...
Expand | ||
---|---|---|
| ||
Does your organisation have a Records Retention Policy? Yes, please see details in our https://www.commonplace.is/privacy-policy and our GDPR compliance statement. Respondents can use their profile: profile.commonplace.is to update their data at any time. This includes all demographic data (except anonymised special category data) and communication preferences. They can also request deletion from here or by emailing support@commonplace.is Two years after the license ends at the latest, each project dataset is archived and anonymised. It will not be deleted. The archiving process anonymises all data and removes relationships between data and people, but maintains the website as published (with visible status completed / closed) in the interest of public / open data. More information: https://commonplace.atlassian.net/l/cp/aSNRQm92 |
Expand | ||
---|---|---|
| ||
Does your organisation have robust detection, investigation and reporting procedures in place for personal data breaches, including maintaining a record of all personal data breaches? We log every data breach or suspected data breach. We track the date, severity and resolution. Upon becoming aware of a security incident an assessment must be made to understand if a data breach has occurred, and if so to what extent. The assessment is broken up into 2 stages: triage and investigation. The purpose of this is to ensure that appropriate mechanisms are in place to identify when a data breach has occurred with a proportional amount of resource. The objectives of this procedure are:
We also have a guidance document as part of our Information Security Management System. |
...