PILGRIM’S PRIDE LTD DATA PROTECTION COMPLIANCE POLICY Appendix 1 Compliance Guidelines on Protection of Personal Data
Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 1 of 7
Contents 1
INTRODUCTION ................................................................................................. 3
2
GUIDELINES ....................................................................................................... 3 2.1
GENERAL GUIDELINES ............................................................................... 4
2.2
GUIDELINE RE PROCESSING OF HR DATA .............................................. 5
2.3 GUIDELINE RE PROCESSING OF PERSONAL DATA FOR MARKETING PURPOSES ............................................................................................................ 5 2.4 GUIDELINE RE PROCESSING OF PERSONAL DATA ON OWNERS AND FARMERS .............................................................................................................. 5 2.5
GUIDELINE RE RIGHTS OF THE DATA SUBJECT ..................................... 6
2.6 GUIDELINE RE TRANSFER OF PERSONAL DATA TO THIRD PARTY COMPANIES .......................................................................................................... 6 2.7 GUIDELINE RE NEW SYSTEMS, APPLICATIONS OR METHODS FOR PROCESSING OF PERSONAL DATA ................................................................... 6 3
REPORTING REQUIREMENTS .......................................................................... 6
4
POINTS OF CONTACT ....................................................................................... 7
Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 2 of 7
1 INTRODUCTION In order to ensure compliance with data protection legislation a number of practical Data Protection Compliance Guidelines (the “Guidelines”) have been developed. The Guidelines are an integral part of the Pilgrim’s Pride Ltd Data Protection Compliance Policy and apply to all employees. In addition, training on the Guidelines is also given to all relevant employees as part of our compliance programme. The Guidelines are set out in section 2 below in the form of “dos and don’ts”, providing guidance on how to ensure data protection compliance in some practically relevant and important situations. The Guidelines are to be adhered to by all employees processing personal data as a part of their daily jobs. Personal data means any information which can be related to an identified or identifiable physical person (“Data Subject”). Personal data is divided into two overall groups: sensitive personal data and ordinary personal data. Sensitive personal data is information revealing racial or ethnic origin, political opinions, religious, philosophical beliefs or trade union membership. It is also genetic data, biometric data (if the purpose is uniquely identifying the Data Subject) and data concerning health, sex life or sexual orientation. Social security number and information on criminal records are confidential data and must be treated as sensitive personal data. The above-mentioned information is an exhaustive list of sensitive personal data. Any other type of personal data is by default defined as ordinary personal data. Ordinary personal data is information not mentioned in the above exhaustive definition of sensitive personal data e.g. name, address, performance measures and electronic trails. Processing of personal data is basically everything you can do with personal data, both automated, processing and manual handling, such as collection, structuring, storing, disclosure, making available, erasure and destruction. Section 3 sets out certain reporting requirements to be adhered to in the event of a suspected violation of the Guidelines and/or certain types of behaviour that require careful legal monitoring.
2 GUIDELINES The Guidelines aim to ensure that we comply with the data protection legislation in force.
Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 3 of 7
The Guidelines do not provide exhaustive advice or substitute the need for detailed guidance on the subject matters. The Guidelines contains the following sections: A. General Guidelines B. Guideline re processing of HR data C. Guideline re processing of personal data for marketing purposes D. Guideline re processing of personal data on owners/farmers E. Guideline re rights of the Data Subject F. Guideline re transfer of personal data to third party companies G. Guideline re new systems, applications or methods for processing of personal data 2.1
GENERAL GUIDELINES
• DON’T process sensitive personal data without the prior approval from Legal Department. However, you should not seek a prior approval if an identical process has previously been approved • DO make sure that the necessary legal basis for processing of personal data exists. The constitution of a sufficient legal basis is described in the Pilgrim’s Pride Ltd Data Protection Compliance Policy • DO make sure that processing of personal data is compliant with the data protection principles describes in the Pilgrim’s Pride Ltd Data Protection Compliance Policy • DO only process personal data on a “need to have” basis • DON’T collect and process personal data on a “nice to have” basis • DO base processing of personal data on a written consent (not oral) when the processing necessitates a consent • DON’T process personal data if the Data Subject withdraws his/her consent and no other legal basis for the processing can be justified • DO update or delete personal data that is no longer correct or relevant e.g. on file drives, e-mails and physical archives • DO seek advice from the Legal Department if you are planning to transfer personal data to countries outside EU • DON’T share your passwords with others. A password is strictly personal and may not be passed on to others • DO always lock your computer if you leave you workplace
Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 4 of 7
2.2
GUIDELINE RE PROCESSING OF HR DATA
• DO store physical HR files in locked cabinets or rooms • DO destroy physical documents comprising personal data when you don’t need the documents any more • DON’T store identical files with personal data twice e.g. electronically and physically • DO always advise job applicants to apply for a job on our webpage provided such online functionality is available in your business unit • DON’T process sensitive personal data on employees without the prior approval from the Legal Department. However, you should not seek a prior approval if an identical HR process has previously been approved. As an example, Legal Department has approved that CVs from job applicants can be processed even though CVs often holds sensitive information (ethnic origin, religion etc.) • DO send job applications and CVs to the HR department after the hiring process has ended. Alternatively, destroy the material Remember the following if you are employed in the HR department and receive job applications and CVs after the hiring process has ended: • DO archive job applications, CVs etc. received from job applicants who were successfully hired to the job. However, remember to destroy such material when the period of employment has ended • DON’T archive job applications, CVs etc. received from job applicants who were not successfully hired to the job without the written consent from the applicant. The applicant’s written consent must be renewed every six months 2.3
GUIDELINE RE PROCESSING OF PERSONAL DATA FOR MARKETING PURPOSES • DO always obtain a written consent from a third party to whom marketing material is about to be sent (whether sent by e-mail, text-message or otherwise) • DO always contact Legal Department when you are planning processing of personal data on Data Subjects under the age of 13 2.4
GUIDELINE RE PROCESSING OF PERSONAL DATA ON OWNERS AND FARMERS
• DON’T process sensitive data on farmers Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 5 of 7
• DON’T disclose personal data on farmers to companies outside Pilgrim’s Pride Ltd without a prior approval from the Legal Department • DON’T publish any personal data (e.g. on the internet) on farmers without a prior approval from the Legal Department 2.5
GUIDELINE RE RIGHTS OF THE DATA SUBJECT
• DO always inform the Data Subject when you collect personal data on him/her • DO always inform the Data Subject if you are processing his/her personal data for new or altered purposes • DO always promptly consult the Legal Department if anyone asks for access to their personal data • DO always promptly consult the Legal Department if anyone claims “the right to be forgotten” • DO update incorrect personal data in IT-systems or applications • DO always reply to third parties’ request for access to their personal data processed by Pilgrim’s Pride Ltd • DO as a general rule reply within one month to any third party requests 2.6
GUIDELINE RE TRANSFER OF PERSONAL DATA TO THIRD PARTY COMPANIES
• DON’T transfer personal data to third party companies without consulting the Legal Department. 2.7
GUIDELINE RE NEW SYSTEMS, APPLICATIONS OR METHODS FOR PROCESSING OF PERSONAL DATA
• DO always promptly contact the Legal Department when you are purchasing or developing new systems, services and products which process of personal data.
3 REPORTING REQUIREMENTS You are required to report the following incidents to the Legal Department: Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 6 of 7
• Any potential violation of the data protection rules (both internal rules and legislation) • Any loss of personal data (both digital and physical) • Any unintended disclosure of personal data • Any complaints re processing of personal data from Data Subjects • Any request from a company outside of Pilgrim’s Pride Ltd requesting an audit of the security measures
4 POINTS OF CONTACT If you have any questions in respect of the Guidelines and/or require further advice and guidance on specific issues, please contact either: Scythia Cross Head of Legal (Tel: 01926 417508, Mobile: 07341 790600) Anna Barlow Commercial Lawyer (Tel: 01926 417544, Mobile: 07970106249)
Employee Handbook Policy Name Issue Number: Issue Date: Issued by/Author:
Pilgrim's Pride Ltd Data Protection Compliance Policy 2.0 15/10/2019 Rachel Baldwin, VP HR
Page 7 of 7