TSL GDPR Compliance Statement
TSL4Training/TSL Holistic Centre 75 Wood Gate Loughborough, Leicestershire LE11 2TZ
GDPR Compliance Statement 19th May 2018 – Directors David Vickers & Helen Vickers
The General Data Protection Regulation (GDPR) comes into force in the UK (and across the EU) on 25 May 2018. The GDPR, which will replace the Data Protection Directive (95/46/EC), aims to strengthen the security and protection of personal data in all Member States.
TSL4Training/TSL Holistic Centre 75 Wood Gate Loughborough Leicestershire LE11 2TZ
TSL4Training/TSL Holistic Centre is committed to the principles inherent in the GDPR and particularly to the concepts of privacy by design, the right to be forgotten, consent and a risk-based approach. In addition, we aim to ensure:
- transparency with regard to the use of data;
- that any processing is lawful, fair, transparent and necessary for a specific purpose;
- that data is accurate, kept up to date and removed when no longer necessary;
- that data is kept safely and securely.
Our Data Protection Officer (DPO)/appointed data protection person is David Vickers. They work to promote awareness of the GDPR throughout the organisation and to oversee the organisation’s commitment to best practice. They will inform and advise the organisation and monitor its compliance.
Right to be forgotten
TSL4Training/TSL Holistic Centre recognises the right to erasure, also known as the right to be forgotten, laid down in the GDPR. These will be acted on provided there is no compelling reason for continued processing and that the exemptions set out in the GDPR do not apply. These exemptions include where the personal data is processed for the exercise or defence of legal claims and to comply with a legal obligation for the performance of a public interest task or exercise of official authority.
Subject access requests
TSL4Training/TSL Holistic Centre recognises that individuals have the right to access their personal data and supplementary information and will comply with the one month time frame for responses set down in the GDPR. As a general rule, a copy of the requested information will be provided free of charge TSL4Training reserves the right to charge a “reasonable fee” when a request is manifestly unfounded or excessive, particularly if it is repetitive. If this proves necessary, the person concerned will be informed of their right to contest our decision with the supervisory authority (the Information Commissioner’s Office (ICO).
As set out in the GDPR, any fee will be notified in advance and will be based on the administrative cost of providing the information.
TSL4Training/TSL Holistic Centre will implement data protection “by design and by default”, as required by the GDPR. Safeguards will be built into products and services from the earliest stage of development and privacy-friendly default settings will be the norm. The privacy notice, which is on our website and which is provided to anyone from whom we collect data, explains our lawful basis for processing the data and gives the data retention periods. It makes clear that individuals have a right to complain to the ICO. TSL4Training has conducted a privacy impact assessment (PIA) to ensure that privacy risks have been properly considered and addressed.
Data transfers outside the EU – TSL4Training does not transfer personal data outside the EU.
The GDPR provides for special protection for children’s personal data and TSL4Training will comply with the requirement to obtain parental or guardian consent for any data processing activity involving anyone under the age of 16.
If a data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, the people affected will be informed as soon as possible and the ICO will be notified within 72 hours.
Any questions related to GDPR or to issues concerning data protection generally should initially be addressed to TSL 75 Wood Gate Loughborough Leicestershire LE11 2TZ David Vickers TSL Director of training.