GDPR (General Data Protection Regulation) is an EU law that came into effect in May 2018. Any organisation processing and / or storing EU residents’ personal data is likely to need to amend their data policy / policies.
If your organisation collects visitor data it is advisable to create a data policy specifically for visitors. We have put together this template to help you prepare your visitor data policy in order to comply with GDPR.
Using this template should help you put together your new visitor data policy. However please note the following (it is very important!):
Welcm is not a law firm. This document is to provide general information only. It is not intended to be legal advice and should not be treated as such nor is it intended to address your specific requirements. The information is not a complete and comprehensive statement of the law. Organisations should seek independent legal advice regarding data protection, the law, creation of data policies and their specific requirements.
Creating a data policy specifically for visitors:
In order to use this template you will need to replace some terms with your organisation’s details. These terms are:
- *Company Name* replace with your organisation’s name
- *Company Address* replace with your organisation’s registered address
- *Country Name* replace with the country in which you hold data on your systems (if applicable)
- *timescale 1* replace with the timescale you choose before Welcm automatically anonymises visitor data (this is a feature that can be found and adjusted in your System Settings)
- *timescale 2* replace with the timescale you choose before Welcm automatically deletes visitor data (this is a feature that can be found and adjusted in your System Settings)
- *email address* replace with the email address of your Data Officer (or whoever is responsible for your data policies)
Visitor Data Policy
*Company Name*, * Company Address* (“we”, “us”) are committed to protecting and respecting your privacy. This Visitor Data Policy (together with any other documents referred to in this document) sets out the basis on which the personal data collected from you, or that you provide to us, will be processed by us in connection with our visitor management processes. Please read the following document carefully, to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the General Data Protection Regulation (“GDPR”) the Data Controller is *Company Name*.
We use Welcm, an online application provided by Welcm Limited, to assist with our visitor management process. We use Welcm to process personal information as a data processor on our behalf. Welcm is only entitled to process your personal data in accordance with our instructions.
Where you visit us, these Visitor Data Policy provisions will apply to our processing of your personal information, in addition to our other Visitor Data Policy which has been provided to you separately or is available on our website.
Your Personal Information
INFORMATION WE COLLECT FROM YOU
We collect and process some or all of the following types of information from you:
- Information that you provide when you visit us. This includes information provided through our Welcm sign in system, an online site, via email, in person at meetings and/or by any other method.
- In particular, we process personal details such as name, email address, company, vehicle registration and information relating to your visit including time / date and your host.
- If you contact us, we may keep a record of that correspondence.
Uses Made Of Your Information
LAWFUL BASIS FOR PROCESSING
We rely on legitimate interest as the lawful basis on which we collect and use your personal data. Our legitimate interests are the management of visitors, safety and security for our business.
PURPOSES OF PROCESSING
We use information held about you in the following ways:
- To register your visit
- To track whether you are still in our building for safety and security
- To communicate with you in respect of your visit
- To notify your host that you have arrived
- To facilitate visitor management
- To help Welcm improve their services.
Welcm’s technology provides us with the facility to link the data you provide to us with our other visitor management related systems – this may include room booking systems, security systems and associated facilities management systems.
We may use Welcm’s technology to send you this Visitor Data Policy via email. Activating this feature is carried out by us and relies on you providing your email to us at sign in however the process of sending this Visitor Data Policy is entirely automated.
We may use Welcm’s technology to invite you to meetings. The process of selecting you is carried out by your host however the invite is automatic.
How we Store Your Personal Data
We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to view it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
WHERE WE STORE YOUR PERSONAL DATA
Where we store your personal data in our own systems, it is stored in *Country Name*.
The data that we collect from you and process using Welcm’s Services will be stored in the UK but may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). By submitting your personal data, you agree to this transfer, storing or processing.
In particular, your data may be accessible to i) Welcm’s staff in the UK or ii) may be stored by Welcm’s hosting service provider on servers in the UK as well as in the EU. A Data Processor Agreement has been signed between Welcm Limited and each of its data processors. These data processor agreements are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.
If you would like further information please contact us (see ‘Contact’ below). We will not otherwise transfer your personal data outside of the United Kingdom OR EEA or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
HOW LONG WE KEEP YOUR PERSONAL DATA
Welcm’s technology allows us to automatically anonymise visitor data after a pre-defined time period. Your data will be anonymised after *timescale 1*.
Welcm’s technology allows us to automatically delete visitor data after a pre-defined time period. Your data will be deleted after *timescale 2*.
Your personal information will be deleted prior to this upon receipt of a written request by you to us.
Under the General Data Protection Regulation you have a number of important rights. In summary, those include rights to:
- access to your personal data and to certain other supplementary information that this Visitor Data Policy is already designed to address
- require us to correct any mistakes in your information which we hold
- request the erasure of personal data concerning you in certain situations
- request access to the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- object at any time to processing of personal data concerning you for direct marketing
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal data
- otherwise restrict our processing of your personal data in certain circumstances
- claim compensation for damages caused by our breach of any data protection laws.
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please:
- contact us using our Contact details below
- let us have enough information to identify you
- let us have proof of your identity and address
- let us know the information to which your request relates
How to complain
We hope that we can resolve any query or concern you raise about our use of your information.
The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at http://ico.org.uk/concerns/ or telephone: 0303 123 1113.
All questions, comments and requests regarding this Visitor Data Policy should be addressed to *email address*