1) Definitions
Personal data refers to information that identifies an individual. This includes information stored electronically or on paper, as well as images, audio recordings, and written details.
Data protection involves safeguarding the rights and privacy of individuals while ensuring compliance with the law when collecting, storing, using, amending, sharing, destroying, or deleting personal data.
2) Responsibility
The management committee holds overall responsibility for data protection. They oversee activities to ensure this policy is implemented effectively.
All volunteers, committee members, and staff are responsible for adhering to this policy and following related procedures in all aspects of their work with the club.
3) Policy Statement
The Binfield Club collects and manages personal data about its committee, members, volunteers, and supporters to carry out its activities effectively.
We are committed to handling personal data in ways that protect individuals' privacy and comply with the General Data Protection Regulation (GDPR) and other relevant laws.
- We will only collect, store, and use the minimum amount of personal data necessary for clearly defined purposes and avoid retaining data that is not needed.
- Personal data will only be collected, stored, and used for:
- Purposes for which the individual has given explicit consent.
- Legitimate interests of the group.
- Fulfilling contracts with the individual.
- Complying with legal obligations.
- Protecting someone’s life.
- Performing public tasks.
- Individuals have the right to request details about the personal data we hold about them, and we will provide this information upon request.
- We will delete personal data at an individual’s request unless retention is required for legal reasons.
- Personal data will be kept accurate and up-to-date.
- We will store personal data securely.
- The purposes for collecting and holding specific data will be clearly recorded, and data will only be used for these purposes.
- Personal data will not be shared with third parties without the explicit consent of the individual unless required by law.
Data Breaches
We aim to prevent data breaches. However, if a breach occurs, we will:
- Take immediate steps to recover any lost or shared data.
- Review our processes to prevent future occurrences.
- Report serious breaches that may affect someone’s rights or freedoms to the Information Commissioner’s Office (ICO) within 72 hours.
- Notify the individual(s) affected.
Procedures
To support this policy, we will maintain a set of data protection procedures that all committee members, volunteers, and staff must follow.