At a Glance Summary
- Malvern International, including Language in Action, commits to adhering to Data Protection legislation and processing personal data in line with the data protection principles.
- The Data Protection Officer is responsible for monitoring compliance and can be contacted at gdpr@malvernplc.com.
- All staff, contractors and suppliers must handle personal data appropriately and protect their credentials.
- Malvern International operates on a least-privilege basis and staff should only access data relevant to their role.
- Data subjects have rights regarding their personal data, including access requests managed by the Data Protection Officer.
Purpose
Malvern International is committed to conducting its business in accordance with all applicable Data Protection laws and regulations and in line with the highest standards of ethical conduct.
This policy sets out the expected behaviours and standards required of employees and third parties in relation to the collection, use, retention, transfer, disclosure and destruction of personal data.
Scope of the Policy
This policy applies to all Malvern International entities where a data subject’s personal data is processed and covers both electronic and structured manual records.
Policy Enforcement
The Leadership Team must ensure that all employees and third parties who process personal data comply with this policy. Appropriate assurances will be sought before granting third parties access to personal data.
Data Protection Principles
Lawfulness, Fairness and Transparency
Personal data must be processed lawfully, fairly and transparently, with clear records of processing activities maintained by the Data Protection Officer.
Purpose Limitation
Personal data shall only be collected for specified, explicit and legitimate purposes and must not be processed incompatibly with those purposes.
Data Minimisation
Only data necessary for the stated purpose shall be collected and retained.
Accuracy
Personal data must be kept accurate and up to date.
Storage Limitation
Data shall only be retained for as long as necessary and in accordance with retention schedules.
Integrity and Confidentiality
- Do not share passwords or credentials.
- Do not upload or forward company data to unauthorised third parties.
- Do not disable security controls or anti-virus systems.
Accountability
Malvern International and its staff are responsible for demonstrating compliance with data protection legislation.
Company Personnel Responsibilities
- Only access personal data required for authorised duties.
- Keep personal data secure and confidential.
- Use strong passwords and lock devices when unattended.
- Do not store company data on personal devices.
- Dispose of personal data securely when no longer required.
Data Collection
Personal data should normally be collected directly from the data subject unless a lawful exception applies. Data subjects must receive appropriate privacy information in line with legal requirements.
Digital Marketing
Promotional communications must comply with data protection law. Individuals must always have the right to object to direct marketing activities.
Data Retention
Personal data will only be retained for as long as necessary to fulfil legal, contractual and business requirements.
Security and Confidentiality
- Prevent unauthorised access to systems.
- Restrict access to authorised personnel only.
- Maintain access logs.
- Protect data during electronic transmission.
- Provide mandatory staff training.
Data Subject Rights and Requests
Data subjects may request:
- Access to their information.
- Rectification of inaccurate data.
- Erasure of data where appropriate.
- Restriction of processing.
- Data portability.
- Objection to processing or automated decision-making.
Requests must be referred immediately to the Data Protection Officer.
Law Enforcement Requests and Disclosures
Personal data may be disclosed without consent where required for crime prevention, legal obligations, taxation matters or court orders.
Data Protection Training
All staff with access to personal data must complete mandatory data protection training as part of induction and ongoing compliance requirements.
Transfers Between Sites and Third Parties
Data transfers must only occur through authorised channels and be supported by appropriate agreements and safeguards.
Complaints Handling
Complaints regarding personal data processing should be directed to gdpr@malvernplc.com.
Breach Reporting
Any suspected personal data breach must be reported immediately to gdpr@malvernplc.com so that appropriate investigation and response measures can be implemented.
Policy Approval
| Date: March 2025 | Version: 1 |
| Author: Kelly McGrath, Head of HR | Review date: March 2027 |
| Approved by Chief Executive Officer Richard Mace: |