Data Protection Policy for Kotak Mahindra (International) Limited

Table of Contents

  1. Introduction

  2. Scope

  3. Overview of the DPA 2017

  4. Terminology

  5. Data Protection Officer

  6. Registration as controller

  7. Data Protection Principles

  8. Lawful and Fair Processing

  9. Conditions for consent

  10. Processing for limited purposes

  11. Collection of personal data

  12. Adequate, relevant and limited purposes

  13. Accurate data

  14. Timely processing

  15. Processing in line with the rights of data subjects

  16. Data Security

  17. Directors and employees personal data used for corporate purposes

  18. Cross border transfer of data

  19. Dealing with Data Subject Access Requests

  20. Data Breach

  21. Data Retention

  22. Data Processing Impact Assessments

  23. Compliance Audit

  24. Data Protection best practices

  25. Changes to this Policy


Annexes:

Annex 1: Record of Processing Operations Annex 2: Clear Desk Principles

Annex 3: Transfer of personal data form Annex 4: Data Subject Access Request form Annex 5: Data Breach Notification form Annex 6: Guide and form for DPIA


  1. Introduction

    Data Protection Policy


    1. Kotak Mahindra (International) Limited (hereinafter, the “Company” or “we” or “our” or “us”) is a company incorporated under the Companies Act 2001 and is the holder of a GBL license issued by the Financial Services Commission operate as a CIS manager, an Investment Advisor (unrestricted) and an Investment Dealer (full service dealer including underwriting) under the Securities Act 2005.


    2. In the course of its activities, the Company processes the personal data of its clients, employees, suppliers, service providers, shareholders, directors and other stakeholders (hereinafter, the “Data Subjects” or “you” or “your”).


    3. The Company is fully committed to processing the personal data of its Data Subjects in accordance with the requirements of the local data protection requirements, namely the Mauritius Data Protection Act 2017 (the “DPA 2017”) and the Data Protection (Fees) Regulations 2020 (the “2020 Regulations”), as amended from time to time (together the “Local DP Laws”) as well as , where applicable, the European Union General Data Protection Regulation (“GDPR”) (the Local DP Laws and the GDPR being referred to as the “applicable data protection laws”). The Company takes the privacy of personal data very seriously and has implemented a variety of measures and controls to ensure that we collect and process personal data in accordance with the applicable data protection laws.


  2. Scope


    1. This data protection policy (the “Policy”) sets out the key principles and requirements to which the Company must adhere in order to ensure continuing compliance with GDPR and Local DP Laws with respect to the collection, use, processing, transfer and destruction of personal data.


    2. The types of personal data that we may be required to handle include information about current, past and prospective Data Subjects with whom/which we communicate. The personal data, which may be held on paper, on a computer or any other types of support, is subject to certain legal saf eguards specified in the applicable data protection laws.

    3. This Policy and any other documents referred to in it sets out the basis on which we will process any personal data we collec t from data subjects, or that is provided to us by data subjects or other sources.


    4. This Policy does not form part of any employee’s contract of employment and may be amended at any time. However, it is a condition of employment that employees of the Company will abide by the rules and policies made by the Company from time to time. Any failure to follow this Policy can therefore result in disciplinary proceedings.


  3. Overview of the DPA 2017


      1. The aims of the DPA 2017 are to:


        1. strengthen the control and personal autonomy of data subjects over their personal data, thereby contributing to respect for their human rights and fundamental freedoms, in particular their right to privacy, in line with current relevant international standards, in particular the GDPR on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.


        2. simplify the regulatory environment for business in our digital economy.


        3. promote the safe transfer of personal data to and from foreign jurisdictions, given the diversification, intensification and globalisation of data processing and personal data flows.


      2. The Company undertakes to:


        1. adhere to the data privacy principles (the “Data Protection Principles”), as contained within section 21 of the DPA 2017 and Chapter II of the GDPR ;


        2. ensure that the rights of the individual, in the context of the treatment of their personal data, are upheld as set out within Chapter III of the GDPR and the Local DP Laws; and


        3. discharge the general obligations imposed on it under Chapter IV of the GDPR and the Local DP Laws.


  4. Terminology



  5. Data Protection Officer


    1. In line with the DPA 2017, the Company has appointed a Data Protection Officer (“DPO”) who shall be responsible for ensuring compliance with the Local DP Laws and this Policy, work independently, report to the highest management level in the Company and have adequate resources to enable the Company to meet its obligations as defined herein. The DPO of the Company shall be Mr. Antish Raj Bundhoo, Head of Legal (email: antish.bundhoo@iqeq.com) or such other person appointed from time to time by the Company. Any questions about this Policy or any concerns that the Policy has not been followed should be referred in the first instance to the DPO.


    2. The responsibilities of the DPO include the following:


      1. Inform and advise the Company as the controller and its employees who carry out processing activities of their obligations under the Local DP Laws;

      2. Monitor compliance with the Local DP Laws and with the policies of the Company in relation to the protection of personal data;


      3. Assignment of responsibilities, awareness-raising and training of staff involved in the processing of personal data, and the related audits;


      4. Provide advice, where requested, regarding data protection impact assessments and monitor their performance;


      5. Cooperate with all relevant supervisory and regulatory authorities responsible of the subject matter of data protection;


      6. Act as the contact point for the Data Protection Office on issues relating to the processing of personal data by the Company.


  6. Registration as controller


    1. The Company is a controller as defined in the DPA 2017. All controllers and processors in Mauritius must be registered with the Data Protection Commissioner. This involves completing the relevant registration forms available from the Data Protection Office (website – www.dataprotection.govmu.org) and paying the prescribed registration fees as provided for by Regulations 2020. The registration is valid for a period of three years and may be renewed not later than three months before the date of its expiry.

  7. Data Protection Principles


    1. Every controller or processor processing personal data must comply with the principles set out in the Local DP Laws. Particularly, they shall ensure that personal data are:


      1. processed lawfully, fairly and in a transparent manner in relation to any data subject;


      2. collected for specified, explicit and legitimate purposes, and not further process in a manner incompatible with such purposes.


      3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;


      4. accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure that any inaccurate personal data are erased or rectified without delay;


      5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; and


      6. Processed in accordance with the rights of data subjects under the DPA 2017.


  8. Lawful and fair processing


    1. The DPA 2017 contains provisions to ensure that processing of personal data is done fairly and without adversely affecting the rights of the data subject.


    2. For personal data to be processed lawfully, they must be processed on the basis of one of the legal grounds set out in the DPA 2017, namely:


      1. the data subject consents to the processing for one or more specified purposes;


      2. the processing is necessary –

        1. for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject before entering into a contract;


        2. for the compliance with a legal obligation to which the controller is subject;


        3. in order to protect the vital interests of the data subject or another person;


        4. for the performance of a task carried out in the public interest or in the exercise of an official task vested in the controller;


        5. the performance of any tasks carried out by a public authority;


        6. the exercise by any person in the public interest of any other functions of a public nature;


        7. for the legitimate interests pursued by the controller or by a third party to whom the data are disclosed, except if the processing is unwarranted in any particular case having regard to the harm and prejudice to the rights and freedoms or legitimate interests of the data subject; or


        8. for the purpose of historical, statistical and scientific research.


    3. We will not process special categories of personal data unless:


      1. Paragraph 8.2 above applies to the processing; and


      2. the processing relates to personal data which are manifestly made public by the data subject;or


      3. the processing is necessary for –


        1. the establishment, exercise or defence of a legal claim;


        2. the purpose of preventive or occupational medicine, for the assessment of the working capacity of an employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services or pursuant to a contract with a health professional and subject that the data are processed by or under the responsibility of a professional or other person which are under an obligation of professional secrecy;


        3. the purpose of carrying out the obligations and exercising specific rights of the controller or of the data subject; or


        4. protecting the vital interests of the data subject or of another person where the data subject is physically or legally incapable of giving consent.

    4. When processing personal data as controller in the course of our business, we will ensure that those requirements are met.


  9. Conditions for consent


    1. For consent to be valid, it must be freely given, specific, informed and represents an unambiguous indication of the wishes of a data subject, either by a statement or a clear affirmative action, by which he signifies his agreement to personal data relating to him being processed.


    2. In determining whether consent was freely given, account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.


    3. The data subject shall have the right to withdraw consent at any time. However, please bear in mind that if you withdraw consent, we may not be able to perform the contract that we have entered into with you.


  10. Processing for limited purposes


    1. In the course of our business, we may collect and process your personal data which include data we receive directly from you (for example, by completing forms, applying to job adverts or by corresponding with us by mail, phone, email or otherwise) and data we receive from other sources (including, for example, business partners, sub-contractors in technical, credit reference agencies and others).

    2. We will only process personal data for the specific purposes for which they were collected. We will notify the data subject of each of those purposes and seek their consent (where applicable) before we process data for any other purpose.


    3. Pursuant to the requirement of the DPA 2017, we will maintain a record of processing operations. A template of such record of processing operations can be acceded to at Annex 1 of the Policy.


  11. Collection of personal data


    1. The Company will not collect personal data unless –

      1. it is done for a lawful purpose connected with a function or activity of the Company; and

      2. the collection of the personal data is necessary for that purpose.


    2. Where we collect personal data directly from you, we shall ensure, at the time of collecting the personal data that you are informed of the following, by way of a data protection notice:


      1. the identity and contact details of the Company and, where applicable, our representatives and the identity and contact details of our DPO;


      2. the purposes for which the data are being collected;


      3. whether or not the supply of the data by you is voluntary or mandatory;


      4. the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;


      5. the existence of your right to request from the us access to and rectification, restriction or erasure of your personal data or to object to the processing of the said personal data;

      6. the period for which the personal data shall be stored;


      7. your right to lodge a complaint with the Data Protection Commissioner;


      8. where applicable, that we intend to transfer your personal data to another country and on the level of suitable protection afforded by that country; and

      9. any further information necessary to guarantee fair processing in respect of the data subject’s personal data, having regard to the specific circumstances in which the data are collected.

    3. Please note that we shall not be required to comply with paragraph 11.2 above if –


      1. you already have the information referred to in paragraphs 11.1 and 11.2 above; or


      2. the personal data are not collected from the data subject and –


        1. the provision of such information proves impossible or would involve a disproportionate effort; or


        2. the recording or disclosure of the personal data is laid down by law.


  12. Adequate, relevant and limited processing


    1. We will only collect personal data to the extent that it is required for the specific purpose notified to the data subject.


    2. Information should never be kept “just in case” a use can be found for it in the future.


  13. Acurate data


    1. We will ensure that personal data we hold is accurate and kept up to date. We will take all reasonable steps to destroy or amend inaccurate or out-of- date data.


  14. Timely processing

    1. We will not keep personal data longer than is necessary for the purpose or purposes for which they were collected. We will take all reasonable steps to destroy, or erase from our systems, all data which is no longer required.


  15. Processing in line with the rights of data subjects


    1. The law confers upon you a number of rights relating to the personal data being processed by us. These rights are set out below. If you wish to exercise any of the said rights, we encourage you to contact our DPO.


    2. Right of access

      You may request a copy of the personal data we hold about you. Kindly ensure that such request is made in writing to our DPO as is morefully described at paragraph 19 below. Please note that if, in our opinion, your request is manifestly excessive, we may either not attend to your request or charge a fee for attending to same.


    3. Rectification, erasure or restriction of processing You may also, at any time, request:


      1. to have any inaccurate personal data we hold on you corrected. This includes the right to supplement and/or update existing personal data provided to us;


      2. that we erase any personal data we hold on you where (i) such data is no longer necessary in relation to the purpose for which it was collected or otherwise processed; (ii) you have withdrawn your consent to us holding and processing such data and there are no overriding legitimate grounds for the continued processing; or (iii) your personal data has been unlawfully processed.


        You will understand that this right is not absolute and that it will not be applicable where the exceptions provided for by the applicable data protection laws apply, including where our processing of your personal data is necessary for the purpose of historical, statistical or scientific research or for compliance with a legal obligation or for the establishment, exercise or defence of a legal claim;


        It will be necessary for us to restrict processing of your personal data where (i) the accuracy of your personal data is contested by you. This restriction will apply for such period as may be necessary to enable us to verify the accuracy of the data; (ii) we no longer need the personal data for the purpose of processing; (iii) you deem the processing of your personal data to be unlawful, but do not wish us to erase it; or (iv) you have objected to the processing of your data. Such restriction will apply pending verification as to our legitimate grounds to keep processing the personal data, despite your objection.

    4. Right to object


      You have the right to object to our processing of your personal data at any time. Upon receiving such objection, we will stop processing your personal data, except where there are compelling legitimate grounds to continue such processing.


    5. Right to lodge a complaint with the Data Protection Commissioner


      If you feel that we have not processed your personal data lawfully, please do feel free to contact us through our Data Protection Officer. If you remain unsatisfied, you may lodge a complaint with the Data Protection Commissioner in Mauritius. The contact details are as follows:


      Data Protection Office

      Address: 5th Floor, SICOM Tower, Wall Street, Ebène Email address: dpo@govmu.org

      Phone number: + (230) 460-0251

      Fax: + (230) 489-7346


  16. Data Security


    1. We have/will implement appropriate security and organizational measures for the prevention of unlawful or unauthorized access to; alteration of; the disclosure of; the accidental loss of; and destruction of the data in our control.


    2. We have/will put in place procedures and technologies to maintain the security of all personal data from the point of collection to the point of destruction. Personal data will only be transferred to a data processor if he agrees in writing to comply with those procedures and policies as well as the applicable data protections laws.


    3. We have/will maintain data security by protecting the confidentiality, integrity and availability of the personal data, defined as follows:


      • Confidentiality means that only people who are authorised to process the data can access it.

      • Integrity means that personal data should be accurate and suitable for the purpose for which it is processed.


      • Availability means that authorised users should be able to access the data if they need it for authorised purposes. Personal data should therefore be stored on the Company’s central server instead of individual PCs.


    4. Security measures and procedures include:


      • Entry controls. Any stranger seen in entry-controlled areas should be reported.


      • Secure lockable desks and cupboards. Desks and cupboards should be kept locked if they hold confidential information of any kind. Personal information is always considered confidential (except if publicly available).


      • Methods of disposal. Paper documents should be shredded. Personal data stored on digital storage devices will be erased when they are no longer necessary.


      • Application of clean desk principles – please refer to Annex 2.


      • Encryption – as far as technology allows, ensure that all mobile devices which have access to the server of the Company are encrypted and/or pseudonymised.


      • Equipment. Data users must ensure that individual monitors do not show confidential information to passers-by and that they log off from their PC when it is left unattended.


      • Restitution. The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.


      • Processor Agreements. When dealing with personal data, agreements between the Company and its processors have to be in writing and in line with the requirements of the applicable data protection laws, with specific clauses relating to the guarantees given by the processor that it has all

        the safeguards in place to protect the personal data of the Company, that it will act upon the instructions of the Company and that it will delete or hand over the personal data to the Company after the termination of the contract with the Company.


      • Sharing agreements. When dealing with personal data, agreements between us and sharing entities (such as but not limited to auditors, bankers, lawyers or group companies) must be envisaged with specific clauses relating to the respective obligations and responsibilities of the controller and the sharing party in terms of data protection.


      • Processor Assessments. When transferring or sharing personal data to a processor, the Company needs to assess the professionalism, integrity and security measures put in place by the processor in accordance with its data protection obligations to the satisfaction of the Company.


    5. All data users are responsible for ensuring that:


      1. Any personal data that they hold is kept securely; and


      2. Personal information is not disclosed either orally or in writing or via web pages or by any other means, accidentally or otherwise, to any unauthorised third party.


  17. Directors and employees personal data used for corporate purposes


    1. It is understood that the Company can process the personal data of directors and employees for the following corporate purposes provided consent of the data subject is obtained for the said purposes:


      1. Use of personal data for corporate presentation and documentation including e-documentation such as company website and social media pages (Instagram and Facebook pages);


      2. Use of directors’ or employees’ images in photos or corporate movies for posting on the intranet, corporate website or the Company’s social pages to promote/share corporate events including welfare event; and

      3. Communication to directors and employees of all corporate newsletters and memos as well as promotional offers (services and goods) from the Company or entities/subsidiaries (whether direct or indirect) forming part of the Group.


  18. Cross border transfer of data


    1. The Company has put in place appropriate safeguards with respect to the protection of the personal data and complies the conditions of transfer established in section 36 of the DPA 2017. Therefore, the Company may transfer any personal data we hold to a country outside of Mauritius, provided that:


      1. it has provided the Data Protection Commissioner proof of appropriate safeguards with respect to the protection of the personal data as provided for at Annex 3 or


      2. after having been informed of the possible risks of the transfer owing to the absence of appropriate safeguards the data subject has given his explicit consent to the proposed transfer; or


      3. The transfer is necessary for one of the reasons set out in the DPA 2017 which would include: (i) the performance of a contract between us and the data subject; (ii) protection of the vital interests of the data subject; (iii) when it is legally required for reasons of public interests (iv) for the establishment, exercise or defence of legal claims (v)for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another person or(vi) for the purpose of compelling legitimate interests pursued by the controller..


  19. Dealing with data subject access request (“DSARs”)


    1. Data subjects must make a formal request to get access to the personal data we hold about them. This must be made in writing by completing the form referred to at Annex 4. The one who receives a written request should forward it to the DPO (or anyone from his/her team) immediately.


    2. When receiving telephone enquiries, we will only disclose personal data we hold on our systems if the following conditions are met:


      1. We will check the caller’s identity to make sure that information is only given to a person who is authorised to receive it.


      2. We will never respond to a request regarding the personal data of data subjects unless the request is put in writing.


      3. Payment of the relevant prescribed access fee if the request is manifestly excessive.


      4. The conditions set out in the DPA 2017 in respect of the data subjects’ right of access are fulfilled.


    3. Our employees will refer an access request to the DPO (or anyone from his/her team) for assistance in difficult situations. Employees should not be bullied into disclosing personal information.


    4. The DPO will assess the query (the length of time it will take, how difficult it will be and the effect on the Company of not having the information on a permanent form) and will deliver the personal data requested in an intelligible form using clear and plain language to the data subject. The Company shall within one month from receiving the request inform the data subject in writing whether or not any action has been taken pursuant to his request. The said period of one month may be extended by a further month where necessary taking into account the complexity and the number of requests made by the data subjects. Where the request is manifestly excessive, the Company may charge a fee for providing the information or taking the action requested or it may not take the action requested. The Company shall bear the burden of proving the manifestly excessive character of the request.


  20. Data Breach


    1. A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized/unlawful disclosure o, or access to, personal data transmitted, stored or otherwise processed.


    2. Examples of personal data breaches include:


      1. sending personal data (accidentally or deliberately) to internal or external persons who do not have a legitimate need to have access to such personal data;


      2. databases containing personal data being compromised, for instance by being illegally accessed by hackers;


      3. an intruder stealing or accessing a device containing the Company’s customer database and misusing it to impersonate the customers;


      4. loss or theft of computer devices, mobile devices, or paper records containing personal data;


      5. paper records containing personal data being left unprotected for anyone to see;


      6. staff accessing or disclosing personal data outside the requirements or authorisation of their job;


      7. being deceived by a third party into improperly releasing the personal data of another person; and


      8. the loss of personal data due to unforeseen circumstances such as a fire or flood.


    3. Under the applicable data protection laws, all personal data breaches must be reported to Data Protection Office or the supervisory authority (as applicable) within 72 hours of the controller becoming aware of the said breach. Failing to do so without good and justifiable reasons would amount to a breach of the law rendering the controller liable to a fine of up to Rs200,000 and to imprisonment for term not exceeding 5 years (where the personal data breach falls under the DPA 2017) or to a fine of up to EURO 20 million or up to 4% of the Company’s annual turnover (where the personal data breach falls under the GDPR). In addition, under the GDPR, the fine may be combined with other regulatory sanctions including an order for the forfeiture of any equipment or any article used or connected in any way with the commission of an offence.


    4. All identified, actual or possible, personal data breaches must immediately be reported by the employee discovering the breach to the DPO. If the breach is IT related, the IT officer must also be immediately notified by the employee in order for the latter to take immediate actions to contain the risks.


    5. The DPO must thereafter immediately start a preliminary investigation to determine the nature and severity of the personal data breach including:


      1. when the breach occurred;


      2. suspected cause (s) of the breach;

      3. description of the personal data breach including the nature and content of the personal data breach;


      4. categories and number of living individuals affected by the breach;


      5. in the case of communication of the breach to data subjects, the likely consequences of the breach and whether the breach is likely to result in a high risk to the rights and freedoms of the persons affected by the breach.

      6. The measures taken to contain the risks associated with the breach or proposed to be taken to deal with the breach.


    6. The DPO shall without undue delay and, where feasible, not later than 72 hours after becoming aware of the personal data breach inform the Data Protection Office of the personal data breach.


    7. Where the Company fails to notify the personal data breach within the time limit specified in paragraph (20.6 above, he shall provide the Data Protection Commissioner with the reasons for the delay).


    8. The notification to the Data Protection Commissioner shall be made using the prescribed form which is referred to at Annex 5. The notification shall:


      1. describe the nature of the personal data breach, including where possible, the categories and approximate number of data subjects and the categories and approximate number of personal data records concerned;


      2. communicate the name and contact details of the data protection officer or other contact point where more information may be obtained; and


      3. recommend measures to address the personal data breach, including, where appropriate, measures to mitigate the possible adverse effects of the breach.


    9. Where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the controller shall, after the notification mentioned at paragraph 20.8 above, communicate the personal data breach to the data subject without undue delay.


    10. The communication to the data subject shall describe in clear language the nature of the personal data breach and set out the information and the recommendations provided for in paragraph 20.8 above.


    11. The communication of a personal data breach to the data subject shall not be required where the Company can show that –


      1. it has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular, those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;


      2. it has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise; or


      3. it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.


    12. Where the controller has not already communicated the personal data breach to the data subject, the Data Protection Commissioner may, after having considered the likelihood of the personal data breach resulting in a high risk, require it to do so.


    13. Depending on the nature of the personal data breach, there may be additional notification obligations under other laws to be considered including notifying third parties such as the police, insurers, professional bodies, banks, tourism authority and any other relevant body. Each case must be assessed on its own merits.


    14. As with any security incident, the Company should investigate whether or not the breach was as a result of human error or a systemic issue and be proactive and innovative to implement preventative measures to guard against future risks of a similar nature occurring – including training its staff, having robust contracts with appropriate warranties from third party processors, implementing appropriate processes to detect breaches at an early stage and to contain the associated risks.


    15. The management of a personal data breach and any document prepared or furnished in connection therewith shall be kept strictly confidential by all members of the data protection team working on the breach. Information concerning the personal data breach must be communicated only to those on a strictly needs-to-know basis.

  21. Data Retention


    1. The law provides that where the purpose for keeping any personal data has lapsed, we should destroy the data as soon as reasonably practicable.


      We will keep storing your data for as long as is necessary:


      1. for us to fulfil the purposes we collected it for;


      2. for the performance of your contract of employment;


      3. for us to share with you the latest news regarding our organisation and our services;


      4. for us to satisfy any legal requirement, including statutory reporting obligations;


      5. for the keeping of adequate records for historical, financial or statistical purposes;


      6. for security purposes;


      7. for the prevention of fraud and abuse; and


      8. for us to defend or enforce our rights.


    2. We wish to draw your attention to the fact that the legal prescription period in Mauritius (i.e. the period during which one party may sue another after the happening of an event) is 10 years for non-immovable-property-related matters (actions personnelles). Depending on the nature of our relationship with you, we may, in this context, also choose to keep your personal data for at least the legal prescription period in order to be able to defend or enforce our rights.

    3. In some circumstances, we may anonymise your personal data such that the personal data can no longer be associated with you, for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.


  22. Data protection impact assessments (“DPIAs”)


    1. Where processing operations are likely to result in a high risk to the rights and freedoms of data subjects by virtue of their nature, scope, context and purposes, the Company, as a controller, shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.


    2. Section 34 of the DPA 2017 specifies that a DPIA shall include:


      1. a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the Company;


      2. an assessment of the necessity and proportionality of the processing operations in relation to the purposes;


      3. an assessment of the risks to the rights and freedoms of data subjects; and


      4. the measures envisaged to address the risks and the safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with the regulations, taking into account the rights and legitimate interests of data subjects and other persons concerned.


    3. In general, DPIAs are undertaken for projects where the processing operations are one or more of the following:


      1. The systematic and extensive valuation of personal aspects relating to individuals which is based on automated processing, including profiling and on which decision are based that produced legal effects concerning the individual or significantly affect the individual;


      2. Processing on a large scale of special categories of data;

      3. A systematic monitoring of a publicly accessible area on a large scale;


      4. Any other processing operations for which consultation with the Data Protection Office is required.


    4. If there is uncertainty regarding whether it is appropriate to carry out a DPIA for a specific project, by default the project team should err on the side of caution and ensure that one is performed. The DPO may be consulted for clarification and further guidance may be sought from the Data Protection Office.


    5. The overall environment in which the DPIA is carried out should be described and the reasons for it explained. This should include a description of the internal and external context of the project and its overall objectives.


    6. The link to the guide on how to complete the DPIA form as well as the DPIA form can be acceded to at Annex 6.


  23. Compliance audit


    1. The Data Protection Office may carry out (or procure the carrying out of) periodical audits of the systems of the Company, as controlle, to ensure compliance with the Local DP Laws.


  24. Data protection best practices


    1. Each data subjects should adopt the following data protection best practices, where relevant to their respective business context:

      • Ensure awareness and training of staff on data protection;

      • Undertake a personal data audit to identify compliance gaps, if any;

      • Draw a personal data flowchart;

      • Set up a register of personal data processors;

      • Set up a register of contracts pursuant to which personal data is processed by processors and ensuring that the necessary clauses relevant to third party processors have been stipulated in the contracts;

      • Introduce systematic DPIAs on new projects and systems;

      • Develop IT security protocols and behaviours to endorse a privacy by design organisation;

      • Ensure that a data breach reporting procedure in place; and

      • Ensure that DSARs can be fully entertained.

  25. Changes to this policy


    1. The Company reserves the right to amend and update this Policy at any time. Where appropriate, data subjects will be notified of any changes made, by mail or email or otherwise.

ANNEX 1

Record of processing operations


The template for the record of processing operations can be found from the following link: https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Records-of-processing-operations.aspx


ANNEX 2


CLEAN DESK PRINCIPLES


These principles are applicable to all employees of the Company


ANNEX 3


FORM FOR THE TRANSFER OF PERSONAL DATA ABROAD


The form for the transfer of personal data abroad can be found on the following link:


https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Transfer-of-data-abroad.aspx


ANNEX 4


DATA SUBJECT ACCESS REQUEST FORM


The data subject access request form can be found on the following link:


https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Rights-of-Data-Subjects-Form.aspx


ANNEX 5

FORM FOR DATA BREACH NOTIFICATION


The form for data breach notification can be found on the following link:


https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Personal-Data-Breach-Notification.aspx


ANNEX 6


GUIDE AND FORM FOR DPIA


The guide and form for DPIAs can be found on the following link:


https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Data-Protection-Impact-Assessment-and-High-Risk- Operations.aspx