“Who in your company is your Data Controller? Does anyone maintain a Data Protection policy within their organisation – and if so would anybody be prepared to share this with ourselves?”
(I would be happy to forward – anonymously if required- any policy document anyone is willing to share. David Mensley)”
FTSE SMALL CAP said
our group company and a handfull of smaller subsidiaries are registered as data controllers and we have a Data Protection Officer within the organisation. We are going to be reviewing this role in the near future so I would be very interested to see the advice on the role and personal liability/responsibility of the DP officer which others are pulling together.
FTSE 250 said
Our main listed holding company, main operating company and pension trustee company are all registered as data controllers. Our data protection officer is one of the lawyers in my team. Would be happy to share our policy once it has been anonymised.
FTSE SMALL CAP said
Topical question. Happy to share our policy on a confidential basis. As Co Sec and Head of Legal I am also the DP Officer although I now think that actually we need to appoint DP officers within each of the subsidiary companies as you need people closer to the processing to take ownership of the processing. The 1998 Act itself is regulates the Data Controller, which will be the notifying company. I am in the process of pulling together som advice on the role and personal liability/responsibility of the DP officer, which I would also be happy to share.
EX LISTED said
Technically it is the Company that is the data controller but typically it is the Company Secretary that is the main contact and listed as so in the Notification under the DPA98.
I am Data Protection Compliance officer within our organisation.
FTSE SMALL CAP said
The Company Secretary is Data Controller, and there are various policies that are issued by the company, depending on context, which I will send to David Mensley.
FTSE SMALL CAP said
We do have a policy and a separate HR attachment, as we control customer data and employee data. I will send David a standard document and also examples of our policy and the HR attachment. We have named Data Controllers for customer data and employee data as the data is cntrolled by diffferent departments and also in different territories.
FTSE 250 said
The Company Secretary is Data Controller