Data Protection Responsibilities

1. Personal Data Handling

  • Personal data must not be disclosed to unauthorized third parties.
  • Personal data must be retained according to Glow Telecom's data retention schedule.
  • Queries regarding data protection should be directed to the Managing Director.
  • Data protection breaches must be reported to and dealt with by the Managing Director.
  • In cases of uncertainty regarding data protection, advice must be sought from the Managing Director.

2. Third-Party Data Processors

  • When external companies process personal data for Glow Telecom, Glow Telecom retains responsibility for its security.
  • Data processors must provide guarantees about their security measures.
  • A written contract must detail the personal data being processed and the purpose of processing.

3. Contractors, Consultants, and Short-Term Staff

  • Personal data must be returned or securely destroyed upon the completion of work.
  • Glow Telecom is responsible for the data use by contractors/consultants.
  • Managers must ensure personal data is processed securely and confidentially.
  • Personal data should not be stored or processed outside the UK without written consent.
  • Only essential personal data should be accessible to contractors and consultants for their work.

4. Data Subject Access Requests

  • Data subjects have the right to receive copies of their personal data held by Glow Telecom.
  • Individuals are entitled to information regarding the processing of their personal data, including:
    • Categories of personal data being processed
    • Recipients/categories of recipients
    • Retention periods
    • Information about their rights
    • Right to complain to the ICO
    • Relevant safeguards for data outside the EEA
    • Source of the personal data
  • Disclosure of personal data must not occur without proper authorization.
  • Requests for access to personal data should not result in alterations or destruction of that data.

5. Reporting Personal Data Breaches

  • Personal data breaches must be reported to the Information Commissioner's Office (ICO) if there is a risk to data subjects.
  • High-risk breaches require notification to data subjects unless security measures mitigate the risk.
  • Public communication may be required in such cases to inform data subjects.

Security Measures and Compliance

Security Principles

  • Personal data must be processed securely through appropriate technical and organizational measures.
  • Risk analysis and organizational policies should guide security measures and decision-making.
  • Regular reviews of information security policies and practices are necessary for continued compliance.
  • All actions must ensure the confidentiality, integrity, and availability of personal data.

Implementation Checklist

  • Policies on personal data retention and justification for the duration must be in place.
  • An examination of data processing risks informs the required security level.
  • Basic technical controls should comply with established frameworks (e.g., Cyber Essentials).
  • Regular testing and reviews of security measures must be conducted to highlight areas for improvement.
  • Backup processes should be established to restore access to personal data when needed.