Security Policy 07
Security Policy 07
Security Policy 07
Introduction
At IDA Ireland privacy and data protection rights are very important to us.
IDA Ireland is registered under the Data Protection Acts 1988 and 2003 as a data
controller and data processor and all personal data will be maintained in accordance
with the obligations of that Act.
This document outlines IDA Ireland’s policy to help ensure that we comply with the
Data Protection Acts.
Inquiries about this Data Protection Policy should be made to: Manager, Compliance
& Information Management, IDA Ireland, Wilton Park House, Wilton Place,
Dublin 2.
Data Protection Policy
Purpose of this policy
This policy is a statement of IDA Ireland’s commitment to protect the rights and
privacy of individuals in accordance with the Data Protection Acts.
Individuals’ Responsibilities
Any staff member of IDA Ireland who is involved in the collection, storage or
processing of personal data has responsibilities under the legislation:.
Any staff member involved in the processing/storing of personal data should make
sure;
Any data access requests received should be forwarded immediately to the Manager,
Compliance & Information Management. A fee of €6.35 applies to any application
for information under the Data Protection Acts.
Individual Rights
The individuals for whom IDA Ireland stores personal data have the following rights:
IDA Ireland will administer its responsibilities under the legislation in accordance
with the eight stated data protection principles outlined in the Act as follows:
2. Keep data only for one or more specified, explicit and lawful purposes.
IDA Ireland will keep data for purposes that are specific, lawful and clearly stated and
the data will only be processed in a manner compatible with these purposes.
3. Use and disclose data only in ways compatible with these purposes.
IDA Ireland will only disclose personal data that is necessary for the purpose/s or
compatible with the purpose/s for which it collects and keeps the data.
7. Retain data for no longer than is necessary for the purpose or purposes for which
they are kept.
IDA Ireland will have a policy on retention periods for personal data.
IDA Ireland has overall responsibility for ensuring compliance with the Data
Protection legislation. However, all employees of IDA Ireland who collect and/or
control the contents and use of personal data are also responsible for compliance with
the Data Protection legislation. IDA Ireland will provide support, assistance, advice
and training to all relevant Departments, Offices and staff to ensure it is in a position
to comply with the legislation.
IDA Ireland is registered as a Data Controller in compliance the Act and the following
roles are included in the registration,
This policy supports the provision of a structure to assist in IDA Ireland’s compliance
with the Data Protection legislation, including the provision of best practice
guidelines and procedures in relation to all aspects of Data Protection.
Review
This Policy will be reviewed regularly in light of any legislative or other relevant
indicators.
Appendix I
Definitions
The following definitions are taken from the Data Protection Acts 1998 and 2003
Full copies of the act are available at the Data Protection Commissioner web site
www.dataprotection.ie.
Personal data means data relating to a living individual who is or can be identified
either from the data or from the data in conjunction with other information that is in,
or is likely to come into, the possession of the data controller;
(a) The racial or ethnic origin, the political opinions or the religious or
philosophical beliefs of the data subject.
(c) the physical or mental health or condition or sexual life of the data subject.
(d) the commission or alleged commission of any offence by the data subject, or
(e) any proceedings for an offence committed or alleged to have been committed
by the data subject, the disposal of such proceedings or the sentence of any court
in such proceedings.
Appendix II
Sample Letter
Please see below, sample wording for letter to access data held under the Data
Protection Acts 1988 and 2003.
When requesting information, it is important to give any details that will help the
person to identify you and find your data – for example a staff number, any previous
address or your date of birth; and be clear about which details you are looking for if
you only want certain information. This will help IDA Ireland to respond more
quickly.
A fee of €6.35 applies to any application for information under the Data Protection
Acts.
Manager
Compliance & Information Management
IDA Ireland
Wilton Park House
Wilton Place
Dublin 2
Dear Manager,
Under the Data Protection Acts 1988 and 2003, I wish to make an access request for a
copy of any information you keep about me, on computer or in manual form.
[Insert relevant information to assist IDA Ireland to identify you and find your data]
Yours faithfully,
[Name]