Cookie policy

What is a cookie?

A cookie is a piece of information in the form of a very small text file that is placed on an internet user’s device. It is generated by a web page server, which is the computer that operates a web site. The information the cookie contains is set by the server and it can be used by that server whenever the user visits the site.

Types of cookies

Cookies can be grouped in the following categories:

Session cookies

These cookies are temporary. They are stored in the devices’ memory only during a user’s browsing session and are automatically deleted from the user’s device when the browser is closed.

Persistent or permanent

These cookies are stored on the user’s device and are not deleted when the browser is closed. Permanent cookies can retain user preferences for a particular web site, allowing those preferences to be used in future browsing sessions. These cookies remain on your device until you erase them or they expire (this depends on how long the visited website has defined the cookie to last).

Here is a list of all the cookies used on this website:

Necessary

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Advertisement

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

Others

Other cookies are those that are being identified and have not been classified into any category as yet.

Site usage and consent

By continuing to use the site we assume that you agree to accept cookies on your device in accordance with this cookie policy. We have detailed where to find information on how to delete and manage cookies.

Deleting and managing cookies

Most web browsers allow you to manage or delete your cookies by accessing the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org . This cookie policy is in relation to Corlann’s website. This statement does not cover links within this site to other websites.

Data Protection Policy

The Data Protection Act and the EU GDPR enacted in May 2018, sets out a framework for the handling of personal data and is supported by eight data protection principles as follows.

  1. Personal data shall be processed fairly and lawfully.
  2. Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
  3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
  4. Personal data shall be accurate and, where necessary, kept up to date.
  5. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
  6. Personal data shall be processed in accordance with the rights of data subjects under this Act.
  7. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
  8. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

Corlann is committed to respecting and protecting the privacy and rights of the people we support, their families, our Employees, students, suppliers, contractors, affiliates and other contacts in accordance with the Data Protection Act and GDPR. This document sets out how Corlann seeks to apply the requirements of the Data Protection Act and GDPR.

Personal data collected by Corlann and how it is used

Corlann will only collect the information required to ensure a quality service delivery. Corlann needs for administrative and operational purposes to collect and process certain data about the People who use our services, Staff, Students, suppliers, ex-staff, and other individuals (i.e. people who enquire about jobs). This information will not be collected via the web site but through the recruitment portal.

Financial information

If an individual makes a donation to Corlann it is paid by Direct Debit, Corlann collects bank account details to enable the transaction to be processed. Corlann does not retain any credit card details as all payments are taken directly through Paypal. Any hard copies of credit card information received are processed and immediately securely destroyed.

Personal data collected and recorded by Corlann’s for commercial services.

The information collected includes: title, name, company name, job title, correspondence address, email address, telephone number, past purchases and requests for future information on products. This information is recorded and reviewed to ensure we are compliant with procurement regulations.

Methods of data collection

Corlann uses several methods for collecting data, including: e-mail and hard copy such as applications to access Services, HRM and Financial information of employees and those who use our services, contractors and professional supports.

Data storage & security

Your data is kept on a secure system. All staff with access to your data are contractually bound to keep this information confidential. All data in transit is encrypted.

Disclosure to third parties

As we are a State Funded Voluntary Body we are obliged to provide various levels of data to third parties under legislation or by request mainly from the following State Agencies (note this list is not definitive other State Bodies and Agencies may request information from us):

HSE – Health Service Executive
HIQA – Health Information Quality Agency
An Garda Síochána
Health & Safety Authority
Health Research Board
Acute Hospitals
Medical/Health Professionals
State Claims Agency
Council of Quality & Leadership
Department of Health
Department of Education and Youth
Department of Justice, Home Affairs and Migration
Department of Employment Affairs & Social Protection
Department of Public Expenditure, NDP Delivery and Reform
Department of Further and Higher Education Research, Innovation & Science
Department of Social Protection
Department of Children, Disability and Equality
Department of Climate Energy and the Environment
Department of Enterprise, Trade and Employment
Department of Housing, Local Government and Heritage

Mailings – Print companies / fulfilment houses

Corlann will only disclose your information to agents who are conducting business on our behalf and only use it for the agreed purposes i.e. contact in relation to issues which may affect your service.

Tuition providers

Staff names, e-mails, roles, and phone numbers may be issued to Tutors with your prior consent.

Details provided in support of employment applications

As an employer Corlann receives verification requests from prospective employers, employment agencies, regulators or other third party contacts we will confirm only that you are an employee and issue reference on request.

Sharing / selling data to third parties

Corlann only shares data internally if appropriate to carry out Services and with those State Agencies listed above. Your data is never sold or made available to a third party.

Retention of data – relevant periods

Corlann has a National Records Management Policy which sets out Retention Periods that are in line with the requirements under various legislation relating to health records, financial records and employee records.

Changes to data

Corlann will review and maintain up-to-date records for all current employees, and past employees for the purpose of administering pensions and references. However it is the responsibility of the individual to ensure that the data held by Corlann is accurate and up-to-date. Individuals should notify their local HR Department of any changes to their circumstances i.e.: address, contact details, email address etc. to ensure accurate records are maintained.

Rights

The Data Protection Act and General Data Protection Regulations gives individuals a right of access to a copy of the information comprising their personal data.

If you wish to access a copy of your data please contact the Regional Data Protection Representative details available under the Data Protection section of this website.

Corlann as a data controller maintains its statutory rights to hold data for as long as is required under legislation and for legitimate purposes.

Right to object

You have the right to object to the use of your personal data if the processing of the data is construed as likely to cause damage or distress.

Notification

Corlann is recognised as the Data Controller by the Data Protection Commissioner’s Office. See Data Protection Page for individual user privacy notices.

APPENDIX 1 GLOSSARY OF TERMS AND DEFINITIONS

Data Means: Information which is being processed by means of equipment operating automatically in response to instructions given for that purpose; is recorded with the intention it should be processed by means of such equipment; is recorded as part of a relevant filing system or with the intention that it should form part of a filing system. The Act refers to a relevant filing system as any paper or manual filing system which is structured in such a way as to make that information about an individual readily accessible.

“Biometric data” means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyl-scopic data.

“Personal data” is data relating to a living individual who can be identified from that data or information which is in the possession of, or is likely to come into the possession of, the data controller. This includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.

“Binding Corporate Rules” means personal data protection policies which are adhered to by Corlann for transfers of personal data to a controller or processor in one or more third countries or to an international organisation.

“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Cross Border Processing” means processing of personal data which takes place in more than one Member State; or which substantially affects or is likely to affect data subjects in more than one Member State

“Data controller” means, means any person (or organisation) that determines the purposes for which and the manner in which any personal data are, or are to be, processed. The data controller has a responsibility to ensure all files relating to individuals are kept securely, are accurate, are up-to-date and are used only for the purposes specified. A data controller must be a “person” recognised in law; this would be individuals, organisations and other corporate or unincorporated bodies of persons. Corlann is a data controller.

“Data processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

“Data protection laws” means for the purposes of this document, the Data Protection Act and the EU General Data Protection Regulations (GDPR), and any other relevant data protection laws that are introduced by the EU and the Irish State.

“Data subject” means an individual who is the subject of personal data

“GDPR” means the General Data Protection Regulation (EU) (2016/679)

“Genetic data” means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.

“Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. In essence data processing, means obtaining, recording or holding the information or data or carrying out any operations on the information or data i.e.: viewing, amending, copying, extracting storing, disclosing, destroying, deleting etc.

“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

“Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

“Supervisory Authority” means an independent public authority – Data Protection Commissioner’ Office – (see contact details below)

“Third Party” means any individual and or organisation other than the data subject or the data controller.

“Regional Data Protection Representative means the Data Protection administrator identified in each of the five Corlann Regions. Each Region has a Data Protection Representative (DPR).

Data Protection Officer’s role is defined in the Data Protection Bill 2018 as someone appointed by the organisation who informs, advises and monitors, the controller, in this case Corlann, and its employees who carry out processing, of their obligations under the Data Protection Law and GDPR. Corlann has appointed a Data Protection Officer in line with GDPR Regulations Contact. dpo@Corlann.ie

APPENDIX 2 DATA PROTECTION COMMISSIONER

Contact Details: https://dataprotection.ie/en/contact/how-contact-us

 

Update your consent preferences