. Draft. Version 3.1. Published by

Guidelines on Data Protection. Draft. Version 3.1. Published by Guidelines on Data Protection Draft Version 3.1 Published by National Information Technology Development Agency (NITDA) September 2013 Table of Contents Section One... 2 1.1 Preamble... 2 1.2 Authority...

More information

ATMD Bird & Bird. Singapore Personal Data Protection Policy

ATMD Bird & Bird. Singapore Personal Data Protection Policy ATMD Bird & Bird Singapore Personal Data Protection Policy Contents 1. PURPOSE 1 2. SCOPE 1 3. COMMITMENT TO COMPLY WITH DATA PROTECTION LAWS 1 4. PERSONAL DATA PROTECTION SAFEGUARDS 3 5. ATMDBB EXCEPTIONS:

More information

Caedmon College Whitby

Caedmon College Whitby Caedmon College Whitby Data Protection and Information Security Policy College Governance Status This policy was re-issued in June 2014 and was adopted by the Governing Body on 26 June 2014. It will be

More information

Corporate Policy. Data Protection for Data of Customers & Partners.

Corporate Policy. Data Protection for Data of Customers & Partners. Corporate Policy. Data Protection for Data of Customers & Partners. 02 Preamble Ladies and gentlemen, Dear employees, The electronic processing of virtually all sales procedures, globalization and growing

More information

Data Protection Avoiding Information Commissioner Fines. Caroline Egan 5 June 2014

Data Protection Avoiding Information Commissioner Fines. Caroline Egan 5 June 2014 Data Protection Avoiding Information Commissioner Fines Caroline Egan 5 June 2014 Why is data protection a hot topic in pensions? Pension schemes hold large amounts of personal data Individuals more aware

More information

Data protection policy

Data protection policy Data protection policy Introduction 1 This document is the data protection policy for the Nursing and Midwifery Council (NMC). 2 The Data Protection Act 1998 (DPA) governs the processing of personal data

More information

Data Protection Acts 1988 and 2003: Informal Consolidation

Data Protection Acts 1988 and 2003: Informal Consolidation Page 1 of 55 Data Protection Acts 1988 and 2003: Informal Consolidation IMPORTANT NOTICE This document is an informal consolidation of the Data Protection Acts 1988 and 2003, prepared by the Office of

More information

Data Protection and Privacy Policy

Data Protection and Privacy Policy Data Protection and Privacy Policy 1. General This policy outlines Conciliation Resources commitments to respect the privacy of people s personal information and observe the relevant data protection legislation.

More information

Data Protection Policy

Data Protection Policy Data Protection Policy April 2014 Author: Jennifer McLaren, Assistant Principal, Curriculum Support & Finance Impact Assessment Date: 15 February 2010 Date: April 2014 Contents 1 Purpose... 2 2 Policy...

More information

John Leggott College. Data Protection Policy. Introduction

John Leggott College. Data Protection Policy. Introduction John Leggott College Data Protection Policy Introduction The College needs to keep certain information about its employees, students and other users to allow it to monitor performance, achievements, and

More information

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data *) For the purposes of these Corporate Guidelines, Third Countries are all those countries, which do not

More information

PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE

PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE ADOPTED ON 9 th January 2008 TABLE OF CONTENTS Page No. 1 Introduction...3 2 Glossary...3 3 Types of Personal Data held by Us...3 4 Obligations

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Policy Details Produced by Assistant Principal Information Systems Date produced Approved by Senior Leadership Team (SLT) Date approved July 2011 Linked Policies and Freedom of Information

More information

Information Privacy Policy

Information Privacy Policy Information Privacy Policy pol-032 Version: 2.01 Last amendment: Oct 2014 Next Review: Aug 2017 Approved By: Council Date: 04 May 2005 Contact Officer: Director, Strategic Services and Governance INTRODUCTION

More information

DATA PROTECTION CORPORATE POLICY

DATA PROTECTION CORPORATE POLICY DATA PROTECTION CORPORATE POLICY Information Management V1.1 03 July 2012 Not protectively marked This policy must be complied with fully by all Members, Officers Agents and Contractors of Plymouth City

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1 Protection of Personal Data RPC001147_EN_WB_L_1 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Responsibility of Employees

More information

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY INFORMATION GOVERNANCE AND DATA PROTECTION POLICY WN CCG Information Governance & Data Protection Policy July 2013 1 Document Control Sheet Name of Document: Information Governance & Data Protection Policy

More information

GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS

GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS December 2005 2 GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS I. OBJECTIVE... 1 II. SCOPE... 1 III. APPLICATION OF LOCAL LAWS...

More information

Information Security Policy. Appendix B. Secure Transfer of Information

Information Security Policy. Appendix B. Secure Transfer of Information Information Security Policy Appendix B Secure Transfer of Information Author: Data Protection and Information Security Officer. Version: 0.7 Date: March 2008 Document Control Information Document ID Document

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date Approving Body N/A Governing Body Date of Approval

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Implementation date: 30 September 2014 Control schedule Approved by Corporate Policy and Strategy Committee Approval date 30 September 2014 Senior Responsible Officer Kirsty-Louise

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Rev No. 0 New Document 1 2 3 4 5 6 7 Revision Status Details of Amendments Name Date Update of College DPA statement New Reference to Appendix 4 Staff Guidelines ESF document retention

More information

University of Limerick Data Protection Compliance Regulations June 2015

University of Limerick Data Protection Compliance Regulations June 2015 University of Limerick Data Protection Compliance Regulations June 2015 1. Purpose of Data Protection Compliance Regulations 1.1 The purpose of these Compliance Regulations is to assist University of Limerick

More information

FIRST DATA CORPORATION SUMMARY: BINDING CORPORATE RULES FOR DATA PRIVACY AND PROTECTION

FIRST DATA CORPORATION SUMMARY: BINDING CORPORATE RULES FOR DATA PRIVACY AND PROTECTION FIRST DATA CORPORATION SUMMARY: BINDING CORPORATE RULES FOR DATA PRIVACY AND PROTECTION SUMMARY: BINDING CORPORATE RULES FOR DATA PRIVACY AND PROTECTION v 1.3 Supersedes: v 1.2 Summary Owner: Corporate

More information

Corporate Data Protection Policy

Corporate Data Protection Policy Corporate Data Protection Policy September 2010 Records Management Policy RMP-09 GOLDEN RULE When you think about Data Protection remember that we are all data subjects. Think about how appropriately and

More information

Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion

Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion Page 1 sur 155 Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion Legal nature of the instrument Règlement Directive Directly applicable act in internal law 91 articles 34 articles Art.

More information

GSK Public policy positions

GSK Public policy positions Safeguarding Personally Identifiable Information A Summary of GSK s Binding Corporate Rules The Issue The processing of Personally Identifiable Information (PII) 1 and Sensitive Personally Identifiable

More information

Data Protection Policy A copy of this policy is published in the following areas: The school s intranet The school s website

Data Protection Policy A copy of this policy is published in the following areas: The school s intranet The school s website Data Protection Policy A copy of this policy is published in the following areas: The school s intranet The school s website Date created: November 2015 Date for review: July 2016 Created by: Mark Vanstone,

More information

UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY

UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY 1. Purpose 1.1 The Data Protection Act 1998 ( the Act ) has two principal purposes: i) to regulate the use by those (known as data controllers) who obtain,

More information

DIFC LAW NO. 1 OF 2007

DIFC LAW NO. 1 OF 2007 DATA PROTECTION LAW DIFC LAW NO. 1 OF 2007 Consolidated Version (December 2012) Amended by Data Protection Law Amendment Law DIFC Law No. 5 of 2012 CONTENTS PART 1: GENERAL... 4 1. Title... 4 2. Legislative

More information

MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY. Ensuring Information is Accurate and Fit for Purpose

MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY. Ensuring Information is Accurate and Fit for Purpose MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY Index: Introduction Information is a Corporate Resource Personal Responsibility Information Accessibility Keeping Records of what we do Ensuring

More information

2015 No. 0000 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Businesses (Credit Information) Regulations 2015

2015 No. 0000 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Businesses (Credit Information) Regulations 2015 Draft Regulations to illustrate the Treasury s current intention as to the exercise of powers under clause 4 of the the Small Business, Enterprise and Employment Bill. D R A F T S T A T U T O R Y I N S

More information