This Policy sets out the obligations of Millview Advisory Limited (“the Company”) regarding data protection and the rights of clients, employees, service providers (contractors/sole traders) and business contacts (“data subjects”). This includes obligations in dealing with personal data, in order to ensure that the organisation complies with the requirements of the relevant Irish legislation, namely the General Data Protection Regulation (GDPR) which replaced the Irish Data Protection Act (1988), and the Irish Data Protection (Amendment) Act (2003), (the Acts), as and from 25th May 2018.
The Regulation defines “personal data” as any information relating to an identified or identifiable natural person (a data subject); an identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, and identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
The Company is committed not only to the letter of the law, but also to the spirit of the law and places high importance on the correct, lawful and fair handling of all personal data, respecting the legal rights, privacy and trust of all individuals with whom it deals.
This Policy sets out the procedures that are to be followed when dealing with personal data. The procedures and principles set out herein must be followed at all times by the Company’s employees, agents, contractors or other parties working on behalf of the Company.
The policy covers both personal and sensitive personal data held in relation to data subjects by the Company and applies equally to personal data held in manual and automated form.
All personal and sensitive personal data will be equally referred-to as personal data in this policy, unless specifically stated otherwise.
This policy should be read in conjunction with the associated:
This Policy aims to ensure compliance with the Regulation. The Regulation sets out the following principles with which any party handling personal data must comply. Article 5 in the GDPR states that all personal data must be:
The Regulation seeks to ensure that personal data is processed lawfully, fairly and transparently, without adversely affecting the rights of the data subject. The Regulation states that processing of personal data shall be lawful if at least one of the following applies:
The data subject has given consent to the processing of his or her personal data for one or more specific purposes;
Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
Processing is necessary for compliance with a legal obligation to which the controller is subject;
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The Company will ensure that at least one of the conditions outlined above will be satisfied whenever any processing activities take place.
Identity of the controller and the data protection officer (or equivalent) Purpose and legal basis for processing. An explanation of the legitimate interest of the Company will be provided if it is being used as the legal basis. Data subject’s rights to withdraw consent, request access, rectification or restriction of processing. Data subject’s rights to complain to the Data Protection Commissioner’s Office Recipients of the personal data. Storage periods or criteria used to determine the length of storage. Legal basis for intended international transfer of data to a third country or organisation, including the fact that either the receiving country has an adequacy decision from the Commissioner or other appropriate safeguards are in place and how to obtain a copy.
In situations where the data is not being collected directly from the data subject, the Company will provide the source along with the other information listed above to the data subject within a reasonable period after obtaining the data but not more than one month. Information will not be provided to the data subject if it will require disproportionate effort or it would render it impossible or seriously impair the purpose of the data processing.
The Company will place a Fair Processing Notice in a highly visible position if it intends to record activity on CCTV or video.
The Data Subject’s data will not be disclosed to a third party other than to a party contracted to the Company and operating on its behalf.
The Company follows this purpose limitation principle and only collects and processes personal data for the specific purposes set out in the “Record of Processing Activities” document held by the Company, see 3.g. below. The purposes for which we process personal data will be informed to data subjects at the time their personal data is collected or not more than a month if obtained from a third party.
The Company will not further process personal data in a manner that is incompatible with those purposes unless:
The Company follows this data minimisation principle and only collect and process personal data for and to the extent necessary for the specific purpose(s) informed to data subjects.
The Company will ensure that all personal data collected and processed is kept accurate and up-to- date. The accuracy of data will be checked when it is collected and thereafter, see below. Where any inaccurate or out-of-date data is found, all reasonable steps will be taken without delay to amend or erase that data, as appropriate.
Send out an annual mailshot to all individuals on the Companies databases to ensure that consent is requested for further marketing etc Amend inaccurate data which has been notified to the Company by the Data Subject or is revealed as a result of a subject access request.
The Company follows this storage limitation principle and does not keep personal data for any longer than is necessary in light of the purposes for which that data was originally collected and processed.
The Company will verify whether statutory data retention periods exist in relation to the type of processing e.g., personal data may need to be kept in order to comply with tax, health and safety, or employment regulations etc. If the law is silent, internal data retention periods will be set to meet the storage limitation principle.
Retention periods will be set considering the purpose or purpose for which the data is collected and used, and once the storage periods expire, data will be securely deleted/destroyed in the absence of a sound new lawful basis to retain it. However, personal data may be stored for longer periods by the Company as the personal data will be processed solely for archiving purposes in the public interest, scientific, historical research or statistical purposes ensuring appropriate safeguards are in place i.e. irreversibly anonymised.
The Company has a Data Retention & Destruction Schedule, review for further details
The Company will ensure that all personal data collected and processed is kept secure and protected against unauthorised or unlawful processing and against accidental loss, destruction or damage. The state of technological development, the cost of implementing the measures, the nature of the data concerned and the degree of harm that might result from unauthorised or unlawful processing are all taken into account when the Company are determining the security measures that are put in place. Further details are outlined in the Company’s Security Policy
Under the GDPR, organisations are obliged to demonstrate that their processing activities are compliant with the Data Protection Principles. The principle of accountability seeks to guarantee the enforcement of the Principles.
The Company will demonstrate compliance in the following ways:
When the Company is acting as a Data Controller this record will contain the following:
• Detailed descriptions of the security measures implemented in respect of the processed data
When the Company is acting as a Data Processor this record will contain the following:
The Company also ensures that data protection by default is implemented by choosing the most data protective setting as the default i.e. users will have to opt in to any settings that presents greater risks. By default, only the personal data that is necessary is processed.
The Company has implemented a Subject Access Request procedure by which to manage such requests in an efficient and timely manner, within the timelines stipulated in the Regulation.
As part of the day-to-day operation of the organisation, the Company’s staff members engage in active and regular exchanges of information with Data Subjects. Where a formal request is submitted by a Data Subject in relation to the data held by the Company, such a request gives rise to access rights in favour of the Data Subject, the Regulation sets out the following rights applicable to data subjects:
The right to restrict processing; The right to data portability; The right to object; Rights with respect to automated decision-making and profiling. The right to withdraw consent
The Company’s staff members will ensure that, where necessary, such requests are forwarded to the Data Protection Officer in a timely manner, and they are processed as quickly and efficiently as possible.
The Company has a Data Access Request Policy/Procedure, refer to this document for detailed information on the topic.
The Company may from time to time transfer (“transfer” includes making available remotely) personal data to countries outside the Economic European Area (EEA).
The transfer of personal data to a “third country” i.e. outside the EEA, will only take place if one or more of the following applies:
The Company have outlined the procedure for data breach notification in a separate document, see Data Breach Procedure for Management (detailed procedure covering notification to the Office of the Data Protection Commissioner) or for Staff (detailed procedure outlined up to the point where Management are notified of the breach) along with an incident log and form. See the relevant document for more details.
It should be noted that the Company treat data breaches very seriously and any employee who becomes aware of a likely data breach and fails to notify the Data Protection Officer or a member of
the Data Protection Committee may be subject to the Companies disciplinary procedure depending on the severity of the breach.
The Company shall ensure that the following measures are taken with respect to the collection, holding, and processing of personal data:
The Company ensures that any entity which processes Personal Data on its behalf (a Data Processor) does so in a manner compliant with the Regulations. See the Company’s procedure on Engaging Third Party Processors for further details.
Failure of a Data Processor to manage the Company’s data in a compliant manner will be viewed as a breach of contract.
Failure of the Company’s staff members to process Personal Data in compliance with this policy may result in disciplinary proceedings.
Adam Honan acts as the Data Protection Officer & his contact details are: [email protected]
T: +353 (0)1 221 0610
E: [email protected]
5 Fitzwilliam Square,
Dublin 2 D02 R744
Copyright © 2022. All rights reserved.