GDPR Compliance Definition
Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), governs the protection of natural persons in relation to the processing of personal data and the free movement of such data. It has applied since 25 May 2018.
The GDPR establishes obligations for organisations acting as controllers or processors and provides rights and protections for all individuals whose personal data falls within its territorial scope.
GDPR Compliance Statement
LEADing Practice is committed to protecting personal data and complying with all applicable data-protection legislation, including the GDPR. We process personal data in accordance with the principles established by Article 5 of the GDPR, under which personal data shall be:
- Processed lawfully, fairly and in a transparent manner in relation to the data subject.
- Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- Accurate and, where necessary, kept up to date.
- Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
LEADing Practice also applies the accountability principle and is responsible for demonstrating compliance with these requirements.
GDPR Compliance Commitment
LEADing Practice respects the privacy and data-protection rights of our customers, software users, learners and other individuals whose personal data we process. We maintain and periodically review internal policies, procedures and working practices designed to ensure ongoing compliance with the GDPR.
We apply technical and organisational measures appropriate to the nature and risk of the processing. These include purpose limitation, data minimisation, need-to-know access controls, secure storage, accuracy and version control, retention and deletion controls, confidentiality obligations and incident-management procedures.
Depending on the processing activity, LEADing Practice acts as either controller or processor. When processing personal data on behalf of a customer, we act under applicable contractual terms and documented instructions. Relevant service providers that process personal data for us are subject to appropriate contractual, security and data-protection safeguards.
Data Security and Approved Service Providers
Personal data may be stored or processed using approved cloud and technology service providers where this supports a specified and legitimate business purpose. Access is restricted to authorised personnel with a need to know. Appropriate contractual, security and international-transfer safeguards are applied, unnecessary duplication is avoided, and personal data is retained only for as long as required.
GDPR Contact
Questions about this statement, our processing of personal data or the exercise of applicable data-protection rights may be sent to info@leadingpractice.com. Further information is available in our Privacy Policy.