Skip to content

GDPR > Clean Desk Policy

GDPR and Data Protection Updated 21 November 2023 5 min read
  1. Introduction
    1. This policy sets out the policies and procedures of Recycly Ltd (the "company") with respect to information, and the security of it, is important to the company, and it is committed to ensuring that it manages that information in the best way possible.
    1. A clean desk policy is an important tool to ensure that all sensitive/confidential materials are removed from an end-user workspace and locked away when the items are not in use or an employee leaves his/her workstation. It is one of the top strategies to utilise when trying to reduce the risk of security breaches in the workplace. The purpose of the policy is to increase employee’s awareness about protecting sensitive information and to establish the minimum requirements for maintaining a “clean desk” – where sensitive/critical information about the employees, the company’s intellectual property, the customers and the vendors are secure in locked areas and out of sight.  A Clean Desk Policy is part of standard basic privacy controls.
  1. Scope

This policy applies to all Recycly Ltd employees and affiliates. The purpose of this Clean Desk Policy is to set out the minimum requirements for maintaining a “clean desk”, to outline what employees and contractors are required to do in order to maintain the policy and to highlight the sanctions that may apply if the terms of the policy are not adhered to. The policy applies to all permanent, temporary, and contracted staff working for the company without no exemption.

  1. Policy
    1. Employees are required to ensure that all sensitive/confidential information in hardcopy or electronic form is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
    1. Must ensure that any computer workstation, laptop, tablet or other electronic device is locked and passworded when he/she is away from his/her workspace and completely shut down (and if a tablet or portable device locked away in the secure cabinet/drawer/facility provided for that purpose) at the end of the working day. If an employee has been given permission to use a mass storage device such as a CD, DVD, portable hard drive and USB drive (note restrictions in respect of the use of such devices in the Information Security Policy) then that mass storage device must be locked away in the secure cabinet/drawer/facility provided for that purpose.
    1. File cabinets containing confidential and/or sensitive information must be kept closed and locked when not in use or when not attended. Keys used for access to restricted or sensitive information must not be left at an unattended desk.
    1. Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
    1. Confidential and/or sensitive information should be immediately removed from the printer.
    1. Ensure that any sensitive and/or confidential information which does not form part of a file and which is no longer required is disposed of either by being shredded and the shredded papers placed in the appropriate shredding bins or disposed of using the designated confidential waste procedures. Under no circumstances should this information be placed in regular waste paper bins.
    1. Ensure that all whiteboards containing sensitive and/or confidential information are wiped clean unless they are in an area that has been designated as an area that is, either permanently or temporarily, to be kept secure and from which non-authorised staff are excluded.
  1. The responsibility of the business
    1.  The company will make available for the purposes of this policy locking cabinets /locking drawers / individual locking boxes for personal and smaller items / shredding facilities / confidential waste facilities and shall ensure that all employees are made aware of how they are to be used.
    1.  The company will ensure that all electronic data stored on the company’s network is capable of being securely backed up and in the event of a problem able to be accessed as and when necessary.
    1. The company will ensure that all employees are trained in the importance of this policy and in the need to abide by the terms and provisions which it contains. Refresher training will be provided from time to time.
  1. Compliance
    1.  Any exception to the policy must be approved by the company in advance.
    1. Compliance with this policy will be verified using various methods including, but not limited to, periodic walk-throughs, inspections, video monitoring, end-of-day checks.
    1. If any employee shall deliberately or negligently disregard any of the Clean Desk Policy requirements then this may, in the absolute discretion of the company, result in disciplinary action being taken against him/her.
    1. If someone who is not a direct employee of the company shall deliberately or negligently disregard any of the Clean Desk Policy requirements, the company shall take such punitive action against that person and/or his or her employer as the firm in its absolute discretion deems appropriate.
  1. Approval and review details

This policy must be reviewed and updated annually.

The following matters must be considered as pan of each review of this policy:

  1. changes to the legal and regulatory environment;
  1. changes to any codes of conduct to which the company subscribes;
  1. developments in industry best practice;
  1. any new data collected by the company;
  1. any new data processing activities are undertaken by the company, and
  1. any security incidents affecting the company.

More in GDPR and Data Protection

  • DP-01 Data Protection Policy

    Data Protection Policy Document Ref No DP-01 Version No V1 Last review date 02/10/2021 Approved by Dom Tyler Next review 02/10/2022 Table of Contents1...

  • DP-02 Individual Rights Policy

    Individual Rights Request Procedure Document Ref No DP-02 Version No 1 Last review date 02/10/2021 Approved by Dom Tyler Next review 02/10/2022 Contents1...

  • DP-03 Data Protection Impact Assessment Policy

    Data Protection Impact Assessment Policy Document Ref No DP-03 Version No V1.0 Last review date 03/10/2021 Approved by Next review 03/10/2022 Contents1...

  • DP-04 Template Data Protection Impact Assessment

    DATA PROTECTION IMPACT ASSESSMENT (DPIA-01) 1. Data Controller 2. Reference Number DPIA-01 3. Description of Project 4. Purpose of Project Explain broadly what...

  • DP-05 Privacy Policy

    1. This privacy policyThis Privacy Policy applies to the Recycly.com website and associated services and governs data collection, retention and usage. By using...

  • DP-06 Cookies Policy

    1. What is a CookieA cookie is a small file, often encrypted, when you visit web pages. We use cookies to keep track of the options you have selected on our...

  • GDPR > Acceptable Use Policy

    Introduction The Acceptable Use Policy sets out the policies and procedures of Recycly Ltd (the "company") regarding a set of rules applied by the owner...

  • GDPR > Data Breach Policy

    Background: Recycly Ltd understands that your privacy is important to you and that you care about how your information is used and shared online. We respect...

Still stuck? Contact the Recycly support team