diff --git a/.gitignore b/.gitignore index c264253..3362802 100644 --- a/.gitignore +++ b/.gitignore @@ -114,14 +114,10 @@ npm-debug.log* /front_end/webpack_bundles webpack-stats.json +# SSL +/ssl/certificate.crt +/ssl/private_key.key +-out + # Other .DS_Store -/key.pem -!/-out - -!/cert.crt - -!/cert.key - -!/cert.pem -!/db.sqlite3 diff --git a/app/core/templates/privacy_notice.html b/app/core/templates/privacy_notice.html index d94e66e..4ee643f 100644 --- a/app/core/templates/privacy_notice.html +++ b/app/core/templates/privacy_notice.html @@ -13,136 +13,116 @@
This privacy notice explains how the Department for Business and Trade (DBT), as a 'data controller', - processes personal data for the 'Check when large businesses pay their suppliers' service on GOV.UK. +
This privacy notice explains how the Department for Business and Trade (DBT), as a 'data controller', processes personal data for the 'Find business regulations and guidance' service on GOV.UK.
-This notice is supplemented by our main privacy notice which provides further information on how DBT +
This notice is supplemented by our main privacy notice which provides further information on how DBT processes personal data, and sets out your rights in respect of that personal data.
-DBT collects information about:
+We collect:
DBT collects the following categories of personal data:
-DBT collects this information to meet its obligations under 'The Reporting on Payment Practices and - Performance Regulations 2017', which requires qualifying UK businesses to report on their payment - practices. -
-The 'Check when large businesses pay their suppliers' service is provided by DBT to enable this - reporting to take place. Personal data is collected through this service to:
-This personal data must be provided by all qualifying businesses to meet their legal obligations - under the regulations.
+Our cookies policy explains what cookies we collect, why we collect these and how long these remain on your device.
+ +The legal bases for processing your personal data (Article 6(1) UK General Data Protection Regulation - (GDPR)) are that:
+We use this information to:
In some instances, we may process your data further for a compatible purpose and/or on other legal - bases. For example, your data may be used for archiving, research and/or statistical purposes. These - are compatible purposes for further processing in UK GDPR and your data will be subject to - appropriate safeguards if used for such purposes.
-Once received:
+You are providing consent for DBT to use your data. The legal basis for collecting this data is that it is necessary:
We use the following third-party processors to operate the service:
+We use the following third-party processors to operate the service:
In addition to the open publishing of company director names, we may share personal data you provide: -
+We will not:
You can find out more detailed information about how we share data and further processing in the main privacy - notice. -
-DBT will only retain your personal data for as long as necessary to fulfil the purposes we collected - it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. -
-Names of company directors will be retained indefinitely.
-Email addresses of individuals who file reports will be retained for 10 years.
-If we decide that we need to process your personal data for a reason which is incompatible with the - purposes for which we collected it for, we will contact you to explain why we are doing this and why - it is lawful to do so.
-To determine the appropriate retention period for personal data, we consider the amount, nature, and - sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of - your personal data, the purposes for which we process your personal data and whether we can achieve - those purposes through other means, and the applicable legal requirements.
+We will also share your data if we are required to do so by law or regulation - for example, by court order, or to prevent fraud or other crime.
+ +We will only retain your personal data for as long as it is needed for the purposes set out in this document or for as long as the law requires us to.
+We will:
+You have a number of rights available to you under UK data protection legislation, including:
+You have the right to request:
+You can also:
You can contact DBT's Data Protection Officer for further information about how your data has been + +
You can contact DBT's Data Protection Officer for further information about how your data has been processed by the department or to make a complaint about how your data has been used. Please contact: data.protection@businessandtrade.gov.uk
-You can also submit a complaint to the Information Commissioner's Office (ICO) at:
-Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
-
Website: https://ico.org.uk/
-Telephone: 0303 123 1113
-You can find out more about your rights as a data subject, and details of how to contact our Data - Protection Officer and the ICO in our main privacy notice.
+ +DBT's Data Protection Officer (DPO) is responsible for independent advice and monitoring of DBT's use of personal information.
+Contact the DPO with any concerns about how DBT handles your personal information.
+ +Data Protection Officer
+Department for Business and Trade
+Old Admiralty Building
+Whitehall
+LONDON
+SW1A 2DY
+Email: data.protection@businessandtrade.gov.uk
+ +Contact the Information Commissioner for independent advice about data protection, privacy and data-sharing issues. + +
Information Commissioner's Office
+Wycliffe House
+Water Lane
+Wilmslow
+Cheshire
+SK9 5AF
+ +Website: Information Commissioner's Office (ICO)
+Telephone: 0303 123 1113
+You can find out more about your rights as a data subject, and details of how to contact our Data Protection Officer and the ICO in our main privacy notice
+