ANNOUNCEMENT : ALL OF ROYAL MAIL'S EMPLOYMENT POLICIES (AGREEMENTS) AT A GLANCE (Updated 2021)... HERE

ANNOUNCEMENT : PLEASE BE AWARE WE ARE NOT ON FACEBOOK AT ALL!

LTB 227/18 - General Data Protection Regulations (GDPR)

CWU LTB's
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72657
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

LTB 227/18 - General Data Protection Regulations (GDPR)

Post by TrueBlueTerrier »

LTB 227/18 - General Data Protection Regulations (GDPR)

No. 227/18

17th April 2018



Dear Colleague,

General Data Protection Regulations (GDPR)

The purpose of this LTB is to inform all Branches of changes we will be making on the issue of Data Protection. These arise from the need for us to comply with new regulations known as “General Data Protection Regulations” (GDPR) that will come into force on the 25th May 2018.

The new GDPR regulations mean that from the above date information on members is no longer owned by the CWU but is owned by the member. As such the regulations place greater emphasis on the documentation we must keep to demonstrate our compliance with these new requirements. As stated above individuals will now have total control of their personal data as it is their data not ours. The member, known as the data subject will have the right to obtain from the Data Controller (the CWU) confirmation as to where, how and for what purpose their personal data is being held and processed.

To ensure we are compliant we are currently in the process of drafting a number of notices that will cover privacy information, individual rights and data consent.

As the issue progresses we will continue to keep Branches informed of developments to any new strategy that we are required to implement to alleviate any potential fines that the Information Commissioner’s Office (ICO) could impose if we are in breach of GDPR. This point is made because it will only be in the light of working experience will any areas of dubiety be cleared up.

What is important for us to understand is that breaches of the new regulations can result in organisations being fined up to 4% of turnover. To put this in perspective, unless we take action to show we are compliant we risk a fine that could total up £1.1 million for breaches. Clearly our job is to mitigate against such risk and as such there will be number of actions we have to take.

The first of these and the purpose of this LTB is to ensure that the organisation has in place a secure system that contains only data we are entitled to hold, that a member knows where this data is held and is able to access and change their own personal data at any time.

This means we must work to one main database that being the database held by CWU Headquarters in our Membership Records Dept. It is essential that the only data held within Branches is that from the central Integra Online Service (OLS). It is only through such central control can we show the member and the Information Commissioners Office that we are protecting membership information, can inform members where their information is stored and allow them direct access to it. It is not possible to do this if such information is held across multiple platforms in different locations.

As a result any Branch who holds their own data should cease using and maintaining these files with immediate effect. Failure to adhere to this instruction will place the union into conflict with legislation and risks punishment by way of a fine or fines in line with the parameters set out above.

We have already received a small number of queries on this matter from Branches wishing to ensure they don’t do anything that falls foul of the new regulations. Our advice on this is fairly straightforward, as a rule of thumb, do not use any locally held databases for contacting members and contact CWU Headquarters (details below) if you are unsure about the content contained within any message to members.

These new regulations place restrictions on what issues we can communicate with our members on and we will write separately to Branches on this nearer to the 25th May 2018. We are committed to continued communication with our members both at Branch and National level but we have no choice under these regulations but to focus in the immediate future on maintaining data privacy and that is the reason for this particular LTB. We are also assessing a number of options available to us including the development of a Member Case Management Online Service for Branches to utilise.

We will need write to Branches separately to receive written confirmation that no other membership data is being held by them in order that, if necessary, we can show to the relevant authority, that we have acted to ensure compliance with these new regulations.

We also have in place a temporary Data Protection Officer at CWU Headquarters, Denis Lenihan who can be contacted for further information on dlenihan@cwu.org

Any enquiries regarding this Letter to Branches should be addressed to the Senior Deputy General Secretary’s Department on telephone number 020 8971 7237, or email address sdgs@cwu.org

Yours sincerely,



Tony Kearns
Senior Deputy General Secretary

http://emails.cwu.org/t/d-l-okjiho-ztijditiu-d/" onclick="window.open(this.href);return false;
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.
hans solo
Posts: 3270
Joined: 06 Feb 2011, 18:08
Gender: Male

LTB 227/18 - General Data Protection Regulations (GDPR)

Post by hans solo »

i take it this applies to royal mail as well and we can freely access any information they may have on us
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72657
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

LTB 227/18 - General Data Protection Regulations (GDPR)

Post by TrueBlueTerrier »

hans solo wrote:i take it this applies to royal mail as well and we can freely access any information they may have on us
Freely - No

But the Data Protection Act has always allowed you to make a Subject Access Request on anyone who holds data about you. However, they can charge a small admin fee.
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.
Oldschooladdict
Posts: 7
Joined: 24 Oct 2017, 00:55
Gender: Female

LTB 227/18 - General Data Protection Regulations (GDPR)

Post by Oldschooladdict »

TrueBlueTerrier wrote:However, they can charge a small admin fee.
r