Data Protection / GDPR Policy
1. Policy Purpose
This policy sets out Delta Force Group Ltd's commitment to protecting personal information and complying fully with the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Its purpose is to ensure that all data is handled lawfully, fairly, securely, and transparently, protecting the rights and freedoms of individuals at all times.
The policy provides a clear framework for how personal data is collected, processed, stored, shared, and disposed of. It ensures that only the minimum necessary information is used, that it is kept accurate and up to date, and that it is retained only for as long as required. By embedding these principles into our daily operations, Delta Force Group Ltd safeguards the trust of clients, employees, residents, suppliers, and partners while meeting both legal obligations and industry best practice.
2. Scope
This policy applies to all employees, contractors, agency workers, and partners working for or on behalf of Delta Force Group Ltd. It covers anyone who handles personal data as part of their role, whether in digital systems, paper records, communications, or images such as CCTV.
The scope includes all personal data relating to:
- Employees and Applicants: HR records, recruitment files, training records, and payroll information.
- Clients and Residents: Service user information, contact details, and records required to deliver our services.
- Suppliers and Partners: Business contact information and contractual data required for procurement and collaboration.
- Visitors and the Public: Information gathered through site access records, security systems, and incident reporting.
By applying this policy across all areas of operation, Delta Force Group Ltd ensures that personal data is handled consistently, securely, and in compliance with legal requirements, regardless of its source or format.
3. Policy Statement
Delta Force Group Ltd is committed to upholding the highest standards of data protection. We respect the privacy of every individual whose personal data we process and take full responsibility for handling that data lawfully and securely.
We process personal data only where there is a clear and valid legal basis, such as consent, the performance of a contract, compliance with legal obligations, or legitimate interests. We are transparent about how information is used, and individuals are informed of their rights and how to exercise them.
Personal data will always be:
- Collected for specified and legitimate purposes.
- Accurate, relevant, and limited to what is necessary.
- Kept secure using technical and organisational safeguards.
- Retained only for as long as required before being securely destroyed.
Through this policy, Delta Force Group Ltd demonstrates its accountability under UK GDPR and its commitment to protecting the rights of employees, clients, residents, suppliers, and all other data subjects.
4. Legal and Standards References
This policy is informed by the following legislation, regulations, and standards which together establish the framework for data protection within the UK:
- UK General Data Protection Regulation (UK GDPR): Governs the lawful collection, processing, storage, and transfer of personal data.
- Data Protection Act 2018: Provides additional rules and safeguards for processing personal information in the UK.
- Human Rights Act 1998: Protects the right to privacy and ensures that individuals' personal information is treated with respect.
- Privacy and Electronic Communications Regulations (PECR): Applies to electronic communications, cookies, and marketing practices.
- Cyber Essentials Certification: Demonstrates that Delta Force Group Ltd has appropriate IT security controls to protect against common cyber threats.
- ISO 9001 & ISO 27001 Principles: Reinforce data protection through structured management systems, focusing on quality assurance and information security.
By following these frameworks and standards, Delta Force Group Ltd ensures that personal data is managed responsibly, securely, and in full compliance with both legal requirements and recognised best practice.
5. Roles and Responsibilities
Delta Force Group Ltd ensures that responsibilities for data protection are clearly defined and understood at every level of the organisation.
Managing Director: Holds overall accountability for compliance with data protection legislation and this policy. Provides leadership, resources, and oversight to ensure data protection is integrated into company strategy and daily operations.
Data Protection Lead (DPL): Appointed to oversee the implementation of this policy. The DPL is responsible for advising on compliance, monitoring practices, coordinating staff training, and acting as the first point of contact for data subjects or regulatory authorities.
Managers and Supervisors: Ensure that data protection procedures are followed within their teams. They are responsible for checking that staff handle personal data correctly, addressing risks, and escalating issues to the DPL where required.
All Staff and Subcontractors: Every individual has a duty to comply with this policy. This includes completing data protection training, safeguarding the information they handle, and reporting any suspected breaches or concerns immediately.
By assigning clear roles, Delta Force Group Ltd ensures that data protection is a shared responsibility embedded throughout the organisation.
6. Implementation
Delta Force Group Ltd puts this policy into practice through a range of measures designed to ensure compliance with data protection law and the safeguarding of personal information.
- Fair Processing: Personal data is collected and processed only for specified, explicit, and legitimate purposes. Individuals are informed of how their data will be used at the point of collection through clear privacy notices.
- Lawful Basis: Data is processed only where there is a valid legal basis, such as consent, performance of a contract, compliance with a legal obligation, or legitimate business interests.
- Data Subject Rights: We respect the rights of individuals under UK GDPR, including the right to access, rectify, restrict, or erase their personal data, and the right to object to certain types of processing. Requests are handled promptly and in line with statutory timeframes.
- Data Sharing: Personal data is only shared with authorised third parties where necessary and subject to appropriate safeguards such as contractual agreements. Information will never be sold to third parties.
- Security Measures: We use secure IT systems, encryption, password protection, access controls, and staff training to protect data. Hard copy information is stored in locked facilities with access restricted to authorised staff.
- Retention and Disposal: Personal data is retained only for as long as necessary to meet business or legal requirements. Once no longer needed, data is securely destroyed using approved disposal methods for both digital and paper records.
- Data Breaches: All suspected or actual breaches must be reported immediately to the Data Protection Lead. Incidents are investigated without delay, and where legally required, reported to the Information Commissioner's Office (ICO) within 72 hours.
7. Monitoring and Continuous Improvement
Delta Force Group Ltd recognises that effective data protection requires regular monitoring and a commitment to continuous improvement.
- Policy Review: This policy is reviewed annually, or sooner if there are changes to legislation, regulatory guidance, or business operations. Updates are communicated to all staff to ensure ongoing compliance.
- Audits and Inspections: Regular audits are carried out to assess compliance with GDPR principles, test the effectiveness of security measures, and identify areas for improvement.
- Training and Awareness: Staff training is refreshed annually to reinforce responsibilities and raise awareness of emerging risks, such as cyber threats or phishing attempts.
- Feedback and Lessons Learned: Feedback from staff, clients, and regulators is used to improve our processes. Any lessons from data incidents or breaches are built into future procedures and training.
- Commitment to Improvement: We continuously update our systems, policies, and procedures to reflect best practice, making sure that data protection remains a central part of our culture and service delivery.
8. Associated Policies
This Data Protection / GDPR Policy is supported by a range of related policies and procedures which together ensure compliance and robust information governance:
- Information Security Policy: Sets out how digital and physical information assets are protected against loss, misuse, or unauthorised access.
- Confidentiality Agreements: Signed by all staff and contractors, reinforcing their responsibility to protect personal data and maintain trust.
- Whistleblowing Policy: Provides a safe and confidential process for staff to raise concerns about data misuse or breaches without fear of reprisal.
- Equality & Diversity Policy: Ensures personal data is handled fairly and without discrimination, supporting compliance with the principles of lawful and fair processing.
- Health & Safety Policy: Includes provisions for secure handling of physical records and equipment, linking workplace safety with information security.
- Cyber Essentials Certification and IT Usage Guidelines: Demonstrate technical controls and staff responsibilities for maintaining secure IT systems and preventing cyber threats.
Together, these policies form a comprehensive framework that supports the protection of personal data and ensures Delta Force Group Ltd operates in line with legal and regulatory requirements.
Delta Force Group Ltd
No 31 The Broadway, Rainham, RM13 9YW
Reg No. 07683845
Tel: 02080047669
Web: www.deltaforcegroup.co.uk
Email: Info@deltaforcegroup.co.uk