Designamite collects data about you and your customers for various purposes. Outlined below are the measures that we take to ensure that personal data is protected. We expect that the same principles are followed when it comes to processing the personal data of Designamite staff members.
Consent
Personal data is collected over the phone and using other methods such as e-mail. Written consent is not requested as it is assumed that the consent has been granted when an individual freely gives their own details. Designamite will only use the data collected for the reason collected and no other purpose.
Personal data will not be passed on to anyone outside the organisation without explicit consent from the data owner unless there is a legal duty of disclosure under other legislation, in which case the management will discuss and agree disclosure with relevant staff members. Contact details held on the organisation’s database may be made available to groups/ individuals outside of the organisation. Individuals are made aware of when their details are being collected for the database and their verbal or written consent is requested.
Access
Only the organisation’s staff will normally have access to personal data. All staff, are made aware of the General Data Protection Regulation (GDPR) and their obligation not to disclose personal data to anyone who is not supposed to have it.
Information supplied is kept in a secure filing, paper and electronic system and is only accessed by those individuals involved in the delivery of the service.
Information will not be passed on to anyone outside the organisation without their explicit consent, excluding statutory bodies e.g. the Inland Revenue.
Individuals will be supplied with a copy of any of their personal data held by the organisation if a request is made via a subject access request.
All confidential post must be opened by the addressee only.
Accuracy
Designamite will take reasonable steps to keep personal data up to date and accurate. Personal data will be stored for as long as the data owner uses our services and normally longer. Where an individual ceases to use our services and it is not deemed appropriate to keep their records, their records will be destroyed. However, unless we are specifically asked by an individual to destroy their details, we will normally keep them on file for future reference. After 3 years, this data should be deleted.
If a request is received from an organisation/ individual to destroy their records, we will remove their details from the database and request that all staff holding paper or electronic details for the organisation destroy them. This work will be carried out by Management.
This procedure applies if Designamite is informed that an organisation ceases to exist.
Storage
Personal data may be kept in paper-based systems and on a password-protected computer system. Paper-based data are stored in organised and secure systems. Designamite operates a clear desk policy at all times. The clear desk policy dictates the following:
- Personal data should not be written unless essential, and should be shredded after use
- Staff computers have password-protected screensavers enabled after 2 mins or less
- Post should be filed or shredded as soon as possible
- Any paper-based personal data should be left face down on the desk
- Printing of documents (including emails) should be kept to a minimum
- Calendar items containing personal data should be deleted after the event has passed
Use of Photographs
Designamite will seek consent of individuals before displaying photographs in which they appear. If this is not possible (for example, a large group photo), the organisation will remove any photograph if a complaint is received. This policy also applies to photographs published on the organisation’s website or in the Newsletter.
Criminal Records Bureau
Designamite will act in accordance with the CRB’s code of practice. Copies of disclosures are kept for no longer than is required. In most cases this is no longer than 6 months in accordance with the CRB Code of Practice. There may be circumstance where it is deemed appropriate to exceed this limit e.g. in the case of disputes.
Responsibilities of staff
During the course of their duties with Designamite, staff will be dealing with information such as names/addresses/phone numbers/e-mail addresses of clients/suppliers/contacts. They may be told or overhear sensitive information while working for Designamite. The General Data Protection Regulation (GDPR) gives specific guidance on how this information should be dealt with. In short to comply with the law, personal information must be collected and used fairly, stored safely and not disclosed to any other person unlawfully. Staff, paid or unpaid must abide by this policy.
To help staff meet the terms of the General Data Protection Regulation (GDPR), staff are asked to read and sign a statement to say that they have understood their responsibilities.
Compliance
Compliance with the General Data Protection Regulation (GDPR) is the responsibility of all staff, paid or unpaid. Designamite will regard any unlawful breach of any provision of the Regulation by any staff, paid or unpaid, as a serious matter which will result in disciplinary action. Any employee who breaches this policy statement will be dealt with under the disciplinary procedure which may result in dismissal for gross misconduct. Any such breach could also lead to criminal prosecution.
Any questions or concerns about the interpretation or operation of this policy statement should in the first instance be referred to the line manager.
Retention of Data
No documents will be stored for longer than is necessary. All documents containing personal data will be disposed of securely in accordance with the Data Protection principles. Designamite have a retention policy and schedule.