COVENT GARDEN MARKET AUTHORITY

Data Protection Notification for data subject category "employee"

Notification drafted on May 21, 2018

Our name/contact details are Covent Garden Market Authority, Food Exchange, New Covent Garden Market, London, SW8 5EL

This process engages the following data categories:

Our 18 processes engage 51 data categories: address; contact information; first name; last name; postcode; telephone; email address; name; telephone number; contact; employment; birthdate; date of birth; signature; time in-out; mixed data; private information; religion; salary; sexual orientation; cv; ethnic origin; ni number; referee name; medical history; staff disqualification data; references; car registration and description; emergency contact details; disciplinary record; performance review; photograph; bank details; DBS held and date; driving licence details; medical emergency details; passport details; pension contributions; training records; social security number; app; banking; browser details; business contact; cookies; description; device fingerprint; location; personal activity; tracking; and financial summary.

We process your data in 18 different ways

Process: Entry Permit Records

Dataset Process Legal Basis Purposes
Entry Permits Entry Permit Records Legitimate interest recording entry permit contact details.

Non-aggregated information specific to process "Entry Permit Records"

This process engages the following data categories:

Our process engages 11 data categories: address; contact information; first name; last name; postcode; telephone; email address; name; telephone number; contact; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

Yourself

Yourself

Process: Health and Safety

Dataset Process Legal Basis Purposes
HSE Health and Safety Legal obligation details sent if investigation to be carried out.

Non-aggregated information specific to process "Health and Safety"

This process engages the following data categories:

Our process engages 13 data categories: address; birthdate; contact information; email address; first name; last name; name; postcode; telephone; date of birth; telephone number; contact; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

Yourself

Yourself

insurers

Process: Insurance

Dataset Process Legal Basis Purposes
Zurich Insurance Legal obligation details sent if investigation to be carried out.

Non-aggregated information specific to process "Insurance"

This process engages the following data categories:

Our process engages 13 data categories: address; birthdate; contact information; email address; first name; last name; name; postcode; telephone; date of birth; telephone number; contact; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

Yourself

Yourself

insurers

Process: RIDDOR

Dataset Process Legal Basis Purposes
HSE RIDDOR Legal obligation details provided should an incident be severe enough to have to submit riddor.

Non-aggregated information specific to process "RIDDOR"

This process engages the following data categories:

Our process engages 13 data categories: address; birthdate; contact information; email address; first name; last name; name; postcode; telephone; date of birth; telephone number; contact; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

Yourself

Yourself

insurers

Process: Sign in/out book

Dataset Process Legal Basis Purposes
Key signing in/out Sign in/out book Legal obligation signing in/out book.

Non-aggregated information specific to process "Sign in/out book"

This process engages the following data categories:

Our process engages 5 data categories: name; signature; telephone number; time in-out; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

Yourself

Yourself

Process: Key sign in/out book

Dataset Process Legal Basis Purposes
Key signing in/out Key sign in/out book Legitimate interest signing in/out book.

Non-aggregated information specific to process "Key sign in/out book"

This process engages the following data categories:

Our process engages 11 data categories: address; contact information; first name; last name; postcode; telephone; email address; name; telephone number; contact; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

Yourself

Yourself

Process: Teamseer-Teamseer

Dataset Process Legal Basis Purposes
UNSPECIFIED Teamseer-Teamseer Legitimate interest keep holiday and sick records.

Non-aggregated information specific to process "Teamseer-Teamseer"

This process engages the following data categories:

Our process engages 3 data categories: mixed data; private information; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

Unlimited

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: HR-QCG

Dataset Process Legal Basis Purposes
Applicant, Offer, Starter HR-QCG Legitimate interest annual reviews and disciplinary.

Non-aggregated information specific to process "HR-QCG"

This process engages the following data categories:

Our process engages 13 data categories: religion; salary; sexual orientation; cv; ethnic origin; ni number; referee name; medical history; staff disqualification data; references; car registration and description; emergency contact details; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data source is applicant [not particularised].

Categories of Recipients of your data

applicant

Process: Employ Staff-Clerical Medical, Scottish Widows

Dataset Process Legal Basis Purposes
Staff Performance Employ Staff-Clerical Medical, Scottish Widows Legitimate interest annual reviews and discipllnary.

Non-aggregated information specific to process "Employ Staff-Clerical Medical, Scottish Widows"

This process engages the following data categories:

Our process engages 3 data categories: disciplinary record; performance review; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data sources are: yourself [not particularised]; and applicant [not particularised].

Categories of Recipients of your data

applicant

Process: Staff Records-Moorepay

Dataset Process Legal Basis Purposes
Staff Admin Staff Records-Moorepay Legal obligation maintain staff details.

Non-aggregated information specific to process "Staff Records-Moorepay"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; applicant [not particularised]; and hmrc [not particularised].

Categories of Recipients of your data

hmrc

applicant

Process: Medical Records-Dr Cooper

Dataset Process Legal Basis Purposes
Staff Admin Medical Records-Dr Cooper Legal obligation maintain details of medication; and allergies and conditions.

Non-aggregated information specific to process "Medical Records-Dr Cooper"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

Unlimited

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; applicant [not particularised]; and hmrc [not particularised].

Categories of Recipients of your data

Yourself

Yourself

applicant

Process: HR

Dataset Process Legal Basis Purposes
UNSPECIFIED HR Legal obligation maintain staff details.

Non-aggregated information specific to process "HR"

This process engages the following data categories:

Our process engages 4 data categories: address; social security number; telephone; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

Unlimited

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: Pension Admin-Scottish Widows

Dataset Process Legal Basis Purposes
Staff - Admin Pension Admin-Scottish Widows Legitimate interest maintain staff details.

Non-aggregated information specific to process "Pension Admin-Scottish Widows"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: Administrator-BBVA No.2

Dataset Process Legal Basis Purposes
Staff - Admin Administrator-BBVA No.2 Legal obligation maintain record of payment.

Non-aggregated information specific to process "Administrator-BBVA No.2"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: Administrator-BBVA No.4

Dataset Process Legal Basis Purposes
Staff - Admin Administrator-BBVA No.4 Legal obligation maintain record of payment.

Non-aggregated information specific to process "Administrator-BBVA No.4"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: Administrator-Canada Life

Dataset Process Legal Basis Purposes
Staff - Admin Administrator-Canada Life Legal obligation maintain record of payment.

Non-aggregated information specific to process "Administrator-Canada Life"

This process engages the following data categories:

Our process engages 16 data categories: address; email address; name; photograph; salary; bank details; date of birth; DBS held and date; driving licence details; emergency contact details; medical emergency details; ni number; passport details; pension contributions; training records; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for 2,557 days.

Legal Bases for Processing

Our processing legal basis is legal obligation

Sources from which we receive your data

Our data source is yourself [not particularised].

Categories of Recipients of your data

applicant

Process: Mass email

Dataset Process Legal Basis Purposes
Employee, Tenant, Customer, External stakeholder Mass email Legitimate interest inform.

Non-aggregated information specific to process "Mass email"

This process engages the following data categories:

Our process engages 17 data categories: address; app; banking; browser details; business contact; cookies; description; device fingerprint; email address; location; name; personal activity; telephone; tracking; financial summary; telephone number; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

Unlimited

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data source is [unspecified source category code] [not particularised].

Categories of Recipients of your data

[none]

Process: SMS

Dataset Process Legal Basis Purposes
Employee, Tenant, Customer SMS Legitimate interest inform.

Non-aggregated information specific to process "SMS"

This process engages the following data categories:

Our process engages 17 data categories: address; app; banking; browser details; business contact; cookies; description; device fingerprint; email address; location; name; personal activity; telephone; tracking; financial summary; telephone number; and employment.

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

Unlimited

Legal Bases for Processing

Our processing legal basis is legitimate interest

Sources from which we receive your data

Our data source is [unspecified source category code] [not particularised].

Categories of Recipients of your data

[none]

Storage

We store your data in United Kingdom (UK).

Data Retention Criteria

We retain your data for periods varying from 0.0 to 2,557 days (click on the table's individual processes for details).

Legal Bases for Processing

Our processing legal bases are: legitimate interest, legal obligation

Sources from which we receive your data

Our data sources are: yourself [not particularised]; [unspecified source category code] [not particularised]; applicant [not particularised]; and hmrc [not particularised].

Categories of Recipients of your data

Yourself

Yourself

insurers

hmrc

applicant

Your Rights

You have qualified rights to access, rectify, and erase your personal data; and to restrict or object to processing; and to make your data portable.

Supervisory Authority

You have the right to complain to a Supervisory Authority.
Export this notification content as .doc