What our promise means to us
We promise to respect the rights of those people whose personal information we process. These are:
the right to be informed;
the right of access
the right to rectification;
the right to erasure;
the right to restrict processing;
the right to data portability;
the right to object to processing; and
the right not to be evaluated solely based on automated decision-making and the right in relation to profiling
We understand that allowing individuals to exercise these rights is at the very heart of privacy compliance - it is their personal information after all and so we need to protect it and their rights in relation to it.
What we all need to do to keep our promise
We ensure that we are all aware of the rights of individuals and that we recognise what a subject access request looks like and what to do if we receive one (nb. it may not be a written request and may be directed at anyone in our organisation).
We recognise that compliance with Promise 3 (Transparency) and Promise 8 (Privacy by design and by default) will help us comply with this Promise 5.
We will always tell individuals about their rights explicitly and in our first communication with them. Such notification will be presented clearly and separately from any other information in a way that is:
concise;
transparent;
intelligible and easily accessible; and
clear, using plain language.
We will adapt such communication to our audience, using appropriate media, because if they don’t understand it, we haven’t given them the rights that they are entitled to.
We will:
ensure that individuals are informed of all their rights and how to enforce them effectively and not just in privacy notices (for example whenever we communicate with them);
use pre-prepared templates and processes which make it as easy as possible to comply with requests from individuals quickly and correctly within the legal deadline without hampering our business;
provide individuals with easy ways to keep their personal information accurate and up to date when we communicate with them whether by email, on the telephone, or in delivering our products or services;
ensure that any of our Vendors & Partners that process personal information inform us immediately of any requests from individuals which they receive;
keep accurate records within our Hub of our decisions in relation to the processing of personal information (compliance with Promise 2 will help us achieve this);
ensure that all product developments include a consideration of whether personal information is being processed and whether easier ways of responding to individuals’ rights in relation to that personal information should be included in the product (e.g building a customer profile page which customers can access and update); and
ensure that all privacy notices include information on the rights of individuals and how they can be exercised.
Our documents demonstrating compliance with our promise
TEMPLATES - Generic documents for us to customise | |
---|---|
If you'd like to see these documents, speak to a Hub Owner or Privacy Champion. |
RECORDS - Documents recording our compliance activities | |
---|---|
If you'd like to see these documents, speak to a Hub Owner or Privacy Champion. |
INFORMATION - Documents containing information to help us comply | |
---|---|
No documents made available yet |
POLICIES - Documents containing our policies | |
---|---|
No documents made available yet |