1. Home
  2. Knowledge Base
  3. Assurance & Risk

Assurance & Risk

Disclosure form (for Contract Holder use)

This is the disclosure form you need to get the tenant to fill out if they want someone else to...

GDPR Breach Procedure – purpose of the procedure

This procedure must be used in conjunction with our Confidentiality & Data Protection policy. The procedure sets out the process for...

GDPR Breach Procedure – What is covered by the procedure?

This procedure details how our staff and Board members will be expected to respond to an incident (i.e. breach of...

GDPR Breach Procedure – What are the definitions?

Personal data – this is information about a living individual who can be identified from that information or from this information and other...

GDPR Breach Procedure – Overview

Information security breaches can happen for a number of reasons and may cause harm and distress to the individuals they...

GDPR Breach Procedure – Breach Management Plan

The ICO identifies four elements that should be applied as part of any breach management plan and includes:- Containment and...

GDPR Breach Procedure – Assessing the risks

The following will be considered:- The type of data involved How sensitive the data is e.g. health records, bank account...

GDPR Breach Procedure – Notifications to ICO

If we ever have occasion to notify the ICO of a breach then we will need to include details of...

GDPR Breach Procedure – How can I prevent a breach from occurring?

Do not:- Use someone else’s password/access code to access information. Leave personal data or sensitive personal data on your desk...

GDPR Breach Procedure – evaluation and response

It is important that we evaluate the effectiveness of our response to a breach and not just the cause.  Evaluation...

Contract Holder Data Management

A contract holder’s data will be collected, stored and shared in accordance with our Privacy Policy which is available on...

What is a Subject Access Request?

Individuals have the right to access and receive a copy of their personal data, and other supplementary information. This is...

How is a Subject Access Request made?

A SAR is a request that can be made in writing, by email or verbally asking for access to the...