Rotary Club of Lincoln Colonia Privacy Notice

ROTARY CLUB OF LINCOLN COLONIA

Local Data Protection Policy

This policy applies to all club members, club officers and volunteers or any individual or organisation working on behalf of The Rotary Club of Lincoln Colonia

The purpose of this policy:

·      to ensure person identifiable data is controlled and processed in a manner which respects individual rights and our legal obligations

·      to provide club members and volunteers with the overarching principles that guide our approach to data protection.

We will seek to keep personal data secure and accurate by:

Awareness

·      Ensuring all club members and volunteers are aware of the need to protect personal identifiable data

·      Designating a club officer (council member) with specific responsibility for Data Protection

Information we hold

·      We will maintain a personal identifiable data (PID) register

·      Only personal identifiable data (PID) necessary to The Rotary Club of Lincoln Colonia. to carry out its activities as defined in the club objectives will be held. This will include data on the following subjects

o   Club Members

o   Club officers

o   Children (recipients of charity services)

o   Adults (recipients of charity services)

o   Fundraisers

o   Volunteers

o   Donors

o   Others

Communicating privacy

·      We will publish a data privacy statement on our website

·      We will display/publish a data privacy statement at our public events

Individuals rights

·      Subject access requests will be responded to with information in a format accessible to the subject

·      Individuals have the right to request information we hold is amended or deleted

·      Individuals have the right to restrict how The Rotary Club of Lincoln Colonia  processes their data

·      We will respond to Individual requests within the required timescales

 

Subject Access Requests

·      We will respond to Subject Access requests in the UK for data which we hold in accordance with the timescales and requirements of the EU GDPR and UK Data Protection Act

Lawful basis for processing personal data

·      Person Identifiable Data will only be processed by The Rotary Club of Lincoln Colonia where there is a legitimate reason to access the data in carrying out the defined objectives of the charity. Specifically

o   Charity Service Recipient data is processed on the basis of consent

o   Donor & fundraiser data is processed on the basis of consent

o   Volunteer data is processed on the basis of Agreement

Consent

·      Donors and fundraisers will give consent to The Rotary Club of Lincoln Colonia to hold and process their data as part of the donation and fundraiser registration

·      Individual recipients of charity services will give consent to The Rotary Club of Lincoln Colonia to hold and process their data

Children

·      The Rotary Club of Lincoln Colonia does not offer any online services to children.

Data Breaches

·      Any data breach (or suspected breach) will be referred to the Data Protection Lead who will be responsible for investigating the breach/potential breach and if required reporting to the RIBI Data Protection Lead who will in turn report if required report to the Information Commissioner Office (ICO) as required under GDPR.

·      Risk assessments will include an assessment of the risk of data breaches

Data protection by design and Data protection impact assessments

·      Recording and storing information professionally and securely

·      Maintaining a personal identifiable data (PID) register

·      No automated decision making (including profiling) based on individual’s data will be carried out.

Data Protection Officer

·      A Data protection officer (DPO) is not required to be assigned locally

Registration

·      RIBI as the responsible legal organisation will be responsible for registering for payment of a data protection fee with the Information Commissioners Office (ICO).

 

International

·      As The Rotary Club of Lincoln Colonia does not operate in any EU states other than the UK the lead data protection authority will be the UK Information Commissioners Office (ICO).

General

·      Providing effective management for members and volunteers through supervision, support, training and quality assurance measures

·      Ensuring we have effective complaints and whistleblowing measures in place

Record Retention & Disposal

·      Personal Identifiable data collected as part of an event or project will be held for the duration of the project the data was collected for and for a further period of no more than six months (unless there is a statutory requirement to hold data for longer periods).

Legal Framework

The policy has been drawn up on the basis of law and guidance, applicable within the UK, that seeks to protect children, namely:

·      Data Protection Act 1998

·      EU General Data Protection Regulations (GDPR) 2016 (UK enforceable May 2018)

·      Computer misuse act 1990

·      Human Rights Act 1998

This policy should be read alongside all other Rotary Club of Lincoln Colonia and RIBI  Policies


Contact Details

Data Protection Lead (club officer)

Name

Email

We are committed to reviewing our policy and good practice annually.

This policy was last reviewed on  15th May 2018

Signed :

(President)

Cookies:

Like most websites, we use “cookies” to help us make our site, and the way you use it, better. We do not store any personal data in the cookies that we use. Cookies mean that a website will remember you. They’re small text files that sites transfer to your computer (or phone or tablet). They make interacting with a website faster and easier – for example by automatically filling your name and address in text fields.

In addition, the type of device you’re using to access our website or apps and the settings on that device may provide us with information about your device, including what type of device it is, what specific device you have, what operating system you’re using, what your device settings are. Your device manufacturer or operating system provider will have more details about what information your device makes available to us.

The type and quantity of information we collect and how we use it depends on why you are providing it. You should be able to control what cookies are placed on your device through your browser settings. Go to www.aboutcookies.org to find out more about cookies, including how to see what cookies have been set and how to manage and delete them.