This policy establishes and maintains a comprehensive data privacy program that ensures the protection of personal data within Gant Travel. This policy outlines the principles, roles, and responsibilities necessary to comply with applicable data protection laws and regulations.
This Policy applies to all employees, contractors, and third parties who process personal dataon behalf of Gant Travel.
Data Protection: In the context of this Policy, data protection means a set of principles and practices put in place to ensure that any personal data collected and used by, or on behalf
DATA PRIVACY POLICY
Gant Travel
Data Privacy Policy
Version 1.0
of, Gant Travel is accurate and relevant, and that the personal data is not misused, lost, corrupted, or improperly accessed and shared.
Personal Data: Personal data is any information that may lead to the identification of a living (identified or identifiable), natural person. Some examples of personal data include name, email or location data, identification number, gender, marital status, date, and place of birth.
Sensitive Personal Data: Sensitive personal data types, including health information (ePHI), religious and political beliefs, biometric and genetic data, are considered special personal data categories. It should be noted that whether personal data is sensitive may be heavily dependent on the context. When personal data is found to be sensitive, additional protections and restrictions should be put in place during collection and processing. Such additional protections may include the controls identified for handling highly confidential information in the Data Classification Policy.
Data Controller: The term Data Controller is used to refer to the person or entity that determines the purposes and means of the processing of personal data. A Data Controller has primary responsibility for the protection of personal data. In practice there may be more than one Data Controller. It should also be noted that there will be circumstances where a Data Controller is a third party, and Gant Travel will only be a processor of personal data.
Data Processor: A Processor is the individual or entity that performs one or more processing operations on personal data under instructions from the Data Controller.
Third Party: Third Party is any natural or legal person, public authority, agency, or body other than the data subject, Gant Travel, data controller, or data processor.
Processing of Personal Data: Any operation, or set of operations, automated or not, which is performed on personal data, including but not limited to the collection, recording, storage, adaption or alteration, retrieval, use, transfer, dissemination, correction, or destruction.
Data Subject: An individual whose personal data is subject to processing.
Affected persons: Individuals who look to or benefit from Gant Travel’s protection or assistance. This may include any person in the country or local community where Gant Travel operates.
Data Privacy Policy Version 1.0
[Updated Date]
Personal Data Breach: Unauthorized access to, or destruction, loss, alteration, or disclosure of personal data.
4.1 Roles and Responsibilities
Data Protection Officer (DPO)
The Data Protection Officer (DPO) is responsible for overseeing the company’s data protection strategy and its implementation to ensure compliance with GDPR requirements. The specific responsibilities of the DPO include:
Compliance Committee
The Compliance Committee supports the CPO and DPO in implementing and maintaining the privacy program. It is composed of representatives from key departments such as IT, HR, Legal, and Compliance. Responsibilities include:
IT Department
The IT Department plays a crucial role in ensuring data security and supporting data privacy initiatives. Their responsibilities include:
Human Resources Department
The Human Resources Department is responsible for managing personal data of employees and job applicants. Their specific responsibilities include:
Legal and Compliance Department
The Legal and Compliance Department ensures that all data processing activities comply with GDPR and other relevant data protection laws. Their responsibilities include:
4.2 General Principles
Gant Travel’s processing of personal data shall be guided by the following general principles.
4.2.1 Fairness and Legitimacy
Personal data should be processed in a fair and legitimate manner. This means that Gant Travel will only process personal data where a legitimate basis exists and that data subjects should be provided with easily understandable information related to the collection and processing of their data.
Consent is the preferred legitimate basis for processing personal information. However, if obtaining freely given, fully informed consent is not possible, the circumstances should always be documented.
Under certain circumstances, one or more of the following legitimate bases may be used in addition to, or in lieu of consent.
When evaluating the legitimate bases applicable to a particular processing operation, special consideration should be given to the vulnerability of the data subject and the sensitivity of the personal data to be collected and processed, noting that what may be considered as ordinary personal information in one context could be considered as highly sensitive in another.
4.2.2 Information
Gant Travel should provide data subjects with the following information, in an easily understandable manner, when collecting personal data, or as soon thereafter as possible:
The information listed above may not be provided when Gant Travel is aware or can assume that the data subject already has, or has access to the relevant information, and where the provision of such information would be impractical in relation to the benefit to the data subject.
Additionally, the above information may not be provided when Gant Travel’s legitimate interest in the non-disclosure of such information outweighs the data subject’s rights. In case of any doubt, the DPO may be consulted for guidance.
In addition to this Policy, Gant Travel has privacy statements on its websites and other electronic communications. These privacy statements shall be reviewed for information more specific to the collection and use of personal data in the context of the relevant website or process.
4.2.3 Purpose Specification
Personal data should be collected and processed for a specified purpose and may typically only be processed for other purposes that are compatible with the original purpose. Gant Travel may process personal data for additional incompatible purposes where a legitimate basis exists and after considering the rights of the data subjects and weighing the benefits of such further processing against any potential risks.
4.2.4 Data Quality and Minimization
Personal data collected should be adequate, relevant, accurate, and not excessive considering the specified purpose for which the data was collected. All reasonable steps should be taken to ensure that personal data is updated, when necessary. When inaccurate personal data is identified, it should be corrected or deleted without undue delay.
4.2.5 Data Retention and Disposal
Personal data, whether stored on paper or electronically, should be kept no longer than is necessary to fulfill the specified purpose for which the data is processed.
Retention schedules should be maintained by Legal and implemented by each Gant Travel office, division, department, or team, based on the anticipated continuing need for the relevant personal data and in accordance with the Information and Data Classification Policy. The DPO may be consulted for guidance regarding retention.
Personal data should be disposed of in accordance with any applicable Gant Travel policy. The Legal Department should be consulted for assistance with secure disposal and electronic file deletion.
4.2.6 Confidentiality and Security
All stages of personal data processing shall be done so that it ensures the appropriate security and confidentiality of personal data. Personal data must be kept secure and protected against data breaches.
It is particularly important to review the adequacy of any security measures during the design phase of any project that involves the processing of personal data to ensure that adequate security is in place throughout the project.
Gant Travel shall routinely review data security measures and upgrade them, as necessary, to ensure an adequate level of data protection with respect to the degree of sensitivity of the personal data.
4.2.7 Management of Personal Data
Gant Travel will make reasonable efforts to ensure that the personal data provided is reflected accurately and completely. Gant Travel will also put in place reasonable security arrangements to ensure that the personal data provided is adequately protected and secure.
Appropriate security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage, and/or alteration of the personal data provided.
4.2.8 Storing of Personal Data
Gant Travel will safeguard the confidentiality of the identified personal data. Gant Travel holds personal data in secure computer storage facilities and takes steps to protect the personal data from misuse, loss, unauthorized access, modification, or disclosure.
4.2.9 Handling of Personal Data / Sensitive Data
To ensure compliance with data protection, Gant Travel will:
4.2.10 End Users’ Consent
4.3 Personal Data Protection and Privacy Training
Each team that handles personal data must ensure that it is handled and processed in line with this policy and data protection principles. Employees who handle personal data of other employees or customers must receive training to ensure that they handle it appropriately.
Gant Travel will ensure that its relevant employees (including affiliates or subsidiaries’ employees) and any third party acting as a sub-processor on Gant Travel’s behalf receive appropriate training regarding their responsibilities and obligations with respect to the processing, protection, and confidentiality of Personal Data.
Data Protection and Privacy awareness training is part of the hiring and onboarding process, and all personnel must acknowledge the Data Classification and Protection Policy during onboarding.
Gant Travel will roll out training across all personnel covering data protection and privacy policy, keep a record of the training, and provide update and refresher training at least once a year to help personnel understand their responsibilities.
4.4 Data Security and Privacy Controls
Data security is kept appropriate to the risks to individuals if data was lost, stolen, or disclosed to unauthorized people. Organizations may consider the state of the art, costs, and the nature, scope, and context of processing to determine what is appropriate to the risks involved.
Security covers organizational and technical measures.
Gant Travel shall implement appropriate organizational and technical measures designed to protect Personal Data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, access, or use.
The security and privacy controls listed above shall be reviewed and revised annually to reflect changing regulations, security requirements, emerging threats and vulnerabilities, and the availability of modern technologies.
4.5 Data Privacy Compliance Program
Data privacy is one of Gant Travel’s top priorities. Gant Travel acts as a processor when it receives personal data on behalf of, on instructions from, and under the authority of its clients acting as controllers.
It is the responsibility and liability of clients to implement effective measures and demonstrate compliance of processing activities, even when processing is carried out by Gant Travel as a data processor.
As a processor, Gant Travel shall:
4.6 Data Subject Rights
4.6.1 Data Subject Rights
Gant Travel will ensure that a formal mechanism is in place to allow data subjects to exercise their rights by submitting a corresponding request.
4.6.1.1 Information on Processing
Data subjects have the right to request information regarding whether their personal data has been, is being, or will be processed by Gant Travel, and the specific purposes of such processing.
4.6.1.2 Access to and Correction of Personal Data
Data subjects have the right to review their personal data for accuracy, completeness, and relevance. Inaccurate or incomplete data will be corrected in a timely manner.
4.6.1.3 Objection to Processing
Data subjects may object to the processing of their personal data at any time. If justified, Gant Travel shall cease processing for the purposes related to the objection.
4.6.1.4 Request for Deletion
Data subjects may request permanent deletion of their personal data. Where justified, secure deletion procedures shall be followed.
4.6.2 Modalities of Requests Regarding Personal Data
Requests to exercise data subject rights should be made in writing to the DPO whenever possible and must clearly explain the request with sufficient reasoning and evidence.
Requests must include contact details and documentation verifying the identity or authority of the requester. Additional information may be requested if necessary.
Gant Travel staff shall facilitate such requests when data subjects are unable to contact the DPO directly.
4.6.3 Responses to Requests
Timely responses shall be provided in an understandable manner. Requests may be limited or refused in circumstances including:
4.7 Commitments
4.7.1 Data Protection Impact Assessments and Privacy Impact Assessments
Gant Travel shall provide reasonable assistance to controllers with DPIAs or prior consultations as required by EU Data Protection Legislation.
DPIAs and PIAs shall be conducted for the following processing activities:
DPIAs/PIAs shall be conducted for processing activities that are likely to result in a high risk to the rights and freedoms of individuals. The DPIA/PIA process includes:
4.7.2 Data Breach Response Plan
The Information Security Coordinator (ISC) shall support and coordinate the implementation and enforcement of Information Security and Data Protection Policies.
The Information Security Management Forum (ISMF) shall provide management direction and support for data protection initiatives and data breach management.
A data breach occurs when personal information is subjected to unauthorized access or disclosure, or where information is lost and unauthorized access or disclosure is likely to occur.
A data breach is categorized as a Major Incident and handled under the Incident Management Policy. Incident management plans are tested and updated annually to ensure effectiveness.
The ISC shall oversee data breach response efforts, including containment, remediation, investigation, breach notification compliance, and prevention of recurrence, as required by applicable law.
In the event of an incident or breach involving Client Personal Data, Gant Travel shall:
4.7.3 To Build the Data Privacy Compliance Program, Gant Travel Shall:
4.8 Personal Data Transfers
Personal data transfers are a necessary part of Gant Travel’s operations but involve risks of misuse or unauthorized disclosure.
4.8.1 Transfers to Third Parties
Transfers of personal data to third parties must comply with the general principles of this policy and be supported by adequate safeguards and a written agreement.
At a minimum, transfer agreements shall require third parties to:
Special consideration shall be given to the legal enforceability of agreements in relevant regions.
4.8.2 Transfers to Investigative Bodies or Governmental Authorities
Gant Travel may transfer personal data to investigative bodies or governmental authorities under legally valid circumstances.
Such transfers may occur only if:
The DPO shall be consulted before entering into any agreement for such data transfers.
4.9 Lawful Basis and Transparency
Appropriate written agreements with clients shall clearly define personal data processing requirements, including:
Staff members found in policy violation may be subject to disciplinary action, up to and including termination.
This policy must be reviewed by management regularly but at least annually.
Any exception to this policy must be approved by the Chief Executive Officer and documented with the rationale for the exception.
Executive management commits to enforcing this policy, providing the appropriate technology to carry out security controls documented in this policy, and reviewing and approving the policy annually and when major changes are made to Gant Travel systems and services.
Click on proceed to redirect our Gant Chat Support.