The GDPR: what it is and what it means for Freelance Dietitians

Size: px
Start display at page:

Download "The GDPR: what it is and what it means for Freelance Dietitians"

Transcription

1 The GDPR: what it is and what it means for Freelance Dietitians Nan Millette, MEd, RD Panellists: Mariette Abrahams Rebecca McManamon Tracey Clarke

2 Overview Disclaimer What is GDPR? BDA Data Protection for Volunteers FDSG; your freelance business

3 GDPR EU law Will replace current Data Protection Act New requirements as to how organisations process personal data After Brexit, all businesses and charities will have to comply, so we will most likely adopt all or most of GDPR as domestic legislation

4 Under GDPR, UK citizens will benefit from new or stronger rights: to be informed about how their data is used; around data portability across service providers; to erase or delete their personal information; over access to the personal data an organisation holds about them; to correct inaccurate or incomplete information; and over automated decisions and profiling.

5 How do we begin? Adopt a whole organisational approach This impacts campaigning, marketing, managing volunteers and recording information about service users processing personal data Audit the personal data you hold, where it came from and who you share it with

6 Review how you ask for consent Explain clearly why you are collecting personal data and how you intend to use it Get explicit consent to provide date to third party users Consent needs to be freely given

7 Opt in v Opt out Big debate Best practice is a separate issue Key: meet a set of lawful conditions to process data for direct marketing Balancing act Individual s choice to say no is paramount. silence, pre-ticked boxes or inactivity should not constitute consent

8 Provide user access to personal data User s rights to access their own personal data Subject access requests at any time to check the data you hold and what you do with it You need to plan how you will handle requests within the new timescales so that it is not too onerous and time-consuming

9 Manage the data you hold properly right to be forgotten Up to date data; what to do with old data? Clear Privacy Policy Find out what information we hold on you Remove all information about me sections

10 Beware of data breaches Increased fines by ICO (Information Commissioner s Office) Ensure you have procedures in place to detect, report and investigate a personal data breach Review ICO updates regularly

11 Don t panic, but be prepared GDPR an evolution DPA already requires data to be processed fairly and lawfully Opportunity to review how you process data already Plans in place to make any changes to be ready for May 2018 ENCOURAGEMENT AND EDUCATION BEFORE ENFORCEMENT

12 12 Steps: GDPR guidance from ICO 1. Awareness 2. Information you hold 3. Communicating privacy information 4. Individuals rights 5. Subject access requests 6. Lawful basis for processing personal data 7. Consent 8. Children 9. Data breaches 10. Data protection by design/impact assessments 11. Data protection officers 12. International

13 BDA process (1) The BDA are unable to assist with any professional practice guidelines for Freelance Group members Beccie is not qualified or experienced within a clinical setting. Her professional focus is to ensure that the BDA is compliant with the requirements of the GDPR, which is a very different context to dietetic practitioners. Beccie is not able to commit the BDA to providing any specialist advice to the FDG. -Rebecca Jeffries, BDA Data Development Officer (27 Feb 2018)

14 BDA process (2) The Education & Professional Development team : guidance in the March edition of Dietetics Today. any specific guidance on this matter will come from them however, it is a complex area and any practitioners with specific concerns or a need for legal guidance should seek that from a qualified expert or legal advisor. The ICO is the only recommended source of information as they are the body responsible for enforcing the regulations. They are the BDA s only source of information and guidance, so we are not able to provide anything other than what they produce. For any other queries speak to Kiri or Najia in Education & Professional Development.

15 BDA Data Protection for Volunteers Draft guidelines for groups, 2017 Sensitive personal data Guidelines are the minimum requirements BDA cannot share data if you do not meet the minimum requirements

16 What groups need to do Appoint one member as Data Contact Requests for data Do not share data, unless agreed with BDA Storage of data: computers or servers with virus and hacking protection, not accessible to others No hard copy member details Inform BDA if data has been lost or accessed Profile updates on MyBDA, or BDA office

17 Communications Use newsletter function on BDA website Do not store contact lists between communications; request a contact list each and every time (accuracy) Do not use BDA data to advertise or campaign without BDA agreement

18 How can you use data? Valuable resource; tight controls required Third parties need to speak directly to BDA central team Do not undersell or undervalue membership data; penalty under GDPR and PECR

19 What data can you access? Live data Common request: names & addresses Some demographic and geographic data Professional interests and expertise Low completion rate for non-compulsory data Timescale: when, how long, when destroyed

20 Where to find more details? ICO guides and good practise documents Helplines for smaller businesses Chat box on ICO website Currently developing guidelines around new legislation (May 2018) BDA contacts: Kiri or Najia in Education & Professional Development

21 Implications for BDA specialist groups Summary: groups and branches FDG can no longer hold membership data FDG must request each and every time from BDA FDG must use the newsletter function on BDA website, TBA

22 Privacy Policies BDA: FDG: Johanna Heath, Baobab Solutions

23 FDG Website As a minimum, update all forms to include a mandatory tick box to grant explicit permission for the data to be collected. Given that dietitian enquiries are being sent to individual dietitians, the responsibility for the safe-keeping of the information is theirs. Extend the form descriptions, where appropriate, to explain why the information is required. For any data being recorded, we need to specify who will have access to it, how long it will be kept for, give the individual the option of updating their information and also having their information completely deleted, including user accounts. FDG are required to run regular security audits and have a mechanism for reporting security breaches to affected individuals.

24 For enquiry forms Every enquiry is currently recorded in the database, primarily as a fallback in the event of notification failure. This is default behaviour for the software. Under GDPR, this becomes a liability. Functionality can be added to stop these entries from being created (so we lose the backup), or a manual process can be put in place for the information to be deleted periodically.

25 For Freelance Dietitians The information you supply is public domain anyway, but you still need to have the explicit consent of clients. option to have their information removed altogether (including the user account) and not just from the public domain blog and product submissions. The FDG website should either add a manual process to delete these, or add functionality for the user to do so themselves

26 Other Functionality such as spam detection also comes under scrutiny. By default, all communications from visitors are logged. There is an option to restrict this to suspected spam only. Even so, this will have to be covered by the privacy policy. The same applies to any security monitoring software used as IP addresses are being recorded as a minimum, and potentially form details as well. Does the BDA set out requirements for security monitoring on the website itself? Also to consider, there are the usual website access and error logs, as well as Google analytics and cookies.

27 Wordpress Wordpress itself is being reviewed for GDPR compliance. They are in the process of creating a GDPR validation environment for all plugins, such that plugin authors can verify their plugins as GDPR compliant.

28 Existing data Many website owners tend to assume that once they have been contacted by someone, they have the right to use the details for marketing purposes. This can no longer be done. The best way to deal with this is to send an to all individuals currently in the marketing database, requesting them to opt in or out of future marketing.

29 Summary GDPR comes into effect 25 May 2018 BDA will manage dietitian data for branches and SGs As a Freelance Dietitian, you will need to manage any data you hold for your clients in a different way. Keep up to date on the ICO website

30 What if you have your own business?

31 Your Questions 1. Do I have to encrypt e mails? What about texts? Some patients like to text a lot. How do I know if my is safe. What about the clients? 2. Some clients contact me in the first place via e mail. I then assume that they are happy for correspondence. Should I be getting them to sign something? 3. I have written a privacy policy. Is it enough to provide to clients or should they be signing to say they are in agreement. 4. I keep paper records in a locked filing cabinet in a locked room in a secure building. What if I am burgled? Would this count as a breach, or a have I done enough? What is enough? Has this changed from the previous data protection laws? 5. My understanding is that the fines have increased for data breaches, however, I have read the info, and it seems that little has actually changed in terms of advice on how to remain secure. Am I right? Or is there more to it than that? -Anne

32 My main question is about how the FDG site will be managed as if someone say looks me up and inputs details on there for a query, how will this be managed? For example I know I will need a privacy statement on my own website, will there be a generic statement on the FDG plus need to put our own on? -Rebecca My concerns are ensuring protection using the Internet - in particular through , and how long to retain client records. - Elizabeth

33 I ve done a bit of reading about the new regulations but as a lone working freelancer I just cannot work out if I am supposed to change anything I do or not. Work I do within other organisations e.g. registered hospitals, is fine as they are ready for the change in regulations. When it is just me and a member of the general public, possibly a GP or consultant receiving letters, do I need to change what I do? How do I need to change wording on my website under terms and conditions/ data protection clauses? -Lucy

34 Most of what I have seen relates to bigger businesses involved in using client s data for advertising or potentially selling on. What I d like to know is the impact for those of us managing personal data on a very small scale. In particular, the new rules about having to inform clients of how the data will be stored/used. What exactly do we have to inform them of? For example, if someone s us with an initial enquiry, do we have to start explaining about security and that we won t be passing their on to a third party, before we can actually respond to their enquiry?! I presume not as that would be silly but from some things I have seen about GDPR, this seems to be the implication. A plan to draw up a nice FDG flow chart would be good, if the info can be simplified sufficiently?! -Isi

35 Do we need tighter physical security for clients' personal data records, not relying on our house security but buying in cabinets with better locks? Extra layer of password protection, eg for s? What permissions do we need to get from new clients before we start, with any specific wording you have available? Do we need to contact old clients to let them know what we re doing with their data? What needs to be done to old client records..shredding, burning, etc? Anything specific as regards IPO registration? Places we can look for more information and guidance? -Hilary

36 These are some of the questions I have about the GDPR related to the practicalities of being a private practitioner: 1) how should I store paper patient records? 2) how should I store electronic patient records? 3) how do I ensure s are secure if not using an NHS.net 4) what permissions do I need to get from the patient? 5) if I am not using patient records for any marketing activity and only communicating with other HCPs such as referer/gp/slt does this make a difference? 6) When and how should I dispose of patient records paper and electronic? - Nicole

37

38

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

This privacy notice outlines our commitment to keeping your data safe and secure and explains how we collect and process your data.

This privacy notice outlines our commitment to keeping your data safe and secure and explains how we collect and process your data. Data Privacy Notice This privacy notice outlines our commitment to keeping your data safe and secure and explains how we collect and process your data. 1. What is Personal Data? Personal data means information

More information

How will GDPR legislation affect B2C digital marketing?

How will GDPR legislation affect B2C digital marketing? How will GDPR legislation affect B2C digital marketing? GENERAL DATA PROTECTION REGULATION GDPR READY How will GDPR legislation affect B2C digital marketing? From May 2018 when GDPR legally applies it

More information

GDPR Compliance. Clauses

GDPR Compliance. Clauses 1 Clauses GDPR The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a privacy and data protection regulation in the European Union (EU). It became enforceable from May 25 2018. The

More information

Frequently Asked Questions

Frequently Asked Questions Frequently Asked Questions After having undertaken a period of research within recreational cricket, this document is aimed at addressing the frequently asked questions from cricket Clubs, Leagues, Boards

More information

This Privacy Policy applies if you're a customer, employee or use any of our services, visit our website, , call or write to us.

This Privacy Policy applies if you're a customer, employee or use any of our services, visit our website,  , call or write to us. Privacy Policy Background This policy explains when and why we collect personal information about you; how we use it, the conditions under which we may disclose it to others and how we keep it secure.

More information

DATA SECURITY - DATA PROTECTION ACT

DATA SECURITY - DATA PROTECTION ACT DATA SECURITY - DATA PROTECTION ACT Data Security - Data Protection Act Many businesses are totally reliant on the data stored on their PCs, laptops, networks, mobile devices and in the cloud. Some of

More information

This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant.

This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant. GDPR and BMC Clubs Lawful basis for Processing Personal Data This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant.

More information

A Homeopath Registered Homeopath

A Homeopath Registered Homeopath A Homeopath Registered Homeopath DATA PROTECTION POLICY Scope of the policy This policy applies to the work of homeopath A Homeopath (hereafter referred to as AH ). The policy sets out the requirements

More information

EIT Health UK-Ireland Privacy Policy

EIT Health UK-Ireland Privacy Policy EIT Health UK-Ireland Privacy Policy This policy describes how EIT Health UK-Ireland uses your personal information, how we protect your privacy, and your rights regarding your information. We promise

More information

Data Protection and Information Security. Presented by Emma Hawksworth Slater and Gordon

Data Protection and Information Security. Presented by Emma Hawksworth Slater and Gordon Data Protection and Information Security Webinar Presented by Emma Hawksworth Slater and Gordon 1 3 ways to participate Ask questions link below this presentation Answer the polls link below this presentation

More information

GDPR effects on Gift Aid. Presented by Keren Caird Business Development Gift Aid Manager Sue Ryder

GDPR effects on Gift Aid. Presented by Keren Caird Business Development Gift Aid Manager Sue Ryder GDPR effects on Gift Aid Presented by Keren Caird Business Development Gift Aid Manager Sue Ryder Accountability Processed lawfully, fairly and in a transparent manner Collected for specified, explicit

More information

The isalon GDPR Guide Helping you understand and prepare for the legislation

The isalon GDPR Guide Helping you understand and prepare for the legislation The isalon GDPR Guide Helping you understand and prepare for the legislation 01522 887200 isalonsoftware.co.uk Read our guide today to help you plan for the new legislation.. The General Data Protection

More information

General Data Protection Regulation (GDPR) Key Facts & FAQ s

General Data Protection Regulation (GDPR) Key Facts & FAQ s General Data Protection Regulation (GDPR) Key Facts & FAQ s GDPR comes into force on 25 May 2018 GDPR replaces the Data Protection Act 1998. The main principles are much the same as those in the current

More information

If you start the process of wanting to purchase a property or unit from us, we may also collect the following information from you:

If you start the process of wanting to purchase a property or unit from us, we may also collect the following information from you: Privacy Notice WHO ARE WE? We are Stirlin Group Limited, which, for the purposes of this policy, includes Stirlin Developments Limited and Lodge Lane Developments Limited, trading as Homes by Stirlin.

More information

CommuniGator. Your GDPR. Compliance Checklist

CommuniGator. Your GDPR. Compliance Checklist CommuniGator Your GDPR Compliance Checklist The impact of the EU GDPR on your business As of April 2016, the EU General Data Protection Regulation was adopted but it does not come into force until 25th

More information

In this Policy the following terms shall have the following meanings:

In this Policy the following terms shall have the following meanings: NJR TRADING LTD understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone who visits this website, https://bar-tonic.

More information

Hertfordshire Natural History Society

Hertfordshire Natural History Society Hertfordshire Natural History Society Privacy Policy This privacy policy sets out how the Hertfordshire Natural History Society (and Herts Bird Club) ( HNHS ) complies with its data protection obligations

More information

How the GDPR will impact your software delivery processes

How the GDPR will impact your software delivery processes How the GDPR will impact your software delivery processes About Redgate 230 17 202,000 2m Redgaters and counting years old customers SQL Server Central and Simple Talk users 91% of the Fortune 100 use

More information

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings:

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings: PRIVACY POLICY BACKGROUND: Leaman Mattei Limited (LM) understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone

More information

Website Privacy Notice

Website Privacy Notice This privacy notice explains the processing of personal data on the website of Assurity Consulting Ltd (including the entity of Assurity Consulting Holdings Ltd). Assurity Consulting Ltd is committed to

More information

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017 Data Protection should be part of every company s or organisation s DNA Do you process

More information

NHS R&D Forum Privacy Policy: FINAL v0.1 May 25 th 2018

NHS R&D Forum Privacy Policy: FINAL v0.1 May 25 th 2018 NHS R&D Forum Privacy Policy: FINAL v0.1 May 25 th 2018 This privacy policy is published to provide transparent information about how we use, share and store any personal information that you may provide

More information

The New Data Protection Law a Basic Guide

The New Data Protection Law a Basic Guide The New Data Protection Law a Basic Guide The new Data Protection Law and how it affects fundraising. DRF Group Ltd has prepared this basic guide to the main provisions of the new Data Protection Act as

More information

Grand Orange Lodge of Ireland Privacy Notice

Grand Orange Lodge of Ireland Privacy Notice Grand Orange Lodge of Ireland Privacy Notice Introduction The Grand Orange Lodge of Ireland is registered with the Information Commissioner s Office for the purposes of compliance with the Data Protection

More information

General Data Protection Regulation (GDPR) The impact of doing business in Asia

General Data Protection Regulation (GDPR) The impact of doing business in Asia SESSION ID: GPS-R09 General Data Protection Regulation (GDPR) The impact of doing business in Asia Ilias Chantzos Senior Director EMEA & APJ Government Affairs Symantec Corporation @ichantzos Typical Customer

More information

INCLUDE-ED PRIVACY POLICY

INCLUDE-ED PRIVACY POLICY INCLUDE-ED PRIVACY POLICY BACKGROUND: Include-ed Limited understands that your privacy is important to you and that you care about how your personal data is used and shared. We respect and value the privacy

More information

Our Data Protection Officer is Andrew Garrett, Operations Manager

Our Data Protection Officer is Andrew Garrett, Operations Manager Construction Youth Trust Privacy Notice We are committed to protecting your personal information Construction Youth Trust is committed to respecting and keeping safe any personal information you share

More information

Badminton England - Data protection Guidance for clubs and counties.

Badminton England - Data protection Guidance for clubs and counties. Badminton England - Data protection Guidance for clubs and counties. This leaflet is intended to provide general guidance for clubs and counties with respect to data protection. It does not however capture

More information

Privacy Policy. England Athletics Limited commitment to Privacy. Introduction. The information we collect about you. The information provided to us

Privacy Policy. England Athletics Limited commitment to Privacy. Introduction. The information we collect about you. The information provided to us Privacy Policy England Athletics Limited commitment to Privacy Introduction The information we collect about you The information provided to us How we use your information Our legal bases for processing

More information

Want to change the communications you get from us?

Want to change the communications you get from us? What is a privacy and cookie policy? At St Anne s Community Services, we are committed to keeping the trust and confidence of everyone who is in contact with us. It is important that you know we record

More information

Europe s General Data Protection Regulation (GDPR) and Your Marketing Efforts

Europe s General Data Protection Regulation (GDPR) and Your Marketing Efforts Europe s General Data Protection Regulation (GDPR) and Your Marketing Efforts Europe s General Data Protection Regulation (GDPR) and Your Marketing Efforts On May 25, 2018 a new set of rules regarding

More information

Promise Dreams Privacy Policy

Promise Dreams Privacy Policy Promise Dreams Privacy Policy Introduction Promise Dreams ( we ) promises to respect any personal data you share with us and keep it safe. We aim to be clear when we collect your data and not do anything

More information

UWC International Data Protection Policy

UWC International Data Protection Policy UWC International Data Protection Policy 1. Introduction This policy sets out UWC International s organisational approach to data protection. UWC International is committed to protecting the privacy of

More information

2. The Information we collect and how we use it: Individuals and Organisations: We collect and process personal data from individuals and organisation

2. The Information we collect and how we use it: Individuals and Organisations: We collect and process personal data from individuals and organisation WOSDEC: Privacy Policy West of Scotland Development Education Centre WOSDEC - (We) are committed to protecting and respecting your privacy. This policy sets out how the personal information we collect

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2 COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September 2018 Table of Contents 1. Scope, Purpose and Application to Employees 2 2. Reference Documents 2 3. Definitions 3 4. Data Protection Principles

More information

Privacy Policy. (GDPR compliance)

Privacy Policy. (GDPR compliance) Privacy Policy (GDPR compliance) Summary This privacy policy sets out the data processing practices carried out by MSE Meeting Rooms. We process personal information through the use of the telephone, a

More information

DLB Privacy Policy. Why we require your information

DLB Privacy Policy. Why we require your information At Etive Technologies Limited (Etive) which operates Digital Log Book, (DLB). We are committed to protecting the privacy of our customers and the responsible management of personal information in accordance

More information

GRAHAM JONES - PRIVACY POLICY

GRAHAM JONES - PRIVACY POLICY GRAHAM JONES - PRIVACY POLICY BACKGROUND: Graham Jones understands that your privacy is important to you and that you care about how your personal data is used. I respect and value the privacy of all of

More information

Made In Hackney Data Protection Policy Last Updated:

Made In Hackney Data Protection Policy Last Updated: Made In Hackney Data Protection Policy Last Updated: 16.05.2018 Definitions Charity GDPR Responsible Person Register of Systems Made In Hackney (MIH), a registered charity. means the General Data Protection

More information

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018 ma recycle.com Rely and Comply... GDPR Privacy Policy Policy Date: 24 May 2018 Max Recycle Hawthorne House Blackthorn Way Sedgeletch Industrial Estate Fencehouses Tyne & Wear DH4 6JN T: 0845 026 0026 F:

More information

GDPR AND WHAT IT MEANS FOR CRM AND CUSTOMER ENGAGEMENT MAY. A 7-step practical guide to achieving and maintaining GDPR compliance by 25 May 2018

GDPR AND WHAT IT MEANS FOR CRM AND CUSTOMER ENGAGEMENT MAY. A 7-step practical guide to achieving and maintaining GDPR compliance by 25 May 2018 GDPR AND WHAT IT MEANS FOR CRM AND CUSTOMER ENGAGEMENT MAY 25 2018 A 7-step practical guide to achieving and maintaining GDPR compliance by 25 May 2018 A 7-step practical guide to achieving and maintaining

More information

GDPR: A QUICK OVERVIEW

GDPR: A QUICK OVERVIEW GDPR: A QUICK OVERVIEW 2018 Get ready now. 29 June 2017 Presenters Charles Barley Director, Risk Advisory Services Charles Barley, Jr. is responsible for the delivery of governance, risk and compliance

More information

GDPR- the new General Data Protection Regulations. Staff PDM- 2 nd May 2018

GDPR- the new General Data Protection Regulations. Staff PDM- 2 nd May 2018 GDPR- the new General Data Protection Regulations Staff PDM- 2 nd May 2018 What, when, how... It will supersede the Data Protection Act 1998. It sets out new regulations about the sharing of personal data

More information

GDPR is coming in less than 2 months Are you ready?

GDPR is coming in less than 2 months Are you ready? GDPR is coming in less than 2 months Are you ready? Charles-Albert Helleputte Partner, Brussels +32 2 551 5982 chelleputte@mayerbrown.com 30 March 2018 2 GDPR is everywhere... You were invited by UNICEO

More information

Cellular Solutions and Services Limited and Cellular Solutions and Network Services Privacy Policy

Cellular Solutions and Services Limited and Cellular Solutions and Network Services Privacy Policy Cellular Solutions and Services Limited and Cellular Solutions and Network Services Privacy Policy This privacy policy sets out how Cellular Solutions and Services Limited and Cellular Solutions and Network

More information

General Data Protection Regulation (GDPR) - A CANDDi perspective

General Data Protection Regulation (GDPR) - A CANDDi perspective General Data Protection Regulation (GDPR) - A CANDDi perspective 1 - Summary With General Data Protection Regulation less than 12 months away there is a legal requirement for all businesses to have taken

More information

Privacy Notice. Any questions regarding this Policy and our privacy practices should be sent by to our team leader

Privacy Notice. Any questions regarding this Policy and our privacy practices should be sent by  to our team leader Privacy Notice BeSpace, is a charity committed to facilitating prayer and reflective spaces in the community. We work with local churches and volunteers to deliver our charitable objectives. We are registered

More information

Data Protection Policy

Data Protection Policy The Worshipful Company of Framework Knitters Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act 1998 (DPA) [UK] For information on this

More information

Privacy Policy. Full name and contact details (including your contact number, and postal address).

Privacy Policy. Full name and contact details (including your contact number,  and postal address). 01326 270212 sales@htiddy.co.uk www.htiddy.co.uk Privacy Policy This privacy notice sets out how we will process personal data we collect from or about you, or which you provide to us. Please read this

More information

DATA PROTECTION POLICY THE HOLST GROUP

DATA PROTECTION POLICY THE HOLST GROUP DATA PROTECTION POLICY THE HOLST GROUP INTRODUCTION The purpose of this document is to provide a concise policy regarding the data protection obligations of The Holst Group. The Holst Group is a data controller

More information

Please let us know if you have any questions regarding this Policy either by to or by telephone

Please let us know if you have any questions regarding this Policy either by  to or by telephone Our Privacy Policy At Torbay Fishing we are committed to protecting and preserving the privacy of our customers when visiting us, visiting our website or communicating (electronically or verbally) with

More information

ATHLETICS WORLD CUP PRIVACY NOTICE

ATHLETICS WORLD CUP PRIVACY NOTICE ATHLETICS WORLD CUP PRIVACY NOTICE This Privacy Notice explains how Athletics World Cup ("AWC") collects, uses and shares the personal information that you provide to us either when using this website

More information

Kohelet Policy Forum R.A. Site Legal Terms. What personal data we collect and why we collect it. Comments. Media. Contact forms and newsletter

Kohelet Policy Forum R.A. Site Legal Terms. What personal data we collect and why we collect it. Comments. Media. Contact forms and newsletter Kohelet Policy Forum R.A. Site Legal Terms Our address: 8 Am Ve'loamo Street Jerusalem office@kohelet.org.il www.kohelet.org.il What personal data we collect and why we collect it We collect anonymous

More information

DCCVITAL GDPR Privacy Statement. This privacy statement sets out

DCCVITAL GDPR Privacy Statement. This privacy statement sets out DCCVITAL GDPR Privacy Statement This privacy statement sets out what information DCCVITAL collects from you and why; how DCCVITAL uses and protects any information that you give; and how you can access

More information

A practical guide to IT security

A practical guide to IT security Data protection A practical guide to IT security Ideal for the small business The Data Protection Act states that appropriate technical and organisational measures shall be taken against unauthorised or

More information

Data protection. 3 April 2018

Data protection. 3 April 2018 Data protection 3 April 2018 Policy prepared by: Ltd Approved by the Directors on: 3rd April 2018 Next review date: 31st March 2019 Data Protection Registration Number (ico.): Z2184271 Introduction Ltd

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) Michael Eva, London Grid for Learning What is GDPR? General Data Protection Regulation (GDPR) protects the personal data of EU citizens regardless of where the

More information

A1 Complete Plumbing and Heating Limited Job Applicant Privacy Notice

A1 Complete Plumbing and Heating Limited Job Applicant Privacy Notice A1 Complete Plumbing and Heating Limited Job Applicant Privacy Notice A1 Complete Plumbing and Heating Limited ( A1 ), Company Number 06272295 whose registered office is 1 Horsefair Mews, Romsey, England,

More information

South Hams Motor Club Our Privacy Policy. How do we collect information from you? What type of information is collected from you?

South Hams Motor Club Our Privacy Policy. How do we collect information from you? What type of information is collected from you? South Hams Motor Club Our Privacy Policy At South Hams Motor Club (SHMC) we are committed to protecting and preserving the privacy of our customers when attending our events, visiting our website or communicating

More information

Google Cloud & the General Data Protection Regulation (GDPR)

Google Cloud & the General Data Protection Regulation (GDPR) Google Cloud & the General Data Protection Regulation (GDPR) INTRODUCTION General Data Protection Regulation (GDPR) On 25 May 2018, the most significant piece of European data protection legislation to

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Data Protection Policy Version 3.00 May 2018 For more information, please contact: Technical Team T: 01903 228100 / 01903 550242 E: info@24x.com Page 1 The Data Protection Law...

More information

Adelaide Fringe is committed to protecting the privacy of its artists, employees, prospective employees, venues and the general public.

Adelaide Fringe is committed to protecting the privacy of its artists, employees, prospective employees, venues and the general public. Adelaide Fringe Privacy Statement Revised 16 July 2018 Our Commitment Adelaide Fringe is committed to protecting the privacy of its artists, employees, prospective employees, venues and the general public.

More information

To help customers achieve GDPR compliance, Freshchat has introduced the following new features:

To help customers achieve GDPR compliance, Freshchat has introduced the following new features: GDPR FAQ Here are some frequently asked questions from Freshchat customers. To save customer time and effort, we ve collated information and instructions on how Freshchat tackles requirements of the GDPR.

More information

Site Builder Privacy and Data Protection Policy

Site Builder Privacy and Data Protection Policy Site Builder Privacy and Data Protection Policy This policy applies to the work of the Third Age Trust s Site Builder Team. The policy sets out the approach of the Team in managing personal information

More information

Just-Property Ltd GDPR Client Data Register

Just-Property Ltd GDPR Client Data Register GDPR Client Data Register Company Name Contact Justin Coughlan Role Managing Director Email jcoughlan@just-property.ie Contact number 01 631 52 51 1. Point of Contact with responsibility for Data Protection

More information

Privacy and Cookies Policy

Privacy and Cookies Policy Sohn Foundation London Privacy and Cookies Policy The Sohn Foundation London (company number: 08075575, charity number: 1148454) is a wholly owned subsidiary of The Ira Sohn Conference Foundation, Inc.

More information

A practical guide to using ScheduleOnce in a GDPR compliant manner

A practical guide to using ScheduleOnce in a GDPR compliant manner A practical guide to using ScheduleOnce in a GDPR compliant manner Table of Contents Glossary 2 Background What does the GDPR mean for ScheduleOnce users? Lawful basis for processing Inbound scheduling

More information

MAID2CLEAN (FRANCHISE) LIMITED

MAID2CLEAN (FRANCHISE) LIMITED Privacy Notice - www.maid2clean.co.uk website 1. About this notice This policy notice describes how we collect and process personal data when an individual ( data subject ) uses our website www.maid2clean.co.uk,

More information

Order of Malta Volunteers Privacy Statement

Order of Malta Volunteers Privacy Statement Order of Malta Volunteers Privacy Statement The Order of Malta Volunteers ( the OMV, We, Us ), is a charity registered in England and Wales with charity number 1164242. Its registered address is 13 Deodar

More information

Forms. GDPR for Zoho Forms

Forms. GDPR for Zoho Forms GDPR for Zoho Forms The What The General Data Protection Regulation (GDPR) is a regulation that empowers the residents of the European Union (EU) with better transparency, access and control of their personal

More information

Blue Alligator Company Privacy Notice (Last updated 21 May 2018)

Blue Alligator Company Privacy Notice (Last updated 21 May 2018) Blue Alligator Company Privacy Notice (Last updated 21 May 2018) Who are we? Blue Alligator Company Limited (hereafter referred to as BAC ) is a company incorporated in England with company registration

More information

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke Prepared by: M Franklin Issued: May 2018 Pathways Community Interest Company Review due: May 2020 Pathways CIC Privacy Policy Version 0.3 Approved by: Yvonne Clarke Approval date: 21.05.2018 Pathways CIC

More information

IEEE GDPR Implementation & NTC

IEEE GDPR Implementation & NTC IEEE GDPR Implementation & NTC Ed Perkins, Oregon Section & R6 NWA Chair Based on GDPR presentation at IEEE Conferences Committee 15 February 2018 by: Kevin Dresely, Business Planning and Analysis Director

More information

Privacy Policy May 2018

Privacy Policy May 2018 Privacy Policy May 2018 Laser Surveys Ltd T/A Open Space Rooms Laser Surveys operates a privacy first approach to all our business activities and will only require the minimum information to perform our

More information

Pulsar Instruments Plc Privacy Policy

Pulsar Instruments Plc Privacy Policy 1 Pulsar Instruments Plc Privacy Policy Keeping your personal information safe and secure is our priority. The following text sets out how Pulsar Instruments Plc collects, uses, shares and protects information

More information

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH PRIVACY NOTICE Curv360 is a part of the Project Better Energy Limited group of companies and is a controller of any personal data you provide. We respect your data and your privacy is important to us.

More information

UCSU Student and Applicant Data Privacy Statement

UCSU Student and Applicant Data Privacy Statement UCSU Student and Applicant Data Privacy Statement Version number: 1.0 Policy Owner: Data Protection Officer Last Revised: May 2018 Review Date: July 2018 This document is to be reviewed biannually (January

More information

When you provide personal information to us it will only be used in the ways described in this privacy policy.

When you provide personal information to us it will only be used in the ways described in this privacy policy. Website Privacy Policy Overview Welcome to this Global Payroll Management Institute website, owned and produced by the Global Payroll Management Institute, Inc. (GPMI). Our website is available to all

More information

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready? European Union (EU) General Data Protection Regulation (GDPR) Do you handle EU residents personal data? The GDPR update is coming May 25, 2018. Are you ready? What do you need to do? Governance and Accountability

More information

Ackworth Howard Church of England (VC) Junior and Infant School. Child-friendly GDPR privacy notice

Ackworth Howard Church of England (VC) Junior and Infant School. Child-friendly GDPR privacy notice Child-friendly GDPR privacy notice Child-friendly GDPR privacy notice What s this about? A new law has been made that keeps your information safe things like your address, date of birth and phone number.

More information

About Mark Bullock & Company Chartered Surveyors

About Mark Bullock & Company Chartered Surveyors Privacy Policy Updated 28th November, 2018 By continuing to use this site you a) agree to us providing to you the information you have requested and b) confirm that you have read and agree to the use of

More information

PRIVACY NOTICE. This policy may be updated from time to time so please check back occasionally to make sure you re happy with any changes.

PRIVACY NOTICE. This policy may be updated from time to time so please check back occasionally to make sure you re happy with any changes. PRIVACY NOTICE This policy aims to explain fully and clearly what personal data I collect from you, what happens to that data, and what your rights are in relation to your personal data. If I can clarify

More information

What is this Privacy Policy for? The Website. Use of Cookies

What is this Privacy Policy for? The Website. Use of Cookies What is this Privacy Policy for? This privacy policy is for this website [http://ndfatraining.co.uk] and served by NDFA and governs the privacy of its users who choose to use it. The policy sets out the

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) BCD Travel s Response to the EU General Data Protection Regulation (GDPR) November 2017 Page 1 Response to the EU GDPR Copyright 2017 by BCD Travel N.V. All rights reserved. November 2017 Copyright 2017

More information

center Guide to GDPR

center Guide to GDPR Guide Emailcenter Guide to GDPR For Marketers Contents Introduction...3 What Is GDPR & Why Is This Happening?...4 What Is Going To Change?...5 How You Obtain Email Addresses...6 How You Store Personal

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1 Your Data Protection Responsibilities DATA PROTECTION POLICY 1.1 Everyone has rights with regard to how their personal data is handled. Personal data is any information that a person can be identified

More information

BISHOP GROSSETESTE UNIVERSITY. Document Administration. This policy applies to staff, students, and relevant data subjects

BISHOP GROSSETESTE UNIVERSITY. Document Administration. This policy applies to staff, students, and relevant data subjects BISHOP GROSSETESTE UNIVERSITY Document Administration Document Title: Document Category: Privacy Policy Policy Version Number: 1.0 Status: Reason for development: Scope: Author / developer: Owner Approved

More information

Privacy Policy. What type of personal information we collect. The type and amount of information we collect depends on why you are providing it.

Privacy Policy. What type of personal information we collect. The type and amount of information we collect depends on why you are providing it. Privacy Policy International Schools Partnership Limited ( ISP ) is committed to protecting and respecting your privacy. For the purposes of the General Data Protection Regulations (GDPR) and any subsequent

More information

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ). PRIVACY POLICY Data Protection Policy 1. Introduction This Data Protection Policy (this Policy ) sets out how Brital Foods Limited ( we, us, our ) handle the Personal Data we Process in the course of our

More information

2. Who we collect information (data) from & why we collect it

2. Who we collect information (data) from & why we collect it 1. Introduction Our Privacy Policy applies to the personal data that Ambrey collects and uses. References in this Privacy Policy to Ambrey, we, us or our mean Ambrey Limited and the Ambrey Group of companies:

More information

PORTICO PRIVACY NOTICE

PORTICO PRIVACY NOTICE PORTICO PRIVACY NOTICE Portico is committed to protecting and respecting your privacy. We take your privacy very seriously and we ask that you read this Privacy Notice carefully as it contains important

More information

About Us. Privacy Policy v1.3 Released 11/08/2017

About Us. Privacy Policy v1.3 Released 11/08/2017 Privacy Policy v1.3 Released 11/08/2017 About Us THIS PRIVACY POLICY, OUR VIEWER TERMS (hellopupil.com/viewerterms) AND HEALTH & SAFETY GUIDANCE (hellopupil.com/advice) COLLECTIVELY FORM THE TERMS GOVERNING

More information

Our privacy statement Who are we? Your acceptance of this statement Changes to this privacy statement What is personal data?

Our privacy statement Who are we? Your acceptance of this statement Changes to this privacy statement What is personal data? Privacy Statement Greater Manchester Centre for Voluntary Organisation (GMCVO), its subsidiaries, programmes and projects take your data rights very seriously and as such this privacy statement details

More information

BELLISSIMA BEAUTY SALON PRIVACY NOTICE

BELLISSIMA BEAUTY SALON PRIVACY NOTICE BELLISSIMA BEAUTY SALON PRIVACY NOTICE Bellissima Beauty Salon( Bellissima, we or us ) are committed to protecting your privacy, including online, and in the transparent use of any information you give

More information

GDPR. + Sales & Marketing A Practical Guide

GDPR. + Sales & Marketing A Practical Guide GDPR + Sales & Marketing A Practical Guide General Data Protection Regulation (GDPR) comes into effect on the 25th of May, 2018. Your company should already be a long way down the line with its preparation.

More information

SCHOOL SUPPLIERS. What schools should be asking!

SCHOOL SUPPLIERS. What schools should be asking! SCHOOL SUPPLIERS What schools should be asking! Page:1 School supplier compliance The General Data Protection Regulation (GDPR) comes into force on 25 May 2018 and will be applied into UK law via the updated

More information

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

Plan a Pragmatic Approach to the new EU Data Privacy Regulation AmChamDenmark event: EU Compliant & Cyber Resistant Plan a Pragmatic Approach to the new EU Data Privacy Regulation Janus Friis Bindslev, Partner Cyber Risk Services, Deloitte 4 February 2016 Agenda General

More information

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to Suzanne Dibble 2018. Copyright in this document belongs to Suzanne Dibble. You may not copy or use it for any purpose unless you have purchased this template document from Suzanne Dibble. You may not allow

More information