Category of personal data
Typical purpose at SAL
Primary lawful basis
Notes & safeguards
Identification (name, ID/passport, employee number)
Employee onboarding & HR files
Contractual necessity / Legal obligation
Keep copies as required by law; apply the retention schedule; restrict access.
Contact details (phone, email, address)
Work communications; customer service updates
Contractual necessity / Legitimate interests
Consent required for marketing; provide an opt out.
Employment records (role, evaluations, attendance)
Workforce management & performance
Legitimate interests / Contractual necessity
Provide transparency and allow objections where legitimate interests are used.
Payroll & benefits (bank details, salary, dependents)
Pay salary; administer benefits
Contractual necessity / Legal obligation
Certain details mandated by law.
Government IDs & immigration documents
Work permits and visas; contractor access
Legal obligation
Process only what is required; strict retention.
Vendor/partner KYC data (commercial registration, IDs of signatories)
Due diligence and anti fraud checks
Legal obligation / Legitimate interests
Use legal obligation when mandated; rely on legitimate interests with a documented DPIA when applicable.
Access control logs (badges, visitor logs)
Site security and audit trail
Legitimate interests
Provide notice at entry; maintain short retention (6–12 months unless an incident occurs).
CCTV footage (standard video)
Crime prevention, health & safety, incident investigation
Legitimate interests
Ensure prominent signage; restrict viewing; keep recordings for 30–60 days; complete a DPIA.
Biometric data (fingerprint/face templates)
Attendance and secure access
Explicit consent / Legal obligation
Treat as sensitive; provide alternatives for those who object; encrypt templates.
Health and medical data
Occupational health & safety
Explicit consent / Vital interests / Legal obligation
Minimise collection; store separately; restrict access to those with a legitimate need.
Training records & certifications
Compliance & competence tracking
Legitimate interests / Legal obligation
Use legal obligation when mandated (e.g., safety training); otherwise rely on legitimate interests.
Customer shipment data (names, phones, addresses)
Fulfilment, delivery, and notifications
Contractual necessity
Information is necessary to perform the service contract.
Customer service recordings/chats
Quality assurance & dispute handling
Legitimate interests / Contractual necessity
Inform participants that calls or chats are recorded; define retention periods.
Marketing leads (emails, phones)
Direct marketing and newsletters
Consent
Require separate marketing consent; provide an easy unsubscribe mechanism.
Website/app telemetry, cookies, device IDs
Security, analytics, and personalisation
Legitimate interests (security and essential) / Consent (analytics and ads)
Display a consent banner and allow users to manage their settings.
Audit logs & security events
Incident detection, investigation, and remediation
Legitimate interests / Legal obligation
Necessary for compliance with cybersecurity requirements; restrict access and define retention periods.
Research and analytics on de identified data
Service improvement and statistics
Legitimate interests
Ensure data is de identified; reassess if there is a risk of re identification.