1. Introduction & Policy Statement
Introduction
This Data Protection Policy sets out obligations of Investors in People Community Interest Company (“IIPCIC”, “Investors in People”, “we”, “us”, “our”) regarding data protection and rights of individuals whose Personal Data is collected, used and processed during business activities.
Policy applies to all IIPCIC employees, workers and contractors. Compliance is mandatory. Breaches may result in disciplinary action, including termination for serious offences.
Policy prepared with regard to applicable data protection laws:
- UK General Data Protection Regulation (“UK GDPR”)
- EU General Data Protection Regulation (“EU GDPR” - EU Regulation 2016/679)
- Data Protection Act 2018 (“DPA 2018”)
Related documents:
- IIPCIC Data Protection by Design & Default Policy
- IIPCIC Personal Data Retention and Destruction Policy
- IIPCIC IT Policy
- IIPCIC Data Subject Rights Procedure
- IIPCIC Personal Data Breach Procedure
- IIPCIC DPIA Procedure
- IIPCIC Data Protection Monitoring Framework Guidance
Policy Statement
IIPCIC places high importance on respecting privacy and protecting Personal Data of individuals including clients, end customers and employees. Committed to fair, lawful and transparent handling of Personal Data and facilitating individual rights. Policy aims to comply to both the letter and spirit of the law.
Policy applies to all Personal Data processed by IIPCIC in electronic or physical form, regardless of storage media. Applies to Personal Data processed as Data Controller and Data Processor.
IIPCIC Registration: Registered as Data Controller with Information Commissioner’s Office, registration reference: ZA286529
1.1. Definitions
| Term | Description |
|---|---|
| Accountability | Duty to answer to success or failure of strategies, decisions, practices and processes. |
| Criminal Information | Personal Data relating to criminal convictions, offences, allegations and proceedings. |
| Data Controller | Person, entity or organisation determining purposes and means of processing Personal Data. |
| DPA 2018 | Data Protection Act 2018 |
| Data Protection Officer | Responsible for overseeing data protection strategy and implementation ensuring Data Protection Law compliance. |
| Data Protection Law | UK GDPR, EU GDPR (EU Regulation 2016/679), and Data Protection Act 2018. |
| Data Processor | Person, entity or organisation processing Personal Data on behalf of Data Controller. |
| Data Subject | Any natural person (individual) whose Personal Data is being processed. |
| Data Protection Impact Assessment (DPIA) | Assessment tool helping organisations evaluate risks associated with data processing activities that could compromise individual rights and freedoms. Used to identify and mitigate risk related to products, services, business processes or organisational changes. |
| EU GDPR | EU Regulation 2016/679 General Data Protection Regulation |
| Legitimate Interest Assessment (LIA) | Determines if individual's Personal Data is used in ways they would reasonably expect and which have minimal privacy impact, or where compelling justification exists for processing. |
| Personal Data | Any information relating to identified or identifiable natural person; identifiable person can be identified directly or indirectly by reference to identifier such as name, identification number, location data, online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. |
| Processing | Any operation performed on Personal Data, including collection, recording, organising, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, combination, restriction or erasure. |
| Information Commissioner's Office (ICO) | Independent public body in UK responsible for monitoring UK GDPR, Data Protection Act 2018 and Privacy & Electronic Communications Regulations application. |
| Sensitive Personal Data | Special Category Data and Personal Data relating to criminal convictions and offences. |
| Special Category Data | Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data, biometric data (where used to identify data subject), health data and data concerning natural person's sex life or sexual orientation. |
| UK GDPR | Meaning given in section 3(10) (supplemented by section 205(4)) of Data Protection Act 2018 |
1.2. Responsibilities
Key data protection responsibilities within IIPCIC:
- IIPCIC Board is accountable for ensuring data protection obligations are met.
- Director of Finance and Business Services is responsible for implementing and enforcing policy.
- Executive Team responsible for ensuring personnel under their management are aware of and adhere to policy.
- All personnel with Personal Data decision-making authority responsible for keeping it secure, accessible only to those needing it, not disclosed to third parties without Board member authorisation.
- All personnel required to read, understand, and adhere to policy when processing Personal Data on behalf of IIPCIC.
Contact Business Operations Manager for questions or concerns regarding policy or data protection.
1.3. Data Protection Principles
Following Data Protection Principles govern collection, use retention, transfer, disclosure and destruction of Personal Data by IIPCIC:
- Personal Data must be processed fairly, lawfully and in transparent manner, in relation to Data Subject.
- Personal Data must be collected and processed for specified, explicit and legitimate purposes only.
- Personal Data must be adequate, relevant and limited to what is necessary in relation to processing purposes.
- Personal Data must be accurate and kept up to date.
- Personal Data permitting Data Subject identification (non-anonymised) must be kept in form permitting identification for no longer than necessary.
- Processed in manner ensuring appropriate security including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
1.4. Notifying Data Subjects
All Personal Data breaches must be reported immediately to Finance Manager and added to Personal Data breach register.
IIPCIC as Data Controller
- Where IIPCIC is Data Controller, unless breach occurs that is unlikely to result in risk to Data Subject rights and freedoms (financial loss, confidentiality breach, discrimination, reputational damage, or other significant social or economic damage), relevant supervisory authority must be notified without delay, within 72 hours after becoming aware, if feasible. If notification not made within 72 hours, should be made as soon as possible with delay reasons. Information Commissioner’s Office (ICO) is UK supervisory authority.
- If Personal Data breach is likely to result in high risk (higher than described above) to Data Subject rights and freedoms, all affected Data Subjects must be informed directly and without undue delay.
Regardless of whether IIPCIC is Data Processor or Controller, all data breach notifications must be handled per IIPCIC Personal Data Breach Procedure and added to IIPCIC Personal Data Breach Register located on Sharepoint.
1.5. Data Security
Procedures and technologies maintain security of all personal data from collection point to destruction point.
IIPCIC Certification: Currently holds Cyber Essentials Plus certification.
Security Procedures Include:
Building Entry Controls:
Work in government secured building where only people with valid photo identification can enter. All entry and exit points manned by security personnel.
Floor Access:
Doors on each floor electronically locked. Electronic access control cards required for floor entry. Staff only have access to their department floor.
Device Security:
Becrypt security on all staff laptops prevents unauthorised log-in.
Staff Compliance:
All IIPCIC staff must adhere to internal staff data protection guidance policy.
File Storage: System Security Protocols
All personal data stored on following servers located within European Economic Area (EEA):
File Storage Systems — IIPCIC uses:
- Slack — For Slack security protocols see: https://get.slack.help/hc/en-us/articles/202014843-Slack-data-security-and-privacy-policies
- Zendesk — For Zendesk security protocols see: https://www.zendesk.com/company/customers-partners/privacy-and-data-protection/
- Microsoft Office 365 — See: https://support.office.com/en-us/article/overview-of-security-and-compliance-in-office-365-dcb83b2c-ac66-4ced-925d-50eb9698a0b2
We Invest in People Online Survey
Survey data including personal data stored securely within Amazon Web Services (AWS). Entire data application (instances, databases, snapshots, backups) stored within EU-West-1 (Dublin) data centres, adhering to EU controls limiting storage within EEA.
Database Access: Direct access to data (databases, snapshots) limited to senior database architects using asymmetric key-based authentication, further secured with strict ACLs requiring access through secure Cisco VPNs.
AWS Security Information: https://aws.amazon.com/compliance/
Application Passwords: Managed using Drupal — passwords salted and re-hashed multiple times. Plain-text passwords never stored in database. Brute-force attacks mitigated by auto-blocking login attempts after five failed attempts. Once logged-in, system supports full RBAC, with minimum-granted permissions (user permissions granted only when needed rather than granting system-wide access).
Communications: All site communications via HTTPS, using HSTS and modern cipher suites (TLS1.0+). Ciphers reviewed regularly for security compliance.
We Invest in Wellbeing Online Survey
Survey runs on dedicated resources, not Cloud-based. Servers located in UK with full support and security contract with data centre provider covering firewalls, vulnerability scanning and intrusion detection. Also covers full infrastructure, platform, operating system and data support.
Data Centre Security: 24/7 on-site security presence with internal CCTV monitoring. Comprehensive security procedures including proximity access control. Data centre access restricted to small number of data centre staff.
Power Infrastructure: For power outages: short-term uninterruptible power supply plus multiple generators with minimum 96 hours fuel on site.
Monitoring: Firewalls actively monitored with regular vulnerability scans. Intrusion detection systems run in real-time.
Data Access: Security policies allow only senior technical staff and server administrators access to sensitive data. All login attempts recorded. Offsite backups encrypted before transmission and stored in secure on-site area accessible only by senior staff.
Sensitive Data Storage: All sensitive data such as passwords stored in encrypted format. Data passed over secure SSL connections. Dependent on subscription level, all data including survey responses can pass over SSL channels.
Regular Scanning: Automated scans of server, software and application run regularly with enhancements applied where appropriate.
Investors in People CRM
Web-based application following AWS security and storage controls detailed above.
Data Held on Investors in People CRM:
- Organisation name, address, telephone number(s) and generic email address.
- Client contact names, email address(es), job title and phone number(s) working with Investors in People on assessments or requesting further information.
- Dates managing organisation accreditation period including start date, end date and review dates.
- Other demographic information about Investors in People accredited organisations including sector (SIC code), size (number of employees) and industry sector (public, private, voluntary).
1.6. Data Retention & Destruction
Personal data will not be kept longer than necessary for stated purpose(s). All reasonable steps will be taken to safely and securely destroy or erase all personal data no longer required. Retention periods vary depending on data collected and purpose. See Website Privacy Notice and Client Privacy Notice for various data processing methods.
1.7. Data Protection by Design and Default
IIPCIC shall ensure that risks to Data Subject rights and freedoms associated with processing are key considerations when:
- Designing, implementing and during lifetime of business practices and processes involving Personal Data processing (“processing activities”); and
- Developing, designing, selecting, procuring, and using applications, services, products and other IT systems and technologies for collecting, holding, sharing, accessing, and otherwise processing Personal Data (“processing systems”).
Risk-led approach to processing activities and systems applies throughout full processing lifecycle, from initial planning and specifications, during systems use, through data disposal. Takes into account both likelihood and severity of potential harm to Data Subject rights and freedoms.
DPIA Requirements: Where risk to Data Subject rights and freedoms is likely high, or otherwise required by law or supervisory authority, DPIA shall be performed per IIPCIC DPIA procedure.
Safeguards Implementation: Safeguards and preventive measures implemented into processing activities and systems from outset and throughout processing lifecycle, to mitigate risks and protect rights. Safeguards proportionate to risks and include organisational (policy, awareness, governance, assurance) and technical measures (pseudonymisation).
Safeguard Objectives:
- Data minimisation
- Limiting extent of processing, storage, and access to strictly necessary
- Ensuring Data Subject transparency regarding processing activities
- Ensuring Personal Data security
1.8. Data Processing Obligations
IIPCIC as Data Controller
- Data Subjects must be provided information notifying them of Personal Data processing purposes (“privacy notice”). When data obtained directly, privacy notice provided at collection time. When obtained indirectly, privacy notice provided as soon as possible (not more than one calendar month) after obtaining from third party. Privacy notice must explain processing and include information in Schedule 1.
- Personal Data use by IIPCIC must match privacy notice description and be limited to stated specific purposes. Where lawful basis is legitimate interests, Personal Data only processed if IIPCIC’s legitimate interests not outweighed by Data Subject interests, rights and freedoms. Legitimate interests assessment must be performed to confirm.
- Must not collect or process more Personal Data than strictly necessary for processing purposes (“data minimisation”), as stated in privacy notice. Data minimisation must continue throughout processing lifetime.
- Personal Data must be accurate and up to date. Accuracy checked at collection and regular intervals thereafter. Where inaccurate or out-of-date data found, all reasonable steps taken without delay to amend or erase. Personal Data must not be kept longer than necessary for original collection and processing purpose. When data no longer required, all reasonable steps taken to securely erase or dispose without delay.
- Personal Data must be kept secure and protected against unauthorised or unlawful processing and against accidental loss, destruction or damage.
1.9. Accountability
Only personnel needing Personal Data access and use for assigned duties correctly will be permitted access. All personnel handling Personal Data on behalf of IIPCIC must be:
- Made fully aware of both individual responsibilities and IIPCIC’s responsibilities under policy and applicable law, provided policy copy;
- Appropriately trained and suitably supervised, with training upon starting and refresher training at least annually;
- Bound by contract to handle Personal Data per policy and law.
Methods of collecting, holding and processing Personal Data by personnel or other parties working on behalf of IIPCIC regularly evaluated and reviewed by Head of Finance and Business Services.
Third Party Obligations: All consultants, agencies and other parties working on behalf of IIPCIC and handling Personal Data must ensure all employees involved in Personal Data processing held to same obligations as IIPCIC personnel per policy.
Data Processor Contracts: When using Data Processor (or where permitted, sub-Data Processor), binding contract must be implemented between IIPCIC and Data Processor setting out subject matter and duration of processing; nature and purpose of processing; type of Personal Data and Data Subject categories; controller and processor obligations and rights. Processor contracts must include terms in Schedule 2.
Records of Processing Activities (RoPA): IIPCIC will keep written internal records of processing activities for all Personal Data collection, holding, and processing (“RoPA”). Where IIPCIC is Data Processor, Processor RoPA will be kept; where Data Controller, Controller RoPA will be kept.
Data Controller RoPA
Where IIPCIC is Data Controller, RoPA will incorporate:
- Name and contact details of Data Controller, point of contact for data concerns and any joint controllers;
- Purposes for Personal Data processing;
- Details of Personal Data categories collected, held, and processed and Data Subject categories;
- Details (and categories) of third parties receiving Personal Data;
- Details of Personal Data transfers to countries outside UK or EEA including mechanisms and security safeguards;
- Envisaged retention periods for different Personal Data categories;
- Descriptions of technical and organisational measures ensuring Personal Data security.
1.10. Risk Management
IIPCIC will monitor risks to Data Subjects associated with all existing and planned Personal Data processing activities and implement appropriate technical and organisational measures to safeguard Data Subjects and ensure data protection principles in policy are met. Risk-led approach applies across all IIPCIC business activities ensuring data protection by design and default.
DPIA Requirement: Where risks to Data Subject rights and freedoms associated with existing or planned Personal Data processing potentially high, or where required by applicable law or supervisory authority in country/territory of operation, IIPCIC will carry out Data Protection Impact Assessment (“DPIA”). All DPIAs undertaken per IIPCIC Data Protection by Design & DPIA Policy. DPIA record kept including outcome details, signing parties and next review date.
Data Controller DPIA Assistance: Where Data Controller carries out DPIA for processing activity in which IIPCIC is Data Processor, IIPCIC will provide all information and assistance reasonably required for DPIA.
1.11. Data Subject Rights
Data subjects have following rights regarding Personal Data processing and collected and held data:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure (also ‘right to be forgotten’);
- Right to restrict processing;
- Right to data portability;
- Right to object;
- Rights regarding automated decision-making and profiling.
Facilitation: Data Subject rights requests must be facilitated per IIPCIC Data Subject Rights Procedure and Subject Access Request Policy.
Where IIPCIC is Data Controller, responsible for facilitating Data Subject rights. Where Data Processor, must assist Data Controller to facilitate Data Subject rights appropriately.
1.12. Protection of Personal Data
All personnel must comply when working with Personal Data:
- Personal Data handled with care at all times, not shared with colleagues without access or third parties without authorisation;
- Physical records not left unattended or visible to unauthorised employees, agents, contractors or parties; not removed from business premises without authorisation;
- When Personal Data viewed on screen and computer left unattended, user must lock computer and screen before leaving;
- Physical copies of Personal Data and electronic copies on removable media stored securely in locked filing cabinet, drawer, box or similar;
- Electronic Personal Data stored securely using regularly changed passwords not using easily guessed words or phrases;
- Personal Data not transferred to personally-owned employee devices or uploaded to personal file sharing, storage, communication or equivalent services (personal cloud services);
- Personal Data transferred to agent, contractor, or other party devices only where party agreed to full policy and Data Protection Law compliance (may include demonstrating suitable technical and organisational measures taken and entering Data Processor contract with IIPCIC);
- Electronic Personal Data backed-up regularly and securely;
- Under no circumstances must passwords be written down or shared between employees, agents, contractors, or other parties regardless of seniority or department. If password forgotten, must be reset using applicable method.
Additional Obligations: All personnel involved in Personal Data processing required to read and adhere to IIPCIC Information Security Policy.
1.13. International Data Transfers
Personal Data will only be transferred (transfer includes making available remotely) from UK/EEA countries to outside UK/EEA countries where:
- Transfer to country (or international organisation) that UK government/European Commission determined ensures adequate protection (“Adequacy”);
- Standard contractual clauses (or UK equivalent) adopted by UK government/European Commission put in place between UK/EEA entity and outside UK/EEA entity;
- Binding corporate rules implemented, where applicable; or
- Transfer otherwise permitted by law.
Data Processor Transfers: Where IIPCIC is Data Processor, Personal Data transfers outside UK/EEA only made with controller’s agreement.
Transfer Impact Assessment: Where transfer not based on Adequacy, IIPCIC will undertake transfer impact assessment (“TIA”) or transfer risk assessment (“TRA”) ensuring Data Subjects (whose Personal Data transferred) continue to have protection level essentially equivalent to UK or EU GDPR (whichever applicable). If outcome is safeguard not providing required protection, supplementary measures (e.g. encryption) implemented.
1.14. Implementation & Policy Management
Policy effective date: 16 December 2022. No policy part has retroactive effect; applies only to matters occurring on or after this date.
Policy reviewed annually by Business Operations Manager and Head of Finance & Business Services and following any Personal Data breach.
1.15. More Information
For IIPCIC data protection policy queries contact: gdpr@investorsinpeople.com
Schedule 1: Privacy Notices
Privacy notices for Data Subjects shall include:
- Data Controller identity and contact details including Data Protection Officer identity and EU representative (where applicable);
- Purpose(s) for Personal Data collection and processing and legal basis justifying collection and processing;
- Where applicable, legitimate interests upon which IIPCIC justifies collection and processing;
- Where Personal Data not obtained directly from Data Subject, collected and processed Personal Data categories;
- Where Personal Data transferred to third party(ies), details of those parties;
- Where Personal Data transferred to outside UK/EEA third party, transfer details including safeguards in place;
- Personal Data holding length details (or, where no predetermined period, how length determined);
- Data Subject rights details;
- Where applicable, Data Subject right to withdraw processing consent details;
- Data Subject supervisory authority complaint right details;
- Where applicable, legal or contractual requirement or obligation necessitating collection and processing details and consequences of failing to provide;
- Automated decision-making details using Personal Data (including profiling), decision-making information, significance and consequences.
Schedule 2: Processor Contracts
Data Processor contracts processing Personal Data must set out subject matter and processing duration; nature and purpose of processing; Personal Data type and Data Subject categories; controller obligations and rights.
Contracts must include terms requiring Data Processor to:
- Only act on controller’s written instructions;
- Ensure people processing data subject to confidence duty;
- Take appropriate measures ensuring processing security;
- Only engage sub-Data Processors with prior Data Controller consent under written contract;
- Assist Data Controller providing subject access and allowing Data Subjects exercising UK GDPR and/or EU GDPR rights;
- Assist Data Controller meeting UK GDPR and/or EU GDPR (whichever applicable) obligations relating to processing security, Personal Data breach notification and data protection impact assessments;
- Delete or return all Personal Data to Data Controller as requested at contract end;
- Submit to audits and inspections, provide Data Controller with information ensuring both meet data protection obligations, tell Data Controller immediately if asked to do something infringing Data Protection Law (or other applicable legislation).

