For the purposes of General Data Protection Regulation – UK GDPR and the Data Protection Act 1988 the Data controller in relation to the information you supply is Foilco Ltd.
The registered office is
Foilco Ltd Enterprise Way, Lowton St Mary’s, Warrington, Cheshire, WA3 2BP
1. INTRODUCTION
a. This Policy sets out how Foilco Limited (“we”, “our”, “us”, “Foilco”) handle the personal data of all individuals we come into contact with in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This includes customers, suppliers, stakeholders, employees, workers, consultants, job candidates and any other individuals we come into contact with.
b. This Policy applies to all our workforce (“you”, “your”). You must read, understand and comply with this Policy when processing personal data on our behalf and attend training on its requirements. This Policy sets out what we expect from you for Foilco to comply with applicable law. Your compliance with this Policy is mandatory. Any breach of this Policy may result in disciplinary action.
c. This Policy is non-contractual and may be changed from time to time.
2. SCOPE
a. All employees are responsible for complying with this Policy. All individual business areas are responsible for ensuring that the workforce complies with this Policy and need to implement appropriate practices, processes, controls and training to ensure that compliance.
b. The Data Protection Officer (DPO) is responsible for overseeing this Policy and, as applicable, developing any related policies and procedures. The DPO can be contacted by emailing Angela Cox at DPO@Foilco.com.
c. Please contact the DPO with any questions about the operation of this Policy or the UK GDPR or if you have any concerns that this Policy is not being or has not been followed.
3. INTERPRETATION
a. For the purpose of this Policy, personal data refers to information that relates to an identifiable, living individual, including information such as an online identifier, such as an IP address. The UK GDPR applies to both automated personal data and to manual filing systems, where personal data is accessible according to specific criteria, as well as to chronologically ordered data and pseudonymised data, e.g. key-coded.
b. Sensitive personal data is referred to in the UK GDPR as ‘special categories of personal data’, which are information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data, and personal data relating to criminal offences and convictions.
c. For the purposes of this Policy, processing refers to any operation performed on personal data such as collecting, recording, organising, structuring, storing, altering, retrieving, using, disseminating, erasing or destroying personal data.
d. Examples of personal data and special category data include:
|
|
|
|
|
Health or disability information
|
|
|
|
|
|
|
|
|
|
|
|
Details of criminal offences
|
|
|
Details of sex life or sexual orientation
|
|
|
|
|
|
|
4. DATA PROTECTION PRINCIPLES
a. In accordance with the requirements outlined in the UK GDPR, personal data will be:
i. processed lawfully, fairly and in a transparent manner (Lawfulness, Fairness and Transparency);
ii. collected only for specified, explicit and legitimate purposes (Purpose Limitation);
iii. adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (Data Minimisation);
iv. accurate and where necessary kept up to date (Accuracy);
v. not kept in a form which permits identification of individuals for longer than is necessary for the purposes for which the data is processed (Storage Limitation); and
vi. processed in a manner that ensures its security using appropriate technical and organisational measures to protect against unauthorised or unlawful processing and against accidental loss, destruction or damage (Security, Integrity and Confidentiality).
b. We are responsible for and must be able to demonstrate compliance with the data protection principles listed above (Accountability).
5. DATA PROTECTION OFFICER
a. Foilco will appoint a DPO in order to:
i. Inform and advise Foilco and its workforce about their obligations to comply with the UK GDPR and other data protection laws;
ii. Monitor Foilco’s compliance with the UK GDPR and other laws, including managing internal data protection activities, advising on data protection impact assessments, conducting internal audits, and providing the required training to staff members.
b. The DPO will report to the highest level of management at Foilco.
c. The DPO will operate independently and will not be penalised for performing their task.
d. Sufficient resources will be provided to the DPO to enable them to meet their UK GDPR obligations.
6. LAWFULNESS, FAIRNESS, TRANSPARENCY
6.1 LAWFULNESS AND FAIRNESS
a. Personal data must be processed lawfully, fairly and in a transparent manner in relation to individuals.
b. We may only collect, process and share personal data fairly and lawfully and for specified purposes. The UK GDPR restricts our actions regarding personal data to specified lawful purposes. These restrictions are not intended to prevent processing but ensure that we process personal data fairly and without adversely affecting the individual.
c. The UK GDPR allows processing for specific purposes which are set out below:
i. the individual has given their consent;
ii. it is necessary for the performance of a contract with the individual;
iii. to meet our legal compliance obligations;
iv. to protect the data subject’s vital interests;
v. to carry out a task in the public interest; or
vi. to pursue our legitimate interests (or those of a third party) for purposes where they are not overridden because the processing prejudices the interests or fundamental rights and freedoms of data subjects. The purposes for which we process personal data for legitimate interests need to be set out in applicable privacy notices.
6.2 SPECIAL CATEGORIES OF PERSONAL DATA
a. We may only collect, process and share special category data fairly and lawfully and for specified purposes. The UK GDPR allows the processing of special category data for the following specific purposes:
i. The individual has given their explicit consent;
ii. The processing relates to personal data manifestly made public by the individual;
iii. The processing is necessary for carrying out obligations under employment, social security or social protection law, or a collective agreement;
iv. The processing is necessary for protecting the vital interests of a data subject or another individual where the data subject is physically or legally incapable of giving consent;
v. The processing is necessary for the establishment, exercise or defence of legal claims or where courts are acting in their judicial capacity;
vi. The processing is necessary for reasons of substantial public interest on the basis of UK law which is proportionate to the aim pursued and which contains appropriate safeguards;
vii. The processing is necessary for the purposes of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of UK law or a contract with a health professional;
viii. The processing is reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of healthcare and of medicinal products or medical devices; or
ix. The processing is necessary for archiving purposes in the public interest, or scientific and historical research purposes or statistical purposes in accordance with Article 89(1) UK GDPR.
7. CONSENT
a. We must only process personal data on the basis of one or more of the lawful bases set out in the UK GDPR, which include consent.
b. Consent must be a positive indication. It cannot be inferred from silence, inactivity or pre-ticked boxes.
c. Consent will only be accepted where it is freely given, specific, informed and an unambiguous indication of the individual’s wishes.
d. Where consent is given, a record will be kept documenting how and when consent was given so that Foilco can demonstrate compliance with consent requirements.
e. Foilco ensures that consent mechanisms meet the standards of the UK GDPR. Where the standard of consent cannot be met, an alternative legal basis for processing the data must be found, or the processing must cease.
f. Consent can be withdrawn by the individual at any time.
8. TRANSPARENCY
a. The UK GDPR requires organisations to provide detailed, specific information to individuals about the processing of their personal data. The information must be provided through appropriate privacy notices which must be concise, transparent, intelligible, easily accessible, and in clear and plain language so that an individual can easily understand them.
b. Whenever we collect personal data directly from individuals, we must provide them with all the information required by the UK GDPR including the identity of Foilco, how and why we will use, process, disclose, protect and retain that personal data through a privacy notice which must be presented when the individual first provides the personal data.
c. When personal data is collected indirectly (for example, from a third party or publicly available source), we must provide the individual with all the information required by the UK GDPR as soon as possible after collecting or receiving the data.
d. A copy of our Privacy Policy for Customers and Website Users is available to view on our website.www.foilco.com
9. PURPOSE LIMITATION
a. Personal data must be collected only for specified, explicit and legitimate purposes. It must not be further processed in any manner incompatible with those purposes.
b. You cannot use personal data for new, different or incompatible purposes from that disclosed when it was first obtained unless you have informed the individual of the new purposes and they have consented where necessary.
10. DATA MINIMISATION
a. Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
b. You may only process personal data when performing your role requires it. You cannot process personal data for any reason unrelated to your role.
c. You may only collect personal data that you require for your role: do not collect excessive data. Ensure any personal data collected is adequate and relevant for the intended purposes.
d. You must ensure that when personal data is no longer needed for specified purposes, it is deleted or anonymised in accordance with our data retention policy.
11. ACCURACY
a. Personal data must be accurate and, where necessary, kept up to date. It must be corrected or deleted without delay when inaccurate.
b. You will ensure that the personal data we use and hold is accurate, complete, kept up to date and relevant to the purpose for which we collected it. You must check the accuracy of any personal data at the point of collection and at regular intervals afterwards. You must take all reasonable steps to destroy or amend inaccurate or out-of-date personal data.
12. STORAGE LIMITATION
a. Personal data must not be kept in an identifiable form for longer than is necessary for the purposes for which the data is processed.
b. Foilco will maintain retention schedules to ensure personal data is deleted after a reasonable time for the purposes for which it was being held, unless a law requires that data to be kept for a minimum time.
c. You must not keep personal data in a form which permits the identification of the data subject for longer than needed for the legitimate purposes for which we originally collected it including for the purpose of satisfying any legal, accounting or reporting requirements.
d. You will take all reasonable steps to destroy or erase from our systems all personal data that we no longer require in accordance with Foilco’s data retention requirements.
e. You will ensure individuals are informed of the period for which data is stored and how that period is determined in any applicable privacy notice.
13. SECURITY INTEGRITY AND CONFIDENTIALITY
13.1PROTECTING PERSONAL DATA
a. Personal data must be secured by appropriate technical and organisational measures against unauthorised or unlawful processing, and against accidental loss, destruction or damage.
b. We will develop, implement and maintain safeguards to protect personal data. We will regularly evaluate and test the effectiveness of those safeguards to ensure security of our processing of personal data.
c. You are responsible for protecting the personal data we hold. You must exercise particular care in protecting special categories of personal data from loss and unauthorised access, use or disclosure.
d. You must follow all procedures and technologies we put in place to maintain the security of all personal data from the point of collection to the point of destruction. You may only transfer personal data to third-party service providers who agree to comply with the required policies and procedures and who agree to put adequate measures in place, as requested.
e. You must comply with and not attempt to circumvent the administrative, physical and technical safeguards we implement and maintain in accordance with the UK GDPR to protect personal data.
13.2 DATA SECURITY
The following measures must be taken to protect personal data:
a. Confidential paper records must be kept in a locked filing cabinet, drawer or safe, with restricted access;
b. Confidential paper records must not be left unattended or in clear view anywhere with general access;
c. Digital data must be encrypted or password-protected, both on a local hard drive and on a network drive that is regularly backed up;
d. Where personal data is saved on removable storage or a portable device, the device must be kept in a locked filing cabinet, drawer or safe when not in use;
e. Memory sticks must not be used to hold personal data unless they are password-protected and fully encrypted;
f. All electronic devices must be password-protected to protect the information on the device in case of theft;
g. Emails containing special category or confidential personal data must be password-protected if there are unsecure servers between the sender and the recipient;
h. Circular emails to stakeholders or individuals must be sent blind carbon copy (bcc), so email addresses are not disclosed to other recipients;
i. When sending personal data by email staff will always check that the recipient is correct before sending;
j. When screening sharing on electronic devices, staff will always check that confidential or personal data cannot be viewed by others viewing the screen;
k. Where personal data that could be considered private or confidential is taken off the premises, either in electronic or paper format, staff will take extra care to follow the same procedures for security, e.g. keeping devices under lock and key. The person taking the information from our premises accepts full responsibility for the security of the data; and
l. Under no circumstances are visitors allowed access to confidential or personal information. Visitors to areas of our premises containing private or sensitive information must be supervised at all times.
14. REPORTING A PERSONAL DATA BREACH
a. The term ‘personal data breach’ refers to a breach of security which has led to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
b. We have put in place procedures to deal with any suspected personal data breach and will notify individuals or any applicable regulator where we are legally required to do so.
c. If you know or suspect that a personal data breach has occurred, do not attempt to investigate the matter yourself. Immediately contact the Data Protection Officer in accordance with Foilco’s Data Breach Procedure (set out at Annex One).
d. Where a breach is likely to result in a risk to the rights and freedoms of individuals, the Information Commissioner’s Office (ICO) will be informed. All notifiable breaches will be reported to the ICO within 72 hours of Foilco becoming aware of it.
e. The risk of the breach having a detrimental effect on the individual, and the need to notify the ICO, will be assessed on a case-by-case basis in accordance with our Data Breach Procedure.
f. In the event that a breach is likely to result in a high risk to the rights and freedoms of an individual, Foilco will notify those concerned directly in accordance with our Data Breach Procedure.
g. Failure to report a breach when required to do so may result in a fine, as well as a fine for the breach itself.
15. TRANSFER LIMITATION
a. The UK GDPR restricts data transfers to countries outside the UK to ensure that the level of data protection afforded to individuals by the UK GDPR is not undermined. You transfer personal data originating in one country across borders when you transmit, send, view or access that data in or to a different country.
b. You may only transfer personal data outside the UK if one of the following conditions applies:
i. the UK government has issued regulations confirming that the country to which we transfer the personal data ensures an adequate level of protection for individual’s rights and freedoms (e.g. to a country located within the European Economic Area);
ii. appropriate safeguards are in place such as standard contractual clauses approved for use in the UK or an approved code of conduct or a certification mechanism;
iii. the data subject has provided explicit consent to the proposed transfer after being informed of any potential risks; or
iv. the transfer is necessary for one of the other reasons set out in the UK GDPR including the performance of a contract between us and the data subject, reasons of public interest, to establish, exercise or defend legal claims or to protect the vital interests of the data subject and, in some limited cases, for our legitimate interest.
16. DATA SUBJECT’S RIGHTS AND REQUESTS
a. Data subjects have rights when it comes to how we handle their personal data. These include rights to:
i. withdraw consent to processing at any time;
ii. receive certain information about our processing activities;
iii. request access to their personal data that we hold;
iv. prevent our use of their personal data for direct marketing purposes;
v. ask us to erase personal data if it is no longer necessary in relation to the purposes for which it was collected or processed or to rectify inaccurate data or to complete incomplete data;
vi. restrict processing in specific circumstances;
vii. challenge processing which has been justified on the basis of our legitimate interests or in the public interest;
viii. request a copy of an agreement under which personal data is transferred outside of the UK;
ix. object to decisions based solely on automated processing, including profiling;
x. prevent processing that is likely to cause damage or distress to the individual or anyone else;
xi. be notified of a personal data breach which is likely to result in high risk to their rights and freedoms;
xii. make a complaint to the Information Commissioner’s Office; and
xiii. in limited circumstances, receive or ask for their personal data to be transferred to a third party in a structured, commonly used and machine-readable format.
b. You must immediately forward any request from individuals to exercise their data protection rights to the Data Protection Officer.
17. ACCOUNTABILITY
17.1Foilco must implement appropriate technical and organisational measures in an effective manner, to ensure compliance with data protection principles. Foilco is responsible for, and must be able to demonstrate, compliance with the data protection principles.
17.2Foilco must have adequate resources and controls in place to ensure and to document UK GDPR compliance including:
a. implementing privacy by design when processing personal data and completing data protection impact assessments (DPIAs) where processing presents a high risk to rights and freedoms of individuals;
b. integrating data protection into internal documents including this Policy, related policies and procedures or privacy notices;
c. regularly training all of our workforce on the UK GDPR, this Policy, related policies and procedures. Foilco must maintain a record of training attendance by Foilco workforce; and
d. regularly testing the privacy measures implemented and conducting periodic reviews and audits to assess compliance, including using results of testing to demonstrate compliance improvement effort.
18. RECORD KEEPING
a. The UK GDPR requires us to keep full and accurate records of all our data processing activities.
b. Foilco has created, and will maintain, a record of processing activity. This record should include the name and contact details of Foilco and the DPO, clear descriptions of the personal data types, data subject types, processing activities, processing purposes, third-party recipients of the personal data, personal data storage locations, personal data transfers, the personal data’s retention period and a description of the security measures in place.
19. TRAINING AND AUDIT
a. We are required to ensure all our workforce have undergone adequate training to enable them to comply with data protection laws. We must also regularly test our systems and processes to assess compliance.
b. You must undergo all mandatory data protection related training.
c. You must regularly review all the systems and processes under your control to ensure they comply with this Policy and check that adequate governance controls and resources are in place to ensure proper use and protection of personal data.
20. PRIVACY BY DESIGN AND DATA PROTECTION IMPACT ASSESSMENTS (DPIAs)
a. We will act in accordance with the UK GDPR by adopting a privacy by design approach and implementing technical and organisational measures which demonstrate how Foilco has considered and integrated data protection into processing activities.
b. DPIAs will be used to identify the most effective method of complying with our data protection obligations and meeting individuals’ expectations of privacy.
c. A DPIA will be used when using new technologies or when the processing is likely to result in a high risk to the rights and freedoms of individuals.
d. A DPIA should be conducted when implementing major system or business changes involving the processing of personal data including:
i. use of new technologies (programs, systems or processes), or changing technologies (programs, systems or processes);
ii. Automated processing including profiling;
iii. large-scale processing of special categories of personal data or criminal convictions data; or
iv. large-scale, systematic monitoring of a publicly accessible area.
21. AUTOMATED PROCESSING (INCLUDING PROFILING) AND AUTOMATED DECISION-MAKING
a. Generally, automated decision making is prohibited when a decision has a legal or similar significant effect on an individual unless:
i. an individual has explicitly consented;
ii. the processing is authorised by law; or
iii. the processing is necessary for the performance of or entering into a contract.
b. If certain types of special category data are being processed, then grounds (ii) or (iii) will not be allowed but the special category data can be processed where it is necessary (unless less intrusive means can be used) for substantial public interest like fraud prevention.
c. If a decision is to be based solely on automated processing (including profiling), then individuals must be informed when you first communicate with them of their right to object. This right must be explicitly brought to their attention and presented clearly and separately from other information. Further, suitable measures must be put in place to safeguard the individual’s rights and freedoms and legitimate interests.
d. We must also inform individuals of the logic involved in the decision making or profiling, the significance and envisaged consequences and give the individual the right to request human intervention, express their point of view or challenge the decision.
e. A DPIA must be carried out before any automated processing (including profiling) is undertaken.
22.DIRECT MARKETING
a. We are subject to certain rules and privacy laws when marketing to our supporters and members of the public (e.g. individuals who have subscribed to our e-newsletters and updates) and an individual’s prior consent is required for electronic direct marketing (for example, by email, text or automated calls).
b. The right to object to direct marketing must be explicitly provided to individuals in an intelligible manner so that it is clearly distinguishable from other information within a privacy notice.
c. An individual’s objection to direct marketing must be promptly honoured. If an individual opts out at any time, their details should be suppressed as soon as possible. Suppression involves retaining just enough information to ensure that marketing preferences are respected in the future.
23.SHARING PERSONAL DATA
a. Generally, we are not allowed to share personal data with third parties unless certain safeguards and contractual arrangements have been put in place.
b. You may only share personal data we hold with third parties, such as our service providers, if:
i. they have a need to know the information for the purposes of providing the contracted services;
ii. sharing the personal data complies with the privacy notice provided to the individual and, if required, the consent has been obtained;
iii. the third party has agreed to comply with the required data security standards, policies and procedures and put adequate security measures in place;
iv. the transfer complies with any applicable cross-border transfer restrictions; and
v. a fully executed written contract that contains UK GDPR-approved third party clauses has been obtained.
24.CCTV AND PHOTOGRAPHY
a. Foilco understands that recording images of identifiable individuals constitutes as processing personal data, so the use of CCTV is done in line with data protection principles.
b. Where CCTV is in operation, appropriate signage is put in place to notify individuals that CCTV is in operation.
c. All CCTV footage will be kept for a period of time for security purposes for after which it will securely deleted or overwritten.
d. If Foilco wishes to use images/video footage of individuals in a publication, such as on its website or social media, consent must be obtained from the individual prior to publication.
25.CHANGES TO THIS POLICY
We keep this Policy under regular review and will be reviewed every 2 years, unless there is a change in the law which requires this Policy to be reviewed earlier.
26.RELATED POLICIES AND PROCEDURES
a. This Policy is implemented in conjunction with the following other policies and procedure:
i. Data Breach Procedure
ii. Privacy notices
ANNEX A
DATA BREACH PROCEDURE
1. INTRODUCTION
a. This data breach procedure places obligations on Foilco Limited to take appropriate measures to report potential breaches of personal data and details the course of action to take upon discovery of breach. References in this policy to ‘we’, ‘us’ or ‘our’ means Foilco Limited. References to ‘you’ means any person subject to this procedure as identified below.
2. POLICY STATEMENT
a. Foilco Limited maintains personal and special categories of data relating to individuals, employees, stakeholders, customers, suppliers, partners, our organisation and its affairs. We have a responsibility under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA”) to protect the security of the personal data we hold.
b. We are required to put in place appropriate technical and organisational measures against the unauthorised or unlawful processing of personal data as well as protecting the data against accidental loss, destruction or damage.
c. In the event of a data breach our primary objectives are to:
i. Prevent the further spread or loss of data;
ii. Recover the data that has been lost;
iii. Identify risks arising from the breach;
iv. Notify appropriate parties of the breach;
v. Prevent future breaches.
3. SCOPE
This procedure applies to all employees, workers, consultants and contractors working on our behalf. This procedure supplements our policies relating to data protection and information security.
4. RESPONSIBILITY
a. This procedure is managed by the Data Protection Officer (DPO), who is also responsible for handling personal data breaches under the UK GDPR and ensuring all breaches are recorded and monitored to ensure the appropriate action is taken.
b. All members of staff are responsible for recognising personal data breaches and reporting any suspected data breaches to the DPO immediately by email DPO@Foilco.com.
5. DEFINITIONS
Personal Data: any information identifying an individual or information relating to an individual that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. Personal Data includes Special Categories Personal Data. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour.
Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
Processing: means any operation performed on Personal Data, such as collecting, recording, organising, structuring, storing, altering, retrieving, using, disseminating, erasing or destroying. Processing can be automated or manual.
Special Category Data: information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data, and Personal Data relating to criminal offences and convictions.
Examples of Personal Data and Special Category Data include:
|
|
|
|
|
Health or disability information
|
|
|
|
|
|
|
|
|
|
|
|
Details of criminal offences
|
|
|
Details of sex life or sexual orientation
|
|
|
|
|
|
|
6. WHAT IS A PERSONAL DATA BREACH?
a. A Personal Data Breach means any breach of the UK GDPR and/or the DPA leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. Personal Data Breaches could be caused by a number of factors including:
i. Loss or theft of data or equipment on which data is stored;
ii. Inappropriate access controls allowing unauthorised access to data;
iii. Equipment failure;
iv. Human error; or
v. Hacking.
b. Examples of common Personal Data Breaches include:
i. Sending an email to the wrong recipient
ii. Losing a USB stick which contains Personal Data
iii. Having a laptop stolen which contains Personal Data
iv. Sending a letter or email to the wrong address
v. Network, phishing, malware or other cyber security incidents.
7. ACTIONS UPON DISCOVERY OF A BREACH
a. On finding or causing a breach, or potential breach, you must report the breach to the Data Protection Officer immediately upon discovery. You must record the details of the breach on the form attached at Appendix 1 and inform the Data Protection Officer of the incident by emailing DPO@Foilco.com.
b. Upon being informed of the breach, the Data Protection Officer will carry out an assessment of the actions necessary to mitigate any harm that might result from the breach. Each breach will be assessed on an individual basis and any actions taken shall be appropriate to the particular circumstances of the incident in question.
c. In particular, the Data Protection Officer should take the following actions:
7.1PREVENT THE FURTHER SPREAD OR LOSS OF DATA
a. Identify how the Personal Data Breach occurred and immediately take steps to contain the breach and limit the spread of data. Identifying how the breach occurred will also enable us to take steps to prevent a recurrence of the breach.
7.2 ATTEMPT TO RECOVER THE DATA THAT HAS BEEN LOST
a. Identify ways to recover the data. For example, can physical copies of the data be returned, can an email be recalled or can electronic copies be permanently deleted?
7.3IDENTIFY THE RISKS ARISING FROM THE BREACH
a. Consider obtaining specialist legal advice;
b. Confirm the amount, sensitivity and type of information in question;
c. Identify what security measures were in place when the breach occurred as well as what measures have been put in place following it;
d. Confirm who has been put at risk and assess the potential harm resulting from the breach;
e. Consider the additional consequences of the breach including loss of reputation, loss of business, liability for fines or contractual breaches.
7.4NOTIFY APPROPRIATE PARTIES OF THE BREACH
a. Consider who to inform about the breach both internally and also externally. (E.g. the police, insurers, and individuals affected.)
b. Particular consideration will be given to whether there are any parties that we are legally or contractually obliged to notify (e.g. insurers, regulator).
7.5NOTIFICATION TO THE ICO
• Assess whether the breach must be reported to the Information Commissioner’s Office (“ICO”). This must be judged on a case-by-case basis. To decide, we will consider whether the breach is likely to negatively affect people’s rights and freedoms, and cause them any physical, material or non-material damage (e.g. emotional distress), including through:
• Loss of control over their data;
• Discrimination;
• Identify theft or fraud;
• Financial loss;
• Damage to reputation;
• Loss of confidentiality; or
• Any other significant economic or social disadvantage to the individual(s) concerned.
If it’s likely that there will be a risk to people’s rights and freedoms, we must notify the ICO within 72 hours of the breach occurring. External legal advice may need to be sought at this stage.
The decision of whether or not the breach should be reported must be documented, in case it is challenged at a later date by the ICO or an individual affected by the breach.
Where the ICO must be notified, we will do this via the ‘report a breach’ page of the ICO website within 72 hours. As required, we will set out a description of the nature of the Personal Data Breach including, where possible:
• The categories and approximate number of individuals concerned;
• The categories and approximate number of Personal Data records concerned;
• A description of the likely consequences of the Personal Data Breach; and
• A description of the measures that have been, or will be taken, to deal with the breach and mitigate any possible adverse effects on the individual(s) concerned.
If all the above details are not yet known, we will report as much as we can within 72 hours. The report will explain that there is a delay, the reasons why, and when we expect to have further information. We will submit the remaining information as soon as possible.
7.6NOTIFYING INDIVIDUALS CONCERENED
Consider whether notification to individuals concerned is necessary and beneficial. If a breach is likely to result in a high risk to the rights and freedoms of individuals, then we are required to notify those concerned as soon as possible.
This notification has to be in writing and will set out:
• A description of the likely consequences of the Personal Data Breach;
• A description of the measures that have been, or will be, taken to deal with the data breach and mitigate any possible adverse effects on the individual (s) concerned.
When notifying other parties we will consider what information to tell them and how to do so appropriately as to not cause undue harm.
7.7PREVENTING FURTHER BREACHES
As part of our self-report it is useful to have considered what steps we will take to prevent future breaches. Consideration should be given to the following:
• Assessing data security risks and whether technical or organisational measures could be implemented to minimise these in future;
• Training staff in data security measures; and
• Debriefing any staff involved following the investigation where relevant.
8. IMPLEMENTATION AND REVIEW
This procedure takes effect immediately upon publication and will be subject to a review 2 years after its implementation.
9. CONTACT DETAILS
The Data Protection Officer can be contacted on: +44 (0) 1942 26 26 22 or by email at: DPO@Foilco.com
APPENDIX ONE
PERSONAL DATA BREACH CHECKLIST
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Time/date of discovery of breach
|
|
Description of data involved
|
[provide as much information as possible including the amount, sensitivity and type of information]
|
|
|
[provide a detailed account of what happened]
|
|
|
|
What steps have been taken to minimise the effects of the breach?
|
[confirm any steps taken to rectify the breach]
|
Parties affected by the breach
|
[include details of those individuals affected by the breach]
|
People notified of breach
|
[confirm who is aware of the breach, and if relevant how and why they were notified. Do not notify third parties without first discussing the breach with the Data Protection Officer. Confirm whether there has been any media coverage of the breach]
|
Details of the investigation
|
[confirm the details the investigation into the breach, when is this likely to be completed and what format will it take]
|
|
|
|
|
|
|
|
|
|
|
|
|
SEC15 Issue 01 03.07.2024Page 1 of 13
This document is controlled & updated only if accessed on public folders
If hard copy is printed off it becomes uncontrolled and should be used for immediate reference only.