1. Your personal data – what is it?
Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation (the “GDPR”).
2. Who are we?
The Christchurch Claypath Durham is the data controller (contact details below). This means it decides how your personal data is processed and for what purposes.
3. What data do the controllers listed above process?
They will process some or all of the following where necessary to perform their tasks:
- Names, titles, and aliases, photographs;
- Contact details such as telephone numbers, addresses, and email addresses;
- Where they are relevant to our mission, or where you provide them to us, we may process demographic information such as gender, age, date of birth, marital status, nationality, education/work histories, academic/professional qualifications, hobbies, family composition, and dependants;
- Where you make donations or pay for activities such as weekends away, financial identifiers such as bank account numbers, payment card numbers, payment/transaction identifiers, policy numbers, and claim numbers;
- The data we process is likely to constitute special category data because, as a church, the fact that we process your data at all may be suggestive of your religious beliefs. Where you provide this information, we may also process other categories of special category data: racial or ethnic origin, sex life, mental and physical health, details of injuries, medication/treatment received, political beliefs, labour union affiliation, genetic data, biometric data, data concerning sexual orientation and criminal records, fines and other similar judicial records.
4. How do we process your personal data?
Christchurch Durham complies with its obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
We use your personal data for the following purposes: -
- To enable us to provide a voluntary service for the benefit of the public in a particular geographical area as specified in our memorandum and articles of association;
- To administer the running of various activities at Christchurch Durham;
- To fundraise and promote the interests of Christchurch Durham;
- To manage our employees and volunteers;
- To maintain our own accounts and records (including the processing of gift aid applications);
- To enable us to meet all legal and statutory obligations;
- To carry out comprehensive Safeguarding procedures (including due diligence and complaints handling) in accordance with best safeguarding practice from time to time with the aim of ensuring that all children and adults-at-risk are provided with safe environments;
- To inform you of news, events, activities and services running at Christchurch Durham;
- Sharing your details (with your explicit consent) with other members of Christchurch Durham for the purposes of congregational communication;
- To comply with legal obligations with regard to health and safety and safeguarding
5. What is the legal basis for processing your personal data?
- Explicit consent of the data subject so that we can keep you informed about news, events, activities and services and process your gift aid donations and keep you informed about diocesan events.
- Processing is necessary for carrying out obligations under employment, social security or social protection law, or a collective agreement;
- Processing is necessary to protect the vital interests of individuals and protecting life with regard to safeguarding and individuals medical health and safety;
- Processing is necessary to carry out the legitimate interests of Christchurch Durham in terms of the administering of the voluntary service for the benefit of the public;
- Processing is carried out by a not-for-profit body with a political, philosophical, religious or trade union aim provided: -
- the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes); and there is no disclosure to a third party without consent.
6. Sharing your personal data
Your personal data will be treated as strictly confidential. It will only be shared with third parties where it is necessary for the performance of our tasks where we are legally required to share your personal data, where we share your personal data to protect CCM or another individual, or where you first give us your prior consent. It is likely that we will need to share your personal data with some or all of the following (but only where necessary):
Other members of the Christchurch Durham Congregation (with your consent);
Our agents, servants and contractors. For example, we may ask a commercial provider to maintain our database software e.g. ChurchSuite;
Public Bodies and Government departments (e.g. HMRC for Gift Aid Claims;
On occasion, other churches with which we are carrying out joint events or activities.
7. How long do we keep your personal data?
We keep data in accordance with our data retention policy. Christchurch Durham will retain data only for as long as is necessary and no personal data in any form will be held for longer than is necessary. This means that we may delete it when it is no longer needed. Certain types of data will therefore be kept for longer periods than others based on what is deemed necessary or based on certain legal requirements.
Certain data may be processed for a number of different purposes and therefore different access and use policies will be in effect. When it is deemed that it is no longer necessary to retain data for one particular use, but it is necessary to retain data for other uses, then the policy of access and use for the remaining necessary purposes will be followed. For example, a person and their contact details may be removed from our active use database whilst their details are retained on the gift aid database and form with the appropriate limited access and security over use.
The active database will be reviewed by relevant staff members with access on a quarterly basis. The purpose of this review will be check the accuracy of the data and remove any data where the retention period has lapsed. A full data review of all digital and physical personal data will be conducted annually for the purpose of complying with the data retention policy.
Specifically, we retain visitor, congregation and supporters data whilst it is still current; employment information and records for 6 years after the financial year to which they relate; gift aid declarations, financial records and paperwork for up to 6 years after the financial year to which they relate; children’s group registers for 7 years and the baptism register and any records relating to safeguarding matters permanently.
8. Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data: -
The right to request a copy of your personal data which Christchurch Durham holds about you;
The right to request that Christchurch Durham corrects any personal data if it is found to be inaccurate or out of date;
The right to request your personal data is erased where it is no longer necessary for Christchurch Durham to retain such data;
The right to withdraw your consent to the processing at any time
The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability), (where applicable) [Only applies where the processing is based on consent or is necessary for the performance of a contract with the data subject and in either case the data controller processes the data by automated means].
The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
The right to object to the processing of personal data, (where applicable) [Only applies where processing is based on legitimate interests (or the performance of a task in the public interest/exercise of official authority); direct marketing and processing for the purposes of scientific/historical research and statistics]
The right to lodge a complaint with the Information Commissioner’s Office.
9. Further processing
If we wish to use your personal data for a new purpose, not covered by this Data Protection Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
10. Changes to this notice
We keep this Privacy Notice under regular review and we will place any updates on our website. If we make a significant change, we will notify you. This Notice was last updated in May 2018.
11. Contact Details
To exercise all relevant rights, queries of complaints please in the first instance contact the Church Manager at Christchurch Durham, Simeon House, 32 Claypath, Durham, DH1 1RH; 0191 370 9063; firstname.lastname@example.org
You can contact the Information Commissioners Office on 0303 123 1113 or via email https://ico.org.uk/global/contact-us/email/ or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire. SK9 5AF.