Motion Workforce Solutions
Governance

Data Protection Policy

This policy sets the standards Motion Workforce Solutions Ltd applies when personal information is collected, accessed, shared, retained or deleted in the course of workforce, payroll, recruitment and business operations.

1. Governing principles

  • lawfulness, fairness and transparency
  • specified and legitimate purposes
  • data minimisation
  • accuracy
  • retention for no longer than necessary
  • appropriate security
  • documented accountability

2. Roles and responsibilities

The directors are accountable for data protection governance. Everyone with access to personal information must follow this policy, use approved systems and report concerns. Client and supplier contracts must identify controller and processor responsibilities where relevant.

3. Collection and use

Personal information may be collected only for a defined business purpose and with an identified lawful basis. Privacy information must be provided at the required time. Special category and criminal offence information requires an additional legal condition and enhanced handling controls.

4. Access and sharing

  • grant access according to role and business need
  • verify recipients and use approved transfer methods
  • do not use personal email, unapproved storage or informal messaging for sensitive records
  • complete due diligence and data protection terms for processors
  • record material disclosures where accountability requires

5. Quality, retention and deletion

Reasonable steps must be taken to keep material records accurate and current. Information is reviewed against the retention schedule and securely deleted or anonymised when no longer required. Disposal must cover working copies, exports and physical records where applicable.

6. Individual rights

Requests relating to access, correction, deletion, restriction, objection, portability or automated decisions must be forwarded promptly to the person responsible for privacy. Identity, scope, exemptions and response deadlines will be assessed and documented.

7. Security incidents

Loss, unauthorised access, incorrect disclosure, malware and other suspected personal data breaches must be reported immediately to a director. The company will contain the incident, assess risk, preserve evidence and notify the ICO and affected individuals where the legal threshold is met.

8. New systems and changes

Privacy and security requirements must be considered before introducing a system, supplier or materially different use of information. A data protection impact assessment will be completed where processing is likely to create a high risk to individuals.

9. Training and compliance

Personnel receive guidance appropriate to their access and duties. A deliberate or negligent breach may result in access removal, disciplinary or contractual action and reporting to a client, regulator or law enforcement body.

10. Contact

Questions, rights requests and incident reports should be sent to info@motionworkforcesolutions.com. Further information for individuals is set out in the Privacy Policy.