Data protection policy for the Business Council of Kalundborg Region
Overall organization of personal data
As a general rule, Kalundborgegnen's Business Council wishes to use digital data processing systems and digital storage of personal data with external suppliers who securely host and make IT systems available, so that Kalundborgegnen's Business Council does not itself need to have the competence to be in charge of day-to-day operations of such systems.
Kalundborgegnen's Business Council also wants to organize the storage of personal data in specific central systems to the greatest extent possible, so that personal data about individual people is not distributed over several systems and in both electronic and manual form.
1. Purpose
The data protection policy describes it management-approved level for safety in the Kalundborg Region's Business Council and contains the overall safety objectives and forms the basis for the design of the Kalundborg Region's Business Council I-4 Data Security Handbook with the underlying guidelines and business processes.
The guidelines that are drawn up to support the main objectives of the data protection policy must ensure that all employees work with and relate to data security in the processing of personal data in their daily work.
The data protection policy is especially formulated with a view to the protection of personal data, but it applies equally to financial and other data.
Data security is therefore a key value, and it is a natural part of the Kalundborg Region's Business Council's automatic and manual data processing of information, including especially personal data.
2. Scope
The data protection policy applies to everyone associated with the company either as employees, management, voluntary affiliates, board of directors, suppliers and business partners.
All suppliers and business partners, who have physical or logical access to the Kalundborg Region's Business Council's IT systems, data and personal data must be made aware of the policy and undertake to follow it.
The data protection policy covers all technical and administrative matters that have a direct or indirect influence on the operation and use of the Kalundborgegnen Erhvervsråd's digital data processing systems as well as manual archives and registers.
3. Main objectives and security level
Kalundborgegnen's Business Council has the following safety objective:
"Kalundborgegnens Erhvervsråd has an appropriate and sufficient technical and organizational security level, which applies to all employees, suppliers and business partners when processing personal data and other data through full or partial use of automatic data processing, as well as for processing manual documents."
An appropriate and sufficient level of data protection[1] is achieved through technical and organizational measures that ensure:
- ongoing confidentiality, integrity, availability and robustness of the Kalundborg Region Business Council's digital processing systems and processing services in relation to the risk assessment carried out for the individual systems and personal data.
- the use of pseudonymisation and encryption, where relevant, including when exchanging data with data processors and external parties and public authorities
- the ability to timely to restore availability of and access to data in the event of a physical or technical incident
- procedures for regular testing, assessment and evaluation of the data protection security
- protection of the Kalundborgegnen Business Council's IT assets, personal data and other data in the custody of the Kalundborgegnen Business Council.
A sufficient level of security is maintained by:
- that there has been found persistent exists guidelines and business procedures, which ensures that data security is an integral part of the Kalundborg Region's Business Council's operation and daily work
The goal is to ensure a continuous improvement process that continuously maintains and optimizes the data protection policy, guidelines and business procedures
- that through contract and supplier management it is ensured that the use of external suppliers, consultants and business partners complies with the applicable data protection legislation and the Kalundborg Region's Business Council's data protection level.
- that in connection with the introduction of new IT systems implemented:
- suitable technical and organizational measures in order to ensure through default settings that only personal data that is necessary is processed
- if deemed necessary, carrying out an analysis of the consequences of the intended processing of personal data for the protection of the data, (Consequence analysis)
- Kalundborg Business Council follows up on data security through ongoing maintenance and optimization of the data protection policy and the related guidelines and business processes.
4. Organization and responsibility
Safety objective:
"All employees have responsibility for data security. They are familiar with and comply with the Kalundborg Region's Business Council's data protection policy, guidelines and business procedures, which are described in the I-4 Data protection handbook."
Planning, implementation and control of data security is defined by Kalundborg Region's Business Council management that is also responsible for the implementation and maintenance of the data protection security system and is responsible for following up on security incidents (breach).
Management determines i I-4 The Data Protection Handbook who is responsible for each of the secretariats of the Kalundborg Region Business Council, digital and manual data processing systems, management of system access and network access, assignment of rights, conclusion of IT contracts and other contracts, purchase of hardware and installation of software, Treatment of inquiries from the registered, ocollection and management of notification of breach of personal data security to the Data Protection Authority and the data subjects affected by the breach.
The data protection policy is reassessed and approved once a year, or in connection with any situations that necessitate it.
Business director and employees are responsible for complying with guidelines and procedures for data security in daily work. Employees who observe or experience a breach of data security must report it to the Business Director as soon as possible.
The necessary knowledge and competence about data protection and security is communicated to all employees, and there is ongoing work on attitudes and knowledge about data protection and security.
The Business Director is responsible for compliance with the data protection policy.
5. The Data Protection Handbook
The data protection policy is elaborated by the management in guidelines and business procedures. Together, the policy, guidelines, contingency policy and business procedures make up the Data Protection Handbook, which is divided into the following main areas:
- Guidelines for employees' handling of security
- Focus on personal data always being treated confidentially
- Rules for login and password
- Rules for the use of mobile equipment, PCs, USB keys, mobile phones etc.
- Rules for the use of private PCs for processing personal data relating to residents and employees
- Rules for using the Internet
- Rules for the use of e-mails, including secure e-mail, and private use of the Kalundborg Region's Business Council's info e-mail
- Rules for or prohibitions against downloading IT programs, games, images, etc.
- Guidelines for access control
- Guidelines for the treatment of data on mobile devices
- Guidelines for the use of secure mail when communicating with Kalundborg Municipality and other public authorities
- Guidelines for network management, including wireless networks
- Guidelines for security incident management (breach), including
- Notification of security incidents (breach) of personal data security to the Danish Data Protection Authority and the data subjects, including procedures, contact to the data processor and content of the notification
- Business processes for processing, reestablishing and correcting personal data
- Principles and business procedures for processing of personal data as described below in section 6
- Guidelines for management of IT suppliers and data processors
- Data processor agreements
- The data processor's security level and handling of security
6. Principles and business procedures for processing personal data
Management lays down principles and procedures for the processing of personal data that ensure compliance with the Data Protection Regulation and the Personal Data Act.
The business corridors, there be documented, includes:
- Principles for processing personal data
- The use of consent as a basis for processing personal data
- Procedures for exercising it data subject's rights, including notification when registering and exercising the right to rectification, deletion or restriction of processing and the right to data portability
- Listings compiled over treatment activities with personal data
7. Risk assessment and classification of data
Risk assessment
Kalundborgegnen's Business Council wants to be aware of any risk, and based on a risk assessment achieve an appropriate and sufficient level of security established both electronically and physically.
The management actively participates in the risk assessment and is responsible for assessing threats, consequences and risks of automatic and manual data processing.
It is raised in the management once a year whether the risk assessment needs to be reassessed, as well as in case of any major changes in tasks, suppliers, data processing systems.
classification
To ensure that systems and data have the right level of security, these must be classified. Data and systems must be classified according to both availability, integrity (reliability) and confidentiality.
Availability
The accessibility criterion states that it must be possible to access systems and data for authorized persons when this is necessary.
It is particularly important for Kalundborgegnen's Business Council to have high accessibility to data and IT systems that contain information used in connection with personal data, personnel administration, including salary payments and reports to authorities.
Availability is primarily ensured through provisions in the IT contracts and/or data processing agreements entered into with the suppliers.
Integrity and reliability
Integrity and reliability mean that data on and in the systems is correct, reliable, accurate, up-to-date and complete.
It is particularly important for Kalundborgegnen's Business Council to have high integrity and reliability in data and IT systems that contain information used in connection with the processing of personal data and personnel administration.
Integrity and reliability are ensured primarily through the quality control that takes place during the established business processes for processing personal data and cases.
Confidentiality
With confidentiality it is believed that only authorized persons have the right to access the personal data, and the personal data must only be accessible to authorized persons.
Personal information is always treated confidentially and is only disclosed or published with the consent of the data subject, unless disclosure is otherwise authorized by law.
I I-4 The data protection handbook indicates which persons have access to citizens in Project Motorvej til Job and the employees' information, respectively.
8. Violation of the data protection policy
All employees at the Kalundborgegnens Erhvervsråd are obliged to comply with the data security policy in force at all times with associated guidelines, business procedures and related appendices.
All employees receive a copy of the most important provisions on data and personal data security addressed to employees when they take up their position.
9. Deviations
If situations arise where the requirements of the Data Protection Policy cannot exceptionally be complied with, this must be approved by the management and documented, and alternative security measures introduced.
10. Preparation and entry into force
Changes to the safety documentation are submitted and approved by management.
The data protection policy was approved on 23 May 2018, and will come into force on 25 May 2018.
Concepts and definitions
| Concept | Definition |
|---|
| Confidentiality | Only authorized persons have the right to process the information that must be accessible only to authorized persons. |
| Privacy | It is possible to validate whether data on the systems is correct, reliable, accurate, up-to-date and complete. Including securing Backup and or system duplication |
| Availability | It must be possible to access systems and data for authorized persons when this is necessary. |
| Robustness | The technical and organizational resilience of processing systems and services that protect them from harmful events. This can, for example, be protection against failure during duplication, cooling, emergency power systems, fire extinguishing, etc. |
| Pseudonymization | Processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information that is stored separately and securely. |
| encryption | A process that transforms the original information into information that is unreadable by a third party. |
| Persistent | The ability to ensure confidentiality, integrity, availability and robustness of processing systems and services is an ongoing technical and organizational commitment |
| Data protection policy | The data protection policy is part of a document structure, where the policy is the overall document decided by the management and which sets out the overall requirements and objectives, which are met through specific guidelines, business processes and instructions found in the Data Protection Handbook. |
| Guidelines | In the guidelines, the objectives set out in the policy are filled in with concrete descriptions of how the security policy is implemented. The guidelines work at an overall level and do not contain technical and system-related descriptions. |
| Business procedures and instructions | Business procedures and instructions constitute specific guidelines for how the guidelines are complied with and implemented at a detailed level in the individual department. |
| Security conditions | By security conditions is meant all the conditions that can affect the security of information in relation to confidentiality, reliability and availability. |
| Security incidents | The term is broadly understood as all events that affect data protection security, including security breaches |