a. Data Protection and Access to Information for members of staff

 One Maidstone CIC will comply with all statutory requirements of the Data Protection Act by registering all personal data held on its computer and/or related electronic equipment and by taking all reasonable steps to ensure the accuracy and confidentiality of such information.

The Data Protection Act protects individuals’ rights concerning information about them held on computer.  Anyone processing personal data must comply with the eight principles of good practice.  Data must be:

  • fairly and lawfully processed
  • processed for limited purposes
  • adequate, relevant and not excessive
  • accurate
  • not kept longer than necessary
  • processed in accordance with the data subject’s rights
  • secure
  • not transferred to countries without adequate protection

Employees can request access to the information held on them by the Company. All requests by employees to gain access to their personnel records should be made in writing. There is no charge for this service.  

All paper copies must be locked in a cabinet, all the key remain with the Town Centre Coordinator. 

Privacy Policy for personal data and Data Processing

  • One Maidstone does not share personal information with any outside bodies.
  • When a business or internal contact chooses to provide personal contact details a consent form will be provided and kept for our records.
  • We will adhere to our retention schedules for holding personal data which form part of our regular self-assessments for GDPR
  • Any group email must be sent Blind Copy (BCC)
  • Under the right of access any request made by an individual wanting to obtain:
  • Confirmation that their data is being processed
  • Access to their personal data
  • Other supplementary information 

Will be complied with free of charge and within one calendar month of the receipt of the request.  One Maidstone will verify the identity of the person making the request using reasonable means.  If the request is made electronically One Maidstone will provide the information in a commonly used electronic format.

  • Under the right to rectification and data quality any request from an individual to have their personal data rectified if it is inaccurate or incomplete will be responded to without delay and at least within one month of receipt of the request.
  • Under the right to erasure any request made by an individual to be forgotten by One Maidstone will be complied with. However we may refuse to comply when the personal data has been processed for the purpose of the business crime reduction partnership including for exclusion notices/orders.  We will adhere to our retention schedule for offender information which form part of our regular self assessments for GDPR.
  • Under the right to restrict processing if an individual requests the restriction of processing their data we will store that data but will no longer process it.  We may need to retain the data for a period of seven years to allow us to establish, exercise or defend a legal claim.  If we decide to lift a restriction on processing the individual concerned will be informed.
  • One Maidstone undertakes a quarterly self assessment on data protection policies
  • Data protection awareness training is provided for members of staff

In the case of a breach the company ‘panic plan’ is as follows:

  • Any breach will be immediately reported to the ICO within 72 hours
  • The individual whose data is involved will be notified
  • If a criminal offence is thought to have taken place the Police will be informed
  • The company will seek to retrieve the data if possible and/or prevent it from being shared more widely