General Data Protection Regulation Policy Statement
Rorcon Limited (hereafter referred to as the Company), is fully committed to full compliance with the requirements of the General Data Protection Regulation as applicable from 25th May 2018. The Company will therefore follow procedures which aim to ensure that all employees, contractors, consultants, partners or other agents of the Company (collectively known as data users or processors) who have access to any personal data held by or on behalf of the company are fully aware of and abide by their duties under the General Data Protection Regulation.
The Company needs to collect and use information about people with whom it works in order to operate and carry out its functions and processes, and have a Legal Basis for doing so. The people for whom we need to have personal information on include current, past and prospective employees, and current, past or prospective clients, customers and suppliers. In addition the Company may be required to collect and use information in order to comply with the requirements of government or to gain accreditation. This personal information must be handled and dealt with properly however it is collected, recorded and used and whether it is on paper, in computer records or recorded by other means.
The Company regards the lawful and appropriate treatment of personal information as very important to its successful operations and essential to maintaining confidence between the Company, those it employs and those with whom it carries out business.
Background
The Principles of Data Protection
The Data Protection Act stipulates that anyone processing personal data must comply with 8 principles of good practice. These principles are legally enforceable.
Summarised, the principles require that personal data:
1. Shall be processed fairly and lawfully and in particular, shall not be processed unless specific conditions are met.
2. Shall be obtained only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or those purposes.
3. Shall be adequate, relevant and not excessive in relation to the purpose or purposes for which it is processed.
4. Shall be accurate and where necessary, kept up to date.
5. Shall not be kept for longer than is necessary for that purpose or those purposes.
6. Shall be processed in accordance with the rights of data subjects under the Regulation.
7. Shall be kept secure, i.e. protected by an appropriate degree of security.
8. Shall not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of data protection. The Regulation provides conditions for the processing of any personal data. It also makes a distinction between personal data and ‘sensitive’ personal data.
Personal Data is defined as any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier – personal identifiers include items such as: name, identification number, location data or online identifier. Even if the data has been pseudonymised it is still classed as Personal Data.
Sensitive personal data is defined as personal data consisting of information as to:
- Race
- Ethnic origin
- Politics
- Religion
- Trade union membership
- Genetics
- Biometrics (used for ID purposes)
- Health
- Sex life
- Sexual Orientation
How We Will Implement this Policy:
Company Roles and Internal Communication
Under the GDPR, given the nature of our business and processing, we are not required to have a formally appointed Data Protection Officer. However, we have nominated the following individual to be our lead on all data protection related matters:
Name: Lesley Grogan
We will provide a briefing on this Policy to all of our employees on initial introduction, whenever it changes, and as part of induction for all new employees. Should we need to pass relevant data to, or receive it from, a Sub-contractor.
Handling personal/sensitive data
The Company will, through management and use of appropriate controls, monitoring and review:
- Document the data types we hold, where we get it from, the retention period for any files or documents containing the data, and anywhere we pass the data to.
- Produce and keep up to date our Privacy Notice to tell people about the data we hold and other key information required under the GDPR.
- Ensure we only gather and retain information we have a Legal Basis for to deliver our Business processes.
- Use personal data in the most efficient and effective way to deliver bette services.
- Strive to collect and process only the data or information which is needed.
- Use personal data for such purposes as are described at the point of collection, or for purposes which are legally permitted.
- Strive to ensure information is accurate.
- Operate a clear desk policy.
- Not keep information for longer than is necessary.
- Securely destroy data which is no longer needed, including shredding of hard copies.
- Take appropriate technical and organisational security measures to safeguard information (including unauthorised or unlawful processing and accidentalloss or damage of data).
- Ensure that information is not transferred abroad without suitable safeguards.
- Investigate and report (where appropriate) any suspected or actual breaches immediately and take actions to address the breach.
- Ensure that the rights of people about whom information is held can be fully exercised under the General Data Protection Regulations.
These rights include:
- the right to be informed;
- the right of access (within 1 month);
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability; and
- the right to object.
This Policy has been adopted & issued to all relevant parties who have a stakeholder interest in our organisation via instruction, receipt of hard copy, e-mail or our website.
Scheduled date of next review of this Policy: by the end of March 2026 unless required earlier.