Data Protection Policy
1. Introduction
This Data Protection Policy outlines our commitment to safeguarding personal data and ensuring compliance with relevant data protection laws. It applies to all employees, contractors, and third parties who handle personal data on behalf of our organisation.
2. Scope
This policy covers all personal data processed by our organisation, regardless of the format (electronic, paper, etc.) or location (on-premises, cloud, etc.).
3. Data Protection Principles
Our organization adheres to the following data protection principles:
a: Lawfulness, Fairness, and Transparency
- We process personal data lawfully, fairly, and transparently.
- Individuals are informed about the purpose and legal basis for data processing.
b: Purpose Limitation
- Personal data is collected for specific, explicit purposes.
- Data is not used for purposes incompatible with the original intent.
c: Data Minimisation
- We collect only necessary and relevant personal data.
- Unnecessary data is not retained.
d: Accuracy
- We maintain accurate and up-to-date personal data.
- Individuals have the right to correct inaccurate information.
e: Storage Limitation
- Personal data is retained only for as long as necessary.
- Retention periods are defined based on legal requirements and business needs.
f: Security
- We implement appropriate technical and organisational measures to protect personal data.
- Access controls, encryption, and regular security assessments are part of our security practices.
4. Sensitive Information
- Special categories of personal data (e.g., health, ethnicity, religion) receive additional protection.
- Consent or legal grounds are required for processing sensitive data.
5. Rights of Individuals
Individuals have the following rights:
- Access: Individuals can request access to their personal data.
- Rectification: Individuals can correct inaccurate data.
- Erasure: Individuals can request deletion of their data (subject to legal exceptions).
- Restriction: Individuals can limit certain processing activities.
- Data Portability: Individuals can receive their data in a structured, commonly used format.
- Objection: Individuals can object to specific processing activities.
6. Automated Decision-Making and Profiling
- We provide transparency regarding automated decision-making processes.
- Individuals have the right to challenge decisions based solely on automated processing.
7. Accountability
- Our organisation is accountable for compliance with this policy.
- Regular reviews and audits ensure ongoing adherence to data protection requirements.
8. Training and Awareness
- Employees and contractors receive training on data protection.
- Awareness campaigns promote a culture of privacy.
9. Contact Information
For any data protection inquiries or to exercise your rights, please contact our Data Protection Officer (DPO) at accounts@eventproav.co.uk
