## Data Protection Responsibilities

### 1. Personal Data Handling  
- Personal data must not be disclosed to unauthorized third parties.  
- Personal data must be retained according to Glow Telecom's data retention schedule.  
- Queries regarding data protection should be directed to the Managing Director.  
- Data protection breaches must be reported to and dealt with by the Managing Director.  
- In cases of uncertainty regarding data protection, advice must be sought from the Managing Director.

### 2. Third-Party Data Processors  
- When external companies process personal data for Glow Telecom, Glow Telecom retains responsibility for its security.  
- Data processors must provide guarantees about their security measures.  
- A written contract must detail the personal data being processed and the purpose of processing.

### 3. Contractors, Consultants, and Short-Term Staff  
- Personal data must be returned or securely destroyed upon the completion of work.  
- Glow Telecom is responsible for the data use by contractors/consultants.  
- Managers must ensure personal data is processed securely and confidentially.  
- Personal data should not be stored or processed outside the UK without written consent.  
- Only essential personal data should be accessible to contractors and consultants for their work.

### 4. Data Subject Access Requests  
- Data subjects have the right to receive copies of their personal data held by Glow Telecom.  
- Individuals are entitled to information regarding the processing of their personal data, including:  
  - Categories of personal data being processed  
  - Recipients/categories of recipients  
  - Retention periods  
  - Information about their rights  
  - Right to complain to the ICO  
  - Relevant safeguards for data outside the EEA  
  - Source of the personal data  
- Disclosure of personal data must not occur without proper authorization.  
- Requests for access to personal data should not result in alterations or destruction of that data.

### 5. Reporting Personal Data Breaches  
- Personal data breaches must be reported to the Information Commissioner's Office (ICO) if there is a risk to data subjects.  
- High-risk breaches require notification to data subjects unless security measures mitigate the risk.  
- Public communication may be required in such cases to inform data subjects.

## Security Measures and Compliance

### Security Principles  
- Personal data must be processed securely through appropriate technical and organizational measures.  
- Risk analysis and organizational policies should guide security measures and decision-making.  
- Regular reviews of information security policies and practices are necessary for continued compliance.  
- All actions must ensure the confidentiality, integrity, and availability of personal data.

### Implementation Checklist  
- Policies on personal data retention and justification for the duration must be in place.  
- An examination of data processing risks informs the required security level.  
- Basic technical controls should comply with established frameworks (e.g., Cyber Essentials).  
- Regular testing and reviews of security measures must be conducted to highlight areas for improvement.  
- Backup processes should be established to restore access to personal data when needed.
