Data protection and securityย
Little Lives UK’s privacy responsibilitiesย
Little Lives UK has a legal responsibility to protect the privacy of its staff, volunteers, customers, donors and supporters. We must all work together to make sure we uphold our regulatory and best practice obligations with regards to data in a professional, robust and trustworthy manner.ย
What is personal data?ย
Personal data means data relating to a living individual who can be identified from that data (or from other information in our possession). Personal data can be factual (such as name, address or date of birth) or it can be an opinion (such as a performance review). Sensitive personal data includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, medical conditions, sexual orientation or criminal record. Sensitive personal data can only be processed under strict conditions, and will usually require the explicit consent of the person concerned. We must take extra care when collecting, using or storing sensitive data.ย
Data protectionย
The Data Protection Act 1998 states that anyone processing personal data must comply with theย eight principles of good practice. These provide that personal data must be:ย
โช Processed fairly and lawfullyย
โช Processed for limited purposes and in an appropriate wayย
โช Adequate, relevant and not excessive for the purposeย
โช Accurate and up to dateย
โช Not kept longer than necessary for the purposeย
โช Processed in line with the data subjects’ rightsย
โช Kept secureย
โช Not transferred to people or organisations situated in countries without adequate protection.
What the law means for us
Getting this right is important as it helps strengthen the continued trust which our supporters place in the Little Lives UK. Getting it wrong could result in a loss of confidence by the public, the Little Lives UK being fined by the information Commissioner’s Office and our reputation being damaged.
What we need to do
The first thing is to fully understand why data protection is important, how you can help, and what to do if there is a problem.
Secure it
Any paper based information must be held securely in locked cabinets or cupboards. For example, when people share their personal details with us, if the Gift Aid form is not locked away immediately it is then open for anyone to see, which means the data could be copied. This is the same for paperwork completed for volunteers, work experience placements, stock collections and deliveries.
Shred it
If you have been authorised by your Manager or the Legal Team to dispose of a document containing personal data, you must use a cross- cut shredder, don’t just put it in the bin.
Protect it
Keep your passwords private and don’t write them down anywhere. Always log off’ the till and lock the back-office PC when you leave. Our shops have a lot of visitors so we must be vigilant around access to our data and systems.
Don’t share itย
Do not disclose any data about anyone else without their permission. Be aware that people may try to get you to give out personal information.ย
Subject Access Requestย
All individuals have the right to know what information an organisation holds about them and they can request a copy of this. This is called a Subject Access Request and must be made in writing to the organisation. If you receive such a request from a member of the public, a supporter, a volunteer or a member of staff please notify the person in charge in the shop. We are legally obliged to respond within 40 days so it is essential that you pass on any requests as soon as possible.ย
Data securityย
The Little Lives UK IT Security Policy sets out what is not permitted whilst using Little Lives UK IT equipment and systems. This covers all paid and unpaid employees, contractors, volunteers and any other people accessing Little Lives UK IT systems.ย
What we need to doย
Protect itย
When using the back-office computer, use passwords with a mixture of numbers and letters (upper / lower case) and symbols.ย
Keep it cleanย
Don’t install software or attach equipment, including memory sticks, to the till, back office or the network without authorisation or agreement. To protect us from malware (malicious software) and viruses, don’t open suspicious attachments or click on strange links. Delete spam or emailsย from addresses you don’t trust.ย
Wirelessย
If you are in a building with a wireless network, it must only be used for the business purpose for which it was installed.ย
Internet securityย
While a small amount of personal use is permitted access to the Internet is provided for business use and as such certain sites or categories are blocked automatically. The internet must not be usedย inappropriately including but not limited to the following:ย
โช To download software or any inappropriate or illegal materialย
โช To access the following categories: sexually explicit, gambling, fraud, hacking, illegalย
โช Drugs, violence, intolerance, terrorism and any other site that may affect the Little Lives UK`s reputationย
โช To conduct any form of internet bullying, racism, ethnic impropriety, age discrimination or sexual harassmentย
โช To access other sites such as social networking sites or chat rooms unless part of your business responsibilitiesย
โช For re-selling donated Little Lives UK stock for personal gain.ย
Email security
Email content is treated the same way as verbal or written information, and is admissible in a court of law. This also includes the use of other similar communication such as instant messaging, text orย video. While a small amount of personal use is permitted, email must not be used for the following:ย
โช Transmission of material which infringes copyright, is confidential Little Lives UK material or is deemed to be junk mail of any kindย
โช Activities that waste staff effort or networked resourcesย
โช The creation or transmission of any offensive, obscene or indecent material
โช The distribution of material deemed offensive, abusive, threatening, discriminatory or defamatoryย
โช The transmission of business data to home or personal accounts.ย
Now that you have completed the Data Protection and Data Security sectionย
Here are some specific questions for you to go through with your trainer:ย
Data Protection:ย
1. Read the ‘Data Protection Policy’ on the notice boardย
2. What is the key thing to remember about forms containing personal or sensitive personal data?ย
3. Who do you report a data protection breach to?ย
Data Security:ย
1. Read the IT Security Policy’ on the notice boardย
2. Can you install software or plug a USB stick into office computer?ย
3. Who do you report any IT security incidents to?