Data Assurance Policy
Purpose
The Marketing Guys is committed to ensuring the integrity, accuracy, confidentiality, and availability of data across all our operations. This policy sets out our data assurance framework in alignment with the UK GDPR and Data Protection Act 2018.
Data Principles
We ensure that data is:
-
Accurate and up to date
-
Collected and processed lawfully and fairly
-
Stored securely with appropriate safeguards
-
Accessible only to authorised personnel
-
Retained only for as long as necessary
Data Accuracy
-
Regular audits of client and project data to ensure correctness.
-
Data updates must be logged and version-controlled.
Data Integrity
-
Controls in place to prevent unauthorised alterations.
-
Change logs maintained for critical data sets.
Data Confidentiality
-
Access restricted to those with a legitimate business need.
-
All employees bound by confidentiality agreements.
Data Availability
-
Daily system backups stored securely in multiple locations.
-
Disaster recovery plan in place with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
Roles and Responsibilities
-
Data Protection Officer (DPO): Oversees compliance with GDPR.
-
Managers: Ensure correct data handling within their teams.
-
Employees: Must handle data responsibly and report breaches or errors.
Continuous Improvement
-
Annual reviews of data policies and controls.
-
Monitoring of legislative changes and regulatory updates.
-
Regular staff training on data handling and assurance.