Data Protection Responsibilities
1. Personal Data Handling
- Personal data must not be disclosed to unauthorized third parties.
- Personal data must be retained according to Glow Telecom's data retention schedule.
- Queries regarding data protection should be directed to the Managing Director.
- Data protection breaches must be reported to and dealt with by the Managing Director.
- In cases of uncertainty regarding data protection, advice must be sought from the Managing Director.
2. Third-Party Data Processors
- When external companies process personal data for Glow Telecom, Glow Telecom retains responsibility for its security.
- Data processors must provide guarantees about their security measures.
- A written contract must detail the personal data being processed and the purpose of processing.
3. Contractors, Consultants, and Short-Term Staff
- Personal data must be returned or securely destroyed upon the completion of work.
- Glow Telecom is responsible for the data use by contractors/consultants.
- Managers must ensure personal data is processed securely and confidentially.
- Personal data should not be stored or processed outside the UK without written consent.
- Only essential personal data should be accessible to contractors and consultants for their work.
4. Data Subject Access Requests
- Data subjects have the right to receive copies of their personal data held by Glow Telecom.
- Individuals are entitled to information regarding the processing of their personal data, including:
- Categories of personal data being processed
- Recipients/categories of recipients
- Retention periods
- Information about their rights
- Right to complain to the ICO
- Relevant safeguards for data outside the EEA
- Source of the personal data
- Disclosure of personal data must not occur without proper authorization.
- Requests for access to personal data should not result in alterations or destruction of that data.
5. Reporting Personal Data Breaches
- Personal data breaches must be reported to the Information Commissioner's Office (ICO) if there is a risk to data subjects.
- High-risk breaches require notification to data subjects unless security measures mitigate the risk.
- Public communication may be required in such cases to inform data subjects.
Security Measures and Compliance
Security Principles
- Personal data must be processed securely through appropriate technical and organizational measures.
- Risk analysis and organizational policies should guide security measures and decision-making.
- Regular reviews of information security policies and practices are necessary for continued compliance.
- All actions must ensure the confidentiality, integrity, and availability of personal data.
Implementation Checklist
- Policies on personal data retention and justification for the duration must be in place.
- An examination of data processing risks informs the required security level.
- Basic technical controls should comply with established frameworks (e.g., Cyber Essentials).
- Regular testing and reviews of security measures must be conducted to highlight areas for improvement.
- Backup processes should be established to restore access to personal data when needed.