
Effective 1st June, 2007
Introduction
YourSpecialDays is required to maintain certain personal data about living individuals for the purposes of satisfying operational and legal obligations. Yourspecialdays recognises the importance of the correct and lawful treatment of personal data; it maintains confidence in the organisation and provides for successful operations.
The types of personal data that YourSpecialDays may require includes information about: Yourspecialdays users; suppliers and others with whom it communicates. This personal data, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the Data Protection Act 1998.
YourSpecialDays fully endorses and adheres to the eight principles of the Data Protection Act. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data. Employees and any others who obtain, handle, process, transport and store personal data for Yourspecialdays must adhere to these principles.
Principles
The principles require that personal data shall:
Satisfaction of principles
In order to meet the requirements of the principles, YourSpecialDays will:
YourSpecialDays’ Designated Data Controller
YourSpecialDays’ Designated Data Controller is David Dorward, e-mail: data@yourspecialdays.co.uk . Any questions or concerns about the interpretation or operation of this policy should be taken up in the first instance with the Designated Data Controller.
Subject Access
All individuals who are the subject of personal data held by YourSpecialDays are entitled to:
Data Security
The need to ensure that data is kept securely means that precautions must be taken against physical loss or damage, and that both access and disclosure must be restricted. All staff are responsible for ensuring that:
Rights to Access Information
Any individual whose personal data is held by YourSpecialDays have the right to access any personal data that is being kept about them on computer and also have access to paper-based data held in certain manual filing systems. This right is subject to certain exemptions which are set out in the Data Protection Act. Any person who wishes to exercise this right should make the request in writing to Yourspecialdays’ Designated Data Controller.
YourSpecialDays reserves the right to charge the maximum fee payable for each subject access request. If personal details are inaccurate, they can be amended upon request.
YourSpecialDays aims to comply with requests for access to personal information as quickly as possible, but will ensure that it is provided within 40 days of receipt of a completed request unless there is good reason for delay. In such cases, the reason for delay will be explained in writing to the individual making the request.
Subject Consent
The need to process data for normal purposes has been communicated to all data subjects. In some cases, if the data is sensitive, for example information about health, race or gender, express consent to process the data must be obtained.
Retention of Data
YourSpecialDays will keep some forms of information for longer than others. YourSpecialDays will ensure that information is not kept for longer than necessary.