Contents
- Status of this Policy
- Designated data Controller and Data Protection Officers
- Staff Responsibilities
- Data Security
- Disaster Recovery
- Subject Consent
- Subject Access
- Conclusion
- Appendix 1 - Equality Impact Analysis
- Appendix 2 - About this Document
Rosedene is fully committed to prepare for and, after 25 May 2018, to comply with the General Data Protection Regulation (GDPR). The GDPR applies to all organisations that process data relating to their employees, as well as to others including customers, contractors and clients. It sets out principles which should be followed by those who process data; it gives new and extended rights to those whose data is being processed.
To this end, Rosedene endorses fully and adheres to the six principles of data protection, as set out in the Article 5 of the GDPR.
These principles must be followed at all times when processing or using personal information. Therefore, through appropriate management and strict application of criteria and controls, Rosedene will:
The Policy does not form part of the formal contract of employment for staff but it is a condition of employment that staff will abide by the rules and policies made by Rosedene from time to time. Any failure to follow the Data Protection Policy may lead, therefore, to disciplinary proceedings. This Policy was approved on 01 April 2018. It will be reviewed no later than 01 April 2019.
The Designated Data Controllers and Data Protection Officers (DPO) are Doreen Orlebar and Cher Lewis will deal with day-to-day matters. Any member of staff, or other individual who considers that the policy has not been followed in respect of personal data about himself or herself should raise the matter with one of the above named persons.
All staff are responsible for:
All staff are responsible for ensuring that:
Staff should note that unauthorised disclosure will usually be a disciplinary matter, and may be considered gross misconduct in some cases. Personal information should be kept in a locked filing cabinet, drawer, or safe. If it is computerised, it should be coded, encrypted or password protected both on a local hard drive and on a network drive that is regularly backed up. If a copy is kept on removable storage media, that media must itself be kept in a locked filing cabinet, drawer, or safe.
The GDPR sets a high standard for consent and requires a positive opt-in. Neither pre-ticked boxes nor any other method of default consent are allowed. As required by the GDPR, Rosedene takes a "granular" approach ie it asks for separate consent for separate items and will not use vague or blanket requests for consent. As well as keeping evidence of any consent, Rosedene ensures that people can easily withdraw consent (and tells them how this can be done).
It should be noted, however, that consent is only one of the lawful bases on which data processing depends. In brief, the others include the following.
Note that the GDPR provides for special protection for children’s personal data and Rosedene will comply with the requirement to obtain parental or guardian consent for any data processing activity involving anyone under the age of 16.
An employee may request details of personal information which Rosedene holds about him or her under the GDPR. A small fee may be payable and will be based on the administrative cost of providing the information. If an employee would like a copy of the information held on him or her, they should write to Rosedene Nursing Home, 141-147 Trinity Road, Wandsworth Common, London SW17 7HJ. The requested information will be provided within one month. If there is any reason for delay, that will be communicated within the four week time period. A request which is manifestly unfounded or excessive may be refused. The person concerned will then be informed of their right to contest this decision with the supervisory authority (the ICO).
If an employee believes that any information held on him or her is incorrect or incomplete, then they should write to or email Doreen Orlebar or Cher Lewis as soon as possible, at the above address. Rosedene will promptly correct any information found to be incorrect.
This policy sets out this organisation’s commitment to protecting personal data and how that commitment is implemented in respect of the collection and use of personal data.
|
|
|
|
|
|
|