Transcription of Contents
1 ICB GDPR fair Processing Notice Ver:1:0. Contents 1. What is the Irish Credit Bureau ( ICB )? .. 1. 2. About this fair Processing Notice .. 1. 3. Data protection laws .. 2. 4. Data protection principles .. 2. 5. Where did you get my Personal Data from? .. 3. 6. Why does ICB collect this information?.. 3. 7. What Personal Data is held on the ICB database? .. 3. 8. Who do we share your personal data with? .. 4. 9. What entitles ICB to process my Personal Data? .. 5. 10. Security of your personal 6. 11. Does ICB make decisions about lending to me?
2 6. 12. What about a Credit Bureau Score? .. 6. 13. How do I find out what information you hold and how do I request a copy of my data? .. 7. 14. Who should you contact with other data protection queries? .. 7. 15. What can I do if my Personal Data is wrong? (Right to rectification).. 7. 16. Right to object to processing and right to deletion .. 8. 17. Can I restrict what ICB does with my personal data? .. 8. 18. Data portability right .. 9. 19. Right to 9. 20. Changes to the fair Processing Notice.
3 9. 1. What is the Irish Credit Bureau ( ICB )? ICB is a secure database, set up in 1963, which is used to collect and store personal data on credit agreements from members of ICB. Please see for a full list of members. Our contact details are as follows: Telephone +353 1 2600388. Email Irish Credit Bureau , ICB House, Newstead, Post Clonskeagh, Dublin 14, D14 PX09. 2. About this fair Processing Notice This fair Processing Notice relates to our privacy practices and policies. It sets out what personal data we collect and process about you in connection with the services and functions of ICB; where we obtain the data from; what we do with that data; how we comply with the data protection rules; who 1 | Page 23-Feb-2018 IRISH CREDIT BUREAU ICB GDPR fair Processing Notice Ver:1:0.
4 We transfer data to and how we deal with individuals' rights in relation to their personal data. Any personal data is collected and processed in accordance with Irish and EU data protection laws. All our employees and contractors are required to comply with this fair Processing Notice when they process personal data on our behalf. Any failure by employees or contractors to comply with the data protection rules (including as they are outlined in this fair Processing Notice) may result in disciplinary action or sanction.
5 3. Data protection laws The data protection rules that apply to us are currently contained in the Data Protection Acts 1988. and 2003. As and from 25 May 2018, the applicable rules will be contained in the General Data Protection Regulation (GDPR) and in related Irish data protection legislation which gives effect to the GDPR. This document is to ensure compliance with Article 14 of the GDPR - which stipulates what information needs to be provided where personal data have not been obtained directly from the data subject.
6 Data controllers are organisations who determine the purposes for which, and the manner in which, any personal data is processed, who make independent decisions in relation to the personal data and/or who otherwise control that personal data. For the purposes of the GDPR, ICB is the data controller with regard to the personal data described in this fair Processing Notice. 4. Data protection principles The eight data protection principles that apply to ICB are that: 1. We must process personal data fairly, lawfully and transparently.
7 This obligation includes that we must have a valid legal basis for our processing of personal data and that we must be transparent with individuals about our processing of their personal data. 2. We can only collect personal data for specified, identified and legitimate purposes. 3. We can only then process the personal data that we have collected for the purposes which we have identified or for purposes that are compatible with the purposes that we have identified. 4. The personal data that we collect and process must be adequate, relevant and limited to what is necessary for the purposes.
8 5. The personal data that we collect and process must be accurate and (where necessary) kept up to-date. 6. We must not keep personal data any longer than is necessary, bearing in mind the purpose for which we collected it. This includes that we should keep personal data in a form which permits identification of the data subject for no longer than is necessary. 7. We must keep personal data safe and secure from unauthorised access, deletion, disclosure or other unauthorised uses. This includes not just keeping data safe and secure from persons outside our organisation, but also from people within our organisation who have no need to access or use the personal data.
9 We must also be careful when transferring personal data outside the European Economic Area (the EEA , being the EU plus Norway, Liechtenstein and Iceland), and make sure that we have a valid legal basis on which to transfer that data. Transfers can include using cloud servers located outside the EU or allowing people who are located outside the EEA access to personal data that is stored within the EEA. 8. We must comply with data subjects' rights of information about, and (separately) access to, their personal data and with their other data protection rights, including rights to correct or erase their personal data, rights to be forgotten , rights to object to processing (including 2 | Page 23-Feb-2018 IRISH CREDIT BUREAU ICB GDPR fair Processing Notice Ver:1:0.)
10 Profiling), rights against automated decision-making and (under the GDPR) rights to data portability. 5. Where did you get my Personal Data from? We receive personal data along with data relating to credit agreements from registered members of ICB. When you enter into a credit agreement with a member of ICB, this data is registered on the database. Each month ICB receives an update for each open account. This builds up a credit history which indicates how you are meeting the repayment terms of any credit agreements you may have.