Electronic Communications with Citizens Guidance (Updated 5 January 2015)

Size: px
Start display at page:

Download "Electronic Communications with Citizens Guidance (Updated 5 January 2015)"

Transcription

1 Electronic Communications with Citizens Guidance (Updated 5 January 2015) Overview - Activities Outside Of The Scope Of The Policy And This Guidance Requests To Use /SMS Outside The Scope Of The Guidance - The Risks And Appropriate Use Reasonable Adjustments Overview SMS/Texting When And How To Use SMS Retention Of SMS Information Overview - This guidance supports the DWP Policy on use of and SMS with citizens and defines the circumstances and controls which are necessary when using and SMS for these purposes. Staff must continue to follow existing DWP Security Guidance on the Security Portal, the Electronic Media Policy and the Standards of Behaviour Policy. Staff are reminded that potential breaches or inappropriate use will be investigated and could result in disciplinary action. Following this guidance will manage some of the risks associated with and SMS texting, for citizens, staff, and the Department. This guidance: helps staff to understand the risks so that they can explain them to citizens, helps staff to make best use of the communication tools they have available to them (such as Microsoft Outlook),

2 describes best practice and gives examples of the types of messages staff can use as part of initial and ongoing conversations with citizens, particularly but not only in relation to work search activity, creates a firm, clear, consistent message to citizens that DWP will never ask them to send passwords/pins, or personal, medical or financial information by , Suggests how businesses should use one-way and two-way address boxes to better manage these communications. Where possible use shared mailboxes when contacting citizens, as amongst other things, this approach helps to protect staff identities. Activities Outside Of The Scope Of The Policy And This Guidance Where /sms activity is already part of business processes and does not comply with this guidance, these activities should be reviewed. A compliant process should be introduced or permission to continue sought via an exception request whilst the business moves, over time, to a more secure solution. Requests To Use /SMS Outside The Scope Of The Guidance An Exceptions Board will consider requests from within the Department to use /sms in ways other than those set out in the policy and this guidance. However, it will not permit any new activity which encourages citizens to send personal information to the DWP via these means, pending the introduction of a secure communications solution, or set aside any binding legal agreements. Requests should be made either by or on behalf of the Business Process Owner, and on a template provided for that purpose. - The Risks And Appropriate Use s are targeted by criminals and foreign intelligence agencies, and the threats and risks are real. communication over the internet is inherently insecure - messages can be captured and data stolen or amended without the knowledge of the sender or recipient, and an can be used to carry threats such as malware and viruses. There are also risks that s can be inadvertently sent to one or many incorrect recipient(s). Once SEND is pressed the information is no longer in a secure environment, and cannot easily be recalled or recovered. GOV. UK provides advice from DWP to citizens on protecting their data, you can read this by clicking the link at the end of this guidance. Where members of the

3 public requires general advice or wishes to report phishing please make them aware of the document. In addition DWP must operate within the legislative framework and follow our business processes including records management. Our legacy systems were not created with electronic communications in mind. Electronic communications in relation to claims must be lawful. correspondence must be carefully managed, and follow this guidance. can be used to communicate routine business information. For other authorised exchanges see the list of circumstances which have been approved. must not be used for the inward or outward exchange of personal information with citizens. Never Date of birth, bank account details, information on family members, pension and health/medical details. Checklists have been provided to help. Only include the minimum amount of contact information without which such communication would not be possible (for example claimant s name, National Insurance number - where a reply is required - and address). Information supporting work search activity (such as C.Vs) is an approved exception. If an is received with a NINO in the subject line, or body of the message, it is acceptable to a reply to the sender, including those details. Phishing and malware attacks often rely on recipients clicking on s containing live web links and attachments and entering personal information. For example, MoJ, DVLA and HMRC have all had their identities spoofed (copied by criminals) who have then sent citizens s asking them to click links, and divulge passwords or other sensitive information. Adding attachments and links provide or direct people to specific information, much of our activity supporting people into work relies on the fast and direct electronic transfer of information. As a result the Department allows the use of attachments and links provided: Attachments to s to citizens should only be included where the citizen has requested the information or has been informed in advance to expect it (for example in the case of a CV exchange or request for a blank form), Staff using links or attachments in should consider whether these are really necessary to deliver the business requirement,

4 Wherever possible avoid sending concealed, clickable links, because these can sometimes take the recipient to inappropriate websites. Wherever possible, business areas should work to propose blank forms and templates to be placed on the gov.uk website, direct citizens, there rather than using to send individual copies to them. All s must have appropriate disclaimers which make clear that DWP will never ask citizens for usernames, passwords, personal, health/medical or bank account information via . Where is to be used to communicate with a claimant, the Department s limitations on its use should be discussed at an early stage of the customer journey so as to manage and create the right expectations and raise awareness of the risks of using . Citizens must be informed DWP will never ask you to send usernames or passwords, or personal, medical or financial information by . This is because unencrypted is the equivalent of putting the information on a postcard in a public place. If you this type of information we will not take any action until we have contacted you to confirm the message and that you sent it. This may delay our ability to deal with your . Only routine information can be sent using an insecure channel. Reasonable Adjustments Two way can be used as a Reasonable Adjustment where it is necessary for an individual disabled citizen. Requesting communications via must be for a valid reason which relates to the individual s disability, for example they find it more difficult or are unable to communicate and use our services through usual communication and contact routes, for example, written letters because they are blind or partially sighted. The customer must be advised of the risk of their data travelling over the unsecure network and being seen by third parties, and provide confirmation that they accept this risk. The Use of as a reasonable adjustment guide details how to agree and arrange the request. Check with the Equality team if you have any doubt on the course of action to take to agree the use as a way of communicating with a disabled claimant. Staff of the independent case examiner will continue to follow previously agreed business guidance when dealing with complaints from customers.

5 Citizen Awareness Provided on Gov.UK Any security queries should be discussed with your local Security Business Partner (SBP) or the Security Advice Centre. Overview SMS/Texting This guidance provides more detail as to under what circumstances and with what controls they can use SMS texts to communicate with citizens. HTK remains the Department s safest and mandated method of SMS communication. Business mobile phones may be used for texting in limited circumstances, subject to sign off by the Exceptions Board sign off will not be given where it is possible to use HTK., Staff must continue to follow existing DWP Security Guidance on the Security Portal and the Standards of Behaviour policy. Staff are reminded that potential breaches or inappropriate use will be investigated and could result in disciplinary action. For your protection and for legal reasons, personal mobiles must never be used for texting citizens or their representatives. When And How To Use SMS SMS messaging can be a useful way of sending short reminders or updates to citizens. The use of SMS is appropriate when it is being used to give citizens routine non-personal business information and reminders. SMS/texting must not be used for the inward or outward exchange of personal information with citizens. This includes date of birth, bank account details, pension, information on family members and health/medical information. This excludes the minimum amount of contact information without which such communication would not be possible (for example name, telephone number), or to confirm receipt of sensitive information, such as a Fit for Work note. Business areas wishing to make use of routine notification SMS communications with citizens must use template responses which have been agreed by the OED External Communications team. When sending text messages via HTK the SMS protocols must be followed.

6 There may be some circumstances where it would be useful to send text messages but the HTK system is not available/appropriate. This may be possible with the relevant Exceptions board approval in limited circumstances, for example: 1. An outreach setting (where HTK is not available) - Previous experience has shown that customers regularly respond to and send text messages to their outreach adviser as a preferred form of communication, 2. An area of the Department where HTK is not (yet) available, 3. A requirement for two way communication (not possible through HTK). Where a business need for use of DWP mobile phones for SMS is identified, an exceptions request must be prepared by the business area for decision by the Exceptions board working with the OED External Communications Team, who will take it through the Security Governance if necessary. SROs cannot take risk acceptance decisions on this subject. Exceptions requests for SMS/texting from DWP mobiles should generally only support one-way communication from DWP to citizens. If a business case requires two-way communication via DWP mobile phones this must not invite any personal information and the protocols for records management of such communication chains must be clearly established and followed. SMS should only be sent to mobile phone numbers and not to land lines, as land lines are more likely to be a shared resource. Any use of DWP business mobile phones must apply the following protocols in order to maintain a professional relationship and not risk compromising staff personal safety or citizen information: As the authorised holder of the DWP mobile phone it is your responsibility for how it is used and safeguarding of the equipment and when using it, you must adhere to the Electronic Media Policy, Face to face/telephone conversations or written correspondence must always be used for anything that goes beyond a basic keep in touch, or reminder basis, Under no circumstances should messages include inappropriate material; jokes of any kind or text speak such as LOL,

7 If a citizen replies to an SMS message providing or requesting personal information the standard response should be - Sorry I am unable to answer your text for security reasons, please ring XXXX / I will call you on (date and time) or we can discuss at your appointment on XXX, You should not strike up conversations through texts with citizens. Your relationship with the citizen is one of a professional nature, and extending the boundaries could compromise your position, All data on a DWP mobile phone is held on the device in an unencrypted form so you should ensure messages contain minimal information and never capture full contact details in the address book. Retention Of SMS Information Use of SMS must comply with the Records Management Policy on supporting and ephemeral data. Contact details must be deleted immediately once you no longer have a business reason to retain them. All SMS communication and records management processes must take into account any requirements for mandated recording for information that has sanctionable consequences. Any security queries should be discussed with your local Security Business Partner (SBP) or the Security Advice Centre.

The New Government Security Classification System -

The New Government Security Classification System - The New Government Security Classification System -? Industry The guidance in this booklet is being developed for use from April 2014. It is but is being shared with industry in order to raise awareness

More information

Transport Exchange Group Ltd Complaints procedure 2018

Transport Exchange Group Ltd Complaints procedure 2018 Transport Exchange Group Ltd Complaints procedure 2018 We take complaints about our work, staff and levels of service very seriously. If you are not satisfied, please follow our process for raising a formal

More information

Access to personal accounts and lawful business monitoring

Access to personal  accounts and lawful business monitoring Access to personal email accounts and lawful business monitoring Contents Policy statement... 2 Access to personal emails... 2 Manager suspects misuse... 3 Lawful business monitoring... 4 Additional information...

More information

UCL Policy on Electronic Mail ( )

UCL Policy on Electronic Mail ( ) LONDON S GLOBAL UNIVERSITY UCL Policy on Electronic Mail (EMAIL) Information Security Policy University College London Document Summary Document ID Status Information Classification Document Version TBD

More information

Acceptable Use Policy

Acceptable Use Policy IT and Operations Section 100 Policy # Organizational Functional Area: Policy For: Date Originated: Date Revised: Date Board Approved: Department/Individual Responsible for Maintaining Policy: IT and Operations

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

PRIVACY NOTICE ST BENEDICT S HOSPICE SUNDERLAND, LTD

PRIVACY NOTICE ST BENEDICT S HOSPICE SUNDERLAND, LTD PRIVACY NOTICE ST BENEDICT S HOSPICE SUNDERLAND, LTD Registered Charity No: 1019410 Company Registration No: 02803974 VAT Number: 268486844 Registered Offices: St Benedict s Hospice & Centre for Specialist

More information

Privacy Policy GENERAL

Privacy Policy GENERAL Privacy Policy GENERAL This document sets out what information Springhill Care Group Ltd collects from visitors, how it uses the information, how it protects the information and your rights. Springhill

More information

Keeping your healthcare information secure: Simple security and privacy tips

Keeping your healthcare information secure: Simple security and privacy tips Keeping your healthcare information secure: Simple security and privacy tips This guide provides awareness of privacy settings that you can use to adjust your My Health Record to suit your own requirements.

More information

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

DATA PROTECTION POLICY THE HOLST GROUP

DATA PROTECTION POLICY THE HOLST GROUP DATA PROTECTION POLICY THE HOLST GROUP INTRODUCTION The purpose of this document is to provide a concise policy regarding the data protection obligations of The Holst Group. The Holst Group is a data controller

More information

Important Information

Important Information Important Information Important Information Effective from 13 January 2018 1. Your information 1.1 Who we are We are Coutts & Co, of 440 Strand, London WC2R OQS. We are a member of The Royal Bank of Scotland

More information

It s still very important that you take some steps to help keep up security when you re online:

It s still very important that you take some steps to help keep up security when you re online: PRIVACY & SECURITY The protection and privacy of your personal information is a priority to us. Privacy & Security The protection and privacy of your personal information is a priority to us. This means

More information

Date Approved: Board of Directors on 7 July 2016

Date Approved: Board of Directors on 7 July 2016 Policy: Bring Your Own Device Person(s) responsible for updating the policy: Chief Executive Officer Date Approved: Board of Directors on 7 July 2016 Date of Review: Status: Every 3 years Non statutory

More information

Token Sale Privacy Policy

Token Sale Privacy Policy Token Sale Privacy Policy PRIVACY POLICY LAST UPDATED ON: [11 SEP 2018] A. OVERVIEW You must read the entirety of this Privacy Policy carefully before making any decision to purchase Tokens. You must also

More information

Frequently Asked Questions

Frequently Asked Questions Frequently Asked Questions After having undertaken a period of research within recreational cricket, this document is aimed at addressing the frequently asked questions from cricket Clubs, Leagues, Boards

More information

Guidance to support the DWP 2 Tier Complaints Resolution Process

Guidance to support the DWP 2 Tier Complaints Resolution Process Guidance to support the DWP 2 Tier Complaints Resolution Process Purpose This guidance is for all DWP staff that are following the 2 tier complaints resolution process, except those working in a Contact

More information

19 Dec The forwarding and returning obligation does not concern messages containing malware or spam.

19 Dec The forwarding and returning obligation does not concern messages containing malware or spam. E-mail rules 1/5 E-mail rules These e-mail rules concern all users of the university's e-mail systems. The parts aimed at university staff members concern all of the University's units, their employees

More information

It applies to personal information for individuals that are external to us such as donors, clients and suppliers (you, your).

It applies to personal information for individuals that are external to us such as donors, clients and suppliers (you, your). Our Privacy Policy 1 Purpose Mission Australia is required by law to comply with the Privacy Act 1988 (Cth) (the Act), including the Australian Privacy Principles (APPs). We take our privacy obligations

More information

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018 ma recycle.com Rely and Comply... GDPR Privacy Policy Policy Date: 24 May 2018 Max Recycle Hawthorne House Blackthorn Way Sedgeletch Industrial Estate Fencehouses Tyne & Wear DH4 6JN T: 0845 026 0026 F:

More information

Clubs template privacy notice wording

Clubs template privacy notice wording Clubs template privacy notice wording This template sets out the headings required under GDPR. Where possible, we have sought to include options for different categories of data subject and include examples.

More information

Changes to Government Security Levels. A DWP perspective

Changes to Government Security Levels. A DWP perspective Changes to Government Security Levels - A DWP perspective Every working day the Department: What DWP does takes 15,000 job vacancies/processes over 830,000 internet job searches conducts over 65,000 adviser

More information

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager.

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager. London School of Economics & Political Science IT Services Policy Remote Access Policy Jethro Perkins Information Security Manager Summary This document outlines the controls from ISO27002 that relate

More information

IT Appropriate Use - Best Practice for Guidelines. Section 1 - Purpose / Objectives. Section 2 - Scope / Application. Section 3 - Definitions

IT Appropriate Use - Best Practice for  Guidelines. Section 1 - Purpose / Objectives. Section 2 - Scope / Application. Section 3 - Definitions IT Appropriate Use - Best Practice for Email Guidelines Section 1 - Purpose / Objectives (1) Email is used at Victoria University as a business communication tool and users are obliged to use this tool

More information

Stopsley Community Primary School. Data Breach Policy

Stopsley Community Primary School. Data Breach Policy Stopsley Community Primary School Data Breach Policy Contents Page 1 Introduction... 3 2 Aims and objectives... 3 3 Policy Statement... 4 4 Definitions... 4 5 Training... 5 6 Identification... 5 7 Risk

More information

VFS GLOBAL PVT LTD PRIVACY DISCLAIMER

VFS GLOBAL PVT LTD PRIVACY DISCLAIMER VFS GLOBAL PVT LTD PRIVACY DISCLAIMER Version 1.0 Privacy Disclaimer Scope VFS GLOBAL (hereinafter referred to as VFS GLOBAL ) is an outsourced partner of Diplomatic Missions across globe, and is authorized

More information

Application for Advice and Assistance

Application for Advice and Assistance Protect - Personal Information Application for Advice and Assistance Please complete in block capitals and ensure that form CRM1 is also completed Client's Declaration Please tick the box below which applies

More information

Starflow Token Sale Privacy Policy

Starflow Token Sale Privacy Policy Starflow Token Sale Privacy Policy Last Updated: 23 March 2018 Please read this Privacy Policy carefully. By registering your interest to participate in the sale of STAR tokens (the Token Sale ) through

More information

Subject access policy and template response letters

Subject access policy and template response letters Barham Parish Council. Subject Access Requests ( SAR ) Checklist Inform data subjects of their right to access data and provide an easily accessible mechanism through which such a request can be submitted

More information

Access Control Policy

Access Control Policy Access Control Policy Version Control Version Date Draft 0.1 25/09/2017 1.0 01/11/2017 Related Polices Information Services Acceptable Use Policy Associate Accounts Policy IT Security for 3 rd Parties,

More information

Mobile Computing Policy

Mobile Computing Policy Mobile Computing Policy Overview and Scope 1. The purpose of this policy is to ensure that effective measures are in place to protect against the risks of using mobile computing and communication facilities..

More information

Valley Blinds GDPR Privacy Policy. Introduction. What kind of personal data do we collect?

Valley Blinds GDPR Privacy Policy. Introduction. What kind of personal data do we collect? Valley Blinds GDPR Privacy Policy Introduction This Privacy Policy explains what we do with your personal data, whether we are in the process of dealing with an enquiry, processing an order, continuing

More information

Our Data Protection Officer is Andrew Garrett, Operations Manager

Our Data Protection Officer is Andrew Garrett, Operations Manager Construction Youth Trust Privacy Notice We are committed to protecting your personal information Construction Youth Trust is committed to respecting and keeping safe any personal information you share

More information

BEEDS portal Bank of England Electronic Data Submission portal. User guide. Credit unions Version 1.2

BEEDS portal Bank of England Electronic Data Submission portal. User guide. Credit unions Version 1.2 BEEDS portal Bank of England Electronic Data Submission portal User guide Credit unions Version 1.2 May 2018 Contents Document versions 3 1. Introduction 4 a. Bank of England contact details 4 2. General

More information

Grand Avenue Primary and Nursery School ICT Data management. Contents

Grand Avenue Primary and Nursery School ICT Data management. Contents Grand Avenue Primary and Nursery School ICT Data management Contents 1. Acceptable Use Statement 2. Transfer and Offsite Use of Sensitive Data 3. E-safety 4. Declaration Introduction These three policy

More information

BISHOP GROSSETESTE UNIVERSITY. Document Administration. This policy applies to staff, students, and relevant data subjects

BISHOP GROSSETESTE UNIVERSITY. Document Administration. This policy applies to staff, students, and relevant data subjects BISHOP GROSSETESTE UNIVERSITY Document Administration Document Title: Document Category: Privacy Policy Policy Version Number: 1.0 Status: Reason for development: Scope: Author / developer: Owner Approved

More information

Information Security Controls Policy

Information Security Controls Policy Information Security Controls Policy Classification: Policy Version Number: 1-00 Status: Published Approved by (Board): University Leadership Team Approval Date: 30 January 2018 Effective from: 30 January

More information

Mailbox Rental Terms and Conditions

Mailbox Rental Terms and Conditions Mailbox Rental Terms and Conditions (valid from 26th September 2018) Subject to the customer ("the Customer") observing the Terms and Conditions set out below, Mail Boxes Etc. ("the Company") agrees to

More information

Controls Electronic messaging Information involved in electronic messaging shall be appropriately protected.

Controls Electronic messaging Information involved in electronic messaging shall be appropriately protected. I Use of computers This document is part of the UCISA Information Security Toolkit providing guidance on the policies and processes needed to implement an organisational information security policy. To

More information

DATA BREACH POLICY [Enniskillen Presbyterian Church]

DATA BREACH POLICY [Enniskillen Presbyterian Church] DATA BREACH POLICY [Enniskillen Presbyterian Church] Enniskillen Presbyterian Church is committed to complying with data protection legislation and will take appropriate technical and organisational measures

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Introduction Stewart Watt & Co. is law firm and provides legal advice and assistance to its clients. It is regulated by the Law Society of Scotland. The personal data that Stewart

More information

2. The Information we collect and how we use it: Individuals and Organisations: We collect and process personal data from individuals and organisation

2. The Information we collect and how we use it: Individuals and Organisations: We collect and process personal data from individuals and organisation WOSDEC: Privacy Policy West of Scotland Development Education Centre WOSDEC - (We) are committed to protecting and respecting your privacy. This policy sets out how the personal information we collect

More information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information Privacy Statement Introduction Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information about how IT Support (UK) Ltd handle personal information.

More information

Data Protection Policy

Data Protection Policy The Worshipful Company of Framework Knitters Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act 1998 (DPA) [UK] For information on this

More information

Your security on click Jobs

Your security on click Jobs Your security on click Jobs At Click Jobs is a trading name of Raspberry Recruitment Limited, we're committed to helping you find the right job in a safe and secure environment. On these pages, you can

More information

Data Breach Incident Management Policy

Data Breach Incident Management Policy Data Breach Incident Management Policy Policy Number FCP2.68 Version Number 1 Status Draft Approval Date: First Version Approved By: First Version Responsible for Policy Responsible for Implementation

More information

Communication and Usage of Internet and Policy

Communication and Usage of Internet and  Policy Communication and Usage of Internet and Email Policy Policy Category Administration Policy Code ADM HE 27 Policy owner Chief Executive Officer Responsible Officer Chief Executive Officer Approving authority

More information

These pieces of information are used to improve services for you through, for example:

These pieces of information are used to improve services for you through, for example: Eolach Accountants & Business Advisors Limited t/a McGinley & Co. Privacy Policy At Eolach Accountants & Business Advisors Limited t/a McGinley & Co. our policy is simple we understand the importance of

More information

The Provincial Grand Lodge and Chapter of East Lancashire. Data Protection Act 1998

The Provincial Grand Lodge and Chapter of East Lancashire. Data Protection Act 1998 The Provincial Grand Lodge and Chapter of East Lancashire Data Protection Act 1998 Why do I need to read this? If you have access to the systems and records that the Province holds about our members, or

More information

Order of Malta Volunteers Privacy Statement

Order of Malta Volunteers Privacy Statement Order of Malta Volunteers Privacy Statement The Order of Malta Volunteers ( the OMV, We, Us ), is a charity registered in England and Wales with charity number 1164242. Its registered address is 13 Deodar

More information

PRIVACY NOTICE. This policy may be updated from time to time so please check back occasionally to make sure you re happy with any changes.

PRIVACY NOTICE. This policy may be updated from time to time so please check back occasionally to make sure you re happy with any changes. PRIVACY NOTICE This policy aims to explain fully and clearly what personal data I collect from you, what happens to that data, and what your rights are in relation to your personal data. If I can clarify

More information

COLLECTION & HOW THE INFORMATION WILL BE USED

COLLECTION & HOW THE INFORMATION WILL BE USED Privacy Policy INTRODUCTION As our esteemed client, your privacy is essential to us. Here, at www.indushealthplus.com, we believe that privacy is a top priority. We know that you care how information about

More information

Digital Assets: Practitioner s Guide Australia

Digital Assets: Practitioner s Guide Australia Digital Assets: Practitioner s Guide Australia This practitioner s guide has been prepared to assist Australian practitioners with the issue of digital assets when taking instructions from clients for

More information

Complaint Handling Procedure and Escalation Policy

Complaint Handling Procedure and Escalation Policy Complaint Handling Procedure and Escalation Policy COPYRIGHT STATEMENT This document is the property of Nottingham Rehab Ltd. and may not, without our express written consent, be copied in whole or in

More information

Canadian Anti-Spam Legislation (CASL)

Canadian Anti-Spam Legislation (CASL) Canadian Anti-Spam Legislation (CASL) FREQUENTLY ASKED QUESTIONS The purpose of this document is to assist and guide U of R employees regarding their obligations under the Canadian Anti-Spam Legislation

More information

Clyst Vale Community College Data Breach Policy

Clyst Vale Community College Data Breach Policy Clyst Vale Community College Data Breach Policy Contents 1. Aim Page 2 2. Definition Page 2-3 3. Scope Page 3 4. Responsibilities Page 3 5. Reporting a data breach Page 3-4 6. Data breach plan Page 4 7.

More information

Pulsar Instruments Plc Privacy Policy

Pulsar Instruments Plc Privacy Policy 1 Pulsar Instruments Plc Privacy Policy Keeping your personal information safe and secure is our priority. The following text sets out how Pulsar Instruments Plc collects, uses, shares and protects information

More information

In this policy, whenever you see the words we, us, our, it refers to Ashby Concert Band Registered Charity Number

In this policy, whenever you see the words we, us, our, it refers to Ashby Concert Band Registered Charity Number ASHBY CONCERT BAND PRIVACY POLICY The privacy and security of your personal information is extremely important to us. This privacy policy explains how and why we use your personal data. We will keep this

More information

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July Privacy Notice Lonsdale & Marsh understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of all of our clients and will

More information

Canadian Anti-Spam Legislation (CASL) Campaign and Database Compliance Checklist

Canadian Anti-Spam Legislation (CASL) Campaign and Database Compliance Checklist Canadian Anti-Spam Legislation (CASL) Campaign and Database Compliance Checklist Database Checklist Use this Checklist as a guide to assessing existing databases for compliance with Canada s Anti-Spam

More information

User Guide Submitter v2.5

User Guide Submitter v2.5 IssueTrak Quick Start! 1. All LSE Finance Staff have advised that all Accounts Payable Issues must be routed via IssueTrak 2. To Submit any Accounts Payable Query, please login to the IssueTrak Portal

More information

General Data Protection Regulation (GDPR) Policy

General Data Protection Regulation (GDPR) Policy General Data Protection Regulation (GDPR) Policy Original prepared on: 01 May 2018 Reviewed on: 01 May 2018 To be reviewed on: 31 March 2019 Prepared by: Ralph Elliott-King - Financial Controller Reviewed

More information

Privacy notice. Last updated: 25 May 2018

Privacy notice. Last updated: 25 May 2018 Privacy notice Last updated: 25 May 2018 www.courtprice.co.uk ('Website') is provided by Courtprice Limited ('we'/'us'/'our'). In doing so, we may be in a position to receive and process personal information

More information

Overview Bank IT examination perspective Background information Elements of a sound plan Customer notifications

Overview Bank IT examination perspective Background information Elements of a sound plan Customer notifications Gramm-Leach Bliley Act Section 501(b) and Customer Notification Roger Pittman Director of Operations Risk Federal Reserve Bank of Atlanta Overview Bank IT examination perspective Background information

More information

Use of Personal Mobile Phone Whilst on Duty

Use of Personal Mobile Phone Whilst on Duty Use of Personal Mobile Phone Whilst on Duty (Incorporating Smartphones and Hand Held Devices) Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland

More information

Care Recruitment Matters Limited Privacy Notice

Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited (CRM) is a specialist recruitment agency, sourcing permanent candidates for companies focused in the Health and Social Care

More information

A Homeopath Registered Homeopath

A Homeopath Registered Homeopath A Homeopath Registered Homeopath DATA PROTECTION POLICY Scope of the policy This policy applies to the work of homeopath A Homeopath (hereafter referred to as AH ). The policy sets out the requirements

More information

We may change the privacy notice from time to time by amending this page. What type of information will we collect from you?

We may change the privacy notice from time to time by amending this page. What type of information will we collect from you? This privacy notice sets out how we will process personal data we collect from or about you, or which you provide to us. Please read this notice carefully to understand why data is being collected and

More information

Canada s Anti-Spam Legislation (CASL) What it means for Advisors. Distributor Learning & Development

Canada s Anti-Spam Legislation (CASL) What it means for Advisors. Distributor Learning & Development Canada s Anti-Spam Legislation (CASL) What it means for Advisors Distributor Learning & Development Learning objectives By the end of this session, you will be able to: Describe CASL and how it impacts

More information

University Policies and Procedures ELECTRONIC MAIL POLICY

University Policies and Procedures ELECTRONIC MAIL POLICY University Policies and Procedures 10-03.00 ELECTRONIC MAIL POLICY I. Policy Statement: All students, faculty and staff members are issued a Towson University (the University ) e-mail address and must

More information

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk CURTIS BANKS LIMITED Privacy Information Notice curtisbanks.co.uk Contents Section Page 1 Who we are 3 2 Why we need to collect, use and process personal information 3 3 The information we may collect,

More information

This factsheet intends to provide guidance on how you can manage your s. You will discover:

This factsheet intends to provide guidance on how you can manage your  s. You will discover: Summary This factsheet intends to provide guidance on how you can manage your emails. You will discover: Why it is important to manage your emails Guidance for approaching email management How to identify

More information

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

VISTRA (CYPRUS) LTD. PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA (CYPRUS) LTD. PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

Checklist: Credit Union Information Security and Privacy Policies

Checklist: Credit Union Information Security and Privacy Policies Checklist: Credit Union Information Security and Privacy Policies Acceptable Use Access Control and Password Management Background Check Backup and Recovery Bank Secrecy Act/Anti-Money Laundering/OFAC

More information

MNsure Privacy Program Strategic Plan FY

MNsure Privacy Program Strategic Plan FY MNsure Privacy Program Strategic Plan FY 2018-2019 July 2018 Table of Contents Introduction... 3 Privacy Program Mission... 4 Strategic Goals of the Privacy Office... 4 Short-Term Goals... 4 Long-Term

More information

INFORMATION GOVERNANCE. Caldicott Approval Procedure

INFORMATION GOVERNANCE. Caldicott Approval Procedure NHS TAYSIDE INFORMATION GOVERNANCE Caldicott Approval Procedure Author: Peter McKenzie Review Group: Information Governance Group Review Date: September 2010 Last Update: September 2009 Document : NHST-ISC-CAP

More information

BEEDS portal Bank of England Electronic Data Submission portal. User guide. New PRA Authorisations Version 1.1

BEEDS portal Bank of England Electronic Data Submission portal. User guide. New PRA Authorisations Version 1.1 BEEDS portal Bank of England Electronic Data Submission portal User guide New PRA Authorisations Version 1.1 May 2018 Contents Document versions 3 1. Introduction 3 a. Bank of England contact details 4

More information

VISTRA NETHERLANDS PRIVACY NOTICE

VISTRA NETHERLANDS PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA NETHERLANDS PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

GDPR Processor Security Controls. GDPR Toolkit Version 1 Datagator Ltd

GDPR Processor Security Controls. GDPR Toolkit Version 1 Datagator Ltd GDPR Processor Security Controls GDPR Toolkit Version 1 Datagator Ltd Implementation Guidance (The header page and this section must be removed from final version of the document) Purpose of this document

More information

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke Prepared by: M Franklin Issued: May 2018 Pathways Community Interest Company Review due: May 2020 Pathways CIC Privacy Policy Version 0.3 Approved by: Yvonne Clarke Approval date: 21.05.2018 Pathways CIC

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Policy adopted: April 2016 Policy review date: April 2018 OAT Model Policy 1 Contents 1. Policy statement and principles... 3 1.1 Policy aims and principles... 3 1.2 Data protection

More information

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory ("we"; "us"; "our") respects your privacy and is committed to protecting your personal information at all times in everything we do. We are

More information

HBW LAW LTD T/A HESELTINE BRAY & WELSH

HBW LAW LTD T/A HESELTINE BRAY & WELSH HBW LAW LTD T/A HESELTINE BRAY & WELSH CLIENT INFORMATION POLICY HOW WE STORE AND USE YOUR PERSONAL INFORMATION INFORMATION WE COLLECT AND HOLD ABOUT YOU To enable us to provide you with our services we

More information

Vistra International Expansion Limited PRIVACY NOTICE

Vistra International Expansion Limited PRIVACY NOTICE Effective Date: from 25 May 2018 Vistra International Expansion Limited PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal

More information

Privacy Notice For Our Customers And Contacts

Privacy Notice For Our Customers And Contacts Privacy Notice For Our Customers And Contacts What Is The Purpose Of This Notice? This notice applies to all businesses operating within The Alumasc Group plc group of Companies (the Group ), as follows:

More information

SCHOOL SUPPLIERS. What schools should be asking!

SCHOOL SUPPLIERS. What schools should be asking! SCHOOL SUPPLIERS What schools should be asking! Page:1 School supplier compliance The General Data Protection Regulation (GDPR) comes into force on 25 May 2018 and will be applied into UK law via the updated

More information

Red ALERT Apparent Breach of an Unidentified Pharmacy Related Database

Red ALERT Apparent Breach of an Unidentified Pharmacy Related Database Red ALERT Apparent Breach of an Unidentified Pharmacy Related Database Making the UK more resilient against Cybercrime Date: August 2017 Reference: 0449-CYB This Red Alert is issued by the United Kingdom

More information

WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7. Appropriate Methods of Communicating Protected Health Information

WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7. Appropriate Methods of Communicating Protected Health Information WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7 Appropriate Methods of Communicating Protected Health Information Statement of Policy Washington University and its member organizations (collectively, Washington

More information

St Edmund Arrowsmith Catholic Centre for Learning

St Edmund Arrowsmith Catholic Centre for Learning St Edmund Arrowsmith Catholic Centre for Learning Mobile Device Policy (Students) September 2016 This Policy was adopted and ratified by the Full Governing Body of SEA. C.F.L. at the meeting held on Signed...

More information

Privacy Impact Assessment

Privacy Impact Assessment Automatic Number Plate Recognition (ANPR) Deployments Review Of ANPR infrastructure February 2018 Contents 1. Overview.. 3 2. Identifying the need for a (PIA).. 3 3. Screening Questions.. 4 4. Provisions

More information

Marketing Law in Canada Has Changed... Are You Ready?

Marketing Law in Canada Has Changed... Are You Ready? Email Marketing Law in Canada Has Changed... Are You Ready? Webinar May 29 th, 2014 Hosted by: Tracey Hart, Director of Marketing, Discover Boating Canada Presented by: Lonnie Brodkin-Schneider, Partner,

More information

Privacy Policy. Information about us. What personal data do we collect and how do we use it?

Privacy Policy. Information about us. What personal data do we collect and how do we use it? This privacy policy sets out the way in which your personal data is handled by Leeds Bradford Airport Limited (referred to as "we", "us" and "our") whether collected through one of the websites we operate,

More information

We reserve the right to modify this Privacy Policy at any time without prior notice.

We reserve the right to modify this Privacy Policy at any time without prior notice. This Privacy Policy sets out the privacy policy relating to this site accessible at www.battleevents.com and all other sites of Battle Events which are linked to this site (collectively the Site ), which

More information

PRIVACY NOTICE. 1. Definitions

PRIVACY NOTICE. 1. Definitions PRIVACY NOTICE This Privacy Notice applies to Ecctis Limited and its operational entities: UK NARIC; Europass; the Centre for Professional Qualifications (CPQ); ECVET; and ReferNet. Ecctis Ltd understands

More information

Terms & Conditions. Privacy, Health & Copyright Policy

Terms & Conditions. Privacy, Health & Copyright Policy 1. PRIVACY Introduction Terms & Conditions Privacy, Health & Copyright Policy When you access our internet web site you agree to these terms and conditions. Bupa Wellness Pty Ltd ABN 67 145 612 951 ("Bupa

More information

SMS for REST Professional

SMS for REST Professional RockendSMS Enhanced Integration SMS for REST Professional RockendSMS has newly designed and developed an upgrade to the way you send SMS through REST Professional V14 and above (RockendSMS Enhanced Integration).

More information

TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE

TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE 1. General The term PPS refers to: Professional Provident Society Holdings Trust, (The Holding Trust); Professional

More information

Professional Engineers Ontario. canada s anti-spam. Guidelines for Chapters

Professional Engineers Ontario. canada s anti-spam. Guidelines for Chapters Professional Engineers Ontario canada s anti-spam legislation (CASL) Guidelines for Chapters Published by Association of Professional Engineers of Ontario, February 2015 Contents 1. Introduction... 3 2.

More information

BRIDGEWATER SURGERIES. Privacy Notice

BRIDGEWATER SURGERIES. Privacy Notice BRIDGEWATER SURGERIES Privacy Notice We understand how important it is to keep your personal information safe and secure and we take this very seriously. We have taken steps to make sure your personal

More information

HIPAA Security and Privacy Policies & Procedures

HIPAA Security and Privacy Policies & Procedures Component of HIPAA Security Policy and Procedures Templates (Updated for HITECH) Total Cost: $495 Our HIPAA Security policy and procedures template suite have 71 policies and will save you at least 400

More information