1. Introduction
The EU General Data Protection Regulation ('GDPR' or 'Regulation') came into force across the European Union on 25th May 2018 and brought with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age.
The 21st Century brings with it broader use of technology, new definitions of what constitutes personal data, and a vast increase in cross-border processing. The new Regulation aims to standardize data protection laws and processing across the EU; affording individuals stronger, more consistent rights to access and control their personal information.
2. Our Commitment
Silk Road Professionals is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. Silk Road Professionals is dedicated to safeguarding the personal information under our remit and in developing a data protection regime that is effective, fit for purpose and that demonstrates an understanding of, and appreciation for the new Regulation. Our preparation and objectives for GDPR compliance have been summarised in this statement. This Statement also includes the development and implementation of new data protection roles, policies, procedures, controls and measures to ensure maximum and ongoing compliance.
3. Measures and Precautions
Silk Road Professionals complies with GDPR. Our measures and precautions include:
Information Audit
To ensure compliance with the GDPR, we have carried out a company-wide information audit aimed to identify, record, and structure the personal data that we hold and process. The audit has outlined clearly the types of personal data that we have collected, sources of the data, the legal grounds for processing, and the purposes of processing such data.
Policies & Procedures
The Company has implemented data protection policies and procedures to meet the requirements and standards of the GDPR including:
Data Protection
Our data and security policy addresses all facets of collection, use, storage, and disclosure of personal data. The Company has also put in place accountability and governance measures to ensure that we understand and adequately disseminate and evidence our obligations and responsibilities.
Data Retention & Erasure
The Company has updated its personal retention and erasure policy including a retention schedule that will govern the period that personal data will be retained. The schedule will also ensure that the Company meets GDPR's 'data minimization' principles and that personal information is stored, archived and destroyed in a lawful and transparent manner. We have put erasure procedures in place to meet the new 'Right to Erasure' obligations and are aware of when this and other data subject's rights apply along with limitations on this right, response timeframes and notification requirements.
Data Breaches
As part of our commitment to comply with data protection laws and GDPR, we have adopted a data breach procedure to ensure that we have safeguards and measures in place to identify, assess, investigate, record, report, mitigate and prevent any personal data breach at the earliest possible time.
Subject Access Request (SAR)
The Company has established SAR procedures that complement our data protection and procedures policy, including the revised 30-day timeframe for handling subject requests for information. In the event of a subject access request, an extract of information processed by the Company shall be provided to the data subject free of charge.
Legal Basis for Processing
We have reviewed processing activities to identify the legal basis for processing of personal data. Where applicable, we also maintain records of our processing activities.
Privacy Policy
We have revised our Privacy Policy to comply with GDPR, ensuring that all individuals whose personal information we process have been informed of why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their information.
Processor Agreements
We have drafted Data Processing Agreements and due diligence procedures for ensuring that third parties understand and meet GDPR obligations.
4. Data Subject Rights
Your GDPR Data Rights:
To exercise your rights, mail privacy@srpsoftware.com with the subject line "Data Subject Request" and include:
What to expect:
5. Information Security Measures
Silk Road Professionals takes the privacy and security of individuals and their personal information very seriously and takes reasonable measures and precautions to protect and secure the personal data that we process. We have information security policies and procedures in place to protect personal information from unauthorised access, alteration, disclosure or destruction.
6. GDPR Contact
If you have any questions about our GDPR policy, please contact privacy@srpsoftware.com
If you have any questions about this policy, please contact us at privacy@srpsoftware.com