On May 25, 2018, the General Data Protection Regulation (GDPR) became fully enforceable across the European Union (EU), creating a higher standard for data protection, privacy, and security for the processing of personal data from the EU. The GDPR applies to the processing of personal data (PII) regardless of where that takes place in the world and impacts any company that handles personal data of EU and by extension UK citizens and others within the EU / EEA.
In June 2022, The Data Protection Act 2018 applies in the UK specifying those Data Protection Principles that apply to all UK organisations that process data.
The Data Protection Principles include the following requirements:
UKGDPR adds some new requirements regarding how all businesses should protect individuals' personal data that they collect and process. We strongly believe that your data privacy is very important and, we already have solid security and privacy practices in place that go beyond the requirements of the UKGDPR.
We are committed to UKGDPR compliance in full. We offer a data processing addendum (DPA) for our customers and clients who collect data from citizens within UK. Our DPA offers contractual terms that meet UKGDPR requirements and that reflect our data privacy and security commitments to our customers, clients and where appropriate third-party vendors.
Our DPA / Data Processing Agreements and applicable addendums provide for our Terms of Service.
Yes, Our Terms and Conditions and associated agreements and addendums have been updated to reflect strict data protection requirements & compliance to ensure complete compliance and data safety.
An extensive standardised DPA has been added as an extension of our Terms and Conditions and includes both the relevant information on data processing along with a list of sub-processors.
By reviewing our product, its processes and procedures to make sure we meet the necessary UKGDPR standards:
Compliant. Updated policies and contract language and DPAs. Our Data Privacy Policy can be found on our Website
Compliant. Updated guidelines, implemented two-factor authentication where required, audited vendors and IT systems.
Compliant. Developed processes for SAR requests.
Compliant. Completed data mapping and inventory of systems that manage personal data, including implementation of data retention guidelines, data minimisation standards, and de-identification methods.
Compliant. Conducted training and implemented additional data controls at the functional level.
Compliant. Updated enterprise Security Incident Response Plans.
Compliant. We have appointed a Data Protection Officer. They can be contacted at iso@redflagert.com
We only work with industry standard service providers for Our Service to be able to supply a service that is up to the highest standards of availability, stability, security and privacy. In other words, we are building on the shoulders of giants.
Yes where applicable and used, we have in place written Data Processing Agreements (“DPA”) with all of Our Sub-Processors.
We have reviewed and identified all the areas of the Business where we collect and process Customer data; categorising and recording all data from cookies to help desk and User conversations. We have fully validated our legal basis for collecting and processing personal data and ensured that we are applying appropriate security and privacy safeguards across our entire infrastructure and software ecosystem.
We implement data impact assessments (DPIA) where this is a process requirement for UKGDPR in considering the processing of PII.
Any time we introduce a change to the way we handle personal data, a DPIA is conducted. Where a risk is identified, the Business will seek to mitigate the data privacy and security risk to anyone who interacts with our client platform. We will continue to execute this risk assessment process as we expand our business services and products.
Our Business has in place a breach management and communication plan. We constantly update our processes to comply with the UKGDPR regulations concerning the escalation process and requirements for data subject notification.
Users and customers are free to opt-out and be forgotten as per the DPA 2018 Right-To-Be-Forgotten principles. Where you seek to exercise your rights all relevant member data will be permanently deleted in our user database, and any peripheral data such as ideas will be transferred to an anonymous placeholder.
You’re always welcome to contact us in case you’d like to access, correct, amend or delete information that we hold about you.
We practice transparency internally and we believe that transparency extends to our Customers. With our updated Privacy Policies, we openly describe which personal data we are collecting, processing, why, how we use it, who we share it with and how long we store it. We have always made an effort to keep the language in our Privacy Policy as clear as possible and we have updated these notices to describe how we are respecting and protecting your personal data. We hope you find it concise, transparent, intelligible and easily accessible.
We continually review and where required update our cookie policy and other relevant and applicable policies to provide you with complete transparency into what is being set when you visit our site and how it's being used. Please refer to our cookie policy for further guidance and steps you can take in order to control how your browser handles cookies.
We are committed to helping our customers meet the data subject rights requirements of UKGDPR. We process or store all personal data in fully vetted, DPA compliant vendors. Where applicable we store all contract and personal data for up to 7 years in line with Statute of Limitations unless your account is deleted. In which case, we dispose of all data in accordance with our Terms of Service and Privacy Policy, within 60 days. We are aware that if you are working with EU customers, you need to be able to provide them with the ability to access, update, retrieve and remove personal data and will assist you with any such UKGDPR related requests free of charge.