The General Data Protection Regulation
1. THE RULES
- 1.1 -The General Data Protection Regulation (GDPR) came into force on the 25th May 2018. It replaced the Data Protection Act 1998, however many of the rules remain the same.
- 1.2 – Like the DPA, the GDPR applies to ‘personal data’. The GDPR’s definition, however, is more detailed and makes it clear that even information such as an online identifier – e.g. an IP address, can be deemed as personal data.
- 1.3 This manual specifically focuses on the rules relating to the General Data Protection Regulation (GDPR) and the requirement for privacy relating to customers data held on file.
Controllers and Processers
- 1.4 – The GDPR applies to ‘Controllers’ and ‘Processers’. The definitions are broadly the same as under the DPA i.e. the Controller says how and why personal data is processed and then the processor acts on the Controllers behalf.
- 1.5 – Controllers – A Controller determines the purposes and means of processing personal data. This includes deciding what data is collected and how it will be used. In the majority of cases Brokers will be deemed a Controller.
- 1.6 – To determine whether the firm is a data Controller it took the following into consideration:
- The firm will collect the personal data in the first place and decide on the legal basis for doing so;
-
- Which items of personal data it will collect;
- The purpose or purposes the data is to be used for;
- Which individuals to collect data about;
- Whether to disclose the data, and if so, to who;
- How long to retain data.
- 1.7 – As the above would be carried out as part of the firms service it has identified itself as a Controller.
- 1.8 – The firm is aware that the GDPR places further obligations on Controllers to ensure contracts with Processers comply with the GDPR. Therefore, where a Data Processor is used the firm will ensure that it has a contract in place.
- 1.9 – Processers – A Processer is responsible for processing personal data on behalf of a Controller. The GDPR places specific legal obligations on Processers, for example they are required to maintain records of personal data and processing activities.
- 1.10 – When processing data on the Controllers behalf the Data Processor may decide:
-
- What IT systems or methods to use to collect personal data;
-
- How to store the personal data;
-
- The detail of the security surrounding the personal data from one organisation to another;
-
- The means used to retrieve personal data about certain individuals;
-
- The method for ensuring a retention schedule is adhered to; and
-
- The means used to delete or dispose of the data.
GDPR Principles
- 1.11 -The GDPR also puts more accountability on those who process personal data. The principle of accountability requires the firm to demonstrate that it is complying with the GDPR, and have appropriate policies and processes in place.
- 1.12 – The GDPR Principles set out the main responsibilities which Seico Insurance & Mortgages Limited adheres to and requires all personal data to be:
- Processed lawfully, fairly and in a transparent manner;
-
- Collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes;
-
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
-
- Accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data is accurate and updated without delay.
-
- Kept in a form which permits identification of customers for no longer than is necessary for the purposes for which the personal data is processed and in line with FCA requirements;
-
- Processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
GDPR Data Mapping
- 1.13 – The firm has reviewed how personal data flows through the organisation and how it is processed. As part of this the following has been considered:
- What information the firm holds that constitutes personal data;
-
- What the firm does with the personal data it processes;
-
- What the firm actually needs to carry out these processes;
-
- Whether the firm is collecting the information it needs;
-
- Whether the firm is creating derived or inferred data about people, for example by profiling them; and
-
- Where the firm will be likely to do other things with it in the future.
- 1.14 – The firm will continually monitor and review the above to ensure that the information used is relevant, accurate and up to date at all times.
Data Protection Officer
- 1.15 – The GDPR states firms must appoint a Data Protection Officer (DPO) if:
- The firm carries out a large scale systematic monitoring of individuals (for example, online behaviour tracking) or;
- The firm carries out large scale processing of special categories of data or data relating to criminal convictions and offences.
- 1.16 – Whilst the firm may not carry out the above to a large scale it has appointed Rob Starr as the DPO.
- 1.17 – As a regulated firm it is deemed that a Senior Manager/Director should take on the role to ensure that it is enforced within the business.
- 1.18 – Where changes are required within the firm and/or to its data protection processes the DPO will make the necessary adjustments and update staff accordingly.
- 1.19 – The duties of a DPO includes the following:
- Informing and advising the firm and its employees about their obligations to comply with the GDPR;
- Monitoring compliance with the GDPR including managing internal data protection activities, advise on data protection impact assessments, train staff and conduct internal audits;
-
- Being the first point of contact for supervisory authorities and for individuals whose data is processed.
2. LAWFUL BASIS FOR PROCESSING
- 2.1 – Under GDPR firms must have a lawful basis in order to process personal data.
- 2.2 – The first principle requires that firms process all personal data lawfully, fairly and in a transparent manner. Processing is only lawful if there is a lawful basis to process it under.
- 2.3 – In addition, under the accountability principle the firm must be able to demonstrate that a lawful basis applies.
- 2.4 – There are six lawful basis for processing. No single basis is ‘better’ or more important than the others and the basis depends on the purpose and relationship with the customer.
- 2.5 – The firm has worked through the GDPR requirements and established which lawful basis it will need to process data. This is set out in the firms Privacy Notice.
- 2.6 – The lawful basis are set out in Article 6 of the GDPR and confirms that at least one must apply whenever processing personal data:
- Consent has been given – the individual has given clear consent to process their personal data for a specific purpose.
-
- Necessary for the performance of a contract – The processing is necessary for a contract with the individual, or because they have asked to take specific steps before entering into a contract.
-
- Necessary for compliance with a legal obligation – The processing is necessary to comply with the law (not including contractual obligations).
-
- Necessary to protect vital interest – The processing is necessary to protect someone’s life.
-
- Necessary for the performance of a task in the public interest – The processing is necessary to perform a task in the public interest or official functions, and the task or function has a clear basis in law.
-
- Necessary for the purposes of legitimate interests – The processing is necessary for legitimate interests or the legitimate interest of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
- 2.7 – It is important that the correct lawful basis is decided upon before processing any personal data. Therefore, the firm has:
- Reviewed its purposes for processing activities, and selected the most appropriate lawful basis (or bases) for each activity;
-
- Checked that the processing is necessary for the relevant purpose, and is satisfied that there is no other reasonable way to achieve that purpose;
-
- Documented its decision on which lawful basis applies to the firm to demonstrate compliance;
-
- Included information about both the purposes of the processing and the lawful basis for the processing in its privacy notice.
- 2.8 – The firm will continue to review the lawful basis it uses to ensure that they remain the most suitable.
Consent
- 2.9 – Consent under GDPR must be freely given and there must be some form of clear affirmative action such as a positive opt-in. Consent cannot be inferred from silence, pre-ticked boxes or inactivity.
- 2.10 – When consent is obtained it must be clear to the customer what they are consenting to. Therefore, the firm takes particular care when obtaining consent.
- 2.11 – Consent must also be separate from other terms and conditions and specifically cover:
- The firms (Controllers) name
-
- The name of any third part Controller who will rely on the consent
-
- Why the firm wants the data (purpose of processing)
-
- What the firm will do with it (types of processing activity); and
-
- That the individual can withdraw their consent at any time and how they can do this.
- 2.12 – To evidence that the above is obtained the firm has put in place a Consent Register to record the individuals name, time and date of when consent was obtained, the means of consent (verbal / email) and what the individual has consented to.
- 2.13 – The GDPR gives a specific right to withdraw consent, which the customer is informed of when consent is obtained.
- 2.14 – In addition, the lawful basis ‘consent’ can only be used where the individual can withdraw their consent. Therefore, care must be taken to not use the lawful basis where the customer cannot withdraw their consent.
- 2.15 – The firm regularly reviews consents to check that the relationship and the processing and purposes have not changed. Where it has, and if required, individuals consent will be refreshed.
- 2.16 – Where an individual wishes to withdraw its consent then this will be actioned as soon as possible and records updated accordingly.
Consent – Marketing
- 2.17 – The firm will always ensure that customers have the right to object to processing for the purposes of marketing no matter what lawful basis is used, as set out in the GDPR individual rights requirements.
- 2.18 – The firm can rely on the lawful basis legitimate interests when sending marketing material to customers. However, it must be deemed as material the customer would reasonably expect to receive, such as information about products the customer has previously purchased.
- 2.19 – Where an individual is no longer a customer or has never been a customer then the firm will obtain the individuals consent to market to them.
- 2.20 – Where explicit consent is required it must be done so expressly confirming in words, rather than by any other positive action. For example, ‘I consent to receive emails regarding insurance products and offers [ ]’.
Consent – Website
- 2.21 – Where an individual completes a form online to either be contacted to discuss a particular product or obtain a quote then they will have been deemed to be making a positive action for their data to be used for that purpose.
- 2.22 – However, by submitting the form they are not consenting to any further uses such as marketing.
- 2.23 – As such, the firm ensures that it is clear what the individuals data will be used for along with a separate section to obtain consent from the individual to receive marketing and/or any other purposes, if required.
Consent – Record Keeping
- 2.24 – The firm maintains a record of who, when and how consent was obtained along with what the individual consented to. This includes the individuals name, the date and time consent was provided, by what means (verbal / email) and what they consented to. This provides evidence that consent was obtained.
- 2.25 – The GDPR does not set a specific time limit on consent. However, consent is likely to degrade over time, but how long it lasts will depend on the context.
- 2.26 – As consent will only be used for marketing purposes then it should continue to be deemed relevant. For example if the firm is continually marketing to an individual this will continue until such time it is deemed no longer required.
- 2.27 – Where the firms processing operations or purposes evolve then fresh consent would be obtained.
- 2.28 – Seico Insurance & Mortgages Limited actively manages consent by:
- Regularly reviewing consents to check that the relationship, the processing and the purposes have not changed;
- Having processes in place to refresh consent at appropriate intervals;
- Making it easy for individuals to withdraw their consent at any time and publicise how to do so;
- Acting on withdrawals of consent as soon as possible;
- Not penalising individuals who wish to withdraw consent.
Legal Obligation
- 2.29 – There are certain instances whereby the firm has a legal obligation to provide personal information to comply with the law. An example of this is that the firm has a legal obligation under the Proceeds of Crime Act to process data in order to submit a Suspicious Activity Report to the National Crime Agency when it knows or suspects that a person is engaged in, or attempting, money laundering.
- 2.30 – As such, the firm has included a section within its Privacy Notice to inform individuals that their information maybe passed on when the firm has a legal obligation to do so.
- 2.31 – Regulatory requirements also qualify as a legal obligation for these purposes where there is a statutory basis underpinning the regulatory regime and which requires regulated obligations. As the firm is regulated by the FCA then they may require sight of client files therefore the firm has ensured that this is also covered within the firms Privacy Notice.
Legitimate Interests
- 2.32 – The firm uses the legal basis legitimate interests to process customer information and to contact them at renewal or review date of a regulated product.
- 2.33 – To be able to demonstrate compliance under the GDPR accountability principle the firm has outlined the reasons why it has decided that the lawful basis legitimate interests is the most suitable for processing individuals data to arrange a regulated product and then retain their information on file by completing a legitimate interests assessment (LIA). A summary of which is contained below.
- 2.34 – Article 6(1)(f) states that the lawful basis legitimate interests maybe used for processing where:
Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party except where such interests are overridden by the interest or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Legitimate Interests Assessment – LIA
- 2.35 – The firm has carried out a LIA to assess whether the lawful basis legitimate interests is the most suitable basis to use. A copy of this test is held on file and will be continually updated where relevant. A summary of the test carried out is as follows:
- Purpose Test: identify a legitimate interest.
-
- Necessity Test: is the processing necessary for that purpose
-
- Balancing Test: does the individuals interests override the legitimate interest
- 2.36 – Legitimate interests is the most flexible lawful basis for processing and is the most appropriate in terms of holding and processing customers personal data. As a regulated firm, and as part of the purpose test, the firm has a legitimate interest/reason to obtain the customers data so that it can arrange a regulated product on their behalf.
- 2.37 – When completing the Purpose Test the following was considered:
- Why does the firm want to process the data and what is it trying to achieve;
-
- Who benefits from the processing and in what way;
-
- What would be the impact if the firm couldn’t go ahead;
-
- Would the use of the data be unethical or unlawful in any way.
- 2.38 – The ‘Necessity Test’ requires that the processing must be necessary to achieve the purpose. There must also be no other lawful basis that could be used. As the firm has a duty to hold client data for a specific period of time to meet the Financial Conduct Authority rules, it wouldn’t be able to use the lawful basis consent as that has a requirement to provide customers with the right to withdraw their consent and be forgotten. Therefore, as the firm has a legal requirement to hold onto data it could not use the consent lawful basis. If it did it would do so falsely as it could not give the customer the right to withdraw. Therefore, all data held on customer files is done so under the legitimate interests lawful basis and therefore meets the Necessity Test.
- 2.39 – The following was also taken into consideration when completing the Necessity Test:
- Does the processing actually help to achieve the firms purpose;
-
- Could the firm achieve the same purpose without the processing and is there any other reasonable way to go about it;
-
- Is there another less intrusive way to achieve the same result.
- 2.40 – The firm has also carried out a Balancing Test. To do this the firm has balanced its interests against the individual’s interests. In particular, it has considered that the individual would reasonably expect the firm to use their personal data to arrange a regulated product and then keep in contact at renewal/review therefore meeting the Balancing Test.
- 2.41 – As part of the balancing test the firm has considered:
- The nature of the relationship with the individual;
- Would the individual expect their data to be used in this way;
- If some individuals are likely to object or find it intrusive;
- The possible impact on the individual.
- 2.42 – Recital 47 indicates that if the individual does not reasonably expect the processing, their rights may override the firms legitimate interests. Therefore, care is taken to ensure that the processing carried out using the lawful basis legitimate interests would reasonably be expected by the individual.
- 2.43 – When determining whether the individual would reasonably expect the processing to occur the following factors were taken into consideration:
- How long ago the data was collected;
- The source of the data – where the data was obtained from;
- The precise nature of any existing relationship with the individual and how the firm has used their data in the past; and
- Whether the firm is using any new technology or processing data in a way that individuals would not have anticipated – or conversely whether there are any developments in technology or updates to services which individuals have come to expect.
- 2.44 – The firm will also use the lawful basis legitimate interests to pass personal data onto a Lender or Insurer so that they are able to offer a contract with the individual. The individual will expect that the firm will pass the details on therefore meeting the Legitimate Interests Assessment.
- 2.45 – The firm will only use the lawful basis legitimate interests where it has carried out the three-part test to ensure it is suitable. The firm will not use the basis of legitimate interests in the following circumstances:
- The processing does not comply with broader legal, ethical or industry standards;
- The firm doesn’t have a clear purpose and is keeping the data ‘just in case’;
- The firm could achieve the end result without using personal data;
- The firm intends to use the personal data in ways people are not aware of and do not expect;
- The firm is not confident on the outcome of the balancing test;
- Another lawful basis more obviously applies to a particular purpose.
- 2.46 – When using the legitimate interests to process data, the customers right to data portability does not apply. This is noted within the firms Privacy Notice.
Legitimate Interests – Marketing
- 2.47 – Where the firm uses the lawful basis legitimate interests for direct marketing the customer has the right to object at anytime. If they object the firm will cease all marketing unless the firm can demonstrate that its legitimate interests are compelling enough to override the individuals rights.
Legitimate Interests – Record Keeping
- 2.48 – Seico Insurance & Mortgages Limited has identified where the lawful basis legitimate interests is the most appropriate and therefore has:
- Completed a Legitimate Interests Assessment (LIA) to justify the firms decision;
-
- Checked that the processing is necessary and there is no less intrusive way to achieve the same result;
-
- Assessed that individuals will reasonably expect their data being used for the purpose of processing;
-
- Put a process in place to keep the firms LIA and Privacy Notice under review and change/update where relevant;
-
- Included information about the firms legitimate interests in the Privacy Notice.
- 2.49 – The firm will keep a copy of all of the above along with an audit trail of changes for a period of at least six years. Where it is decided that a document should be held for longer then a note will be made on the file confirming the reason.
3. INDIVIDUAL RIGHTS
- 3.1 – The GDPR provides individuals with rights, these are:
- The right to be informed – The customer has the right to be informed on how the firm uses, shares and stores personal information on them.
-
- The right of access – The customer has the right to request access about the personal data the firm holds on them. (This is also known as a Subject Access Request (SAR)). Where a SAR is requested the firm will respond promptly and within one month from the date it receives the request.
-
- The right to rectification – The customer has the right to request that the firm amends inaccurate or incomplete personal data on them.
-
- The right to erasure – The customer has the right for its personal data to be erased, where there is no compelling reason for its continued processing and the firm doesn’t have a legitimate interest to retain it.
-
- The right to restrict processing – The customer can request that the processing of their personal data is restricted.
-
- The right to data portability – the customer has the right to obtain and reuse its personal data for its own purposes across different services. However, where the firm processes data under the lawful basis legitimate interests then the right to portability does not apply.
-
- The right to object – The customer has the right to object to its personal data being processed.
-
- Rights in relation to automated decision making and profiling – The customer has the right not be subject to a decision when it is based on automated processing and produces a legal effect on the individual.
The right to be informed
- 3.2 – The right to be informed encompasses the firms obligation to provide fair processing information and the need for transparency over how personal data is used.
- 3.3 – This is detailed with the firms Privacy Notice which includes:
- The firms identity and contact details;
- The purpose of processing and the lawful basis for that processing;
- The existence of each data subjects rights;
- The right to withdraw consent at any time, if applicable;
- The right to lodge a complaint;
- The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences.
The right to access (Subject Access Requests SAR)
- 3.4 – Under the GDPR, individuals have the right to obtain confirmation that their data is being processed as expected and have access to their personal data.
- 3.5 – When a client makes a request for copies of personal data held about them, it is known as a ‘Subject Access Request’ (SAR).
- 3.6 – Previously, the DPA allowed firms to charge a fee of £10 for a SAR request. However, the GDPR has removed this charge.
- 3.7 – Firms can charge a reasonable fee when a request is manifestly unfounded or excessive, particularly if the customer repeatedly requests a copy. Where a charge is applied it must be based on the administrative cost of providing the information and a note made on the file.
- 3.8 – Where a SAR request has been received the information must be provided without delay and at the latest; within one month of receipt of the request. This period maybe extended by a further two months where requests are complex or numerous however the individual must be informed of this fact within one month of the request along with the reason why it will take longer.
The right to rectification
- 3.9 – Individuals are entitled to have personal data rectified if it is inaccurate or incomplete.
- 3.10 – Where the firm receives a request for information to be updated the firm will update the individuals data as required and respond to the individual within one month of their request.
- 3.11 – Where the data has been disclosed to a third party the firm will inform them of the rectification wherever possible. This will also be confirmed to the individual when responding to their request.
The right to erasure
- 3.12 – The right to erasure is also known as the right to be forgotten.
- 3.13 – The broad principle underpinning this right is to enable the individual to request the deletion or removal of personal data where there is no compelling reason for its continued processing.
- 3.14 – The right to erasure does not provide an absolute right to be forgotten. Individuals have a right to have personal data erased and to prevent processing in specific circumstances:
- Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed;
- When the individual withdraws consent (where the firm uses the lawful basis of consent);
- When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing;
- The personal data was unlawfully processed;
- The personal data has to be erased in order to comply with a legal obligation.
- 3.15 – Where the firm has disclosed the personal data in question to third parties then the firm will inform them about the erasure of the personal data, unless it is impossible or involves disproportionate effort to do so.
The right to restrict processing
- 3.16 – Under the DPA individuals had a right to block or suppress processing of personal data. This restriction is similar under the GDPR.
- 3.17 – Where processing is restricted the firm is permitted to store the personal data, but not process it. The firm can retain just enough information about the individual to ensure that the restriction is respected in future.
- 3.18 – The firm will restrict the processing of personal data in the following circumstances:
- Where an individual contests the accuracy of the personal data. Where this occurs the data will be restricted from processing until the accuracy of the personal data has been verified;
- Where an individual has objected to the processing and the firm is considering whether it has legitimate grounds to override those of the individual;
- When processing is unlawful and the individual opposes erasure and requests restriction instead;
- If the firm no longer needs the personal data but the individual requires the data to establish, exercise or defend a legal claim.
- 3.19 – Where the personal data is disclosed to a third party the firm will inform them about the restriction on processing personal data, unless it is impossible or involves disproportionate effort to do so.
The right to data portability
- 3.20 – The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services.
- 3.21 – The right to data portability will only apply:
- To personal data an individual has provided to a Controller;
- Where the processing is based on the individuals consent;
- When processing is carried out by automated means.
- 3.22 – Where the firm uses the lawful basis legitimate interests then the right to data portability will not apply.
The right to object
- 3.23 – Individuals have the right to object to processing based on legitimate interests (including profiling). Unless, the firm can demonstrate it has compelling legitimate grounds for the processing, which overrides the interests, rights and freedoms of the individual. Or, the processing is for the establishment, exercise or defence of legal claims.
- 3.24 – The individual also has the right to object to receiving direct marketing (including profiling for this purpose) or processing for the purposes of statistics.
- 3.25 – Where an individual uses its right to object then the firm will stop processing their personal data for this purpose as soon as possible.
Rights related to automated decision making and profiling
- 3.26 – The GDPR provides safeguards for individuals against the risk that a potentially damaging decision is taken without human intervention. Individuals have the right not to be subject to a decision when:
- It is based on automated processing; and
- It produces a legal effect or a similarly significant effect on the individual.
- 3.27 – All decisions made within the firm regarding the sales process has human intervention therefore minimising the risk that this would occur.
4. PRIVACY NOTICE
- 4.1 – The GDPR requires personal data to be processed fairly and lawfully and that firms are transparent about who they are and what they will do with their data. Providing individuals with a Privacy Notice is an important part of meeting this requirement.
- 4.2 – As such, the firms Privacy Notice includes information that is transparent about the lawful basis applied along with the purpose for processing customer data.
- 4.3 – In addition the below was taken into consideration when producing a Privacy Notice:
- The firms name and contact details;
- What information is being collected;
- How is it collected;
- Why is it collected;
- What the firm will do with their information;
- Who will it be shared with;
- What will be the effect of this on the individuals concerned;
- Is the intended use likely to cause individuals to object or complain.
Confirmation of Consent
- 4.4 – Consent is required to be obtained separately from the Privacy Notice or any other Terms of Business type document. The firm has therefore adopted this policy.
- 4.5 – The firm has however mentioned when consent would be required and why within its Privacy Notice to be transparent of each lawful basis used.
Privacy Notice Communication
- 4.6 – The Privacy Notice will be issued:
- As soon as possible to any individual that expresses an interest in the firms services or at the very latest when personal data is collected from them;
- At renewal, as a reminder to how the firm holds and uses it data;
- When taking out another product;
- When asked for a copy.
- 4.7 – Generally the Privacy Notice will be issued at the same time as the firms Terms of Business / Disclosure Document.
- 4.8 – Where communication is by phone / email then a copy of the Privacy Notice will be emailed to the individual at the outset so that they understand how the firm will use their data provided.
- 4.9 – Where an individual visits the firms website then a copy of the Privacy Notice will be made clearly available on the page that an individual would complete their data. There attention will also be drawn to read the Privacy Notice prior to providing any data.
Privacy Notice Accuracy/Review
- 4.10 – The Privacy Notice will be reviewed at least annually to ensure that it remains accurate and up to date.
- 4.11 – In addition the Privacy Notice will be reviewed whenever the firm changes or updates a process. This is to ensure that the Privacy Notice is up to date and relevant.
- 4.12 – If the firm plans to use personal data for a new purpose its Privacy Notice will be updated and a copy sent to customers.
5. DATA RECEIVED FROM A THIRD PARY
- 5.1 – Any data received from a third party will be processed in the manor expected.
- 5.2 – Where the data is obtained from a third party such as a Lead Generator then the firm will ensure that they have obtained consent from the customer.
- 5.3 – As part of this the firm will expect to receive written notification from the Lead Generator to include:
- Confirmation that the customer has given their consent and that it is GDPR compliant;
- The customer is clear what they have consented to;
- The customer is clear that their data will be passed to the firm and for what purpose;
- The customer is expecting a call/email from the firm.
Third Party Due Diligence
- 5.4 – The firm will carry out due diligence on any lead generation firms it decides to use.
- 5.5 – This will include carrying out back ground checks such as, but not limited to, google search, the firm has a data protection license, Companies House check.
- 5.6 – The firm will also request a copy of the lead generators Private Notice.
6. BREACH / FORMAL NOTIFICATION REPORTING
- 6.1 – On identification of a data breach, no matter how small or large, reportable or not, it must be reported to the DPO immediately.
- 6.2 – Following receipt of such a notification the DPO will quickly establish whether a personal data breach has occurred, the likelihood of the risk to individual’s rights and freedoms, the severity and, where relevant, take steps to promptly address it.
- 6.3 – Where a breach has occurred, the DPO will record all facts, its effects and any remedial action taken, if any, on the firms Data Protection Register.
- 6.4 – As with any security incident, the DPO will investigate whether or not the breach was a result of human error or a systemic issue and will take steps to prevent any reoccurrence.
- 6.5 – Human error is the leading cause of reported data breaches; therefore the firm will continually consider how to reduce the risk through:
- Data protection training;
- Support and supervision of employees until they are proficient in their role;
- Updating policies and procedures, and implementing a culture of trust so employees feel able to report incidents or near misses;
- Working to a principle of ‘check twice, send once’;
- Investigating the root causes of breaches and near misses; and
- Protecting employees and personal data the firm is responsible for. This could include restricting access and auditing systems, or implementing technical and organisational measures.
Customer Notification
- 6.6 – Where a breach is likely to result in a high risk to the customers rights and freedoms, the DPO will notify them directly as soon as possible and without undue delay.
- 6.7 – As part of this the DPO will assess both the severity of the potential or actual impact on individuals. Where the breach is likely to affect individuals then they will be notified so that they can mitigate any immediate risk of damage and take steps to protect themselves.
- 6.8 – Should the DPO decide not to notify individuals, they may still need to notify the ICO, unless they can demonstrate that the breach is unlikely to result in a risk of the individuals rights and freedoms. Refer to Reportable Data Breach Section below for details.
- 6.9 – In any event, the DPO will record their decision-making process on whether to notify individuals or not within the Data Protection Register.
- 6.10 – When reporting a breach to an individual the DPO will, in a clear and plain language:
- Provide their contact details, or other contact point where more information can be obtained;
- Describe the nature of the personal data breach;
- Describe the likely consequences of the personal data breach;
- Describe the measures taken or proposed to deal with the personal data breach and, where appropriate, a description of the measures taken to mitigate any possible adverse effects; and
- Where possible provide advice on any steps individuals can take to protect themselves, such as:
-
-
- Forcing a password reset;
- Advising individuals to use strong, unique passwords; and
- Advising them to look out for phishing emails or fraudulent activities on their accounts.
-
Reportable Data Breach
- 6.11 – When a personal data breach has occurred, the obligation to notify the ICO is only triggered if the breach is likely to ‘result in a risk to the rights and freedoms of natural persons’.
- 6.12 – The General Data Protection Regulations does not provide a clear definition of what a ‘risk to the rights and freedoms of natural persons’ entails. Recital 75 of GDPR provides potential situations where such a risk is likely to result. For example, identify theft or fraud, financial loss, loss of confidentiality of personal data.
- 6.13 – The WP29 Notification Guidelines however provides further guidance on how to assess a risk, to establish whether the breach is reportable. With this in mind, the firm will objectively consider the likelihood and severity of the impact of the breach along with the following:
- The category in which the breach falls;
- The quantity of personal data breached and its sensitivity;
- How easily individuals can be identified;
- How serious the consequences of the breach are to individuals;
- Whether individuals affected are particularly vulnerable;
- Whether the firm, as a controller, has a particular role that may entail a high risk (e.g. a health-related controller); and
- The size of the breach in terms of numbers of individuals affected.
- 6.14 – Where a breach is reportable the DPO will make a formal notification to the Information Commissioner, without undue delay and, where feasible, within 72 hours of becoming aware of the breach, via the ICO website address:
Website: www.ico.org.uk
Information line: 0303 123 1113
- 6.15 – Where a reportable breach will take longer than 72 hours, the DPO will provide the ICO with the information they have along with a full explanation to the reasons for the delay.
- 6.16 – In addition to the above, the DPO will consider notifying third parties such as the police, insurers, professional bodies, or bank or credit card companies who can help reduce the risk of financial loss to individuals.
- 6.17 – When reporting a breach to the ICO, the DPO will provide:
- A description of the nature of the personal data breach including, where possible, the categories and approximate number of individuals and personal data records concerned;
- Their contact details, or other contact point where more information can be obtained;
- A description of the likely consequences of the personal data breach; and
- A description of the measures taken, or proposed to be taken, to deal with the personal data breach and, where appropriate, of the measures taken to mitigate any possible adverse effects.
- 6.18 – A summary of the GDPR and further guidance can be found on their website: www.ico.gov.uk
Data Protection Manual
Ecompli (UK) Limited is a compliance support firm who specifically assists Mortgage Brokers (inc Equity Release), Insurance Brokers and Insurance Claim Handlers. As such all documents are produced with these types of firms in mind. Where a document is specifically produced for just one of these areas it will be noted as such within the title.
Ecompli has taken due care in the preparation of this document. It has been prepared based on the Financial Conduct Authority rules at the time of being produced.
This manual has also been prepared using the GDPR rules. Firms should note that whilst this manual and other GDPR documents have been produced in line with the ICO/GDPR rules, Ecompli are not GDPR specialists and therefore firms should appoint their Solicitor for advice and review.
Firms using this manual should also ensure that it meets their requirements and make any changes necessary. Firms should ensure that they replace this document with any updated versions.
Ecompli do not accept any liability to any firm or third party for any loss arising out of / or in connection with this document. Nor does it accept any errors and / or omissions that arise out of such information / documentation.
Ecompli (UK) Limited
Business First Business Centre
Davyfield Road
Blackbu
Lancashire
BB1 2QY
Tel: 01254 675 674
Website: www.ecompli.co.uk
