WELCOME NOTE

Welcome to the Greencastle Wiki! On the Wiki you will find a range of information relating from Payroll, Marketing, HR news and more. The Intranet will keep you up to date with any news, deadlines or important information. If you have any content or suggestions you would like to appear on the Intranet then please feel free to email helpdesk@greencastlesolutions.co.uk and they will deal with your request.

  • WELCOME NOTE

Send

  • 8 years ago
  • 2 Mins

GDPR FAQ

1.  What is a data subject?

This is anyone that the data refers to i.e. a person, an employee or a temporary worker.

 2. What is personal data?

This is data that relates to an identified or identifiable person. This can be data that is processed electronically, be kept in a filing cabinet, be part of an accessible record or be held by a public authority. This includes data that does not name an individual but could identify them i.e. employee number. This also includes interview notes and Adapt journal notes.

 3. What is GDPR?

GDPR is the General Data Protection Regulations and replaces the current Data Protection Act. It is the biggest overhaul in data protection in 20 years and is being enforced across the EU. It is part of British law regardless of Brexit. The GDPR is concerned with respecting rights of individuals when processing their personal information. All staff have a responsibility to ensure that their activities comply with the data protection principles.

4. What are the 6 principles of GDPR?

. Personal data should be processed fairly, lawfully and in a transparent manner

. Data should be obtained for specific and lawful purposes and not further processed in a matter incompatible with those purposes

. The data should be adequate, relevant and not excessive

. The data should be accurate and where necessary kept up to date

. Data should not be kept for longer than necessary

. Data should be kept secure

5. What is a subject access request?

This can be sent in so that a worker can have access to any information that an employer has on them. This needs to be in writing and has to include specific information. If a subject access request is sent in, we have 30 days to give you the information we have.

6. What should I do if a temp sends in a subject access request?

If you receive a subject access request you need to send this to data@coyles.co.uk as soon as you receive it.

7. What do I do if someone has a question I cannot answer?

Please direct any questions to data@coyles.co.uk and we will assist with any queries you might have.

8. What happens if I do not comply?

GDPR breaches will be written in to our disciplinary procedures as they are very serious.

9. What happens if a temp wants to change their consent?

If a temp needs to change their consent please get them to do this via the portal on the website or email data@coyles.co.uk and we can edit their preferences.

10. How long can we keep data for?

Data can only be kept for as long as is necessary. For a list of our statutory retention periods please see the document on the Wiki.

11. What about client’s data?

GDPR is quite candidate led however if you do have any personal data of one of your clients i.e. telephone number, you will need to follow all of the same GDPR principles and only process this if we have a legitimate interest to do so.

12. What do I do if someone asks to be removed?

It means exactly that - remove them. If you get a removal request please send it to data@coyles.co.uk ASAP and we can remove them from the systems. However, you need to make sure you remove them from your mailing lists, phones, spreadsheets and Outlook etc. as this is very important.