Data Protection Policy
Snorkel Commitment to Data Protection
At Snorkel Europe Ltd, we are committed to protecting the privacy and personal data of all individuals we work with, including employees, contractors, volunteers, apprentices, and others (collectively referred to as “relevant individuals”). We handle personal data in a transparent, secure, and lawful manner, in line with the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
This policy outlines our responsibilities, your rights, and the principles we follow when collecting, processing, storing, and sharing personal data.
Policy Purpose
This policy is designed to:
· Inform relevant individuals of their rights regarding personal data.
· Ensure compliance with applicable data protection laws.
· Promote best practices for the handling of personal information within the company.
This policy applies to:
· Current and former employees
· Apprentices and interns
· Volunteers and placement students
· Self-employed contractors
· Any individual whose personal data is processed by the company
Key Definitions
· Personal Data: Any information that can identify an individual, directly or indirectly.
· Special Categories of Data: Sensitive data such as health information, race, religion, or sexual orientation.
· Criminal Records Data: Details of criminal convictions or offences.
· Processing: Any operation involving personal data, such as collecting, storing, or deleting it.
We may hold the following personal information:
· Contact details (e.g. name, address, phone numbers)
· Recruitment details (e.g. CVs, references)
· Employment records (e.g. job title, performance data)
· Payroll and tax information
· Health and medical records
· Disciplinary and grievance records
· Training and development information
Data Protection Principles
We process personal data in line with the following key principles:
· Lawfulness, fairness and transparency
· Purpose limitation
· Data minimisation
· Accuracy
· Storage limitation
· Integrity and confidentiality (security)
· Accountability
We only process data for specified purposes and always ensure it is kept accurate and secure.
Individual Rights
As a data subject, you have the right to:
· Access your personal data (Subject Access Request)
· Request correction or deletion of inaccurate or outdated data
· Object to or restrict the processing of your data
· Request data portability (where applicable)
· To make a request, please contact Jane Simpson – HR Manager at jane.simpson@snorkellifts.com.
Subject Access Requests (SARs)
You have the right to request access to personal data we hold about you. To submit a SAR:
· Use the form available from the HR department or on the company intranet.
· Requests will be handled within one month (extendable for complex cases).
· Normally, we do not charge for requests unless excessive or repetitive.
Data Security
We implement appropriate technical and organisational measures to safeguard personal data. Employees must:
· Secure all confidential data (both digital and paper-based)
· Avoid sharing sensitive information through personal email accounts
· Use password-protected systems
· Not store data on unencrypted USBs or devices
· Breaches of data security may result in disciplinary action, including dismissal in serious cases.
Third-Party Data Processing
Where we share data with third parties (e.g. benefit providers or occupational health professionals), they are required to:
· Process data only under our instructions
· Maintain strict confidentiality
· Follow robust data security protocols
Data Breaches
We will report any data breaches that pose a risk to individual rights to the Information Commissioner’s Office (ICO) within 72 hours. Individuals affected by high-risk breaches will also be informed directly.
International Transfers
We do not transfer personal data outside the European Economic Area (EEA).
Data Retention
We retain personal data only as long as necessary. HR-related data is typically held for the duration of employment and up to six years post-termination, in accordance with our retention policy.
Impact Assessments
Where any processing may pose a high risk to individual rights (e.g. large-scale use of sensitive data), we will conduct a Data Protection Impact Assessment (DPIA) to evaluate and minimise potential risks.
Employee Responsibilities
All employees and contractors must:
· Only access personal data for legitimate purposes
· Keep data secure and confidential
· Notify the HR team of any changes to personal information
Failure to follow these responsibilities may lead to disciplinary action.
Training and Awareness
All new staff receive data protection training as part of their induction. Additional training is provided to those who regularly handle personal data or manage data-related responsibilities.
Snorkel Europe Ltd is dedicated to handling all personal data responsibly, ethically, and in line with the law.