INSPIRED ERGONOMICS LTD – DATA PROTECTION POLICY
1. INTRODUCTION
1.1 Background to the UK’s Data Protection Regime
The UK General Data Protection Regulation (UK GDPR) replaced the EU GDPR following the UK’s withdrawal from the European Union in 2020. Its purpose is to protect the “rights and freedoms” of natural persons (i.e. living individuals) and to ensure that organisations process their personal data in line with specific principles.
The Data Protection Act (2018) (DPA 2018) came into effect to supplement the EU GDPR in the UK’s legislative framework.
1.2 Definitions used by the organisation
Material scope (Article 2, UK GDPR) – the UK GDPR applies to the processing of personal data wholly or partly by automated means (i.e. by computer) and to the processing other than by automated means of personal data (i.e. paper records) that form part of a filing system or are intended to form part of a filing system.
Territorial scope (Article 3, UK GDPR and Section 207, DPA 2018) – the UK GDPR will apply to all controllers and processors in the UK who process the personal data of data subjects, in the context of that establishment. It will also apply to controllers and processors outside of the UK that process personal data in order to offer goods and services, or monitor the behaviour of data subjects in the UK.
1.3 Definitions
a. Personal data – any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
b. Special categories of personal data – personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation
c. Data controller – the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
d. Data subject – any living individual who is the subject of personal data held by an organisation.
e. Lawful Basis – One of six specific bases under which processing personal data can be processed lawfully, usually determined by the purpose(s) for processing. Without an established lawful basis, or being able to demonstrate one applies, then both the organisation and the processing are unlawful.
f. Biometric Data – personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person.
g. Health Data – personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
h. Processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
i. Profiling – is any form of automated processing of personal data intended to evaluate certain personal aspects relating to a natural person, or to analyse or make predictions about that person, such as their location, health, personal preferences, or behaviour. This definition is linked to the right of the data subject to object to profiling and a right to be informed about the existence of profiling, of measures based on profiling and the envisaged effects of profiling on the individual.
j. Personal data breach – a breach of security leading to the accidental, or unlawful, destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. There is an obligation on the controller to report personal data breaches to the supervisory authority and where the breach is likely to adversely affect the personal data or privacy of the data subject.
k. Data subject consent – means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data. Consent is one of the available lawful basis justifications for processing personal data.
l. Third party – a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
m. Filing system – any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
2. POLICY STATEMENT
2.1 The Board of Directors and management of Inspired Ergonomics, located at 8 Hermitage Street, Paddington, London, W2 1BE, UK are committed to compliance with all laws in respect of personal data, and the protection of the “rights and freedoms” of individuals whose information Inspired Ergonomics collects and processes in accordance with the UK GDPR and the DPA 2018.
2.2 Compliance with the UK GDPR/DPA 2018 is described by this policy and other relevant policies, along with connected processes and procedures.
2.3 The UK GDPR/DPA 2018 and this policy apply to all of Inspired Ergonomics’ personal data processing functions, including those performed on customers’, clients’, employees’, contractors’, suppliers’ and partners’ personal data, and any other personal data the organisation processes from any source.
2.4 Inspired Ergonomics has established objectives for data protection and privacy, which are contained within company policies and the record of processing activities.
2.5 Inspired Ergonomics have identified that the nature of its processing activities requires the appointment of a Data Protection Officer (Nichola Adams, CEO).
2.6 The Data Protection Officer is responsible for reviewing the record of processing activities annually in the light of any changes to Inspired Ergonomics’ activities (as determined by changes to the data mapping and periodic management operations and risk reviews for the company) and to any additional requirements identified by means of data protection impact assessments (DPIAs). This record of processing activities needs to be available on the Supervisory Authority’s (Information Commissioner’s Office (ICO)) request.
2.7 This policy applies to all Staff and interested parties of Inspired Ergonomics such as sub-contracted specialists and outsourced suppliers. Any breach of the UK GDPR/DPA 2018 or this policy will be dealt with accordingly and may also be a criminal offence, in which case the matter will be reported as soon as possible to the appropriate authorities.
2.8 Partners and any third parties working with or for Inspired Ergonomics, and who have or may have access to personal data, will be expected to have read, understood and to comply with this policy. No third party may access personal data held by Inspired Ergonomics without having first entered into a confidential data sharing agreement for this processing, which imposes on the third party obligations no less onerous than those to which Inspired Ergonomics is committed, and which gives Inspired Ergonomics the right to audit compliance with the agreement.
3. RESPONSIBILITIES AND ROLES
3.1 Inspired Ergonomics is a data controller for its internal staff, client relationship and contract data.
3.2 The Directors and all those in managerial or supervisory roles throughout Inspired Ergonomics are responsible for developing and encouraging good information handling practices within Inspired Ergonomics; responsibilities are set out in individual job descriptions.
3.3 The Data Protection Officer’s job description and responsibilities, a role specified in the UK GDPR, should be accountable to Board of Directors of Inspired Ergonomics for the management of personal data within Inspired Ergonomics, and be concerned with ensuring that compliance with data protection legislation and good practice can be demonstrated. This accountability includes:
3.3.1 development of policies and procedure implementation related to data protection compliance, as required by this policy; and
3.3.2 providing advice, guidance and oversight on security and risk management in relation to compliance with the policy
3.4 The Data Protection Officer, whom the Board of Directors considers to be suitably qualified and experienced, has been appointed to take responsibility for Inspired Ergonomics’ compliance with this policy on a day-to-day basis and, in particular, has direct responsibility for ensuring that Inspired Ergonomics complies with data protection legislation, as do the Directors in respect of data processing that takes place within their area of responsibility.
3.5 The Data Protection Officer has specific responsibilities and is the first point of call for Staff seeking clarification on any aspect of data protection compliance.
3.6 Compliance with data protection legislation is the personal responsibility of all Staff of Inspired Ergonomics who process personal data.
4. DATA PROTECTION PRINCIPLES
All processing of personal data must be conducted in accordance with the data protection principles as set out in Article 5 of the UK GDPR. Inspired Ergonomics’ policies and procedures are designed to ensure compliance with the principles
4.1 Personal data must be processed lawfully, fairly and transparently
Lawful – the data controller must ensure that the processing does not breach any other laws and must identify a lawful basis before it can process personal data.
Fair – in order for processing to be fair, the data controller must consider how the processing may impact the data subjects and be able to justify any adverse impacts, ideally through relevant data protection impact assessments (DPIAs). Data should be processed in ways that data subjects would reasonably expect.
The data controller has to make certain information available to the data subjects as practicable. This applies whether the personal data was obtained directly from the data subjects or from other sources.
The UK GDPR has increased requirements about what information should be available to data subjects, which is covered in the ‘Transparent’ requirement.
Transparent – the UK GDPR includes rules on giving privacy information to data subjects in Articles 12, 13 and 14. These are detailed and specific, placing an emphasis on making privacy notices appropriate to the target audience reading them and the processing that is carried out on their personal data, and these notices must be understandable and accessible. Information must be communicated to the data subject in an intelligible form using clear and plain language.
Inspired Ergonomics’ Privacy Notice is available online and for all clients and external parties.
The specific information that must be provided to the data subject must, as a minimum, include:
4.1.1 the identity and the contact details of the controller;
4.1.2 the contact details of the Data Protection Officer;
4.1.3 the purposes of the processing for which the personal data are intended as well as the lawful basis for the processing;
4.1.4 the period for which the personal data will be stored;
4.1.5 the existence of the rights to request access, rectification, erasure, restriction or to object to the processing, and the conditions (or lack of) relating to exercising these rights, such as whether the lawfulness of previous processing will be affected;
4.1.6 the categories of personal data concerned;
4.1.7 the recipients or categories of recipients of the personal data, where applicable;
4.1.8 where applicable, that the controller intends to transfer personal data to a recipient in a third country and the level of protection afforded to the data;
4.1.9 any further information necessary to guarantee fair processing.
4.2 Personal data can only be collected for specific, explicit and legitimate purposes
Data obtained for specified purposes must not be used for a purpose that differs from those formally notified to the supervisory authority as part of Inspired Ergonomics’ record of processing activities.
4.3 Personal data must be adequate, relevant and limited to what is necessary for processing
4.3.1 The Data Protection Officer is responsible for ensuring that Inspired Ergonomics does not collect personal data that is not strictly necessary for the purpose(s) for which it is obtained.
4.3.2 All data collection forms (electronic or paper-based), including data collection requirements in new information systems, must be include a fair processing statement or link to the Company’s Privacy Notice, and be approved by the Data Protection Officer.
4.3.3 The Data Protection Officer will ensure that, on an annual basis, all data collection methods are reviewed to ensure that collected data continues to be adequate, relevant and not excessive.
4.4 Personal data must be accurate and kept up-to-date with every effort to erase or rectify without delay
4.4.1 Data that is stored by the data controller must be reviewed and updated as necessary. No data should be kept unless it is reasonable to assume that it is accurate.
4.4.2 The Data Protection Officer is responsible for ensuring that all staff are trained in the importance of collecting accurate data and maintaining it.
4.4.3 It is also the responsibility of the data subject to ensure that data held by Inspired Ergonomics is accurate and up-to-date. Completion of a registration or application form by a data subject will include a statement that the data contained therein is accurate at the date of submission.
4.4.4 Staff and other relevant stakeholders should be required to notify Inspired Ergonomics of any changes in circumstance to enable personal records to be updated accordingly. Instructions for updating records are circulated as required by the Director. It is the responsibility of Inspired Ergonomics to ensure that any staff notification regarding change of circumstances is recorded and checked for accuracy before being acted upon. It is the responsibility of the client to ensure that any notification regarding change of circumstances is checked for accuracy before notifying Inspired Ergonomics, who are responsible for recording and acting upon such notification.
4.4.5 The Data Protection Officer is responsible for ensuring that appropriate procedures and policies are in place to keep personal data accurate and up-to-date, taking into account the volume of data collected, the speed with which it might change and any other relevant factors.
4.4.6 On at least an annual basis, the Data Protection Officer will arrange the review the retention dates of all the personal data processed by Inspired Ergonomics, by reference to the record of processing activities, and will identify any data that is no longer required in the context of the registered purpose. This data will be securely deleted/destroyed.
4.4.7 Any Inspired Ergonomics member of staff (including consultants) who receives a request from a data subject (written or verbal) must notify the Data Protection Officer. The Data Protection Officer is responsible for responding to requests (such as for rectification) from data subjects within one month. This can be extended to a further two months for complex requests. If Inspired Ergonomics decides not to comply with the request, the Data Protection Officer must respond to the data subject to explain its reasoning and inform them of their right to complain to the Supervisory Authority (ICO) and seek judicial remedy.
4.4.8 The Data Protection Officer is responsible for making appropriate arrangements that, where third party organisations may have been passed inaccurate or out-of-date personal data, to inform them that the information is inaccurate and/or out-of-date and is not to be used to inform decisions about the individuals concerned; and for passing any correction to the personal data to the third party where this is required.
4.5 Personal data must be kept in a form such that the data subject can be identified only as long as is necessary for processing
4.5.1 Personal data will be retained in line with the Privacy Notice and, once its retention date is passed, it must be securely destroyed
4.5.2 The Data Protection Officer must specifically approve (in writing) any data retention that exceeds the retention periods defined in the Privacy Notice and must ensure that the justification is clearly identified and in line with the requirements of the data protection legislation.
4.6 Personal data must be processed in a manner that ensures the appropriate security
Where appropriate or required by law, the Data Protection Officer will provide advice where requested on a risk assessment taking into account all the circumstances of Inspired Ergonomics’ controlling or processing operations.
In determining appropriateness, the Data Protection Officer should consider the extent of possible damage or loss that might be caused to individuals (e.g. staff or customers) if a security breach occurs, the effect of any security breach on Inspired Ergonomics itself, whether the company had implemented effective and appropriate technical and organisational measures, and any likely reputational damage including the possible loss of customer trust.
When assessing appropriate technical measures, Inspired Ergonomics will consider the following:
When assessing appropriate organisational measures, the Inspired Ergonomics will consider the following:
These controls have been selected on the basis of identified risks to personal data, and the potential for damage or distress to individuals whose data is being processed.
4.7 The Data Controller must be able to demonstrate compliance with the UK GDPR’s other principles (accountability)
The UK GDPR includes provisions that promote accountability and governance. These complement the UK GDPR’s transparency requirements. The accountability principle in Article 5(2) requires organisations that process personal data to demonstrate that they comply with the principles, and states explicitly that this is each organisation’s responsibility.
Inspired Ergonomics will demonstrate compliance with the data protection principles by implementing data protection policies, adhering to codes of conduct, implementing technical and organisational measures, and providing appropriate training to all staff afforded access to personal data in carrying out their roles, as well as adopting techniques such as data protection by design, DPIAs, breach notification procedures and incident response plans.
5. DATA SUBJECT RIGHTS
5.1 Data subjects have the following rights regarding data processing, and the data that is recorded about them:
5.1.1 To be informed about the collection and use of their personal data.
5.1.2 To request access to copies of their data, and to additional information regarding the nature of information held and to whom it has been disclosed.
5.1.3 To prevent processing likely to cause damage or distress.
5.1.4 To prevent processing for purposes of direct marketing.
5.1.5 To be informed about the mechanics of automated decision-taking process that will significantly affect them.
5.1.6 To not have significant decisions that will affect them taken solely by automated process.
5.1.7 To sue for compensation if they suffer damage by any contravention of the UK GDPR.
5.1.8 To request an organisation takes action to rectify, block, erased, including the right to be forgotten, or destroy inaccurate data.
5.1.9 To lodge a complaint with the supervisory authority.
5.1.10 To have personal data provided to them in a structured, commonly used and machine-readable format, and the right to have that data transmitted to another controller.
5.1.11 To object to any automated profiling that is occurring without consent.
5.1.12 To withdraw consent, where it has been sought and provided.
5.2 Inspired Ergonomics ensures that data subjects may exercise these rights:
5.2.1 Data subjects may make data access requests as described in Subject Access Request Procedure; this procedure also describes how Inspired Ergonomics will ensure that its response to the data access request complies with the requirements of the UK GDPR.
5.2.2 Data subjects have the right to complain to Inspired Ergonomics related to the processing of their personal data, the handling of a request from a data subject and appeals from a data subject on how complaints have been handled.
5.2.3 The lawful basis Inspired Ergonomics rely on to justify their data processing will have a direct impact on data subjects’ rights and how they may exercise them:
| Rights: | Consent | Contract | Legal obligation | Vital interests | Public task | Legitimate interest |
| Access | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Rectification | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Erasure | ✓ | ✓ | ✕ | ✓ | ✕ | ✓ |
| Restriction | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Data Portability | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Object | (can withdraw consent) | ✕ | ✕ | ✕ | ✓ | ✓ |
6.1 Inspired Ergonomics understands ‘consent’ to mean that it has been explicitly and freely given, and a specific, informed and unambiguous indication of the data subject’s wishes that, by statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them. The data subject can withdraw their consent at any time.
6.2 Inspired Ergonomics understands ‘consent’ to mean that the data subject has been fully informed of the intended processing and has signified their agreement, while in a fit state of mind to do so and without pressure being exerted upon them. Consent obtained under duress or on the basis of misleading information will not be a valid basis for processing.
6.3 There must be some active communication between the parties to demonstrate active consent. Consent cannot be inferred from non-response to a communication. The Controller must be able to demonstrate, through diligent record keeping, that consent was obtained for the processing operation.
6.4 Given the nature of the processing that is carried out by Inspired Ergonomics on behalf of their clients’ employees and on their own staff, it is expected that consent will not be a valid basis to rely upon – this is because the nature of the employment relationship and the imbalance of power negates the freely given and easily withdrawn criteria for consent to be valid under UK GDPR. Other lawful basis justifications are therefore outlined in the relevant Inspired Ergonomics privacy notices.
7. SECURITY OF DATA
7.1 All Staff (including consultants) are responsible for ensuring that any personal data that Inspired Ergonomics holds, and for which they are responsible, is kept securely and is not under any conditions disclosed to any third party unless that third party has been specifically authorised by Inspired Ergonomics to receive that information and has entered into a suitably robust legal or confidentiality agreement.
7.2 All personal data should be accessible only to those who need to use it. All personal data should be treated with the highest security and must be kept:
7.3 Care must be taken to ensure that PC screens and terminals are not visible except to authorised Employees/Staff of Inspired Ergonomics. This is especially relevant when working remotely. All Staff are required to follow company policy guidelines and receive appropriate training and guidance in this respect.
7.4 Manual records may not be left where they can be accessed by unauthorised personnel and may not be removed from business premises without explicit authorisation. As soon as manual records are no longer required for dayto-day client support, they must be removed and securely destroyed, shredded or collected by a certified secure disposal service in line with Company policy and procedure.
7.5 Personal data may only be deleted or disposed of in line with the Privacy Notice. Manual records that have reached their retention date are to be shredded and disposed of as ‘confidential waste’. Hard drives of redundant PCs are to be removed and destroyed or disposed of by an approved and certified secure disposal service provider.
7.6 Processing of personal data ‘off-site’ and in remote locations presents a potentially greater risk of loss, theft or damage to personal data. Staff who use company-owned devices must be specifically authorised to process data off-site. All staff (including consultants) shall carry out their work in line with remote and flexible working requirements and be trained in the appropriate data protection and cyber security requirements for remote working.
8. PERSONAL DATA BREACH
8.1 All staff (including consultants) are responsible for escalating a potential or actual personal data breach or any risk or concern with regards to handling of personal data to the Data Protection Officer without undue delay.
8.2 On receipt of such notification, the Data Protection Officer is responsible for carrying out an investigation, notifying the appropriate parties (where the breach affects client data subjects) and/or the Supervisory Authority in a timely manner.
8.3 All agreements with third parties must detail the parties’ responsibilities with regards to data breaches and notification. Where a breach is found to be caused fully or partly by another party, Inspired Ergonomics must ensure that the third party is notified without undue delay and understands that mutual co-operation is for the benefit of data subjects affected by the breach.
8.4 The Data Protection Officer should review the Data Breach Register in all instances.
9. DISCLOSURE OF DATA
9.1 Inspired Ergonomics must ensure that personal data is not disclosed accidentally or unlawfully to unauthorised third parties which includes family members, friends, government bodies, and in certain circumstances, the Police. All Staff should exercise caution when asked to disclose personal data held on another individual to a third party and will be required to attend specific training that enables them to deal effectively with any such risk. It is important to bear in mind whether or not disclosure of the information is relevant to, and necessary for, the conduct of Inspired Ergonomics’ business.
9.2 All requests to provide data for one of these reasons must be supported by appropriate paperwork and all such disclosures must be specifically authorised by the Data Protection Officer.
10. RETENTION AND DISPOSAL OF DATA
10.1 Inspired Ergonomics shall not keep personal data in a form that permits identification of data subjects for longer a period than is necessary, in relation to the purpose(s) for which the data was originally collected.
10.2 Inspired Ergonomics may store data for longer periods if the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the implementation of appropriate technical and organisational measures to safeguard the rights and freedoms of the data subject.
10.3 The retention period for each category of personal data will be set out in the Privacy Notice along with the criteria used to determine this period including any statutory obligations Inspired Ergonomics has to retain the data.
10.4 Personal data must be disposed of securely in accordance with the sixth principle of the UK GDPR – processed in an appropriate manner to maintain security, thereby protecting the “rights and freedoms” of data subjects. Any disposal of data will be performed in accordance with the company’s secure disposal policy and procedure.
11. DATA TRANSFERS
11.1 All exports of data from the UK to other jurisdictions poses risk to data subjects unless there is an appropriate “level of protection for the fundamental rights of the data subjects”.
The transfer of personal data outside of the UK is prohibited unless one or more of the specified safeguards, or exceptions, apply:
11.1.1 An adequacy decision
The UK can and does assess third countries, a territory and/or specific sectors within third countries to assess whether there is an appropriate level of protection for the rights and freedoms of natural persons. In these instances no authorisation is required.
Countries and territories that are considered adequate are:
A list of countries that currently satisfy the adequacy requirements of the Secretary of State are published on the UK government website.
A list of countries that currently satisfy the adequacy requirements of the Commission are published in the Official Journal of the European Union. https://commission.europa.eu/law/law–topic/data–protection/international–dimension–data–protection/adequacy–decisions_en
Assessment of adequacy by the data controller
In making an assessment of adequacy, the UK or EEA based exporting controller should take account of the following factors:
11.1.2 Binding corporate rules
Inspired Ergonomics may adopt approved binding corporate rules for the intra-company transfer of data outside the UK. This requires submission to the relevant supervisory authority for approval of the rules that Inspired Ergonomics is seeking to rely upon.
11.1.3 International Data Transfer Agreements (IDTA) or Addendums
Where intending to make a restricted transfer, Inspired Ergonomics will enter into an international data transfer agreement with the receiver of the data. The IDTA came into force on 21 March 2022.
Inspired Ergonomics will hold records of any EU standard contractual clauses (SCCs) entered into with receivers issued under the old Data Protection Directive but will change to the UK IDTA as an appropriate mechanism, where appropriate.
11.1.4 Exceptions
In the absence of an adequacy decision, binding corporate rules and/or international data transfer agreements, a transfer of personal data to a third country or international organisation can take place under an exception; however it is extremely unlikely that such a context will arise due to the nature of processing activities Inspired Ergonomics carries out. Guidance can be sought from the Data Protection Officer.
12. INFORMATION ASSET REGISTER/DATA INVENTORY – ‘DATA MAPPING’
12.1 Inspired Ergonomics has carried out data mapping to establish a data inventory and data flow process as part of its approach to address risks and opportunities throughout its UK GDPR compliance project. Inspired Ergonomics’ data inventory and data flow determine:
12.2 Inspired Ergonomics is aware of any risks associated with the processing of particular types of personal data.
12.2.1 Inspired Ergonomics assesses the level of risk to individuals associated with the processing of their personal data. Data protection impact assessments (DPIAs) are carried out in relation to processing of personal data by Inspired Ergonomics identified as of higher risk, and in relation to processing undertaken by other organisations on behalf of Inspired Ergonomics.
12.2.2 Inspired Ergonomics shall manage any risks identified by the risk assessment in order to reduce the likelihood of a non-conformance with this policy.
12.2.3 Where a type of processing, in particular using new technologies and taking into account the nature, scope, context and purposes of the processing is likely to result in a high risk to the rights and freedoms of natural persons, Inspired Ergonomics shall, prior to the processing, carry out a DPIA of the impact of the envisaged processing operations on the protection of personal data. A single DPIA may address a set of similar processing operations that present similar high risks.
12.2.4 Where, as a result of a DPIA it is clear that Inspired Ergonomics is about to commence processing of personal data that could cause damage and/or distress to the data subjects, the decision as to whether or not Inspire Ergonomics may proceed must be escalated for review to the Data Protection Officer.
12.2.5 The Data Protection Officer shall, if there are significant concerns, either as to the potential damage or distress, or the quantity of data concerned, escalate the matter to the supervisory authority.
12.2.6 Appropriate controls will be applied to reduce the level of risk associated with processing individual data to an acceptable level, by reference to the requirements of the GDPR.
Data Protection Policy 2024 October v1