Data Privacy Policy & Procedure
Data Privacy Policy & Procedure
-
Purpose
The Purpose of this policy is to protect and secure Personally Identifiable Information (PII) in compliance with applicable local and international data protection laws and regulatory requirements. This includes ensuring the proper collection, processing, storage, and disposal of PII while implementing measures to safeguard privacy and minimize risks to data security.
-
Scope
This policy applies to all employees, contractors, and third parties who handle Personally Identifiable Information (PII) on behalf of Infocomm Group LLC. It encompasses all aspects of data privacy and protection, including the collection, processing, storage, sharing, and disposal of PII.
-
Policy
- Personal Identifiable Information shall refer to any information that shall be used to identify an individual, including but not limited to names, addresses, email addresses, and financial data.
- Infocomm shall collect PII only when necessary for legitimate business purposes and shall inform individuals about the purpose of data collection and shall seek their consent when required by applicable laws.
- Infocomm shall implement and maintain security controls to protect PII from unauthorized access, disclosure, alteration, or destruction.
- Infocomm is committed to using PII exclusively for the purposes for which it was collected, ensuring compliance with legal requirements and obtaining explicit consent.
- Infocomm shall not share PII with third parties unless it is necessary for the intended purpose or required by law.
- Infocomm is responsible for retaining PII only for as long as necessary to fulfill its intended purpose or as required by law.
- Once the retention period has expired, Infocomm shall securely dispose of PII collected, ensuring that it cannot be accessed or reconstructed.
- Individuals have the right to access, correct, update, erase, restrict, object to, withdraw consent for, and request portability of their PII, where applicable. Infocomm shall provide a clear and accessible mechanism for data subjects to exercise these rights through the Data Subject Rights Request Form or the designated privacy contact channel published with this policy: email info@i-grp.com or contact +968 24151020 / +968 24151025.
- In the event of a data breach involving PII, Infocomm shall handle the incident in accordance with the Incident Management Policy and Procedure, ensuring timely reporting, investigation, and remediation.
- Infocomm shall provide regular training to employees and contractors on data privacy and security best practices, ensuring they are informed of their responsibilities and equipped to handle Personally Identifiable Information (PII) in a secure and compliant manner.
- This policy shall be subject to periodic review and update to ensure it remains effective and aligned with changing regulatory requirements.
- Infocomm shall ensure this policy, together with the Data Subject Rights Request Form and the designated privacy contact details, is placed in a visible and accessible location for data subjects, including the company website, reception/public-facing area, customer or employee portal where applicable, or any other suitable access point. The designated privacy contact details are email info@i-grp.com and contact numbers +968 24151020 / +968 24151025.
-
Procedure
-
- Name
- Contact details
- Identification numbers
- Location
- Online identifiers
- Information related to their physical, economic, cultural, or social identity
Personal Data:
Personal data refers to any information that can identify an individual, either directly or indirectly. This includes, but is not limited to,
-
- Health: Medical records, information about disabilities, or details about an individual’s physical or mental health
- Racial or Ethnic Origin: Information indicating a person’s racial or ethnic background
- Religious or Philosophical Beliefs: Data revealing an individual’s religious beliefs, philosophical convictions, or membership in religious or philosophical organizations.
- Political Opinions: Information related to an individual’s political opinions, affiliations, or activities.
- Sexual Orientation and Sex Life: Information regarding an individual’s sexual orientation, sexual activities, or preferences.
Special Data:
Special data is a subset of personal data that is considered particularly sensitive and deserving of extra protection under data protection laws. This type of data typically includes information related to an individual:
Special data requires additional protection due to its sensitive nature, as mishandling can lead to discrimination or harm.
-
- Consent Form will be used to obtain clear and explicit permission from individuals to collect and process their personal data. It outlines what personal data will be collected, the specific purpose for its use, and any third parties who may access it
- Individuals must provide their explicit consent by signing the form or taking an affirmative to confirm they understand and agree to the data collection and processing as outlined.
- Personal data will only be processed for the specific purpose stated in the Consent Form. Infocomm will ensure that data is used exclusively as described and within the scope of the consent given.
Consent Form
-
- Privacy Notice, also known as the Privacy Policy, will be provided by Infocomm to inform individuals about how their personal data will be collected, processed, stored, shared, retained, protected, and disposed of. It will outline the organization’s data handling practices, including the purpose and lawful basis of processing, categories of personal data processed, retention periods, security measures, data subject rights, and the clear mechanism for exercising those rights.
- The Privacy Policy shall be placed in a visible location accessible to data subjects, including Infocomm’s website, reception/public-facing area, customer or employee portal where applicable, or any other suitable access point. The policy shall be made available upon request and shall clearly display the Data Subject Rights Request Form availability and the designated privacy contact channel through which individuals may exercise their rights: email info@i-grp.com or call us at +968 24151010/25.
Privacy Notice
-
- Division head in coordination shall collaborate with their teams to accurately and comprehensively complete the DPIA sheet for their respective processing activities.
-
The sheet contains the fields such as :
-
Division:
The name of the department which collects and process the data shall be mentioned in this field.
-
Processing details:
The details about the processing of data shall be mentioned in a brief to understand the processing of the data
-
Personal data item:
What are the personal data collected shall be mentioned here.
-
Source of Data:
The source from where the data is collected shall be mentioned in this field to have an insight of the source of the data gathering.
-
Is special category of personal data collected:
Special category of personal data, also known as sensitive data, is:
- Highly private information about a person, like their race, religion, health, or sexual orientation.
- Requires extra protection due to the potential for discrimination or harm if mishandled.
- This field is to ensure that the personal data collected falls under the special category.
-
Who are the Data subjects?
Data subjects are individuals about whom personal data is collected, processed, and stored shall be mentioned here
-
Data owner:
The data owner is the person or group responsible for overseeing and making decisions about a specific set of data.
-
Purpose of processing:
Specific reason or intention for collecting, using, or handling personal data. It explains why the data is being processed and what the data controller aims to achieve by doing so shall be mentioned in this field.
-
Lawful processing of the data:
- For each data processing activity, carefully consider the lawful bases of data processing.
- Choose the most appropriate lawful basis that justifies the processing of personal data for the specific purpose.
-
The types of lawful basis processing are;
- For each data processing activity, carefully consider the lawful bases of data processing.
- Choose the most appropriate lawful basis that justifies the processing of personal data for the specific purpose.
-
The types of lawful basis processing are;
-
Consent:
Individuals give explicit and informed consent for their data to be processed for specific purposes.
-
Contractual Necessity:
Processing is necessary for the performance of a contract with the individual or for taking pre-contractual steps at the individual’s request.
-
Legal Obligation:
Processing is necessary to comply with a legal obligation to which the data controller is subject.
-
Vital Interests:
Processing is necessary to protect someone’s life.
-
Public Task:
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
-
Legitimate Interests:
Processing is necessary for the legitimate interests pursued by the data controller or a third party, except where such interests are overridden by the interests, rights, or freedoms of the data subject.
-
-
Storage location:
The location where the data is stored shall be mentioned in this field. This is to have a clear view on where the collected personal data is stored. Example: production server, Cloud storage.
-
Personal Data Analysis
-
-
Data Protection Impact Assessment
-
- The identification of risks will be performed by a combination of group discussion and interview with interested parties.
-
Such interested parties will normally include (where possible):
- Division Head responsible for each activity
- Representatives of the people that normally carry out each aspect of the activity
- Providers of the inputs to the activity (including, where appropriate, the data subject)
- Recipients of the outputs of the activity
- Appropriate third parties with relevant knowledge
- Representatives of those providing supporting services and resources to the activity
- Any other party that is felt to provide useful input to the risk identification process
- Identified risks will be recorded with as full a description as possible that allows the likelihood and impact of the risk to be assessed.
Identify risk scenarios
-
- Risk analysis within this process involves assigning a numerical value to the a) likelihood and b) impact of a risk. These values are then multiplied to arrive at a classification level of high, medium, or low for the risk.
-
Likelihood is categorized as “Very High”, “High”, “Possible”, “Rarely” and “Very rarely” based on the likelihood of occurrence. The following table defines the likelihood ratings:
- Rare: The threat has very rare probability of occurrence at least once in five years
- Unlikely: Probability of the threat compromising the vulnerability is once in three years
- Possible: Threat can occur sometimes at least once in a year.
- Likely: The threat has high probability of occurrence of half yearly once.
- Probable: The threat has very high probability of occurrence of quarterly once.
-
Impacts are rated as “Very High”, “High”, “Medium”, “Low”, and “Very Low” based on ease of exploit and level of protection currently present on the asset. The following table defines the impact ratings.
- Very Low : Little or no effect if the personal data is compromised.
- Low : Some effect if the personal data is compromised. (Negligible Internal Operation loss)
- Medium : Considerable effect if the personal data is compromised. (Essential Internal Operation loss)
- High : Great effect if the personal data is compromised. (It might lead to breach in SLA and cause nominal financial impact)
- Very High : Catastrophic effect if the personal data is compromised (It might lead to financial loss for customer and reputation or financial loss for Infocomm or leads to Legal or Lawsuit against Infocomm)
-
The ranking of risks is based on a qualitative and quantitative method. Risk ranking is arrived based on following formula:
- Risk Rating = Impact Rating x Likelihood Rating
Analyze the risks
-
- Based on the assessment of the grade of likelihood and impact, a score is calculated for each risk by multiplying the two numbers. This resulting score is then used to decide the classification of the risk based on the matrix shown.
-
Each risk will be allocated a classification based on its score as follows:
- HIGH: 12 or more
- MEDIUM: 5 to 10 inclusive
- LOW: 1 to 4 inclusive
Risk Classification
-
- Based on the above matrix the risk can be ranked on a scale of 1 to 25. Threshold level of risk rating is <=12.
Risk Threshold Level
li>The result of the Data protection Impact assessment will be reported to MR with its recommendation regarding the Risk threshold level. Once the same is approved by the all risks & opportunities above the threshold level would need a treatment plan which would be monitored by the MR.
li>MR will review and provide approval or advice next steps to minimize/mitigate/leverage for any risk which is above the risk threshold level of the Organization.
-
li>All risk which is above the threshold limit and cannot be mitigated will be has to be considered as the residual risk which would need to be approved by the MR.
- For those risks that are agreed to be above the threshold for acceptance by Infocomm, the options for treatment will then be explored.
- The overall intention of risk treatment is to reduce the classification of a risk to an acceptable level. This is not always possible as sometimes although the score is reduced, it remains in the same classification, for example, reducing the score from 5 to 10 means it remains a medium level risk. The organization may decide to accept these risks even though they remain at a medium rating. Such decisions should be recorded with a suitable explanation.
Define Risk Treatment Plan
- At each stage of the data protection impact assessment process, management will be kept informed of progress and decisions made, including formal signoff of the proposed residual risks. Management will approve the data protection impact assessment report and will consider to what extent the report should be made public, either in full or in summarized form.
- Signoff will be indicated according to Infocomm documentation standards.
- In addition to overall management approval, the acceptance or treatment of each risk should be signed off by the relevant Department owner.
Obtain Management Approval for Residual Risks
- If the results of the data protection impact assessment indicate a high level of risk prior to the identified controls being implemented, the supervisory authority be consulted before any processing takes place
-
The following information must be provided:
- Details of the respective responsibilities of the controller, joint controllers and processors, where applicable
- Purposes and means of the processing
- The controls that will be implemented to protect the data
- Contact details for the data protection officer (if applicable)
- A copy of the impact assessment report
- The supervisory authority has eight weeks (extendable by a further six weeks) to provide a judgement on the proposed processing and, if appropriate, give details of what must be done to make the processing acceptable
Prior Consultation with Supervisory Authority
- Data Protection Impact assessment is the overall responsibility of the MR wherever applicable. MR should implement controls to mitigate the identified risk in the processing of the personal data.
- Appropriate Controls shall be put in place to ensure that all the risk above the threshold level is mitigated and proper security is provided for all the personal data collected, stored and processed.
- This Data privacy Impact Assessment sheet shall be reviewed by the MR on a yearly basis or on the need to verify basis in case of changes made inside the organization. This is to identify that is there any new risk emerged on the processing of the personal data inside the organization and to identify is there any need to change the control.
Risk Treatment and Monitoring
-
Data Processing Agreement, is a legal contract that outlines the responsibilities and obligations of two key entities under the Data Protection Regulation: the data controller and the data processor.
- Data Controller: The data controller is the entity that determines the purposes and means of processing personal data. In simpler terms, they decide why and how personal data is collected and used. Data controllers have specific legal obligations, including ensuring that the processing of personal data is lawful and that data subjects’ rights are respected.
- Data Processor: The data processor is the entity that processes personal data on behalf of the data controller. They act based on the instructions provided by the data controller and are responsible for implementing appropriate security measures to protect the data. Processors can be external service providers or internal departments within an organization.
-
The Data Processing Agreement, or DPA, is a legally binding document that clarifies the relationship between these two entities and ensures that both parties comply with Privacy requirements. Key elements typically included in a DPA include:
- The nature and purpose of data processing.
- The types of personal data involved.
- The obligations and responsibilities of the data processor, including data security measures.
- The data controller’s right to audit the data processor’s activities.
- Provisions for the data processor to assist the data controller in responding to data subject requests and data breaches.
- Terms related to sub-processing (if the data processor uses subcontractors).
- Provisions for the termination of the agreement.
- A well-crafted Data Processing Agreement is essential to establish a clear understanding of data processing responsibilities, ensure compliance with Privacy, and protect the rights and privacy of data subjects. It is a crucial component of data protection when data is shared or processed by third parties on behalf of a data controller.
Data Processing Agreement:
Data Subject Rights
- Data subjects are individuals whose personal data is collected, processed, or stored by organizations, and they have specific rights and protections under data protection and privacy regulations.
- All the data subject has certain rights to their data those rights are
-
Under data protection regulations like the Data Protection Regulation, data subjects have several rights to protect their personal data. Here is a list of the key data subject rights:
- Right to Access: Data subjects have the right to obtain confirmation from the data controller as to whether their personal data is being processed and, if so, access to that data and related information.
- Right to Rectification: Data subjects can request the correction of inaccurate or incomplete personal data.
- Right to Erasure (Right to Be Forgotten): Data subjects have the right to request the deletion of their personal data under specific circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
- Right to Restriction of Processing: Data subjects can request the limitation of the processing of their personal data under certain conditions, such as during the verification of the accuracy of the data.
- Right to Data Portability: Data subjects can request to receive their personal data in a structured, commonly used, and machine-readable format, allowing them to transfer it to another data controller.
- Right to Object to Processing: Data subjects have the right to object to the processing of their personal data, particularly for direct marketing purposes or when the processing is based on legitimate interests.
- Rights Related to Automated Decision-Making and Profiling: Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, if these decisions significantly affect them.
- Right to Withdraw Consent: If processing is based on consent, data subjects have the right to withdraw their consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: Data subjects can lodge a complaint with a data protection authority if they believe their data protection rights have been violated.
- Mechanism for Exercising Rights: Data subjects may exercise their rights by completing the Data Subject Rights Request Form available with this policy or by submitting a written request through the designated privacy email address/public contact channel published with this policy. The designated privacy email address is info@i-grp.com and contact number is +968 24151010/25. The request shall include sufficient information to identify the requester, the right being exercised, the personal data or processing activity concerned, and any supporting details required to process the request.
- The data subject may exercise any of the above rights without charge by submitting the Data Subject Rights Request Form or by using the designated privacy contact channel: email info@i-grp.com or call us at +968 24151010/25. The form and contact details shall be published together with this policy and maintained in a visible and accessible location for data subjects. All requests shall be acknowledged after receipt and routed to the MR for review, verification, and action.
- MR will verify the identity of the requester, assess the request, coordinate with the relevant data owner where required, and respond within 45 calendar days in line with applicable PDPL requirements. During review of the request, the data subject may request suspension of processing relating to the request until it is addressed. If additional time is required due to data gathering, complexity, or dependency on third parties, the delay and reason shall be communicated to the data subject. If the request is rejected in whole or in part, the data subject shall be informed of the decision and the reasons for rejection.
- All data subject requests received shall be recorded by the MR in the Data Subject Request Register, including the date received, requester details, right exercised, responsible owner, status, response date, decision, and closure evidence. The register shall be reviewed periodically to confirm timely handling and to support audit review.
Control for timely disposition
-
To ensure timely and compliant disposition at the end of each retention period, the following controls and processes are used:
-
Policy and schedule
Documented records retention and disposal policy that defines responsibilities, retention periods by category, and approved destruction methods.
A records / data inventory linking systems and record types to their retention rules so they are applied consistently.
-
Technical controls
Configuration of document management and core systems to tag records with metadata (type, owner, closure date).
Review of the document management on annual basis, execute secure deletion for standard, non‑exception items.
-
Secure destruction
For electronic data: secure deletion that prevents recovery (e.g., overwriting, cryptographic erasure), applied both to production and backups according to technical feasibility.
For physical records: use of approved shredding / pulping vendors with certificates of destruction.
-
Governance and exceptions
Hold / suspension process: if there is a legal hold, audit, or dispute, the affected records are flagged and excluded from destruction until the hold is lifted.
-
- Periodic reviews and internal audits to confirm that destruction is occurring on schedule and that any deviations (early destruction or over‑retention) are documented and approved.
Data Breach or Incident
- Any incident or data breach that involves personal information will be managed following the incident management procedure.
- In case of an incident or data breach involving personal information, affected data subjects will be promptly informed about the incident and will receive ongoing updates on how it is being handled by the MR.
Abbreviations & Definitions
- IT : Information Technology
- MR : Management Representative
- DPA : Data Processing Agreement
