Presentation is loading. Please wait.

Presentation is loading. Please wait.

Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:

Similar presentations


Presentation on theme: "Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:"— Presentation transcript:

1 Session 11 Data protection

2 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4: Failure to comply and reporting breaches Part 5: Summary

3 2 Introduction Part 1

4 3 Purpose of the data protection policy Protect personal data Ensure staff understand the rules Ensure that relevant compliance steps are met

5 4 Definitions Business purposes—the purposes for which we may use personal data Personal data—information relating to identifiable individuals Sensitive personal data—personal data about an individual’s race/ethnicity, political opinions, religion, trade union membership, physical or mental health, criminal offences or related proceedings

6 5 Applicability and responsibility Part 2

7 6 Applicability and responsibility To whom does it apply? All staff Who is responsible for policy? the COLP

8 7 Our procedures on data protection Part 3

9 8 Our procedures Fair and lawful processing We must process personal data fairly and lawfully in accordance with individuals’ rights Sensitive personal data Require explicit consent to process sensitive personal data unless exceptional circumstances apply Accurate and relevant Ensure personal data processing is accurate, adequate, relevant, not excessive and appropriately processed Your personal data Ensure that your personal data we hold is accurate Data securityKeep personal data secure against loss or misuse

10 9 Our procedures (cont) Data retention Must not retain personal data for longer than is necessary Transferring data internationally There are restrictions on international transfers of personal data; please consult the COLP Subject access requests Individuals may ask for access to information we hold about them Processing data in accordance with an individual's rights Abide by any request from an individual not to use their personal data for direct marketing purposes

11 10 Failure to comply and reporting breaches Part 4

12 11 Failure to comply and reporting breaches Failure to comply: puts both you and the firm at risk may lead to disciplinary action possibly resulting in dismissal Report any actual or potential breach of policy

13 12 Summary Part 5

14 13 Summary Sensitive personal data must be treated especially carefully Data must be: o processed fairly and lawfully and in accordance with individuals’ rights o accurate and relevant o kept secure o retained for no longer than necessary

15 14 Summary (cont) Data must not be transferred internationally without consent We must: o respond to subject access requests o ensure our personal data is kept up to date Failure to comply may lead to disciplinary action— possibly dismissal Our Data protection policy applies to all staff

16 15 Final comments Any questions? Email to nigel.harper@parfittcresswell.comnigel.harper@parfittcresswell.com Update your training records in Compliance Manager


Download ppt "Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:"

Similar presentations


Ads by Google