Tawzef Data Protection Policy

Tawzef Data Protection Policy

Tawzef Internal Data Protection Policy

1. Purpose and Scope

This Data Protection Policy defines Tawzef’s commitment to safeguarding personal, client, and employee data. It applies to:

  • Tawzef for Recruitment LLC and Tawzef for Business Consultancy LLC (collectively “Tawzef”).

  • All Tawzef employees, contractors, consultants, and third parties processing data on Tawzef’s behalf.

  • All forms of data (electronic, paper, verbal).

The policy ensures compliance with:

  • Egyptian Personal Data Protection Law No. 151 of 2020.

  • GDPR principles (for international clients).

  • Applicable ISO and international best practices.


2. Legal Basis and Principles

Tawzef commits to the following principles of data protection:

  • Lawfulness, Fairness & Transparency: Data is collected and processed only for legitimate business purposes and communicated clearly to data subjects.

  • Purpose Limitation: Data is processed solely for the purpose for which it was collected.

  • Data Minimization: Only essential data is collected and retained.

  • Accuracy: Data is regularly updated and corrected when inaccuracies are identified.

  • Storage Limitation: Data is retained only for as long as legally or contractually necessary.

  • Integrity & Confidentiality: Data is secured against unauthorized or unlawful processing, accidental loss, destruction, or damage.


3. Roles and Responsibilities

  • Management: Ensure compliance with this policy and provide resources for enforcement.

  • IT & Security Team: Maintain technical safeguards, monitor threats, and ensure resilience.

  • HR Department: Oversee employee training, NDAs, and awareness.

  • Employees: Follow confidentiality requirements, report incidents, and handle data responsibly.


4. Data Protection Measures

4.1 Confidentiality and Access Control

  • All employees sign Non-Disclosure Agreements (NDAs).

  • Role-based access rights restrict data access to authorized personnel only.

  • Visitors and third parties are restricted from sensitive data areas.

4.2 Technical Safeguards

  • Zoho One (HRIS): Operates on ISO/IEC 27001, 27017, 27018, 27701, 9001, and 22301 certified platforms.

  • Microsoft 365: Provides encryption in transit and at rest, Multi-Factor Authentication (MFA), Data Loss Prevention (DLP), Advanced Threat Protection (ATP), and secure cloud backups.

  • Corporate network protected by firewalls, intrusion detection, and monitoring.

4.3 Training and Awareness

  • Annual data protection and cybersecurity training is mandatory for all staff.

  • Refresher sessions are provided in line with regulatory or system updates.

4.4 Incident Management

  • All data breaches or suspected incidents must be reported immediately to the IT & HR teams.

  • A documented escalation and notification procedure ensures rapid containment and communication with affected parties.

4.5 Data Retention and Disposal

  • Employee and client records are retained only for statutory or contractual periods.

  • Upon expiry, records are securely destroyed through shredding (paper) or certified digital wiping (electronic).


5. Rights of Data Subjects

Tawzef respects the rights of individuals to:

  • Access their personal data.

  • Request correction of inaccurate data.

  • Request deletion when legally permissible.

  • Object to unlawful processing.

Requests are handled promptly by the HR department, with escalation to management as needed.


6. Monitoring and Compliance

  • This policy is reviewed annually and updated in line with regulatory changes.

  • Compliance is monitored through internal audits and management reviews.

  • Violations may result in disciplinary action, up to and including termination of employment.


7. Whistleblowing and Reporting

Employees and stakeholders can report suspected breaches or violations confidentially through:

  • HR Department ([email protected]).

  • Tawzef’s secure Support Portal: support.tawzef.com.

    Anonymous reporting is permitted and retaliation is strictly prohibited.


8. Approval and Review

This Data Protection Policy has been approved by Tawzef’s senior management and applies across all business units and entities. It is reviewed annually, or sooner if required by law or business changes.

    • Related Articles

    • Tawzef's Vaccine Policy

      At Tawzef for Recruitment & HR Consultancy, the health and safety of our employees, clients, and partners remain our top priority. In response to the global COVID-19 pandemic and the ongoing need to ensure a safe working environment, Tawzef has ...
    • Hybrid Workplace Policy

      At Tawzef for Recruitment & HR Consultancy, we recognize the importance of adapting to the ever-evolving workplace landscape. Our hybrid workplace model is designed to align with the responsibilities of each role and the business's operational needs. ...
    • Code of Conduct

      0. Definitions & Abbreviations Tawzef: Refers collectively to Tawzef for Recruitment LLC and Tawzef for Business Consultancy LLC, both Egyptian limited liability companies. Unless otherwise specified, “Tawzef” in this Code of Conduct encompasses the ...
    • Tawzef Employee Handbook

      Objective To provide clear and transparent terms and conditions of employment, ensuring compliance with all legal requirements. Operating Authorities Human Resources (HR) Department Employee's Direct Supervisor Operating Procedures Work Schedule: ...