top of page

 GDPR Compliance

Introduction

The EU General Data Protection Regulation (“GDPR”) came into force across the European Union on 25th May 2018 and brought with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age.

The aim of the regulation was to standardise data protection laws and processing across the EU; providing individuals with stronger and more consistent rights to access and control their personal data.

Our Commitment

MM-ICT Limited are committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place. However, we recognise our obligations in updating and expanding this program to meet the demands of the GDPR and the Data Protection Act 2018.

MM-ICT Limited are dedicated to safeguarding the personal information under our remit and in developing a data protection regime that is effective, fit for purpose and demonstrates an understanding of, and appreciation for GDPR. Our preparation and objectives for compliance have been summarised in this statement to ensure maximum and ongoing compliance.

How We Have Prepared for GDPR

MM-ICT Limited have a consistent level of data protection and security across our organisation. In particular, to prepare for GDPR-compliancy, we undertook

  • Information Audit – an audit was conducted to identify and assess what personal information was held by us, where it came from, how and why it was processed and to whom it was disclosed to.

  • Privacy Notice – we have revised our Privacy Notice to comply with GDPR, ensuring that all individuals whose personal information we process have been informed of why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measure are in place to protect their information.

  • Direct Marketing – we have revised the wording and processes for direct marketing, including clear opt-in mechanisms for marketing subscriptions; a clear notice and method for opting out and providing unsubscribe features on all subsequent marketing materials.

Information Security & Technical and Organisational Measures

MM-ICT Limited takes the privacy and security of individuals and their personal information very seriously and take every reasonable measure and precaution to protect and secure the personal data that we process. We have robust information security policies and procedures in place to protect personal information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures, including password policies, two-factor authentication, and user-access restrictions.

 

If you have any questions regarding our compliance with GFPR, please contact us at gdpr@mm-ict.com

Our Privacy Notice can be accessed via the link below:

bottom of page