Data Protection / Data Breach Policy

DATA PROTECTION BREACH POLICY

This policy applies to all personal and sensitive data held by BUSINESS MONEY SAVER The Data Protection Act 1998 makes provision for the regulation of the processing (use) of Information relating to individuals, including the obtaining, holding, use or disclosure of such information. Principle 7 of the Data Protection Act 1998 states that organisations which process personal data must take “appropriate technical and organisational measures against the unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”.

  1. TYPES OF BREACH

Data protection breaches could be caused by a number of factors. Some examples are:

  • Loss or theft of data or equipment on which data is stored
  • Inappropriate access controls allowing unauthorised use
  • Equipment Failure
  • Human Error
  • Unforeseen circumstances such as fire or flood
  • Hacking or offences where information is obtained by deception
  1. PROCEDURES

Immediate Containment/Recovery

  • The person who discovers/receives a report of a breach must inform the relevant Employee. If the breach occurs or is discovered outside normal working hours, this should begin as soon as is practicable.
  • The relevant Employee must ascertain whether the breach is still occurring. If so, steps must be taken immediately to minimise the effect of the breach. An example might be to shut down a system, or to alert relevant staff.
  • The relevant Employee must inform the Security Manager as soon as possible.
  • The relevant Employee must also consider whether the police need to be informed. This would be appropriate where illegal activity is known or is believed to have occurred, or where there is a risk that illegal activity might occur in the future.
  • The relevant Employee must quickly take appropriate steps to recover any losses and limit the damage.
  1. STEPS MIGHT INCLUDE:
  • Attempting to recover lost equipment.
  • Contacting the other relevant Departments, so that they are prepared for any potentially inappropriate enquiries ‘phishing’ for further information on the individual concerned.
  • Consideration should be given to a global email. If an inappropriate enquiry is received by staff, they should attempt to obtain the enquirer’s name and contact details if possible and confirm that they will ring the individual making the enquiry back. Whatever the outcome of the call, it should be reported immediately to the relevant Employee.
  • The use of back-ups to restore lost/damaged/stolen data. If bank details have been lost/stolen, consider contacting banks directly for advice on preventing fraudulent use.
  • If the data breach includes any entry codes or passwords, then these codes must be changed immediately, and the relevant agencies and members of staff informed.

4.

INVESTIGATION

In most cases, the next stage would be for the relevant employee to fully investigate the breach. That person should ascertain whose data was involved in the breach, the potential effect on the data subject and what further steps need to be taken to remedy the situation.

The investigation should consider the type of data, its sensitivity, what protections are in place (e.g encryption), what has happened to the data, whether the data could be put to any illegal or inappropriate use, how many people are affected, what type of people have been affected (the public, suppliers, etc.) and whether there are wider consequences to the breach.

A clear record should be made of the nature of the breach and the actions taken to mitigate it. The investigation should be completed urgently and wherever possible within 24 hours of the breach being discovered / reported. A further review of the causes of the breach and recommendations for future improvements can be done once the matter has been resolved.

  1. NOTIFICATION

Some people/agencies may need to be notified as part of the initial containment. However, the decision will normally be made once an investigation has taken place. The security manager should, after seeking legal advice, decide whether anyone should be notified of the breach. In the case of significant breaches, the Information Commissioners Office (ICO) should be notified. Every incident should be considered on a case by case basis. The following points will help you to decide whether and how to notify:

Are there any legal/contractual requirements to notify?

Will notification help prevent the unauthorised or unlawful use of personal data? Could notification help the individual – could they act on the information to mitigate risks? If a large number of people are affected, or there are very serious consequences, you should notify the ICO. The ICO should only be notified if personal data is involved. There is guidance available from the ICO on when and how to notify them, which can be obtained at http://www.ico.org.uk/for_organisations/data_protection/lose.aspx

Consider the dangers of over-notifying. Not every incident warrants notification and over-notification may cause disproportionate enquiries and work. The notification should include a description of how and when the breach occurred and what data was involved. Include details of what you have already done to mitigate the risks posed by the breach. When notifying individuals, give specific and clear advice on what they can do to protect themselves and what you are willing to do to help them. You should also give them the opportunity to make a formal complaint if they wish.

  1. REVIEW AND EVALUATION

Once the initial aftermath of the breach is over, the relevant employee should fully review both the causes of the breach and the effectiveness of the response to it.

  • A report should be written and sent to the next available Management Team meeting for discussion.
  • If systemic or ongoing problems are identified, then an action plan must be drawn up to put this right.
  • If the breach warrants a disciplinary investigation, the manager leading the investigation should liaise with Human Resources for advice and guidance.
  1. ENFORCEMENT

BUSINESS MONEY SAVER employees who breach this policy may be denied access to the organisations information technology resources, and maybe subject to disciplinary action, including suspension and/or dismissal.

BUSINESS MONEY SAVER DATA RETENTION POLICY

As per the ICO website, https://ico.org.uk/for-organisations/guide-to-data- protection/principle-5retention/,

Business Money Saver keep customer data for a period of time in order to conduct business, and also to reply to complaints or queries to the best of our ability.

We understand that data can change, such as a customer’s personal circumstances, address, etc.

BUSINESS MONEY SAVER ensures the highest level of data security within their business. BUSINESS MONEY SAVER understand the severity of a data breach, or unauthorized personnel accessing customer data. We have secure platforms where the data is stored, this is password protected and only authorized employees have access to these encrypted databases.

Information may be kept longer than usual guidelines if it is required for legal or regulatory requirements, this may be due to an ongoing complaint for example.

BUSINESS MONEY SAVER will only keep customer data in our live marketing database for 6 months, once 6 months from the most recent opt-in date has passed, we will cease marketing to this data. (This only relates to data that has specific marketing consent), When holding data past the 6 month mark, this is not for marketing purposes or for business use, this is to assist with any potential queries, complaints or legal action that may arise.

We confirm on each of our websites that all customers have the right to a Subject Access Request, this service is no longer charged for, and will provide the customer with all data, information and communications that relate to them.

BUSINESS MONEY SAVER confirms that data will never be held longer than necessary. We will securely archive or securely dispose of the data. We will continually comply with GDPR and DPA regulations when disposing of personal information. We understand that holding data longer than reasonably necessary can cause risk or detriment to the customer as the information provided originally may longer be factual or valid.

In regards to our third party partners, we carry out thorough and continual audits throughout our working relationships. This starts from the initial sign up process. We ensure we gather a confirmation that customer data over 6 months old will not receive marketing communications or be used for business purposes. We also require that our partners comply with all relevant laws and regulations and are registered with the ICO.

 

BUSINESS MONEY SAVER DATA DISPOSAL POLICY

How Do We Keep Your Information Secure? We recognise the importance of keeping your personal information secure and confidential. We take reasonable and appropriate precautions and security measures against unlawful or unauthorised processing of your data including the use of Secure Sockets Layer (SSL) encryption, to secure the personal and non-personal information you provide us against accidental loss, misuse, alteration or unauthorised access. We regret that no transmission of data can ever be perfectly secure over the internet. As such, while we strive to protect your personal information, we cannot guarantee its security or confidentiality. Please be cautioned that we do not request your sensitive information except through online forms, or through our user-initiated contact. Your personal data will only be transferred to a data processor (such as a lender) if it agrees to comply with those procedures and policies, or puts in place adequate measures itself.

Your Access to Information

Section 7 of the Data Protection Act gives you the right to access information we hold about you. We will not charge for this service. Please submit your request in writing to accounts@BusinessMoneySaver.com or by post to Business Money Saver Limited, 32 Willoughby Road, London, England, N8 0JG. We will provide the information within a month of receiving the request.

Information Maintenance

We maintain customer data on secured servers, and will hold that data subject to the following rules:

  • If you request that we do not contact you for advertising and marketing purposes, we must still maintain a record of your preferences;
  • We will maintain any information you have entered into forms on the website for a minimum of six (6) years, beginning at the termination of our relationship with you;
  • We maintain your information for as long as we continue to provide a service to you (as an affiliate or otherwise);
  • Where legitimate legal or business reasons exist, we will maintain your information for so long as such condition remains.

Right to be forgotten

As above, we do have the right to store your data as we have outlined. We will do this safely and securely for the stated period of time. As per the General Data Protection Regulation (GDPR), all consumers have the right to be forgotten under the following circumstances:

  • Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed.
  • When the individual withdraws consent.
  • When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing.
  • The personal data was unlawfully processed (ie otherwise in breach of the GDPR).
  • The personal data has to be erased in order to comply with a legal obligation.
  • The personal data is processed in relation to the offer of information society services to a child.

(Reference: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection- regulationgdpr/individual-rights/right-to-erasure/)

Please request your ‘right to be forgotten’ to ourselves in writing to Accounts@BusinessMoneySaver.com or by post to Business Money Saver, 32 Willoughby Road, London, England, N8 0JG.

All data will be encrypted through all stages, including at point of disposal or archive. We strongly believe in keeping all customer details safe and secure, and our company free from data breach.