Compliance Policy & Digital Governance

Compliance Policy and Digital Governance Framework

Compliance

Purpose

This framework ensures adherence to laws, regulations, and internal policies, and supports the organisation's governance and risk management obligations.

Definition

Compliance is the process of ensuring the organisation follows applicable laws, regulations, industry standards, internal policies, and contractual obligations. Compliance activities span policy creation, staff training, audits and monitoring, risk assessments, incident reporting, and regulatory reporting.

Scope

This policy applies to all employees, contractors, and third-party suppliers, as well as all digital systems and data processing activities operated by or on behalf of Connect Install.

Principles

Connect Install operates a zero-tolerance approach to compliance breaches. All business activities are conducted with ethical conduct and transparency as foundational standards.

Areas of Compliance

The organisation's compliance obligations span GDPR and data protection, health and safety, financial reporting, cybersecurity, and employment law.

 

Data Protection

Definition

Data protection is the practice of safeguarding personal and sensitive information from unauthorised access, misuse, loss, breaches, and corruption. It is both a legal and an operational responsibility.

Key Principles

Connect Install's approach to data protection is aligned with the GDPR principles of lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

Data Protection Controls

Controls in place to protect personal data include access controls, encryption, multi-factor authentication (MFA), secure backups, data retention schedules, privacy notices, and breach response procedures.

Data Types

The organisation processes a range of data types including customer records, employee data, financial data, health information, and supplier information. Each data type is subject to appropriate handling and retention requirements.

Lawful Bases for Processing

All processing activities are recorded in the organisation's Records of Processing Activities (ROPA) in accordance with Article 30 GDPR. Processing is carried out under one or more of the lawful bases set out in Article 6 GDPR.

Data Subject Rights

Procedures are in place to support all data subject rights under GDPR: the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, and the right to object. Requests should be submitted to dataprotection@connectinstall.ie.

Data Retention

Personal data is retained only for as long as necessary for legitimate business, legal, or regulatory purposes. Employee records are retained for 6 years. Financial records are retained for 7 years. Customer data is retained for the duration of the contract plus any applicable legal requirement. All data is subject to secure deletion and disposal processes at the end of the retention period.

Data Breach Response

In the event of a data breach, the response procedure follows a defined sequence: identify the breach, contain the incident, assess impact, notify management, notify the Data Protection Commission if required, notify affected individuals if required, and record corrective actions. A breach register is maintained capturing the date and time, nature of breach, impact assessment, actions taken, and notification status for each incident.

 

Digital Governance

Definition

Digital governance is the framework for managing digital systems, technology, data, and digital operations responsibly and strategically. It ensures that technology aligns with business objectives, digital risks are controlled, data is governed properly, and systems remain secure and compliant.

Areas Covered

The framework covers IT governance, cybersecurity governance, data governance, AI governance, cloud governance, digital risk management, and information management.

Core Components

The digital governance framework consists of governance structures, policies and standards, defined roles and responsibilities, clear decision-making authority, monitoring and reporting mechanisms, and risk management processes.

How Compliance, Data Protection, and Digital Governance Work Together

Compliance focuses on following rules and regulations, with the goal of avoiding legal and regulatory issues. Data protection focuses on protecting personal and sensitive data to prevent breaches and misuse. Digital governance focuses on managing digital operations and technology to ensure strategic and secure digital control. Together, these three areas form an integrated risk and governance framework for the organisation.

Benefits

Organisations with strong compliance, data protection, and digital governance frameworks typically achieve reduced risk, better security posture, regulatory readiness, improved customer trust, better operational control, faster audit response, and improved organisational resilience.

 

Governance Roles and Responsibilities

The Board and Directors hold overall oversight and strategic governance responsibility. Heads of Departments are responsible for regulatory compliance monitoring within their areas. The Data Protection Officer (DPO) provides GDPR and privacy oversight across the organisation. IT Support is responsible for technical governance and security. Department Managers are accountable for operational compliance. Employees are responsible for policy adherence and reporting.

 

Regulatory Register

The following regulations are applicable to Connect Install's operations. GDPR governs personal data processing and is owned by the DPO, with an annual review cycle. Employment Law governs HR operations and is owned by the HR Manager, with an annual review cycle. Health and Safety governs workplace safety and is owned by the relevant Head of Department, with a quarterly review cycle. Cybersecurity Standards govern IT systems and are owned by IT Support, with a quarterly review cycle.

 

Data Classification

Connect Install classifies data across four levels. Public data — such as marketing content — carries a low protection level. Internal data — such as operational procedures — carries a medium protection level. Confidential data — such as financial records — carries a high protection level. Sensitive data — including personal or special category data — carries a critical protection level and is subject to the strictest handling and access controls.

 

IT Governance Framework

Objectives

IT governance objectives are to align technology with business goals, protect digital assets, ensure system availability, and manage technology risk effectively.

Cybersecurity Controls

Security controls in place include MFA enforcement, strong password policies, endpoint protection, encryption, access management, logging and monitoring, and patch management.

Access Control

Access is managed on a role-based model using the principle of least privilege. Joiner, mover, and leaver processes are in place, and regular access reviews are conducted. MFA is required for all privileged accounts.

Acceptable Use

Employees are required to use systems responsibly, protect their credentials, avoid unauthorised software, report suspicious activity, and follow security procedures at all times.

Backup and Disaster Recovery

Daily backups are performed to encrypted storage with offsite and cloud redundancy. Recovery testing is conducted regularly. The Recovery Time Objective (RTO) is 4 hours. The Recovery Point Objective (RPO) is 24 hours.

 

Supporting Documents

This framework should be read in conjunction with the Connect Install IT, Confidentiality and Information Security policies (Handbook Chapter 3) and the Connect Install GDPR Library.

 

Review and Updates

This policy will be reviewed annually or upon legislative or governance changes, or recommendations from auditors, regulators, or legal advisers. Any amendments must be approved by the Board and communicated to all relevant personnel.

 

Approval and Ownership

Framework Owner: Risk & Compliance Lead (Human Resources Manager)

Approved By: Board / Executive Leadership

Effective Date: Q2 FY27

© 2026 Copyright Connect Install. All Rights Reserved.
DUBLIN HQ · IE · UK · EU  |  Production-backed  |  Survey-led
printer