Data Protection Policy
– International Security Register
In accordance with the Data Protection Act 1998, Retainagroup
Limited upholds the eight
principles in relation to its secure data base – the
International Security Register (ISR)
in that:-
1. Personal data is obtained directly and voluntarily
from individuals, or is provided
by our trade customers in a fair and lawful
manner.
2. Data is held on file for legitimate verification
and security purposes. Data is passed
to our trade customers either when the
data subject has returned a completed form
without opting out, or by default if the data
subject has not responded to an
acknowledgement form within 60 days.
3. The data held contains no more information than is necessary
regarding an
individual, in order to maintain an adequate
history of the life of a security marked
and registered item.
4. Every effort is made to ensure that data on the ISR is
up-to-date and the
verification process ensures the data is
as accurate as possible.
5. When electronic data is marked as “old/archived”,
it is stored indefinitely in a secure
environment. Information is kept in order
to support crime prevention and
investigation enquiries by law enforcement
agencies.
6. Data is accessible on written request and a discretionary
administration cost of £10
is payable. A “screen dump”
can be provided to the data subject within 10 days.
The ISR verification process ensures that
data subjects know what is stored and that
the information is correct; if inaccurate
information is notified, it is amended or, if
requested, erased. Access to data subjects
is “removed” from the ISR on request
and their record is archived to a secure
area.
7. The ISR is protected by a firewall and there are no open
links through the Internet.
Paper records are archived and then destroyed
by shredding and recycling the paper
after a set length of time.
All staff entrusted with access to
the ISR do so through a password entry system and
each member of staff is security vetted
prior to joining the company. All transactions
are logged and traceable.
8. Currently the data on the ISR is used only in the EEA.
|