Information Security Policy
Policy Statement
TransformGen CIC is committed to protecting the confidentiality, integrity, and availability of all information it holds, including personal data, organisational data, and sensitive information. We recognise that effective information security is essential to maintaining trust, complying with UK GDPR, and ensuring the safe delivery of our services.
Purpose of this Policy
This policy sets out how TransformGen CIC manages and protects information against unauthorised access, loss, misuse, disclosure, or damage.
It aims to:
- Protect information assets
- Reduce the risk of data breaches and cyber incidents
- Ensure safe handling of digital and physical information
- Support compliance with legal and regulatory requirements
- Promote good security practices among staff and volunteers
Scope
This policy applies to:
- Staff
- Volunteers
- Trustees
- Contractors and freelancers
- Any third parties handling information on behalf of TransformGen CIC
It covers all forms of information, including:
- Digital data (emails, files, databases, cloud storage)
- Paper records
- Communications (phone, messaging, online platforms)
Information Security Principles
TransformGen CIC follows these core principles:
Confidentiality Information is only accessible to authorised individuals
Integrity Information is accurate, complete, and protected from unauthorised modification
Availability Information is accessible when needed by authorised users
Access Control
We ensure that:
- Access to information is restricted on a need-to-know basis
- Strong passwords are used and kept confidential
- Accounts are not shared between individuals
- Access is removed promptly when staff or volunteers leave
- Multi-factor authentication is used where available
Device Security
All devices used to access organisational information must:
- Be password or PIN protected
- Use up-to-date antivirus or security software where applicable
- Be kept secure when not in use
- Avoid accessing sensitive data on public or unsecured Wi-Fi where possible
Data Storage and Handling
We ensure that:
- Digital data is stored on secure systems or approved cloud services
- Paper records are stored in locked or restricted-access locations
- Sensitive information is not left unattended
- Unnecessary data is securely deleted or destroyed
Email and Communication Security
Staff and volunteers must:
• Use official email accounts for organisational communication
• Avoid sending sensitive data via unsecured channels
• Double-check recipients before sending emails
• Be alert to phishing emails and suspicious links
Third-Party Services
Where third-party providers are used (e.g. cloud storage, email platforms), we ensure that:
- Providers are reputable and GDPR-compliant
- Appropriate data processing agreements are in place where required
- Access is reviewed regularly
Incident and Breach Management
All suspected or actual information security incidents must be reported immediately to:
Chikodi Oraka / Data Protection Lead
Incidents may include:
- Lost or stolen devices
- Unauthorised access to systems
- Accidental sharing of sensitive data
- Malware or phishing attacks
Where necessary, incidents may be escalated to the Information Commissioner’s Office (ICO).
Remote Working
Where staff or volunteers work remotely, they must:
- Ensure devices are secure and password protected
- Avoid leaving devices unattended in public spaces
- Use secure internet connections where possible
- Store documents securely and avoid local unencrypted storage where possible
Training and Awareness
TransformGen CIC will ensure that staff and volunteers receive appropriate training on:
- Information security risks
- Safe data handling practices
- Recognising phishing and cyber threats
- Reporting incidents
Monitoring and Review
We will regularly review information security practices to ensure they remain effective, up to date, and aligned with legal requirements and organisational needs.
Policy Review
This policy will be reviewed annually or sooner if there are significant changes to technology, legislation, or organisational operations.
Approved by: Chikodi Oraka
Position: Director
Date: 17th May 2026
Review Date: 17th May 2027
