1.0 INTRODUCTION
Deon & Noed International-Ghana (DNI-Ghana) is a professional services firm providing audit, tax, human resources, advisory and related professional services.
In the course of providing our services and conducting our business, the firm may collect, receive, access, use, record, organize, store, retain, disclose, transfer, transmit, modify, retrieve, analyze and otherwise process personal data relating to clients, prospective clients, employees, job applicants, contractors, consultants, suppliers, service providers, business contacts, directors, shareholders, beneficiaries, representatives of client organizations, and other individuals whose personal data comes into our possession or control in connection with our professional activities, business operations, contractual relationships, or the provision of our services.
DNI-Ghana recognizes that personal data is entrusted to us in circumstances requiring a high degree of confidentiality, professional integrity and accountability. DNI-Ghana is therefore committed to protecting personal data and respecting the privacy rights of individuals in accordance with applicable laws and statutes while recognizing international data protection principles.
This Policy explains how DNI-Ghana processes personal data, the purposes for which the firm processes it, the circumstances in which the firm may disclose or transfer it, the safeguards being applied, and the rights available to individuals.
This Policy is intended to operate alongside the firm’s professional confidentiality obligations, engagement letters, employment policies, information-security policies, records-management procedures, contractual obligations and other applicable internal policies.
Where a specific engagement or legal obligation imposes a higher standard of confidentiality or data protection than this Policy, the higher standard shall apply to the extent legally permissible.
2.0 LEGAL, REGULATORY FRAMEWORK AND SCOPE
1. This Policy is principally governed by the laws applicable to the processing of personal data in Ghana, including:
The Constitution of the Republic of Ghana, 1992, Article 18(2), 21(1)(f).
The Data Protection Act, 2012 (Act 843).
Applicable regulations, directives, guidance and decisions issued by the Data Protection Commission (DPC).
The Cybersecurity Act, 2020 (Act 1038), where applicable to the Firm's cybersecurity and information-security obligations.
Applicable tax, employment, company, anti-money laundering, audit, accounting and professional-regulatory legislation.
Applicable requirements of the Institute of Chartered Accountants, Ghana (ICAG) and other professional or regulatory bodies governing the Firm or a particular engagement.
Applicable contractual and professional confidentiality obligations.
2. The Data Protection Act establishes principles including accountability, lawfulness of processing, specification of purpose, compatibility of further processing, quality of information, openness, data security safeguards and data subject participation.
3. Where DNI-Ghana processes personal data originating from another jurisdiction or provides services involving individuals located outside Ghana, additional foreign data-protection laws may apply.
4. Where more than one legal regime applies, DNI-Ghana will seek to comply with all mandatory requirements applicable to the processing activity. Where legally permissible, the Firm may adopt the higher or more protective standard, where doing so does not conflict with mandatory Ghanaian law or another applicable legal requirement.
2.1 SCOPE
1. This Policy applies to:
All employees, partners, directors, managers, trainees, secondees, consultants, contractors and other personnel of Deon & Noed International-Ghana.
All departments and business units of the Firm.
All personal data processed by or on behalf of the Firm.
All physical and electronic records containing personal data.
All client, employee, recruitment, supplier, marketing and administrative information.
All Firm websites, online platforms, client portals and electronic communication channels.
Third-party service providers processing personal data on behalf of the Firm, to the extent required by contract and applicable law.
2. This Policy applies regardless of whether information is collected directly from an individual or obtained from a client, employer, regulator, public source, service provider, professional adviser or another third party.
3.0 DEFINITIONS OF TERMS
1. For purposes of this Policy:
Personal Data means information relating to an natural persons or representatives of clients organizations.
Data Subject means the individual to whom personal data relates.
Processing includes collecting, recording, organizing, storing, retrieving, analyzing, disclosing, transferring, restricting, deleting or destroying personal data.
Data Controller means a person or organization that determines the purposes and manner in which personal data is processed.
Data Processor means a person or organization that processes personal data on behalf of a data controller.
Special Personal Data means personal data requiring enhanced protection under applicable law, including information concerning matters such as health, biometric information, religious or political beliefs, racial or ethnic origin, sexual life and orientation, criminal matters or other categories protected by law.
Data Protection Supervisor or DPS means the person appointed by DNI Ghana to oversee compliance with applicable data-protection requirements in Ghana.
Personal Data Breach means a security incident resulting in or reasonably likely to result in, accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to personal data.
Data Protection Commission means the statutory regulator responsible for enforcing Ghana's data protection framework.
4.0 DEON & NOED’s ROLE AS A DATA CONTROLLER AND DATA PROCESSOR
1. DNI may act as a data controller, data processor, or both, depending on the nature of a particular activity. In doing so, the firm may act as a data controller when processing:
Employee information
Job applications
Supplier information
Business-contact information
Information required for the firm’s administration
Information collected through its website
Personal information required to manage its own professional and regulatory obligations.
2. The firm may act as a data processor when processing personal data on behalf of a client, particularly in certain HR, payroll, recruitment, advisory, outsourcing or consultancy engagements.
The applicable engagement letter, statement of work or data-processing agreement shall determine the respective responsibilities of DNI and the client where the Firm acts as a processor.
3. Where DNI Ghana acts as a processor, it shall process personal data only on documented instructions from the relevant controller, subject to applicable law.
5.0 DATA PROTECTION PRINCIPLES
Deon & Noed International-Ghana shall process personal data in accordance with the following principles.
5.1 Accountability
The Firm shall be responsible for demonstrating compliance with applicable data-protection obligations and shall maintain appropriate policies, procedures, records and controls.
5.2 Lawfulness and Fairness
Personal data shall be processed lawfully, fairly and reasonably and shall not be processed in a manner that unjustifiably infringes the privacy rights of an individual.
5.3 Purpose Limitation
Personal data shall be collected for specified, explicit and legitimate purposes and shall not subsequently be used for incompatible purposes unless permitted by law or otherwise lawfully authorised.
5.4 Data Minimisation
The Firm shall collect and process only personal data that is adequate, relevant and reasonably necessary for the identified purpose.
5.5 Accuracy and Quality
The Firm shall take reasonable steps to ensure that personal data is complete, accurate, current and not misleading having regard to the purpose for which it is processed.
5.6 Transparency and Openness
Individuals shall in reflecting the express transparency obligation under Section 34 of Act 843, be informed about:
the nature of information being collected
the identity of the person responsible for processing
the purpose of processing
whether providing the information is mandatory or discretionary
the consequences of not providing required information
applicable recipients
the categories of information collected
applicable rights.
5.7 Security
The Firm shall implement appropriate technical and organisational measures to protect personal data against unauthorised access, unlawful processing, accidental loss, destruction, alteration or disclosure.
5.8 Storage Limitation
Personal data shall not be retained for longer than reasonably necessary, subject to legal, regulatory, professional, contractual and legitimate business requirements.
5.9 Data Subject Participation
The Firm shall provide reasonable mechanisms through which individuals may exercise rights granted under applicable law.
6.0 CATEGORIES OF PERSONAL DATA PROCESSED
Depending on the nature of our relationship with an individual, Deon & Noed International-Ghana may process:
6.1 Identification Information
This may include;
full name
date of birth
photograph
passport information
national identification information
signatures
nationality
residential or business address
6.2 Contact Information
This may include:
telephone numbers
email addresses
postal addresses
emergency contact information
professional contact information
6.3 Professional and Employment Information
This may include;
curriculum vitae and applications
educational qualifications
employment history
professional memberships
references
performance information
remuneration information
disciplinary information
training records
leave information
employment contracts
6.4 Financial and Tax Information
Where relevant to an engagement, the Firm may process:
bank details
tax identification information
payroll information
income information
financial statements
transaction records
payment information
accounting records
information relating to assets, liabilities and financial interests.
6.5 Audit, Tax and Client Information
Depending on the engagement, information may include:
customer records
supplier records
employee information
director and shareholder information
beneficial ownership information
transaction information
tax records
financial statements
correspondence
identification and know your client (KYC) documentation
information obtained for statutory, regulatory or professional purposes
6.6 Human Resources and Employee Information
The Firm may process employee information relating to:
recruitment
employment
payroll
benefits
performance
attendance
leave
disciplinary and grievance matters
workplace investigations
training
health and occupational matters where lawfully required
emergency contacts
6.7 Website and Digital Information
This may include:
IP address
browser information
device information
approximate location
website interaction data
cookies and similar technologies
information submitted through online forms
client-portal information.
6.8 Special Personal Data
Where necessary and lawful, the Firm may process special personal data, including health, biometric, criminal records or other sensitive information.
Such information shall receive enhanced safeguards and shall only be processed where an appropriate legal basis and, where required, an additional statutory condition exist.
7.0 SOURCES OF PERSONAL DATA
1. DNI Ghana may obtain personal data from:
the individual directly
a client or prospective client
an individual's employer or organisation
employees and job applicants
authorised representatives
government departments and regulators
publicly available registers and sources
professional advisers
referees and background-screening providers
service providers
business partners
websites and digital platforms
other lawful sources.
2. Where personal data is obtained from a third party, the Firm shall take reasonable steps to ensure that the collection and subsequent processing are lawful and compatible with the relevant purpose.
8.0 PURPOSES OF PROCESSING
DNI Ghana may process personal data for purposes including:
8.1Professional Services
providing audit and assurance services
providing tax services
providing HR and people advisory services
providing management and business advisory services
conducting financial and operational reviews
conducting due diligence
supporting client engagements
preparing reports and professional deliverables
8.2 Regulatory and Legal Compliance
complying with legal and regulatory obligations
responding to lawful requests from regulators and public authorities
satisfying audit and professional requirements
performing KYC and anti-money-laundering checks
meeting tax obligations
preventing fraud and financial crime;
establishing, exercising or defending legal claims.
8.3 Human Resources
recruiting personnel
administering employment
processing payroll and benefits
managing performance
maintaining employee records
administering leave
workplace investigations
health and safety
complying with employment and social-security obligations
8.4 Business Administration
billing and collections
maintaining financial records
managing suppliers
managing client relationships
maintaining internal systems
risk management
quality assurance
professional indemnity and insurance matters
8.5 Marketing and Communications
Subject to applicable law, the firm may use business contact information to communicate information about services, publications, events or other firm activities.
Direct marketing shall be conducted in accordance with applicable Ghanaian law. In particular, the firm shall not use personal data for direct marketing where prior written consent is required unless that consent has been obtained.
9.0 LEGAL BASES FOR PROCESSING AND CONSENT
1. Depending on the circumstances and applicable law, Deon & Noed International-Ghana may process personal data where processing is:
necessary for the performance of a contract
necessary to take steps requested by an individual before entering into a contract
required by law
necessary for legitimate professional or business purposes that do not unjustifiably override the rights and interests of the individual
based on the individual's consent
necessary to protect vital interests
otherwise permitted under applicable law
2. Consent shall not be treated as the default basis for every processing activity.
3. Where processing is based on consent, the Firm shall ensure that consent is appropriately informed and capable of being withdrawn, subject to applicable legal limitations.
4. Withdrawal of consent shall not invalidate processing lawfully conducted before the withdrawal.
9.1 CONSENT
1. Where Deon & Noed International-Ghana relies on consent, consent shall be:
informed
specific
voluntary
capable of being demonstrated
appropriately documented and
capable of withdrawal
2. Consent shall not ordinarily be bundled into unrelated terms where the individual should reasonably be able to choose whether to consent.
3. The firm shall maintain appropriate records of consent where consent is relied upon.
10.0 DATA SUBJECT RIGHTS
1. Subject to applicable law and legitimate exceptions, individuals may have the right to:
be informed about the processing of their personal data
request access to personal data held about them
obtain information concerning the purposes for which their data is processed
know applicable recipients or categories of recipients
request correction of inaccurate or incomplete information
object to specified processing
prevent processing that causes or is likely to cause unwarranted damage or distress
withdraw consent where consent is the basis of processing
object to direct marketing
request deletion, blocking, destruction or cessation of processing where provided by law
object to certain automated decision-making
lodge a complaint
seek compensation where applicable law provides such a remedy
2. Requests should be submitted in writing to the firm's Data Protection Supervisor using the contact details contained in Section 38(1) of this Policy.
3. The firm may request reasonable information necessary to verify the identity of the requester before releasing personal data.
4. The firm may refuse or limit a request, where permitted or required by law, including where compliance would conflict with statutory retention obligations, legal proceedings, regulatory obligations, professional confidentiality or the rights of another person.
11.0 DATA SUBJECT REQUEST PROCEDURE
1. Upon receiving a data-protection request, the Firm shall:
record the request
verify the identity of the requester, where reasonably necessary
identify the relevant systems, files and personnel
determine whether the Firm is controller, processor or another relevant party
assess applicable legal restrictions and exemptions
consult the Data Protection Supervisor where appropriate
respond within the applicable statutory period
maintain a record of the request and the action taken
2. Where a request cannot be granted, the firm shall, within the applicable statutory period ,where legally permissible, explain the reason for the refusal or limitation.
12.0 DISCLOSURE OF PERSONAL DATA
1. Deon & Noed International-Ghana shall not disclose personal data except where the disclosure is lawful and reasonably necessary.
2. Recipients may include:
affiliated or associated professional entities
clients and authorised representatives
regulators
tax authorities
courts of competent jurisdiction and law enforcement bodies
professional and regulatory organisations
insurers
external advisers
auditors
banks and payment providers
cloud and technology providers
payroll and HR service providers
background screening providers
other contractors and professional service providers and
prospective successors in connection with a merger, restructuring, acquisition or transfer of business
3. The firm shall apply appropriate confidentiality, contractual and security controls to third parties receiving personal data.
4. DNI does not sell personal data.
5. The firm shall not disclose personal data for unrelated third-party marketing purposes unless permitted by law and appropriately authorised.
13.0 PROFESSIONAL CONFIDENTIALITY
1. Deon & Noed International-Ghana operates as an audit, tax, HR and advisory firm hence personal data may be contained within information that is subject to professional confidentiality.
2. Personal data obtained during a professional engagement shall:
be used only for authorised engagement and lawful purposes
be accessible only to personnel who require access
be protected against unauthorised disclosure
not be disclosed outside the engagement team without proper authority
remain subject to applicable professional and legal obligations after completion of an engagement
3. Nothing in this Policy overrides a legal obligation requiring disclosure to a competent authority, regulator, court of competent jurisdiction or other persons acting in law enforcement capacity.
4.Where disclosure is legally required, the firm shall disclose only information reasonably necessary for the relevant purpose, subject to applicable law.
14.0 CLIENT DATA AND HR ADVISORY ENGAGEMENTS
1. Where Deon & Noed International-Ghana processes personal data belonging to employees, customers or other individuals of a client organisation, the firm shall determine its role under applicable law.
2. Where the firm acts as a processor, it shall:
process information only for authorised purposes
follow documented client instructions
maintain appropriate confidentiality
apply appropriate security measures
restrict access to authorised personnel
ensure relevant subcontractors are appropriately bound
notify the client of relevant personal-data incidents as required by contract and law
return, delete or otherwise handle information at the end of the engagement in accordance with applicable instructions and legal retention obligations
3. Where the firm independently determines the purposes and means of processing, it may be acting as a controller and shall comply with the corresponding obligations.
15.0 DATA SHARING WITH SERVICE PROVIDERS
1. The Firm may appoint third-party providers for functions including:
cloud hosting
document management
email
cybersecurity
payroll
HR management
accounting
communications
IT support
document destruction
background checks
professional research
other operational services
2. Before appointing a provider that will process material amounts of personal data, the firm shall conduct proportionate due diligence and assess the provider's security, confidentiality and data protection practices.
3. Where required, contracts shall include provisions addressing:
permitted processing
confidentiality
security
access controls
subcontracting
data breaches
assistance with data-subject requests
retention and deletion
audits or assurance
international transfers
termination
16.0 INTERNATIONAL AND CROSS-BORDER DATA TRANSFERS
1. Deon & Noed International-Ghana may transfer personal data outside Ghana where necessary for:
international client engagements
group or affiliate support
cloud hosting
technology services
professional collaboration
regulatory or legal purposes
international HR or mobility services
other legitimate professional purposes
2. Cross-border transfers shall only be made where legally permissible and where appropriate safeguards have been assessed.
3. Depending on the applicable legal framework, safeguards may include:
contractual data-protection provisions
approved standard contractual clauses
adequacy arrangements
appropriate intra-group agreements
consent where legally appropriate
another lawful transfer mechanism
4. Where personal data originating outside Ghana is processed in Ghana, the firm shall take reasonable steps to comply with applicable requirements of the originating jurisdiction.
5. The Firm shall maintain appropriate records of significant recurring international data transfers.
17.0 DATA SECURITY
1. Deon & Noed International-Ghana shall implement reasonable and appropriate technical and organisational measures designed to protect personal data which may include:
role based access controls
least-privilege access
strong authentication
multi-factor authentication where appropriate
encryption in transit
encryption at rest where appropriate
secure passwords
endpoint protection
network security
vulnerability management
security monitoring
backups
business continuity arrangements
secure physical storage
secure disposal
employee confidentiality obligations
information-security training
vendor due diligence
periodic security assessments
2. The firm shall periodically assess foreseeable internal and external risks to personal data and update safeguards where necessary.
18.0 ACCESS CONTROL AND CONFIDENTIALITY
1. Access to personal data shall be based on legitimate business need.
2. Personnel shall:
access only information necessary for their duties
not share passwords or access credentials
not disclose client or employee information without authority
not copy personal data unnecessarily
not transfer confidential information through unauthorised channels
immediately report suspected loss or unauthorised disclosure
comply with the firm's information-security and confidentiality requirements
3. Personnel who leave the firm or change roles shall have access rights reviewed and revoked or amended as appropriate.
19.0 PERSONAL DATA BREACHES
1. A suspected or actual personal data breach including:
lost laptops or mobile devices
stolen documents
accidental disclosure of information
email sent to the wrong recipient
unauthorised access to systems
compromised passwords
malware or ransomware
unauthorised downloading or copying
accidental deletion
loss of physical records
unauthorised disclosure by an employee or service provider
shall be treated as a priority incident.
2. Personnel must report a suspected or actual breach immediately to the Data Protection Supervisor and/or designated information-security contact.
3. The Firm shall:
contain the incident
assess the nature and scope of the incident
identify affected information and individuals
assess risks to affected individuals
preserve relevant evidence
take remedial action
determine whether notification is required
notify regulators and affected individuals where required by law
document the incident and remedial actions
4. The firm shall not delay reporting an incident internally merely because it has not yet been established whether a legal notification obligation exists.
20.0 DATA RETENTION
1. Personal data shall be retained only for as long as reasonably necessary for the purpose for which it was collected or as required by:
applicable legislation
professional standards
tax requirements
audit requirements
employment obligations
contractual obligations
regulatory requirements
legal proceedings
legitimate claims
legitimate business needs
2. Retention periods shall be established through the firm's records-retention schedule.
3. Different categories of information may therefore have different retention periods.
4. At the end of the applicable retention period, information shall be securely deleted, destroyed or anonymised, unless continued retention is lawfully required.
21.0 RECRUITMENT AND EMPLOYEE PRIVACY
1. The firm may process applicant and employee data for purposes including recruitment, selection, onboarding, payroll, benefits, performance management, training, disciplinary procedures, workplace administration and legal compliance.
2. The firm shall seek to limit recruitment data to information reasonably relevant to assessing candidates and administering recruitment.
3. Background checks shall be conducted only where justified and permitted by law.
4. Employee information shall be accessible only to authorised personnel with a legitimate need to access it.
5. Health, disciplinary, grievance and other particularly sensitive employee information shall receive enhanced protection.
22.0 EMPLOYEE MONITORING
1. Where Deon & Noed International-Ghana monitors use of firm systems, communications, devices, premises or other resources, monitoring shall be:
proportionate
reasonably necessary
conducted for legitimate purposes
appropriately communicated to affected personnel
subject to applicable employment and data-protection law
limited to information reasonably required for the identified purpose
2. Monitoring shall not be undertaken merely because technology makes it possible.
23.0 CHILDREN'S DATA
1. Deon & Noed's International-Ghana services and website are not ordinarily directed at children.
2. The firm does not knowingly seek to collect children's personal data unless necessary for a legitimate professional, employment, legal or administrative purpose.
3. Where children's data is processed, additional care shall be taken to ensure that the processing is lawful, proportionate and appropriately safeguarded.
24.0 COOKIES AND WEBSITE PRIVACY
1. Deon & Noed International-Ghana may use cookies and similar technologies on its websites.
2. Cookies may be used for purposes including:
essential website functionality
security
remembering user preferences
analytics
performance monitoring
website improvement
social-media functionality
other functions disclosed to website visitors
3. The firm shall distinguish, where applicable, between essential and non-essential cookies.
4. Where consent is legally required for non-essential cookies or similar technologies, the firm shall provide an appropriate mechanism for obtaining and managing that consent.
5. Website visitors may also control cookies through browser settings, although disabling certain cookies may affect website functionality.
6. Third-party services, including analytics, social-media and embedded-content providers, may process information in accordance with their own privacy policies.
7. The firm shall not represent any third-party websites or services controlled by DNI merely because links or embedded features are made available on the firm's website.
25.0 MARKETING AND ELECTRONIC COMMUNICATIONS
1. Deon & Noed International-Ghana may communicate with clients, prospective clients and business contacts about:
professional services
events
publications
regulatory updates
business information
newsletters
other Firm activities.
2. Where consent is required, the firm shall obtain appropriate consent before sending direct marketing.
3. Recipients may opt out of marketing communications at any time using the mechanism provided in the communication or by contacting the firm.
4. An individual opting out of marketing communications may continue to receive communications necessary for contractual, regulatory, legal or administrative purposes.
26.0 AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
1. The firm may use technology, including automated systems and artificial intelligence tools, to support administrative, analytical, research or professional activities.
2. Where such technology involves personal data, the firm shall assess:
the purpose of processing
the categories and sensitivity of data
the security implications
confidentiality obligations
whether data is transferred to a third party
whether the provider may use the information for its own purposes
whether information is retained by the provider
the potential effect on individuals
whether additional safeguards or a data-protection impact assessment are required
3. The firm shall not permit personal data or confidential client information to be submitted to an external AI system, where doing so would breach applicable law, professional confidentiality, a client agreement, Firm policy or contractual restrictions.
4. Where a decision producing significant effects on an individual is made solely through automated processing, the firm shall comply with applicable legal requirements relating to automated decision making.
27.0 DATA PROTECTION IMPACT ASSESSMENTS
1. The firm shall conduct a data-protection impact assessment (DPIA) where a proposed processing activity is likely to create significant or high risks to individuals, particularly where it involves:
large-scale sensitive personal data
systematic monitoring
new technologies
significant profiling
extensive employee monitoring
biometric information
substantial processing of client employee information
other high-risk processing
2. The Data Protection Supervisor shall determine whether a DPIA is required and shall maintain appropriate records.
28.0 THIRD-PARTY WEBSITES AND SOCIAL MEDIA
1. The firm's website and communications may contain links to third-party websites, social media platforms or other external services.
2. The firm does not control the privacy practices of those third parties.
3. Individuals should review the privacy policies and terms of the relevant third-party service before submitting personal information.
4. Where social media features are incorporated into firm websites, interactions with those features may result in information being processed by the relevant social media provider.
29.0 PROFESSIONAL WEBSITE DISCLAIMER
1. Information published by Deon & Noed International-Ghana through its website, publications, newsletters or other general communications is intended for general informational purposes.
2. Unless expressly stated otherwise, such information does not constitute legal, tax, accounting, audit, investment or other professional advice and should not be relied upon as a substitute for advice tailored to the relevant circumstances.
3. Laws and regulations may change and their application may depend on the particular facts of a matter.
4. No person should make a decision or take action solely on the basis of general information published by the firm without obtaining appropriate professional advice where necessary.
5. The firm shall not be responsible for third-party websites or content to which its website may link.
30.0 INTELLECTUAL PROPERTY AND WEBSITE MATERIALS
1. Unless otherwise stated, content published on the firm's website, including text, graphics, logos, reports, publications and other materials, belongs to Deon & Noed International-Ghana or is used under appropriate rights.
2. Website materials may not be reproduced, modified, commercially exploited or distributed without appropriate authorisation, except where permitted by law.
3. Third-party content remains subject to the rights of its respective owners.
31.0 DATA PROTECTION GOVERNANCE
1. Deon & Noed International-Ghana shall appoint a Data Protection Supervisor or other appropriately designated persons responsible for overseeing data protection compliance in Ghana.
2. The Data Protection Supervisor shall, as appropriate:
monitor compliance
advise management and personnel
coordinate data-protection training
maintain relevant records
support data-subject requests
coordinate breach responses
support regulatory engagement
advise on DPIAs
coordinate vendor assessments
monitor data-processing activities
liaise with the Data Protection Commission
3. The firm shall provide the Data Protection Supervisor with appropriate authority, access and resources to perform these functions.
32.0 PERSONNEL RESPONSIBILITIES
1. All personnel of Deon & Noed International-Ghana are responsible for protecting personal data.
2. Personnel shall:
follow this Policy
complete required privacy and security training
use personal data only for authorised purposes
maintain confidentiality
report suspected breaches promptly
comply with access controls
protect physical and electronic records
avoid unnecessary copying or disclosure
cooperate with data-protection investigations and requests
3. A breach of this policy may result in disciplinary action and may also expose an individual or the firm to legal or regulatory consequences.
33.0 TRAINING AND AWARENESS
1. All personnel shall receive appropriate data protection and information security training.
2. Training shall be provided:
during onboarding
periodically thereafter
when material changes occur in applicable law or firm procedures
where additional training is required because of an individual's role.
3. Personnel with elevated access to personal or sensitive information, including HR, IT, audit, tax and engagement personnel, may receive additional role specific training.
34.0 DATA PROTECTION REGISTRATION AND REGULATORY COMPLIANCE
1. Deon & Noed International-Ghana shall maintain any registration, renewal, notification or other regulatory status required by the Data Protection Commission.
2. The firm shall maintain appropriate records and documentation demonstrating compliance with Act 843 and applicable DPC requirements.
3. The firm shall ensure and maintain up to date registration requirement of the commission.
4. This registration requirement is subject to renewal every 2 years.
5. The firm shall periodically review whether its registration status, processing activities and regulatory filings remain accurate.
35.0 COMPLAINTS
1. Any individual who believes that Deon & Noed International-Ghana has mishandled personal data may submit a complaint to the firm's Data Protection Supervisor.
2. Complaints should include sufficient information to enable the firm to investigate the matter.
3. The firm shall investigate complaints fairly and within a reasonable period, subject to applicable statutory requirements.
4. Nothing in this policy shall prevent an individual from exercising a right to complain directly to the Data Protection Commission or another competent authority.
36.0 DATA PROTECTION COMMISSION
Where an individual remains dissatisfied with the firm's response, the individual may contact:
Data Protection Commission, Ghana
Accra, Ghana
Email: info@dpc.gov.gh
Website: https://dpc.gov.gh/
37.0 POLICY REVIEW
1. This Policy shall be reviewed at least annually and sooner where necessary following:
material legislative changes
regulatory guidance
significant changes in Firm activities
material changes to technology
significant data breaches
changes to international operations
introduction of new categories of personal data processing
recommendations arising from audits or assessments
2. Material amendments shall be approved by the appropriate authority within Deon & Noed International-Ghana.
38.0 CONTACT DETAILS
1. For questions, requests or complaints concerning the processing of personal data by Deon & Noed International- Ghana, please contact:
Data Protection Supervisor
Mrs. Mavis Oparebea
Deon & Noed International
C1-69 London Street, Lakeside Estate
Ashaley botwe, Accra – Ghana.
Email: info@deon-noed.com
Telephone: +233 (0) 277 799 999
Website: www.deon-noed.com
2. Requests concerning personal data should preferably be marked:
“DATA PROTECTION REQUEST”
39.0 GOVERNING PRINCIPLE
Deon & Noed recognises that trust is fundamental to the provision of Audit, Tax, HR and Advisory services.
The firm therefore commits to treating personal data not merely as an information-technology asset, but as information entrusted to the firm by individuals and organisations.
Personal data shall be handled with confidentiality, integrity, fairness, professionalism and respect for the rights of the individuals to whom it relates.
Where uncertainty exists concerning the appropriate treatment of personal data, personnel shall consult the Data Protection Supervisor before proceeding with the proposed processing.
- Deon & Noed International (DNI) is an integrated Audit,Tax,
Advisory and HR Firm duly registered in accordance with The Incorporated Private Partnership Act, 1962 (Act 152) and with the Registrar General?s Department since 2009 and the Institute of Chartered Accountants (Ghana) in 2013.