DATA PROTECTION POLICY
1. Introduction
This policy sets out the framework for an Urras Stòras in Rubha approach to handling information relating to identifiable, living individuals (‘personal data’).
1.1 Personal data are any information from which a person can be identified, directly or indirectly. In addition to basic personal information such as names, contact details etc, it includes opinions expressed about a person and information regarding the intentions of the data controller and third parties about a person. It does not include information that has been appropriately anonymised.
1.2 Processing means anything we do with personal information. For example, collecting, editing, storing, holding, disclosing, sharing, viewing, recording, listening, erasing, deleting, etc. We are committed to processing personal information appropriately and lawfully, in terms of the Data Protection Act 2018 (the ‘2018 Act’) and the General Data protection regulation (“GDPR”).
2. Purpose
Urras Storas an Rubha need to use personal data in order to carry out some of its functions as a local development trust, working on behalf of the local community. It processes and stores personal data on behalf of organisations, service users, leaseholders, contractors, suppliers, employees, volunteers and members. It has a legal duty to protect that personal data.
We use your personal data for the following purposes:
· To administer membership records
· To promote the interests and activities of USAR
· To manage our employees and volunteers
· To maintain our own accounts and records
· To develop and maintain a database of organisations/groups in the Point area
· To inform individuals of news, events, activities, or services delivered by USAR
· To contact individuals via surveys to conduct research and consult about their opinions on current services and future plans for the Point area
The law does not restrict the legitimate use of personal data but does ensure that any use of personal data is subject to safeguards so that the individual’s right to privacy is not unlawfully infringed.
It is important to the efficient operation of Urras Stòras an Rubha that the community has confidence in its ability to protect the privacy of individuals. This policy is intended to enable Urras Stòras an Rubha to demonstrate that it processes personal data in a respectful, fair, lawful and secure way.
3. Scope
The policy applies to all personal data processed by Urras Stòras an Rubha and is part of its approach to compliance with data protection law. All Urras Stòras an Rubha staff and trustees are expected to comply with this policy and failure to comply may lead to disciplinary action.
4. Roles and Responsibilities
All employees and trustees are responsible for protecting personal data, and that applies to data held electronically and in hard copy. The basic principle is that employees and directors must respect the private nature of personal data and take reasonable steps to ensure that no unauthorised person has access to them.
It is important that data are shared proportionately. Only those who need to have access to personal data should do so.
5. Data Protection Principles
Personal data held by Urras Stòras an Rubha is processed in accordance with the 7 GDPR Protection Principles, which stipulate that information must be:
· Processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)
· Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (‘purpose limitation’)
· Adequate, relevant and limited to what is necessary in relation to the purpose for which it is processed (‘data minimisation’)
· Accurate and where necessary, kept up-to-date and reasonable steps will be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’)
· Kept in a form that permits identification of individuals for no longer than is necessary for the purpose for which it is processed (‘storage limitation’)
· Processed securely, with protection against unauthorised or unlawful processing and against accidental loss or damage, using appropriate technical or organisational measures (‘integrity and confidentiality)
· And, in accordance with the seventh principle, we are responsible for and must be able to demonstrate compliance with, the first 6 principles as listed above.
There is stronger legal protection for more sensitive information, such as:
· race
· ethnic background
· political opinions
· religious beliefs
· trade union membership
· genetics
· biometrics (where used for identification)
· health
· sex life or orientation
There are separate safeguards for personal data relating to criminal convictions and offenses.
6. Process and procedures
Urras Storas an Rubha will:
· ensure that the legal basis for processing information is identified in advance and that all processing complies with the law
· not do anything with your data that you would not expect given the content of this policy and the fair processing or privacy notice
· ensure that appropriate privacy notices are in place advising staff and others why their data are being processed and advising data subjects of their rights
· only collect and process the personal data that it needs for purposes it has identified in advance
· ensure that, as far as possible, the personal data it holds is accurate, or a system is in place for ensuring that they are kept up to date as far as possible
· Only hold onto your personal data for as long as needed, after which time Urras Stòras an Rubha will securely erase or delete the personal data
· ensure that appropriate security measures are in place to ensure that personal data can only be accessed by those who need to access them and that they are held and transferred securely.
7. Rights of the Data subjects
7.1 Data subjects have certain rights under the GDPR and the 2018 Act. These include the right to know what personal data are being processed and stored, the purposes of such processing, and the legal basis or bases for the processing.
7.2 Data subjects also have the right to request that we have any inaccurate incomplete personal information rectified, and to have their personal data erased if we are not entitled by law to process them or it is no longer necessary for us to process them for the purpose for which they were collected. In situations where consent is the only legal basis that we have for processing then personal information should be erased if and when the individual revokes that consent.
7.3 Urras Stòras an Rubha will facilitate any request from a data subject who wishes to exercise their rights under data protection law as appropriate, always communicating in a concise, transparent, intelligible and easily accessible form and without undue delay.
8. Data security breach
8.1 A data breach is where there is accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This can happen in many different ways:-
· loss or theft of data or equipment on which personal information is stored;
· unauthorised access to or use of personal information by a member of staff, volunteer or third party;
· loss of data resulting from an equipment or systems failure;
· human error, such as accidental deletion, alteration, or transfer of data;
· unforeseen circumstances, such as fire or flooding;
· deliberate attacks on IT systems, such as hacking, viruses, or phishing scams;
8.2 Should a data security breach occur then we will in the first instance notify the Urras Stòras an Rubha trustees who will take the appropriate decisive action and will assess whether to report the breach to the Information Commissioner’s Office as the Regulator of DPA.
9. Training
Urras Stòras an Rubha will ensure that all staff engaged in the processing of personal information will receive adequate training in data protection.
10. Data Protection Policy Review
The policy will be reviewed and updated as required.
This Data Protection Policy was adopted on (insert date). The company trustees will be responsible for the implementation of this policy.