Insight Statistical Consulting is registered with the Data Protection Commissioner as a Data Processor (Ref: 1850/A) and has key responsibilities in relation to the information which we keep on computer or in a structured manual file about individuals.
These responsibilities state that we will:
- Obtain and process the information fairly
- Keep information only for one or more specified and lawful purposes
- Process information only in ways compatible with the purposes for which it was given to us initially
- Keep information safe and secure
- Keep information accurate and up-to-date
- Ensure that information is adequate, relevant and not excessive
- Retain information no longer than is necessary for the specified purpose or purposes
- Give a copy of his/her personal data to any individual, on request.
Insight Statistical Consulting (Insight) shall at all times comply with the Data Protection Act 1988 and 2003 (as applicable) (the “Legislation”) and any regulations made under or separate to the Legislation or any other legislation relating to the protection of personal data.
As Data Processors our responsibility as a research agency is to ensure that customer information is stored and handled in a safe and secure manner at all times. When using client lists Insight act as Data Processors.
Customer lists are only used for the intended purpose of the client – the market research project. All customer lists are password protected on the internal server. Soft copies are only saved on the server – never on desktops or USB keys. If printed, they are stored in a locked filing cabinet when not in use and are disposed of using a shredder. All customer lists are securely deleted from the server within a timeframe agreed with the client.
In the absence of any express instructions to the contrary, all personal data received by Insight from any client shall be retained for as long as is necessary, having consideration to the processing that was carried out, and in any event for no longer than 6 months once such processing ceases and thereafter such data shall be securely deleted and/or destroyed thereafter, whether in electronic or manual format.
Where it is necessary to transfer personal data from one location to another, whether physically or electronically, the necessary information security precautions need to be taken. This includes the use of electronic encryption technology.
The Insight server has adequate security provided by Cloudstrong who have signed an NDA. Our server can be accessed by selected Insight staff who have signed a Confidentiality Agreement and abide the Market Research Society Code of Conduct. We have procedures in place to control access to the server. The server is located in a secure area to protect against access, spillage and other potential hazards.
Back-ups are conducted at our Dublin office every evening. Back-up data is also stored in a secure area off-site. We are located in a central Dublin area so outages due to electricity supply problems are minimal.
Insight will refrain from disclosing personal data to any third parties other than to permitted sub-contractors to whom disclosure is reasonably necessary in order for the us to carry out the Services, provided that in all cases:
- such disclosure is made subject to written terms substantially the same as the terms contained in this processor agreement;
- such disclosure has been approved in writing in advance by the client; and
- upon the request of the client, promptly provide a written description of the technical and organisational measures employed by it and/or any of its permitted sub-contractors, detailed to such a level that the client can determine whether or not, in connection with personal data, the Supplier and its permitted sub-contractors are complying with their obligations under this Agreement. If, in the clients opinion, the measures employed by the Supplier and/or its permitted sub-contractors are not sufficient to ensure compliance with their obligations under this Agreement, the Supplier shall take all steps (or procure that its permitted sub-contractors take all steps) which are reasonably required to ensure that such compliance is achieved;
- afford to the client (and procure that its permitted sub-contractors afford to the client) access on reasonable notice and at reasonable intervals to any premises where the relevant personal data are being processed to enable The client to ensure that the Supplier is complying with its obligations under this Agreement and/or that the Supplier’s permitted sub-contractors are complying with the equivalent contractual obligations imposed on them;
- promptly refer to The client any requests, notices or other communication from data subjects, the office of the Data Protection Commissioner or any other law enforcement agency relating to personal data for The client to resolve;
- at no additional cost, provide such information to The client as The client may reasonably require, and within the timescales reasonably specified by The client, to allow The client to comply with rights of data subjects, including subject access, or with notices served by the office of the Data Protection Commissioner; and
Our Data Protection Officer – David Harmon (an Insight employee) – ensures adherence to secure storage and handling of data by all Insight employees.
How to contact us
Questions regarding this policy, complaints about our practices and access requests should be directed to the Insight Data Protection Officer via e-mail at firstname.lastname@example.org or by mail to 60 Merrion Square (South), Dublin 2, D02 NT04, Ireland. Insight can also be contacted via phone at ++353 1 6612467.