This Data Security & Information Governance Manual supplements the policies and procedures in our Quality Manual.

The purpose of this Manual is to assist us in ensuring that we meet the standards required in relation to the handling and processing of data.  In particular, it sets out our policies and procedures which we have implemented to mitigate against risks to the security and integrity of data and confidential information.

Responsibilities:

The key personnel involved in developing and implementing the policies and procedures in this Manual are as follows:

Name Role Specific Responsibilities
Andrew Ayres COLP Authorisation and Implementation
Andrew Ayres Data Protection Officer (DPO) Authorisation and Implementation
Andrew Ayres COFA Authorisation and Implementation
Andrew Ayres, Rachel Smith. Cybercrime and Fraud prevention Training, Alerts, Implementation

The person with overall responsibility for authorisation and implementation of the policies and procedures in this Manual and for monitoring compliance is our COLP/DPO, Andrew Ayres.

In addition, specific responsibilities may be delegated on a day-to-day level to other personnel and who are required to report at least monthly to Rachel Smith.  Where relevant, these delegated duties will be confirmed in the individual policies and procedures in the body of this Manual.

Review:

Rachel Smith undertakes an annual review of this Manual to ensure that the policies, procedures and information remains in effective operation across the practice.

If any member of staff has suggestions to change the Manual, they should contact Andrew Ayres or Rachel Smith directly.

Whenever the manual is updated, the following actions will be undertaken:

Amendments are incorporated into the manual.

On the page footer, the date it was issued, and its revision status is shown.

The amendment(s) in the Revision Register are recorded at the front of the Manual, and all staff are informed of the change.

 

Location and Access

The master copy of this document is located with Rachel Smith.  Copies are available from her.

Copies of the manual are also kept:

In our COLP’s office

In hard-copy format on each floor

Electronically on the Intranet [S: Data/Office Manual]

POLICIES

 

Data Protection Policy

We take our obligations under the Data Protection legislation very seriously.  The nature of our work means that we hold highly confidential information in respect of our clients, staff and others.

We are registered with the Information Commissioner’s Office (ICO) under registration number Z7879439.

 

Responsibilities

[Our COLP, Andrew Ayres is also our appointed Data Protection Officer (DPO).  We are not required to appoint a Data Protection Officer (DPO) but our COLP is responsible for ensuring compliance with all relevant Data Protection legislation].

It is our COLP’s / DPO’s responsibility to ensure that:

the firm is, at all times, registered with the ICO

there is a process of continual review to determine whether any changes in the firm’s registration are required as a result of changes in the nature of the business

the details of the firm as registered are kept up to date

the notification to the ICO is renewed annually

the firm maintains and updates the public Data Protection Register which will be reviewed regularly and at least on an annual basis, and

the firm maintains the policies and procedures in this Manual

This policy has been updated to reflect the requirements of the General Data Protection Regulation (GDPR) (and the Data Protection Bill 2017-19).

Data Protection by Design

 

We consider data protection issues at the earliest opportunity and consider data protection within the design process where we are implementing new technologies or where we are making significant changes to the way in which we process personal data.

To maintain client confidentiality and ensure that no information is shared with a caller affecting to be the client, when handling incoming calls all staff must ask ‘clients’ two out of three identification questions to confirm the identity of the caller.  These questions cannot be information that could easily be known by anybody other than the client themselves e.g. date of birth.

Whenever we substantially change our policies, procedures, software or infrastructure, we will consider data security and data protection issues and, where necessary, undertake a data protection impact assessment. It is our COLP/DPO’s responsibility to ensure that any necessary Data Protection Impact Assessment is undertaken.

 

Data Protection Principles

When handling any personal data, this firm does so in compliance with the principles set out in the GDPR, namely that personal data will be:

processed lawfully, fairly and in a transparent manner in relation to individuals

collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes

adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed

accurate and, where necessary, kept up to date with every reasonable step being taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, and are erased or rectified without delay

kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, and

processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures

To ensure compliance with these principles, we have also put in place or adapted the policies and procedures in this Manual.

This and the other associated policies and procedures in this Manual have been implemented to mitigate and manage data protection related risks.

Information Audit and Risk Assessment

We have undertaken a detailed information audit and risk assessment and have recorded associated risks as Risk Registers on the office Z Drive.

It is the role of our COLP / DPO to ensure that the information audit and risk assessment is reviewed annually or as is necessary during the year and that any necessary policy or procedural changes are implemented and updated.

As part of the audit process, our network and devices are reviewed to determine if further steps are required to ensure the security of our systems.

As part of the process, we also maintain a record of our data processing, including maintaining records of:

all data that we process

how we process it

the purposes for which it is processed, and

any associated consents, destruction methods and other relevant information

The records are documented in our client care letters, a copy of which is with each individual client file.  Data recorded is securely stored on OPSIS. These records are reviewed annually or as is necessary during the year.

Privacy Notices

We have implemented clear Privacy Notices setting out why data is held; how it is processed; how long it is held; and that data subjects have statutory rights in respect of that data.  These privacy notices are reviewed at least annually by our COLP / DPO (and more often if circumstances require).

Conditions for Processing

We typically process data only for the performance of our contract / retainer with the data subject (typically our client or our employee) or for statutory or contractual purposes associated with our performance of our contract / retainer with the data subject.  Where we seek to process data for any reason other than for the performance of our contract / retainer with the data subject we will always consider whether we have a lawful basis for that processing and, if necessary, we will seek explicit consent from the data subject.

[If we use client data for direct marketing purposes we will only use it for email marketing and only for services that are the same or similar to those for which they originally provided the data.  We will always ensure that any such marketing communications give them a clear opportunity to opt-out of future communications.]

Consent

Where we need to seek consent (for instance to use the data for marketing purposes or to make it available to an external auditor, [other than in legally aided cases where no consent is required] then we will seek individual consent for each of the purposes for which we seek to process the data.  We do not use deemed consent or opt out consent options.  All consents sought will be clearly worded; individual and opt in.

Emergency cases will be given the consent to sign at the first meeting. This will be followed up by a formal Client Care Letter, which details the full policy and is attached to a copy of the signed consent.

Non-emergency clients will be guided through the consent process at the first meeting, offered a hard copy of the GDPR booklet and required to sign consent to data use, which is part of the Client Care Letter.

Details of any necessary consents will be recorded on the central register of consents.  This register will also include the consents signed by external Data Processors (save for Counsel and Registered Medical Professionals who are regulated by their relevant Regulatory Authority) or who are not members of the ICO.  Refer to our Transfer of Data to Third Parties Policy.

External Data Processors

There are circumstances where we are likely to have to use external Data Processors.  Typical examples include:

Counsel

Experts

Costs Draftsmen

File Storage Companies

IT support and data storage companies

Some of these are Data Processors in their own right (i.e. counsel and experts).

Wherever we use external Data Processors we will do so in accordance with our Transfer of Data to Third Parties Policy.

Training

All staff receive training on data protection and data security as part of their induction process.  This training is updated annually (or more frequently if necessitated by changes in legislation or guidance or as a result of previously identified breaches or changes to our systems, policies or procedures).

Data Breaches

If any staff member becomes aware of a data breach including a breach or potential breach of this policy or any of the policies or procedures in this Manual (and in particular our Information Management & Security Policy and Information Security Procedures) they must report that breach to our COLP immediately (and in the COLP’s absence to Rachel Smith) and agree:

What steps should be taken to mitigate or manage the impact of the breach

Whether the data subject needs to be notified, and

Whether the ICO needs to be notified

Breaches are likely to need to be reported to the ICO where they are likely to result in a risk to the rights and freedoms of the data subject.  If unaddressed, such a breach is likely to have a significant detrimental effect on the data subject.  For example, the breach is likely to require reporting to the ICO where it results in:

discrimination

damage to reputation

financial loss

loss of confidentiality, or

any other significant economic or social disadvantage

This has to be assessed on a case by case basis and it is the role of the COLP to determine whether a breach must be reported to the ICO or otherwise.  Breaches must be reported to our COLP immediately in accordance with our Compliance Policy as set out in our Quality Manual.  He will determine whether the breach needs to be recorded on our Breach Register and whether an incident management plan needs to be implemented.

Information Management & Security Policy

 

The information we hold is often highly confidential, subject to legal professional privilege and may also be commercially sensitive and potentially valuable.  If this information is mismanaged there could be serious repercussions for clients, other individuals as well as for the firm.

Our policy is to protect the information we hold from all threats, whether internal, external, deliberate or accidental.

It is our policy to ensure that:

information is protected against unauthorised access

information is kept confidential

the integrity of information we hold is maintained

all breaches of information security, actual or suspected are reported (immediately), investigated and resolved, and

business and individual requirements for the availability of information and information systems are met

Maintaining Security and Confidentiality

We maintain the security and confidentiality of the information we hold as well as our information systems and applications by:

when handling incoming calls, all staff must ask ‘clients’ two out of three identification questions to confirm the identity of the caller:

each new client will be advised that they will be asked up to three questions that are specific to the personal details of their case when they call Ayres Waters

these questions cannot be information that could easily be known by anybody other than themselves e.g. date of birth

they will generally be questions about the most recent client contact,

this will ensure that no confidential information is shared with a caller affecting to be the client, maintaining client confidentiality

ensuring that all staff are aware of and fully comply with all relevant UK and European legislation and regulatory requirements including, but not limited to:

the General Data Protection Regulation (EU) 2016/679

the Data Protection Act 1998

the Data Protection (Processing of Sensitive Personal Data) Order 2000

The Copyright, Designs and Patents Act 1988

The Computer Misuse Act 1990

Regulation of Investigatory Powers Act 2000

Freedom of Information Act 2000 and,

having a consistent approach to security by ensuring that all staff are aware of the information security policies and procedures applicable in their work area and fully understand their own responsibilities

creating and maintaining within our firm a level of awareness of the need for information security and data management as an integral part of our day-to-day business

having in place up to date contingency and recovery plans

having in place measures to ensure data is secured against loss and unauthorised access

protecting the information assets under our control

Measures to ensure the adequate physical security of our premises that are used to store, process or access our information assets are considered in the Quality Manual (Arriving and Leaving Policy).

Specific measures which we have put in place to ensure the protection and security of all of our information assets include:

ensuring that all equipment is physically protected from threats and environmental hazards

ensuring that only authorised persons who have a justified business need are given access to any restricted area containing information systems or stored data

ensuring access controls are maintained at appropriate levels, and

information will be held only as long as is required, and disposed of in accordance with our Archiving, Retention & Destruction Procedure.

The measures and safeguards we have in place to ensure the integrity of our systems are set out in our Information Security Procedures.

 

Changes and New Systems

Whenever we look to implement significant systematic, hardware, software or procedural changes, we will undertake a Data Protection / Data Security Impact Assessment and will ensure that we consider data protection throughout the design and procurement processes.  Data protection and data security will be at the heart of our decisions and not addressed as an afterthought or subsidiary issue.  We will not make any changes which do not support our overall compliance with the data protection legislation and our ability to comply with it.

Transfer of Data to Third Parties Policy

Other than in the context of normal correspondence or where necessary for attending at Court or conference with counsel etc., confidential or other data is not removed from our offices without the express permission of our DPO.  Where permission is granted, all reasonable steps are taken to ensure that the integrity and the confidentiality of the information are maintained including:

keeping files and information in a secure and locked environment

transporting files and information securely, and

not leaving files or information unattended in places where they are at risk (such as in cars, conference rooms or other public places)

Any external supplier to whom we transfer client or personnel data will likely be a Data Processor (as defined under the relevant data protection legislation).  Fee earners must consult with Andrew Ayres prior to transferring data to any Data Processors (other than counsel and registered medical practitioners who are regulated by their relevant Regulatory Authority), including expert witnesses and other external advisers to whom client or personnel data is transferred.

Prior to the transfer of data to any Data Processors (other than in the case of transfers of data to counsel and registered medical practitioners), Andrew Ayres will conduct a due diligence exercise to determine that the Data Processor:

is registered with the Information Commissioner’s Office (ICO), and

can provide assurances that they have adequate policies and systems in place to protect data and will keep our data confidential and secure

In this regard, he will have regard to any current and future guidance issued by the ICO or other appropriate regulators and/or including the Solicitors Regulation Authority.

Wherever possible, we will require a third-party Data Processor to sign an agreement that we have drafted which commits them to keeping our data secure and confidential.  However, we acknowledge that it will not always be possible to dictate terms or conditions to third parties.

Where we are able to dictate the terms of an agreement with a Data Processor, we will endeavour to include confirmations that the Data Processor will:

ensure that the data transferred to them is kept confidential and is stored and processed securely and in any event in accordance with the requirements of the GDPR

use it for no purpose other than the purpose for which we have provided it to them

return the data to us (and delete copy data) at our request and, in any event, not keep the data for any longer than six years

indemnify us against any loss or damage caused by any breach by them of their obligations under the GDPR and the agreement in respect of their data security and data processing obligations

Any such agreement should ideally set out:

the subject matter and duration of the processing

the nature and purpose of the processing

the type of personal data and categories of data subject, and

the obligations and rights of the controller

They should also, wherever possible, set out that the Data Processor must:

only act on our written instructions (unless required by law to act without such instructions)

ensure that anyone processing the data is subject to a duty of confidence (i.e. that their staff have signed confidentiality agreements)

take appropriate measures to ensure the security of processing

only engage a sub-processor with our prior written consent and a written contract

assist us in providing subject access and allowing data subjects to exercise their rights under the GDPR

assist us in meeting our GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments and must notify us immediately if any breaches occur whilst they are processing the data

delete or return all personal data to us as requested at the end of the contract, and

submit to audits and inspections, provide us with whatever information we need to ensure that we are both meeting our obligations, and tell us immediately if it is asked to do something infringing the GDPR or other data protection law of the EU or a member state

Where the data processor is being instructed on an ad hoc basis and will not accept a written agreement (i.e. where we instruct an expert or other ad hoc data processor), as a minimum, we will verify that the terms or guarantees provided by the Data Processor, such as those provided in their standard terms of business, commit that Data Processor to keeping our data secure and confidential and that data transferred to them will be stored and processed securely and in accordance with the requirements of the GDPR.  In addition, the letter of instruction should set out such of the information as is appropriate and, as an absolute minimum, that accepting the instructions will be taken as acceptance of the following terms:

That they will ensure that the data transferred to them is kept confidential and is stored and processed securely and in any event in accordance with the requirements of the GDPR

That they use it for no purpose other than the purpose for which we have provided it to them

That they return the data to us (and delete copy data) at our request and, in any event, not keep the data for any longer than six years

That they will notify us must notify us immediately if any breaches occur whilst they are processing the data.

Cybercrime and Fraud Prevention Policy

One of our primary objectives is to ensure that we continue to maintain and develop established systems and controls to prevent the firm from being a victim of fraud or cybercrime and to protect us from the associated risks to our business, in particular the risk to data security and confidential information.  [In creating and updating this policy we review guidance issued, from time to time] by the National Cyber Security Centre.]

We also appreciate that the consequences of our being the victim of a cyber-attack could render key IT and operating systems unavailable which could impact on our ability to deliver our services.

It is our policy to ensure an overall sense of awareness of the risks and to provide an environment which will minimise the opportunities for cybercrime and fraud to occur.

Specific technical measures which we have in place to ensure the protection of our systems are set out in our Information Security Procedures.  In addition, the following measures encompass our overall approach to mitigating against the risks of cybercrime and financial fraud.

Assessing the Risks of Fraud

The risks associated with cybercrime and financial fraud are evaluated routinely by us.  Records of the risk assessment for fraud will be contained within our Risk Register, with suggested improvements and a timetable date for review.

Controls

In order to mitigate against the risks of cybercrime and/or financial fraud, we endeavour to maintain effective prevention controls.  In particular, we:

conduct screening and identity checks on new clients and payees including all checks required for the prevention of money laundering and for other regulatory requirements

ensure the integrity of staff through background checks and ongoing monitoring of their work.  In particular, we conduct initial and ongoing checks on those staff members who have financial/accounts roles in our firm or have access or control of IT systems where technical access levels raise fraud risk

ensure effective management and security of our accounts payable and reconciliation activities including management of payees, interaction with our bank and other financial providers and secure use of all technology including online banking and payment facilities

ensure effective management and security of IT systems in accordance with our Information Management and Security Policy to protect against a range of cyber threats

Awareness and Training

We accept that technical measures cannot protect us in isolation as there may be a human element with any instance of financial fraud or cybercrime.

It is our policy to ensure an overall sense of awareness of the issues surrounding cybercrime and fraud prevention and provide specific or update training where it is necessary or recommended.  We also maintain an ongoing awareness programme in order to ensure that fraud prevention and cybercrime awareness is refreshed and updated regularly.  In particular, we:

proactively monitor fraud alerts such as those provided by regulators or local, national or global authoritative bodies

analyse trends in fraud and those which are most applicable to our firm and services

updating staff on any new and relevant information concerning existing or new fraud risks

reminding staff of the monitoring and detection processes and systems which staff members must use

provide specific or update training where it is necessary or recommended for their particular role

enable staff members to attend external training courses or utilise other training resources such as webinars.  Where relevant, training resources will be cascaded to other staff members

provide mechanisms by which staff members may share and discuss fraud prevention measures across the firm and encourage them to make suggestions for improving systems

encourage staff members to raise any issues or voice any concerns

However, it is fundamental that all staff members:

take personal responsibility for their actions

be familiar with the risks and appreciate how to mitigate against those risks, and

take a sensible approach when taking action to mitigate against any risks

 

Clients and Third Parties

We will ensure that our clients and relevant third parties are advised of the need to protect themselves and our firm from cybercrime and fraud.  In our client care information, we make it clear of any practical safeguards we have put in place.  In particular, we inform them of the means by which we verify bank account details in order to protect against fraud.

Communication

As new or different threats and risks associated with fraud and cybercrime emerge and develop over time, we need to ensure that our processes remain effective.

We therefore encourage all staff members to discuss any issues or raise any concerns with Andrew Ayres in order that we can share any ideas or issues with the firm as a whole and take steps to assess the measures we have in place.   He must be notified immediately if it is suspected that we may have been a victim of cybercrime or fraud or there has been a cyber-attack or incidence of financial fraud that may affect us in some way.

In the event of a cyber-attack or incidence of financial fraud, Andrew Ayres will prepare a response plan to identify the procedures and safeguards that need to be put in place on a contingency basis to manage the issue.  We recognise immediate steps may be needed to mitigate the consequences or losses and the response plan will look to identify who will need to be notified and/or whom we may approach for assistance.   When compiling the response plan, we will recognise that we may not be the only victim of the crime and may need to take immediate steps to protect the interest of our clients and relevant third parties.

All incidents of fraud or cybercrime must also reported immediately to our COLP.  He will determine if there are any associated compliance breaches which need to be addressed.

The ‘Fire Drill’ for reporting of breaches will include: informing the IT provider, relevant staff and affected clients.

Payment Management and Control

Only authorised staff members are permitted to access financial data, make payments and/or to process accounts transactions. Authorisation to access financial data and handle our accounts will be restricted to staff members who currently have a legitimate business need or whose jobs require such access.  Access controls will only be granted following a suitable background check on the individual staff member.  Access controls will be removed where the staff member’s role no longer justifies their authorisation.

Any limits on a staff member’s authorisation will be documented in the relevant staff member’s job description. Each authorised staff member will also receive appropriate and bespoke compliance training.

Andrew Ayres, our COFA, is responsible for authorising staff members to have access to financial data and/or to process accounts transactions on behalf of our firm and for maintaining necessary access levels or other controls.

In particular, when handling any transaction, authorised staff members must:

ensure that unauthorised staff members or other personnel including visitors, cannot inadvertently access financial data or other confidential information

process financial transactions through our firm’s approved terminals or equipment, and

process financial transactions in a secure environment where confidentiality can be assured

Furthermore, we have imposed the following security measures to mitigate against fraud events:

those assigned responsibility for handling financial transactions including making and receiving payments must never divulge account credential such as usernames, password or PINS to others

all passwords are maintained securely in accordance with protocols within our Information Security Procedures

fraudsters commonly want to define new payees and make payments to them immediately.  As a means to interrupt a fraudster’s ability to do this, wherever possible, there will be a requirement for a minimum period of one hour separating the definition of a new payee on our payment/accounts system and our making the first payment to them.  On occasions where payments need to be made immediately, then additional checks must be made to verify the payee’s identity

reviews must be conducted regularly with all redundant payee details being immediately removed from all relevant payee/accounts systems

all payee management activities must be verified by separate, authorised, staff members using rigorous authentication methods including necessary identity checks. Refer to our Money Laundering Policy, Anti-Money Laundering and Countering Terrorist Financing Policies as set out in our Quality Manual]

all payment systems are constituted so that one staff member will raise a payment (or payment batch) but a different authorised staff member must release that payment (or payment batch)

all payment reconciliations are performed by an authorised staff member with appropriate skills and experience but who does not have access to any payee management or payment functions

for any staff member whose access controls have been removed or restricted, any accounts or systems which they used for those functions are immediately disabled and/or removed

handling all credit card transactions in accordance with our Credit Card Policy sensitive or confidential financial data will not be stored on a personal computer, laptop, tablet or other removable media or in an email account

storing and destroying financial data in accordance with our Archiving, Retention & Destruction Procedure

Network Devices

All network devices which are part of or connected to our payment systems or are otherwise involved in the transmitting of payments are configured securely.

Steps that we currently take and which are reviewed are set out in our Information Security Procedures.

Banking

We adhere to the terms and conditions of our bank and other relevant institutions or providers to which our firm is bound for the provision of online or other payment services.  We acknowledge the need to bring to the bank or providers’ attention any breaches of these terms by our firm or staff members.

Any requests to access financial or devices used to transmit or store financial data must be approved by Andrew Ayres, our COFAIn particular, he/she must verify the identity of any individual or entity requesting access to data or to any device.   Any enquiries made with or by our bank or other financial provider must be protected both by security checks made by the provider’s staff in addition to an additional security check made by us to validate them.

We ensure that all payment providers, including our bank, independently verifies, prior to authorisation, the creation of all new payees located outside the UK.

[We do not permit the use of Faster Payments as a method of payment via online banking from our Client Account(s).  We have requested that our bank disable or remove this payment method from our online banking service wherever possible.]

Email Policy

This policy outlines the use of emails when carrying out the business of our firm.   The majority of this firm’s communications are undertaken by email but it is also a recognised way in which viruses and malware can enter our IT systems and so extra care must be taken.

 

Personal Use

Ayres Waters is a family-friendly working environment, acknowledging the need for parents and carers to be contactable by their families during working hours (within reason).  Staff members may use their work email for personal use in limited circumstances, such as when messages that could not easily be sent by another means.  Staff members are prohibited from subscribing to third party websites using their work email address or from adding their work email address to contact or orders forms on third party websites where this is not done for reasons related to their work or employment].   Staff members’ use of the firm’s email and domains must be in accordance with our Acceptable Use of IT Facilities Policy.

 

All emails sent by staff members in the conduct of their employment and for the purposes of their employment remain the property of the firm and as such may be accessed, read and monitored by the firm where necessary (i.e. during staff absence or in an emergency or during an investigation).  Any monitoring of emails will be done in accordance with our Acceptable Use of IT Facilities Policy.

Attachments

All staff must be vigilant when receiving attachments on email and all attachments should be viewed with caution.  In particular, we ask staff members to be mindful of our Cybercrime and Fraud Prevention Policy. There is a danger that any attachment could carry viruses that may affect our entire IT system.

All staff are to avoid opening links or attachments in an email that is unexpected. Staff are not to respond to an email or fill out any requests for information on a website unless confident in its authenticity and security.  If a member of staff is unsure about an attachment or they do not know the sender, they should contact Rachel Smith for their consideration and advice.

Where it is required to send a client advice via email, staff members should ensure that the advice is written in a letter that is attached to the email.  Any such letter falls within our normal outgoing post supervision processes and, where appropriate, must be passed to a supervisor before it is sent out to the client.  It is important when sending attachments via email, that the contents of the attachments are secure.  Staff members should ensure that any attachment is in PDF format.  Confidential and sensitive information should not be transmitted by email, unless it is secured through encryption or other secure means.

Recording emails

All incoming or outgoing emails that relate to a client’s case should be saved onto the relevant case file.  Staff members should always ensure that a copy is printed and placed on file and/or attached and referenced to the relevant file in the case management system.

It is the responsibility of each individual member of staff to manage their emails carefully.  Periodically, each member of staff should review their emails and delete any that are no longer required.  All fee earners should be aware that emails relating to clients’ cases are subject to the normal retention period for files, therefore before deleting, copies should be printed and retained with the paper file and/or copies should be attached and referenced to the electronic case management system.

Once an email is saved on the relevant case file the email, a regular review should be made to assess if the email should be deleted from the fee earner’s individual Inbox, ensuring that the only copy is then on the relevant case files.  Ideally, this review procedure should be completed on a monthly basis.

 

Acceptable Use of IT Facilities Policy

All of the firm’s IT facilities and information resources remain the property of the firm and not of any individual staff member.

Personal Use

Staff members must use our firm’s IT facilities in accordance with this policy and our Email Policy.

Staff members may use the firm’s computers, networks or domains for personal use.  Staff members should not use the firm’s computers, networks or domains to create or store personal or non-work-related documents.

No member of staff must attempt to gain unauthorised access to information (including other people’s files or restricted information).  The Computer Misuse Act 1990 makes it a criminal office to obtain unauthorised access to any computer (including workstations and PCs) or to modify its contents.

Internet Access

All staff members have a duty to use the Internet responsibly.  Staff should not at any time access, or seek to access, websites which promote:

 

sexually explicit material

violence

discrimination based on colour, age, marital status, gender, sexual orientation, race, belief, religion, disability, national or ethnic origin, or

illegal activities or violations of intellectual property rights

In addition, staff should not use the internet to:

access streamed or real-time audio, data, graphics, video or any other data which uses large amounts of bandwidth unless to access services directly related to their work, or

download any information that is not directly related to their work

Email & Internet Monitoring

 

We reserve the right to monitor all external and internal communication, user access controls and access to our network and internet where the property of the firm is used by staff members to include where it is accessed remotely from outside the firm.  This includes laptops and mobile devices.

We do not permit the use by staff members of any approved personally-owned devices for work related purposes.    We therefore do not envisage routinely monitoring such devices, but do reserve the right to prevent access from a device to our network or systems and to take steps to retrieve the firm’s data on those devices.

Andrew Ayres and Rachel Smith are responsible for assessing the impact of any monitoring before it is introduced.  Any assessment considers:

the reason for implementing monitoring and whether it is justified

the likely adverse impact on employees and third parties communicating with the firm

the use of alternatives to monitoring or alternative methods of monitoring and

any additional obligations that arise as a result of the monitoring i.e. the secure storage of and access to information gathered by the monitoring

In addition, he/she considers the impact of the monitoring on staff members, such as:

the risk of intrusion into the staff members’ private lives

the extent to which staff members will be aware of the monitoring

the impact monitoring will have on the relationship between staff members and the firm, and

how monitoring will be perceived by staff members

Andrew Ayres and Rachel Smith will inform all members of staff prior to the introduction of any monitoring.  Furthermore, he/she informs individuals if their communications or internet access is specifically being monitored or accessed.  However, an individual is not informed where serious breaches of the policy or criminal activity is suspected and where informing the individual would hamper any investigation or risk the loss of data as evidence.

Andrew Ayres and Rachel Smith are responsible for overseeing all monitoring and for reporting the results to our COLP / our DPO.

Use of Company-Issued and Personally-Owned Devices Policy

The use of company-issued and personally-owned equipment, media or devices to create, handle and/or process the firm’s data creates issues in relation to the maintaining of confidentiality and data security.  It is our policy to ensure so far as is possible that our firm remains in control of the data for which it is responsible irrespective of the ownership of the device used to handle or process that data.

Staff members who make use of company-issued and personally owned equipment, media or devices for purposes related to their work must do so in accordance with this policy and our Acceptable Use of IT Facilities Policy.

Staff members may not use personally owned devices to open or edit a document containing confidential data.

Staff members may not, under any circumstances, copy or transfer data from a company-issued device to another personally owned device.

Staff members must take responsibility for their own company-issued device and how it is used.  In particular, they must:

familiarise themselves with any security features and controls

ensure that the installed anti-virus and malware software is up to date and ensure that it is only sourced through the Play Store or App Store

take responsibility for all software installed on the device

prevent the loss of the device through theft

prevent the loss of data and keep data confidential and secure

prevent the use of any devices by non-authorised persons such as family members by use of biometric touch ID.

maintain the integrity of data

Personal devices must be encrypted.  All default passwords must have been removed and updated in accordance with our Password Protocol and staff must use biometric touch ID.

Staff members should only use personally owned devices to access the firm’s data using the firm’s remote access.

Cloud storage

The use of cloud storage services for storing the firm’s data is permitted only with the prior permission of our DPO.  Only certain cloud storage services will be approved, such as those which maintain a facility for data to be encrypted before it is uploaded.

Use of Wi-Fi

The use of public Wi-Fi networks must be avoided as they may not be secure.  The data plan for company-issued devices is sufficient to avoid use of public/open Wi-Fi networks. If a staff member regularly finds that they reach their data limit, they should inform Rachel Smith, who will consider the need to adjust the data bundle.

Staff members must ensure that home Wi-Fi networks are encrypted.

Loss of device or data

 

Staff members must immediately report the loss of any approved personally-owned device to our DPO, Andrew Ayres and, where necessary, assist with accessing or wiping the device remotely in accordance with our Data Protection Policy.

Destruction of devices

In the event that a company-issued device is no longer needed to be used for work purposes, needs to be upgraded or needs to be disposed of, the device must be handed to our DPO, Andrew Ayres.

The date the phone is returned and the method for data clearance will be recorded by our DPO, Andrew Ayres.

Monitoring of use

The firm may monitor the use of personally-owned devices in accordance with our Acceptable Use of IT Facilities Policy.

 

Credit Card Policy

Ayres Waters is bound by the Payment Card Industry Data Security Standard (PCI DSS) when it accepts debit/credit card payments.

We are committed to ensuring the secure handling and processing of credit card (including debit cards) transactions in compliance with the Payment Card Industry Data Security Standard (PCI DSS).

We acknowledge that we have a duty to protect cardholder data.

Authorisation to handle data

Only approved staff members are permitted to access cardholder data and/or to process card transactions.

Authorisation to access cardholder data and/or handle card transactions will be restricted to staff members who have a legitimate business need or whose jobs require such access.  Any limits on a staff member’s authorisation will be documented in the relevant staff member’s job description.   The staff member will also receive appropriate compliance training.  Each authorised staff member will also be assigned a unique identity reference.

Andrew Ayres, our COFA and DPO, is responsible for authorising staff members to have access to cardholder data and/or to handle card transactions on behalf of our firm and for maintaining necessary access levels or other controls.

Any requests to access cardholder data or devices used to transmit or store cardholder data must be approved by Andrew Ayres, our COFA, COLP and DPO.  In particular, he must verify the identity of any individual or entity claiming to attend for repair or maintenance of any device.

Handling Transactions

Cardholder data must only be entered using our firm’s approved credit card terminal(s).

Transactions may only be made in a secure environment where confidentiality can be assured.  The staff member handling the transaction must ensure that unauthorised staff members or other personnel including visitors, cannot inadvertently access cardholder data or other confidential information.

Credit card information is not accepted by email.

Credit card information is accepted over the telephone once the appropriate client checks have been completed.

Any display or record of cardholder data must be redacted. Only authorised staff members deemed to have a legitimate business need may see the full primary account number.

Protection and destruction of cardholder data

As there is a business need to retain it, cardholder data is not to be destroyed immediately after the transaction is processed.  Data will be redacted, and it will be destroyed as soon as it is no longer required in accordance with our Archiving, Retention & Destruction Procedure.

Andrew Ayres, our COFA and COLP is responsible for:

maintaining an inventory of all media and devices which contain or accept cardholder data

overseeing the storage of information

conducting a quarterly review of all media to identify and securely delete stored cardholder data that exceeds the defined retention period

overseeing its permanent deletion or destruction when it no longer needs to be retained in accordance with our Archiving, Retention & Destruction Procedure

Storage of cardholder data

All cardholder data stored and handled will be securely protected against unauthorised access at all times.

In particular:

the storage of cardholder data will be restricted to that needed for a legitimate business reason

cardholder data will not be stored on a personal computer, laptop, tablet or other removable media or in an email account

only essential cardholder data is stored

the full magnetic stripe data, Personal Identification Number (PIN) or Card Verification Values/Codes (CVV/CVC) will never be stored

PAN data is rendered unreadable before storage

all electronic media containing cardholder data is marked as confidential and encrypted or password protected

hard copy information is stored in a locked filing cabinet

Transportation of cardholder data

All cardholder data is protected securely in all cases where it is transported physically or electronically.

In particular, cardholder data (or media containing cardholder data) is:

never sent by email or otherwise stored in an email account

encrypted before transmission

transported by secure courier services or other secure delivery methods that can be accurately tracked

Any distribution of any media containing cardholder data (whether internally or externally) must be approved in advance and overseen by Andrew Ayres, our COFA, COLP and DPO.

Network Devices

All network devices which are part of or connected to our cardholder data environment or are otherwise involved in the transmitting of cardholder data are configured securely in accordance with the requirements of the PCI DSS.

Additional security measures are set out in our Information Security Procedures.

 

Third Party Service Providers

All third-party service providers providing hosting, transactional or other services which involve the sharing of cardholder data or that could affect the security of cardholder data are properly managed in accordance with the PCI DSS requirements.

The instruction of third party service providers is only be approved if a valid business case for its use is identified.

Andrew Ayres, our COFA, COLP and DPO is responsible for authorising agreements with third party service providers and for evaluating their services.

In particular, he is responsible for overseeing our engagement of third party service providers by the following methods:

conducting due diligence on any potential third-party service provider.  As a minimum:

carrying out background checks on the potential third party service provider.  As a minimum, this will include the carrying out of an assessment of their technical abilities and an assessment of the provider’s own performance standards and monitoring procedures

ensuring that a detailed risk assessment is carried out and ensure that adequate protections or safeguards are put in place to minimise the identified risks

only commissioning the services of external service providers where he is satisfied that they:

take all appropriate steps to ensure that our cardholder data will be secure

undertake to comply with legal and professional obligations in particular, the requirements in the PCI DSS

take all appropriate steps to ensure that their actions do not cause our firm to be in breach of those obligations

have provided sufficient evidence to verify that they adhere fully to the PCI DSS

ensuring any third-party service provider provides an appropriate and proportionate service level agreement including:

a commencement and end date and allow for a periodic review of the arrangements

a documented acknowledgement that they are responsible for the security of the cardholder data they process or otherwise store, process or transmit on our behalf (or to the extent that they could impact on the security of our cardholder data environment)

an ability by our firm to access and/or recall information and documentation from the service provider to be able to validate their compliance

default and termination of the agreement and the extent of liability for each party

maintaining a list of all third-party service providers

 

assessing and evaluating third party service providers’ PCI DSS compliance status at least annually

maintaining information about which PCI DSS requirements are managed by each third-party service provider and which are managed by our firm

 

PROCEDURES

 

Information Security Procedures

Network and Devices

All network devices, whether they are computers, printers, tablets or other pieces of equipment that can connect to and communicate over the internet, are configured securely in accordance with current Information Commissioner’s Office (ICO) and other relevant guidelines.  In particular, OPSIS  will conduct regular reviews of our network and devices to determine if further steps are required to ensure the security of our systems.

Steps that we currently take in partnership with OPSIS and which are reviewed include:

installing, maintaining and updating a firewall configuration to protect financial data

direct public access is prohibited between the internet and any system component

using appropriate encryption software

all vendor-supplied default passwords, encryption keys, access-points and other defaults security parameters are always changed before a system is installed on our network

unnecessary default accounts are removed or disabled before a system is installed on our network

configuration standards are developed for all system components in accordance with industry-accepted hardening standards

maintaining a vulnerability management program to protect our systems against malware including installing and updating anti-virus software

conducting internal and external network vulnerability scans

updating passwords on our router in accordance with our Password Protocol (see below)

ensuring that all of our computers are password protected and that passwords are updated in accordance with our Password Protocol (see below)

ensuring anti-malware is installed on all of our computers, laptops, servers and other electronic media and kept up to date

All staff must ensure their computers and other devices are locked whenever they are not in use.

Destruction

The disposal of any computers or electronic media is overseen by Andrew Ayres to ensure that appropriate destruction methods are used.

Mobile Devices and Removable Media

We appreciate that there are large risks associated with the use of removable media (i.e. any medium which can be removed from the workstation including discs and USB storage devices).  The use of removable media devices is only approved if a valid business case for its use is developed.  Requests for access to, and use of, removable media devices must be made in advance to Andrew Ayres.

Under no circumstances must any document containing client data be opened and / or edited on a personal device not belonging to us if doing so will cause that document to be saved on that device or on a cloud storage system associated with that device (i.e. icloud or one-drive).

 

Mobile devices, wherever possible, are encrypted.  When new IT Equipment including mobile devices are purchased, all default passwords are removed and updated in accordance with our Password Protocol and, wherever available, use biometric touch ID.

If any changes need to be made to existing passwords, these must be discussed with Andrew Ayres and he will oversee the process in accordance with our Password Protocol.

 

Users may only install official app-store (Play Store or App Store) or application signings on their business mobile devices.  Prior to installation, staff members must obtain approval from Andrew Ayres who will check the application before it is loaded.

Should access to, and use of, removable media devices be approved the following must be adhered to at all times:

Staff Members are not permitted to use personal mobile devices to store or access the firm’s data or applications.  Staff Members requiring mobile access to the firm’s data and applications as part of their role will be issued with an authorised mobile device for business use

in all cases where the data/information to be held on the removable media device or laptop could be used to cause any individual damage or distress, in particular where it contains financial or medical information, the data/information must be encrypted before it will be permitted to leave our premises

removable media should not be the only place where data is held.  Copies of any data stored on removable media must also remain on the source system or computer

in order to minimise physical risk, loss, theft or electrical corruption, all removable storage media is stored in an appropriately secure and safe environment

all data copied to any removable media is deleted as soon as possible from that media

each member of staff is responsible for the appropriate use and security of data and for not allowing removable media devices, and the information stored on these devices, to be compromised in any way whist in their care or under their control

Security of Data

 

Backups

All electronic data is securely backed up OPSIS (specialist legal software from Advanced Legal).  Records are maintained by OPSIS of all backup information, including any failures or other issues.

 

Third Parties

Third parties including barristers and clients or agents may not receive confidential data on removable media devices or IT equipment without explicit agreement from Andrew Ayres.  Should third parties be allowed access to data on such devices or systems, then the firm ensures that our Transfer of Data to Third Parties Policy is applied in full to their use, storage and transfer of the data.

Operating Systems

It is our policy that all high-risk or critical security updates for operating systems and firmware such as Patches and security updates are installed within seven days of release.

Applications

All applications are supported and business sensitive applications are chosen with support packages whenever offered.

All high-risk or critical security updates for applications (including any associated files and any plugins) are applied within five days.  We ensure that none of our devices or applications have Flash plugins installed.

Routers and firewalls

Our network is protected by the use of software firewalls which are built into our computer operating system.  We also have a hardware firewall (a router) in operation.  Both are supplied and updated by OPSIS.

We do not use or have enabled any services that are accessible externally from our internet routers or hardware firewall devices. They are also similarly configured so as to prevent access to their configuration settings over the internet.

We have configured our internet routers and hardware firewall devices so that they block all other services from being advertised to the internet.

When all new routers/firewalls are set up, the default password must be removed immediately.  The systems must not be live until such time as Andrew Ayres, our DPO, is satisfied in respect of security.  New Passwords will be set up and managed in accordance with our Password Protocol (see below).

Software

No unlicensed software may be used on our systems.

All software must be authorised by our DPO, Andrew Ayres before being implemented on to any device.  Rachel Smith is responsible for planning and managing all information security risks and for overseeing its installation.  Where necessary an impact assessment will be undertaken in accordance with our Data Protection Policy.

In order to ensure we preserve the security and integrity of our systems and data, Andrew Ayres and Rachel Smith are responsible for:

maintaining a record of all software used by our firm and is used as a means of monitoring and updating all software to ensure that all software is kept up to date, continues to be appropriate for our firm and works efficiently

conducting reviews of all systems in order that any faulty or malicious software may be detected, removed and, if necessary, replaced by an alternative product

ensuring that we have removed or disabled all applications, system utilities, network services and software that are not in use on all IT equipment including mobile devices

ensuring that any applications are removed from our devices where they are no longer supported and no longer receive regular fixes for security problems

ensuring the periodic removal of temporary files, logs and caches

conducting a quarterly review of our software records and updating or removing applications that are redundant and/or no longer required

reporting to the COLP on the implementation of the plan and ensuring that all changes to the plan are communicated to relevant staff members

It is the responsibility of all staff to ensure they use software legally in accordance with relevant licensing and copyright agreements.  Copying software for use outside of these agreements is illegal and may result in criminal charges.

Malware

With the growing threat of viruses and spyware, we aim to ensure that any malicious software on our devices that is connected to the internet is detected as soon as reasonably practicable, quarantined and then removed.

All devices are covered by anti-Malware software. In addition, only applications that come from trusted sources are used.

Should malicious software be found on any device, (for instance, if anti-virus software has identified a potential threat or there is any concern about the operation of the device), staff members should immediately stop using the device and, if possible, close all programmes, ensuring any work is saved.

Andrew Ayres will oversee the quarantine of the malicious software on the device and begin a clean-up exercise and removal of the malicious software.   If this does not result in the complete removal of the malicious software, he will instruct a computer contractor to completely wipe the device and rebuild it, ensuring that there is no trace of any malicious software left on the device.

Access Controls

Individual user accounts are approved by Andrew Ayres.  He has responsibility for authorising new user accounts and for maintaining necessary access levels or other controls over existing accounts.  Access rights will not be provided/amended without the prior authentication and authorisation by Andrew Ayres.

Requests for new accounts or requests by existing users for amendments or adjustments to access rights must be made to Rachel Smith who has responsibility to oversee the implementation of access controls.  She will conduct checks and assess any risks associated with the request and, if relevant, discuss any issues with our COLP.  Only when he is satisfied that all risks have been identified and any necessary control measures implemented will the account be created/modified.

User Accounts

IT equipment and mobile devices only contain necessary user accounts that are regularly used in the course of our business.

User accounts shall only be used by the person (or persons) it was issued to.  Each user is responsible for the appropriate use of their accounts in accordance with our Acceptable Use of IT Facilities Policy.

Each individual user will be provided with personal password in accordance with our Password Protocol, which must be kept confidential.  Access to systems is restricted and will be set by management according to the staff members’ role within the firm.  An employee must not access other users’ accounts.

Any limits on access will be confirmed to the user prior to authorisation.

Andrew Ayres monitors the use of user accounts in accordance with our Acceptable Use of IT Facilities Policy.

Managing Leavers

Staff members’ user rights will cease and access to all systems will be revoked upon termination of an employee’s employment contract.  Where an employee leaves the firm, access rights are immediately revoked in accordance with our End of Employment Procedures.

Administrator Access

To ensure data minimisation and security accounts, application and file access is restricted so as to be relevant to the staff members’ role in Ayres Waters Family Lawyers.

Each device, wherever possible, will have a single administrator account and the user account.  Administrator accounts will only be assigned to a manager or director where there is a business need and user accounts will be assigned to the employee.  Any deviation from this default position will only be considered where there is valid business case and must be approved by Andrew Ayres.

Only our DPO/COLP is permitted to make software and configuration changes.

Unless there is reasonable cause, an administrator must not access email or web browsing of user accounts.  In general terms, only patches, updates and other system performance tasks are carried out by the administrator.  Default browsers are installed but are not used.

We ensure all usage is logged through the Administration Log File as part of our GDPR compliance.

Andrew Ayres reviews access and user rights at least annually.

 

Password Protocol

 

Setting of Passwords

Andrew Ayres is responsible for setting up all new user accounts and passwords.  All requests for new passwords must be directed to him.

Authorisation for the setting of new passwords and the maintaining of records is overseen by Andrew Ayres.  On a day-to-day basis, responsibility has been passed to our Rachel Smith to assist with the administration of any change/update and to oversee the implementation.

Staff members must keep any passwords confidential and shall not disclose them to colleagues without the express permission of Andrew Ayres.

All passwords are reviewed and updated routinely in accordance with the following protocol:

 

each individual is provided with their own unique secure password with restricted area access dependent on role.  Access to the system is strictly controlled and updates are managed by the provider

staff members will be provided with personal passwords for each device or application including Microsoft Outlook and OPSIS

each individual user is provided with a personal password which must be kept confidential.  In the event that a password needs to be changed or if there are problems with gaining access to an account, then individuals will report the issue to Andrew Ayres who will liaise with the software provider to administer the change of password

Passwords for Online banking and other financial payment systems are maintained by Andrew Ayres, our DPO / COFA

Passwords for mobile telephones and internet/telephone passwords for dealing with the mobile operators are retained securely by our COLP, Andrew Ayres, and Rachel Smith

All passwords will be strong passwords.  Wherever available, we will make use of biometric touch ID.

Records of all passwords are maintained confidentially by our COLP Andrew Ayres, supported by Rachel Smith.

Once a password has been generated, Andrew Ayres will ensure it is entered onto our secure log and then shared with the individual.

In the event that a password needs to be changed or if there are problems with gaining access to an account, then individuals must report the issue to Andrew Ayres.

Password renewals

Records of all passwords are maintained confidentially by Andrew Ayres.

If any member of staff has concerns that a password may have been compromised, they must notify Andrew Ayres immediately.  Where he is unavailable, the staff member should approach either Rachel Smith, Clare Sorrell or Paul Waters.

If any changes need to be made to existing passwords, these must be discussed with Andrew Ayres and he will oversee the process in accordance with our Password Protocol.

Archiving, Retention & Destruction Procedure

The following procedures set out how long information will normally be held by us and when that information will be confidentially destroyed.

Retention Periods

The storage of data will be restricted to that needed for a legitimate business reason.

Unless expressly stipulated otherwise by our COLP/DPO Andrew Ayres, records will ordinarily be kept for at least the following periods:

Client Information
Information Retention Period
Client Case Files 6 years after the last activity on the file (typically payment of bill, closure and archive). If the firm has acted for a person under 18, the file should be kept for 6 years after the client has turned 18.
Client Enquiry Forms 18 months (unless a full client file was opened in which case in line with that file)
Client Complaints 6 years (with client file)
Staff Information
Information Retention Period
Application forms/interview notes for unsuccessful candidates 12 months
Offer letters and acceptance Permanently
Disciplinary, working time and training 6 years after employment ceases
Redundancy details 6 years from date of redundancy
Documents proving the right to work in the UK Two years after employment ceases
Health and safety consultations Permanently
Information on senior executives Permanently for historical purposes
PAYE Records 4 years
Workplace accidents 3 years after date of last entry. There are specific rules on recording incidents involving hazardous substances
Payroll 3 years after the end of the tax year they relate to
Statutory maternity, adoption and paternity pay 3 years after the end of the tax year they relate to
Statutory sick pay 3 years after the end of the tax year they relate to
Working time arrangements 2 years from date on which they were made
Corporate Information
Information Retention Period
Meeting Agendas, Reports and Minutes Permanently for historical purposes
Constitutional documents, Resolutions and Special Resolutions Permanently
Business/Strategic Plans 3 years
Financial Information
Information Retention Period
Books of account, reconciliations, bills, bank statements and passbooks 6 years
Paid cheques, digital images of paid cheques and other authorities for the withdrawal of money from a client account 2 years
Other vouchers and internal expenditure authorisation documents relating directly to entries to the client account books 2 years
Cardholder data Unless there is a business need to retain it, cardholder data should be destroyed immediately after the transaction is processed. If cardholder data needs to be retained then it must be destroyed as soon as it is no longer required

If a staff member believes there is a genuine business need to retain data for longer than the above retention periods, this must be referred to Andrew Ayres, our COLP/DPO.  He is responsible for:

maintaining an inventory of all media and devices which contain data

overseeing the storage of data

conducting a quarterly review of all media to identify stored data that exceeds the defined retention period

Storage and Archiving

Hard copy and electronically held data must be securely stored and/or archived in a managed way which facilitates effective access and control and enables destruction at the appropriate time.

All data stored will be securely protected against unauthorised access at all times.  In particular:

only essential financial data is stored and in accordance with our Cybercrime and Fraud Prevention Policy

cardholder data is stored in accordance with our Credit Card Policy

The following steps are to be followed when preparing records for archival.

Documents are sorted in order that the retention periods are easily identifiable and not mixed within archive boxes

Documents are stored in archive boxes and are not over-filled

The archive boxes are labelled with a reference, brief description of the contents, archiving date and destructions date(s) and make clear whether access to the box should be restricted to particular staff members

Where the box contains confidential or personal data, this will be marked clearly on the box

Document Destruction

Andrew Ayres is responsible for overseeing the destruction of any documents and for maintaining the records of all such documents for future audit purposes.

All data, whether in electronic or hard copy format, must be deleted at the end of the retention period in accordance with this procedure.

When records are identified for destruction at the end of the retention period, Andrew Ayres will oversee the destruction process:

All information will be reviewed by Andrew Ayres before destruction to determine if there are special factors (such as any potential litigation, complaints or ongoing cases) which mean that destruction should be delayed

With due regard for client confidentiality, hard copy and electronically held documents and information are passed to Andrew Ayres to oversee their permanent deletion or destruction

All data is destroyed by secure means.  Ayres Waters use SAICA Natur whose methodology is governed by the United Kingdom Security Asociation (UKSSA).  See www.b2b.naturuk.saica.com for their privacy policy.

There are no personal shredders on the premises

a register (and reference) of the records is kept by Andrew Ayres of all data and documents and the method of destruction for future audit purposes

End of Employment Procedure

We recognise the contribution and commitment of our staff. We are fully committed to the provision of a good working environment for all of our employees. However, it is acknowledged that for a variety of reasons, people will leave, some after a relatively short time and others after many years of employment.

These procedures have been developed to ensure the process of leaving is smooth and without issue and applies to staff who leave employment, regardless of length of service and their reason for leaving.  They not only provide a channel for gathering information but also the means by which we record an employee’s reasons for leaving, including perceptions of workplace issues.  This procedure aims to help ensure that any key knowledge is retained within the firm and that the employee leaves on positive terms and that any improvements that could be implemented can be identified.

Handover

The member of staff leaving is asked to draft detailed handover notes in relation to all existing clients, open matters and any other issues (where appropriate).  This is discussed in detail with the supervisor.

Leavers Meeting

A Leavers Meeting will be with the member of staff during the last week of their employment.

The immediate line manager is responsible for carrying out the meeting, unless the employee specifically requests (in view of their reasons for leaving) or it is considered more appropriate that another Partner conducts the meeting.  The person who conducts the meeting will be responsible for taking a detailed record and, whom in accordance with our Equality & Diversity Policy as set out in our Quality Manual, may discuss any of the points with the other Partner.

The primary purpose of the interview is to ascertain where the practice has excelled and where we may be able to improve as an employer.  Employees will have the opportunity at the meeting to provide honest feedback on their perceptions about working for the firm and their reasons for leaving.

Leaving Day

On the final day of their employment, the employee will be asked to return all property belonging to the firm.  This will include electronic equipment, documents belonging to the firm, keys/security passes etc.

It is the responsibility of the Partner who has conducted the Leavers Meeting to ensure that all relevant property is returned.

Furthermore, he will liaise with Andrew Ayres to ensure that the employee’s user access to computers and/or other equipment ceases that day and/or that any relevant passwords which the employee used or had knowledge of are changed in accordance with our Information Security Procedures.