3 October 2021 — Pobl Tech
This policy outlines the Company’s commitment to protecting the personal data of its employees, customers, and third parties. It ensures compliance with relevant data protection legislation, including the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, as well as any subsequent amendments.
This policy applies to all employees, contractors, and any third parties who have access to or handle personal data on behalf of the Company.
Personal Data: Any information relating to an identifiable individual, including but not limited to name, address, contact details, or employment history.
Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or destruction.
Data Subject: The individual whose personal data is processed.
In accordance with data protection legislation, personal data must be:
-Processed lawfully, fairly, and in a transparent manner.
-Collected for specified, legitimate purposes and not further processed in a manner incompatible with those purposes.
-Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
-Accurate and kept up-to-date.
-Retained only for as long as necessary for the purposes for which it was collected.
-Processed securely to prevent unauthorised or unlawful processing, loss, destruction, or damage.
All employees must familiarise themselves with and adhere to the Company’s data protection policies.
Employees must ensure that any personal data they process is handled in accordance with the principles outlined above.
Access to personal data should only be given to those who require it for legitimate business purposes.
Any breaches of data protection must be reported immediately to the Data Protection Officer (DPO).
Employees and other data subjects have the following rights regarding their personal data:
-The right to access their personal data.
-The right to rectification if their personal data is inaccurate or incomplete.
-The right to request the deletion of personal data when it is no longer necessary or if consent is withdrawn.
-The right to restrict processing under certain circumstances.
-The right to object to the processing of their personal data.
In the event of a data breach, the Company will promptly assess the situation and, if required, notify the relevant supervisory authority within 72 hours, as well as the individuals affected if there is a high risk to their rights and freedoms.
Any employee found to be in breach of this policy may be subject to disciplinary action, up to and including dismissal, depending on the severity of the breach.
This policy will be reviewed regularly to ensure it remains up-to-date with legal requirements and best practices.