{"id":5367,"date":"2020-07-22T12:00:18","date_gmt":"2020-07-22T12:00:18","guid":{"rendered":"http:\/\/wmtours.co.uk\/wmtours\/?page_id=5367"},"modified":"2021-06-04T06:21:40","modified_gmt":"2021-06-04T06:21:40","slug":"data-protection-gdpr-2021","status":"publish","type":"page","link":"https:\/\/wmtours.co.uk\/wmtours\/data-protection-gdpr-2021\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<p>[vc_row][vc_column][vc_column_text]<\/p>\n<h3 style=\"text-align: center;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Welcome to the Privacy\u00a0 Policy Notice.<\/h3>\n<p>&nbsp;<\/p>\n<p><strong>General Data Protection Regulation EU Regulation 2018 Data protection in the UK England and Wales<\/strong><\/p>\n<p><strong>Under the GDPR, customers have the following rights<\/strong><\/p>\n<p>How do You Use Personal Data:<\/p>\n<p><strong> When to provide it<\/strong><br \/>\nWe provide individuals with privacy information at the time we collect their personal data from them.<br \/>\n\u2022 If we obtain personal data from a source other than the individual it relates to, we provide them with privacy information:<\/p>\n<p>\u2022 within a reasonable of period of obtaining the personal data and no later than one month;<\/p>\n<p>\u2022 if we plan to communicate with the individual, at the latest, when the first communication takes place; or \u2022 if we plan to disclose the data to someone else, at the latest, when the data is disclosed.<br \/>\nElectronic communications: No consent is required when cookies are either:<\/p>\n<p>\u2022 Used for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network.<\/p>\n<p>\u2022 Strictly necessary for the provision of an information society service requested by the subscriber or user. How to provide it<br \/>\n\u2022 We provide the information in a way that is: \u2022 concise; \u2022 transparent; \u2022 intelligible; \u2022 easily accessible; and \u2022 uses clear and plain language.<br \/>\nChanges to the information<br \/>\n\u2022 We regularly review and, where necessary, update our privacy information. \u2022 If we plan to use personal data for a new purpose, we update our privacy information and communicate the changes to individuals before starting any new processing.<\/p>\n<p><strong>How long will you keep my personal Data:<\/strong><\/p>\n<p>The storage limitation principle is broadly similar to the fifth principle (retention) of the 1998 Act. The key point remains that you must not keep data for longer than you need it.<br \/>\nAlthough there is no underlying change, the GDPR principle does highlight that you can keep anonymised data for as long as you want. In other words, you can either delete or anonymise the personal data once you no longer need it.<br \/>\nInstead of an exemption for research purposes, the GDPR principle specifically says that you can keep personal data for longer if you are only keeping it for public interest archiving, scientific or historical research, or statistical purposes (and you have appropriate safeguards).<br \/>\nNew documentation provisions mean that you must now have a policy setting standard retention periods where possible.<br \/>\nThere are also clear links to the new right to erasure (right to be forgotten). In practice, this means you must now review whether you still need to keep personal data if an individual asks you to delete it.<br \/>\nPersonal data shall be:<br \/>\n(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (\u2018storage limitation\u2019)\u201d<br \/>\n\u2022 You must not keep personal data for longer than you need it.<br \/>\n\u2022 You need to think about \u2013 and be able to justify \u2013 how long you keep personal data. This will depend on your purposes for holding the data.<br \/>\n\u2022 You need a policy setting standard retention periods wherever possible, to comply with documentation requirements.<br \/>\n\u2022 You should also periodically review the data you hold, and erase or anonymise it when you no longer need it.<br \/>\n\u2022 You must carefully consider any challenges to your retention of data. Individuals have a right to erasure if you no longer need the data.<br \/>\nYou can keep personal data for longer if you are only keeping it for public interest archiving, scientific or historical research, or statistical purposes.<br \/>\n\u2022 We know what personal data we hold and why we need it.<br \/>\n\u2022 We carefully consider and can justify how long we keep personal data. \u2022 We have a policy with standard retention periods where possible, in line with documentation obligations. \u2022 We regularly review our information and erase or anonymise personal data when we no longer need it. \u2022 We have appropriate processes in place to comply with individuals\u2019 requests for erasure under \u2018the right to be forgotten\u2019. \u2022 We clearly identify any personal data that we need to keep for public interest archiving, scientific or historical research, or statistical purposes.<\/p>\n<p><strong>Why is storage limitation important?<\/strong><br \/>\nEnsuring that you erase or anonymise personal data when you no longer need it will reduce the risk that it becomes irrelevant, excessive, inaccurate or out of date. Apart from helping you to comply with the data minimisation and accuracy principles, this also reduces the risk that you will use such data in error \u2013 to the detriment of all concerned.<br \/>\nPersonal data held for too long will, by definition, be unnecessary. You are unlikely to have a lawful basis for retention.<br \/>\nFrom a more practical perspective, it is inefficient to hold more personal data than you need, and there may be unnecessary costs associated with storage and security.<br \/>\nRemember that you must also respond to subject access requests for any personal data you hold. This may be more difficult if you are holding old data for longer than you need.<br \/>\nGood practice around storage limitation &#8211; with clear policies on retention periods and erasure &#8211; is also likely to reduce the burden of dealing with queries about retention and individual requests for erasure.<br \/>\nWhat is documentation?<br \/>\n\u2022 Most organisations are required to maintain a record of their processing activities, covering areas such as processing purposes, data sharing and retention; we call this documentation.<br \/>\n\u2022 Documenting your processing activities is important, not only because it is itself a legal requirement, but also because it can support good data governance and help you demonstrate your compliance with other aspects of the GDPR.<\/p>\n<p><strong>How can I access my personal data:<\/strong><br \/>\nThe right of access personal data.<br \/>\n\u2022 Confirmation that their data is being processed; \u2022 Access to their personal data; and \u2022 Other supplementary information. You must comply with any Subject Access Request (SAR) within one month of receipt. Full details on how to handle these are provided in a separate DIN, reference: Time limit<\/p>\n<p>As stated above, for most of these rights the Data Protection legislation introduces a deadline of one month from the date the request is received. Therefore, it is important that the request reaches the relevant person as soon as possible.<\/p>\n<p>Do you share my personal Data: Personal data must not be transferred to a country or territory outside the EEA unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. Implied consent is possible in certain limited circumstances where it is clear from the context that a person consents, for example, where the only purpose of filling in the form is to sign up.<\/p>\n<p>Where the processing is necessary for the purposes of legitimate interests pursued by the data controlle, or by the third party or parties to whom the data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject.<\/p>\n<p>Where the processing is necessary for the purposes of making a good faith disclosure under the Terrorism Act 2000 or the Proceeds of Crime Act 2002. In determining the risk, should consider\/ The harm that might result from its improper use or from its accidental loss, damage or destruction.<\/p>\n<p>How and where do you store or transfer my personal data..<\/p>\n<p><strong>Data protection rules<\/strong><br \/>\nYou must make sure the information is kept secure, accurate and up to date.<br \/>\nWhen you collect someone\u2019s personal data you must tell them who you are and how you\u2019ll use their information, including if it\u2019s being shared with other organisations. Choose a data processor that can provide sufficient guarantees in relation to the technical and organisational security measures governing their processing.<br \/>\nYou must also tell them that they have the right to:<br \/>\n\u2022 see any information you hold about them and correct it if it\u2019s wrong<br \/>\n\u2022 request their data is deleted \u2022 request their data is not used for certain purposes \u2022 The right to access personal data and supplementary information. \u2022 The right to have inaccurate personal data rectified, or completed if it is incomplete. \u2022 The right to erasure (to be forgotten) in certain circumstances. \u2022 The right to restrict processing in certain circumstances. \u2022 The right to data portability, which allows the data subject to obtain and reuse their personal data for their own purposes across different services. \u2022 The right to object to processing in certain circumstances. \u2022 Rights in relation to automated decision making and profiling. \u2022 The right to withdraw consent at any time (where relevant).<\/p>\n<p>We aim for full transparency on how we gather, use, and share your personal information\u00a0<a href=\"https:\/\/automattic.com\/privacy\/\">Privacy Policy Automatic<\/a><\/p>\n<p>[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text] \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Welcome to the Privacy\u00a0 Policy Notice. &nbsp; General Data Protection Regulation EU Regulation 2018 Data protection in the UK England and Wales Under the GDPR, customers have the following rights How [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-5367","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/pages\/5367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/comments?post=5367"}],"version-history":[{"count":10,"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/pages\/5367\/revisions"}],"predecessor-version":[{"id":12205,"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/pages\/5367\/revisions\/12205"}],"wp:attachment":[{"href":"https:\/\/wmtours.co.uk\/wmtours\/wp-json\/wp\/v2\/media?parent=5367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}