POLICIES & PROCEDURES
Data Protection
Revised 21 August 2020
1. Policy
-
The Worcester Society of Artists (the Society) takes very seriously the protection of the personal data with which it is entrusted.
-
The Society has a Data Protection Policy and appropriate Procedures. The Policy and Procedures will be reviewed annually.
-
The purpose of this Policy is to demonstrate that the Society has a robust approach to data protection.
-
The Society will store and use personal data only for the purpose: a. of running the Society, and b. to contact individuals about meetings and events that are being run by the Society or associated organisations.
-
Personal data will not be shared with any other organisation, nor will it be shared with members of the Society other than members of the committee for the purpose of running the Society.
-
No sensitive personal data will be held about Members.
2. Responsibilities
-
The Branch Committee appoints from time to time an individual to be the Data Protection Lead.
-
The Data Protection Lead is responsible for managing Data Protection within the Branch. This includes maintaining and reviewing the Policy and Procedures.
-
The Committee is responsible for approving the Policy and Procedures and any changes thereto.
-
Those on the Committee who handle personal data are personally responsible for adhering to the Policy and Procedures.
3. Procedures
-
All personal data held by the Worcestershire Society of Artists (the Society) must be identified and a Schedule prepared.
-
The Schedule must document:
a. the type of data held
b. the details of the data held
c. how the data is collected
d. how the data is stored
e. what the data is used for
f. when the data is destroyed
-
Personal data must only be collected, stored, used and destroyed in accordance with the Schedule.
-
Consent must be obtained before any personal data can be held or used by the Branch. Giving an 'opt out' facility is not sufficient. The consent must be recorded.
-
Individuals can request that the Branch deletes their personal data. If the individual is a Member then their membership will be terminated.
-
Personal data must only be made available to members of the Committee or others, as defined in the Schedule, who need access to carry out their role or duties.
-
When sending e-mails to Members or other interested parties the latest list of e-mail addresses from the appropriate spreadsheet must be used as the data is frequently updated.
-
Any e-mails sent to all Members, must be sent via worcesterarts@googlegroups.com which by default does not show the e-mail addresses of recipients. Emails sent to selected groups of members (eg attendees/ exhibitors at an event) must be blind copied (BCC), rather than sent or copied (CC), to the distribution list so that the e-mail addresses are not revealed to recipients. Care must also be taken when forwarding an existing e-mail chain that email addresses and other personal details are not revealed to the recipients. This constraint does not apply to e-mails sent solely between members of the Committee.
-
Any suspected or actual breaches of the Policy or Procedures must be reported immediately to the Data Protection Lead or, in their absence, to another Committee member. They will investigate and decide on any remedial or preventative actions to be taken and also report any non-trivial data loss to the Information Commissioner's Office within 72 hours of becoming aware of an actual data loss. All suspected or actual breaches will also be discussed and minuted at the next Committee meeting.
-
When someone joins the Committee they must confirm by e-mail to the Data Protection Lead that:
a. they have read the Policy and Procedures and will abide by them, and
b. agree that when they leave the Committee they will carry out the actions listed in paragraph 11.
-
When someone leaves the Committee they must: a. pass any personal data they alone hold to another Committee member, and then b. destroy all personal data they hold. Electronic data (e-mails, documents and spreadsheets) should be deleted and then further deleted from the recycle bin or deleted items. Such data must also be deleted from any data backups if possible. Any paper documents should be confidentially destroyed or returned to the Committee. c. Confirm by e-mail to the Data Protection Lead that they have carried out the actions in a) and b) above.
