...
Expand | ||
---|---|---|
| ||
Can your organisation facilitate an individual's data privacy rights? Yes, please see details in our https://www.commonplace.is/privacy-policy and our GDPR compliance statement. Respondents can use their profile: profile.commonplace.is to update their data at any time. This includes all demographic data (except anonymised special category data) and communication preferences. They can also request deletion from here or by emailing support@commonplace.is Two years after the license ends at the latest, each project is archived and anonymised. |
Expand | ||
---|---|---|
| ||
Does your organisation have a Records Retention Policy? Yes. XXXXX, please see details in our https://www.commonplace.is/privacy-policy and our GDPR compliance statement. Respondents can use their profile: profile.commonplace.is to update their data at any time. This includes all demographic data (except anonymised special category data) and communication preferences. They can also request deletion from here or by emailing support@commonplace.is Two years after the license ends at the latest, each project is archived and anonymised. |
Expand | ||
---|---|---|
| ||
Does your organisation have robust detection, investigation and reporting procedures in place for personal data breaches, including maintaining a record of all personal data breaches? We log every data breach or suspected data breach. We track the date, severity and resolution. Upon becoming aware of a security incident an assessment must be made to understand if a data breach has occurred, and if so to what extent. The assessment is broken up into 2 stages: triage and investigation. The purpose of this is to ensure that appropriate mechanisms are in place to identify when a data breach has occurred with a proportional amount of resource. The objectives of this procedure are:
We also have a guidance document as part of our Information Security Management System. |
...