3. Your rights and obligations
You have the right to be provided with
clear, transparent and easily understandable information about how we use your
information and your rights. This is why we’re providing you with the
information in this policy. You might need a copy of the information we hold,
or you may ask us to correct it or delete it amongst other things. This section
explains your rights and what to do if you’re not happy.
3.1
Your
rights in connection with personal information
Under certain circumstances, by law you have
the right to:
·
Object to processing of your personal information where we are relying on a legitimate interest (or that of a third
party) and there is something about your particular situation which makes you
want to object to processing on this ground. You also have the right to object
to being subject to automated decision processes and where we are processing
your personal information for direct marketing purposes.
·
Request access to your personal information (commonly known as a "data subject access request"). This
enables you to receive a copy of the personal information we hold about you and
to check that we are lawfully processing it.
Where we have requested a reference in confidence from a referee and
that reference has been given on terms that it is confidential and that the
person giving it wishes that it should not to be disclosed to you, it is our
policy that it would not normally be reasonable to disclose such a reference to
you unless the consent of the person who gave the reference is first
obtained.
We reserve the right not to disclose to you any management forecasts or
management planning documentation, including documents setting out the
Company’s plans for your future development and progress. We will also not disclose to you any
information that contains personal data of any other person.
·
Request correction of your personal information that we hold about you. This enables you to have any incomplete or
inaccurate information we hold about you corrected.
·
Request erasure of your personal information. This enables you to ask us to delete or remove personal information
where there is no good reason for us continuing to process it. You also have
the right to ask us to delete or remove your personal information where you
have exercised your right to object to processing (see above).
·
Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal
information about you, for example if you want us to establish its accuracy or
the reason for processing it.
·
Request the transfer of your personal information to another party in a machine-readable, commonly used and structured
format.
Where you have previously given us your permission to use your personal
information, you may withdraw that permission. Where your permission is
withdrawn, your previous consent will remain valid in respect of our use of
your information prior to the date you withdrew it, or if any marketing
material has been sent prior to you advising that you do not wish us to contact
you again.
If you wish to exercise any of these rights
then please contact the Data Protection Officer (see section 10).
Please
note that in some cases, even when you make a request concerning your personal
information, we may not be required, or may not be able, to honour it as this
may result in us not being able to fulfil our legal and regulatory obligations
or there is a minimum statutory period of time for which we have to keep your
information. If this is the case, then we will let you know our reasons.
3.2
Your
duty to inform us of changes
It is important that the personal
information we hold about you is accurate and current. Please keep us informed
if your personal information changes during your working relationship with us.
3.3
Your
Obligations in Relation to Personal Information
You
must comply with the company’s policies and procedures pertaining to data
protection at all times:
· Do not
give out confidential personal information except to the data subject, unless the
data subject has given their explicit consent to this.
· Be
aware that those seeking information sometimes use deception in order to gain
access to it. Always verify the identity
of the data subject and the legitimacy of the request, particularly before
releasing personal information by telephone.
· Only
transmit personal information between locations by fax or email if a secure
network is in place, for example, a confidential fax machine or encryption is
used for email.
· If you
receive a request for personal information about another employee, you should
forward this to your Manager, HR or the Data Protection Officer.
· Ensure
that any personal data which you hold is kept secure in accordance with Castle
Trust’s policies and procedures.
· Do not send
personal data to any email recipient outside the European Economic Area ("EEA")
without their prior explicit consent,
and the explicit consent of the Data Protection Officer.
3.4 Fees
You will not have to pay a fee to access
your personal information (or to exercise any of the other rights). In some cases, we may charge a reasonable fee
if your request for access is clearly unfounded or excessive, or if you request
multiple copies of the information. Alternatively, we may refuse to comply with
the request in such circumstances.
3.5 What
we may need from you
We may need to request specific information
from you to help us confirm your identity and ensure your right to access the
information (or to exercise any of your other rights). This is another
appropriate security measure to ensure that personal information is not
disclosed to any person who has no right to receive it.
3.6 Right
to complain
If you wish to request further information
about any of the above rights, or if you are unhappy with how we have handled
your information, contact the Data Protection Officer (see section 10 for
contact details).
If you are not satisfied with our response
to your complaint or believe our processing of your information does not comply
with data protection law, you can make a complaint to the Information
Commissioner’s Office: https://ico.org.uk/global/contact-us/ 0303 123 1113.