This page is provided for general company policy information. It should be read alongside Greystone Labour Ltd's Privacy Policy, Cookie Policy, Terms & Conditions and any worker/client agreements that apply.
1. Purpose
The purpose of this Data Protection Policy is to ensure that Greystone Labour Ltd processes personal data lawfully, fairly, transparently, and securely in compliance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018 where applicable.
2. Scope
This policy applies to:
All employees, contractors, consultants, temporary staff, and third parties.
All personal data processed by Greystone Labour Ltd in electronic or paper format.
All systems, applications, devices, and services used to process personal data.
3. Definitions
Personal Data Any information relating to an identified or identifiable natural person.
Special Category Data Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health information, or data concerning a person's sex life or sexual orientation.
Processing Any operation performed on personal data, including collection, storage, use, disclosure, alteration, transfer, or deletion.
Data Subject An individual whose personal data is processed.
4. Data Protection Principles
Greystone Labour Ltd shall process personal data according to the following principles:
Lawfulness, fairness, and transparency.
Purpose limitation.
Data minimization.
Accuracy.
Storage limitation.
Integrity and confidentiality.
Accountability.
5. Lawful Basis for Processing
Personal data shall only be processed where there is a lawful basis, including:
Consent.
Performance of a contract.
Compliance with a legal obligation.
Protection of vital interests.
Performance of a task carried out in the public interest.
Legitimate interests where applicable.
6. Collection of Personal Data
Greystone Labour Ltd shall:
Collect only the personal data necessary for legitimate business purposes.
Inform individuals about how their information will be used.
Ensure transparency through privacy notices.
Avoid excessive or unnecessary data collection.
7. Use of Personal Data
Personal data shall be used only for:
Employment administration.
Customer relationship management.
Service delivery.
Supplier management.
Legal and regulatory compliance.
Security and fraud prevention.
Other purposes communicated to the individual.
8. Special Category Data
Special category data shall:
Be processed only where legally permitted.
Receive enhanced protection.
Be accessible only to authorized personnel.
Be encrypted where appropriate.
9. Data Security
Greystone Labour Ltd shall implement appropriate technical and Greystone Labour Ltdal measures including:
Access controls.
Strong authentication.
Encryption.
Secure backups.
Anti-malware protection.
Firewalls.
Security monitoring.
Regular vulnerability assessments.
Security awareness training.
10. Access Control
Access to personal data shall:
Be granted on a need-to-know basis.
Follow the principle of least privilege.
Be reviewed regularly.
Be removed promptly when no longer required.
11. Data Retention
Personal data shall:
Be retained only as long as necessary.
Follow documented retention schedules.
Be securely destroyed when no longer required.
12. Data Sharing
Personal data may only be shared:
Where there is a lawful basis.
Under appropriate contractual safeguards.
With approved processors.
In accordance with applicable legal requirements.
International transfers shall comply with applicable GDPR transfer requirements.
13. Individual Rights
Greystone Labour Ltd respects the rights of individuals, including:
Right to be informed.
Right of access.
Right to rectification.
Right to erasure ("right to be forgotten"), where applicable.
Right to restrict processing.
Right to data portability.
Right to object.
Rights relating to automated decision-making and profiling.
Requests shall be handled within applicable legal timeframes.
14. Data Breach Management
All suspected or actual personal data breaches shall:
Be reported immediately to the appropriate manager or Data Protection Officer (DPO).
Be investigated promptly.
Be documented.
Be reported to the relevant supervisory authority where legally required.
Be communicated to affected individuals where required by law.
15. Employee Responsibilities
Employees shall:
Protect personal data.
Follow this policy and related procedures.
Complete mandatory data protection training.
Report suspected data breaches immediately.
Use personal data only for authorized business purposes.
16. Third-Party Processors
Before engaging third parties, Greystone Labour Ltd shall:
Conduct appropriate due diligence.
Ensure written data processing agreements are in place.
Verify adequate security measures.
Monitor compliance where appropriate.
17. Data Protection by Design and Default
Privacy and data protection shall be considered during:
System design.
Software development.
Procurement.
Business process changes.
New projects involving personal data.
Where required, Data Protection Impact Assessments (DPIAs) shall be conducted.
18. Training and Awareness
Greystone Labour Ltd shall provide:
Data protection training for all employees.
Refresher training at regular intervals.
Role-specific training where appropriate.
19. Monitoring and Compliance
Compliance with this policy shall be monitored through:
Internal audits.
Risk assessments.
Management reviews.
Incident reporting.
Corrective actions where necessary.
Failure to comply with this policy may result in disciplinary action and, where applicable, legal consequences.
20. Policy Review
This policy shall be reviewed:
At least annually.
Following changes in legislation or regulatory guidance.
Following significant data protection incidents.
Following major Greystone Labour Ltdal or technological changes.
