Appropriate Policy Document (APD)

FOR THE PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA AND CRIMINAL OFFENCE DATA UNDER THE DATA PROTECTION LEGISLATION

 

What data protection legislation applies?

The processing of personal data by GroupNexus must be compliant with the UK Data Protection Act 2018 (the “DPA”) as well as other related legislation which is applicable including the General Data Protection Regulation (EU) 2016/679 as implemented in the UK (the “UK GDPR”).  Together, this legal framework is referred to in the rest of this document as the Data Protection Legislation.

 

What is the purpose of this document?

We process special category data in accordance with the requirements of Article 9 of the UK GDPR and Schedule 1 of the DPA.  Some of the Schedule 1 conditions for processing special category and criminal offence data require us to have an Appropriate Policy Document (“APD”) in place, setting out and explaining our procedures for securing compliance with the principles in Article 5 of the UK GDPR and policies regarding the retention and erasure of such personal data.

This APD explains our processing and satisfies the requirements of Schedule 1, Part 4 of the DPA and, along with our suite of data protection policies and notices, aims to ensure that the processing of special categories of data carried out by [Company] is compliant with these requirements.

 

What is defined as special category data?

Special category data is defined at Article 9 UK GDPR as personal data revealing:

  • Racial or ethnic origin.
  • Political opinions.
  • Religious or philosophical beliefs.
  • Trade union membership.
  • Genetic data.
  • Biometric data for the purpose of uniquely identifying a natural person.
  • Data concerning health; or
  • Data concerning a natural person’s sex life or sexual orientation.

 

What is defined as special category data?

Criminal offence data is defined in Section 11 of the DPA as:

  • Personal data relating to criminal convictions and offences.
  • The alleged commission of offences by the data subject; and
  • Proceedings, disposal and sentencing for an offence committed or alleged to have been committed by the data subject.

 

What does processing mean under the UK GDPR?

Processing means almost any use of personal data that is part of or intended to be part of a filing system.  This is a wide definition and includes almost anything you can do with personal data (e.g.  storing it (whether you access it or not) and deleting it are considered to be processing).  Processing can be carried out on both electronic and paper records.

 

Whose personal data does GroupNexus process?

We process certain special category data of:

  • Job applicants and employees
  • Staff of our contractors
  • Blue Badge holders as part of processing client information to manage parking permit schemes

We process certain criminal offence data of:

  • Job applicants and employees.

 

What type of special category personal data do we process?

  • We process special category personal data ((sensitive personal information regarding physical and/or mental health) including data relating to:
  • Information in sickness and absence records
  • Occupational health provision
  • Making reasonable adjustments for interviews and working environments
  • Allergy and dietary information for travel and training catering purposes
  • Maternity status for maternity and paternity leave purposes
  • Grievance handling, disciplinary and legal purposes.
  • Identifying Blue Badge holders as part of processing client information to manage parking permit schemes

 

What type of criminal offence personal data do we process?

We process criminal offence data including data relating to:

  • Assessing job applications and carrying out background and criminal record checks for employment purposes.
  • Business travel to certain countries.

We maintain records of our processing of personal data in accordance with Article 30 of the UK GDPR which documents what special category data of which types of data subjects we process, and the purposes for which we process it.

LEGAL GROUNDS FOR PROCESSING PERSONAL DATA

Schedule 1 conditions for processing

 

Special category data:

We process special category data under the following condition in Schedule 1 of the DPA:

  • Paragraph 1 – employment, social security and social protection.
  • Paragraph 8 – equality of opportunity or treatment

 

Criminal offence data:

We process criminal offence data under the following condition in Schedule 1 of the DPA:

  • Paragraph 1 – employment, social security and social protection.

 

PROCEDURES FOR ENSURING COMPLIANCE WITH THE UK GDPR PRINCIPLES

 

Accountability principle

We have put in place appropriate technical and organisational measures to meet the requirements of accountability.  These include:

  • The appointment of a data protection compliance manager.
  • Maintaining documentation of our processing activities.
  • Adopting and implementing data protection policies.
  • Ensuring we have written contracts in place with our data processors.
  • Implementing appropriate security measures in relation to the personal data we process.
  • Carrying out risk assessments for our high-risk processing.
  • Taking a “data protection by design and default” approach to our activities; and
  • Providing data protection training to all staff.

 

Principle (a): lawfulness, fairness and transparency

Processing personal data must be lawful, fair and transparent.  It is only lawful if and to the extent it is based on law and: either the data subject has given consent for the processing; or one of the other lawful bases in Article 6 of the UK GDPR applies and (in the case of processing special category data) a condition under Article 9(2) of the UK GDPR; and (in the case of criminal offence data) Article 10 is satisfied;  and (for processing under the exceptions for processing special category data contained in Article 9(2)(b), (g), (h), (i) and (j) of the UK GDPR, or processing of criminal offence data) the processing meets at least one of the conditions in the relevant part or parts of Schedule 1 of the DPA.

 

We provide clear and transparent information about why we process personal data (the lawful purposes), including our lawful bases for processing, in our website privacy policy, our other privacy policies and in this policy document.

 

Principle (b): purpose limitation

We process personal data for the lawful purposes referred to above.

We are authorised by law to process personal data for these purposes.   If we are sharing data with another controller, we will document that they are authorised by law to process the data for their purpose.

We will not process personal data for purposes incompatible with the original purpose for which it was collected.

 

Principle (c): data minimisation

We collect personal data necessary for the relevant purposes and ensure it is not excessive.  The information we process is necessary for and proportionate to our purposes.  We keep records of processing of personal data to ensure that we do not collect more data than is necessary for our purposes.

 

Principle (d): accuracy

Where we become aware that personal data is inaccurate or out of date, having regard to the purpose for which it is being processed, we will take every reasonable step to ensure that data is erased or rectified.  When we receive a valid request for erasure or rectification, if we decide not to either erase or rectify the relevant data, for example because the lawful basis we rely on to process the data means these rights do not apply, we will document our decision.

 

Principle (e): storage limitation

All special category data or criminal offence data processed by us is retained for the periods set out in our corporate Data Retention Policy.

 

Principle (f): integrity and confidentiality (security)

Hard copy and electronic information are processed in line with our security procedures, corporate Information Security Policy and Data Protection Policy.

Our electronic systems and physical storage have appropriate access controls applied.  Electronic information is processed within our secure network.  We check the security of our processors, or we require our processors to adhere to our policies.

The systems we use to process personal data allow us to erase or update personal data at any point in time where appropriate in accordance with our Information Security Policy, Data Retention Policy and Data Protection Policy and in accordance with our data subject rights response procedures.

 

APD review

This APD will be reviewed annually by our data protection compliance manager.  This policy will be retained for the duration of our processing and for a minimum of 6 months after processing ceases.

 

Additional special category processing

We process special category data in other instances where it is not a requirement to keep an appropriate policy document.  Our processing of such data respects the rights and interests of the data subjects.  We provide clear and transparent information about why we process personal data including our lawful basis for processing in our website privacy policy and other privacy policies.

 

Name: Ian Langdon
Appointment: Operations Director
Date: 03.09.26

PAY PCN OR APPEAL