1. Introduction
Penta Consulting is committed to conducting its business in accordance with all applicable Data Protection laws and regulations and in line with the highest standards of ethical conduct.
This policy sets forth the expected conduct of Penta Consulting Employees and Third Parties in relation to the collection, use, retention, transfer, disclosure and destruction of any Personal Data belonging to a Penta Consulting Contact (i.e. the Data Subject). Personal Data is any information (including opinions and intentions) which relates to an identified or Identifiable Natural Person and is subject to certain legal safeguards and other regulations, which impose restrictions on how organisations may process Personal Data. An organisation that handles Personal Data and makes decisions about its use is known as a Data Controller. Penta Consulting, as a Data Controller, is responsible for ensuring compliance with the Data Protection requirements outlined in this policy. Non-compliance may expose Penta Consulting to complaints, regulatory action, fines and/or reputational damage.
Penta Consulting’s leadership is fully committed to ensuring continued and effective implementation of this policy, and expects all Penta Consulting Employees and Third Parties to share in this commitment. Any breach of this policy will be taken seriously and may result in disciplinary action or business sanction.
2. Scope
This policy applies to all Penta Consulting Entities where a Data Subject’s Personal Data is processed:
In the context of the business activities of the Penta Consulting Entity.
For the provision of services to individuals or businesses by Penta Consulting or its Entities.
To actively monitor the behaviour of individuals.
Monitoring the behaviour of individuals includes using data processing techniques such as persistent web browser cookies or dynamic IP address tracking to profile an individual with a view to taking a decision about them.
This policy applies to all Processing of Personal Data in electronic form (including electronic mail and documents created with word processing software) or where it is held in manual files that are structured in a way that allows ready access to information about individuals.
This policy has been designed to establish a worldwide baseline standard for the Processing and protection of Personal Data by all Penta Consulting and its Entities. Where national law imposes a requirement which is stricter than imposed by this policy, the requirements in national law must be followed. Furthermore, where national law imposes a requirement that is not addressed in this policy, the relevant national law must take precedence hereto. If there are conflicting requirements in this policy and national law, the Data Protection Team must be contacted for further guidance.
The protection of Personal Data belonging to Penta Consulting Employees is not within the scope of this policy.
3. Definitions
Employee: An individual who works part-time or full-time for Penta Consulting under a contract of employment, whether oral or written, express or implied, and has recognised rights and duties (including temporary employees and independent contractors).
Third Party: An external organisation with which Penta Consulting conducts business and is also authorised to, under the direct authority of Penta Consulting, Process the Personal Data of Penta Consulting Contacts.
Personal Data: Any information (including opinions and intentions) which relates to an identified or Identifiable Natural Person.
Contact: Any past, current or prospective Penta Consulting customer.
Identifiable Natural Person: Anyone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data Controller: A natural or legal person, Public Authority, Agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
Penta Consulting Entity: A Penta Consulting establishment, including subsidiaries and joint ventures over which Penta Consulting exercises management control.
Data Subject: The identified or Identifiable Natural Person to which the data refers.
Process, Processed, Processing: Any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means. Operations performed may include collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Protection: The process of safeguarding Personal Data from unauthorised or unlawful disclosure, access, alteration, Processing, transfer or destruction.
Data Protection Authority: An independent Public Authority responsible for monitoring the application of the relevant Data Protection regulation set forth in national law.
Data Processors: A natural or legal person, Public Authority, Agency or other body which Processes Personal Data on behalf of a Data Controller.
Consent: Any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
Special Categories of Data: Personal Data pertaining to or revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership; data concerning health or sex life and sexual orientation; genetic data or biometric data.
Third Country: Any country not recognised as having an adequate level of legal protection for the rights and freedoms of Data Subjects in relation to the Processing of Personal Data.
Profiling: Any form of automated processing of Personal Data where Personal Data is used to evaluate specific or general characteristics relating to an Identifiable Natural Person, in particular to analyse or predict certain aspects concerning that natural person’s performance at work, economic situations, health, personal preferences, interests, reliability, behaviour, location or movement.
Binding Corporate Rules: The Personal Data protection policies used for the transfer of Personal Data to one or more Third Countries within a group of undertakings, or group of enterprises engaged in a joint economic activity.
Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
Encryption: The process of converting information or data into code, to prevent unauthorised access.
Pseudonymisation: Data amended in such a way that no individuals can be identified from the data (whether directly or indirectly) without a “key” that allows the data to be reidentified.
Anonymization: Data amended in such a way that no individuals can be identified from the data (whether directly or indirectly) by any means or by any person.
4. Policy
Governance
Data Protection Team
To demonstrate our commitment to Data Protection, and to enhance the effectiveness of our compliance efforts, Penta Consulting has appointed a Data Protection Team. The DP Team operates with independence and reports to Penta Consulting’s Group Operations Director. The Data Protection Team’s duties include:
Informing and advising Penta Consulting and its Employees who carry out Processing pursuant to Data Protection regulations, national law or Union based Data Protection provisions.
Ensuring the alignment of this policy with Data Protection regulations, national law or Union based Data Protection provisions.
Acting as a point of contact for and cooperating with Data Protection Authorities (DPAs).
Determining the need for notifications to one or more DPAs as a result of Penta Consulting Ltd.’s current or intended Personal Data processing activities.
Making and keeping current notifications to one or more DPAs as a result of Penta Consulting Ltd.’s current or intended Personal Data processing activities.
The establishment and operation of a system providing prompt and appropriate responses to Data Subject requests.
Informing senior managers, officers, and directors of Penta Consulting of any potential corporate, civil and criminal penalties which may be levied against Penta Consulting and/or its Employees for violation of applicable Data Protection laws.
Ensuring establishment of procedures and standard contractual provisions for obtaining compliance with this Policy by any Third Party who:
provides Personal Data to a Penta Consulting Entity
receives Personal Data from a Penta Consulting Entity
has access to Personal Data collected or processed by a Penta Consulting Entity.
Policy Enforcement
The management team of each Penta Consulting Entity must ensure that all Penta Consulting Ltd Employees responsible for the Processing of Personal Data are aware of and comply with the contents of this policy.
In addition, each Penta Consulting Entity will make sure all Third Parties engaged to Process Personal Data on their behalf (i.e. their Data Processors) are aware of and comply with the contents of this policy. Assurance of such compliance must be obtained from all Third Parties, whether companies or individuals, prior to granting them access to Personal Data controlled by Penta Consulting.
Compliance Monitoring
The Data Protection Team, in cooperation with key business stakeholders from each Penta Consulting Ltd Entity, will devise a plan with a schedule for correcting any identified deficiencies within a defined and reasonable time frame. Any major deficiencies identified will be reported to and monitored by the Penta Consulting Executive Management team.
Data Protection Principles
Penta Consulting has adopted the following principles to govern its collection, use, retention, transfer, disclosure and destruction of Personal Data:
Principle 1: Lawfulness, Fairness and Transparency
Personal Data shall be processed lawfully, fairly and in a transparent manner in relation to the Data Subject. This means Penta Consulting must tell the Data Subject what Processing will occur, the Processing must match the description given to the Data Subject, and it must be for one of the purposes specified in the applicable Data Protection regulation.
Principle 2: Purpose Limitation
Personal Data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Penta Consulting Ltd must specify exactly what the Personal Data collected will be used for and limit Processing to what is necessary.
Principle 3: Data Minimisation
Personal Data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. Penta Consulting must not store Personal Data beyond what is strictly required.
Principle 4: Accuracy
Personal Data shall be accurate and kept up to date. Penta Consulting must have processes for identifying and addressing out-of-date, incorrect and redundant Personal Data.
Principle 5: Storage Limitation
Personal Data shall be kept in a form permitting identification of Data Subjects for no longer than necessary. Wherever possible, Penta Consulting must store Personal Data in a way that limits or prevents identification of the Data Subject.
Principle 6: Integrity & Confidentiality
Personal Data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful Processing and against accidental loss, destruction or damage. Appropriate technical and organisational measures must maintain integrity and confidentiality.
Principle 7: Accountability
The Data Controller shall be responsible for, and able to demonstrate, compliance. Penta Consulting must demonstrate that the six Data Protection Principles outlined above are met for all Personal Data for which it is responsible.
Justification for using the Data
The conditions for processing are set out in Schedules 2 and 3 to the Data Protection Act. Unless a relevant exemption applies, at least one of the following conditions must be met whenever we process your personal data:
You have consented to the processing.
The processing is necessary in relation to a contract which we entered into, or because you have asked for something to be done so we can enter into a contract.
The processing is necessary because of a legal obligation that applies to you (except an obligation imposed by a contract).
The processing is necessary to protect your “vital interests”.
The processing is necessary for administering justice, or for exercising statutory, governmental, or other public functions.
The processing is in accordance with the “legitimate interests” condition.
We may source your CV data from external sources including but not limited to LinkedIn, Job Boards and/or referrals and may keep it on our database for our legitimate business interest.
We may share your CV with our Clients if you are looking for your next role, and we will always obtain your consent before doing so. We may enter into a legal contract that will contain your express consent for processing your data under one of the conditions for data processing.
At the end of the contract we may still have a legal obligation for processing your data until reaching the retention period. We will retain your data in line with our 10-year retention policy.
Data Sources
Personal Data should be collected only from the Data Subject unless one of the following applies:
The nature of the business purpose necessitates collection of the Personal Data from other persons or bodies.
The collection must be carried out under emergency circumstances in order to protect the vital interests of the Data Subject or to prevent serious loss or injury to another person.
If Personal Data is collected from someone other than the Data Subject, the Data Subject must be informed unless they have received the required information by other means, the information must remain confidential due to a professional secrecy obligation, or national law expressly provides for the collection, Processing or transfer.
Where notification to a Data Subject is required, it should occur promptly, but in no case later than:
One calendar month from the first collection or recording of the Personal Data.
At the time of first communication if used for communication with the Data Subject.
At the time of disclosure if disclosed to another recipient.
Data Subject Consent
Each Penta Consulting Entity will obtain Personal Data only by lawful and fair means and, where appropriate, with the knowledge and Consent of the individual concerned. Where Consent is needed before collection, use or disclosure, Penta Consulting is committed to seeking it. The Data Protection Team, in cooperation with Group General Counsel, the Operations Director and other relevant representatives, shall establish a system for obtaining and documenting Data Subject Consent. The system must include provisions for:
Determining what disclosures should be made to obtain valid Consent.
Ensuring the request for Consent is clearly distinguishable from other matters, intelligible, easily accessible and written in clear and plain language.
Ensuring Consent is freely given and is not based on a contract conditional on unnecessary Processing.
Documenting the date, method and content of disclosures, as well as the validity, scope and volition of Consents.
Providing a simple method for a Data Subject to withdraw Consent at any time.
Data Subject Notification
Each Penta Consulting Entity will, when required by applicable law or contract, or where reasonably appropriate, provide Data Subjects with information as to the purpose of Processing their Personal Data.
When a Data Subject is asked to give Consent and when Personal Data is collected from them, all appropriate disclosures will be made in a manner that draws attention to them, unless the Data Subject already has the information or a legal exemption applies. Disclosures may be given electronically or in writing. The associated receipt or form should be retained with a record of the facts, date, content and method of disclosure.
External Privacy Notices
Each external website provided by a Penta Consulting Entity will include an online Privacy Notice and Cookie Notice fulfilling the requirements of applicable law. All Privacy and Cookie Notices must be approved by the Data Protection Team prior to publication.
Data Use
Penta Consulting uses the Personal Data of its Contacts for the following broad purposes:
The general running and business administration of Penta Consulting Entities.
To provide services to Penta Consulting Clients.
The ongoing administration and management of customer services.
The use of a Contact’s information should always be considered from their perspective and whether the use will be within their expectations or they are likely to object. It would be within a Contact’s expectations that their details are used to respond to a request for information, but not that their details are provided to Third Parties for marketing purposes.
Each Penta Consulting Entity will process Personal Data in accordance with applicable laws and contractual obligations. Penta Consulting Ltd will not process Personal Data unless at least one of the following requirements is met:
The Data Subject has given Consent for one or more specific purposes.
Processing is necessary for performance of a contract, or to take steps at the Data Subject’s request before entering into a contract.
Processing is necessary for compliance with a legal obligation.
Processing is necessary to protect the vital interests of the Data Subject or another natural person.
Processing is necessary for a task carried out in the public interest or exercise of official authority.
Processing is necessary for legitimate interests pursued by the Data Controller or a Third Party, except where overridden by the interests or fundamental rights and freedoms of the Data Subject, particularly a child.
Where Personal Data may be further processed beyond its original purpose, guidance and approval must be obtained from the Office of Data Protection before Processing begins. Where Consent has not been gained, Penta Consulting will consider links between the original and proposed purposes, the collection context and relationship, the nature of the data, possible consequences for the Data Subject, and appropriate safeguards such as Encryption, Anonymisation or Pseudonymisation.
Special Categories of Data
Penta Consulting will only Process Special Categories of Data where the Data Subject expressly consents or where one of the following conditions applies:
The Personal Data has already been made public by the Data Subject.
Processing is necessary for the establishment, exercise or defence of legal claims.
Processing is specifically authorised or required by law.
Processing is necessary to protect vital interests where the Data Subject is physically or legally incapable of giving consent.
Further conditions or limitations based on national law apply to genetic data, biometric data or data concerning health.
Prior approval must be obtained from the Data Protection Team and the basis for Processing clearly recorded. Additional protection measures will be adopted, including measures addressing local custom or social expectation where appropriate.
Children’s Data
Children are unable to Consent to the Processing of Personal Data for information society services. Consent must be sought from the person who holds parental responsibility. Where Processing is lawful under other grounds, Consent need not be obtained. Any business need for parental consent for services offered directly to a child requires guidance and approval from the Office of Data Protection before Processing may commence.
Data Quality
Each Penta Consulting Entity will adopt necessary measures to ensure that Personal Data it collects and Processes is complete and accurate initially and updated to reflect the current situation of the Data Subject. Measures include:
Correcting Personal Data known to be incorrect, inaccurate, incomplete, ambiguous, misleading or outdated, even without a rectification request.
Keeping Personal Data only for the period necessary to satisfy permitted uses or statutory retention periods.
Removing Personal Data where it violates Data Protection principles or is no longer required.
Restricting rather than deleting Personal Data where law prohibits erasure, erasure would impair legitimate interests of the Data Subject, or accuracy is disputed and cannot be clearly ascertained.
Profiling & Automated Decision-Making
Penta Consulting will only engage in Profiling and automated decision-making where necessary for the provision of services or authorised by law. Profiling relating to a Data Subject must be based on accurate data.
Digital Marketing
From time to time, promotional or direct marketing material may be sent to a Penta Consulting Ltd Contact through digital channels without first obtaining Consent only where necessary for the provision of services, such as marketing a job they may be interested in. Any campaign without prior Consent must first be approved by the Office of Data Protection. The Data Subject must be informed at first contact of the right to object at any stage. If they object, digital marketing Processing must cease immediately and their details must be kept on a suppression list with a record of the opt-out decision rather than being completely deleted.
Where digital marketing is carried out in a business-to-business context, there is no legal requirement to obtain an indication of Consent provided individuals are given the opportunity to opt out.
Data Retention
To ensure fair Processing, Personal Data will not be retained for longer than necessary for the purposes for which it was collected or further Processed. Retention periods take account of minimum and maximum legal and contractual requirements. Personal Data should be deleted or destroyed as soon as it is confirmed there is no longer a need to retain it.
Data Protection
Each Penta Consulting Entity will adopt physical, technical and organisational measures to ensure the security of Personal Data, including prevention of loss or damage, unauthorised alteration, access or Processing, and other risks arising from human action or the physical or natural environment. Measures include:
Prevent unauthorised persons gaining access to data processing systems in which Personal Data is Processed.
Prevent authorised users accessing Personal Data beyond their needs and authorisations.
Protect Personal Data during electronic transmission or transport from unauthorised reading, copying, modification or removal.
Maintain access logs showing whether, and by whom, Personal Data was entered, modified or removed.
Ensure Data Processors act only in accordance with Data Controller instructions.
Protect Personal Data against undesired destruction or loss.
Ensure Personal Data collected for different purposes can be processed separately.
Ensure Personal Data is not kept longer than necessary.
Data Subject Requests
The Data Protection Team will establish a system to enable and facilitate Data Subject rights related to:
Information access.
Objection to Processing.
Objection to automated decision-making and Profiling.
Restriction of Processing.
Data portability.
Data rectification.
Data erasure.
Requests will be considered in accordance with applicable Data Protection laws. No administration fee will be charged unless a request is deemed unnecessary or excessive. Following a written request and successful identity verification, Data Subjects are entitled to information about the purposes, sources, categories, recipients, storage period, automated decision-making and their rights to object, complain, rectify, erase or restrict Processing.
All requests for access to or rectification of Personal Data must be directed to the Office of Data Protection or dpo@pentaconsulting.com. A response will be provided within 30 days of receipt. Appropriate verification must confirm the requester is the Data Subject or authorised legal representative. If Penta Consulting cannot respond fully within 30 days, it will provide an acknowledgement, information located to date, details and reasons for anything withheld, available appeal procedures, an estimated completion date, any estimated costs where the request is excessive, and a contact for follow-up.
Where providing requested information would disclose Personal Data about another individual, information must be redacted or withheld as necessary or appropriate to protect that person’s rights.
4.8 Law Enforcement Requests & Disclosures
In certain circumstances, Personal Data may be shared without the knowledge or Consent of a Data Subject where disclosure is necessary for:
The prevention or detection of crime.
The apprehension or prosecution of offenders.
The assessment or collection of a tax or duty.
An order of a court or any rule of law.
An exception to the Processing rules may be applied only to the extent that not doing so would be likely to prejudice the case. Any request from a court, regulator or law enforcement authority relating to a Penta Consulting Contact must be notified immediately to the Office of Data Protection for guidance and assistance.
4.9 Data Protection Training
All Penta Consulting Employees with access to Personal Data will have their responsibilities outlined during induction. Each Entity will also provide regular Data Protection training and procedural guidance covering, at a minimum:
The Data Protection Principles in Section 4.2.
The duty to use and permit use of Personal Data only by authorised persons and for authorised purposes.
The forms and procedures adopted to implement this policy.
Correct use of passwords, security tokens and access mechanisms.
Limiting access through password-protected screen savers and logging out when systems are unattended.
Secure storage of manual files, printouts and electronic storage media.
Authorisation and safeguards for transfers outside the internal network and physical office premises.
Secure disposal using shredding facilities.
Special risks associated with particular departmental activities or duties.
4.10 Data Transfers
Penta Consulting Entities may transfer Personal Data to internal or Third Party recipients in another country where that country is recognised as providing an adequate level of legal protection. Transfers to Third Countries must comply with an approved transfer mechanism. Transfers may only take place where one of the following applies:
The Data Subject has given Consent.
The transfer is necessary for performance of a contract.
The transfer is necessary for pre-contractual measures taken at the Data Subject’s request.
The transfer is necessary for a contract with a Third Party in the Data Subject’s interest.
The transfer is legally required on important public-interest grounds.
The transfer is necessary for the establishment, exercise or defence of legal claims.
The transfer is necessary to protect the vital interests of the Data Subject.
Transfers between Penta Consulting Entities
Where Personal Data is transferred between Entities or accessed from overseas, the sending Entity remains responsible for its protection. Transfers to a Third Country use the Binding Corporate Rules mechanism, which provides legally binding and enforceable rights for Data Subjects. Before transferring, ensure the recipient is on the approved list maintained by the Office of Data Protection, transfer only the minimum necessary data, and use adequate security measures including password protection and Encryption where necessary.
Transfers to Third Parties
Each Entity will transfer Personal Data to, or allow access by, Third Parties only where assured that it will be processed legitimately and protected appropriately. The Entity will identify whether the Third Party is a Data Controller or Data Processor. Controllers require an appropriate agreement clarifying each party’s responsibilities. Processors require a Processing agreement mandating protection from further disclosure, Processing only on Penta Consulting instructions, appropriate technical and organisational measures, and Personal Data Breach notification procedures.
Outsourcing, including Cloud Computing, must identify whether the Third Party will Process Personal Data and whether Third Country transfers are involved. Adequate contractual provisions must be included in cooperation with the Office of Data Protection, using the Standard Provisions for Outsourcing Agreement as guidance. The Office of Data Protection will conduct regular audits of Third Party Processing, with major deficiencies reported to and monitored by the Executive Management team.
4.11 Complaints Handling
Data Subjects with a complaint about Processing should put the matter in writing to the Data Protection Team. An investigation will be carried out as appropriate to the merits of the case, and the Data Subject will be informed of progress and outcome within a reasonable period. If unresolved through consultation, the Data Subject may seek redress through mediation, binding arbitration, litigation or complaint to the applicable Data Protection Authority.
4.12 Breach Reporting
Any individual who suspects a Personal Data Breach due to theft or exposure must immediately notify the Data Protection Team and describe what occurred. Notifications can be made by email to dpo@pentaconsulting.com or by calling (+44) 208 647 3999.
The Data Protection Team will investigate all reported incidents. If a breach is confirmed, it will follow the relevant authorised procedure based on the criticality and quantity of Personal Data involved. For severe breaches, the Group Operations Director will initiate and chair an emergency response team to coordinate and manage the response.
5. Policy Maintenance
All inquiries about this policy, including requests for exceptions or changes, should be directed to the Data Protection Team via email: dpo@pentaconsulting.com.
5.1 Publication
This policy shall be available to all Penta Consulting Employees through the Penta Consulting Ltd Policy intranet or via alternative means as deemed appropriate by the Data Protection Team.
5.2 Effective Date
This policy is effective as of 19 March 2018 and reviewed annually.
5.3 Revisions
The Office of Data Protection is responsible for the maintenance and accuracy of this policy. Notice of significant revisions shall be provided to Penta Consulting Employees through the Human Resources department. Changes will come into force when published on the website.