Introduction
Kelliher Insurance Group Limited (‘KIG’) which is authorised by the Financial Conduct Authority (‘FCA’) is required to establish and maintain appropriate systems and controls for managing operational risks which can arise from inadequacies or failures in its process and systems.
Appropriate and effective data management controls are recognised as integral to the business, as a failure to meet data privacy and protection obligations could mean potential customer or indeed employee detriment; significant operational loss; loss of reputation; loss of customers and loss of income which also, could lead to regulatory censure.
KIG maintains physical, electronic, and procedural safeguards to protect client and employee personal and non-personal data. Strict internal policies exist against unauthorised use or disclosure of data. Client and employee data is accessible only to employees or other personnel who need it to undertake the specific tasks assigned to them. Staff members are reminded on a regular basis of their obligations about the confidentiality of client and employee information through employee training and operating procedures. Data must only be given to those who have a verified right to that information.
The purpose of this policy is to set out how KIG achieves compliance with statutory requirements when processing information that can be used to identify a living individual. This policy has been drafted in line with overarching FCA system and control requirements and data protection laws within the United Kingdom and the European Union, which have been refreshed. This includes the UK’s Data Protection Act 2018 (‘DPA 2018’); UK General Data Protection Regulation (‘UK GDPR’) and EU General Data Protection Regulation (‘GDPR’) where applicable.
Scope
This policy applies across all workplace locations and to all employees, including temporary and contract workers who may have access to Company data.
What is personal data?
Personal data means any information relating to an identified or identifiable natural person (commonly referred to as a data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
In a work context, additional examples of personal data may include records referring to an employee’s performance, staff absence, notes on conduct and disciplinary matters.
Personal data may also contain data that is referred to as Special Category Data. Historically this information was referred to as being sensitive personal data. Special Category Data may include the following data relating to an individual:Last review:
• Sexual orientation
• Sex life
• Trade union membership
• Political or religious views
• Health data
• Genetic and biometric data, where processed to uniquely identify an individual.
Personal data relating to criminal convictions and offences are not considered as being Special Category Data; however additional conditions apply to its processing.
Data processing activities
KIG is required to demonstrate that it fully understands the lawful basis for collecting and processing personal data, as well as knowing where personal data is located and accessed from, the purpose for collecting the data, who is using the data, for how long it is necessary to retain the data and communicating our data processing activities to data subjects.
The lawful bases for processing data are:
1. Contract: the processing is necessary for a contract we have with the individual, or because they have asked us to take specific steps before entering into a contract.
2. Consent: the individual has given clear consent to process their personal data for a specific purpose.
3. Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
4. Legal obligation: the processing is necessary for us to comply with the law (not including contractual obligations).
5. Vital interests: the processing is necessary to protect someone’s life.
6. Public task: the processing is necessary for us to perform a task in the public interest or for our official functions, and the task or function has a clear basis in law.
All processing activities must be reviewed periodically to ensure alignment with their original purpose. Any new or changed purpose requires reassessment of the lawful basis.
KIG ensures that all personal data collected is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Any special category data processing requires enhanced safeguards and, where appropriate, a Data Protection Impact Assessment (‘DPIA’).
Data retention and disposal
KIG applies a defined data retention schedule to ensure personal data is not kept longer than necessary. At the end of the retention period Data is securely deleted, anonymised, or archived in accordance with legal requirements. Disposal methods ensure data cannot be reconstructed or accessed.
Retention periods are reviewed regularly to ensure compliance with legal, regulatory, and business requirements.
Individual rights
The DPA 2018 and the UK GDPR grant data subjects specific rights where their personal data is being processed. Key requirements centre on individuals being able to request information being held, for what purpose, how the data was gathered, who the data is shared with, where the data is located, how the data is safeguarded, to request the rectification and the deletion of data and to object to the processing of data, including preventing further processing.
KIG maintains a register of requests from data subjects and third parties about data subjects’ individual rights. Data subjects have the right to be informed when the data relating to them has been rectified, restricted or erased. As part of our processes and procedures we shall determine likely scenarios where we are required to comply with this right.
If an individual is unhappy with how their personal data has been handled, they have the right to complain to KIG directly at complaints@kelliherinsurance.co.uk or 020 7623 4957. All data protection related complaints will be handled in accordance with the Group’s established Complaints Policy and Procedure.
Any data subject has the right to refer their complaint to the Information Commissioner’s Office (‘ICO’), but the ICO will expect the complaint to be made to KIG in the first instance.
Data Protection Officer
KIG’s appointed Data Protection Officer (‘DPO’) is Lauren Ciaravolo, Group Compliance Manager. Responsibilities of the DPO include:
• informing and advising KIG and its employees about their obligations to comply with the DPA 2018, the UK GDPR and other applicable data protection laws;
• monitoring compliance with the DPA 2018, the UK GDPR and other applicable data protection laws including managing internal data protection activities, advising on data protection impact assessments, training staff and conducting internal audits;
• being the first point of contact for supervisory authorities and for individuals whose data is processed i.e., employees, customers, etc.; and
• providing MI data reporting to senior management on meeting DPA 2018 and UK GDPR requirements, particularly around access requests and to provide visibility on non-compliance issues.
When requested, employees shall fully co-operate with requests for assistance. Non-cooperation may be treated as a disciplinary offence.
Data sharing and third parties
Where personal data is shared with third parties KIG ensures that appropriate data sharing agreements are in place that third parties are subject to due diligence and contractual obligations and that processing is limited to agreed purposes and lawful bases.
Where personal data is transferred outside the UK, transfers are conducted in accordance with UK GDPR requirements and appropriate safeguards are implemented.
Data breach procedure
KIG is committed to ensuring that all personal data breaches are identified, reported, and managed effectively to minimise harm to individuals and ensure compliance with DPA 2018 and UK GDPR and requirements.
A personal data breach is defined as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data” and includes breaches caused by both internal and external factors.
All employees, contractors, and third parties must report any suspected or actual personal data breach immediately upon discovery to the DPO. Reports must include the following information:
• the nature of the breach;
• the type of personal data involved;
• the number of individuals affected;
• the date and time of the breach;
• how the breach occurred; and
• any immediate action that has been taken.
Upon notification, the DPO will record the breach in the Data Breach Register, assess the severity and potential impact, determine whether personal data is involved, and if so, contain and mitigate the breach to as far as is reasonably practicable.
The Data Breach Register will include facts relating to the breach, effects of the breach, any remedial actions taken and the justification for notification decisions.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the DPO will notify the ICO within 72 hours of becoming aware of the breach. If notification is delayed, reasons must be documented.
Where the breach is likely to result in a high risk to individuals, the DPO will inform affected individuals without undue delay. Data subject notification is not essential if the data was encrypted or otherwise protected, if steps have eliminated the risk or if it would involve disproportionate effort.
All breaches will be subject to a post-incident review to identify root causes, assess control failures, implement corrective actions and prevent recurrence. This procedure operates alongside KIG’s Information Security and Incident Response frameworks.
KIG will ensure regular staff training on recognising and reporting breaches occurs and that there is ongoing awareness of data protection responsibilities.