Statement of Intent
FiFi’s Fancy Furniture LLP is sometimes required to collect personal information for its customers and suppliers. We intend to meet all the requirements of the Data Protection Act 1998 (the Act) and the General Data Protection Regulations 2018 when collecting, storing, and destroying personal data.
To comply with the law, information must be collected and used fairly, stored safely and not disclosed to any other person unlawfully. To do this, FiFi’s Fancy Furniture LLP must comply with the Data Protection Principles which are set out in the Data Protection Act 1998. In summary these state that personal data must be:
- obtained and processed fairly and lawfully;
- obtained for a specified and lawful purpose and not processed in any manner incompatible with that purpose; adequate, relevant, and not excessive for that purpose;
- accurate and kept up to date;
- not kept for longer than is necessary;
- processed in accordance with the data subject’s rights;
- kept safe from unauthorised access, accidental loss, or destruction;
- not be transferred to a country outside the European Economic Area, unless that country has equivalent levels of protection for personal data.
All FiFi’s Fancy Furniture LLP staff who process or use any Personal Information must ensure that they follow these principles at all times. In order to ensure that this happens, FiFi’s Fancy Furniture LLP has adopted this Data Protection Policy.
Notification of Data Held and Processed
All suppliers and customers have the right to:
- know what information FiFi’s Fancy Furniture LLP holds and processes about them and why;
- know how to gain access to it;
- know how to keep it up to date;
- know what FiFi’s Fancy Furniture LLP is doing to comply with its obligations under the Act.
The Data Controller and the Designated Data Controllers
FIONA PARSONS of FiFi’s Fancy Furniture LLP is the Data Controller under the Act, and the organisation is therefore ultimately responsible for implementation.
Personal Information is defined as any details relating to a living, identifiable individual. Within FiFi’s Fancy Furniture LLP this relates to suppliers and customers. We need to ensure that the information gained from each individual is kept securely and to the appropriate level of confidentiality.
The personal information collected from individuals could include:
- Their name
- Email address
- Telephone numbers-
- Bank Details in some cases
Personal information should be:
- kept in a locked filing cabinet; or
- in a locked cupboard; or
- if it is computerised, be password protected;
- kept on a storage device which is itself kept securely.
Disposal of Confidential Material
Sensitive material should be shredded as soon as it is no longer needed; following retention guidelines and statutory requirements. Particular care should be taken to delete information from the tablets or the computer hard drive if they are to be disposed of.
Retention of Data
FiFi’s Fancy Furniture LLP takes care to only store personal information that is absolutely necessary.
Personal information is kept for the period of time requested following guidelines from the HMRC these retention periods are either recommended or statutory.
Stored information is filed in sealed filing boxes and locked in a cupboard. Once the retention period has lapsed, the information is destroyed.