My Vital Metrics – Information Governance Policy

Last updated: January 2025

1. Policy Statement

My Vital Metrics is committed to maintaining high standards of information governance across all areas of operation. We ensure that personal, confidential, and commercially sensitive information is handled lawfully, securely, and responsibly. This policy outlines our approach to information governance, covering confidentiality, data integrity, information security, access management, and compliance with UK legislation, including the Data Protection Act 2018 and UK GDPR.

2. Purpose

The purpose of this policy is to ensure that all information used by My Vital Metrics is managed properly, protected against misuse or loss, and accessible to authorised personnel when required. This includes ensuring that all staff understand their roles and responsibilities in maintaining high standards of information governance.

3. Scope

This policy applies to all staff, contractors, trainees, and temporary workers, as well as all systems, devices, and platforms used to store or process information at My Vital Metrics. It covers all forms of information including electronic data, paper records, emails, client test results, booking information, employee records, operational documents, and digital communications.

4. Principles of Information Governance

My Vital Metrics follows the principles of good information governance, ensuring that: Information is processed legally, securely, and transparently. Access to confidential information is restricted to authorised individuals. Information is accurate, complete, and stored appropriately. Information is available when required for legitimate business functions. Staff are trained in confidentiality, data protection, and secure information-handling practices.

5. Information Security

We implement appropriate organisational and technical measures to protect information, including: Secure access controls and role-based permissions. Password protection and multi-factor authentication where applicable. Up-to-date antivirus, firewall, and security patching. Encrypted storage and secure data transfer. Regular backups of critical systems and data. Routine audits of access logs and digital systems.

6. Confidentiality

All staff must protect confidential information, including client records, staff information, financial data, and operational documents. Confidentiality agreements form part of staff contracts and must be followed at all times. Information must not be disclosed to unauthorised individuals inside or outside the organisation.

7. Information Handling and Storage

Information must be handled with care and stored securely. Electronic data must be stored on approved systems with controlled access. Paper records, where used, must be stored in locked cabinets or restricted areas. Unauthorised storage of personal data on personal devices or unapproved cloud platforms is prohibited.

8. Access Management

Access to systems and information is granted only where necessary for staff to perform their duties. User access rights are reviewed regularly. When staff leave the organisation, all access to systems and data is revoked promptly.

9. Data Quality and Accuracy

My Vital Metrics ensures that all information, particularly test results, client records, and staff data, is accurate, up to date, and recorded consistently. Errors or inaccuracies must be corrected as soon as identified.

10. Sharing of Information

Information may be shared only when necessary for service delivery, operational needs, or legal compliance. All sharing must be lawful, proportionate, and secure. Third parties receiving information must meet appropriate confidentiality and data-protection standards. Information is never sold or shared for non-essential purposes.

11. Incident Management

Any incident involving the loss, unauthorised disclosure, or misuse of information must be reported immediately to management. All incidents are investigated promptly, with appropriate corrective actions implemented. Where required, regulatory bodies will be notified in line with legal obligations.

12. Staff Training and Responsibilities

All staff receive training in information governance, confidentiality, and secure information handling. Staff are responsible for following all policies and procedures, reporting concerns, and maintaining high standards of information security at all times.

13. Review and Monitoring

My Vital Metrics reviews this Information Governance Policy annually or sooner if required due to changes in legislation, technology, or business operations. Compliance with this policy is monitored through audits, system checks, and management review.

14. Contact Details

For information governance enquiries, individuals may contact: Information Governance Lead – My Vital Metrics Email: info@myvitalmetrics.com All enquiries will be handled promptly and in accordance with relevant legislation.