DATA GOVERNANCE POLICY AND PROCEDURES
This Data Governance Policy and Procedures (hereinafter referred to as” Policy”) is effective from [INSERT DATE ON WHICH THE POLICY COMES INTO FORCE] and applies to all employees of the [INSERT NAME OF THE COMPANY] (hereinafter referred to as “Us” or “we” or “our” or “Company”).
This policy outlines the security measures and best practices to safeguard the confidentiality, integrity, and availability of Company’s data.
- PURPOSE
- The purpose of this policy is to provide clear and structured guidelines for the management and security of Company’s confidential data. It outlines measures to protect sensitive and valuable data from unauthorized access, breaches and loss.
- SCOPE
- This policy applies to all [INSERT NAME OF THE COMPANY] employees, contractors or any individual with whom company’s confidential information is being maintained, distributed or stored within the Company.
- DATA COLLECTION AND USE
- Confidential information should only be collected for specific, legitimate purposes and should not be used or disclosed for other purposes without obtaining consent, unless required by law.
- Data collection should be minimized to what is necessary and relevant for the intended purpose.
- Review the authentication mechanisms to ensure only authorized personnel can access sensitive systems and data. Access to areas containing sensitive equipment or data is restricted to authorized personnel only and will be regulated by the security department.
- DATA STORAGE AND SECURITY
- Personal and Confidential information of the Company should be stored securely, whether in physical or electronic form, to prevent unauthorized access, use, or disclosure.
- Appropriate technical and organizational measures should be implemented to protect personal information against accidental or unlawful destruction, loss, alteration, or unauthorized access.
- Access to personal information should be restricted to authorized personnel on a need-to-know basis.
- All devices of the facility containing sensitive information and data must be secured by the security personnel when not in use. The devices or other systems of the facility such as computers or mobile devices must be encrypted, and password protected.
- DATA RETENTION AND STORAGE
- Personal information should be retained only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.
- When personal information is no longer needed, it should be securely disposed of using appropriate methods, such as shredding physical documents or permanently deleting electronic data.
- CONFIDENTIALITY, INFORMATION SECURITY, PROPRIETARY INFORMATION AND INTELLECTUAL PROPERTY
- We are committed to business information confidentiality, integrity and accessibility, we implement proper technical security measures and it is our staff’s obligation to uphold this. Proprietary information includes all non-public information that might be harmful to the company or its customers, business partners if disclosed to unauthorized parties. All members must handle any such information as secret. It also covers that, no one is entitled to trade with securities while in possession of non-public information or deliver non-public information to others that could have an impact on the securities. Every rule ensuring information security must be followed all the time.
- Employees must maintain the confidentiality of the company and information. Sharing sensitive information with unauthorized individuals is strictly prohibited.
- COMPLIANCE
- Compliance with this policy and applicable laws should be regularly monitored and audited to identify and address any potential gaps or non-compliance.
- Any identified breaches or non-compliance should be promptly investigated and appropriate corrective actions should be taken.
- CHANGES TO THE POLICY
- We reserve the right to update and make changes to this policy from time to time based on the working conditions of the Company. The Company on updating this policy will inform the members of the Company.
- FURTHER INFORMATION
- For any queries or further Information regarding our Company or about this Policy, the concerned person can contact us through email[ INSERT COMPANY’S EMAIL ADDRESS]
- ACKNOWLEDGEMENT
- We expect all employees to adhere to this policy of the Company. The Company will apply this policy consistently and fairly to ensure a harmonious and productive workplace for all.
- By signing below, you acknowledge that you have carefully read and understood the terms and contents of this policy.
- You acknowledge that you will follow the set guidelines of this policy as well as of the Company and failure to do so; the Company can take Disciplinary action against such person.
COMPANY
[INSERT COMPANY’S NAME]
Authorized Signature
Print Name and Title
[INSERT SIGNING AUTHORITY AND DESIGNATION]