|
data protection
Welcome Solutions is required to maintain certain personal data
about living individuals
for the purposes of satisfying operational and legal obligations.
Welcome Solutions
recognises the importance of the correct and lawful treatment of
personal data; it
maintains confidence in the organisation and provides for
successful operations.
The types of personal data that Welcome Solutions may require
includes information
about current, past and prospective employees; suppliers;
creditors; clients
and others with whom it communicates. This personal data, whether
it is held on
paper, on computer or other media, will be subject to the
appropriate legal
safeguards as specified in the Data Protection Act 1998.
Welcome Solutions fully endorses and adheres to the eight
principles of the Data
Protection Act. These principles specify the legal conditions
that must be satisfied in
relation to obtaining, handling, processing, transportation and
storage of personal
data. Employees and any others who obtain, handle, process,
transport and store
personal data for Welcome Solutions must adhere to these
principles.
Principles
The principles require that personal data shall:
1. Be processed fairly and lawfully and shall not be processed
unless certain
conditions are met;
2. Be obtained for a specified and lawful purpose and shall not
be processed
in any manner incompatible with that purpose;
3. Be adequate, relevant and not excessive for those purposes;
4. Be accurate and, where necessary, kept up to date;
5. Not be kept for longer than is necessary for that purpose;
6. Be processed in accordance with the data subject’s rights;
7. Be kept secure from unauthorised or unlawful processing and
protected
against accidental loss, destruction or damage
by using the appropriate
technical and organisational measures;
8. And not be transferred to a country or territory outside the
European
Economic Area, unless that country or
territory ensures an adequate level
of protection for the rights and freedoms of
data subjects in relation to the
processing of personal data.
Satisfaction of principles
In order to meet the requirements of the principles, Welcome
Solutions will:
•
observe fully the conditions regarding the fair collection and
use of personal
data;
•
meet its obligations to specify the purposes for which personal
data is used;
•
collect and process appropriate personal data only to the extent
that it is
needed to fulfill operational or any legal requirements;
•
ensure the quality of personal data used;
•
apply strict checks to determine the length of time personal data
is held;
•
ensure that the rights of individuals about whom the personal
data is held,
can be fully exercised under the Act;
•
take the appropriate technical and organisational security
measures to
safeguard personal data;
•
and ensure that personal data is not transferred abroad without
suitable
safeguards.
Welcome Solutions Designated Data Controller
Welcome Solutions Information Compliance Manager is responsible
for ensuring
compliance with the Data Protection Act and implementation of
this policy. The Information
Compliance Manager is Nigel Palmer,
Welcome Solutions, Welcome House, 20 Foxglove Drive , Chorley, PR6
7SG.
Any questions or concerns about the interpretation
or operation of this policy should be taken up in the first
instance with the Information
Compliance Manager.
Subject Access
All individuals who are the subject of personal data held by
Welcome Solutions are entitled
to:
•
Ask what information Welcome Solutions holds about them and why.
•
Ask how to gain access to it.
•
Be informed how to keep it up to date.
•
Be informed what Welcome Solutions is doing to comply with its
obligations under
the 1998 Data Protection Act.
Data Security
The need to ensure that data is kept securely means that
precautions must be taken
against physical loss or damage, and that both access and
disclosure must be
restricted. All staff are responsible for ensuring that:
•
Any personal data which they hold is kept securely
•
Personal information is not disclosed either orally or in writing
or
otherwise to any unauthorised third party.
Rights to Access Information
Employees and other subjects of personal data held by Welcome
Solutions have the
right to access any personal data that is being kept about them
on computer and also
have access to paper-based data held in certain manual filing
systems. This right is
subject to certain exemptions which are set out in the Data
Protection Act. Any
person who wishes to exercise this right should make the request
in writing to
Welcome Solutions Information Compliance Manager.
Welcome Solutions aims to comply with requests for access to
personal information as
quickly as possible, but will ensure that it is provided within
40 days of a request unless there
is good reason for delay. In such cases, the reason for
delay will be explained in writing to the
individual making the request.
Subject Consent
The need to process data for normal purposes has been
communicated to all data
subjects. In some cases, if the data is sensitive, for example
information about
health, race or gender, express consent to process the data must
be obtained.
Processing may be necessary to operate Welcome Solutions
policies, such as health and safety
and equal opportunities.
Retention of Data
Welcome Solutions will keep some forms of information for longer
than others. All staff are
responsible for ensuring that information is not kept for longer
than necessary.
|