Data Protection Policy

Size: px
Start display at page:

Download "Data Protection Policy"

Transcription

1 Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience: Staff, Volunteers, Contractors Review Date: May 2017, check April 2018 Lead Executive Author/Lead Manager: Senior Information Risk Officer Karen Pearce Page 1 of 14

2 Contents Contents 2 Page 1. Policy Statement of Intent Definition of terms used in the Act and interpreted in this policy Disclosure of information 6 2. The Eight Principles of Data Protection Application of criteria and controls 9 4. Data Collection Data Storage Data Access and Accuracy Appendix A: Gaining Consent Page 2 of 14

3 1. Policy Statement of Intent The Motor Neurone Disease Association (the Association ) believes it is of the utmost importance that information we may store or use in order to deliver our various functions is done so in compliance with legal requirements. A number of key pieces of legislation and guidance inform the development of the policies, procedures, guidance and agreements within this document. They include:- Data Protection Act 1998 (the Act) General Data Protection Regulation (effective ) Minimum Data Handling Measures (Cabinet Office Standard) The Caldicott Report Data Sharing Code of Practice (Information Commissioner s Office guidance) Common Law Duty of Confidence. This states that data given in confidence should not be disclosed unless; o The consent of the individual has been obtained o A statute of law dictates that disclosure is made o It is in the overriding public interest to do so. The Association is committed to the lawful and correct treatment of personal, sensitive and commercially sensitive information. This is important to successful working and to maintaining the confidence of those with whom we deal. The Association needs to collect and use certain types of information about the people (called Data Subjects) who come into contact with it in order to carry out its work. A data subject is the Individual whose personal information is being held or processed by the Association. These Individuals include, and are not limited to, people with MND and those affected by MND, Association employees and volunteers including trustees, supporters and donors and health and social care professionals. This personal information must be collected and dealt with appropriately, whether on paper, a computer, or recorded on other material. There must be safeguards in place to ensure this under the Act. To ensure it is compliant with the Act, the Association should ensure it has at least one legitimate reason for processing (collecting, using, managing or disclosing) personal data. In some circumstances the consent of the Individual may not be necessary. Compliance with the Act is a legal requirement, therefore any breach of this may be considered serious and can result in penalties such as fines of up to 500,000, imprisonment and may also have considerable implications for our reputation. The fines will increase with the introduction of the General Data Protection Regulation (GDPR) in May 2018, and may be up to 4% of the previous year s income. Page 3 of 14

4 The interpretation of the Act and the GDPR are supported by this policy and the associated procedures and guidance. They are designed to ensure that the Association is compliant with the law. Where there is the possibility of ambiguity in interpretation, guidance is given to minimise any risk and therefore protect the Individual as well as balance this with the ability to continue to deliver the various functions of the Association. The principles of the Act will be further enhanced by the additional rights Individuals can expect following the introduction of the GDPR. The GDPR addresses the rapidly changing technology environment which has created a plethora of new options for the collection, storage, sharing and use of personal data. The GDPR enhances some of the principles, and also introduces new expectations with regard to consent to use an Individual s data and the need to be very clear on how that data is used. This policy should be read in conjunction with the following policies, procedures and guidance: Confidentiality Policy Photography Policy Disciplinary Policy Privacy Policy Condition of employment policies including: o Safeguarding Vulnerable Adults Policy o Safeguarding Children and Young People Policy o Working at Home Policy o Information Communication Technology (ICT) User & Security Policy Data Protection Breach Reporting Procedure Subject Access Request Procedure Sharing Personal Information Procedure Information Sharing Agreement Retention, Archiving & Destruction of Information Guidance Intellectual Property Guidance The Minimum Data Set (MDS) and Enhanced MDS Guidance Voic and Call-back Protocol Procedure for Recording and Storing Employee Information. Page 4 of 14

5 The scope of the policy applies to the following: National and Regional Offices of the Association All branches and groups All sessional workers/contractors operating on behalf of the Association All staff and volunteers. 1.2 Definition of terms used in the Act and interpreted in this policy are: Data Controller The person or team who decides what personal information the Association will hold and how it will be held or used. In this instance, the Association is the Data Controller under the Act. It is also responsible for notifying the Information Commissioner s Office (ICO) of the data it holds, or is likely to hold and the general purposes that the data will be used for. This is reviewed annually as part of the registration process with the ICO. Senior Information Risk Officer The person accountable for ensuring that the Association follows its data protection policy and complies with the Act. In this instance responsibility has been delegated by the Chief Executive to the Director of Fundraising, however overall accountability sits with the Board of Trustees (see Information Governance Policy). Data Subject The individual whose personal information is being held or processed by the Association, for instance: person with MND, person affected by MND, employee, volunteer, supporter etc. Throughout the policy and the supporting procedures and guidance the data subject will be referred to as the Individual. Personal Data/Information Information that relates to a living person (e.g. name and address). The Data Protection Act principles do not relate to deceased people, however the Association would need to carry out an assessment of any other obligations, legal or otherwise, towards any deceased person before using their information in any way. Sensitive Data/Information This includes: o Racial or ethnic origin o Political opinions o Religious or similar beliefs o Trade union membership o Physical or mental health including a diagnosis of MND o Sexual life o Criminal record o Criminal proceedings relating to an Individual s offences. Page 5 of 14

6 Only relevant factual information that the Association needs to know should be captured. The Association should be clear why it wants the information and how it will be used and this information is captured within the Minimum Data Set (MDS). 1.3 Disclosure of information The Association may share data with other agencies such as the local authority, funding bodies and other voluntary agencies where it improves delivery of care, supports carers, underpins research and maximises fundraising. This may require consent from the Individual if there is not a lawful basis to share the data. (see Appendix A) The Individual will be made aware in most circumstances, how and with whom their information will be shared through the use of clear fair processing notices located on the website, on application forms and other relevant documentation. There are circumstances where the law allows the Association to disclose data (including sensitive date) without the Individual s consent. These are: i. Carrying out a legal duty or as authorised by the Secretary of State ii. Protecting vital interests of an Individual or other person iii. The Individual has already made the information public iv. Conducting any legal proceedings, obtaining legal advice or defending any legal rights v. Monitoring for equal opportunities purposes i.e. race, disability or religion however always anonymised vi. Providing a confidential service where the Individual s consent cannot be obtained or where it is reasonable to proceed without consent: e.g. where we would wish to avoid forcing stressed or ill Individuals to provide consent signatures. The policy will be reviewed and revised as and when it becomes necessary and at least every three years. Page 6 of 14

7 2. The Eight Principles of Data Protection 2.1 The Principles require that personal information: i. shall be processed fairly and lawfully. This means that the Association must: have legitimate grounds for collecting and using the personal data not use the data in ways that have unjustified adverse effects on the Individuals concerned be transparent about how the Association intends to use the data and give Individuals appropriate fair processing notices when collecting their personal data handle people s personal data only in ways they would reasonably expect make sure the Association does not do anything unlawful with the data ii. shall be obtained only for one or more of the purposes specified in the Act and shall not be processed in any manner incompatible with those purposes. This means that the Association must: be clear from the outset about why the Association is collecting personal data and what it intends to do with it comply with the Act s fair processing requirements including the duty to give clear fair processing notices to Individuals when collecting their personal data comply with what the Act says about notifying the Information Commissioner ensure that if the Association wishes to use or disclose the personal data for any purpose that is additional to, or different from, the originally specified purpose, the new use of disclosure is fair. iii. shall be adequate, relevant and not excessive in relation to those purpose(s). This means that: the Association holds personal data about an Individual that is sufficient for the purpose it is holding it for in relation to that Individual the Association does not hold more information than needed for that purpose and has a minimum data set to describe this iv. shall be accurate and, where necessary, kept up to date. This means that the Association must: take reasonable steps to ensure the accuracy of any personal data it obtains ensure that the source of any personal data is clear carefully consider any challenges to the accuracy of information consider whether it is necessary to update the information. Page 7 of 14

8 v. should not be kept for longer than is necessary. This means that the Association should: review the length of time it keeps personal data consider the purpose or purposes it holds the information for in deciding whether (and for how long) to retain it securely delete information that is no longer needed for this purpose or these purposes update, archive or securely delete information if it goes out of date. vi. shall be processed in accordance with the rights of Individuals under the Act. This means that the Individual has: a right of access to a copy of the information comprised in their personal data a right to object to processing that is likely to cause or is causing damage or distress a right to prevent processing for direct marketing a right to object to decisions being taken by automated means a right in certain circumstances to have inaccurate personal data rectified, blocked, erased or destroyed a right to claim compensation for damages caused by breach of the Act. vii. shall be kept secure by the Data Controller and any Data Processor, who take appropriate technical and other measures to prevent unauthorised or unlawful processing or accidental loss or destruction of, or damage to, personal information. This means that the Association, and those organisations who process an Individuals data through contracted agreement with the Association, must: design and organise security to fit the nature of the personal data it holds and the harm that may result from an information security breach be clear about who in the organisation is responsible for ensuring information security make sure it has the right physical and technical security, backed up by robust policies and procedures and reliable, well-trained staff and volunteers be ready to respond to any breach of security swiftly and effectively. viii. shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of Individuals in relation to the processing of personal information. Of specific relevance to the Association: the European Commission has decided that certain countries have an adequate level of protection for personal data. Currently, the following countries: Guernsey, Isle of Man, Jersey are considered as having adequate protection. Page 8 of 14

9 3. Application of criteria and controls The Association will ensure the appropriate actions are taken to comply with the Act and other relevant legislation through the application of criteria and controls. These would mean adhering to the eight principles by: observing the conditions regarding the fair collection and use of information meeting the legal obligations to specify the purposes for which information is used collecting and processing appropriate information and only to the extent that it is needed to fulfil any operational needs or to comply with any legal requirements ensuring the quality of information used ensuring that the rights of people about whom information is held, can be fully exercised under the Act. These include: o the right to be informed that processing is being undertaken o the right of access to one s personal information o the right to prevent processing in certain circumstances o the right to correct, rectify, block or erase information which is regarded as wrong information. taking appropriate technical and organisational security measures to safeguard personal information ensuring that personal information is not transferred abroad without suitable safeguards treating people justly and fairly whatever their age, religion, disability, gender, sexual orientation or ethnicity when dealing with requests for information setting out clear procedures for responding to requests for information. The relevant policies, procedures and guidance relating to these criteria and controls have been listed in Section 1 of this policy, and hyperlinked to the relevant document. It should be noted that failure of staff and volunteers to adhere to this policy could lead to disciplinary action being taken in line with the following: Disciplinary Policy, Managing Concerns about a Volunteer or Managing Concerns about a Trustee procedure. Page 9 of 14

10 4. Data Collection The Association will ensure that data is collected within the boundaries defined within this policy. This applies to data that is collected in person (face to face or over the telephone), electronically or by completing a form. It applies to any location that is being used by staff, volunteers or contractors to deliver Association related business. When collecting data, the Association will ensure, wherever possible, that there is a fair processing notice in place and that the Individual: clearly understands why the information is needed understands what it will be used for and what the consequences are should the Individual decide not to give consent to processing (more relevant to sensitive health information) understands who the data may be shared with and why has the option to agree to sharing the data grants explicit written or verbal consent to collect and share sensitive data (health related information) wherever possible gives explicit consent to contact via is competent enough to give consent and has given so freely without any duress. The above points indicate that the Individual will have enough information for them to give Informed consent. Any concerns regarding competence should be referred to a health care professional. There are instances within the Association where implicit/implied consent is assumed for collecting data, for example information given when responding to an appeal. The Privacy Policy clearly explains this. Page 10 of 14

11 5. Data Storage Information and records relating to Individuals will be stored securely and will only be accessible to authorised staff and volunteers. Information will be stored for only as long as it is needed or required by statute and will be disposed of appropriately in line with the Retention, Archiving and Destruction of Information procedure. It is the Association s responsibility to ensure all personal and company data is nonrecoverable from any computer system previously used within the organisation which has been passed on/sold to a third party. Page 11 of 14

12 6. Data Access and Accuracy All Individuals have the right to access the information the Association holds about them. The Association will also take reasonable steps to ensure that this information is kept up to date by asking Individuals whether there have been any changes. All employees have the responsibility of ensuring information stored about an Individual is factual and not subjective. In addition, the Association will ensure that: it has a Senior Information Risk Officer with specific responsibility for ensuring compliance with the Act everyone processing personal information understands that they are contractually responsible for following good data protection practice everyone processing personal information is appropriately trained to do so everyone processing personal information is appropriately supervised everyone processing personal information will report a suspected or actual breach of data management using the Data Protection Breach Reporting procedure anybody wanting to make enquiries about handling personal information knows what to do it deals promptly and courteously with any enquiries about handling personal information it describes clearly how it handles personal information it will regularly review and audit the ways it holds, manages and uses personal information it regularly assesses and evaluates its methods and performance in relation to handling personal information all staff are aware that a breach of the rules and procedures identified in this policy may lead to disciplinary action being taken against them. This policy will be updated as necessary to reflect best practice in data management, security and control and to ensure compliance with any changes or amendments in the law. Date of policy: May 2017 Date of review: April 2018 (or earlier if changes in law) Page 12 of 14

13 7. Appendix A - Gaining Consent Under GDPR, a lawful basis needs to be identified before personal data can be processed. If there is no other lawful purpose identified, then consent must be sought. To be considered a lawful basis to process data one of the following must apply: Processing is necessary for the performance of a contract with the Individual, or to take steps to enter a contract. This could be to fulfil an employment contract, or a contract to provide goods or services. Processing is necessary to comply with a legal obligation Processing is necessary to protect the vital interests of an Individual or another person Processing is necessary to fulfil a task that is in the public interest or in the exercise of official authority vested in the Data Controller Processing is necessary for the purposes of legitimate interests of the Association and those legitimate interests are not outweighed by possible harm to the Individuals rights and interests Processing of data has consent from the Individual. What is valid consent? Consent must be: Freely given: the Individual has choice and control on how their personal data may be used Specific and informed: the Individual understands all the purposes for which their data may be used. If there are multiple purposes, consent must be sought for each Unambiguous: the Individual knows what they have consented to, and that they have given their consent A deliberate action by the Individual e.g. signing / verbal / electronic binary choice options. Consent may be implied, for example when completing a survey. The personal data provided may be used for the purposes stated in the survey. The data may not be used for any other purpose unless specific consent has been asked and an action has been taken to indicate it has been given. Page 13 of 14

14 Consent may provide a soft opt-in for further contact. For example details may be captured to provide a service and it would be reasonable to send details about similar services as long as there is the ability to opt-out every time there is contact. For charities, this may include information about their shop, however would not be permissible for campaigning or other direct marketing activities. Obtaining, recording and managing consent Consent must be clearly distinguishable from other matters, written in an accessible and intelligible form and in clear and plain language. It must be clear who has consented, when the consent was given, how it was given, what was consented to (it may be appropriate to note which version of the privacy notice was in use at the time) and when the Individual withdrew consent. Consent is likely to degrade over time. If there is still interaction with the Individual renewed consent will not be necessary. However if the processing or purposes the personal data is used for changes then the original consent may not be specific enough. A number of charities are using a guideline of renewing consent for telephone contact every 2 years. Page 14 of 14

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

DATA PROTECTION POLICY 2018

DATA PROTECTION POLICY 2018 DATA PROTECTION POLICY 2018 Amesbury Baptist Church is committed to protecting all information that we handle about people we support and work with, and to respecting people s rights around how their information

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ] SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY Adopted: [17-04-2018] 1 SAFFRON WALDEN COMMUNITY CHURCH is committed to protecting all information that we handle about people we support and work

More information

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3 Norwich Central Baptist Church DATA PROTECTION POLICY Adopted: May.2018 Norwich Central Baptist Church (NCBC) is committed to protecting all information that we handle about people we support and work

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY Adopted: 5 June 2018 1 Earls Hall Baptist Church is committed to protecting all information that we handle about people we support and work with, and to

More information

UK Research and Innovation (UKRI) Data Protection Policy

UK Research and Innovation (UKRI) Data Protection Policy UK Research and Innovation (UKRI) Data Protection Policy Document Information Revision History Version Comment Date By 0.1 Draft Policy created July 2017 DH 0.2 Revision post review by information manager

More information

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY Dingwall Baptist Church DATA PROTECTION POLICY Adopted: By Trustees Dingwall Baptist Church May 2018 1 Dingwall Baptist Church is committed to protecting all information that we handle about people we

More information

Baptist Union of Scotland DATA PROTECTION POLICY

Baptist Union of Scotland DATA PROTECTION POLICY Baptist Union of Scotland DATA PROTECTION POLICY Adopted: May 2018 1 1.The Baptist Union of Scotland 48, Speirs Wharf, Glasgow G4 9TH (Charity Registration SC004960) is committed to protecting all information

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

SHENLEY BROOK END SCHOOL

SHENLEY BROOK END SCHOOL SHENLEY BROOK END SCHOOL DATA PROTECTION POLICY Linked Policies: CCTV Review Information Reviewed by Finance Pay and Personnel Committee 15 May 2012 Reviewed by Policy Committee August 2013 Adopted by

More information

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH, NORTHALLERTON (referred to in this policy as NLBC) is committed to

More information

Information Sharing Policy

Information Sharing Policy Information Sharing Policy DOCUMENT CONTROL: Version: 1 Ratified by: Risk Management Sub Group Date ratified: 19 December 2012 Name of originator/author: Information Governance Manager Name of responsible

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Control History Title Data Protection Policy Version no. 1.0 Date of publication May 2018 Author(s) Amanda Cramb, HR Manager Next review date May 2021 Page 1 Introduction

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

DATA PROTECTION POLICY 2016

DATA PROTECTION POLICY 2016 DATA PROTECTION POLICY 2016 ADOPTED FROM BRADFORD METROPOLITAIN COUNCIL MODEL POLICY AUTUMN 2016 To be agreed by Governors on; 17/10/16 Signed by Chair of Governors: Statutory policy: Yes Frequency of

More information

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: 4 1. Statement of Intent 1.1 Radian 1 must collect, store and process information about its customers,

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

Brasenose College Data Protection Policy Statement v1.2

Brasenose College Data Protection Policy Statement v1.2 Brasenose College Data Protection Policy Statement v1.2 1. Introduction All documents referred to in this policy can be found online at the address below: https://www.bnc.ox.ac.uk/privacypolicies 1.1 Background

More information

This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects.

This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects. BELFAST ROYAL ACADEMY Data Protection Policy Introduction Belfast Royal Academy recognises and accepts its responsibilities as set out in the Data Protection Act 1998. The School will take all reasonable

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

CHANNING SCHOOL DATA PROTECTION POLICY

CHANNING SCHOOL DATA PROTECTION POLICY CHANNING SCHOOL DATA PROTECTION POLICY The School may amend/change/update this Policy from time to time. 1. Background Data protection is an important legal compliance issue for Channing School. During

More information

Responsible Business Alliance. Data Privacy and GDPR Compliance Policy

Responsible Business Alliance. Data Privacy and GDPR Compliance Policy Responsible Business Alliance Data Privacy and GDPR Compliance Policy 1. INTRODUCTION 1.1 As a global non-profit membership organisation, the Responsible Business Alliance ( RBA ) has a responsibility

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions.

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions. Page 2 of 10 Data Protection Policy Chief Information Officer Chief Information Officer Data Protection Officer The current version (July 2018) is derived from, and supersedes, the version published in

More information

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective:

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: 1 Policy Statement Objective 1.1 It is the policy of Penderels Trust to demonstrate compliance

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version Date Revision Author Summary of Changes 1.0 21 st May 2018 Ashleigh Morrow EXECUTIVE STATEMENT At CASTLEREAGH NURSERY SCHOOL (the School ), we believe privacy is important.

More information

The Heritage Alliance. Data Privacy Policy

The Heritage Alliance. Data Privacy Policy The Heritage Alliance Data Privacy Policy 1. INTRODUCTION 1.1 As a national charity supporting heritage organisations in England, The Heritage Alliance ( HA ) has a responsibility to ensure that it uses

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY LEICESTER HIGH SCHOOL DATA PROTECTION POLICY 1. Background Data protection is an important legal compliance issue for Leicester High School. During the course of the School's activities it collects, stores

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY VERSION 1.0

DATA PROTECTION POLICY VERSION 1.0 VERSION 1.0 1 Department of Education and Skills Last updated 21 May 2018 Table of Contents 1. Introduction... 4 2. Scope & purpose... 4 3. Responsibility for this policy... 5 4. Data protection principles...

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company ) RSD Technology Limited - Data protection policy: Introduction Company Name: Document DP3 Topic: RSD Technology Limited ( the Company ) Data Protection Policy Data protection Date: 25 th May 2018 Version:

More information

POLICY ON INFORMATION, SECURITY & DATA PROTECTION

POLICY ON INFORMATION, SECURITY & DATA PROTECTION POLICY ON INFORMATION, SECURITY & DATA PROTECTION As a recruitment company, First Recruitment is a data controller. This means it processes personal data about its work seekers, individual client contacts

More information

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make. What is the purpose of this document? NORTHERN IRELAND SCREEN COMMISSION (Company Number NI031997) whose registered office is at 3 rd Floor Alfred House, 21 Alfred Street, Belfast, BT2 8ED is committed

More information

EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants

EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants 1 Overview Data Protection Policy for Employees, Workers

More information

Data Protection Policy

Data Protection Policy Data Protection Policy for The Astor Bannerman Group of Companies Issue Date: 3 rd January 2014 Version: 01 Approval History Name Department Role/Position Date approved Signature James Stuart- Smith Director

More information

VMS Software Ltd- Data Protection Privacy Policy

VMS Software Ltd- Data Protection Privacy Policy VMS Software Ltd- Data Protection Privacy Policy Introduction The purpose of this document is to provide a concise policy statement regarding the Data Protection obligations of VMS Software Ltd. This includes

More information

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate

More information

Hendre Infants School DATA PROTECTION POLICY. Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris

Hendre Infants School DATA PROTECTION POLICY. Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris Hendre Infants School DATA PROTECTION POLICY Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris Data Protection Policy OBJECTIVES Administration and delivery of quality services involves processing

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1. Company Name: Document DP3 Topic: Skills Direct Ltd ( the Company ) Data Protection Policy Data protection Date: 21 st May 2018 Version: Version 1 Contents Introduction Definitions Data processing under

More information

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?... Data Protection Guidance for Volunteers Last update 26/11/17 Contents Introduction... 2 1. Why is data protection important?... 2 2. How does it apply to volunteers?... 2 3. What volunteers need to do?...

More information

General Data Protection Regulation. What should community energy organisations be doing to prepare?

General Data Protection Regulation. What should community energy organisations be doing to prepare? General Data Protection Regulation What should community energy organisations be doing to prepare? The implementation date of 25 May 2018 for the General Data Protection Regulation (GDPR) is fast approaching.

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

RAW MARKETING DATA PROTECTION POLICY

RAW MARKETING DATA PROTECTION POLICY RAW MARKETING DATA PROTECTION POLICY Introduction We take your privacy very seriously and have updated our Privacy Statement in line with the upcoming GDPR regulation. Were absolutely committed to reflecting

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

Our Volunteer Privacy Notice: protecting and respecting your information

Our Volunteer Privacy Notice: protecting and respecting your information Our Volunteer Privacy Notice: protecting and respecting your information 1. Important information and who we are This privacy notice informs you as to how The Children s Society looks after the personal

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Contents 1. Purpose and scope... 2 2. Background... 2 3. Principles... 2 4. Aims and commitments... 3 5. Roles and responsibilities... 3 6. Breaches of data privacy legislation...

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

Our Volunteer Privacy Notice: protecting and respecting your information

Our Volunteer Privacy Notice: protecting and respecting your information Our Volunteer Privacy Notice: protecting and respecting your information 1. Important information and who we are This privacy notice informs you as to how The Children s Society looks after the personal

More information

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak PROFESSIONAL INDEPENDENT ADVISERS LTD DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Training Manual Data Protection Officer is Mike Bandurak GDPR introduction

More information

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018 LIFE STYLE CARE PLC Privacy Statement for Employees August 2018 Key points Why we use your personal data: We typically use your personal information for purposes related to your employment relationship

More information

BROOKS PERSONAL TRAINING

BROOKS PERSONAL TRAINING BROOKS PERSONAL TRAINING Data Protection Policy Data Protection Policy Lent 2017 0 DATA PROTECTION POLICY Table of Contents: 1. Document Control... 2 2. Introduction... 3 3. General Statement of Scope...

More information

Data Protection Policy

Data Protection Policy Policy Current Status Operational Last Review: May 2018 Responsibility for Review: Director of Administration, Contracts and Health Next Review: September 2019 Internal Approval: & Safety SLT Originated:

More information

Data Protection Policy, including Key Procedures

Data Protection Policy, including Key Procedures Data Protection Policy, including Key Procedures Revision Number :- 0 Date :- 16 April 2018 Status :- Approved Issue Date :- 22 March 2018 HEADING Aims of this Policy SECTION CONTENT Milton s Cottage Trust

More information

Parent / Carer Privacy Notice

Parent / Carer Privacy Notice Document No. PP Issue No. 1 Issue Date: 2018-05-24 Renewal Date: 2019-05-24 Originator: Kate Frith Responsibility: Director of Resources 1. Policy statement Parent / Carer Privacy Notice We are Fullhurst

More information

Sample Data Management Policy Structure

Sample Data Management Policy Structure Sample Data Management Policy Structure This document has been produced by The Audience Agency. You are free to edit and use this document in your business. You may not use this document for commercial

More information

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems LAST UPDATED June 11, 2018 DATA PROTECTION POLICY International Foundation for Electoral Systems 1. Purpose 1.1. International Foundation for Electoral Systems is committed to complying with privacy and

More information

Data Protection Policy

Data Protection Policy Preston and District Data Protection Policy The University of the Third Age Scope of the policy This policy applies to the work of Preston & District U3A (hereafter the U3A ). The policy sets out the requirements

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Reviewed by: Reviewed when Resources Committee As required Date written and last reviewed July 2018 Source and date of model policy, if applicable n/a Contents 1. Aims... 2 2. Legislation

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Mission Statement WeST holds a deep seated belief in education and lifelong learning. Effective collaboration, mutual support and professional challenge will underpin our quest to

More information

Data Protection Policy

Data Protection Policy Data Protection Policy (Data Protection Act 1998) (This policy will be updated to incorporate GDPR by May 2018) Page 1 of 9 Data Protection Policy 1 Statement of Policy The Constellation Trust needs to

More information

Data Protection Policy.

Data Protection Policy. Data Protection Policy. The Leonardo Trust needs to keep certain information on its Employees, Volunteers, Service Users (clients) and Trustees to carry out its day to day operations, to meet its objectives

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

Roundwood Primary School. Privacy Notice Parents

Roundwood Primary School. Privacy Notice Parents Roundwood Primary School Privacy Notice - Parents Name of Policy Privacy Notice Parents Date of adoption April 2018 Date of next review April 2020 Governing Body Committee Responsible Resources Member

More information

2.1.2 Gender, age, date of birth, marital status and nationality;

2.1.2 Gender, age, date of birth, marital status and nationality; PRIVACY STATEMENT FOR THE ROMAN CATHOLIC ARCHDIOCESE OF SOUTHWARK 1 INTRODUCTION 1.1 The Roman Catholic Archdiocese of Southwark (the "Diocese") is a charity registered with the Charity Commission in England

More information

SSI SERVICES (UK) LTD APPLICANT PRIVACY NOTICE

SSI SERVICES (UK) LTD APPLICANT PRIVACY NOTICE SSI SERVICES (UK) LTD APPLICANT PRIVACY NOTICE SSI Services (UK) Ltd is the parent company of the following subsidiary companies: OnSite Central Ltd, Hydrosave UK Ltd, Integrated Water Services Ltd, G

More information

The Society of St Stephen s House Site Security and Monitoring Privacy Notice

The Society of St Stephen s House Site Security and Monitoring Privacy Notice This privacy notice applies to data processing activities undertaken by The Society of St Stephen s House for security and monitoring relating to staff, students and visitors to College premises A summary

More information

POLICY. Data Breach Notification Policy. Version Version 1.0. Equality Impact Assessment Status. Date approved 23 rd May 2018

POLICY. Data Breach Notification Policy. Version Version 1.0. Equality Impact Assessment Status. Date approved 23 rd May 2018 POLICY Document Title Data Breach Notification Policy Version Version 1.0 Equality Impact Assessment Status TBC Approved by Senior Management Team Date approved 23 rd May 2018 Effective date 25 th May

More information

Security of Personal Data Policy and Guidelines

Security of Personal Data Policy and Guidelines Kensington & Chelsea College Security of Personal Data Policy and Guidelines Written by Richard Lane, April 2009 Updated for subject access requests February 2011 1 Introduction KCC holds personal data

More information

Trinity is committed to protecting the privacy and security of personal data.

Trinity is committed to protecting the privacy and security of personal data. This privacy notice applies data processing activities undertaken by Trinity College for security and monitoring relating to staff, students and visitors to Trinity premises including CCTV, other security

More information

THE GENERAL DATA PROTECTION REGULATION (GDPR) A GUIDE FOR CONGREGATIONS

THE GENERAL DATA PROTECTION REGULATION (GDPR) A GUIDE FOR CONGREGATIONS THE GENERAL DATA PROTECTION REGULATION (GDPR) A GUIDE FOR CONGREGATIONS INTRODUCTION The present rules governing how organisations should handle, or process, personal data are set out in the Data Protection

More information

This privacy notice applies to attendees, organisers and others involved in Merton College s conferences and events

This privacy notice applies to attendees, organisers and others involved in Merton College s conferences and events This privacy notice applies to attendees, organisers and others involved in Merton College s conferences and events A summary of what this notice explains Merton College is committed to protecting the

More information

PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING Greenside School

PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING Greenside School PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING Greenside School Greenside School collects data and information about parents / carers of our pupils so that we can operate effectively as a school.

More information

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy DATA PROTECTION POLICY WINCHESTER CITY COUNCIL Document Title: Author: Fiona Sutherland Revision History Version Revision Date Summary of Change Distribution 1.0 08/03/16 Internet Intranet WINCHESTER CITY

More information

DATA PROTECTION POLICY STATEMENT (TIER 1) Client: Born Free Foundation. Born Free Trading Limited

DATA PROTECTION POLICY STATEMENT (TIER 1) Client: Born Free Foundation. Born Free Trading Limited Page: 1 of 17 1. Policy, scope and objectives 1.1 The Board of Trustees and Executive management of and it s affiliated organisations, located at Broadlands Business Campus, Langhurstwood Rd, Horsham,

More information

HOLY TRINITY CE PRIMARY SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS

HOLY TRINITY CE PRIMARY SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS HOLY TRINITY CE PRIMARY SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS Holy Trinity collects data and information about parents / carers of our pupils so that we can operate effectively as a school.

More information

Little Gaddesden C. of E. Primary School

Little Gaddesden C. of E. Primary School PRIVACY NOTICE - PARENTS AND CARERS Approved by Resources Committee 21 May 18 Approved by Governing Body 22 May 18 Review by May 20 Little Gaddesden School collects data and information about parents /

More information

Parents / Carers of Pupils Attending St Catherine s C of E Primary School Privacy Notice

Parents / Carers of Pupils Attending St Catherine s C of E Primary School Privacy Notice Parents / Carers of Pupils Attending St Catherine s C of E Primary School Privacy Notice Created 15th May 2018 PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING ST CATHERINE S C OF E PRIMARY SCHOOL

More information

Brasenose College is committed to protecting the privacy and security of personal data.

Brasenose College is committed to protecting the privacy and security of personal data. This privacy notice (v1.2) applies to data processing activities undertaken by Brasenose College for security and monitoring relating to staff, students and visitors to College premises including CCTV,

More information

PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING: St Luke s School

PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING: St Luke s School St Luke s School Policies, Guidance & Procedures PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING: St Luke s School St Luke s School collects data and information about parents / carers of our pupils

More information

FOOTBALL ASSOCIATION OF IRELAND DATA PROTECTION POLICY

FOOTBALL ASSOCIATION OF IRELAND DATA PROTECTION POLICY FOOTBALL ASSOCIATION OF IRELAND DATA PROTECTION POLICY 2018 1 TABLE OF CONTENTS Glossary of Terms... 3 Introduction... 4 Data Protection Commissioner... 4 Purposes for Holding Personal Information... 4

More information

The Diocese of Galloway - Privacy notice

The Diocese of Galloway - Privacy notice The Diocese of Galloway - Privacy notice Introduction The Diocese of Galloway (the diocese ) is a charity registered with the Office of the Scottish Charity Regulator. Our charity number is SC010576 and

More information

GROUP DATA PROTECTION POLICY

GROUP DATA PROTECTION POLICY GROUP DATA PROTECTION POLICY Conducting business the right way Safeguarding our customer and employee personal data Version 1 [August 2016] CONDUCTING BUSINESS THE RIGHT WAY Our Values, Doing the Right

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title: Data Protection Policy Ref:CP005 Version:2 Approval Body: Corporation via Audit & Risk Committee Date:24th March 2015 Review Date: 24th March 2018 Lead Person: Director, Institutional Effectiveness

More information

Data Protection Policy. UK Policy May 2018

Data Protection Policy. UK Policy May 2018 UK Policy May 2018 5 & 7 Diamond Court, Opal Drive, Eastlake Park, Fox Milne, Milton Keynes MK15 0DU, T: 01908 396250, F: 01908 396251 www.cognitaschools.co.uk Registered in England Cognita Limited No

More information

Data Protection Policy

Data Protection Policy Data Protection Policy General Data Protection Regulations (GDPR) Document control Version control / history Note: This policy requires to be reviewed at least annually from the publication of the last

More information

ScottishPower Data Protection Policy

ScottishPower Data Protection Policy SCOTTISHPOWER CORPORATE SECURITY Nov / 2017 ScottishPower Data Protection Policy In accordance with the Scottish Data Protection Policy ( the policy ) and the Global Personal Data Protection Framework

More information