12.07.2015 Views

ETTA Data Protection Policy - The English Table Tennis Association

ETTA Data Protection Policy - The English Table Tennis Association

ETTA Data Protection Policy - The English Table Tennis Association

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• ensure that all activities that relate to the processing of personal data haveappropriate safeguards and controls in place to ensure information security andcompliance with the Act;• ensure that all contracts and service level agreements (SLAs) between the <strong>ETTA</strong> andexternal third parties (for example funders) - where personal data is processed -make reference to the Act as appropriate;• ensure that all staff acting on the <strong>ETTA</strong>'s behalf understand their responsibilitiesregarding information security under the Act, and that they receive the appropriatetraining / instruction and supervision so that they carry these duties out effectivelyand consistently and are given access to personal information that is appropriate tothe duties they undertake;• ensure that all third parties acting on the <strong>ETTA</strong>'s behalf are given access to personalinformation that is appropriate to the duties they undertake and no more;• ensure that any requests for access to personal data are handled courteously,promptly and appropriately, ensuring that either the data subject or his/her authorisedrepresentative has a legitimate right to access under the Act that the request is valid,and that information provided is clear and unambiguous. All actions regarding datasubject access requests will be logged. This audit trail will include details regardingthe nature of the request, the steps taken to validate it, the information provided aswell as any withheld, e.g. for legal reasons.• never, under any circumstances, exploit your data for commercial gain but it may,from time to time, release your personal data to other National Governing Bodies forUK sport and Government agencies involved in sport in the UK. In thesecircumstances, the data will be held for the duration of the project and destroyedimmediately after use.• allow you to request that your data is held solely for the purposes of the <strong>ETTA</strong>. Thiscan be achieved by you making the request (in writing) to the <strong>Data</strong> <strong>Protection</strong> Officer,at the following address:<strong>English</strong> <strong>Table</strong> <strong>Tennis</strong> <strong>Association</strong> LimitedQueensbury House (Fourth Floor)Havelock RoadHastingsEast Sussex TN34 1HF• work towards adopting, as best working practice, the key principles of BS7799- theBritish Standard on Information Security Management;• Implement a security policy for controlling staff use of data and governing staffhandling of personal data• review this policy and the safeguards and controls that relate to it annually - toensure that they are still relevant, efficient and effective.3 <strong>The</strong> <strong>ETTA</strong> responsibilities under the Act3.1 <strong>Data</strong> <strong>Protection</strong> means that the <strong>English</strong> <strong>Table</strong> <strong>Tennis</strong> <strong>Association</strong> (<strong>ETTA</strong>) must:• manage and process personal data properly• protect the individual's rights to privacy• provide an individual with access to all personal information held on them3.2 <strong>The</strong> <strong>English</strong> <strong>Table</strong> <strong>Tennis</strong> <strong>Association</strong> (<strong>ETTA</strong>) has a legal responsibility to comply withthe Act. <strong>The</strong> Senior Management Team member with overall responsibility for this policy is

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!