Back to About

    DSJ Group: Data Protection Policy

    1. Introduction

    DSJ Group is committed to ensuring the privacy and protection of personal data that we handle. This Data Protection Policy outlines how we manage and safeguard personal information in accordance with the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). The policy applies to all employees, contractors, and third parties who process personal data on behalf of DSJ Group.

    2. Purpose of the Policy

    The purpose of this policy is to:

    • Ensure DSJ Group meets its legal obligations in relation to the processing of personal data.
    • Protect the privacy rights of employees, customers, suppliers, and other stakeholders.
    • Establish clear procedures for handling personal data in a secure and compliant manner.

    3. Data Protection Principles

    We are committed to adhering to the following key principles of data protection:

    • Lawfulness, fairness, and transparency: We will process personal data lawfully, fairly, and in a transparent manner.
    • Purpose limitation: Personal data will only be collected for specified, legitimate purposes and not further processed in a manner that is incompatible with those purposes.
    • Data minimisation: We will ensure that personal data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
    • Accuracy: We will take all reasonable steps to ensure that personal data is accurate and up to date.
    • Storage limitation: Personal data will not be kept longer than necessary for the purposes for which it was collected.
    • Integrity and confidentiality: We will implement appropriate technical and organisational measures to ensure the security of personal data.

    4. Categories of Personal Data We Process

    DSJ Group may process various types of personal data, including but not limited to:

    • Employee data (e.g., name, contact details, employment history)
    • Customer data (e.g., name, address, contact details)
    • Supplier data (e.g., business contact details, financial information)
    • Health and safety records (e.g., medical conditions, accident reports)
    • Financial data (e.g., payment details, tax information)

    5. Data Collection and Use

    Personal data will be collected and used for specific purposes, such as:

    • Employee administration and payroll
    • Client contracts and communication
    • Supplier management
    • Health and safety monitoring and compliance
    • Financial management and tax reporting

    6. Legal Basis for Processing Personal Data

    We process personal data on the following legal bases, as set out by the GDPR:

    • Consent: Where explicit consent is obtained from the data subject.
    • Contractual necessity: For the performance of a contract with the data subject.
    • Legal obligation: Where processing is necessary for compliance with a legal obligation.
    • Legitimate interests: Where processing is necessary for the legitimate interests pursued by DSJ Group, provided that these interests are not overridden by the rights and freedoms of the data subject.

    7. Data Security

    DSJ Group is committed to maintaining the security of personal data by implementing appropriate technical and organisational measures to protect against unauthorised access, alteration, disclosure, or destruction. These measures include:

    • Encryption of sensitive data
    • Access controls and authentication procedures
    • Regular security audits
    • Staff training on data protection and security procedures

    8. Data Subject Rights

    Individuals whose personal data is processed by DSJ Group have the following rights:

    • Right to access: The right to obtain confirmation of whether we are processing their personal data and, if so, to access that data.
    • Right to rectification: The right to request the correction of inaccurate or incomplete personal data.
    • Right to erasure: The right to request the deletion of personal data, subject to certain conditions.
    • Right to restriction of processing: The right to request the restriction of processing personal data, under certain circumstances.
    • Right to data portability: The right to request the transfer of personal data to another organisation in a structured, commonly used, and machine-readable format.
    • Right to object: The right to object to the processing of personal data based on legitimate interests or direct marketing purposes.

    9. Data Breach Reporting

    In the event of a data breach, DSJ Group will take immediate steps to contain and assess the breach. If the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Affected individuals will also be informed if necessary.

    10. Retention of Data

    Personal data will be retained for no longer than is necessary for the purposes for which it was collected. After this period, personal data will be securely deleted or anonymised.

    11. Data Protection Officer (DPO)

    DSJ Group has appointed a Data Protection Officer (DPO) to oversee our data protection activities. The DPO can be contacted via our contact page.

    12. Training and Awareness

    All employees, contractors, and third-party partners who handle personal data are required to undergo data protection training to ensure they understand their obligations under this policy and relevant data protection laws.

    13. Policy Review

    This Data Protection Policy will be reviewed annually and updated as necessary to ensure ongoing compliance with applicable laws and regulations.