Data Protection Policy
About this policy
During the course of our activities we, Snowmedia Consulting Limited, process personal data (which may be held on paper, electronically, or otherwise) about our staff, clients and contacts, and we recognise the need to treat it in an appropriate and lawful manner, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The purpose of this policy is to make you aware of how we handle your personal data.
This policy does not form part of any employee’s contract of employment and we may amend it at any time. We are the “controller” of the personal data we hold about you for the purposes of applicable data protection law.
Data protection principles
We comply with the principles set out in the UK GDPR, which require that personal data is:
- Processed lawfully, fairly and in a transparent manner.
- Collected for specified, explicit and legitimate purposes and not processed in a way incompatible with those purposes.
- Adequate, relevant and limited to what is necessary (data minimisation).
- Accurate and, where necessary, kept up to date.
- Kept in a form that permits identification for no longer than is necessary (storage limitation).
- Processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (integrity and confidentiality).
We are also responsible for, and must be able to demonstrate compliance with, these principles (accountability).
“Personal data” means any information relating to an identified or identifiable living person. It may include contact details, other personal information, photographs, and expressions of opinion about you. “Processing” means doing anything with the data, such as collecting, storing, accessing, disclosing, destroying or using it in any way.
Lawful basis for processing
We will only process your personal data where we have a lawful basis to do so. Depending on the circumstances, this will be one or more of the following:
- Where you have given consent;
- Where processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract;
- Where processing is necessary to comply with a legal obligation;
- Where processing is necessary to protect someone’s vital interests;
- Where processing is necessary for our legitimate interests (or those of a third party), except where overridden by your interests or fundamental rights.
Special category and criminal offence data
Some personal data is more sensitive and is given extra protection under the UK GDPR, for example data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, or data concerning sex life or sexual orientation. We will only process this “special category data”, or data relating to criminal convictions and offences, where an additional condition applies, usually your explicit consent, or where it is necessary for carrying out our obligations in the field of employment law, as permitted by the Data Protection Act 2018.
How we use your personal data
We process data about staff for legal, personnel, administrative and management purposes and to enable us to meet our legal obligations as an employer, for example to pay you, to monitor your performance, and to confer benefits in connection with your employment. We may process special category data relating to staff where appropriate, including:
- information about an employee’s physical or mental health in order to monitor sick leave and take decisions as to fitness for work;
- an employee’s racial or ethnic origin, or religious or similar information, in order to monitor compliance with equal opportunities legislation;
- where necessary to comply with legal requirements and obligations to third parties.
Data minimisation and accuracy
We will only collect and process personal data to the extent that it is necessary for the specific purposes notified to you. We will keep the personal data we hold accurate and up to date, and data that is inaccurate or out of date will be corrected or erased. Please notify us if your personal details change or if you become aware of any inaccuracies in the data we hold about you.
Data retention
We will not keep your personal data for longer than is necessary for the purpose for which it was collected. When personal data is no longer required, it will be securely destroyed or erased from our systems in line with our retention schedule.
Your rights
Under the UK GDPR you have the following rights in relation to your personal data:
- The right to be informed about how your data is used;
- The right of access to the personal data we hold about you;
- The right to rectification of inaccurate or incomplete data;
- The right to erasure (the “right to be forgotten”) in certain circumstances;
- The right to restrict processing in certain circumstances;
- The right to data portability;
- The right to object to processing, including for direct marketing;
- Rights in relation to automated decision-making and profiling.
How to make a request
If you wish to exercise any of your rights, including to know what personal data we hold about you, please make the request in writing to our data protection contact, Anthony Snow, at Snowmedia Consulting Limited. There is normally no charge for making a request, and we will respond within one month. This period may be extended by up to two further months where a request is complex or where several requests have been made; if so, we will let you know and explain why.
Data security
We take appropriate technical and organisational measures against unlawful or unauthorised processing of personal data, and against accidental loss of, or damage to, personal data. We have procedures and technologies in place to maintain the security of all personal data from the point of collection to the point of destruction, and we will only transfer personal data to a third party where they agree to comply with those procedures and policies, or put adequate measures in place themselves. Maintaining data security means safeguarding the confidentiality, integrity and availability of the personal data.
Sharing with third parties
We will not disclose your personal data to a third party without your consent unless we are satisfied that they are legally entitled to the data or that disclosure is otherwise lawful. Where we do share personal data with a processor acting on our behalf, we will put an appropriate written contract in place and ensure they provide sufficient guarantees regarding the security and confidentiality of the data.
International transfers
If we transfer your personal data to a country outside the UK, we will ensure that it is protected to a standard equivalent to that required under UK data protection law, for example, by transferring only to countries that benefit from a UK “adequacy” decision, or by putting in place appropriate safeguards such as standard contractual clauses.
Data breaches
We have procedures in place to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to affected individuals, we will also inform them directly.
Complaints
If you consider that this policy has not been followed, or that your personal data has not been handled correctly, please raise the matter with your line manager or our data protection contact. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk. Any breach of this policy will be taken seriously and may result in disciplinary action.
Snowmedia