Data Protection & GDPR Compliance Policy
Sharing the creativity, passion, and process behind our projects.
1. Introduction
Dynamic X Plus Limited is committed to ensuring the security and protection of personal data that we process. We adhere to the principles of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, ensuring transparency, accountability, and security in handling personal information. Additionally, as a Cyber Essentials Certified company, we implement robust security measures to mitigate cyber risks.
2. Scope
This policy applies to all employees, contractors, and third parties processing personal data on behalf of Dynamic X. It covers data collected, stored, and processed through our business operations, including customer data, employee records, and supplier information.
3. Data Protection Principles
- Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and transparently.
- Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes.
- Data Minimisation: Only necessary data is collected and processed.
- Accuracy: Data is kept accurate and up to date.
- Storage Limitation: Data is retained only for as long as necessary.
- Integrity and Confidentiality: Data is processed securely to prevent unauthorised access.
- Accountability: Dynamic X takes responsibility for data protection compliance.
4. Lawful Basis for Processing
- Consent: The individual has given explicit consent.
- Contractual Necessity: Processing is required for contract fulfilment.
- Legal Obligation: Compliance with legal requirements.
- Legitimate Interest: Where processing is necessary for business operations.
5. Rights of Data Subjects
- Right to Access
- Right to Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Rights Related to Automated Decision Making
6. Data Security Measures
- Firewalls and network security protections
- Access controls and role-based permissions
- Encryption of sensitive data
- Regular security audits and vulnerability assessments
- Secure disposal of redundant data
- Employee training on data protection best practices
7. Data Retention and Disposal
Personal data is retained for only as long as necessary, based on business, legal, and regulatory requirements. Secure disposal methods, such as data wiping and document shredding, are employed for redundant data.
8. Data Breach Management
- Identify and contain the breach
- Assess the risk and impact
- Notify the ICO (if required) within 72 hours
- Inform affected individuals (if necessary)
- Implement corrective measures to prevent future breaches
9. Third-Party Data Processing
Dynamic X ensures that all third-party vendors handling personal data comply with GDPR requirements through data processing agreements.
10. Compliance and Review
This policy is reviewed annually and updated as necessary to remain compliant with GDPR and other relevant regulations.
For any queries related to this policy, please contact:
CTO – Madhawa: madhawa@dynamicxplus.co.uk
IT Support – Dhananjaya (Pltned Limited): dhananjaya.d@platned.com
Certification Reference: Cyber Essentials Certification Number: c25e4e90-ad2c-4b1c-8cdd-8f4b03029751