GDPR – PRIVACY NOTICE
This notice sets out what data is collected, stored and processed, the reasons for collecting, storing and processing that data, where this data is stored, retention period of data, your rights regarding data and complaints procedure regarding data collection, storage and processing.
STATEMENT
ion IT Ltd is an ‘Internet service provider’ and a provider of ‘IT services and solutions’ namely to businesses but not limited to. GDPR covers ‘personal data’ and as a result of our business activities, some ’business information’ may cross over or be classed as ‘personal data’, for example, Joe Blogs Plumbing which we have classed as ‘business information’ clearly identifies Joe Blogs, a personal name, ‘personal data’. As business life often spills over in to personal life and the fact that many of our services are supplied at home or are accessed on a personal basis, these are the reasons we must become GDRP compliant. Any ‘personal data’ or ‘business information’, collected, processed or stored is done so mainly for the provision of ‘IT services and solutions’ and for providing ‘Internet services’. We respect how valuable your data is and thus treat it with the upmost respect and security.
DEFINITIONS
The Supplier / Controller is defined as;
ion IT Ltd. 180 Attercliffe Road Sheffield, S4 7WZ
The Client(s) is defined as;
You are the client. A business, company or an individual.
3rd Party Supplier(s) is defined as;
‘A supplier (or provider of services) who is not directly controlled by either ‘the supplier (first party) or ‘the customer’ (second party) in a business transaction.
Data Protection Officer is defined as;
An enterprise security leadership role required by the General Data Protection Regulation (GDPR). Data protection officers are responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR requirements.
EEA is defined as;
European economic area.
GDPR is defined as;
The Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data as applicable as of 25 May 2018, as may be amended from time to time.
ICO is defined as;
The UK Information Commissioner's Office.
Personal Data is defined as but is not limited to;
“Information and data relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.” An identifier is as described in the GDPR guidelines. This includes personal and business details and data but is not limited to, a company name, personal names, addresses, telephone numbers, IP Addresses, email accounts, location, server account and email access logs.
Business information is defined as but is not limited to;
“Information and data relating to a company or business”. This includes ‘personal data’ and business details and data but is not limited to, a company name, business contacts, business addresses, business telephone numbers, business IP Addresses, business email accounts, business location, server account and email access logs..
IT Services and Solutions is defined as but is not limited to;
“The provision and supply of IT software, hardware and services and facilities to businesses and individuals”. This includes the following email, email accounts, webhosting, websites and content management systems, server accounts, CPanel accounts, ftp accounts, broadband, leased lines, pstn lines, data backups on and off-site, domain names, IT support and consultancy, servers, PC’s, tablets, printers and peripherals, network equipment, network infrastructure”.
Internet Service Provider / Internet Services is defined as but is not limited to:
“The business of providing Internet access and facilities”. This includes email, email accounts, websites, website hosting, broadband, leased lines, co-located servers, server accounts, CPanel accounts, domain names, ftp accounts. In this case the Internet Service Provider is ion IT Ltd.
SME is defined as;
A small to medium enterprise company or business.
The Regulation is defined as;
Replaces. Data Protection Directive. Current legislation. The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union. It addresses the export of personal data outside the EU.
Special Categories / Sensitive Data is outlined by the ICO as;
Special category data broadly similar to the concept of sensitive personal data under the 1998 Act as race, ethnic origin,politics,religion, trade union membership, genetics, biometrics, health, sex life or sexual orientation.
EXEMPTIONS
As ion IT Ltd is an SME with less than 250 employees, certain exceptions apply. The Regulation acknowledges that many SME’s pose a smaller risk to the privacy of data subjects than larger organisations. For example, Article 30 of the Regulation states that organisations with fewer than 250 employees are not required to maintain a record of processing activities under its responsibility, unless “the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or personal data relating to criminal convictions and offences”.
A Data Protection Officer is only mandatory if data processing operations that require regular and systematic monitoring of data subjects on a large scale; or if Large-scale processing of special categories of data (i.e. sensitive data such as health, religion, race, sexual orientation, etc.) and personal data relating to criminal convictions and offences. As this is not this case, a Data Protection Office is not a requirement, but ion IT Ltd have decided to appoint one as one of our directors carries out a lot of the activities that make him a perfect candidate for the Data Protection Officer role. This includes ensuring backups are complete and off-site and stored securely, installing server updates, ensuring access to the network is limited where required, maintaining server and network security, checking for breaches of any type. This list is not exhaustive but gives an idea why he was elected as the Data Protection Officer.
As ion IT Ltd is an ‘Internet service provider’, we are not directly responsible for companies individual ‘personal data’, ‘business information’, special category’ or ‘sensitive data’ on co-located servers and or accounts on our servers, as this is the responsibility of the actual company or individual, ‘the client’ with whom the co-located server or server accounts belong. This is in respect to the content and the data and type of data stored or processed by ‘the client’. Ion IT Ltd acknowledges that they transact data on ‘the clients’ behalf for example email, web requests, but what is stored may come under ‘the clients’ own GDPR compliance where applicable or required.
SPECIAL CONSIDERATION
As ion IT Ltd is in the business of ‘IT services and solutions’ and providing ‘Internet services’ one service offered that particular attention should be drawn too is email. As ion IT Ltd process emails through their servers on ‘the clients’ behalf, it is noted by the ICO that “Another common method of sharing information is by email. By necessity the TO, FROM, DATE and SUBJECT fields of an email are transmitted in plain text and may be accessed by any unintended recipient or third-party who intercepts the communication. There are efforts to design and implement a secure email protocol however there is still currently no universally-adopted method for sending email securely”.
DATA COLLECTION AND USE
What data is collected, stored and processed?
‘The supplier’ collects, stores and processes ‘personal data’ and ‘business information’ as outlined in the definitions. No ‘special categories’ or ‘sensitive data’ as outlined is collected by ‘the supplier’.
Why is this data needed?
‘The supplier’ needs ‘personal data’ or ‘business information’ in order to provide ‘the client’ with ‘IT services and solutions’ and for providing ‘Internet services’ and also for the purposes of billing and accounting. ‘The supplier’ does not collect more data than is necessary in order to provide the services outlined to ‘the client’.
What is done with the data?
With the exception of a few ‘3rd party suppliers’ (details below), the majority of the ‘personal data’ and ‘business information’ collected by ‘the supplier’ is stored and processed personally by ‘the supplier’ in UK, Sheffield. This information is stored and processed on ‘the supplier’ servers here in the UK, Sheffield.
As ‘the supplier’ is in the business of ‘IT services and solutions’ and ‘Internet services’ it is necessary at times to share your ‘personal data’ and ‘business information’ with ‘3rd party suppliers’ in order to provide the services outlined. ‘The supplier’ uses ‘3rd party suppliers’ that are GDPR compliant and reside in the EEA for example, Nominet, BT for the provision of ‘IT services and solutions’ and ‘Internet services’ with the exception of some domain registrars that reside in the USA. These American domain registrars are bound by Eighth Data Protection Principle - United States Privacy Act, the Safe Harbor Act and the Health Insurance Portability and Accountability Act.
How long is data kept?
‘The supplier’ is required under UK tax law to keep ‘personal data’ and ‘business information’ for a minimum of 6 years after which time it will be destroyed. ‘Personal data’ and ‘business information’ not covered by the UK tax laws or any other laws in relation to ‘the client’ may be kept indefinitely until ‘the supplier’ no longer provides ‘IT services and solutions’ and ‘Internet services’ to ‘the client’ or until the data is no longer required at which point it will be removed or deleted. This covers server accounts, CPanel accounts, ftp accounts, email accounts, emails, backups, cloud storage, websites and CMS systems.
What further is done with the data?
Nothing further other than that already outlined is done with ‘personal data’ or ‘business information’. ‘Personal data’ and ‘business information’ is never shared with ‘3rd party suppliers’ that are not pertinent to the supply of ‘IT services and solutions’ and ‘Internet services’. ‘Personal data’ and ‘business information’ is never passed to marketing companies and is never sold, period.
What happens if a data breach is detected?
If a data breach is detected or other serious data incident occurs whether it be ‘personal data’ or ‘business information’, we consult with the individual or business, ‘the client’ concerned first.
The aim is to stop the breach as quick as possible by closing accounts or changing passwords or by killing off the process if possible. Stop the breach by any means possible!
Next, analyse and investigate the breach and apply appropriate fixes and security measures. See if the breach could be linked to a possible further breach and take any further action required.
Report any data breach or other serious data incident should it be required by law under ‘personal data’ GDPR or for a criminal investigation should it be deemed necessary.
Finally, document any data breach.
Client rights
If at any point ‘the client’ believes the information that ‘the supplier’ has collected, stored or processed regarding ‘personal data’ or ‘business information’ is incorrect ‘the client’ may request at any time, free of charge, to see any information ‘the supplier’ currently holds. Any ‘personal data’ or ‘business information’ not required by UK tax law or held for the provision of business ‘IT services and solutions’ and ‘Internet services’ can be requested to be removed immediately and erased. If you wish to raise a complaint on how ‘the supplier’ handles ‘personal data’ or ‘business information’, you can contact ‘the suppliers’ Data Protection Officer who will investigate the matter and report back in a timely manner.‘The supplier’ Data Protection Office is Mr Steven Jackson and he can be contacted via email or telephone.
If ‘the client’ believes ‘the supplier’ is collecting, storing or processing any ‘personal data’ or ‘business information’ not in accordance with the GDPR regulation, you can make a complaint to the Information Commissioner’s Office (ICO).