Legistify Services private limited
Data Privacy and Data Protection Policy
Effective Date: [Insert Date]
Document Name: | Data Privacy and Data Protection Policy |
|
|
Classification: | Internal |
|
|
Document Owner: | CISO/MR- |
|
|
Document Approver: | Top Management |
|
|
Original Document Issue Date: | 10/09/2023 |
|
|
Current Edition: | Version 2.0 |
|
|
Revision History: |
|
|
|
S. No. | Description of Change | Date of Change | Version No. |
1 | Initial Release | 10/09/2023 | 1.0 |
2 | Second Release | 10/09/2024 | 2.0 |
3 |
|
|
|
5 |
|
|
|
6 |
|
|
|
7 |
|
|
|
Introduction
This Data Privacy and Data Protection Policy outlines the principles and procedures for protecting the privacy and ensuring the responsible handling of personal information by Legistify Services private limited.
All employees, contractors, and third-party partners are required to adhere to this policy to uphold the organization's commitment to data privacy.
Scope
This policy applies to all personal information collected, processed, stored, and transmitted by Legistify Services private limited, regardless of the format in which it is stored.
The policy applies to all employees, contractors, and third-party partners who have access to personal information.
Data Protection Principles
Personal information will be processed in accordance with the following principles:
Lawfulness, fairness, and transparency.
Purpose limitation.
Data minimization.
Accuracy.
Storage limitation.
Integrity and confidentiality.
All processing of personal information must have a lawful basis, and individuals will be informed of the purposes for which their data is being collected.
Data Collection and Consent
Personal information will only be collected for specified, explicit, and legitimate purposes.
Individuals will be provided with clear and concise information about the collection and processing of their data, and their consent will be obtained before processing, where applicable.
Consent may be withdrawn at any time, and individuals will be informed of the consequences of withdrawing consent.
Data Security
Appropriate technical and organizational measures will be implemented to ensure the security of personal information.
Access controls, encryption, and regular security assessments will be employed to protect personal data from unauthorized access, disclosure, alteration, and destruction.
Data Retention and Disposal
Personal information will be retained only for as long as necessary to fulfil the purposes for which it was collected.
Retention periods will be defined based on legal, regulatory, and business requirements.
Personal information that is no longer required will be securely disposed of using methods that prevent unauthorised access.
Data Subject Rights
Individuals have the right to access, rectify, erase, restrict processing, and receive their personal information.
Requests from data subjects to exercise their rights will be promptly addressed in accordance with applicable laws.
Data Breach Response
A Data Breach Response Plan will be in place to detect, assess, and respond to any security incidents involving personal information.
Data breaches will be promptly reported to the appropriate authorities and affected individuals, as required by law.
Data Protection Impact Assessments (DPIA)
DPIAs will be conducted for high-risk processing activities to assess and mitigate the impact on data subjects' privacy.
DPIAs will involve consultation with relevant stakeholders, including data protection authorities where necessary.
Third-Party Data Processing
Third-party processors engaged to handle personal information on behalf of Legistify Services private limited must adhere to this policy and relevant data protection laws.
Contracts with third parties will include data protection clauses and provisions for auditing their compliance.
Training and Awareness
All employees will receive training on data protection principles, the organization's policies, and their role in ensuring compliance.
Regular awareness programs will be conducted to keep employees informed about the importance of data privacy.
Policy Review and Compliance
This policy will be reviewed and updated at least annually or as needed to address changes in the organization's structure, technology, or regulations.
Compliance with this policy will be monitored through regular audits and assessments.
Enforcement
Violations of this Data Privacy and Data Protection Policy may result in disciplinary action, including termination of employment or legal action.
Employees are encouraged to report any breaches or violations promptly and may do so without fear of retaliation.
By adhering to this Data Privacy and Data Protection Policy, we demonstrate our commitment to safeguarding the privacy and rights of individuals whose personal information we process.
Policy Revision History
Date | Version | Author | Reviewer | Approver | Comments |
10/09/2023 | 0.1 | ISMS Manager | CIO | Management | Draft Version of Data Privacy and Data Protection Policy |
|
|
|
|
|
|
|
|
|
|
|
|