privacy policy
Following the implementation of the GDPR on 25/05/2018 we suggest that you refer the viewer to a copy of the firms Data Privacy Statement which will explain how you will process their data, before they begin to complete this form.
We suggest that you are able to substantiate that the website complies with the GDPR requirements and that the website provider can also satisfy the GDPR requirements.
If the site is in part being used to provide customers with quotations, we suggest that you are able to ensure that the relevant initial disclosure requirements are met and that you retain evidence of this.
It is a requirement of the Data Protection Act that the firm discloses certain information to customers when collecting personal information via websites, such as how the information will be processed and by whom. We suggest that you visit the following link for information on this.
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/
We suggest that readers are able to make a positive acknowledgement that they have read the privacy notice and also that they have given permission for the firm to process their personal details. The firm should employ appropriate systems to be able to record the client’s acknowledgement. We would suggest that customers are not able to submit their information unless they have agreed to the terms of the privacy statement.
The Data Protection Act requires firms to ensure that data is held securely, this includes data held electronically. We suggest that you consult with the web designers in order to establish how secure the information provided by customers is at point of entry, transmission, receipt and storage. Where any security risks are identified, you should ensure that measures are put in place to address them. We would suggest you refer to the ICO’s general GDPR guidance below and if you want any additional guidance the ICO has a dedicated helpline for queries 0303 123 1113
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/
We note that the website already features a privacy policy on a separate page of the site. We suggest that you consider whether the existing policy meets the guidelines in the ICO link provided above. We have not considered any legal issues with regard to your privacy policy and we suggest that you confirm that it is fit for purpose with your legal representative. We suggest that relevant information regarding the use of personal information is included at the point at which it is requested and that a link is provided to the full privacy policy. This is the ‘layered’ approach referred to in the ICO guidance in the link provided.