Health and Safety Privacy Notice
Introduction
Revell Research Systems Limited
(the Company) is providing you with this information in order to comply with
the
Data Protection Act 2018
and the General Data Protection Regulation 2016
(GDPR), which require us to tell you
what we do
with your personal information.
This notice relates to the personal data that is processed by us in recording health
and safety accidents, incidents and near-miss events as well as managing our overall
health and safety processes. This personal data may relate to members of the public,
client or supplier personnel and anyone working for or on our behalf.
Some of this data may be classified as sensitive.
Who is collecting this personal data?
Revell Research Systems Limited
is collecting this data as the Data Controller.
Revell Research Systems Limited is a private limited company registered in
England and Wales as number 06939580.
Its registered office is at
5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom.
You should send regular correspondence to our principal office at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
You can also contact us on (01392) 259797
or by email via
office@rrs.co.uk.
Revell Research Systems Limited
is registered with the Information Commissioner
in the
United Kingdom as a data controller under number Z186392X.
Who are we sharing your Personal Data with?
It may be necessary to share your personal data processed under this notice with
the following third parties:-
-
The courts and those involved in legal proceedings and non-contentious matters,
including solicitors and barristers
- Police and law enforcement agencies
- Our subsidiaries, our ultimate holding company and all its subsidiaries
- Health and Safety Executive
- Public Health Agencies
- Medical practitioners
- Agents acting on our behalf
- Service providers (including associates)
- Our insurance broker and insurers
- Our professional advisors
We will not sell or rent your data to third parties. We will not share it with third
parties for marketing purposes.
Why are we collecting and what will we do with Your Personal Data?
We are collecting this information to assist us in complying with legislation and
best practice.
We have a legal duty to document workplace incidents and accidents as well as to
report certain types of accident, injury and dangerous event to the relevant enforcing
authority. For instance, we are legally obliged to report RIDDOR accidents to the
Health and Safety Executive. These legal obligations necessitate the collection
of personal data (some of which maybe classified as sensitive).
As part of this legal duty, we record health and safety accidents, incidents and
near-miss events that happen on our premises or to our staff and associates while
they are working for us wherever they may be at the time. These records may include
information about our own personnel, client or supplier staff, relevant managers
in affected organisations, members of the public involved in an accident
and the details of witnesses.
We also collect personal data from various parties when conducting risk assessments
in order to ensure, so far as is reasonably practicable, the health, safety and
well-being of those affected by the Company's activities.
Additionally, we collect personal data from those working for us to support their
well-being and to facilitate appropriate health and safety training and supervision.
We may also report incidents of violent behaviour towards our personnel to the police
or other law enforcement agencies. We may share person data in co-operating with
the police or law enforcement agencies.
We may also occasionally use your personal information where we need to protect
your vital interests (or someone else's vital interests).
We may also need to collect personal data and to share it with public health agencies
either by legal obligation or in protecting your or another's vital interests.
We investigate incidents and accidents to establish what lessons can be learned
to prevent such incidents or accidents re-occurring including the introduction of
additional safeguards, procedures, information, instruction and training, or any
combination of these.
We may process this data for the purpose of the proper administration of our business
and in communicating with you as well as maintaining backups.
We also retain information in the event of any claims for damages and may pass details
to our insurers. We may also use the personal data we collect to establish, exercise
or defend possible legal claims.
What is the legal basis for processing?
Our lawful purposes are Legal Obligation, Vital Interests and Legitimate Interest.
-
legal obligation - the Company has an obligation under law to maintain proper health
and safety records and may be required from time-to-time to share personal data
to comply with health and safety legislation.
-
vital interests - the Company may process personal data in your or another's vital
interests in an emergency.
-
legitimate interest - the Company has a legitimate interest in maintaining the health,
safety and well-being of those who work for or interact with us; in investigating
incidents and accidents to minimise future risk; in improving our health and safety
systems; in establishing, exercising or defending legal claims; and in properly
administering its business and backing up data.
These lawful purposes are detailed in Article 6 of the General Data Protection Regulation
(GDPR):-
-
processing is necessary for compliance with a legal obligation to which the controller
is subject (Article 6(1)(c)).
-
processing is necessary in order to protect the vital interests of the data subject
or of another natural person (Article 6(1)(d)).
-
processing is necessary for the purposes of the legitimate interests pursued by
the controller or by a third party, except where such interests are overridden by
the interests or fundamental rights and freedoms of the data subject which require
protection of personal data, in particular where the data subject is a child
(Article 6(1)(f)).
We process sensitive personal data (GDPR
Article 9(1)) under the regulation because:-
-
processing is necessary to protect the vital interests of the data subject or of
another natural person where the data subject is physically or legally incapable
of giving consent (Article 9(2)(c)).
-
processing is necessary for the establishment, exercise or defence of legal claims
or whenever courts are acting in their judicial capacity (Article 9(2)(f)).
-
processing is necessary for the purposes of preventive or occupational medicine,
for the assessment of the working capacity of the employee, medical diagnosis, the
provision of health or social care or treatment or the management of health or social
care systems and services on the basis of Union or Member State law or pursuant
to contract with a health professional and subject to the conditions and safeguards
referred to in paragraph 3 (Article 9(2)(h)).
The Company is subject to a range of Health and Safety legislation in the United
Kingdom, including:-
- Health and Safety at Work (etc) Act 1974
- Management of Health and Safety at Work Regulations 1999
- The Control of Substances Hazardous to Health Regulations 2002
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013
- Regulatory Reform (Fire Safety) Order 2005
- Health And Safety (Display Screen Equipment) Regulations 1992 (as amended)
How are we collecting this information?
We collect personal data from data subjects when we record health and safety accidents,
incidents or near-miss events. We also collect personal data when we are carrying
out health and safety risk assessments and when we are assessing our health and
safety training needs or in providing well-being support to our staff.
The Company may collect personal information in a variety of ways such as:-
- Via email
- Via telephone
- Through personal communication with our personnel
- Accident or incident reports
- Witness statements
What information are we collecting?
We collect the following personal information when recording accidents, incidents
or near-miss events:-
- your name
- job title
- organisation
- date of birth
- gender
- address and other contact details
- details of any injuries (where applicable)
These details may relate to any injured parties, witnesses, first aiders or any
of our personnel involved as well as managers and others perceived to have a legitimate
interest in the accident, incident or near-miss event, who may not have been present
at the time. We may also collect video, audio and photographic evidence.
We will record the time, date and location as well as any other pertinent information
about the accident, incident or near-miss event.
We collect the following personal information when conducting risk assessments:-
- your name
- job title
- organisation
- date of birth
- gender
- address and other contact details
We may also include information about medical conditions that are pertinent to the
risk and details of your medical practitioners.
We record any health and safety training provided to staff and associates and keep
records of health and safety consultations and meetings.
We may also collect basic contact details of visitors to our premises or events
in connection with public health issues, which we will pass to the relevant public
health agencies, when requested.
Who can see your information within the Company?
Only authorised directors, staff and associates may access your data.
How long is your information kept?
We will only keep your information for as long as necessary. The retention period
is either dictated by law or our legitimate requirements. Once your information
is no longer needed it will be securely and confidentially destroyed.
We retain accident books, records and reports for forty years along with general
health and safety records. We permanently keep risk assessments and records of consultations
with safety representatives and committees. We keep staff medical records for six
years after departure in most cases, although in some very special cases (relating
to asbestos and radiation) the law requires us to keep certain medical records considerably
longer.
We typically retain personal data relating to financial transactions with the
Company for six years after the financial year in which they occurred based on the
Limitation Act 1980.
How secure is your information?
We take stringent steps to keep your information secure. You can read more about
our approach to security at www.rrs.co.uk/security.
Who keeps your information updated?
You are responsible for keeping your personal details up-to-date. Please advise
the Company of any changes.
Will your information be used for any automated decision making?
No.
Our Privacy Statement
You can access the Company's Privacy Statement at
www.rrs.co.uk/privacy.
This statement provides you with more information about how we address data protection
and privacy as well as informing you of your rights.
Other Privacy Notices
You are likely to interact with us in more than one way, so our other privacy notices
may apply to you in different scenarios. We are open and transparent about how we
use your personal data. You can find all of our Privacy Notices
at www.rrs.co.uk/privacy.
Changes to this Notice
We may change this privacy notice at any time. Any changes to this privacy notice
will apply to you and your data immediately. If these changes affect how your personal
data is processed, the Company will take reasonable steps to make sure you know.
Further Information
If you have any queries about this notice then please do not hesitate to contact
us by telephone on (01392) 259797
or via email to
office@rrs.co.uk.
You can write to us at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
Version 0.0; 1st September 2020