Data Protection Policy at St ANdrew’s church, kirk ella

data protection policy

St Andrew’s Church, Kirk Ella, including the Memorial Hall and St Luke’s Church Hall, is committed to upholding the highest standards of data protection. We comply fully with current UK Data Protection legislation and the General Data Protection Regulation (GDPR).

Any personal information collected by the church will be used only for legitimate purposes connected with our ministry, activities, and the safe running of our buildings. Information will be stored securely, kept only as long as necessary, and never shared with third parties without consent unless legally required.

We take the confidentiality and privacy of all congregation members, visitors, staff, and volunteers very seriously. If you have any questions about how your data is used or wish to exercise your rights, please contact the Church Office.

INTRODUCTION

St Andrew’s Church uses personal data about living individuals for the purposes of general church administration and communication.

St Andrew’s Church recognises the importance of the correct and lawful treatment of personal data. All personal data, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the Data Protection Act 1998 as amended by the General Data Protection Regulation 2018 (the “GDPR”).

St Andrew’s Church fully endorses and adheres to the eight principles of the Data Protection Act. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data.

Employees and any others who obtain, handle, process, transport and store personal data for St Andrew’s Church must adhere to these principles.

THE PRINCIPLES

The principles require that personal data shall:

1. Be processed fairly and lawfully and shall not be processed unless certain conditions are met
2. Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with that purpose
3. Be adequate, relevant and not excessive for those purposes
4. Be accurate and, where necessary, kept up to date
5. Not be kept for longer than is necessary for that purpose
6. Be processed in accordance with the data subject’s rights
7. Be kept secure from unauthorised or unlawful processing and protected against accidental loss, destruction or damage by using the appropriate technical and organisational measures
8. And not to be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

MAINTAINING CONFIDENTIALITY

St Andrew’s Church will treat all your personal information as private and confidential and not disclose any data about you to anyone other than the clergy, employed staff, authorised leadership and ministry overseers/co-ordinators of the church in order to facilitate the administration and day-to-day ministry of the church.

Information and data stored by the Church Office will not be distributed in any form such as digital, hard copy or any other form which might breach the Data Protection Act.

Your personal information will not be given or sold to any other person, company or church.

All employed staff are required to sign a confidentiality clause in their contract of employment.
All clergy, employed staff and authorised leadership and ministry overseers/co-ordinators who have access to personal data obtained under this policy will be required to agree and to sign this Data Protection Policy.

There are four exceptional circumstances to the above permitted by law:

    •  Where we are legally compelled to do so
    •  Where there is a duty to the public to disclose
    •  Where disclosure is required to protect our interest
    •  Where disclosure is made at your request or with your consent

USE OF PERSONAL INFORMATION

We use your personal data for the following uses:

1. The day-to-day administration of the Church including pastoral care and oversight, calls, emails and visits, preparation of ministry rotas, maintaining financial/giving records for audit and tax purposes

2. Contacting you to keep you informed of church news, activities and events

3. Statistical analysis to gain a better understanding of church demographics

4. With your specific permission, for the production of a church contact list which will be made available to other members of St Andrew’s Church through ChurchBuilder.

Data will be held whilst you are a member of the church and destroyed shortly after you leave the church or we receive a written request from you. The exception to this will be where we need to keep statutory records for a longer period. For the purposes of this policy ‘member’ means ‘parish electoral roll member’.

Basis for processing: In many cases we will process your data because we have a “legitimate interest” because you have joined the Electoral Roll of the church or you attend a church group (if you are a parent of a child who is involved in a youth or children’s group and you have filled in a parental consent form for that activity then we will also process you and your child’s data under “legitimate interest”). Otherwise we will ask for your consent through a data-processing consent form such as the general one in Appendix B. Inorder to keep you informed about wider church activities, where appropriate we will include a marketing consent section on data collection forms.

For church members we also process data classified as sensitive data (gender and data which reveals religion). We are able to process such data for members as we are “a not-for-profit body with a religious aim”.

For individuals who are not members, consent is required.

THE MEMBERSHIP DATABASES

Membership information is held on the St Andrew’s Church’s ChurchBuilder website (the church website) which is stored offsite on the ChurchBuilder servers, located in the UK. This information can be accessed by individuals using their own username and password. User can only access the data that they have been given permission to access by virtue of their role.

Information collected by the Church Office will be stored on the Database and will not be used for any other purposes than set out in this section.

1. Access to the database is strictly controlled for Electoral Roll members through the use of self-generated passwords.

2. Only the clergy and church staff have access to the full database. Other ministry leaders have limited access to the data about those in the groups they lead. On occasions temporary full access may be granted to trusted and authorized volunteers for a specific task, but this access must only be given while they are under supervision in the church office.

3. The Database will NOT be accessed by any authorised users outside of the EU in accordance with the Data Protection Act, unless prior consent has been obtained from the individual whose data is to be viewed.

4. Personal information will not be passed onto any third parties outside of the church environment.

5. Personal information may be made available to others within the church environment via the password protected members area of the church website with the express permission of the data subject who will be given the opportunity to ‘opt in’ to this. This information may also be published in a church contact list which will be made available, via the office, verbally or in paper form to church members without website access.

6. The need to process data for normal purposes has been communicated to all data subjects.

STORAGE OF DATA ON OTHER ELECTRONIC MEDIA

All clergy, employed staff and authorised leadership and ministry overseers/co-ordinators who store personal information obtained under this policy on any electronic system not connected to the St Andrew’s church computer network or part of the website are required to do so in accordance with the principles of the Data Protection Act and to take care to ensure that the information remains secure through the use of passwords and encryption where appropriate.

This includes:

    •  Email/telephone/address books/ held on personal computers, mobile phones, PDA’s etc
    •  Data stored on memory sticks and/or portable hard drives

RIGHTS TO ACCESS INFORMATION

Employees and other subjects of personal data held by St Andrew’s Church have the right (with some exceptions) to access any personal data that is being kept about them either electronically or in paper-based filing systems. This right may be withheld if the personal information also relates to another individual, Specifically, all individuals who are the subject of personal data held by St Andrew’s Church are entitled to:

  • Ask what information the church holds about them and why.
  • Ask how to gain access to it.
  • Be informed how to keep it up to date.
  • Be informed what the Church is doing to comply with its obligations under the Data Protection Act.

Any person who wishes to exercise this right should make the request in writing to the Data Controller, using the standard letter which is available on-line from www.ico.gov.uk . St Andrew’s Church reserves the right to charge the maximum fee for each subject access request.

St Andrew’s Church aims to comply with requests for access to personal information as quickly as possible, but will ensure that it is provided within 30 days of receipt of a completed form unless there is good reason to delay. In such cases, the reason for delay will be explained in writing to the individual making the request.

If personal details are found to be inaccurate, they can be amended upon request.

PHOTOGRAPHS

Photographs taken within the Church building or at Church events may include individuals or groups of individuals attending these events. These photographs will be used solely for the purpose of St Andrew’s Church advertising, marketing and public relations, and may thus appear in any advertising internal or external, website or other publicity material.

The Data Protection Act DOES apply where photographs are taken for official use, such as for identity passes, and these images are stored with personal details such as names. Where the Act does apply, it will usually be enough for the photographer to ask for permission to ensure compliance with the Act.

Photographs taken at St Andrew’s Church purely for personal use are exempt from the Data Protection Act. This means that parents, friends and family members can take photographs for the family album of their children and friends participating in church events.

WEBSITE PRIVACY STATEMENT

The following statement is provided for users of the St Andrew’s Church Website.
At St Andrew’s Church we collect different types of information about our users for the following main reasons:

1. To provide an interactive web site where email is used to communicate with the users.

2. To provide a security mechanism whereby we can restrict content to certain groups.

3. To help to improve the service we offer.

 

Our principles
We are absolutely committed to protecting your privacy. Our policy can be summarised in one sentence: we will not share your information with others without your consent.

We have established the following two principles:

1. We will respect your email privacy. You will only receive email from St Andrew’s Church in relation to areas you have expressly signed up for.

2. All group emails will be sent as bcc…to protect privacy.

We will not share any individual user details (including your email address) to any third party without your consent.

 

What information do we collect?

We collect information on our users through a consent form. The minimum information we keep is your first and last name, full postal address, phone number and /or email.

 

Who will have access to your information?

    • You have control over who is able to access specific items of information.
    • By default your information will not be visible to anyone else using the site.
    • You can change these settings from your personal profile page.

 

What else you should know about privacy

Remember to close your browser when you have finished your user session. This is to ensure that others cannot access your personal information and correspondence if you share a computer with someone else or are using a computer in a public place like a library or Internet café. You as an individual are responsible for the security of and access to, your own computer.

Please be aware that whenever you voluntarily disclose personal information over the Internet that this information can be collected and used by others. In short, if you post personal information in publicly accessible online forums, you may receive unsolicited messages from other parties in return.

Ultimately, you are solely responsible for maintaining the secrecy of your usernames and passwords and any account information.

Please be careful and responsible whenever you are using the internet.

Our pages may contain links to other websites, and you should be aware that we are not responsible for the privacy practices on other websites.

0
Your Cart
Your cart is empty.