Data Management Policy

1. Introduction

Display Manager Ltd is committed to responsible and secure management of all data under its control.

This policy outlines how the company collects, stores, processes, transfers, and disposes of data, ensuring compliance with the UK GDPR, Data Protection Act 2018, ISO 27001, and applicable international data transfer frameworks such as the Safe Harbor Framework.

The company respects privacy rights and seeks to protect data confidentiality, integrity, and availability across all operations, including Audio & Visual industry-specific activities.

2. Purpose

The purpose of this policy is to:

  • Establish clear rules and responsibilities for data management.
  • Ensure legal compliance for data protection and privacy.
  • Protect personal and sensitive information from unauthorised access, loss, or misuse.
  • Define procedures for lawful international data transfers, including adherence to frameworks such as the Safe Harbor Framework (and its successors).

3. Scope

    This policy applies to all data collected, processed, or stored by Display Manager Ltd in digital or physical form, across all departments and locations. It includes:

    • Personal data of employees, clients, and suppliers.
    • Business operational data, including AV project details and client content.
    • Data transferred to third parties or across international borders.

    4. Data Management Principles

    Principle Description

    Lawfulness, Fairness, and Transparency

    Data shall be processed lawfully, fairly, and transparently to data subjects.

    Purpose Limitation

    Data must be collected for specified, explicit, and legitimate purposes and not further processed incompatibly.

    Data Minimisation

    Only data necessary for the purpose shall be collected and retained.

    Accuracy

    Data must be accurate and kept up to date.

    Storage Limitation

    Data shall not be kept longer than necessary.

    Integrity and Confidentiality

    Data must be secured against unauthorized or unlawful processing, accidental loss, destruction, or damage.

    5. Roles and Responsibilities

    Data Protection Officer (DPO)

    Oversees compliance, manages data subject requests, and monitors data management practices.

    All Employees

    Follow this policy and report any data breaches or concerns immediately.

    IT Department

    Implement and maintain data security controls and backup procedures.

    Management

    Ensure sufficient resources for data management and promote awareness.

    6. Data Collection and Processing

    • Obtain explicit consent from data subjects where required.
    • Collect data only for clear business or contractual reasons related to AV projects or operational
    • Keep records of processing activities as per GDPR Article 30.

    7. Data Storage and Security

    • Store data securely using encryption, access controls, and secure backup.
    • Limit access based on the principle of least privilege.
    • Physical data (e.g., printed AV scripts or contracts) must be stored securely with restricted access.

    8. Data Transfer and Safe Harbor Framework

      • Any transfer of personal data outside the UK/EU must comply with UK GDPR requirements for international data transfers.
      • The Safe Harbor Framework, though superseded and invalidated, is acknowledged historically for guiding personal data transfers to the U.S.
      • Display Manager Ltd will ensure transfers to countries without an adequacy decision are safeguarded using:
        • Standard Contractual Clauses (SCCs) approved by the UK ICO, or
        • Binding Corporate Rules (BCRs), or
        • Other approved transfer mechanisms.
      • The company will monitor ongoing legal developments concerning international data transfer frameworks to maintain compliance.

      9. Data Retention

        • Data shall be retained only as long as necessary to fulfil the purposes for which it was collected or to comply with legal or contractual obligations.
        • Retention periods will be defined based on data type, legal requirements, and business needs.

        Examples include:

        Data Type Retention Period Notes
        Employee Records 6 years after employment ends To comply with tax and employment law
        Client Contracts & Project files 7 years after project completion Based on commercial and legal requirements.
        Financial Records 7 years For auditing and taxation purposes.
        Marketing Data Until consent is withdrawn or inactive for 2 years Respecting data subject rights and preferences.
        Personal Data of Candidates (Unsuccessful) 1 year Unless consented for longer.
        •  Data scheduled for deletion must be securely erased or destroyed to prevent unauthorised recovery.
        • A Data Retention Schedule will be maintained and regularly reviewed by the DPO.

        10 Data Subject Rights

          • Facilitate data subject rights including access, rectification, erasure, restriction, portability, and objection.
          • Respond to data subject requests within statutory timeframes.

          11. Breach Management

            • Report and investigate any personal data breaches immediately in line with the company’s Incident Response Policy.
            • Notify ICO and affected individuals as required by law.

            12. Training and Awareness

            • Provide regular data protection training for all employees.
            • Promote awareness of this policy and legal obligations.

            13. Policy Review

            This policy will be reviewed annually or as required by changes in law, business operations, or technology.

            Date: 28/11/2025

            Get more from your AV investment with monitoring and proactive maintenance

            Call 0844 335 0856 or drop us an email at enquiries@displaymanagervc.com