Data Protection Policy
Introduction
Cube Creative Limited is committed to full compliance with the requirements of the Data Protection Act 1998 and to follow procedures that aim to ensure that all Directors, employees, contractors, agents or consultants who may have access to any personal data held internally or supplied by a client, are fully aware of and abide by their duties and responsibilities under the Act.
Statement of policy
In order to provide the correct level of service to our clients, Cube has, at times requested to do so, use names and address information for client mailings and deliveries. These details may include members of the public, current, past and prospective employees, clients and customers and contractors. This personal information must be handled and dealt with properly, however it is supplied, stored and used, and whether it be on paper, in computer records or recorded by any other means.
Cube Creative Limited regards the lawful and correct treatment of personal information as very important to its clients successful operations and to maintaining confidence between the company and those with whom it carries out business and as such all directors and employees will ensure that all personal data supplied is treated lawfully and correctly.
To this end the Cube Creative Limited fully endorses and adheres to the Principles of Data Protection as set out in the Data Protection Act 1998.
The principles of data protection
The Data Protection Act 1998 stipulates that anyone processing personal data must comply with Eight Principles of good practice. These Principles are legally enforceable.
The Principles require that personal information:
1. Shall be processed fairly and lawfully and in particular, shall not be processed unless specific conditions are met.
2. Shall be obtained only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or those purposes.
3. Shall be adequate, relevant and not excessive in relation to the purpose or purposes for which it is processed.
4. Shall be accurate and where necessary, kept up to date.
5. Shall not be kept for longer than is necessary for that purpose or those purposes.
6. Shall be processed in accordance with the rights of data subjects under the Act.
7. Shall be kept secure i.e. protected by an appropriate degree of security.
8. Shall not be transferred to a country or territory outside the European
Economic Area, unless that country or territory ensures an adequate
level of data protection.
The Act provides conditions for the processing of any personal data. It also makes a distinction between personal data and ”sensitive” personal data.
Personal data is defined as, data relating to a living individual who can be identified from:
• That data.
• That data and other information which is in the possession of, or is likely to come into the possession of the data controller and includes an expression of opinion about the individual and any indication of the intentions of the data controller, or any other person in respect of the individual.
Sensitive personal data is defined as personal data consisting of information as to:
• Racial or ethnic origin
• Political opinion
• Religious or other beliefs
• Trade union membership
• Physical or mental health or condition
• Sexual life
• Criminal proceedings or convictions.
Handling of personal/sensitive information
Cube Creative Limited will, through appropriate management and the
use of strict criteria and controls:-
• Observe all conditions regarding the fair collection and use of personal information.
• Meet its legal obligations to specify the purpose for which information is used.
• Collect and process appropriate information and only to the extent that it is needed to fulfil operational needs or to comply with any legal requirements.
• Apply strict checks to determine the length of time information is held.
• Ensure that personal information is not transferred abroad without suitable safeguards.
In addition, Cube Creative Limited will ensure that:
• Someone will be designated, on behalf of the client, with specific responsibility for the data protection in the organisation.
• Everyone managing and handling personal information understands that they are contractually responsible for following good data protection practice.
• Everyone managing and handling personal information is appropriately trained to do so.
• Everyone managing and handling personal information, both employed by Cube or as a contractor, is appropriately supervised.
• Anyone wanting to make enquiries about handling personal information, whether a member of staff or a member of the public, knows what to do.
• Queries about handling personal information are promptly and courteously dealt with.
• Performance with handling personal information is regularly assessed and evaluated.
All Directors of the company, employees of the company and contractors to the company are to be made fully aware of this policy and of their duties and responsibilities under the Act.