The information security commitments of [TeamTalk Ltd], aligned to the five Cyber Essentials technical control areas and to Article 32 of the UK GDPR.
As at [date] TeamTalk has one director and no employees. Where this policy names a second role or a review cycle, it takes effect when that person is engaged. External escalation: [accountant / solicitor, name and telephone].
[TeamTalk Ltd] holds personal data belonging to other organisations' workforces, including names, mobile numbers and records of what each person was told and when. Those records are relied on as evidence. The company protects the confidentiality, integrity and availability of that information, and holds itself to the technical standard set by Cyber Essentials and to the requirement in Article 32 of the UK GDPR to implement measures appropriate to the risk.
Cyber Essentials: not currently held. Assessment booked with [body], target [date]. The company holds itself to the technical standard of the scheme in the meantime, and the gap analysis and remediation list are available on request. It is not certified to ISO/IEC 27001 and does not claim to be; a written roadmap is available on request. The company does not claim certification it does not hold.
This policy applies to all information the company holds, in any form, and to every employee, director and contractor, and to every device and cloud service used for company work, wherever located. Compliance with it is a condition of engagement.
The company has one director and no employees as at [date], so the following applies to the director today and to each person engaged from the day they are engaged: a right to work check before starting; written confidentiality obligations that survive the end of their engagement; a security and data protection briefing on joining and at least annually; and removal of all access on their last working day. Deliberate misuse of company or customer information is gross misconduct, and unauthorised access to a computer system is a criminal offence under the Computer Misuse Act 1990.
Everyone must report a suspected security incident or data breach immediately to [name, email, mobile], however minor it appears and however it arose. Nobody will be criticised for reporting an incident, including one they caused. The company follows a written incident response procedure and notifies an affected customer without undue delay and in any event within 24 hours where personal data is involved, so the customer can meet its own duty to the Information Commissioner under Article 33.
[Name, Director] owns this policy and information security generally. It is reviewed at least annually, on any material change to the service or the estate, before the Cyber Essentials assessment and each renewal after it, and after any incident.