The EU General Data Protection Regulation (“GDPR”) came into force across the European Union on 25th May 2018 and brought with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age.
The 21st Century brings with it broader use of technology, new definitions of what constitutes personal data, and a vast increase in cross-border processing. The new Regulation standardised data protection laws and processing across the EU; affording individuals stronger, more consistent rights to access and control their personal information.
Redcentric (“we’,“us’”) are committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles. However, we recognised our obligations in updating and expanding this program to meet the demands of the GDPR and the UK’s Data Protection Act 2018.
We are dedicated to safeguarding the personal information under our remit and in maintaining a data protection regime that is effective, fit for purpose and demonstrates an understanding of, and appreciation for the GDPR Regulation. Our objectives for GDPR compliance have been summarised in this statement and include our implementation of the data protection roles, policies, procedures, controls and measures to ensure maximum and ongoing compliance.
Redcentric already operated a consistent level of data protection and security across our entire organisation and were able to successfully implement the necessary changes to fully comply with the GDPR requirements to meet what was the deadline of 25th May 2018.
Our compliance actions included: –
– Information Audit – carrying out a company-wide information audit to identify and assess what personal information we hold, where it comes from, how and why it is processed and if and to whom it is disclosed.
– Policies & Procedures – revising data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including: –
– Data Protection – our main policy and procedure document for data protection was revised to meet the standards and requirements of the GDPR. Accountability and governance measures are in place to ensure that we understand and adequately disseminate and evidence our obligations and responsibilities, with a dedicated focus on privacy by design and the rights of individuals.
– International Data Transfers & Third-Party Disclosures – where Redcentric stores or transfers personal information outside the EU, we have robust procedures and safeguarding measures in place to secure, encrypt and maintain the integrity of the data. Our procedures include a continual review of the countries with sufficient adequacy decisions, as well as provisions for standard data protection clauses and approved codes of conduct for those countries without. We carry out strict due diligence checks with all recipients of personal data to assess and verify that they have appropriate safeguards in place to protect the information, ensure enforceable data subject rights and have effective legal remedies for data subjects where applicable.
– Legal Basis for Processing – we have reviewed all processing activities to identify the legal basis for processing and ensured that each basis is appropriate for the activity it relates to. Where applicable, we also maintain records of our processing activities, ensuring that our obligations under Article 30 of the GDPR and Schedule 1 of the Data Protection Bill are met.
– Direct Marketing – we have revised the wording and processes for direct marketing, including clear opt-in mechanisms for marketing subscriptions; a clear notice and method for opting out and providing ‘unsubscribe’ features on all subsequent marketing materials.
– Special Categories Data – where we obtain and process any special category information, we do so in complete compliance with the Article 9 requirements and have high-level encryptions and protections on all such data. Special category data is only processed where necessary and is only processed where we have first identified the appropriate Article 9(2) basis or the Data Protection Bill Schedule 1 condition. Where we rely on consent for processing, this is explicit and is verified by a signature, with the right to modify or remove consent being clearly signposted.
Data Controller and Data Protection Office
We have appointed an Assurance & Compliance Manager who fulfils the data protection officer (DPO) function and is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the Assurance & Compliance Manager using the following details:
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the following rights:
If you wish to exercise any of the rights set out above, please email us at Data.protectionofficer@Redcentricplc.com.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Redcentric may change this statement at any time by publishing the amendments to this website. Whenever you visit this site, you agree to the current privacy statement at that time and shall apply to the data that we hold about you. By using our site, you give us your permission to our use of your personal data as set out in this Statement. If you wish to contact us directly, please visit our contact us page
Our website may contain links to other sites. We are not responsible for the privacy, content or services provided by the sites from such links and they are not covered by this privacy statement.
Cookies are small text files placed on your device when you visit a website or application. Your web browser then sends these cookies back to the website on each subsequent visit so that things like preferences can be remembered. Cookies enable a user to:
Cookies come in two flavours – session cookies and persistent cookies. As the term suggests, session cookies only remain until you close your online session and close your browser. Persistent cookies, again as the term suggests, remain on your device for the period defined within the cookie.
Your first visit to our web site will set your preference level and we will comply with this level during all subsequent visits initiated from that device. From your browser you can further manage cookies and any settings stored on your device. In addition to the cookies listed further down this section, we also use a cookie to remember the preferences you choose when accessing our web site. Please bear in mind that the preferences you choose are device specific – so if you use different devices you will need to update your preferences.
The cookies used on our website fall into one of three categories: strictly necessary, analytical / performance and functional.
These are cookies that are required for the operation of our site. They include, for example, cookies that enable you to log into secure areas of our site.
These allow us to recognise and count the number of visitors and see how many visitors move around our website when they are connected. This helps us to improve the way our site operates – for example, by ensuring that users are finding what they are looking for easily.
These are used to recognise you when you return to our site. This enables us to personalise our content for you and remember your preferences – for example, your choice of language or region.
There are ways you can control and manage cookies on your device. Please remember that any settings you change will not just affect the cookies we use. These changes will apply to all websites you visit (unless you choose to block cookies from particular sites).
Most browsers will allow you to choose the level of privacy settings you want. You can block all cookies or accept all cookies or pick a setting somewhere in between. This range lets you control your cookie settings, so you can:
Deleting cookies means that any preference settings you have made on a website will be lost. If you’ve set your preferences to opt out of cookies, this setting will be lost too, as that information is stored in a cookie. Blocking all cookies means functionality on our websites will be lost, as described above. We don’t recommend turning all cookies off when using our websites. If you wish to reduce your cookie settings at any time – for example, if you accept all cookies but later decide you don’t want a certain type of cookie – you’ll need to use your browser settings to remove any third party cookies dropped on your previous visit.