General Data Protection Regulation (May 2018)
Awareness
The new General Data Protection Regulation (GDPR) came into full effect in the UK in May 25th, 2018.
The legislation requires all organisations that process personal data, or engage others to do so on their behalf, to instate relevant practices to safeguard personal data.
GDPR requires Thorpe Trees to be aware of and to comply with the new law, including ensuring that the details of how personal data is processed are documented.
We are reviewing our processes and policies to establish what needs to be introduced, developed, amended or stopped to make the company GDPR compliant.Â
Below is a list of relevant points/ actions that can be implemented to immediately improve the security of the information we collect, use and store.
Main Sheds Security.
The codes for the main shed alarm to be changed at periodic intervals
All shed doors to be locked overnight and outside of working hours.
Main entrance gates to be locked overnight and when no member of staff is present on site.
Office Based Roles
Desktop computers should be password protected and ‘locked’ when you are not at your desk
Your PC Log-in and password should be changed at regular intervals
All office areas should be locked securely outside of working hours, with access only available to pre-authorised key holders.
Filing cabinets, storage areas used for storing data (paper copies) should be locked securely outside of working hours with access only available to pre-authorised key holders.
Recycling and shredding bins are in place. These should be cleared and disposed of correctly at the close of each working day
Field Based role
All outdoor sheds and working areas should be locked securely at the end of every working day and any paperwork relating to customers or colleagues securely filed or locked away.Â
Any paperwork relating to customers or colleagues must not be left in agricultural vehicles or delivery vans overnight or outside of working hours.
Filing cabinets, storage areas used for storing data (paper copies) should be locked securely outside of working hours with access only available to pre-authorised key holders.
Electronic devices used for the business i.e. mobile phones, laptops etc should have the correct level of security in place and be ‘locked’ when not in use.
Be observant and consider the impact that un authorised or unlawful processing, accidental loss, destruction or damage to data could have on you, your colleagues, our customers and the company.
GDPR does not define the security measures that we should have in place. It requires us to have a level of security that is ‘appropriate’ to the risks presented by our policies and processing. The considerations outlined above reflect that we believe is appropriate and easily attainable. If all of our staff accept accountability for security, we will ensure that we do not overlook any security issues.
Thorpe Trees has always taken the utmost care to protect the privacy and personal data of our clients, customers, suppliers, our employees and other workers.Â
Thank you for your support and positive actions in making the above considerations every day activities.
Information We Hold
Employees
Name, Address, Date of Birth, Wages Details, Staff Appraisals –Â
Details used by:Â Company book-keeper / Authorised Manager / Director
Customers & Sales Orders / Sales Invoices
Name / Trading Name
Invoice Address
Contact Telephone Numbers
Contact e-mail address
Delivery address
Third party Customer details as above
Sales order details
Delivery details – name, address. Contact tel no./ contact e-mail
Invoice details
Credit / Debit card details / Bank accounts (Bank refunds)
Project correspondence – e-mails / letters / working documents
Information supplied by:
Telephone / Fax
Letter
Web site
Word of Mouth
Shared with
Administrative Office staff – Sales order details/ Delivery details/invoice details/ Payment information
Management staff – Sales Account details / Payment details/ Project & Advisory correspondence
Field & Delivery staff – Sales order details & telephone numbers
Book-keeping / Accounts/Management – Sales orders / Invoices /Statements / Payments/Legal
Communicating privacy information
Handling privacy data
Upon receipt of an enquiry and depending upon the nature of the enquiry:
Advice or Information is given face-face in the office/ telephone / fax / e-mail (if preferred) / letter
Proposals & Quotations – requests received by verbal/letter/fax/e-mail/web-site. All answered by the appropriately agreed method of communication.
Sales Orders – received by verbal/letter/telephone/fax/e-mail/ web site.
Sales orders are noted/written or attached directly on to a specific ‘sales order’ form or written / attached directly into a numerical sales order book before being entered on to computerised sales ordering system.Â
At this stage we require to have the following customer information – Contact name, invoice name, invoice address, contact telephone number, contact e-mail if available, delivery contact name, delivery address & postcode, delivery contact telephone number, delivery e-mail, map & delivery instructions if appropriate. Card payment details may be taken at this stage over the telephone or in writing and held securely on specific paper work associated with the order until the computerised order is created.Â
Upon receipt of an order Customers are advised of either an approximate date or a specific date for the despatch of the goods.
We advise customers that all account details are retained on the specific order form until goods are despatched and invoiced.Â
Sales order picking Lists are generated for the field staff in order to compile the required goods for the order.Â
Customer details printed on the Picking list include
Order Number, Invoice Name & Address & telephone no., Delivery Name & Address & telephone no.
Date of Despatch, Method of despatch, Individual line item. Blank signature panel for goods received.
Comments box.
Invoices are created upon despatch of the goods at which stage the order is converted into an invoice. Invoices may be collected with the goods, posted or e-mailed directly to the customer. Credit / Debit card payments will be taken at the point of invoice and cc paper slips attached to the main invoice.
Records of customer card details are destroyed immediately once the payment transaction has been authorised.
Alternatively, customers can settle direct account payments by Cheque or BACS. Orders placed over the web site are paid by the intermediary payment gateway – SagePay.
Customers who are offered credit facilities may settle the payment for their account by cheque, BACS or Credit/Debit Card as they prefer. Customers are advised to provide card payment details to our administrative staff over the telephone at which point they are advised that card details are destroyed upon successful completion of the payment transaction.Â
Customers have a right at any stage of the procedure to amend, postpone or cancel an order prior to despatch of the goods.
Sales order books are held within a structured filing system in the main office which is locked at any point when no staff are in attendance in the main office or it is outside of working hours.
Invoice copies are filed and held within a structured filing system in the main office which is locked at any point when no staff are in attendance in the main office or it is outside of working hours.
Computerised sales and account data is backed up on a daily basis onto the Server hard-drive and to the ‘Cloud’ for safe storage.
Director – Caroline Taylor                               Date – 01/09/25