Skip to main content
All CollectionsInformation SecurityCompany Policies
Data Privacy and Data Protection Policy

Data Privacy and Data Protection Policy

Akshat Singhal avatar
Written by Akshat Singhal
Updated over a week ago

Legistify Services private limited

Data Privacy and Data Protection Policy

Effective Date: [Insert Date]

Document Name:

Data Privacy and Data Protection Policy

Classification:

Internal

Document Owner:

CISO/MR-

Document Approver:

Top Management

Original Document Issue Date:

10/09/2023

Current Edition:

Version 2.0

Revision History:

S. No.

Description of Change

Date of Change

Version No.

1

Initial Release

10/09/2023

1.0

2

Second Release

10/09/2024

2.0

3

5

6

7

Introduction

  1. This Data Privacy and Data Protection Policy outlines the principles and procedures for protecting the privacy and ensuring the responsible handling of personal information by Legistify Services private limited.

  2. All employees, contractors, and third-party partners are required to adhere to this policy to uphold the organization's commitment to data privacy.

Scope

  1. This policy applies to all personal information collected, processed, stored, and transmitted by Legistify Services private limited, regardless of the format in which it is stored.

  2. The policy applies to all employees, contractors, and third-party partners who have access to personal information.

Data Protection Principles

  1. Personal information will be processed in accordance with the following principles:

    • Lawfulness, fairness, and transparency.

    • Purpose limitation.

    • Data minimization.

    • Accuracy.

    • Storage limitation.

    • Integrity and confidentiality.

  2. All processing of personal information must have a lawful basis, and individuals will be informed of the purposes for which their data is being collected.

Data Collection and Consent

  1. Personal information will only be collected for specified, explicit, and legitimate purposes.

  2. Individuals will be provided with clear and concise information about the collection and processing of their data, and their consent will be obtained before processing, where applicable.

  3. Consent may be withdrawn at any time, and individuals will be informed of the consequences of withdrawing consent.

Data Security

  1. Appropriate technical and organizational measures will be implemented to ensure the security of personal information.

  2. Access controls, encryption, and regular security assessments will be employed to protect personal data from unauthorized access, disclosure, alteration, and destruction.

Data Retention and Disposal

  1. Personal information will be retained only for as long as necessary to fulfil the purposes for which it was collected.

  2. Retention periods will be defined based on legal, regulatory, and business requirements.

  3. Personal information that is no longer required will be securely disposed of using methods that prevent unauthorised access.

Data Subject Rights

  1. Individuals have the right to access, rectify, erase, restrict processing, and receive their personal information.

  2. Requests from data subjects to exercise their rights will be promptly addressed in accordance with applicable laws.

Data Breach Response

  1. A Data Breach Response Plan will be in place to detect, assess, and respond to any security incidents involving personal information.

  2. Data breaches will be promptly reported to the appropriate authorities and affected individuals, as required by law.

Data Protection Impact Assessments (DPIA)

  1. DPIAs will be conducted for high-risk processing activities to assess and mitigate the impact on data subjects' privacy.

  2. DPIAs will involve consultation with relevant stakeholders, including data protection authorities where necessary.

Third-Party Data Processing

  1. Third-party processors engaged to handle personal information on behalf of Legistify Services private limited must adhere to this policy and relevant data protection laws.

  2. Contracts with third parties will include data protection clauses and provisions for auditing their compliance.

Training and Awareness

  1. All employees will receive training on data protection principles, the organization's policies, and their role in ensuring compliance.

  2. Regular awareness programs will be conducted to keep employees informed about the importance of data privacy.

Policy Review and Compliance

  1. This policy will be reviewed and updated at least annually or as needed to address changes in the organization's structure, technology, or regulations.

  2. Compliance with this policy will be monitored through regular audits and assessments.

Enforcement

  1. Violations of this Data Privacy and Data Protection Policy may result in disciplinary action, including termination of employment or legal action.

  2. Employees are encouraged to report any breaches or violations promptly and may do so without fear of retaliation.

By adhering to this Data Privacy and Data Protection Policy, we demonstrate our commitment to safeguarding the privacy and rights of individuals whose personal information we process.

Policy Revision History

Date

Version

Author

Reviewer

Approver

Comments

10/09/2023

0.1

ISMS Manager

CIO

Management

Draft Version of

Data Privacy and Data Protection Policy

Did this answer your question?