Putting it into practice
Check where the data is stored and what the terms of the contract are. What
kind of security practices do they commit to? Usually security settings in cloud
storage platforms can be configured to meet the needs of the customer. Make
sure someone in the NHRI is familiar with the security controls and knows
how to change and manage them.
International Data Transfers
Different countries will have different rules around transferring personal information to other countries.
Generally, ensure that the receiving organisation is able to handle and protect the information in a
manner that is equivalent to the way you would.
Being responsive: handling requests, queries
and complaints
Contact Information
NHRIs should ensure that their forms and websites and any other location where personal information
is collected has their contact details, such as email address and phone number, explicitly inviting
anyone who has complaints, queries or concerns about handling of personal information to use
these contact details. Some countries have a requirement that organisations make individuals aware
of how to complain to the relevant regulatory agency if they are not happy with how complaints are
handled by an organisation.
Requests for access, correction and deletion
Under the GDPR and some other privacy laws, individuals have the ability to access what personal
information is held about them and to request that certain data about them be corrected or deleted.
This is most relevant where the organisation holding the data has some power over the individual,
for example is in a position to grant or deny a service or a benefit.
NHRIs should train staff to handle such requests and generally should be prepared and able to meet
such requests by:
•
Providing the individual with a copy of their personal data in a commonly used format like in an
email or a PDF. The NHRI should, where relevant, include information about the purpose for
which the information is held, who it is shared with externally and how long it is kept.
•
Correcting or deleting the data if requested unless there are lawful reasons you need to keep it.
Lawful reasons could include legal obligations in a court proceeding.
Data Protection Guidelines for NHRIs Toolkit
15