The below details Everthought Education requirements to comply to GDPR. The General Data Protection Regulation (GDPR) gives the individuals the right to request personal data, which is processed from a controller.
Requests are referred to as Data subject access requests or access requests.
RIGHT OF ACCESS, CORRECTION, ERASURE
An individual has the right to obtain the following information from a controller:
Requests in writing, specific as possible in relation to personal data you wish to access. Provide evidence of your identity
Controller will provide information in writing
Controller can refuse where access request is manifestly unfounded or excessive – need to provide proof.
Controller needs to consider the rights of third parties when reviewing a request – rights such as data protection, trade secrets or intellectual property of others.
A balance of rights, the controller should endeavor to comply with the request insofar as possible, whilst protecting the rights and freedoms of others.
Client to put in writing to [email protected]
The request will be assessed by the Data Protection Officer.
The assessment will factor in the GDPR controller requirements – ensuring proof of identity. If not provided in the first instance, the Data Protection Officer will request prior to the assessment.
A response will be issued to the client in writing either providing the requested information or action taken; or in the event the request is deemed to be unfounded or excessive, provide justification for declining the request.
The PII will be reviewed in all listed business systems.
Request to modify can be actioned such as change of name, contact information.
Request to erase information will need to be considered and the client informed of potential implications of engaging with Everthought Education.
Example the client is booked for a course in two months time and requests Everthought Education to remove their email address from our system. Booking management processes in the lead up to training, include email communication.
Staff can source PII retained via Employment Hero and can actively manage their own information.