Midland Motor Caravan Hire
General Data Protection Regulation(GDPR)
GDPR will apply to all EU states from the 25th May 2018.
GDPR is an EU regulation which has two main drivers:
- The EU wants to give people more control on how their personal data is being used.
- The EU wants to give businesses a simpler, clearer legal environment in which to operate, making data protection law identical throughout the single market.
Midland Motor Caravan Limited herein known as MMCHIRE has always complied with data protection laws and regulations surrounding the use of personal data. However, GDPR means we are having to change a number of our processes and policies. This document outlines what we have done at Midland Motor Caravan Limited (MMCHIRE) to ensure we are fully compliant with the new regulation as from 25th May 2018.
What does GDPR change?
In summary, two things:
- Transparency – Customers must be given far more information about what is done with their personal data, why, and what rights they have.
- Control – Customers are given much more control in terms of obtaining a copy of their personal data, have it corrected, having it deleted, being told what legal ground is relied on to process the data, how long it will be kept for, objecting to processing (especially automated processing) and being told about security breaches and loss of data.
Data Controllers and Data Processors at Midland Motor Caravan Limited (MMCHIRE)
A Data Controller states how and why personal data is processed. MMCHIRE has one Data Controllers and we will be more than happy to provide a name should you have a valid request. Please email email@example.com asking for the name of your Data Controller.
A Data Processor is the individual at MMCHIRE who is processing the data.
The duty of our Data Controller is to ensure that our processes abide by the law and our processors must abide by these rules and maintain records of their processing activates.
Our Data Controller must ensure that data is processed lawfully (see below “What is Lawful?”), is transparent and used for a set purpose.
Once this purpose has been fulfilled and the data is no longer required, it then needs to be deleted from our systems.
Who we are and our details?
All our company details on our website, www.mmchire.co.uk
What is Lawful?
Firstly, a person has consented for us to have their personal data and to process it.
Secondly, collecting the data is in our legitimate interest, such as preventing fraud.
How do we get consent from you?
We ask you to submit your name and email address when requesting a quotation. Once we receive your request we will retain your name and email address for a reasonable time unless you ask us to do otherwise.
To comply with GDPR, MMCHIRE need to answer the following questions?
When did you give us consent?
The date you have clicked and submitted to the MMCHIRE a request for information or quotation.
What did you give consent for?
You are giving us consent to supply the information / quotation that you have requested.
How did you give consent?
Via a call or via an email using our contact form.
How can I withdraw my consent for you to hold my data?
You have the right to withdraw your consent for us to hold your data at any time. You do not have to offer a reason for this.
Once we have received notice from you to withdraw consent to hold your data, your details will be removed from our system within seven working days.
To remove your consent for us to hold your data, please email firstname.lastname@example.org
Do we have this history by individual person?
Yes, our records will provide history by the individual, not the company or organisation they represent.
When will the consent expire?
We expire consent two years after it has been given. This period of time is due to returning hires and helps both you and us complete our hire checks when we receive a new hire request from you.
What is classified as personal data?
Personal data could relate to economic, cultural and mental health information on yourself. We do not hold any of this data.
What data we hold and why? Profiling and collection of other personal data
Profiling means any form of automated process of personal data to evaluate certain aspects relating to a person to analyse and predict their interest, behaviour, health and location. At MMCHIRE, at this time we collect information on:
- People’s interests – this is used for only for us to supply you with the information that you are interested in.
- Health – we will only ever record information on an individual’s health for insurance purposes as required by our insurers when you hire one of our motorhomes.
- Location – we use location information, such as where you live, for checks to satisfy our insurers that you are a genuine hirer.
- Age – we collect information on peoples age. When you undertake a motor home hire and sign a hire agreement this data will be needed. With regards to the insurers that we work with, again, we have to carry out basic checks to satisfy our insurance requirements.
- Gender – we collect information on your gender for the purposes of writing to you.
- Spouse and Children – in some instances, we will hold the names and year of birth of immediate family members. This is done only for checks and to satisfy our insurance requirements.
- Contact data – mobile phone number and email address.
Who do we share our data with, selling or offering of your data to third parties (1)
MMCHIRE will not sell your personal data to any third parties.
We will use your personal data for undertaking credit approvals and certain data will be stored for:
- The prevention of fraud.
- Contacting you in the event of a default.
- Resolving a problem relating to the supply of equipment.
(1) The only third party companies we share data with are:
Insurance companies that offer motorhome hire insurance. Even then, this will only be done at a time when we are looking at a specific business opportunity or when we have been requested this information due to a dispute, default or problem in general.
Motor Home hire. When arranging a vehicle hire we will need you to provide a name, address and contact number
Holding of “Special Personal Data” also known as “Sensitive personal Data.”
This relates to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership and health or sex life.
MMCHIRE does not hold or collect any of this data.
Passports, driving Licences or utility bills do not form part of sensitive data.
Where information on the data subject/customer is obtained from a source other than the data subject/customer, what that source is.
There will be instances where we obtain data from a third party. Often, this is where we need to check licenses or verify a persons credentials. We will data load and keep this information to help in obtaining a credit acceptance as long as the information is appropriate to our needs. Should you request it, we will be more than happy to disclose what information we hold and the third party we received it from.
What is soft Opt-in?
Soft opt-in is a term used to allow us to communicate with an individual even though they have not actually opted in as from the 25th May 2018. An individual could be a prospect, customer or supplier with whom we have spoken to about hiring. Under the soft opt-in rules, we are allowed to communicate with this individual via email as long as the subject matter is related to hiring.
The soft opt-in ruling can be deemed to be ambiguous. We have interpreted this section under the new GDPR rules that we can communicate with individuals via their personal email account or mobile phone if we can clearly demonstrate we have communicated with them in the past about a relevant subject matter.
What have we done to comply with the new GDPR ruling?
Board of Directors – The directors have been fully briefed on GDPR and have appointed Data Controllers internally.
Training – All our existing staff – and new recruits – will go through a data protection training course as a minimum.
Company mobile phones – All company mobile phones are password protected.
Company laptops/desktops – All laptops/desktops are password protected. They are hidden when in a vehicle and locked away if ever stored overnight at an office. Employees are aware on the need to keep them safe in a home environment.
Personal Data – Our CRM system, Word, Excel, Outlook are all stored in the cloud via a Microsoft storage facility as opposed to the computer drive with off-site backups.
Downloading of data – The bulk downloading of data from our CRM system has been changed so that only Data Controllers can undertake this process. Excel spreadsheets are then deleted when not needed.
Printed material – We are a paperless office. All documentation that can hold personal data is stored on our CRM system
CRM system – This is security protected (https://) The data is help offsite in a data centre and backed up every day. Only current employees of our company have access to this system.
Personal data – We have historically been storing personal information on a small number of individuals. For example, home address, partners details (wife, husband etc). All this information has been deleted from our systems if older than two years.
Your rights as an individual
The GDPR includes the following rights for individuals:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object
- the right not to be subject to automated decision-making including profiling.
You can remove consent, for any reason at any time by emailing email@example.com
Should you have any questions regarding GDPR and your data at MMCHIRE, again, please email firstname.lastname@example.org and a MMCHIRE Data Controller will attempt to get back to you within two working days.
In the event of a security breach
We take data security very seriously and use best endeavours to ensure the systems and procedures we follow provide us with a high level of data security. Should a data breach occur, we will analyse the situation and report it to the necessary authorities and communicate with any individuals that may have been affected.
MMCHIRE look to report this information to the Information Commissioner’s Office with 48 business hours and communicate with any individual affected within 72 hours.
Filing a Complaint
We hope that you will not find it necessary to file a complaint against our company with reference to Data Protection. Should you feel it appropriate, you will need to contact:
Organisation Information Commissioner’s Officer
Website address www.ico.org.uk
Telephone: You can call their helpline on 0303 123 1113
Who are the ICO? The ICO are the UK’s independent authority set up to uphold information rights in the public interest promoting openness by public bodies and data privacy for individuals.