Policy prepared by
Lawful Basis for Data Storage
Approved by the directors on
1st July 2021
Policy became operational on
1st July 2021
Next review date
1stth July 2022
Hague Dental Supplies Ltd (“The Company”) needs to collect and use certain types of information about the people with whom it deals in order to operate the business in an effective and responsible manner. This information can include current, past and prospective employees, suppliers, clients/customers and others with whom it communicates. In addition, it may occasionally be required by law to collect and use certain types of information of this kind to comply with the requirements of Government departments for example, business data. There are safeguards within UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018 (DPA 2018).to ensure that personal information is dealt with properly, however it is collected, recorded, and used.
We regard the lawful and correct treatment of personal information by the Company as very important to successful operations and to maintaining confidence between those with whom we deal and ourselves. We must ensure that our organisation treats personal information lawfully and correctly.
To this end we fully endorse and must adhere to the ‘Principles’ set out in Article 5 of the UK GDPR. Specifically, the ‘Principles’ require that personal information:
“Lawfulness, Fairness & Transparency”
Personal data shall be processed lawfully, fairly and in a transparent manner in relation to individuals;
Shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is compatible with those purposes;
Shall be adequate, relevant and where necessary, kept up to date;
Shall be accurate and where necessary, kept up to date
Shall not be kept for longer than is necessary for that purpose or those purposes;
“Integrity and confidentiality” –
Shall be processed in accordance with the rights of data subjects under the Act;
The controller shall be responsible for and be able to demonstrate compliance with the above.
Hague Dental Supplies is registered with the Information Commissioner’s Office as a Data Controller, the Company is responsible for all the personal data they hold.
All outside communications, queries and subject access requests relating to Data Protection issues should be addressed to the Kirsty Hague, Director, Hague Dental Supplies, 1 Graylands Gateway, Langhurstwood Road, Horsham RH12 4QD or sent to firstname.lastname@example.org
It is the policy of the Company to aim to ensure that all relevant statutory requirements are complied with and that the Company’s internal procedures are monitored periodically to ensure compliance.
It is the policy of the Company to endeavour to comply with any relevant Industry Codes of Practice issued by the Information Commissioner on the processing of data. In particular to endeavour to comply with the following conditions:
Observe fully conditions regarding the fair collection and use of information
Meet its legal obligations to specify the purposes for which information is used
Collect and process appropriate information and only to the extent that it is needed to fulfil operational needs or to comply with any legal requirements
Ensure the quality of information used
Apply strict checks to determine the length of time information is held
Ensure that the rights of people about whom information is held can be fully exercised under the Act (these include; the right to be informed that processing is being undertaken; the right of access to one’s personal information; the right to prevent processing in certain circumstances; the right to correct, rectify, block or erase information which is regarded as wrong information).
Take appropriate technical and organisational security measures to safeguard personal information;
Ensure that personal information is not transferred abroad without suitable safeguards
In addition The Company will ensure that:
In accordance with the DPA 2018, subject access requests will be actioned within one calendar month of the request being received. This time starts from receipt of identification from the data subject.
In accordance with the DPA 2018 the company will charge £10.00 for subject access requests deemed repetitive or excessive by the Company.
Data Protection is a responsibility shared by employees of the Company and employees have a duty to adhere to the rules, procedures and instructions that may be used from time to time by the Company to ensure this policy is effective. Disciplinary action will be taken against any employee who fails to comply with these rules and procedures.
The Company will take such measures as may be necessary to ensure the proper training, supervision and instructions of all relevant employees in matters pertaining to Data Protection and to provide any necessary information.
Each line manager and supervisor will have immediate responsibility for data protection matters in his/her own area of work.
THIRD PARTY PROCESSING
The Company will pass any data collected to third parties that assist the Company in the operation of its business. The information will only be passed to organisations that fully comply with the DPA 2018 and so ensure the security, integrity and quality of the data as if it was held solely by the Company.
Because we may hold sensitive data due to the nature of our business, all staff are responsible for ensuring that:
Any personal data which they hold is kept secure
Personal data is not disclosed
All employees within the scope of this policy are required to adhere to its terms and conditions.
Hague Dental Supplies Board of Directors is responsible for communicating this Policy to Managers. Individual Managers are responsible for ensuring that this Policy is applied within their own area. Any queries on the application or interpretation of this Policy must be discussed with a nominated Director prior to any action being taken.
Hague Dental Supplies Board of Directors has the responsibility for ensuring the maintenance, regular review and updating of this policy. Revisions, amendments, or alternations to the policy can only be implemented following consideration and approval by the nominated Director.
This Policy will be reviewed periodically to ensure it reflects current legislative requirements and best practice. Any changes will be brought to the attention of all employees.