JSL Data Security Policy
Version 1.0 — June 2026
1. Purpose
This policy sets out how JSL protects the confidentiality, integrity, and availability of all information it processes. It applies to all staff, associates, contractors, and partners who handle client data, internal business information, or personal data on behalf of JSL.
The policy ensures compliance with:
· UK GDPR
· Data Protection Act 2018
· Data (Use and Access) Act 2025
· ISO 27001 principles
· Client contractual requirements
· Sector-specific safeguarding and confidentiality expectations (e.g., education, charity, ecclesiastical settings)
2. Scope
This policy covers:
· All information assets (digital and physical)
· All devices used for JSL business (company-issued or BYOD)
· All cloud platforms, collaboration tools, and communication channels
· All client engagements, including advisory, diagnostic, safeguarding, and governance work
3. Roles and Responsibilities
3.1 Managing Director (Data Owner)
· Holds overall accountability for data security across JSL
· Ensures appropriate resources, training, and oversight
3.2 Data Protection Lead
· Maintains this policy and supporting procedures
· Oversees incident response, DPIAs, and data subject rights
· Acts as the primary point of contact for clients and regulators
· Note: JSL will assess whether the volume and nature of personal data processed — particularly safeguarding and special category data — requires a formally appointed Data Protection Officer (DPO) under UK GDPR Article 37. Where required, this role will be documented and notified to the ICO
3.3 All Staff and Associates
· Must follow this policy and complete mandatory training
· Must report any suspected breach immediately
· Must handle client information with discretion and professionalism
4. Information Classification
JSL uses a four-tier classification model:
1. Public — Information approved for public release
2. Internal — Routine business information
3. Confidential — Client data, internal reports, financial information
4. Highly Confidential — Safeguarding information, sensitive personal data, legal matters
All data must be labelled, stored, and transmitted according to its classification.
5. Data Handling Requirements
5.1 Access Control
· Access is granted on a strict least-privilege basis
· Multi-factor authentication (MFA) is mandatory for all systems
· Shared accounts are prohibited
5.2 Storage
· All data must be stored in approved, encrypted cloud environments (e.g., Microsoft 365)
· Local storage on devices is minimised and encrypted at rest
· Physical documents are stored in locked cabinets with restricted access
5.3 Transmission
· Emailing sensitive data requires encryption or secure file-transfer links
· No client data may be transferred via personal email or unapproved apps
· Portable media (USBs, drives) are prohibited unless encrypted and authorised
5.4 Retention and Disposal
· Data is retained only for the minimum period required by law or contract
· Secure deletion methods are used for digital data
· Physical documents are cross-shredded or disposed of via approved confidential-waste services
6. Device and System Security
6.1 Device Standards
· All devices must have up-to-date antivirus, firewall, and security patches
· Automatic screen-locking after 5 minutes of inactivity
· Lost or stolen devices must be reported immediately
6.2 Remote Working
· Staff must work in environments where screens cannot be overlooked
· Public Wi-Fi requires a secure VPN
· Client calls must be taken in private spaces
7. Third-Party and Supplier Security
· All suppliers handling data must meet JSL’s security standards
· Due diligence is conducted before onboarding
· Contracts include confidentiality, data-processing, and breach-notification clauses
· Cloud providers must meet recognised security certifications (e.g., ISO 27001, Cyber Essentials Plus)
8. Incident Reporting and Response
All staff must report suspected or actual data breaches immediately to the Data Protection Lead.
JSL will:
1. Contain the incident
2. Assess the risk
3. Notify affected clients without undue delay
4. Report to the ICO within 72 hours of becoming aware of a breach where it is likely to result in a risk to individuals’ rights and freedoms (UK GDPR Article 33); where the breach poses a high risk to individuals, those affected must also be notified directly without undue delay (Article 34)
5. Document lessons learned and implement improvements
8a. Data Protection Complaints Handling
Under the Data (Use and Access) Act 2025, individuals have a statutory right to raise data protection complaints directly with JSL before escalating to the ICO. JSL will:
6. Maintain an accessible route for individuals to submit data protection complaints (e.g., by email to the Data Protection Lead)
7. Acknowledge complaints within 30 days of receipt
8. Investigate complaints without undue delay and keep the individual informed of progress and outcome
9. Keep records of all complaints received, actions taken, and outcomes, regardless of whether the complaint is escalated to the ICO
10. Inform individuals of their right to raise a complaint with JSL in relevant privacy notices and communications
9. Training and Awareness
· Mandatory annual data-security training for all staff and associates
· Additional training for those handling safeguarding or sensitive personal data
· Regular phishing-awareness exercises
10. Policy Review
This policy is reviewed annually or sooner if:
· Legislation changes
· New risks emerge
· JSL expands into new sectors or services
11. Approval
Approved by: Managing Director, JSL
Date: June 2026 Next Review: June 2027