
DATA PROTECTION POLICY, RULES AND PROCEDURES
NGB Consulting EOOD
DATA PROTECTION POLICY AND PROCEDURES
NGB Consulting EOOD is a company engaged in commercial activity.
Context and overview
Key details
- Policy prepared by: Milena Dzhoneva
- Approved by management on: 04.2018
- Policy became operational on: 04.2018
- Next review date: 04.2019
Introduction
NGB Consulting EOOD, a company engaged in commercial activity, collects and uses certain information about individuals in the course of carrying out its business activity.
These may include: pupils, students, teachers, clients, suppliers, counterparties, employees and other people with whom the organization has a relationship or may need to contact.
This policy describes how this personal data must be collected, handled and stored in order to meet the company's data protection standards and to comply with the law.
Why does this policy exist?
This data protection policy ensures that NGB Consulting:
- complies with data protection law and follows good practice;
- protects the rights of staff, clients and partners;
- knows how to store and process individuals' data;
- protects itself from the risks of data misuse.
Data protection law
The Personal Data Protection Act of 1988 describes how organizations, including NGB Consulting EOOD, must collect, handle and store personal data.
These rules apply regardless of whether the data is stored electronically, on paper or on other media.
To comply with the law, personal data must be collected and used fairly, stored safely and not disclosed where the law prohibits this.
The Personal Data Protection Act is underpinned by eight important principles. According to them, personal data must:
- be processed fairly and lawfully;
- be obtained only for specific, lawful purposes:
- be adequate and relevant and not excessive;
- be accurate and kept up to date;
- not be kept for longer than necessary;
- be processed in accordance with the rights of data subjects;
- be protected in appropriate ways;
- not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection.
People, risks and responsibilities
Policy scope
These rules apply to:
- The head office and all future branches of NGB Consulting EOOD;
- the places where remote workers are permanently based;
- all employees, interns and volunteers of NGB Consulting;
- all contractors, suppliers and other persons working on behalf of NGB Consulting.
They also apply to all data that the company holds relating to identifiable individuals, even if that data technically falls outside the Personal Data Protection Act of 1998. This may include:
- names of individuals;
- postal addresses;
- email addresses;
- telephone numbers;
- and any other information relating to individuals and/or their activities.
Data protection risks
This policy helps to protect NGB Consulting EOOD from some very real data security risks, including:
Breaches of confidentiality. For instance, information being given out inappropriately.
Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
Reputational damage. For instance, the company's reputation could suffer if hackers successfully gained access to sensitive data.
Responsibilities
Everyone who works for or with NGB Consulting must ensure that data is collected, stored and handled appropriately in accordance with this policy and the data protection principles.
However, these people have key areas of responsibility:
The company's managing director, Milena Dzhoneva, must ensure that NGB Consulting meets its legal obligations.
The data protection officer, Milena Dzhoneva:
- regularly provides the director and the company's management team with information on data protection responsibilities, risks and issues;
- reviews all data protection procedures and related policies in line with an agreed schedule;
- arranges data protection training and advice for the people covered by this policy;
- handles data protection questions from staff and other persons covered by this policy;
- deals with requests from individuals to see the data NGB Consulting holds about them (also called "subject access requests");
- checks and approves contracts or agreements with third parties that may handle the company's sensitive data.
- ensures that all systems, services and equipment used for storing data meet recognized security standards;
- performs regular checks and scans to ensure that security hardware and software are functioning properly;
- evaluates third-party services the company is considering using to store or process data. For instance, cloud computing services.
- approves all data protection statements attached to communications such as emails and letters;
- where necessary, works with other staff to ensure that marketing initiatives comply with data protection principles.
General staff guidelines
- The only people able to access the data covered by this policy are those who need it for their work.
- Data must not be shared informally. When access to confidential information is required, a request for access is made to Milena Dzhoneva.
- NGB Consulting EOOD provides training to all employees to help them understand their responsibilities when handling data.
- Employees must keep all data secure by taking sensible precautions and following the guidelines below.
- In particular, strong passwords must be used and they must never be shared.
- Personal data must not be disclosed to unauthorized persons, either within the company or externally.
- Data must be regularly reviewed and updated if it is found to be out of date. If no longer required, it must be deleted and disposed of.
- Employees should request help from their line manager or the data protection officer if they are unsure about any aspect of data protection.
Data storage
These rules describe how and where data must be safely stored. Questions about storing data safely can be directed to the data controller.
When data is stored on paper, it must be kept in a secure place where unauthorized persons cannot access it.
These guidelines also apply to data that is usually stored electronically but has been printed out for some reason:
- When not required, the paper or files must be kept in a locked drawer or filing cabinet;
- Employees must make sure that paper and printouts are not left where unauthorized persons could access them, for example on a printer;
- Data printouts must be shredded and disposed of when no longer required.
When data is stored electronically, it must be protected from unauthorized access, accidental deletion and malicious hacking attempts:
- Data must be protected by strong passwords that are changed regularly and never shared between employees;
- If data is stored on removable media, these must be kept locked away securely when not in use;
- Data must be stored only on designated drives and servers and must be uploaded only to approved cloud computing services ("cloud services").
- Data must be backed up frequently. These backups must be tested regularly, in line with the company's standard backup procedures;
- Data must never be saved directly to laptops or other mobile devices such as tablets or smartphones;
- All servers and computers containing data must be protected by approved security software and a firewall.
Data use and processes
NGB Consulting must ensure that individuals are aware that their data is being processed and that they understand:
- how the data is being used;
- how to exercise their rights.
Personal data is of no value to NGB Consulting except in connection with carrying out the company's commercial activity. However, it is when personal data is accessed and worked with that it can be at the greatest risk of loss, corruption or theft:
- When working with personal data, employees must ensure that the screens of their computers are always locked when left unattended;
- Personal data must not be shared informally. In particular, it must never be sent by email, as this form of communication is not secure;
- Data must be encrypted before being transferred electronically;
- Personal data must never be transferred outside the European Economic Area;
- Employees must not save copies of personal data to their own computers; always access and update the central copy of any data.
The type and amount of personal data processed depends on the reason why NGB Consulting processes it (the legal basis used) and what it wishes to do with it. We comply with several key rules, including:
- Personal data must be processed lawfully and transparently, ensuring fairness towards the individuals whose personal data we process ("lawfulness, fairness and transparency").
- We must have specific purposes for processing the data and must indicate those purposes to individuals when collecting their personal data. We do not collect personal data for undefined purposes ("purpose limitation").
- We collect and process only the personal data that is necessary to achieve the specific purpose ("data minimization").
- We ensure that personal data is accurate and up to date, taking into account the purposes for which it is processed, and we correct it if it is not up to date ("accuracy").
- We do not further use personal data for other purposes that are incompatible with the original purpose of collection.
- We ensure that personal data is stored only for the period necessary to achieve the purposes for which it was collected ("storage limitation").
- We have taken appropriate technical and organizational measures that ensure the security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technology ("integrity and confidentiality").
Data accuracy
The law requires NGB Consulting to take reasonable steps to ensure that data is kept accurate and up to date.
All employees who work with data must take reasonable steps to ensure that it is kept as accurate and up to date as possible.
- Data is stored in as few places as necessary. Staff must not create unnecessary additional data sets.
- Staff must take every opportunity to ensure that data is updated. For instance, by confirming a client's details when they call.
- NGB Consulting will make it easy for data subjects to update the information the company holds about them. For instance, via the company website.
- Data must be updated when inaccuracies are discovered. For instance, if a client can no longer be reached on the telephone number they provided, this information must be removed from the database.
- The managing director must ensure that marketing databases are checked against unsubscribe lists every 6 months to make sure that those who have unsubscribed remain removed
Subject access requests
Right of access: Individuals have the right to request – and will receive a response from NGB Consulting.
All individuals whose personal data is held by NGB Consulting are entitled to:
- ask what information the company holds about them and why;
- ask how to gain access to it;
- be informed how to keep it up to date;
- be informed how the company is meeting its data protection obligations.
If an individual contacts the company requesting this information, this is called a subject access request.
Subject access requests must be sent by email, addressed to the data controller at info@ngbconsult.com. The data controller can supply a standard request form, although individuals do not have to use it.
Individuals will not be charged for subject access requests. The data controller makes every effort to provide the relevant data within 14 days.
The data controller always verifies the identity of anyone making a subject access request before handing over any information.
Disclosing data for other reasons
In certain circumstances, the Personal Data Protection Act allows personal data to be disclosed to law enforcement agencies without the consent of the data subject.
Under these circumstances, NGB Consulting will disclose the requested data. However, the data controller ensures that the request is legitimate, seeking assistance from the board and from the company's legal advisers where necessary.
Compliance with the General Data Protection Regulation
The General Data Protection Regulation gives EU citizens more rights and protection over their personal data. These include:
- Right to be informed: NGB Consulting must provide certain information, such as a privacy notice, and emphasize transparency regarding the way companies use personal data.
- Right of access: Individuals have the right to request – and receive a response – as to whether an organization is processing their data. This information must be provided largely free of charge within one month of the date of the request.
- Right to rectification: If an individual's data is incorrect or incomplete, they have the right to have it corrected.
- Right "to be forgotten": An individual has the right to request the erasure of their personal data in specific circumstances.
- Right to restrict processing: In certain circumstances, an individual may block the processing of their personal data.
- Right to data portability: An individual can obtain their data for their own use whenever they wish.
- Right to object: An individual can object to the use of their personal data for most purposes.
For this purpose, the company has prepared a privacy statement setting out how individuals' data is used. It is available on the company's website – HERE.
