GDPR compliance

Penguin Office Services – Data Compliance

In order to provide transcription services to the contracting organisation (“the client”), Penguin Office Services may need to have access to some personal data (“Data”) which data is protected under the Data Protection Act 2018 (“the Act”) and General Data Protection Regulation (“GDPR”).

These Data will include, but not necessarily be limited to: Audio or video recordings of of interviews and focus groups, background data sent as Word documents or PDFs

When providing transcription services, the client is the Data Controller and Penguin Office Services is the Data Processor. Penguin Office Services warrants that it shall:

(i)         process the Data at all times in accordance with GDPR within the Act, and solely for the purposes of providing the Services to the client and for no other purpose or in any manner except with the express prior written consent of the Data Controller; and

(ii)        comply with the seventh Data Protection Principle by implementing appropriate technical and organisational measures to prevent unauthorised and unlawful processing of the Data and to prevent accidental loss, or destruction of, or damage to the Data; and

(iii)        ensure that each of its employees, agents and subcontractors are made aware of its obligations with regard to the security and protection of the Data and require that they enter into binding obligations with the Data Processor to maintain the appropriate levels of security and protection of the Data; and

(iv)       not divulge the Data whether directly or indirectly to any person, firm or company or otherwise without the express prior written consent of the Data Controller except to those of its employees, agents and subcontractors who are subject to (iii) above or except as may be required by any law or regulation; and

(v)        not process the Data outside of the European Economic Area except with the express prior written authority of the Data Controller; and

(vi)       to comply with any request from the Data Controller to amend, transfer or delete data and on completion of the Services to deliver to the Data Controller or destroy, at the Data Controller’s sole option, all the Data Controller’s Data in its possession or under its control

Audio and transcription data are stored on password protected computers in secure locations. No cloud storage is used by Penguin Office Services or our subcontractors. Transcripts can be individually password protected at the request of the client, and can also be deleted as soon as we receive confirmation that the client has received the transcript, on request. Otherwise transcripts are held for a maximum of a year. Subcontractors are required to delete both audio and Word data once we have confirmed receipt of their transcript.

If audio is sent via our website it is automatically protected by encryption in transit, and there is a password required in order to send data to us.

Penguin Office Services agrees to indemnify the client for any fine it may receive from the Information Commissioner and/or pursuant to GDPR under the Act arising from any breach by Penguin Office Services of the above warranties; provided: (a) Penguin Office Services has sole control of the defence and/or settlement of such claim to the extent possible; and (b) the client notifies Penguin Office Services promptly in writing of each such claim and gives Penguin Office Services all information known to the client relating thereto and (c) the client cooperates with Penguin Office Services in the settlement and/or defence of such claim and (d) the client mitigates its loss to the fullest extent possible.

The parties agree that any commercially sensitive information disclosed during the provision of the Services shall be treated with confidence and used only to the extent necessary to perform the Services.

For the avoidance of doubt these terms and conditions replace and supersede any other terms and conditions between the parties relating to their respective obligations under GDPR within the Act.

Penguin Office Services is registered with the ICO, registration number Z9621910. The Data Controller within Penguin Office Services is Anne Hickley.

About

Anne Hickley has been running Penguin Transcription and Penguin Office Services since 2003. She is PhD qualified and has worked for a wide range of organisations, from large multinationals to small businesses, before starting her own businesses.