Welcome to EMGHR’s statement on GDPR and Data Security. This document should be read in conjunction with our main Privacy Policy.
Accountability: We are committed to upholding the principles of the General Data Protection Regulation (GDPR) by embedding a privacy-by-design approach throughout our operations. We demonstrate accountability through robust data protection policies, effective systems and controls, and the appointment of a Data Protection Officer who oversees compliance with data protection legislation, including the management of data subject access requests. Our policies are reviewed and updated regularly, and all employees receive ongoing training throughout the year to ensure continued awareness of data protection, privacy, and information security requirements.
Transparency, Fairness and Lawfulness: We process personal data in a fair, transparent, and lawful manner, always considering the rights and interests of data subjects. Transparency is embedded in our processing activities to ensure individuals understand how and why their data is used. We have established robust policies and procedures to support compliance with data protection legislation, including an efficient process for managing and responding to data subject access requests and other individual rights requests.
Data Integrity and Confidentiality: Information security and integrity is key to our smooth operation and we have a dedicated cyber security team who protect our systems.
Data Minimisation and Data Storage: We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected and where a lawful basis for retention exists. Once data is no longer required, it is securely deleted, destroyed, or anonymised in accordance with recognised industry standards and applicable data protection legislation, ensuring that all disposal activities are carried out in a compliant and secure manner.
Data Accuracy: Keeping data accurate is very important to us and we train our staff to ensure they are maintaining data to a high quality and with all the facts available.
Purpose Limitation: We collect and process personal data for clearly defined, legitimate purposes and ensure that it is used only in ways that are consistent with those purposes. We do not process personal data for purposes that are incompatible with the reasons for which it was originally collected, unless permitted by law or with the appropriate legal basis. The tables below outline our approach to data protection across key areas of our operations, providing transparency on the standards, principles, and practices that guide our processing activities. If you have any questions regarding the information
contained in this document or wish to exercise any of your data protection rights, please contact our Data Protection Officer at info@emghr.ie, who will be happy to provide further information and assistance.
| Software and Applications | Software applications are developed, maintained, and managed in accordance with established Agile software development practices. Following the implementation of any system change, comprehensive end-to-end testing is conducted to verify the accuracy of the update and to ensure that existing functionality remains unaffected.
Only approved software applications are permitted for use within the organisation. Software deployment, management, and patching are centrally controlled through our software management processes, ensuring that all authorised applications remain secure and up to date. All software is appropriately packaged, tested, and released in line with defined change management procedures. Operating systems are fully supported and regularly patched to address security vulnerabilities and maintain system integrity. We utilise Windows 11 desktops and laptops, with security and operating system updates applied automatically to ensure ongoing protection and compliance. Sensitive or confidential information is not stored on systems that do not meet our security, compliance, and configuration standards, helping to safeguard personal and business data from unauthorised access or loss.
|
| Network Access | Access to our internal network and systems is restricted through Active Directory security controls, ensuring that only authorised users can access corporate resources. Internal systems are accessible only through our secure corporate network, providing an additional layer of protection against unauthorised access. Strong password controls are enforced across all devices, including complexity requirements and regular password updates in accordance with our security policies. User access rights are managed through Active Directory permissions and are granted on a least-privilege basis, ensuring that individuals have access only to the information and systems necessary to perform their roles. These measures help to protect the confidentiality, integrity, and availability of the data and systems entrusted to us. |
| VPN Access | All remote access via remote working employees is secured by VPN log on technology and you are unable to access the networks unless a secure VPN connection has been established. |
| Encryption | All databases, software and hardware/devices are protected with high levels of encryption. Encryption keys are managed with strict policies and procedures. The key is stored in a secure location which is only accessible to database admins. |
| Testing | On our equipment, all patches are governed by the change control process which includes evaluation, testing and deployment. |
| System Updates | We update systems when the time is appropriate to ensure we are always using the most advanced technical and organisational tools out there. |
| Data Back Ups | Data is backed up daily and a data restore process has been tested. Measures are in place to ensure that the business can continue to function should a compromise occur.
Performance monitoring and file integrity monitoring is in place to ensure our business continuity plan can take full effect. |
| Monitoring and testing | We follow a standardised system build process to ensure that all default administrator, vendor-supplied, and unnecessary accounts are removed or disabled before deployment. This reduces the risk of unauthorised access and strengthens the security of our IT environment.
Our network infrastructure is subject to regular monitoring and review to identify and address any deviations from established security standards and data loss prevention controls. This enables us to detect potential risks promptly and maintain compliance with our information security requirements. In addition, regular penetration testing is conducted at both the network and application levels to assess the effectiveness of our security controls and identify potential vulnerabilities. Findings are reviewed and remediated as part of our ongoing commitment to maintaining a secure and resilient technology environment. |
| Cloud Providers | We utilise secure cloud-based hosting and storage solutions to support the processing and storage of personal data. Where cloud services are used, we ensure that appropriate technical and organisational security measures are implemented, regularly reviewed, and tested to maintain the confidentiality, integrity, and availability of the data.
Our CRM platform is hosted on secure cloud-based infrastructure designed to meet recognised security and reliability standards. All personal data is stored within the European Union (EU) or the United Kingdom (UK). We do not transfer personal data outside the European Economic Area (EEA) unless appropriate safeguards are in place and such transfers are carried out in compliance with applicable data protection legislation. Alternative (if no data ever leaves the EU/UK): We utilise secure cloud-based services for the processing and storage of personal data, with security controls that are regularly monitored, reviewed, and tested. Our CRM system operates on a secure cloud infrastructure, ensuring resilience, availability, and data protection. All personal data is hosted within the EU or UK, and no personal data is transferred outside the European Economic Area (EEA). This approach helps ensure compliance with GDPR and maintains a high standard of data security and governance. |
| Cyber Security | We implement a multi-layered security framework to protect our networks, systems, and data. Firewalls, antivirus software, and advanced malware protection are deployed across all endpoints to detect, prevent, and respond to potential security threats.
Applications that are accessible via the internet are regularly monitored and secured against common web application vulnerabilities, including cross-site scripting (XSS), SQL injection, and other emerging cyber threats. Security controls are continuously reviewed and updated to maintain a strong security posture. External connectivity is protected by enterprise-grade, resilient firewalls, supported by dedicated security monitoring technologies such as Security Information and Event Management (SIEM), Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS). These controls help identify, investigate, and mitigate potential security incidents in a timely manner. Internet usage is managed through dedicated web filtering solutions that restrict access to inappropriate, malicious, or unauthorised websites and control the types of traffic permitted across the network. Firewalls and network monitoring tools continuously inspect and manage inbound and outbound traffic to help safeguard organisational systems and data from unauthorised access and cyber threats. Sensitive and confidential data is processed within secure business systems, including our CRM platform, which are protected by appropriate technical and organisational security measures. In addition, comprehensive security monitoring capabilities, including a dedicated SIEM platform, provide ongoing visibility of the technology environment and support the proactive detection and response to security events. |
| Third Party | We ensure that all third-party service providers and partners are subject to appropriate contractual data protection and information security obligations. These agreements require compliance with applicable data protection legislation, including the GDPR, and help ensure that personal data is processed securely and responsibly throughout the relationship. Where a third party acts as a data processor on our behalf, we implement Data Processing Agreements (DPAs) or incorporate equivalent data protection provisions into our contractual terms and conditions. These arrangements clearly define each party’s responsibilities in relation to the processing and protection of personal data. Where required, we also implement additional transfer safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs), to ensure that personal data remains protected when processed by third parties and that any international data transfers comply with applicable data protection requirements. |
| Staff Security |
We are committed to maintaining a secure and trustworthy workforce through robust recruitment, onboarding, and information security practices. Where appropriate, prospective employees undergo screening and verification processes before employment commences, including validation of qualifications, employment history, and other relevant credentials. All employees receive a comprehensive induction programme that includes training on data protection, confidentiality, information security, and their responsibilities under applicable policies and procedures. This training is reinforced through ongoing awareness initiatives, periodic refresher sessions, and internal communications to ensure staff remain informed of evolving security and compliance requirements. Each employee is provided with an Employee Handbook outlining organisational policies, standards, and expectations. The handbook is reviewed and updated regularly, with employees notified of any significant changes or additions. Confidentiality and data protection obligations form a key part of our employment arrangements. Employees are required to comply with confidentiality requirements and, where appropriate, restrictive covenant provisions designed to protect company and client information. Access to systems and data is controlled through strong authentication measures, including password complexity requirements and regular password updates. When an employee leaves the organisation, their access to all systems, applications, and facilities is revoked promptly to prevent unauthorised access. We maintain a clear desk and clear screen policy to reduce the risk of unauthorised disclosure of information. Employees are expected to secure their workstations whenever they are away from their desks and to handle company information responsibly at all times. Specific data security procedures are in place for remote and mobile working arrangements to ensure that personal and confidential information remains protected regardless of where work is undertaken. To minimise the risk of data loss or unauthorised disclosure, employees are prohibited from storing company or client data on removable media, such as USB devices, or on unauthorised local device storage. All information must be stored and managed through approved and secure business systems and platforms. |
| Data Retention | All data retention activities are managed in accordance with our Data Retention and Disposal Policy. We adopt a practical and compliant approach to the retention, management, and disposal of information, taking into account our legal, regulatory, contractual, and business obligations across Ireland and the United Kingdom.
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and to meet applicable statutory, contractual, and operational requirements. Once the applicable retention period has expired, information is securely deleted, destroyed, or anonymised in accordance with our established procedures. As a general principle, client records are retained for a period of seven years following the termination or completion of the contractual relationship, unless a longer retention period is required by law, regulation, or specific contractual obligations. |
| Data Disposal | As an organisation, we are committed to a digital-first approach and seek to minimise the use of paper records wherever practicable. This helps enhance data security, improve operational efficiency, and support our environmental objectives.
Where confidential paper records are generated or retained, secure disposal arrangements are in place. Confidential waste is collected and destroyed by an approved and vetted third-party provider, who issues a Certificate of Destruction to verify that all materials have been securely and permanently disposed of. We also maintain a formal hardware disposal process to ensure that all end-of-life IT equipment is managed securely. Prior to disposal, storage media is securely wiped using recognised industry-standard methods to prevent data recovery. Hardware is then destroyed or recycled through an accredited disposal provider, with a Certificate of Destruction obtained as evidence of secure disposal. These measures help ensure that both physical and electronic information assets are disposed of securely and in accordance with our data protection, information security, and regulatory obligations. |
EMGHR has designated a Data Protection Officer to oversee compliance with data protection legislation and to act as a point of contact for data subjects, clients, regulators, and other stakeholders. The Data Protection Officer can be contacted in relation to any aspect of this Privacy Policy, our data processing activities, or the operation of our Data Privacy Management System.
We encourage individuals to contact us if they require further information regarding the processing of their personal data or wish to exercise any of their data protection rights. We are committed to addressing all enquiries in a fair, transparent, and timely manner.
Data Protection Officer
Email: info@emghr.iePostal Address:
EMGHR Ltd
10 Elvana, Stamullen, Co. Meath, K32VY74
Ireland
GDPR Oversight Team: info@emghr.ie
If you are unhappy with the response that you receive from us when you exercise your GDPR rights, you have the right to lodge a complaint to the DPC.
This version was last updated and reviewed: March 2026.
We regularly review and monitor regulatory guidance for any industry changes which may impact our business operations or your rights and freedoms.
Copyright © EMGHR Limited 2026