INTRODUCTION
The General Data Protection Regulations (GDPR) came into force on 25 May 2018. It imposes greater obligations on organisations whilst giving more rights to individuals in relation to how their personal data is processed. GDPR will oblige organisations to take a ‘privacy by design and by default’ approach to data protection. This means that data protection must be integral to all data processing activities.
GDPR applies to all organisations which collect the personal data of individuals living within the EU. This bill replaces the Data Protection Act 1998 and will import the GDPR standards into UK law whilst also dealing with any exemptions/derogations permitted by the GDPR.
ShieldMe Solutions are committed to protecting and respecting your privacy.
This policy (together with our terms of and any other documents referred to on it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. This website is governed by the laws of England and Wales and the English and Welsh Courts shall have exclusive jurisdiction over it.
ShieldMe are registered with the Information Commissioners Office (ICO). This ensures we adhere to our data protection obligations under the DPA and appropriate action is taken where there is a breach or a breach is suspected has taken place. The aim of the policy, in line with the DPA obligations, is to ensure all information, including sensitive information is lawfully processed, subject data is held with their knowledge, consent and for a particular purpose. Subjects are also entitled to request their information by making a “Subject Access Requests”.
Data Protections Policy and Privacy Statement also applies to our candidates registering.
Definitions and Key Terms
‘consent’ means any freely given, specific, informed and unambiguous indication of an individual’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of persona data relating to him or her;
‘Data controller’ means an individual or organisation which, alone or jointly with others, determines the purposes and means of the processing of personal data;
‘Data processor’ means an individual or organisation which processes personal data on behalf of the data controller;
“Data subject” is the living individual to whom the personal data relates. Organisations are not data subjects.
“Personal data” means data that can identify a data subject as a living individual. There is general personal data such as a data subject’s name, address, National Insurance number and online identifiers/location data. Sensitive personal data which includes information on physical and mental health, sexual orientation, race or ethnic origin, religious beliefs, trade union membership and criminal records. Information relating to identifiable individuals, such as job applicants, current and former employees, agency, contract and other staff, clients, suppliers and marketing contacts.
Personal data we gather may include: individuals’ contact details, educational background, details of certificates and diplomas, education and skills, marital status, nationality, job title, DBS Status, Eligibility to Work status and CV.
Financial and pay details will remain between the candidate and ShieldMe Solutions or the client/vendor and ShieldMe Solutions. Payment history may be part of the audit requirements between ShieldMe Solutions and the Vendor and/or umbrella company.
Personal data will be uploaded to vendor sites and or for compliance/audit requests
Sensitive personal data must be protected to a higher level: Personal data about an individual’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership (or non-membership), physical or mental health or condition, criminal offences, or related proceedings—any use of sensitive personal data should be strictly controlled in accordance with this policy.
Business Purposes:
The purposes for which personal data may be used by us: Personnel, administrative, financial, regulatory, payroll and business development purposes.
Business purposes include the following:
Lawful basis: There are six lawful bases for processing a data subject’s personal data:
a) The lawfulness of processing conditions for personal data are:
The following are the lawful bases for processing a data subject’s sensitive personal data:
b) The lawfulness of processing conditions for sensitive personal data are:
Consent, legitimate interests, performance of a contract and legal obligations are likely to be the most relevant for recruitment companies (though note that legitimate interests and performance of a contract are not lawful bases for processing sensitive personal data).
In this policy the following terms have the following meanings:
“Third Parties/3rd Party” means Clients, Managed Vendors, Umbrella companies, DBS Services, Occupational Health Providers, Training Providers
“Cookies” means small pieces of data on a user’s device.
‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data;
‘processing’ means any operation or set of operations performed on personal data, such as collection, recording, organisation, structuring, storage (including archiving), adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to an individual without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable individual;
‘supervisory authority’ means an independent public authority which is responsible for monitoring the application of data protection. In the UK the supervisory authority is the Information Commissioner’s Office (ICO).
“User” means the user using the service. The User corresponds with the data subject, who is the subject of personal data.
“Usage Data” means data collected automatically either generated by the use of the service or from the Service Infrastructure itself (e.g. duration of page visit)
WHO IS RESPONSIBLE FOR THE MANAGEMENT OF THIS POLICY
Everyone has the responsibility to adhere to this policy. Our Safeguarding and Compliance Manager holds the role of Data Protection Officer (DPO), and has overall responsibility for the day-to-day implementation of this policy.
INFORMATION WE MAY COLLECT FROM YOU
We may collect and process the following data about you:
WHERE WE STORE YOUR PERSONAL DATA
WHAT WE DO WITH YOUR DATA
Data we collate will be used for the purposes of finding you employment and keeping your contract in date in line with the specific requests from our 3rd party vendors/prospective employers.
We use information held about you in the following ways:
DISCLOSURE OF YOUR INFORMATION
INVESITGATION AND DUE DILIGENCE
At any time where a breach or potential breach is identified, either internally or in the supply chain, it is reviewed using the ShieldMe Solutions Complaints procedure
ShieldMe Solutions undertakes due diligence when considering taking on new suppliers, and regularly reviews its existing suppliers. Our due diligence and reviews include assessing the supply chain broadly to assess particular product or geographical risks
YOUR RIGHTS
You have the right to ask us not to process your personal data for marketing purposes.
You have the right to be removed from our database (“Right to be forgotten”, see Subject access requests).
ACCESS TO YOUR INFORMATION AND CORRECTIONS
All information given to us should be kept up to date and accurate. Please make sure we are kept up to date, if you need to make any changes to details or you think details are inaccurate please email info@shieldmesolutions.co.uk titled “Change of details”. This will be actioned with within 3 working days.
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act. You will need to send an email to info@shieldmesolutions.co.uk titled “Subject Access Request”. This will be dealt with within 30 days.
CHANGES TO OUR PRIVACY POLICY
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on our website.
LIABILTY
We accept no liability for any loss (whether direct or indirect, for any loss of business, revenue or profits, waste expenditure, corruption or destruction of data) arising from registration with ShieldMe Solutions
CONTACT
All questions and comments regarding these policies should be addressed to our Data Controller at info@shieldmesolutions.co.uk
