Tel: 0345 602 6060

Home / Terms & Conditions

Terms & Conditions

Data protection policy in accordance with the EU General Data Protection Regulation (GDPR)

Dotted Line

 

 

Goal of the data protection policy: – Reviewed 12th March 2018

Dotted Line

The goal of the data protection policy is to depict the legal data protection aspects in one summarising document. It can also be used as the basis for statutory data protection inspections, e.g. by the customer within the scope of commissioned processing. This is not only to ensure compliance with the European General Data Protection Regulation (GDPR) but also to provide proof of compliance.

 

Compliance

Dotted Line

 

Lifterz Ltd, will endeavour to protect the information it holds, receives and distributes to our customers, suppliers and individuals. This data protection policy assists with meeting the accountability obligations of the European General Data Protection Regulation (GDPR) as stipulated by the supervisory authorities. It also serves as the basis for statutory data protection audits, e.g. by the customer.

Security policy and responsibilities in the company:

Dotted Line

 

  • For a company (Lifterz Ltd), in addition to existing corporate objectives, the highest data protection goals are to be defined and documented. Data protection goals are based on data protection principles and must be individually modified for every company.
  • Determination of roles and responsibilities (e.g. representatives of the company, operational data protection officers, coordinators or data protection team and operational managers)
  • Commitment to continuous improvement of a data protection management system
  • Training, sensitisation and obligation of the employees

Legal framework in the company:

Dotted Line

 

  • Industry-specific legal or conduct regulations for handling personal data
  • Requirements of internal and external parties
  • Applicable laws, possibly with special local regulations

 

Documentation:

Dotted Line

 

  • Conducted internal and external inspections
  • Data protection need: determination of protection need with regard to confidentiality, integrity and availability. The BSI Standard 100-2

 

Existing technical and organisational measures (TOM):

Dotted Line

 

Appropriate technical and organisational measures that must be implemented and substantiated, taking into account, inter alia, the purpose of the processing, the state of the technology and the implementation costs.

 

Guidelines include:

Dotted Line

  • Guideline for the rights of data subjects
  • Access control
  • Information classification (and handling thereof)
  • Physical and environmental-related security for end users such as:
    • Permissible use of values
    • Guideline for information transfer based on the work environment and screen locks
    • Mobile devices and telecommuting
    • Restriction of software installation and use
  • Data backup
  • Information transfer
  • Protection against malware
  • Handling technical weak points
  • Cryptographic measures
  • Communication security
  • Privacy and protection of personal information
  • Supplier relationships: Noting regular inspection and evaluation of data processing, especially the efficacy of the implemented technical and organisational measures.

Opt-in…
Let’s Get Connected

Keep up-to-date with all the latest deals and news from Lifterz