- Policy Statement
The objective of this Data Protection Policy is to define the legal data protection aspects in one summarising document. It can also be used as the basis for statutory data protection inspections, e.g., by the customer within the scope of commissioned processing. This is not only to ensure compliance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act. (DPA) 2018 but also to provide proof of compliance.
- Scope
This policy refers to all parties (employees, job candidates, customers, suppliers etc.) who provide any amount of information to Service Station Group Ltd.
Who is covered under the Data Protection Policy?
Employees of Service Station Group Ltd must follow this policy. Contractors, consultants, partners and any other external entity are also covered. Generally, this policy refers to anyone Service Station Group Ltd collaborates with or acts on Service Station Group Ltd’s behalf and may need occasional access to data.
- Policy elements
As part of Service Station Group Ltd’s operations, it is required to obtain and process information. This information includes any offline or online data that makes a person identifiable such as names, addresses, usernames and passwords, digital footprints, financial data, etc. Service Station Group Ltd collects this information in a transparent way and only with the full cooperation and knowledge of interested parties. Once this information is available, the following rules apply.
The data will be:
- Accurate and kept up-to-date.
- Collected fairly and for lawful purposes only.
- Processed by the company within its legal and moral boundaries.
- Protected against any unauthorized or illegal access by internal or external parties.
Our data will not be:
- Communicated informally.
- Stored for more than a specified amount of time.
- Transferred to organizations, states or countries that do not have adequate data protection policies.
- Distributed to any party other than the ones agreed upon by the data’s owner (exempting legitimate requests from law enforcement authorities).
In addition to ways of handling the data, Service Station Group Ltd has direct obligations towards people to whom the data belongs. Specifically, Service Station Group Ltd must:
- Let people know which of their data is collected.
- Inform people about how their data will be processed.
- Inform people about who has access to their information.
- Have provisions in cases of lost, corrupted or compromised data.
- Allow people to request that we modify, erase, reduce or correct data contained in our databases.
Actions
To exercise data protection Service Station Group Ltd is committed to:
- Restrict and monitor access to sensitive data.
- Develop transparent data collection procedures.
- Train employees in online privacy and security measures.
- Build secure networks to protect online data from
- Establish clear procedures for reporting privacy breaches or data misuse.
- Include contract clauses or communicate statements on how data is handled.
- Establish data protection practices (document shredding, secure locks, data encryption, frequent backups, access authorization, etc.).
4. Responsibilities
- The highest data protection goals are to be defined and documented and are based on data protection principles.
- Commitment to continuous improvement of a data protection management system.
- Training, sensitisation and obligation of the employees.
5. Documentation
- Conducted internal and external inspections.
- Data protection needs determination of protection needs with regard to confidentiality, integrity and availability.
6. Technical and organisational measures (TOM)
Technical-organisational measures (TOM) are measures described in the GDPR Regulations which are intended to ensure the protection of personal data.
Technical measures include any protection of data processing security that can be realized by physical measures or in software and hardware. Organizational measures include the implementation of instructions, policies and procedures for employees to ensure the security of the processing of personal data.
Appropriate technical and organisational measures must be implemented and substantiated, taking into account, among other things, the purpose of the processing, the state of the technology and the implementation costs.
- Disciplinary Consequences
All principles described in this policy must be strictly followed. A breach of data protection guidelines will invoke disciplinary and possibly legal action.