PRIVACY NOTICE

Who we are

The Committee of the Old Down Wildlife Group is the data controller (contact details below). This means it decides how your personal data is processed and for what purposes.

Our website address is: https://olddownwildlifegroup.org.uk

Our email address is: Old.Down.Wildlife@gmail.com

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller's possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation (the “GDPR”).

How do we process your personal data in general?

The Committee of the Old Down Wildlife Group complies with its obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.

We use your personal data for the following purposes:

  • To enable us to provide a voluntary service for the benefit of the public in a particular geographical area as specified in our constitution;
  • To administer membership records;
  • To fundraise and promote the interests of the group;
  • To manage and inform our volunteers;
  • To maintain our own accounts and records (including the processing of any Gift Aid applications);
  • To inform you of news, events, activities and services run by the Group

What is the legal basis for processing your personal data?

  • Explicit consent of the data subject so that we can keep you informed about news, events, activities and share newsletters.
  • Processing is necessary for carrying out legal obligations in relation to Gift Aid.
  • Processing is carried out by a not-for-profit body with a political, philosophical, religious or trade union aim provided:
    • the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes); and
    • there is no disclosure to a third party without consent.

Sharing your personal data

Your personal data will be treated as strictly confidential and will only be shared with other members of the Group in order to carry out a service to other Group members or for purposes connected with the Group. We will only share your data with third parties outside of the Group with your consent, unless required to do so by law or court order.

How long do we keep your personal data?

We keep data in accordance with our Document Retention Policy (Appendix 3 of this document).

Your rights and your personal data

Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:

  • The right to request a copy of your personal data which the Old Down Wildlife Group holds about you;
  • The right to request that the Old Down Wildlife Group corrects any personal data if it is found to be inaccurate or out of date;
  • The right to request your personal data is erased where it is no longer necessary for the Old Down Wildlife Group to retain such data;
  • The right to withdraw your consent to the processing at any time
  • The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller (known as the right to data portability);
  • The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
  • The right to object to the processing of personal data;
  • The right to lodge a complaint with the Information Commissioners Office.

Further processing

If we wish to use your personal data for a new purpose, not covered by this Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.

Contact Details

To exercise all relevant rights, raise queries or make complaints please in the first instance contact the data controller's representatives. Using the below details:

The Chair
Old Down Wildlife Group Committee
By email to Old.Down.Wildlife@gmail.com

Disputes

Should you have any disputes and/or concerns with how your personal data has been used in the first instance you should contact the Group's data protection officer using the address above.

You also have the right to complain to the Information Commissioner's Office, the supervisory authority, about our collection and use of your personal data. They can be contacted on 0303 123 1113 or via email https://ico.org.uk/global/contact-us/email/ or at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Their website is www.ico.org.uk

Appendix 1: DEFINITION OF SECURE

Introduction

Below are the minimum requirements that the Old Down Wildlife Group will adhere to when storing all personal data without exception.

Hard data

Hard data is personal data that is stored with physical copies, e.g. paper.

Wherever practical, the Old Down Wildlife Group will keep all hard data in locked cabinets when not in use.

Soft data

Soft data is personal data stored on computers of any nature including desktops, laptops, tablets, phones and cloud services (devices).

All soft data stored on Old Down Wildlife Group owned devices will be encrypted, and soft data held on other devices not owned by the Group should have a minimum of password protection.

All distributed personal data (e.g. membership lists) will have access limited to those with legitimate needs to access, and this list of people will be available on request.

Appendix 2: DATA DELETION POLICY

All personal data held by the Old Down Wildlife Group will be deleted within 21 days of receipt of a formal request, made to the Data Controller through the appropriate representative. Exceptions are made for any data required to be held by law.

Please see also the Data Privacy Notice displayed on our website for all definitions.

Appendix 3: DOCUMENT RETENTION POLICY

Principles

  1. Documents stored in the cloud do not need to be printed unless there is a statutory requirement for us to retain hardcopy for Central Records.
  2. The primary location for storing any hardcopy will be determined by the author and secured.
  3. Documents stored in the cloud will exist within the folder system of the organisation by or for which they were generated.

Retention Periods

Documents stored in the cloud will be retained indefinitely unless otherwise required by Data Protection Legislation / Policy or other statute. In the event that space should become an issue with the cloud, the Committee will determine which documents may safely be deleted.

Documents stored as hardcopy will be retained following this principle:

  • We keep all records for 7 years before being destroyed; except where legal requirements (e.g. HMRC or Council regulations) require otherwise

Cloud Folders

These are the responsibility of the leader of the group or team for which the folders were created. Documents within these folders may be retained indefinitely. Hardcopies are not required.

Permissions to cloud storage are maintained by the Committee. Changes to Committee and other organisation membership should be notified as early as possible to allow for proper permissions to be added or removed.

Appendix 4: SUBJECT ACCESS REQUEST (SAR) PROCESS

If a Subject Access Request (SAR) is received by the Committee of the Old Down Wildlife Group, this process sets out how the request will be managed.

Scope

This process applies to all personal data processed by the Committee of the Old Down Wildlife Group.

Roles and Responsibilities

The Chair has overall responsibility for GDPR compliance. The Committee also have responsibility for ensuring GDPR compliance.

Process: Rules and Guidance

Unless subject to an exemption under the Data Protection Act (DPA) 2018 & General Data Protection Regulation 2016/679 (“GDPR”), individuals have the right to:

  • The right to request a copy of your personal data which the Old Down Wildlife Group holds about them;
  • The right to request that the Old Down Wildlife Group corrects any personal data if it is found to be inaccurate or out of date;
  • The right to request that their personal data is erased where it is no longer necessary for the Old Down Wildlife Group to retain such data (see the deletion policy);
  • The right to withdraw their consent to the processing at any time
  • The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability);
  • The right, where there is a dispute in relation to the accuracy or processing of personal data, to request a restriction is placed on further processing;
  • The right to object to the processing of personal data, for any reason deemed to not interfere with the legal obligations of the Group;
  • The right to lodge a complaint with the Information Commissioners Office.

Anyone can ask the Old Down Wildlife Group to provide the above information. Any such request is known as a Subject Access Request.

There is a statutory requirement to respond to a SAR promptly, and in any event within 30 calendar days of receipt of an appropriate request.

Requests to the Committee of the Old Down Wildlife Group

The Secretary will initially deal with any Subject Access Requests.

All requests which appear to be requests for information from an individual received by any other than the Secretary should be sent unacknowledged to old.down.wildlife@gmail.com immediately.

Upon receipt, the Secretary will consider whether the request is appropriate, including:

  • Ensuring the request is in writing;
  • If the request is made by a third party that they are acting on that individual's behalf and have provided that individual's authority;
  • That the data requested is their personal data and not that relating to another individual;
  • Whether we have enough information to be able to locate their personal data;
  • It is not an identical request to one that has already been dealt with recently;
  • Whether an exemption to the subject information provisions applies, such as where data is processed for the prevention or detection of crime, is legally privileged, is publicly available information, or amounts to a record of negotiations with that person which would be prejudiced by subject access.

If the request is not appropriate, the Chair will write to the individual, advising why we are not in a position to respond.

If the request is appropriate, the Chair will write to the individual to confirm the date by which our response will be provided, in accordance with the 30-day time limit.

The Chair will then take steps to access all relevant personal data for that individual from relevant locations within the Group's systems. Anyone asked to provide information in connection with a SAR is asked to do so promptly, given the timescale for us to respond.

On receipt of relevant information, the Chair will review it to determine what personal data can be provided in response to the SAR.

The Chair will specifically determine the following, prior to disclosing relevant information in response to the SAR:

  • Whether certain information should not be disclosed as a relevant exemption under the DPA applies; or
  • Whether other third-party personal data should be redacted prior to the disclosure of information.

A record of the response provided must be retained in a secure location.

Note

This policy is not contractual and is subject to change at the Group's discretion. This policy will be reviewed from time to time to make sure it continues to meet the Group's legal obligations and the needs of the Group.

Appendix 5: THE OLD DOWN WILDLIFE GROUP'S DATA BREACH REPORT FORM

Definition

A personal data breach is one that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

GDPR makes informing the Information Commissioners Office (see the Privacy Notice for contact details) and the individual(s) affected compulsory in certain circumstances, (e.g. where there is a high risk to the individuals involved, for instance, through identity theft).

We have to notify the ICO of a data breach within 72 hours of finding out about this. It is important that those in the Group note this deadline and seek the advice of the ICO about any suspected breaches without delay.

More details can be provided after 72 hours, but before then the ICO will want to know the potential scope and the cause of the breach, mitigation actions we plan to take, and how we plan to address the problem.

All suspected data breaches must be reported to the Chair or one of the Committee members by completion of Part A of this form. The first person within the Old Down Wildlife Group who learns of the suspected data breach must complete this form, in the role of “Reporter”, and ensure that the form is submitted to the Chair or one of the Committee members within 24 hours.

Part A

The reporter records:

  • Reporter name
  • Date of Report, and Date of Breach
  • Type of Breach
  • Description of Breach (full details of breach committed)
  • Impact of breach (what has been the impact of the breach against the person(s) whose data has been affected)
  • Other complaints arising from breach
  • Signature and date

Part B — Old Down Wildlife Group's Use Only

  • Investigating officer
  • Investigation outcome
  • Report to BDBC?
  • Report to ICO?
  • Signature, position and date