Data Protection and Security Policy Statement
At TaxStats Ltd, we are committed to ensuring all personal data is processed in compliance with data protection laws and security standards. This policy outlines our approach to safeguarding personal data and sets the responsibilities of our staff to uphold these principles.
Policy Purpose
This policy aims to:
- Notify staff, customers, suppliers, and third parties about the types of personal data we may collect and process.
- Outline the legal conditions for processing personal data.
- Clarify staff responsibilities in maintaining data security and compliance.
Key Definitions
- Data Controller: TaxStats Ltd, determining purposes and methods of processing personal data.
- Personal Data: Information relating to an identifiable individual.
- Special Categories of Data: Includes sensitive data such as racial/ethnic origin, political opinions, health, and biometric data.
- Processing: Any use of data, including collecting, storing, and destroying it.
Data Protection Principles
All staff must adhere to the following principles:
- Lawful, Fair, and Transparent Processing: Always have a lawful basis for processing and notify data subjects of its purpose.
- Purpose Limitation: Data must only be used for its specified purpose.
- Data Minimisation: Collect only what is necessary.
- Accuracy: Ensure data is accurate and regularly updated.
- Storage Limitation: Retain data only for as long as necessary.
- Security: Protect data with appropriate technical and organisational measures.
Responsibilities
- Staff: Comply with the policy, protect personal data, and report any breaches.
- Managers: Lead by example, enforce compliance, and support data protection efforts.
- Data Protection Officer (DPO): Oversee policy adherence, address queries, and assess risks.
How We Use Personal Data
We use personal data for:
- Employment administration (e.g., contact details, payroll, performance reviews).
- Regulatory compliance (e.g., sickness records, equal opportunities monitoring).
- Operational needs (e.g., IT system monitoring, handling grievances).
Sensitive data is processed only when lawful and necessary, with explicit consent or other valid legal grounds.
Storage, Retention, and Security
- Storage: Data is stored securely using encryption, password protection, and physical security measures.
- Retention: Data is retained only as long as necessary and securely disposed of thereafter.
- Security Measures:
- Lock desks and cupboards with confidential information.
- Encrypt portable storage devices.
- Use approved cloud storage with strong security protocols.
Individual Rights
Individuals have rights to:
- Access: Request information on how their data is processed.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion of unnecessary data.
- Restriction: Limit processing under certain conditions.
To exercise these rights, email info@taxstats.co.uk. Requests are processed within 28 days unless extended for complex cases.
Data Breaches
If a data breach occurs, we will:
- Notify the Information Commissioner’s Office (ICO) within 72 hours if the breach poses a risk to individuals.
- Inform affected individuals if the risk is significant.
- Document all breaches and mitigation efforts.
Training and Awareness
- All staff receive data protection training during onboarding and regular intervals thereafter.
- Staff with significant data responsibilities receive additional training.
- Contact Our DPO
For queries, concerns, or requests, contact our Data Protection Officer at info@taxstats.co.uk.