{"id":4740,"date":"2018-06-10T17:55:41","date_gmt":"2018-06-10T16:55:41","guid":{"rendered":"http:\/\/burnheadchurch.ddns.net\/?page_id=4740"},"modified":"2018-06-10T17:55:41","modified_gmt":"2018-06-10T16:55:41","slug":"data-protection-policy","status":"publish","type":"page","link":"https:\/\/burnheadchurch.com\/?page_id=4740","title":{"rendered":"Data Protection Policy"},"content":{"rendered":"<p class=\"western\" align=\"center\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: large;\"><b>UDDINGSTON BURNHEAD PARISH CHURCH <\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"center\"><span style=\"font-size: large;\"><b>Data Protection Policy <\/b><\/span><\/p>\n<p class=\"western\">\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>CONTENTS<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>1. Overview<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>2. Data Protection Principles<\/b><\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>3. Personal Data<\/b><\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>4. Special Category Data<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>5. Processing<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>6. How personal data should be processed<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>7. Privacy Notice<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>8. Consent<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>9. Security<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>10. Sharing personal data<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>11. Data security breaches<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>12. Subject access requests<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>13. Data subject rights<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>14. Contracts<\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>15. Review<\/b><\/span><\/span><\/p>\n<p class=\"western\">\n<p class=\"western\" align=\"center\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><u><b>Data Protection Policy<br \/>\n<\/b><\/u><\/span><\/span><\/p>\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Overview <\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">The congregation takes the security and privacy of personal information seriously. As part of our activities we need to gather and use personal information about a variety of people including members, former members, adherents, employees, office-holders and generally people who are in contact with us. The<\/span><\/span><b> <\/b><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Data Protection Act 2018 (the \u201c2018 Act\u201d) and the EU General Data Protection Regulation (\u201cGDPR\u201d) <\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">regulate the way in which personal information about living individuals is collected, processed, stored or transferred.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">This policy explains the provisions that we will adhere to when any personal data belonging to or provided by data subjects, is collected, processed, stored or transferred on behalf of the congregation. We expect everyone processing personal data on behalf of the congregation (see paragraph 5 for a definition of \u201cprocessing\u201d) to comply with this policy in all respects.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"3\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">The congregation has a separate Privacy Notice which outlines the way in which we use personal information provided to us. A copy can be obtained from David Combe, our Congregational Data Protection Co-Ordinator. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"4\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">All personal data must be held in accordance with the congregation\u2019s Data Retention Policy, which must be read alongside this policy. A copy of the Data Retention Policy can be obtained from David Combe, our Congregational Data Protection Co-ordinator. Data should only be held for as long as necessary for the purposes for which it is collected. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"5\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">This policy does not form part of any contract of employment (or contract for services if relevant) and can be amended by the congregation at any time. It is intended that this policy is fully compliant with the 2018 Act and the GDPR. If any conflict arises between those laws and this policy, the congregation intends to comply with the 2018 Act and the GDPR.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"6\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Any deliberate or negligent breach of this policy by an employee of the congregation may result in disciplinary action being taken in accordance with our disciplinary procedure. It is a criminal offence to conceal or destroy personal data which is part of a subject access request (see Paragraph 12 below) and such conduct by an employee would amount to gross misconduct which could result in dismissal.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Data Protection Principles<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data will be processed in accordance with the six \u2018<\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Data Protection Principles<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">.\u2019 It must:<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">be processed fairly, lawfully and transparently;<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">be collected and processed only for specified, explicit and legitimate purposes;<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">be adequate, relevant and limited to what is necessary for the purposes for which it is processed;<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">be accurate and kept up to date. Any inaccurate data must be deleted or rectified without delay;<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">not be kept for longer than is necessary for the purposes for which it is processed; and<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">be processed securely.<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">We are accountable for these principles and must be able to demonstrate compliance.<\/span><\/span><\/p>\n<ol start=\"3\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Definition of personal data<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\">\u201c<span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Personal data\u201d<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"> means information which relates to a living person (a \u201cdata subject\u201d) who can be identified from that data on its own, or when taken together with other information which is likely to come into the possession of the data controller. It includes any expression of opinion about the person and an indication of the intentions of the data controller or others, in respect of that person. It does not include anonymised data.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">This policy applies to all personal data whether it is stored electronically, on paper or on other materials.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"4\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Definition of special categories of personal data<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\">\u2018<span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Special categories of personal data<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">\u2019 are types of personal data consisting of information revealing:<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><i>racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic or biometric data; health; sex life and sexual orientation; and any criminal convictions and offences<\/i><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">.<\/span><\/span><\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">A significant amount of personal data held by the congregation will be classed as special category personal data, either specifically or by implication, as it could be indicative of a person\u2019s religious beliefs. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"5\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Definition of processing<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\">\u2018<span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Processing\u2019<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"> means any operation which is performed on personal data, such as collection, recording, organisation, structuring or storage; adaption or alteration; retrieval, consultation or use; disclosure by transmission, dissemination or otherwise making available; and restriction, destruction or erasure.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"6\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>How personal data should be processed<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Everyone who processes data on behalf of the congregation has responsibility for ensuring that the data they collect and store is handled appropriately, in line with this policy, our Data Retention policy and our Privacy Notice. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data should only be accessed by those who need it for the work they do for or on behalf of the congregation. Data should be used only for the specified lawful purpose for which it was obtained.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"3\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">The legal bases for processing personal data (other than special category data, which is referred to in Paragraph 8 below) are that the processing is necessary for the purposes of the congregation\u2019s legitimate interests; or that (so far as relating to any staff whom we employ) it is necessary to exercise the rights and obligations of the congregation under employment law.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol start=\"4\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data held in all ordered manual files and databases should be kept up to date. It should be shredded or disposed of securely when it is no longer needed. Unnecessary copies of personal data should not be made.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Privacy Notice<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">If someone would not reasonably expect the way in which we use their personal data, we will issue information about this using a Privacy Notice which will be given to them at the point when the data is provided. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">If our use of personal data is what someone would reasonably expect, we will provide information about this using a Privacy Notice which will be available on the congregation\u2019s website and can be found on the church noticeboard.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>When is consent needed for the processing of personal data?<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">A significant amount of personal data held by the congregation will be classed as special category personal data, as it could be indicative of someone\u2019s religious beliefs. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">8.2 Processing of such special category data is prohibited under the GDPR unless one of the listed exemptions applies. Two of these exemptions are especially relevant (although others may also apply):<\/span><\/span><\/p>\n<ul>\n<li>\n<p align=\"justify\"><a name=\"a9_p2a\"><\/a><a name=\"zeile_263\"><\/a> <span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">the individual has given <\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>explicit consent<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"> to the processing of the personal data for one or more specified purposes; OR<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<p align=\"justify\">\n<ul>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data is not disclosed outside that body without the consent of the data subjects. <\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">8.3 Most of the processing carried out by the congregation will fall within the latter exemption, and will be carried out by the congregation with appropriate safeguards to keep information safe and secure. This information will not be disclosed outside the Church without consent. Such processing will not require the explicit consent of the data subject. <\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">8.4 Where personal data is to be shared with a third party, the congregation will only do so with the explicit consent of the data subject. For example, personal data will only be included in a directory for circulation or included on a website where consent has been obtained.<\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">8.5 If consent is required to process the information this should be recorded using the style consent form. If consent is given orally rather than in writing, this fact should be recorded in writing. <\/span><\/span><\/p>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Keeping personal data secure <\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data should not be shared with those who are not authorised to receive it. Care should be taken when dealing with any request for personal information over the telephone or otherwise. Identity checks should be carried out if giving out information to ensure that the person requesting the information is either the individual concerned or someone properly authorised to act on their behalf. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Hard copy personal information should be stored securely (in lockable storage, where appropriate) and not visible when not in use. Filing cabinets and drawers and\/or office doors should be locked when not in use. Keys should not be left in the lock of the filing cabinets\/lockable storage. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"3\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Passwords should be kept secure, should be strong, changed regularly and not written down or shared with others. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"4\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Emails containing personal information should not be sent to or received at a work email address (other than an @churchofscotland.org address) as this might be accessed by third parties. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"5\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">The \u2018bcc\u2019 rather than the \u2018cc\u2019 or \u2018to\u2019 fields should be used when emailing a large number of people, unless everyone has agreed for their details to be shared amongst the group.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"6\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">If personal devices have an @churchofscotland.org account linked to them these should not be accessed on a shared device for which someone else has the pin code. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data should be encrypted or password-protected before being transferred electronically. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"8\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Personal data should never be transferred outside the European Economic Area except in compliance with the law. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Sharing personal data<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">We will only share someone\u2019s personal data where we have a legal basis to do so, including for our legitimate interests within the Church of Scotland (either within the Presbytery or to enable central databases held within the Church Office at 121 George Street, Edinburgh to be maintained and kept up to date). This may require information relating to criminal proceedings or offences or allegations of offences to be processed for the protection of children or adults who may be at risk and to be shared with the Church\u2019s Safeguarding Service or with statutory agencies.<\/span><\/span><\/p>\n<\/li>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">We will not send any personal data outside the European Economic Area. If this changes all individuals affected will be notified and the protections put in place to secure your personal data, in line with the requirements of the GDPR, will be explained.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>How to deal with data security breaches<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Should a data security breach occur, the congregation will notify the Presbytery Clerk <\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>immediately.<\/b><\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"> If the breach is likely to result in a risk to the rights and freedoms of individuals then the Information Commissioner\u2019s Office must be notified within 72 hours.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">9.2 Breaches will be handled by the Presbytery Clerk in accordance with the Presbytery\u2019s data security breach management procedure.<\/span><\/span><\/p>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Subject access requests<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Data subjects can make a subject access request to find out what information is held about them. This request must be made in writing. Any such request received by the congregation should be forwarded immediately to the Presbytery Clerk who will coordinate a response within the necessary time limit (30 days).<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">It is a criminal offence to conceal or destroy personal data which is part of a subject access request. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>Data subject rights<\/b><\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Data subjects have certain other rights under the GDPR. This includes the right to know what personal data the congregation processes, how it does so and what is the legal basis for doing so. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"2\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">Data subjects also have the right to request that the congregation corrects any inaccuracies in their personal data, and erase their personal data where we are not entitled by law to process it or it is no longer necessary to process it for the purpose for which it was collected. D<\/span><\/span><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">ata should be erased when an individual revokes their consent (and consent is the basis for processing); when the purpose for which the data was collected is complete; or when compelled by law. <\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"7\">\n<li style=\"list-style-type: none;\">\n<ol start=\"3\">\n<li>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">All requests to have personal data corrected or erased should be passed to David Combe, who will be responsible for responding to them in liaison with the Presbytery Clerk.<\/span><\/span><\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>14. Contracts <\/b><\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">14.1 If any processing of personal data is to be outsourced from the congregation, we will ensure that the mandatory processing provisions imposed by the GDPR will be included in the agreement or contract. <\/span><\/span><\/p>\n<p class=\"western\" align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\"><b>15. Policy review <\/b><\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, serif;\"><span style=\"font-size: medium;\">The Kirk Session will be responsible for reviewing this policy from time to time and updating the congregation in relation to its data protection responsibilities and any risks in relation to the processing of data.<\/span><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UDDINGSTON BURNHEAD PARISH CHURCH Data Protection Policy CONTENTS 1. Overview 2. Data Protection Principles 3. Personal Data 4. Special Category Data 5. Processing 6. How personal data should be processed 7. Privacy Notice 8. Consent 9. Security 10. Sharing personal data 11. Data security breaches 12. Subject access requests 13. Data subject rights 14. Contracts [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/pages\/4740"}],"collection":[{"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4740"}],"version-history":[{"count":2,"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/pages\/4740\/revisions"}],"predecessor-version":[{"id":4743,"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=\/wp\/v2\/pages\/4740\/revisions\/4743"}],"wp:attachment":[{"href":"https:\/\/burnheadchurch.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}