People Group Services
JOINT
EMPLOYMENT
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Information Security Policy

Purpose

The purpose of this Information Security Policy is to protect the confidentiality, integrity, and availability of information assets held by People Group Services Ltd.

Security Objectives

The organisation aims to:

  • Protect personal and corporate information
  • Maintain regulatory compliance
  • Prevent unauthorised access to systems
  • Safeguard client and contractor data
  • Ensure continuity of operations

Information Classification

Information is classified into four categories:

Classification

Description

Public

Information safe for public release

Internal

Non-public internal information

Confidential

Sensitive business information

Restricted

Highly sensitive personal or financial data

Payroll data and contractor records fall under Restricted classification.

Data Handling Requirements

Sensitive information must:

  • Be stored securely
  • Only be accessible by authorised personnel
  • Be transmitted using secure channels
  • Be protected by encryption where appropriate

Data Retention

Information will be retained only for as long as necessary for:

  • Legal obligations
  • Contractual requirements
  • Operational purposes

Secure deletion procedures are used when data is no longer required.

Physical Security

Physical security measures include:

  • Controlled office access
  • Secure storage of documents
  • Visitor access logs
  • Secure disposal of paper records

System Security

Systems are protected through:

  • Authentication controls
  • Security patch management
  • Backup systems
  • Disaster recovery procedures

Third-Party Security

Third-party suppliers must demonstrate adequate security controls before accessing company systems or data.

Contracts must include:

  • Data protection obligations
  • Confidentiality requirements
  • Security responsibilities

Security Awareness

All employees receive training covering:

  • Data protection responsibilities
  • Phishing awareness
  • Secure password practices
  • Incident reporting procedures

Compliance and Enforcement

Failure to comply with this policy may result in:

  • Disciplinary action
  • Contract termination
  • Legal action where appropriate

Policy Review

This policy will be reviewed annually or following major security or regulatory changes.

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 10th March 2026