How do you keep my data secure?
When you trust us with your personal data, you expect us to keep it safe. We know that we have an obligation to you, and in law, to ensure the confidentiality, integrity and availability of our systems and the data within them. We take this very seriously indeed.
We have a number of technical and organisational measures in place that are designed to protect the security of the data that we hold. We carry out regular information risk assessments to ensure that they remain appropriate, effective and up-to-date. This page gives some examples of measures we currently take and explains a little bit about them.
Culture
At Key, data protection is everyone’s responsibility. We cultivate a working environment where privacy and security are central to decision-making, and issues are never overlooked. Here’s how we do this:
- Our staff have all completed our GDPR training programme. Everyone has a general understanding of the GDPR and our responsibilities, as well as specific knowledge of how it affects their own job. We’re all expected to be familiar with our privacy policy and to comply with it.
- We choose our data processors carefully. We only work with trusted partners who have appropriate security credentials. We include GDPR clauses in our contracts with suppliers.
- Staff are expected to report any data breaches they become aware of, no matter how minor, so that we can respond appropriately.
- When we begin any new project we take a ‘privacy by design’ approach, meaning we make data protection a key consideration right from the start.
- We carry out data protection impact assessments whenever they’re needed.
- Our teams are encouraged to question why we do things, which helps us to identify when we no longer need to do a certain type of data processing.
- We employ a fulltime on-site IT Manager, who has the appropriate resources and authority to implement all necessary data security measures.
- We have appointed someone in our business to take overall responsibility for data protection and privacy.
Accuracy
We have a responsibility to ensure that the data we hold about a person is accurate and complete. Since most of the data we collect about an individual comes directly from them, our risk in this area is minimised. We routinely encourage people to review their data for accuracy and make it as easy as possible for them to correct or update it.
Resilience
We have a robust plan in place for restoring access to data in the event of a physical or technical incident that interrupts availability. We regularly test our disaster recovery plan.
This FAQ forms part of our privacy policy.