Privacy Statement / Data Protection / GDPR Policy

Purpose

To ensure that the charity complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, protecting the personal data of our beneficiaries, donors, volunteers, and trustees.

Scope

This policy applies to all personal data held by the charity, whether in paper or electronic form.

Principles

  1. Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and in a transparent manner.
  2. Purpose Limitation: Data will be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  3. Data Minimization: Data collected will be adequate, relevant, and limited to what is necessary.
  4. Accuracy: Personal data will be accurate and kept up to date.
  5. Storage Limitation: Data will be kept in a form that permits identification of data subjects for no longer than necessary.
  6. Integrity and Confidentiality: Data will be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Individual Rights

  1. Right to be Informed: Individuals will be informed about how their data is used.
  2. Right of Access: Individuals have the right to access their personal data.
  3. Right to Rectification: Individuals can have inaccurate data corrected.
  4. Right to Erasure: Individuals can request the deletion of their data.
  5. Right to Restrict Processing: Individuals can request the restriction of their data processing.
  6. Right to Data Portability: Individuals can request their data in a structured, commonly used format.
  7. Right to Object: Individuals can object to the processing of their data.
  8. Rights in Relation to Automated Decision Making and Profiling: Individuals have rights concerning automated decision-making and profiling.

Accountability

The charity will take responsibility for compliance with this policy, including maintaining documentation of data processing activities and implementing appropriate technical and organizational measures.

Data Breaches

In the event of a data breach, the charity will notify the Information Commissioner's Office (ICO) and affected individuals without undue delay.

Review and Update

This policy will be reviewed annually and updated as necessary to ensure ongoing compliance with UK GDPR.

Donate
Help us grow our impact