5.1 Data protection by design
5.1.1 The concept of data protection by design requires organisations to integrate privacy considerations into data processing activities from the design stage. This is the approach Delta takes.
5.2 Data retention
5.2.1 We’ll not retain personal data any longer than required. We’ll comply with legal or regulatory requirements or best practice when determining how long to store data.
5.2.2 We’ll maintain our own data retention schedule so that documentation isn’t retained and stored longer than legally required and to ensure compliance with the Data Protection Act. We will review our data retention periods regularly.
5.2.3 After the relevant retention period has expired, the information will be securely destroyed or retained in a manner which prevents the identification of data subjects (anonymisation).
5.2.4 In exceptional cases we may hold data for longer than specified in our retention schedule, where required to do so by law or under contract with a data subject.
5.3 Data sharing
5.3.1 We’ll only share personal data if we have a lawful basis, and if it’s necessary to do so. If we share personal data with third parties/processors, we will carry out robust and appropriate checks and ensure there’s an adequate Data Processor and Controller Agreement (including Data Sharing Agreements) in place before any sharing takes place. 5.4 Data protection impact assessments
5.4.1 We’ll adopt a risk-based approach to processing personal data, ensuring that we assess any risks to privacy or people’s rights and freedoms before commencing, commissioning or changing data processing activities.
5.4.2 We’ll do this through Data Protection Impact Assessments.
5.5 International transfers
5.5.1 The UK GDPR restricts data transfers to countries outside of the UK to ensure that the level of data protection afforded to individuals by the UK GDPR is not undermined.
5.5.2 We’ll only transfer data outside of the UK where it is strictly necessary to do so and if certain conditions apply. Before transferring any personal data outside of the UK, we’ll take steps to ensure there are appropriate data transfer mechanisms in place to safeguard the data.
5.6 Data breaches
5.6.1 The GDPR defines personal data breach as “a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”. If there is a data breach, we’ll manage this in line with our Data Breach Procedure.
5.6.2 Employees must report any breach, potential breach, incident or data protection concern to the DPO immediately.
5.6.3 We’ll log all data breaches and will investigate each incident immediately.
5.6.4 We’ll take appropriate remedial action as soon as possible to isolate and contain the breach, evaluate and minimise its impact, and to recover from the effects of the breach. 5.6.5 We will record and investigate data protection ‘near misses’.
5.6.6 The Data Breach Procedure sets out responsibilities, decision-making criteria and timescales for notifying data subjects, and where relevant the Information Commissioner’s Office (ICO), the Audit and Risk Committee, and Board.
5.7 Data quality
5.7.1 We acknowledge that good data quality is essential to providing a positive customer experience, maintaining trust and ensures that we can meet our obligations to customers, employees, stakeholders and the Regulator of Social Housing.
5.7.2 Committed to improving data quality, and we insist that all Delta employees have a responsibility for data quality.
5.7.3 We take appropriate measures to detect and mitigate risks to data quality across our systems and processes.