Title: Data Handling Policy

Version:
1.0

Replaces / Date:
October 2024

Lead with responsibility :
Hunrosa Data Protection Lead

Ratified Date:
October 2025

Date for Review:
Twelve months from ratification

Our commitment to client confidentiality and security is unwavering. With the vast amounts of sensitive information we handle, our Data Handling Policy sets forth the standards and protocols we follow in collecting, storing, and disseminating data. This policy reflects our dedication to ensuring that all data, especially personal and health-related, is managed with the utmost care and in line with the highest standards. Trust is a cornerstone of our consultancy, and through this policy, we aim to solidify that trust with every interaction.

1. Introduction

The Hunrosa Data Handling Policy is designed to ensure the responsible, lawful, and secure handling of personal data in compliance with the General Data Protection Regulation (GDPR) and other relevant data protection laws. This policy outlines the procedures and guidelines for the collection, processing, storage, and disposal of personal data.

2. Definitions

2.1 Personal Data: Any information relating to an identified or identifiable natural person (“data subject”).

2.2 Processing: Any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.

3. Data Collection and Consent

3.1 Personal data will be collected lawfully, fairly, and transparently. Data subjects will be informed of the purposes and legal basis for processing their data.

3.2 Consent for data processing will be obtained when necessary, and it must be freely given, specific, informed, and unambiguous.


4. Data Minimisation

4.1 Only the minimum necessary personal data required to fulfil specific purposes will be collected and processed.

4.2 Data accuracy will be maintained through regular updates and validation procedures.


5. Data Security

5.1 Personal data will be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage.

5.2 Encryption, access controls, and other technical measures will be implemented to safeguard personal data.

6. Data Retention and Erasure

6.1 Personal data will be retained only for the period necessary to fulfil the purposes for which it was collected or as required by legal obligations.

6.2 Data subjects have the right to request the erasure of their personal data (the “right to be forgotten”) under certain conditions.


7. Data Subject Rights

7.1 Data subjects have the right to access their personal data, rectify inaccuracies, and receive a copy of their data in a structured, commonly used, and machine-readable format.

7.2 Requests from data subjects to exercise their rights will be addressed within the timeframes specified by GDPR.


8. Data Transfers

8.1 Personal data transfers to countries outside the European Economic Area (EEA) will only occur if appropriate safeguards are in place.

8.2 Adequate measures, such as Standard Contractual Clauses or binding corporate rules, will be employed to ensure data protection during transfers.

9. Data Breach Notification

9.1 Any data breach that could result in a risk to individuals’ rights and freedoms will be reported to the relevant supervisory authority within 72 hours of becoming aware of the breach.

9.2 Data subjects affected by a breach will be notified when there is a high risk to their rights and freedoms.


10. Accountability and Documentation

10.1 Hunrosa will maintain records of all data processing activities as required by GDPR.

10.2 An appointed Data Protection Officer (DPO) will oversee data protection efforts and provide advice on compliance.


11. Training and Awareness

11.1 All employees and authorised users will receive regular training on GDPR principles, data protection laws, and best practices.

11.2 Employees will be educated about the importance of safeguarding personal data and respecting data subjects’ rights.


12. Compliance and Consequences

12.1 Non-compliance with this Data Handling Policy and GDPR may result in severe consequences, including financial penalties and legal actions.

12.2 All employees, contractors, and authorised users are responsible for complying with this policy and GDPR requirements.

13. Review and Updates

This policy will be reviewed periodically and updated to align with changes in data protection laws, regulations, and best practices. Employees are expected to stay informed about policy updates and adhere to the latest guidelines. By adhering to the principles outlined in this Data Handling Policy, we ensure the protection, privacy, and lawful processing of personal data, demonstrating our commitment to GDPR compliance and data subject rights at Hunrosa.

If you require more details or have queries regarding our Data Handling Policy, please contact us at:

Hunrosa 124 City Road London EC1V 2NX Website: hunrosa.co.uk Email: info@hunrosa.co.uk

Search Hunrosa

Find the support you need right here.

Practical sleep guidance for foster carers

Sign up to Hunrosa to access practical, trauma informed guidance designed to help foster carers support better sleep, reduce overnight stress and create calmer nights at home.

Hunrosa will use your information to contact you about our services, updates, and relevant news. You can unsubscribe at any time. For details on how we handle personal data, please see our Privacy Policy.