Policies

PERSONAL DATA PROTECTION POLICY

SSF – Safe Steps Forward Empresa de Trabalho Temporário, LDA

Effective date:
07/09/2026
Version:
1.0
Review Date:
Until further notice

1. Purpose

SSF – Safe Steps Forward Empresa de Trabalho Temporário, LDA is committed to protecting the privacy and personal data of its employees, workers, candidates, clients, suppliers, business partners, visitors and other individuals whose personal data is processed in connection with its activities.

This Personal Data Protection Policy establishes the principles and responsibilities that apply to the collection, use, storage, disclosure and protection of personal data by SFF.

The purpose of this Policy is to ensure that personal data is handled responsibly, securely, transparently and in accordance with applicable legislation.

2. Scope

This Policy applies to:

  • All employees of SFF;
  • Temporary workers and other personnel working on behalf of SFF;
  • Management and directors;
  • Contractors and consultants;
  • Persons with access to SFF information systems;
  • Third-party service providers where applicable;
  • All personal data processed by SFF in connection with its business activities.

The Policy applies regardless of whether personal data is stored electronically, on paper or through another medium.

3. Applicable legislation

SFF processes personal data in accordance with applicable data-protection legislation, including:

  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR/RGPD);
  • Portuguese Law No. 58/2019;
  • Applicable Portuguese employment and labour legislation;
  • Other applicable European Union and Portuguese legislation concerning privacy and personal data.

Law No. 58/2019 establishes the framework implementing the GDPR within the Portuguese legal system.

4. Fundamental principles

SFF shall process personal data according to the following principles.

4.1 Lawfulness, fairness and transparency

Personal data shall be processed lawfully, fairly and transparently.

Individuals shall receive appropriate information regarding how and why their personal data is processed.

4.2 Purpose limitation

Personal data shall be collected for specific, explicit and legitimate purposes and shall not be used for incompatible purposes.

4.3 Data minimisation

SFF shall only collect and process personal data that is adequate, relevant and necessary for the intended purpose.

4.4 Accuracy

SFF shall take reasonable measures to ensure that personal data is accurate and kept up to date where necessary.

4.5 Storage limitation

Personal data shall not be retained for longer than necessary, taking into account legal, contractual, operational and regulatory requirements.

4.6 Integrity and confidentiality

Personal data shall be protected against unauthorised or unlawful processing, accidental loss, destruction, alteration or disclosure.

4.7 Accountability

SFF shall maintain appropriate records, procedures and organisational measures to demonstrate compliance with data-protection requirements.

5. Categories of personal data

Depending on the nature of the relationship with SFF, personal data may include:

  • Identification data;
  • Contact details;
  • Professional information;
  • Employment information;
  • Recruitment information;
  • Contractual information;
  • Payroll and payment information;
  • Tax and social-security information;
  • Communication records;
  • Website and technical information;
  • Information necessary to comply with legal obligations.

Special categories of personal data shall only be processed where an appropriate legal basis and additional conditions under applicable law exist.

6. Legal bases

Before processing personal data, SFF shall identify the appropriate legal basis.

These may include:

  • Performance of a contract;
  • Compliance with a legal obligation;
  • Legitimate interests;
  • Consent;
  • Protection of vital interests;
  • Other legal bases recognised by applicable legislation.

Consent shall not be used where another legal basis is more appropriate.

Where consent is used, it must be freely given, specific, informed and unambiguous. Individuals must also be able to withdraw consent. CNPD specifically notes that consent is only one of the available legal bases under the GDPR and should not automatically be used for contractual processing.

7. Responsibilities of SFF personnel

Anyone who has access to personal data as part of their work with SFF must:

  • Keep personal data confidential;
  • Only access information required for legitimate work purposes;
  • Never disclose personal data to unauthorised persons;
  • Follow SFF security procedures;
  • Use approved systems and communication channels;
  • Report suspected data breaches immediately;
  • Avoid storing personal data on unauthorised personal devices or accounts;
  • Ensure documents containing personal data are securely stored and disposed of.

Access to personal data must be based on the principle of need-to-know.

8. Recruitment and candidate data

SFF may process candidate information for recruitment, selection, placement and employment purposes.

Candidates may provide information such as:

  • CVs;
  • Employment history;
  • Qualifications;
  • Professional experience;
  • Contact information;
  • Availability;
  • References;
  • Information necessary to assess suitability for a position.

Candidate information must only be accessed by authorised persons and disclosed to clients or other parties where there is a lawful and legitimate recruitment or employment purpose.

9. Employee and worker data

SFF may process employee and worker data for purposes including:

  • Employment administration;
  • Contract management;
  • Payroll;
  • Working time and attendance;
  • Legal and regulatory compliance;
  • Social-security and tax obligations;
  • Health and safety obligations;
  • Training;
  • Workforce management;
  • Communication;
  • Business administration.

Where special categories of data are processed, SFF shall implement the additional safeguards required by applicable law.

10. Client and supplier data

SFF may process personal data relating to representatives and contacts of clients, suppliers and business partners.

Such information may be used to:

  • Manage commercial relationships;
  • Negotiate and administer contracts;
  • Provide services;
  • Communicate with business contacts;
  • Process invoices and payments;
  • Meet legal and regulatory requirements.

11. Data sharing

Personal data may only be disclosed where there is a valid legal basis and the disclosure is necessary.

Recipients may include:

  • Clients;
  • Employees and authorised SFF representatives;
  • Payroll and accounting providers;
  • Legal and professional advisers;
  • IT and technology providers;
  • Recruitment partners;
  • Public authorities;
  • Courts or law-enforcement authorities where legally required.

SFF shall ensure that relevant third-party processors are appropriately assessed and, where required, bound by written data-processing agreements.

12. International data transfers

Where SFF transfers personal data outside the European Economic Area, it shall ensure that an appropriate legal mechanism is in place in accordance with the GDPR.

Where applicable, SFF may rely on:

  • An adequacy decision;
  • Standard Contractual Clauses;
  • Appropriate safeguards;
  • Another lawful transfer mechanism recognised under applicable law.

13. Data retention

SFF shall establish appropriate retention periods for different categories of personal data.

Retention periods shall take into consideration:

  • The purpose for which the data was collected;
  • Contractual requirements;
  • Employment legislation;
  • Tax and accounting requirements;
  • Legal limitation periods;
  • Regulatory obligations;
  • Legitimate business requirements.

Once personal data is no longer required, it shall be securely deleted, destroyed or anonymised.

14. Information security

SFF shall maintain appropriate technical and organisational security measures.

Depending on the circumstances, these may include:

  • Access controls;
  • Password protection;
  • User permissions;
  • Secure storage;
  • Encryption where appropriate;
  • Backups;
  • Malware protection;
  • Software updates;
  • Secure disposal of documents;
  • Confidentiality obligations;
  • Staff awareness and training.

Security measures shall be proportionate to the risks associated with the processing.

15. Personal data breaches

A personal data breach may include:

  • Loss of personal data;
  • Theft;
  • Unauthorised access;
  • Accidental disclosure;
  • Unauthorised alteration;
  • Unauthorised destruction;
  • Sending personal data to the wrong recipient.

Any employee or representative who becomes aware of a suspected personal data breach must notify:

[support@safestepsforward.eu]

as soon as possible.

SFF shall assess the incident and, where legally required, notify the competent supervisory authority and affected individuals.

Under the GDPR, certain personal-data breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

16. Data subject rights

Individuals have rights regarding their personal data, subject to the conditions and limitations established by law.

These may include:

  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object;
  • Right to withdraw consent;
  • Rights relating to automated decision-making, where applicable.

SFF shall maintain appropriate procedures for receiving, verifying, assessing and responding to such requests.

17. Confidentiality

All persons working for or with SFF who have access to personal data are required to maintain confidentiality.

Personal data shall not be discussed, copied, transmitted or disclosed except where necessary for authorised business purposes or required by law.

Confidentiality obligations may continue after an individual's employment or engagement with SFF ends.

18. Training and awareness

SFF shall take reasonable steps to ensure that employees and other relevant personnel understand their responsibilities regarding personal data.

Where appropriate, SFF may provide training covering:

  • GDPR principles;
  • Data security;
  • Confidentiality;
  • Phishing and cybersecurity;
  • Data breach reporting;
  • Handling of candidate and employee information;
  • Appropriate use of email and business systems.

19. Data protection by design and default

Where new systems, services, processes or technologies involve the processing of personal data, SFF shall consider privacy and data-protection requirements from the beginning of the process.

Where appropriate, SFF shall assess:

  • What personal data is required;
  • Why it is required;
  • Who needs access;
  • How long it should be retained;
  • Security risks;
  • Whether a less intrusive approach is possible.

Where required by law, SFF shall conduct a Data Protection Impact Assessment (“DPIA”).

20. Cookies and digital services

Where SFF operates websites or digital services, appropriate privacy and cookie information shall be provided to users.

Non-essential cookies and similar technologies shall be used only in accordance with applicable legal requirements.

21. Monitoring and compliance

SFF may periodically review its data-protection practices to ensure that this Policy remains appropriate and effective.

Where necessary, SFF may update internal procedures, security measures, contracts, privacy notices and training requirements.

22. Complaints

Individuals who have concerns regarding the handling of their personal data should first contact SFF:

[support@safestepsforward.eu]

Individuals also have the right to lodge a complaint with the Portuguese data-protection supervisory authority:

23. Policy review

This Policy shall be reviewed periodically and whenever there are significant changes to:

  • Applicable legislation;
  • SFF's business activities;
  • Data-processing activities;
  • Information systems;
  • Security risks;
  • Organisational structure.

SSF – Safe Steps Forward Empresa de Trabalho Temporário, LDA

Lisbon, Portugal

Version 1.0