Nijhuis Saur Industries UK Data Protection Policy
Introduction
Nijhuis Saur Industries UK is required to maintain certain personal data about living individuals for the purposes of satisfying operational and legal obligations. Nijhuis Saur Industries UK recognise the importance of the correct and lawful treatment of personal data under GDPR; it maintains confidence in the organisation and provides for successful operations. The type of personal data that Nijhuis Saur Industries UK may require includes information about:
- Employees - current, past and prospective
- Suppliers
- Sub-contractors
- Clients
- Other organisations and individuals with whom it is necessary to share personal data.
All personal data held, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the Data Protection Act 2018 and GDPR. Nijhuis Saur Industries UK fully endorses and adheres the principles of the Data Protection Act and GDPR. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data. Employees and any others who obtain, handle, process, transport and store personal data for Nijhuis Saur Industries UK must adhere to these principles.
Principles
The principles require that personal data shall:
- Be processed fairly and lawfully and shall not be processed unless certain conditions are met;
- Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with that purpose;
- Be adequate, relevant and not excessive for those purposes;
- Be accurate and, where necessary, kept up to date;
- Not be kept for longer than is necessary for that purpose;
- Be processed in accordance with the data subject’s rights;
- Be kept secure from unauthorised or unlawful processing and protected against accidental loss, destruction or damage by using the appropriate technical and organisational measures;
- And not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
Satisfaction of principles
In order to meet the requirements of the principles, Nijhuis Saur Industries UK will:
-
- observe fully the conditions regarding the fair collection and use of personal data;
-
- meet its obligations to specify the purposes for which personal data is used;
- collect and process appropriate personal data only to the extent that it is needed to fulfil operational or any legal requirements;
- ensure the quality of personal data used;
- apply strict checks to determine the length of time personal data is held;
- ensure that the rights of individuals about whom the personal data is held, can be fully exercised under GDPR;
- take the appropriate technical and organisational security measures to safeguard personal data;
- ensure that personal data is not transferred abroad without suitable safeguards.
Nijhuis Saur Industries UK Data Protection Officer
Nijhuis Saur Industries UK’s Data Protection Officer is responsible for ensuring compliance with the Data Protection Act/GDPR and implementation of this policy on behalf of the Managing Director. The Data Protection Officer is Gareth Hand, Group Compliance & QHSE Manager. Any questions or concerns about the interpretation or operation of this policy should be taken up in the first instance with the Data Protection Officer.
Status of the Policy
This policy has been approved by the Managing Director and any breach will be taken seriously and may result in formal action. Any employee who considers that the policy has not been followed in respect of personal data about themselves should raise the matter with their Line Manager or the Data Protection Officer in the first instance.
Subject Access
All individuals who are the subject of personal data held by Nijhuis Saur Industries UK are entitled to:
-
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability:
- the right to object; and
- the right not to be subject to automated decision making including profiling.
Employee Responsibilities
All employees are responsible for:
-
- Checking that any personal data that they provide to Nijhuis Suar Industries UK is accurate and up to date.
- Informing Nijhuis Saur Industries UK of any changes to information which they have provided,
e.g. changes of address.
-
- Checking any information that Nijhuis Saur Industries UK may send out from time to time, giving details of information that is being kept and processed.
If, as part of their responsibilities, employees collect information about other individuals (e.g. about solicitors’ practice details or personal circumstances, or about employees in their directorate), they must comply with this Policy and with the GDPR Procedures.
Data Security
The need to ensure that data is kept securely means that precautions must be taken against physical loss or damage, and that both access and disclosure must be restricted. All employees are responsible for ensuring that:
-
- Any personal data which they hold is kept securely and is accurate.
- Personal data is not disclosed either orally, in writing or otherwise to any unauthorised third party.
Rights to Access Information
Employees, and other subjects of personal data held by Nijhuis Saur Industries UK, have the right to access any personal data that is being kept about them on computer and also have access to paper-based data held in certain manual filing systems. Any person who wishes to exercise this right should make the request in writing to the Nijhuis Saur Industries UK Data Protection Officer, preferably using the standard form. If any information is inaccurate, it can be amended upon request.
Nijhuis Saur Industries UK will comply with requests for access to personal information as quickly as possible and will ensure that it is provided within the statutory period of one month from receipt of a completed form (or any written request).
Subject Consent
The need to process data for normal purposes will be communicated to all data subjects. In some cases, if the data is sensitive, for example information about health, race or gender, express consent to process the data must be obtained. Processing may be necessary to operate Nijhuis Saur Industries UK policies, for example health and safety or equality, diversity and inclusion.
Retention of Personal Data
Nijhuis Saur Industries UK has a requirement to retain some information for longer than others. All employees are to ensure that information personal information is not retained unnecessarily or for longer than necessary.
This policy will be updated as necessary to reflect best practice in data management, security and control and to ensure compliance with any changes or amendments made to the General Data Protection Regulations.
Ian Stentiford – Managing Director
Nijhuis Saur Industries UK & Ireland
Reviewed 1 October 2021