Automated Processing |
any form of automated processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning that individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Profiling is an example of Automated Processing. |
Company Personnel |
all employees, workers contractors, agency workers, consultants, directors, members and others. |
Consent |
agreement which must be freely given, specific, informed and be an unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear positive action, signifies agreement to the Processing of Personal Data relating to them. |
Data Controller |
the person or organisation that determines when, why and how to process Personal Data. It is responsible for establishing practices and policies in line with the GDPR. We are the Data Controller of all Personal Data relating to our Company Personnel and Personal Data used in our business for our own commercial purposes. |
Data Officer |
the individual described and identified in section 3. |
Data Subject |
a living, identified or identifiable individual about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and may have legal rights regarding their Personal Data. |
Data Privacy Impact Assessment (DPIA) |
tools and assessments used to identify and reduce risks of a data processing activity. DPIA can be carried out as part of Privacy by Design and should be conducted for all major system or business change programs involving the Processing of Personal Data. |
Explicit Consent |
consent which requires a very clear and specific statement (that is, not just action). |
General Data Protection Regulation (GDPR) |
the General Data Protection Regulation ((EU) 2016/679). By this we also mean any local implementation of GDPR in England and Wales. Personal Data is subject to the legal safeguards specified in the GDPR. |
Personal Data |
any information identifying a Data Subject or information relating to a Data Subject that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. Personal Data includes Special Category Data and Pseudonymised Personal Data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal Data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour. |
Personal Data Breach |
any act or omission that compromises the security, confidentiality, integrity or availability of Personal Data or the physical, technical, administrative or organisational safeguards that we or our third-party service providers put in place to protect it. The loss, or unauthorised access, disclosure or acquisition, of Personal Data is a Personal Data Breach. |
Privacy by Design |
implementing appropriate technical and organisational measures in an effective manner to ensure compliance with the GDPR. |
Privacy Notices or Privacy Policies |
separate notices setting out information that may be provided to Data Subjects when the Company collects information about them. These notices may take the form of general privacy statements applicable to a specific group of individuals (for example, employee privacy notices or an external privacy notice for our website) or they may be stand-alone, one-time privacy statements covering Processing related to a specific purpose. |
Processing or Process |
any activity that involves the use of Personal Data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transmitting or transferring Personal Data to third parties. |
Pseudonymisation or Pseudonymised |
replacing information that directly or indirectly identifies an individual with pseudonyms so that the Data Subject cannot be identified without the use of additional information which is meant to be kept separately and secure. |
Related Policies |
the Company’s policies, operating procedures or processes related to this Data Protection Policy and designed to protect Personal Data. |
Special Category Data |
information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data, and Personal Data relating to criminal offences and convictions. |