EBRINGTON PRESBYTERIAN CHURCH DATA PRIVACY NOTICE
General Data Protection Regulation EU 2016/679
The data protection law in the UK and EU will change on 25 May 2018.
This notice explains what to expect when we collect, use, retain and disclose your personal data and advises how you can access the personal data we hold about you.
1. What is personal data?
Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession.
The processing of personal data is governed by the General Data Protection Regulation (the “GDPR”).
2. Who are we?
Ebrington Presbyterian Church is a data controller. This means that we decide how your personal data is processed and for what purposes.
3. How do we use your personal data?
We use your personal data to: –
enable us to provide a voluntary service (pastoral care) for the benefit of the public in a geographical area,
- administer membership records,
- fundraise and promote the interests of the Church and its organisations,
- manage our employees and volunteers,
- maintain our own accounts and records (including the processing of gift aid applications),
- inform you of news, events, activities and services running at or run by us and
- share your contact details with the Presbyterian Church in Ireland so they can keep you informed about news and events, activities and services that will be occurring and in which you may be interested.
4. How do we process your personal data?
We comply with our obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
5. What is the legal basis for processing your personal data?
This is dependent upon the individual (data subject) and the purpose of the data processing. For example: the data processing for an employee in terms of what data is collected and how it is further processed is different from that of a member of our congregation.
Legal bases we rely on will primarily consist of one or more of the following:
- processing is necessary for the purposes of legitimate interests pursued by us or a third party except where such interests are overridden by the interests, rights or freedoms of the data subject.This is where we need to use your data to engage in our normal day to day activities e.g. keeping a record of your name and address on our membership list.
- processing is carried out by us in our capacity as a not-for-profit body with a political, philosophical, religious or trade union aim- provided the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes) and there is no disclosure to a third party without consent.
An example of this may be where a record of sensitive data may need to be kept by us so that effective pastoral care may be provided to members.
- explicit consent of the data subject.
An example of this would be your consent to joining a mailing list so that we can keep you informed about news, events, activities and services and process your gift aid donations and keep you informed about PCI events;
- processing is necessary for us to comply with the law.
Examples of this could be our legal obligations to maintain certain records so that we may carry out our obligations under employment, social security or social protection law, or a collective agreement.
- processing is necessary for us to protect the vital interests of a data subject that cannot physically or legally give consent.
An example of this may be for us to run special needs activities.
6. Sharing your personal data
Your personal data will be treated as strictly confidential and will only be shared with other members of the church to carry out a service to other church members or for purposes connected with the church.
We will not normally share your personal data with any third party and will only share your data with third parties outside of ourselves with your consent.
7. How long do we keep your personal data?
This can vary, we retain members’ data while it is still current. Gift Aid declarations and associated paperwork are retained for up to 6 years after the calendar year to which they relate. Presbytery or congregational registers (baptisms, marriages, funerals) are retained permanently.
Where consent has been obtained, for example – for membership of an organisation or to attend a one-off activity we will normally retain this for one year.
8. Your rights
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data: –
- to request a copy of your personal data which we hold about you;
- to request that we correct any personal data if it is found to be inaccurate or out of date;
- to request your personal data is erased where it is no longer necessary for us to retain such data;
- to withdraw your consent to the processing at any time;
- to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller;
- where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
- to object to the processing of personal data;
- to lodge a complaint with the Information Commissioner’s Office.
9. Further processing
If we wish to use your personal data for a new purpose, not covered by this Data Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
10. Requesting access to your personal data
Under the legislation individuals can access the personal data that Ebrington holds about them.
You will be required to complete a Subject Access Request Form (SAR 1) and return to The Data Protection Lead.
Subject Access Request Forms are available from the vestibule and the May Street entrance to the Church. You can obtain a copy from your Elder or download a copy from our website from the link below.
We will aim to provide the relevant data within 1 month of receipt of the request. If the nature of the request is particularly complex, then we may need an extension of time to comply with the request.
We will inform you if this is the case and the reasons why this is necessary. Also, we may need to ask for information that we reasonably need to find the personal data covered by the request.
You will not have to pay a fee to access your personal information (or to exercise any of your other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
11. Contacting us
If you have any questions about this Privacy Notice or our processing of information or if you wish to raise a complaint on how we handled your personal information or if you wish to exercise any of your rights, set out in this Privacy Notice please in the first instance contact:
Data Protection Lead
Ebrington Presbyterian Church,
Limavady Road, Londonderry. BT47 6JU
You can contact The Information Commissioners Office on 02890278757 or via email email@example.com at the Information Commissioner’s Office, 3rd Floor, 14 Cromac Place, Belfast, BT7 2JB
Ebrington Presbyterian Church is a Registered Charity No. 105644