DATA DELETION POLICY
1. Purpose
This document sets out PRISM Brain Mapping UK’s policy for responding to requests for deletion of data under the GDPR (General Data Protection Regulation), which comes into force on 25th May 2018. This document explains the rights of the data subject in relation to data deletion and the responsibilities of PRISM in responding with such a request.
2. Individual Rights
An individual has the right to erasure also known as ‘the right to be forgotten’. The principle underpinning this right is to enable an individual to request the deletion or removal of personal data where there is no compelling reason for its continued processing.
3. When Does the Right to Erasure Apply?
As stipulated in the GDPR, individuals have a right to have personal data erased and to prevent processing in specific circumstances:
- Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed
- When the individual withdraws consent
- When the individual objects to the processing and there is no legal ground for the relevant processing activity
- When the personal data was unlawfully processed
- Where the personal data has to be erased in order to comply with a legal obligation
4. What Information does PRISM retain?
The PRISM system stores data about individuals in order to create PRISM reports. We store the name, email address, gender, company/organisation and responses from the PRISM questionnaire in order to create a report. This information is stored on our secure server in the UK. This data is stored and used in accordance with our Privacy Policy which can be found at www.prismbrainmapping.com/privacy.aspx
5. How Can Data be Deleted?
PRISM Brain Mapping UK, a PRISM Distributor and PRISM Practitioners can delete data from their PRISM system whenever they wish. This data is deleted from the system immediately and cannot be recovered by any users or PRISM Brain Mapping UK after this point. Data which has been deleted or otherwise destroyed cannot be recovered at any time. Sufficient warning is given before anything is permanently deleted.
Data may still remain in the systems back-up files for a period of 7 days after which the backups will be overwritten and the data destroyed permanently.
Information may be deleted from our CRM upon request to info@prismbrainmapping.com. We undertake to perform the deletion within one month (30 calendar days) and will send you a confirmation once the information has been deleted. We will aim to complete the request well in advance of this deadline.