Legal & Compliance
As a business based in the UK there is both a legal and moral requirement to comply with the letter and spirit of the relevant laws impacting the business. As a small business the compliance landscape is not always the clearest to navigate; primarily because as the business is small and the operating model means there are less than 5 employees it is exempt from a number of recent Acts and Regulations. Although that sounds simple, procurement functions in large organisations often don’t operate separate systems for small businesses. As such, if you want to do business you have to have a stated policy on a number of subjects– exempt or not!
That said, Harina Consulting Limited takes a position on a number of topics and it is important for the clients, the suppliers, and everyone who has any dealings with it, to hear and understand where it comes from and what it stands for. Set out below are the policies and views what are integral to it:
The Modern Slavery Act 2015
The turnover is a little smaller than £36m the business is exempt from complying with this Act. But it fully supports the direction and purpose of this legislation and steps are taken to ensure that all of our corporate clients are in compliance with the Act to the best of our ability. The business model does not rely on complex supply chains to meet our clients’ needs but it does exercise care when entering into supplier arrangements, including contractor arrangements.
Slavery of any type is wholly unacceptable to our values and our purpose.
General Data Protection Regulation (GDPR) (WEF 25th May 2018)
This is a complex and demanding piece of EU regulation that, in effect, replaces the Data Protection Act in the UK. At its heart is the desire to ensure all EU citizen’s personal data is protected, transparent and accessible upon request, relevant to the purpose, and can be removed upon request. The covers data held by an organisation and when it transfers or processes that data to or via a third party.
As we have less than 250 employees and we do not process personal data as such it is reasonable to assume that we are exempt.
But we do hold information that is personal in nature regarding our clients while they engage us. When we mentor or coach our clients share information that is intended for our ears and eyes only. We use that information to help our clients and, as none of us are superhuman, we have to record that information somewhere!
Therefore, regardless of whether we are exempt or not, we take the security and confidentiality of our client’s personal information extremely seriously. We trade on our reputation and that is based on our personal professionalism and integrity. So, what steps do we take?
Under the GDPR, the lawful basis for us to hold personal data is “Consent”; the individual has given clear consent for us to process their personal data for a specific purpose. Therefore, our first action is to gain consent from our clients to hold their personal data. Normally we achieve this by entering into a “Non-disclosure agreement” (NDA) with the client or their employer to manage the taking, holding and confidentiality of their personal data.
We record client personal data in two forms: in a notebook during the mentoring or coaching sessions, and in the Cloud via an iMac or a Mac Pro laptop.
When we record client data in the notebook we use a code to represent the client to protect their identity. This is not full proof but it does make it harder to link the notebook content to an individual should we lose a notebook. Whilst we take material care over the custody of our notebooks, we cannot give a 100% guarantee that it will not be lost or stolen.
There are occasions when we capture personal data digitally. This raises two specific risks: unauthorised access and loss.
We use an iMac or MacBook Air as our main processing machine and MacBook Air as our onsite-portable machines. The machines are linked Microsoft One Drive; G-Drive Cloud or via Apple’s iCloud. All client data and the IP of the business are stored encrypted via iCloud.
No data is specifically held on the hard drives of the machines.
Google Drive, One Drive, and iCloud provide backup and security against loss of data.
Access to our machines is strictly controlled, both physically and logistically.
A cyber-related and data security risk assessment is undertaken quarterly.
When a client engagement has ended and there is no longer a purpose for us to hold that client’s personal data, it is erased from our systems; both in digital and written form.
No system is 100% secure but for the risk levels associated with our business, we believe we have taken “reasonable” steps to ensure our client’s data is both secure and only used for the purpose that it is given for.
Unless our clients have asked us to we never divulge who our clients are. Whilst we do name sponsoring organisations for some client engagements on our website, we do not name any mentoring or coaching clients or discuss the details of our engagements.
Equality & Diversity
We passionately believe that the best solutions come from the contribution of as wide and diverse a set of sources as possible.
With regard to equality we strive to ensure we treat everyone equally and with respect.
We are realistic with what we can do to reduce our carbon footprint as we operate our business, where we can we will.
