Click this link to download a PDF version of the Northgate Church Trust Data Protection Policy. Alternatively, scroll down for the web-based version below.
(Updated May 2018)
1.0 Introduction to the Policy
Northgate Church Trust (hereafter referred to as “We”/”Us”/”Data Controller”) use personal data about living individuals for the purpose of general church administration and communication.
We recognise the importance of the correct and lawful treatment of personal data. All personal data, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards and good practice as specified in the General Data Protection Regulation 2018.
We fully endorse and adhere to the eight principles of the GDPR. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data. Employees and any others who obtain, handle, process, transport and store personal data for us must adhere to these principles.
2.0 At A Glance
What information is being collected?
We collect information such as your name, contact details and age.
Who is collecting it?
Northgate Church Trust.
How is it collected?
The information is collected by the completion of forms or electronic submission of data by the person the data relates to.
Why is it being collected and how will it be used?
For general church administration, for communication with you (if you agree) and for statistical analysis.
Who will it be shared with?
Our relevant leaders, staff and volunteer members, but never with anyone else. You can also choose to share your information with other members of the church, but this is up to you.
How will it affect you?
If you agree, you will receive regular email updates and ad hoc correspondence from us.
3.0 The GDPR Principles
The principles require that personal data shall:
Please see the below Database section 5.1.4.
4.0 Your Rights
The rights of the data subject are:
5.0 Maintaining Confidentiality
We will treat all your personal information as private and confidential and will not disclose any data about you to anyone other than the relevant leaders, staff and volunteer members to facilitate the administration and day-to-day ministry of the church, unless you request otherwise.
All Northgate Church Trust leaders, staff and volunteers who have access to Personal Data will be required to agree to and sign the Data Protection Policy.
We will never sell your data, or share it with any external third party other than those listed below, and we promise to keep your data safe and secure.
Third parties who we may share your data with are:
5.1 Exceptions
There are four exceptional circumstances to the above permitted by law:
5.2 Use of Personal Information
We will use your data for three main purposes:
N.B. although collated church data may be passed to a third party, such as number of small groups or small group’s attendance, no personal data will be disclosed.
6.0 Storage of Data
6.1 The Database
Information contained on the database will not be used for any other purposes than set out in this section. The database is accessed through the cloud and therefore, can be accessed through any computer or smart device with internet access. The server for the database is in the UK and hosted by ChurchSuite.
6.2 Other Storage
Occasionally, data needs to be stored outside of the Database. This includes the written consent for data to be used and processed. On these occasions, it will be stored electronically and/or physically.
6.2.1 Electronic data outside of the Database will be stored on the cloud, specifically One Drive, Dropbox and iCloud to which all principals laid out in 6.1 apply.
6.2.2 Physical Data will be stored in a locked office on the church premises. People who will have secure and authorised access to the data include the relevant Northgate Church Trust leaders, staff and volunteer members.
6.2.3 Data should not and will not be stored on authorised person’s personal computers or devices, or at any address other than the local church office.
7.0 Rights to Access Information
Employees and other subjects of personal data held by Northgate Church Trust have the right to access any of their own personal data that is being held in certain manual filing systems. This right is subject to certain exemptions: Personal Information may be withheld if the information relates to another individual.
Any person who wishes to exercise this right should make the request in writing to Northgate Church Trust, using the standard letter which is available online from www.ico.gov.uk
If personal details are inaccurate, they can be amended upon request, or by the data subject if held on the Database.
Northgate Church Trust aims to comply with requests for access to personal information as quickly as possible, but will ensure that it is provided within 30 days of receipt of a completed form unless there is good reason for delay. In such cases, the reason for delay will be explained in writing to the individual making the request.
8.0 Retention of Data
8.1 Database
Data held on the Database will be held as long as the person is an active member of Northgate Church.
After this point, data will be either
8.2 Data Retention Times
Different data will be retained for different periods of time, dependent on the content. Please see table in Appendix 2.
9.0 Cookies Policy
As a person’s IP address is now considered personal data, our website will include a pop up which advises that we use cookies, and states the assumption that any person continuing to use the website gives permission for cookies to be used.
10.0 What if something goes wrong? (Data Security Breaches)
10.1 Definition
A data security breach could be caused by human error or malicious intent and its definition is “any loss of, or unauthorised access to Northgate Church Trust’s data”.
Examples of data security breaches may include:
10.2 Response
Northgate Church Trust’s response to a data security breach will be as follows:
11.0 Key details
Policy Prepared by: Jo Nutt, Office Manager
Approved by Trustees on: 14/05/18
Next review date: 14/5/19
Appendix 1 – Data Protection Policy Understanding and Acceptance
Your details | ||
Name: | ||
Position/Role: | ||
I function in the following role(s): (Please tick those that are applicable) | Staff Member ð Trustee ð Leadership Team Member ð Pastoral Team Member ð Ministry Team Leader ð Small Group / iConnect Group Leader ð Other …………………………………………………….. | |
Signature | ||
I have read and understood the Northgate Church Trust Data Protection Policy and agree to adhere to its contents. I have received and watched the Northgate Church Trust Data Protection Training Presentation and agree to adhere to its contents. We take your privacy seriously. We will only use this information for the purposes laid out in this document and will not share it with any external party. Details are kept in strict accordance with the General Data Protection Regulation of 2018. To view our Data Protection Policy, please visit www.northgate.org.uk/privacy | ||
Signed: | ||
Date: | ||
For office use only | |||||
Received date: | Key Date added to ChurchSuite: | Added by (name): |
Appendix 2 – Data Retention Times
Description of data | How long is data kept for? |
Personal details held on ChurchSuite. | For as long as the individual is an active member of one of Northgate Church, then either: · Deleted immediately, if a person confirms they have officially “left”. · Archived on the database, then deleted after 6 months. |
Details of those who have completed Gift Aid declarations. | 6 years after the last gift claimed, as per UK Gift Aid guidelines. |
Parental consent forms for children/young people. | For as long as the individual is an active member of Northgate Church, and for 3 years following. |
Application to volunteer with children/young people/vulnerable adults. | For as long as applicant is a volunteer with children/young people/vulnerable adults, and for 3 years following. |
DBS Self declaration forms. | Until DBS certificate expires and new DBS is completed, or 3 years from DBS approval date if new DBS is not required. |
Details of DBS certificate numbers and expiry dates. | Until DBS certificate expires and new DBS is completed, or 3 years from DBS approval date if new DBS is not required. |
Safeguarding incident report forms. | Indefinitely, a minimum of 10 years. |
Accident report forms. | Indefinitely, a minimum of 10 years. |
Staff employment contracts. | 6 calendar years after contract ends/is terminated by employee or employer. |
Employee new starter forms and details. | For as long as the individual is an employee of Northgate Church Trust, and for 6 years following. |
Employee tax codes. | For as long as the individual is an employee of Northgate Church Trust, and for 6 years following. |
Employee Pensions details. | For as long as the individual is an employee of Northgate Church Trust, and for 6 years following. |
Staff annual review forms. | For as long as the individual is an employee of Northgate Church Trust, and for 6 years following. |
Reference requests and forms. | 4 years from issue of reference. |
Contracts for letting of rooms in the church house | 6 years after contract ends. |
Contracts for letting of rooms in the church building. | 6 years after hire event ends. |
CCTV Recording | 2 weeks |
Consultant Terms of Engagement | 6 calendar years after contract ends/is terminated by consultant or Trust. |
Appendix 3 – Data Breach Incident Report Form
Incident Report | |||||||
Description of the Data Breach: | |||||||
Time & Date Data Breach was identified and by whom: | Time: | Date: | |||||
By whom: | |||||||
Who is reporting the Breach: | Name: | ||||||
Position: | |||||||
Site: | |||||||
Email: | |||||||
Telephone: | |||||||
Type of data breached: | Public data ð Internal data ð Confidential data (including personal details) ð | ||||||
Volume of data breached: | |||||||
Is the breach: (Tick one for each row) | Confirmed | Suspected | |||||
Contained | Ongoing | ||||||
If Ongoing, what actions are being taken to recover the data? | |||||||
Who has been informed of the Breach? | |||||||
Any other relevant information: | |||||||
For office use only | |||||
Received by: | Date: | Time: | |||
Action taken: |
Appendix 4 – Glossary
Data Controller
The body or organization that holds and processes the data. In this case, Northgate Church Trust.
Data Subject
The person about which the data is held.
Data Processor
An external organization that processes data on behalf of the Data Controller.
Data Protection Lead
The named person within the organization responsible for Data Protection. In this case the Office Manager.
Personal Data
Personal Data refers to any information about a living person and includes