P008 – NLS – Privacy and Data Policy – July 2024
New Lift Solutions Privacy and Data Protection Policy
Policy Statement
New Lift Solutions is committed to protecting the privacy and security of personal data. We recognise the importance of data protection and are dedicated to complying with the General Data Protection Regulation (GDPR) and other relevant data protection laws in the UK. This policy outlines our approach to handling personal data and ensures that we manage personal data responsibly and ethically.
Objectives
- To comply with GDPR and other applicable data protection legislation.
- To protect the privacy and security of personal data.
- To ensure transparency in our data processing activities.
- To provide individuals with rights regarding their personal data.
- To continuously improve our data protection practices.
Scope
This policy applies to all employees, contractors, consultants, and any other parties who have access to personal data controlled by New Lift Solutions.
Commitments
- Lawful, Fair, and Transparent Processing: Process personal data lawfully, fairly, and in a transparent manner.
- Provide clear information about how we collect, use, and share personal data.
- Data Minimisation: Collect and process only the personal data that is necessary for the purposes for which it is obtained.
- Ensure that personal data is adequate, relevant, and limited to what is necessary.
- Purpose Limitation: Collect personal data for specified, explicit, and legitimate purposes.
- Not process personal data in a manner that is incompatible with those purposes.
- Accuracy: Ensure that personal data is accurate and kept up to date.
- Take reasonable steps to rectify or delete inaccurate data without delay.
- Storage Limitation: Retain personal data only for as long as necessary for the purposes for which it is processed.
- Implement appropriate measures to securely dispose of personal data that is no longer needed.
- Security: Implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
- Regularly review and update our security practices to address emerging threats and vulnerabilities.
- Individual Rights: Respect and uphold the rights of individuals regarding their personal data, including the right to access, rectify, erase, restrict processing, and object to processing.
- Provide individuals with the ability to exercise their rights easily and promptly.
- Data Breach Management: Implement procedures for detecting, reporting, and investigating data breaches.
- Notify the Information Commissioner’s Office (ICO) and affected individuals of any data breaches that pose a risk to individuals’ rights and freedoms.
- Third-Party Processors: Ensure that third-party processors comply with data protection laws and our data protection standards.
- Enter into data processing agreements with third-party processors to ensure the protection of personal data.
- Training and Awareness: Provide regular training and resources to employees on data protection and privacy practices.
- Promote a culture of data protection and privacy awareness within the organisation.
Implementation
- Management Responsibility: Senior management is responsible for the implementation and effectiveness of this policy.
- Allocate appropriate resources to support data protection initiatives and compliance.
- Employee Responsibility: Employees are expected to adhere to this policy and follow data protection procedures.
- Report any concerns or breaches related to data protection to the Data Protection Officer (DPO) or their supervisor.
- Data Protection Officer: A designated Data Protection Officer (DPO) will oversee the implementation of this policy, provide guidance, and address any concerns or reports related to data protection.
Monitoring and Review
New Lift Solutions is committed to the continuous improvement of our data protection practices. This policy will be reviewed annually, or more frequently if necessary, to ensure its effectiveness and relevance. Feedback from employees and other stakeholders will be actively sought and considered in the review process.
Approval
This privacy and data protection policy is endorsed by the senior management of New Lift Solutions and is effective from 26/07/2024.
Nick Beetson
Managing Director
New Lift Solutions