This policy forms part of Learning by Questions Ltd's ( the company’s) suit of data protection policies. It is drafted so as to comply with the GDPR (General Data Protection Regulation) which comes into force in England on the 25th of May 2018 and which replaces the Data Protection Act 1998.
This policy sets out the individual rights of data subjects, including employees of the company and in particular should be read in conjunction with the relevant Privacy Notice.
The law sets out certain rights of data subjects. Some of those rights only arise in specific circumstances, whereas others apply in all cases.
The general rights are as follows:
Some of these rights will only arise in relation to certain specific bases for processing. They are as follows:
|Bases||Right to Erasure||Right to Portability||Right to Object|
|Consent||Y||Y||N (but right to withdraw consent)|
If you are unsure about which basis for processing has been used in any given case, you should refer to the Privacy Notice which will state the basis of processing.
Where we have obtained data directly from you, you have the right to be informed of the following:
In addition, you have certain specific rights depending on the lawful basis for processing which we are relying upon. For example, if we are processing data on the “Legitimate Interests” basis, you are entitled to know what those interests are. Where we are processing data on the “Consent” basis, you are entitled to know that you have the right to withdraw your consent.
Most of this information will have been supplied to you through the Privacy Notice which relates to the processing in question.
If you wish to complain about any matter related to the processing of your personal data, you may complain either to us or to the supervisory authority.
If you wish to make an external complaint, you should contact the Information Commissioner’s Office, whose details are Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF tel: 0303 123 1113.
If we obtain your data from a third party, we must also tell you what categories of personal data we hold and must provide the information referred to above at the earliest of:
This is very similar to the old subject access regime and allows individuals to have the right to obtain:
The right to charge £10.00 has been removed and (subject to the below) all subject access requests must be dealt with for free.
The time lapse for compliance with a subject access request has dropped from 40 days to 1 month.
Where a request for information is made electronically, the information should be provided in commonly used electronic format (typical emails with pdf or other attachments).
Where requests are manifestly unfounded or excessive (especially if they are repetitive) we can charge a reasonable fee to take account of the administrative costs of providing the information or may refuse to respond.
Where we refuse to comply with a subject access request, we must explain why we are refusing and inform the data subject of their right to complain to a supervisory authority and/or for a judicial remedy. That information must be provided within one month.
The larger the amount of data requested, the easier it might be to argue that a request is manifestly unfounded or excessive.
Before complying with the subject access request, we must verify your identity using “reasonable means”. This is to ensure that we do not send your data to the wrong person.
If a subject access request is made by electronic means, we must provide the information requested in a commonly used electronic format.
If we hold a large quantity of information about an individual, we may be permitted to ask you to specify what information you have requested pursuant to your subject access request. This will help us target your request.
You have the right to have data held about your rectified if, for any reason, it is inaccurate or incomplete.
Where we have disclosed your data to third parties, we must notify them of any rectification action which we take.
You may make a request for rectification by post to (Learning by Questions Ltd, Bowland House, Philips Road, Blackburn, BB1 5NA) or by e-mail to email@example.com. Your request for rectification should contain sufficient information for us to understand what data which we hold is inaccurate or incomplete and what the correct data is. It would also assist if you could explain why the data we hold is not correct, although this is not absolutely necessary.
We may have to contact you if there is anything we do not understand in your request for rectification.
We must respond to a request for rectification within one month, although this can be extended to two months where your request is complicated.
If you are not happy with our decision about rectification, you may complain to the Information Commissioner’s Office using the contact details set out above or you may apply to the Courts for a judicial remedy.
Depending on which basis we use for processing your data, you may have a right to erasure of that data. This is also known as the “right to be forgotten” and allows you to request the deletion or removal of your personal data when there is no longer any compelling reason for us to continue processing it.
The right to erasure applies in any of the following circumstances:
We may refuse to comply with a request for erasure in certain limited circumstances, which include bringing or defending legal claims or for archiving purposes which are in the public interest or which for the purposes of scientific or historical research or statistical purposes.
Where we accept a request for erasure, we must tell any third party to whom we have disclosed the data.
We will be obliged to restrict the processing of your personal data in any of the following circumstances:
During a period of restriction, we may still store your data, but we may not use it.
Where we have disclosed your data to third parties, we must notify them of any restriction that is in force.
If you wish to restrict the processing of your data, you may make a request by post to (Learning by Questions Ltd, Bowland House, Philips Road, Blackburn, BB1 5NA) or by e-mail to firstname.lastname@example.org.
The right to data portability is a new right which allows you to re-use data we hold about you for obtaining services elsewhere or for your own purposes. It is designed to allow easy transfer of your data from one IT system to another.
The right to data portability will only apply in limited circumstances (where we are processing your data with your consent or pursuant to an obligation under contract) and also when the processing has been carried out by automated means.
You can request data portability by contacting (Learning by Questions Ltd, Bowland House, Philips Road, Blackburn, BB1 5NA) by post or by e-mail to email@example.com
We must provide the personal data in a structured, commonly used and machine readable form. We must provide the data free of charge. We will send the data to you or direct to a third party organisation if you request it.
We must comply with a request for data portability without undue delay and in any event within one month. However, this can be extended to two months where the request is complex or we receive more than one request. If we need more than one month, we will write to you to tell you why the extension is necessary.
If we refuse your request for data portability, we must explain why and if you are not happy with our decision, you may complain to the Information Commissioner’s Office using the contact details set out above or you may apply to the Courts for a judicial remedy.
You have the right to object to us processing your data if we are processed on the grounds of legitimate interests. The right also applies in certain other circumstances, but these do not apply to the company.
You also have the right to object to the processing of your data for direct marketing (including profiling) and the processing of your data for the purposes of gathering statistics or for scientific/historical research.
Your right to object must be sent to (Learning by Questions Ltd, Bowland House, Philips Road, Blackburn, BB1 5NA)by post or by e-mail to firstname.lastname@example.org. You must set out the grounds for your objection which must relate to your own particular situation.
Upon receipt of your objection, we must stop processing your data unless either of the following criteria applies:
If you object to the processing of your personal data for direct marketing purposes, we must cease that processing immediately. There are no grounds for us to refuse.
Where we carry out processing of data online, you must be able to raise an objection online.
We may occasionally use automated individual decision making or profiling.
Automated individual decision making occurs when decisions on a particular matter are made solely by a computer programme without any human involvement. Profiling occurs when a computer system carries out automated processing of data to draw conclusions about individuals.
We may only carry out automated decision making where such decision making is necessary for the entering into (or the performance) of a contract or is based on you giving your explicit consent.
Usually, we will carry out a data and protection impact assessment to consider and address risks of automated decision making or profiling before we commence with them.