C Plus Security is committed to protecting the privacy and personal data of all individuals we interact with, including employees, clients, customers, visitors, contractors, and members of the public.
As part of our security operations, we may collect, store, and process personal information in the course of providing guarding services, CCTV monitoring, event security, access control, reporting, and incident management. We understand the importance of handling such information responsibly and lawfully.
C Plus Security will comply with all relevant UK data protection laws, including:
We ensure that personal data is processed fairly, securely, and only for legitimate business purposes.
The purpose of this policy is to ensure that:
This policy applies to:
This policy covers all forms of personal data including paper records, digital records, CCTV footage, emails, and incident reports.
Personal Data: Any information that can identify a person directly or indirectly (e.g., name, address, phone number, ID documents).
Special Category Data: Sensitive personal information such as health data, ethnicity, religion, biometric data, or criminal offence records.
Processing: Collecting, storing, sharing, recording, using, or deleting personal data.
C Plus Security will follow the UK GDPR principles, ensuring personal data is:
C Plus Security may process personal data under lawful bases such as:
Special category data will only be processed when legally permitted and necessary.
Personal data may be collected through:
C Plus Security will ensure that only authorised staff have access to personal data, and data will not be shared unnecessarily.
C Plus Security will take reasonable steps to protect personal data by using:
Employees must not store company data on personal devices unless authorised.
Personal data will only be shared when necessary and lawful, such as:
C Plus Security will never sell personal data to third parties.
Individuals have rights under UK GDPR, including the right to:
Requests must be reported to management immediately and handled within legal timeframes.
A data breach includes loss, theft, unauthorised access, accidental sharing, or improper disposal of personal data.
All suspected breaches must be reported immediately to management. C Plus Security will investigate and, where required, report breaches to the ICO within the legal timeframe.
All staff must:
Failure to follow this policy may lead to disciplinary action.
This policy will be reviewed annually or when legal or operational changes occur.