
What is the GDPR Pick’n’Mix?
We recognise that you may already have some procedures in place, and have already had some ‘in-house’ training.
So the aim of our GDPR Pick’n’Mix is to allow you to pick only the documents you need to complete your set of GDPR Procedures.
The following documents and procedures are available.
To order your documents and procedures please go here.
The price for each document is £97 excluding VAT. If you order 3 or more documents the price per document reduces to £77 per document (excluding VAT).
The documents will be delivered to you in either PDF or for some documents Microsoft Word format and are licenced for use within one company only.
If you have a group of companies who wish to use the documents, please contact us for group licence pricing.
GDPR Data Breach Policy
One of the essential elements of GDPR readiness is having a full GDPR Data Breach policy and just as importantly having a Data Breach Register.
Your GDPR Data Breach policy should provide all of your staff with clear guidance on who they should contact within your organisation, where they can find your Data Breach Register and how to complete it, and then it should provide the member(s) of your team allocated to deal with data breaches with clear instruction on who they need to contact, when/if they need to report a data breach to the Information Commissioner’s Office (ICO) and if so, how to report it, together with clear strategies for dealing with outside requests of information, whether that is from clients, the general public or the press.
There are clear time limits on the completion of some of the tasks required under a GDPR Data Breach, and our policy provides you with clear guidance on these and advice on how to comply.
Remember, that all of your staff should be encouraged to record any data breaches in the Data Breach Register, and just as you would (should) record a cut finger in your company accident book, so you should record a simple data breach (such as sending the wrong email to the wrong person or putting the wrong invoice in the wrong envelope) in your GDPR Data Breach Register.
We recognise that many organisations do not currently have a GDPR Data Breach Register and so for a limited period if you order a copy of our GDPR Data Breach policy, not only will you receive a copy of the policy but you also receive a ready to use Data Breach Register too.
GDPR Privacy Policies
You may note we have used the term ‘Privacy Policies’ and not ‘Privacy Policy’ – this is deliberate as under GDPR there are two separate privacy policies which you are required to implement. We have explained these in more detail below:
GDPR Website Privacy Policy
Everyone (hopefully!) by now knows that under GDPR all websites which collect any form of personal data (even if that is restricted to something as simple as a contact us form) needs to have a website privacy policy.
It’s not quite as simple as just having a policy though, there are also a number of things it must contain, for example, your organisation contact details, the site visitor’s rights under GDRP, who they can contact in case of a complaint and so on.
We offer two services to help here, either we can check your privacy policy for any errors or omissions and inform you of the changes you need to make or we can provide you with a fully compliant GDPR privacy policy you can simply slot into your website.
GDPR Employee Privacy Policy
In our experience, this is the policy most likely to be missing, and yet, it is, one of the most important policies under GDPR.
Each of your employees (and for the purposes of GDPR, directors (exec or non-exec), trustees, volunteers, councillors, shareholders etc are all regarded as employees) must have a copy of their Employee Privacy Policy. There should be two copies of the policy for each employee (one of which they retain, the second copy they sign and date and return to you and you should then keep the signed and dated copy on their personnel file).
It is important to note that as from 25th May 2018, the Employee Privacy Policy can no longer be a few sentences in the employee’s Contract of Employment, it MUST be a separate document.
We are able to provide you with model wording for an Employee Privacy Policy.
An important note for all privacy policies (both website and employee)
It is important that every time you update your privacy policy(ies) you ensure that they are clearly dated and also that you retain on file a copy of the previous privacy notices. The reason for this is that in the event of a data breach, or other issue which requires reference to your privacy policies, it is the privacy policy which was in effect at the date the breach/issue took place which is relevant and not the privacy policy which is in place now.
Interested? Contact Keith on keith@ensurety.co.uk or 07858138218
Alternatively, contact Lindsay Lawrence from BBX on lindsay.lawrence@bbxworld.com or 01202 836063










