This Policy helps us:
- Reduce the risk of IT problems, plan for and manage them when they occur.
- Safeguard company, client, and employee data from loss, misuse, or unauthorised access.
- Protect valuable company information such as plans and designs.
- Comply with our legal obligations under the General Data Protection Regulation (GDPR), the
UK Data Protection Act 2018, and other relevant laws. - Meet our professional responsibilities toward clients and customers.
Responsibilities
- Austin Ambrose is the director with overall responsibility for IT security strategy.
- Stacey Chapman has day-to-day operational responsibility for implementing this policy.
- Pete Mylett of CPM Computers is the IT partner organisation we use to help with our
planning and support. - Ian Jones is the nominated Data Protection Officer.
Information classification
- PMA will only classify information which is necessary for the completion of our duties. We will also limit access to personal data to only those that need it for processing. PMA classify information into different categories so that we can ensure that it is protected properly and that we allocate security resources appropriately:
- Unclassified – this is information that can be made public without any implications for the company, such as information that is already in the public domain.
- Employee confidential – this includes information such as medical records, pay and so on.
- Company confidential – such as contracts, source code, business plans, passwords for critical IT systems, client contact records, accounts etc.
- Client & Learner confidential – this includes personally identifiable information such as name or address, passwords to client systems, qualifications, client business plans, new product information, market sensitive information etc.
The deliberate or accidental disclosure of any confidential information has the potential to harm the business. This policy is designed to minimise that risk.
We do not protectively mark documents and systems. Therefore, you should assume information is confidential unless you are sure it is not and act accordingly.
Under the GDPR, where a data breach is likely to result in a ‘risk for the rights and freedoms of individuals’ we must notify the customers and data controllers ‘without undue delay’. We will ensure we inform them within 72 hours.
The Essential actions if you suspect a data breach
At any time, you suspect, or become aware of an attempted, potential or actual data breach you should report it immediately to the contracted IT partner using the contact information below. If, for any reason, you cannot get a timely response then contact any of the Main Contacts listed below.
Where there is even the slightest cause for concern, the most important thing to do is address it. Never ignore suspicious activity, or a suspected or attempted data breach, even if it turns out not to be one. Potential Data breaches can be time sensitive, i.e. the longer you leave it, the more data that can be stolen, so the best thing to do is to report it immediately. This will provide the IT department with the best opportunity to mitigate any data loss or systems damage. Your timely notice may well allow them to contain the threat, so it doesn’t spread any further or even block the attempts together.
Data Breaches and GDPR Reporting
Under GDPR, where a data breach is likely to result in a “risk to the rights and freedoms of individuals,” we must notify the affected parties and the Information Commissioner’s Office (ICO) within 72 hours.
Essential Actions if You Suspect a Data Breach:
- Immediately report any suspected, attempted, or actual breach to CPM Computers.
- If there is no response, escalate to any of the Main Contacts (see internal directory).
- Do not ignore suspicious activity. Timely reporting can reduce harm.
The IT partner will assess the incident and advise the DPO on whether it must be reported to the ICO.
Access controls
PMA adopt a “need to share” approach internally to promote productivity, balanced by the need for security.
- For personal data, we uphold GDPR’s Right of Access: individuals can request details on how and why their data is processed. We will provide this, free of charge, in a timely manner and in electronic format.
- All new staff are onboarded with appropriate access privileges.
- Departing staff will have all access revoked immediately upon termination.
- Admin rights are limited to authorised personnel and approved by a director.
All devices are protected with up-to-date anti-malware software that runs daily scans. When an employee joins, they are:
- Added to Office365 with appropriate SharePoint access.
- Granted Aptem access if required.
Information Classification
PMA classifies information as necessary to perform our duties and limit access to personal data on a “need-to-know” basis. We categorise information as follows:
- Unclassified: Publicly available information (e.g., published content).
- Employee Confidential: Medical records, payroll, performance reviews, etc.
- Company Confidential: Contracts, source code, business plans, system credentials, financials.
- Client & Learner Confidential: Names, addresses, passwords, qualifications, business plans, market-sensitive data.
All employees must treat information as confidential unless confirmed otherwise. Disclosure, accidental or intentional, could harm the business.
PMA Team responsibilities
Effective security is a team effort requiring the participation and support of every employee and associate. It is your responsibility to know and follow these guidelines.
You are personally responsible for the secure handling of confidential information that is entrusted to you. You may access, use or share confidential information only to the extent it is authorised and necessary for the proper performance of your duties. Promptly report any theft, loss or unauthorised disclosure of protected information or any breach of this policy to Austin Ambrose.
It is also your responsibility to use your devices (computer, laptop, phone, tablet etc.) in a secure
way. At a minimum:
- Remove software that you do not use or need from your computer
- Update your operating system and applications regularly
- Keep your computer firewall switched on
- For Windows users, make sure you install anti-malware software (or use the built-in Windows Defender) and keep it up to date. For Mac users, consider getting anti-malware
software. - Store files in official company storage locations so that it is backed up properly and available in an emergency.
- Understand the privacy and security settings on your phone and social media accounts
- Have separate user accounts for other people, including other family members, if they use your computer. Ideally, keep your work computer separate from any family or shared
computers. - Don’t use an administrator account on your computer for everyday use
- An administrator account does not have rights to use the applications or systems.
- An administrator account is only used for administration purposes.
- Don’t share your password with other people or disclose it to anyone else
- Don’t write down PINs and passwords next to computers and phones
- Be alert to other security risks
Cyber Hygiene & User Behaviour
- Be vigilant of email attachments and phishing attempts.
- Use caution when receiving links from unknown sources.
- Avoid sharing confidential information on social media or public forums.
- Be especially careful when using devices outside the office.
- Social engineering (e.g., impersonation scams) is a significant risk – always verify unusual requests.
While technology can prevent many security incidents, your actions and habits are also important. With this in mind:
- Take time to learn about IT security and keep yourself informed.
- Use extreme caution when opening email attachments from unknown senders or unexpected attachments from any sender. Be on guard against social engineering, such as
attempts by outsiders to persuade you to disclose confidential information, including employee, client or company confidential information. Fraudsters and hackers can be extremely persuasive and manipulative. - Be wary of fake websites and phishing emails. Don’t click on links in emails or social media.
- Don’t disclose passwords and other confidential information unless you are sure you are on a legitimate website.
- Use social media, including personal blogs, in a professional and responsible way, without violating company policies or disclosing confidential information.
- Take particular care of your computer and mobile devices when you are away from home or out of the office.
If you leave the company, you will return any company property, transfer any company work-related files back to the company and delete all confidential information from your systems as soon as is practicable.
Where confidential information is stored on paper, it should be kept in a secure place where unauthorised people cannot see it and shredded when no longer required.
The following things (among others) are, in general, prohibited on company systems and while carrying out your duties for the company and may result in disciplinary action:
- Anything that contradicts our equality and diversity policy, including harassment.
- Circumventing user authentication or security of any system, network or account.
- Downloading or installing pirated software.
- Disclosure of confidential information at any time.
Offboarding & Physical Information Handling – summary
If you leave PMA, you must:
- Return all company equipment.
- Transfer work files to the company.
- Permanently delete company data from personal devices as soon as practicable.
Confidential documents on paper must be stored securely and shredded when no longer needed.
Prohibited Actions
The following are strictly prohibited and may result in disciplinary action:
- Discrimination or harassment (breach of our Equality & Diversity Policy).
- Circumventing system authentication or security.
- Using pirated software.
- Sharing or disclosing confidential information without authorization, at any time.
Summary of Key Updates:
- Expanded references to UK Data Protection Act 2018 alongside GDPR.
- Clarified classification labels and access control rationale.
- Added explicit offboarding responsibilities for employees.
- Updated language for modern device security and phishing risks.
- Structured content more clearly for readability.