Frontend and Backend Developers
1.0 Document Purpose
The purpose of this Policy is to ensure that PCUG processes personal data lawfully, fairly, securely and transparently and complies with applicable UK data protection legislation.
This includes the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable UK privacy and data protection legislation.
This Policy applies to personal data, special category personal data and, where relevant, criminal offence data processed by PCUG.
2.0 Scope
This Policy applies to:
- All personal data processed by PCUG where PCUG acts as a data controller.
- Personal data processed by PCUG on behalf of clients where PCUG acts as a data processor.
- All permanent, temporary, associate, agency and contract staff.
- Directors, consultants and other individuals who process personal data on behalf of PCUG.
- All systems, services, projects and business activities involving personal data.
All staff and contractors must comply with this Policy when handling personal data.
3.0 Definitions
3.1 Personal Data
Personal data means any information relating to an identified or identifiable living individual. Further guidance is available from the Information Commissioner’s Office (ICO).
Personal data may include:
- Names and contact details.
- Identification information.
- Employment information.
- Financial information.
- Online identifiers.
- Location information.
- Customer and client records.
- Communications.
- Education and professional information.
- Information relating to an individual’s lifestyle or circumstances.
Information does not need to identify someone directly to constitute personal data if an individual can reasonably be identified when that information is combined with other available information.
3.2 Special Category Personal Data
Special category personal data is personal data that requires additional protection under UK data protection law.
It includes information relating to:
- Racial or ethnic origin.
- Political opinions.
- Religious or philosophical beliefs.
- Trade union membership.
- Genetic data.
- Biometric data used for uniquely identifying an individual.
- Health.
- Sex life.
- Sexual orientation.
Processing special category personal data requires an appropriate lawful basis under Article 6 of the UK GDPR and an applicable condition under Article 9. Depending on the circumstances, additional requirements under the Data Protection Act 2018 may also apply.
3.3 Criminal Offence Data
Personal data relating to criminal convictions, offences, allegations or related security measures is subject to separate safeguards. PCUG will only process criminal offence data where it has lawful authority to do so and any applicable conditions under the Data Protection Act 2018 are satisfied.
Further guidance is available in the ICO’s criminal offence data guidance.
3.4 Data Controller
A data controller determines the purposes and means by which personal data is processed.
3.5 Data Processor
A data processor processes personal data on behalf of a data controller and in accordance with the controller’s documented instructions.
4.0 Responsibilities
- The PCUG Board has overall responsibility for ensuring that the organisation complies with applicable data protection legislation.
- Responsibility for day-to-day data protection compliance will be assigned to an appropriately authorised individual or function.
- Where PCUG is legally required to appoint a Data Protection Officer, the organisation will ensure that the role complies with applicable legal requirements.
- Managers are responsible for ensuring that data protection requirements are incorporated into relevant business processes.
- All staff are responsible for handling personal data securely and in accordance with this Policy.
- Staff must report suspected personal data breaches promptly in accordance with PCUG’s incident management procedures.
- Appropriate data protection training will be provided to staff according to their responsibilities.
5.0 Policy Statement
PCUG will follow the UK GDPR data protection principles and ensure that personal data is:
- Processed lawfully, fairly and transparently.
- Collected for specified, explicit and legitimate purposes.
- Not further processed in a manner incompatible with those purposes unless permitted by law.
- Adequate, relevant and limited to what is necessary.
- Accurate and, where necessary, kept up to date.
- Retained for no longer than necessary for the purposes for which it is processed.
- Protected using appropriate technical and organisational measures.
- Processed in accordance with applicable individual rights.
- Managed in a way that enables PCUG to demonstrate compliance with data protection law.
6.0 Data Protection Principles and Procedures
6.1 Lawful, Fair and Transparent Processing
PCUG will identify an appropriate lawful basis for processing before processing personal data.
6.2 Privacy Information
Where PCUG collects personal data, individuals will be provided with appropriate privacy information. The ICO provides further guidance on the right to be informed.
6.3 Data Minimisation and Accuracy
PCUG will only collect personal data necessary for the relevant purpose. Reasonable steps will be taken to ensure personal data is accurate and kept up to date where necessary.
6.4 Individual Rights
PCUG will respect applicable individual rights under UK data protection law. Further information is available in the ICO’s guidance on individual rights.
6.5 Subject Access Requests
Individuals have the right to request access to their personal data. PCUG will respond without undue delay and normally within one month, subject to applicable legal provisions.
See the ICO’s subject access request guidance for further information.
6.6 Personal Data Storage and Retention
PCUG will only retain personal data for as long as necessary for the purposes for which it was collected and will maintain an appropriate retention schedule.
Further information is available in the ICO’s guidance on storage limitation.
6.7 Security of Personal Data
PCUG will implement appropriate technical and organisational measures proportionate to the risks associated with its processing activities.
Additional guidance is available from the ICO on data protection and information security.
6.8 Personal Data Breaches
Staff must immediately report any actual or suspected personal data breach through the appropriate PCUG internal process.
Where applicable, PCUG will notify reportable personal data breaches to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
See the ICO’s personal data breach guidance for further information.
6.9 Data Protection by Design and Default
PCUG will consider data protection requirements when designing or changing systems, services and business processes involving personal data.
Further guidance is available from the ICO on data protection by design and default.
6.10 Data Protection Impact Assessments
A Data Protection Impact Assessment (DPIA) will be completed where processing is likely to result in a high risk to the rights and freedoms of individuals.
6.11 Suppliers and Data Processors
Where PCUG appoints another organisation to process personal data on its behalf, appropriate due diligence will be carried out and legally compliant contractual arrangements will be used where required.
The ICO provides further information about the responsibilities of controllers and processors.
6.12 Client Data
Where PCUG processes personal data on behalf of a client, PCUG will:
- Process data in accordance with the client’s documented instructions.
- Apply appropriate security controls.
- Ensure authorised personnel are subject to appropriate confidentiality obligations.
- Assist the client with relevant data protection obligations where legally and contractually required.
- Notify the client of relevant personal data breaches without undue delay.
- Return or securely delete client personal data at the end of the engagement where required.
- Maintain appropriate records of processing activities where applicable.
6.13 International Data Transfers
PCUG will identify restricted transfers of personal data outside the UK and ensure that an appropriate legal transfer mechanism is available before making such transfers.
Further information is available in the ICO’s international data transfer guidance.
6.14 Staff Awareness and Training
- Data protection awareness will form part of staff induction.
- Staff who process personal data will receive appropriate training relevant to their responsibilities.
- Refresher training will be provided periodically and where significant changes occur.
- Guidance and supporting materials will be made available to staff.
7.0 Governance
7.1 Accountability
PCUG will maintain appropriate measures to demonstrate compliance with data protection law.
Further information is available in the ICO’s accountability and governance guidance.
7.2 Communication, Review and Maintenance
This Policy will be reviewed regularly and at least annually.
It will also be reviewed following significant legislative, operational, organisational or technological changes, or following a material personal data breach.
7.3 Related Documents
- Information Security Policy.
- Data Retention Schedule.
- Personal Data Breach Procedure.
- Data Subject Rights Procedure.
- Data Protection Impact Assessment Procedure.
- Privacy Notices.
- Supplier and Processor Management Procedures.
- Acceptable Use Policy.
- Information Classification Policy.
7.4 External References
- Data Protection Act 2018
- ICO UK GDPR Guidance and Resources
- ICO Subject Access Request Guidance
- ICO Data Protection Impact Assessment Guidance
- ICO International Data Transfer Guidance
- ICO Personal Data Breach Guidance
Appendix A: Personal Data Retention
PCUG will maintain a documented retention schedule appropriate to the categories of personal data it processes.
The retention schedule should identify the category of record, purpose, applicable retention period, legal or business justification and the action to be taken when the retention period expires.
