Introduction
The security and management of personal data is important to ensure that RSS can function effectively and successfully for the benefit of our customers and sector.
In doing so, it is essential that people’s privacy is protected through the lawful and appropriate use and handling of their personal information.
The use of all personal data by RSS is governed by:
- The UK General Data Protection Regulation (GDPR)
- The UK Data Protection Act 2018
- The Privacy and Electronic Communications Regulations
The GDPR defines personal data as “any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.
Every member of Charity Personnel: all employees, volunteers, workers, contractors, agency workers, consultants, directors, members, and others, has a responsibility to adhere to the Data Protection Principles outlined in the GDPR, and to this Data Protection Policy. Other relevant RSS policies include the Privacy Policy (for contracts) and IT Policy.
If you have a question about this Data Protection Policy or a concern about data protection matters, please contact the RSS Administrator who acts as RSS’s Data Protection Officer (DPO) by emailing: info@regionalscreenscotand.org
Data protection principles
There are six data protection principles defined in Article 5 of the GDPR. These require that all personal data be:
- processed in a lawful, fair, and transparent manner.
- collected only for specific, explicit, and limited purposes (‘purpose limitation’).
- adequate, relevant, and not excessive (‘data minimisation’).
- accurate and kept up to date where necessary.
- kept for no longer than necessary (‘retention’).
- handled with appropriate security and confidentiality.
RSS is committed to upholding the data protection principles. All personal data under our control must be processed in accordance with these principles.
Lawful processing
All processing of personal data must meet one of the six lawful bases defined in Article 6 of the GDPR:
- Where we have the consent of the data subject.
- Where necessary to fulfil a contract, or pre-contractual obligations.
- Where necessary to meet a legal obligation.
- Where we are protecting someone’s vital interests.
- Where we are fulfilling a public task or acting under official authority.
- Where it is in our legitimate interests, and this is not overridden by the rights and freedoms of the data subject.
- Any special category data (sensitive types of personal data as defined in Article 9 (1) of the GDPR) must further be processed only in line with one of the conditions specified in Article 9 (2).
- Where processing is based on consent, the data subject has the option to easily withdraw their consent.
- Where electronic direct marketing communications are being sent, the recipient should have the option to opt-out in each communication sent, and this choice should be recognised and adhered to by us.
Data minimisation and control
- RSS will keep the personal data that we collect, use, and share to the minimum amount required to be adequate for its purpose.
- Where RSS does not have a legal obligation to retain some personal data, we will consider whether there is a business need to hold it.
- RSS will retain personal data only for as long as it is necessary to meet its purpose. Our approach to retaining and erasing data no longer required will be specified in our Data Retention Policy + Schedule.
- In the case of sharing personal data with any third party, only the data that is necessary to fulfil the purpose of sharing will be disclosed.
- Anonymisation and pseudonymisation of personal data stored or transferred should be considered where doing so is a possibility.
Accountability
- RSS will maintain a Data Processing Register as required by Article 30 of the GDPR to document regular processing activities.
- The RSS Administrator will act as RSS’s ‘Data Protection Officer’ (DPO) and will have the specific responsibility of overseeing data protection and ensuring that we comply with the data protection principles and relevant legislation.
- The DPO will ensure that the Data Processing Register is kept up to date and demonstrates how the data protection principles are adhered to by our activities. Individual members of staff have a duty to contribute to ensure that the measures outlined in the Register are accurately reflected in our practice.
- All employees, volunteers, consultants, partners, or other parties who will be handling personal data on behalf of RSS will be appropriately trained and supervised where necessary.
- The collection, storage, use and sharing of personal data will be regularly reviewed by the DPO, the CEO and the RSS board.
Use of data processors
RSS uses several external organisations to process and store our information, including Microsoft 365, Survey Monkey, Veezi, Windcave and WorldPay.
With all our data processors, a contract/policy is in place which confirms that those organisations comply with GDPR requirements and that all data moving between the two organisations is secure.
RSS will only use data processors who can provide sufficient guarantees around compliance with the GDPR and that the rights of data subjects will be protected.
Organisational measures
- All devices owned by RSS will have hardware encryption set up by default where possible, including laptops, mobile devices, and removable media.
- All staff, contractors, temporary workers, consultants, partners, or anyone else working on behalf of RSS and handling personal data are bound by the data protection legislation and this policy.
- Any contractor, temporary worker, consultant, or anyone else working on behalf of RSS who fails in their obligations under this policy risks incurring costs, liabilities, damages, loss, claims or proceedings that may arise from that failure.
Role of the Data Protection Officer (DPO)
The Data Protection Officer role is assigned to a member of RSS staff on a voluntary basis
i.e., we are not legally obliged to have a DPO. We have chosen to do so as part of demonstrating our accountability and ensuring our compliance with data protection requirements.
The DPO assists RSS to:
- monitor our internal compliance.
- inform and advise on our data protection obligations.
- act as a contact point for data subjects.
- The DPO is a point of contact for staff for data protection issues.
- The DPO organises training for staff and meets with new staff during their induction to discuss data protection matters, including this policy.
- The DPO is required to have appropriate knowledge of data protection law and best practice and is provided with adequate resources to help them carry out their role.
- The DPO is nominally responsible for carrying out responses to requests made by data subjects, reporting breaches and drawing up policies and procedures.
- This does not preclude another responsible member of staff from carrying out these.
Procedures for staff
All RSS Charity Personnel must comply with the following general procedures for processing or transmitting personal data:
- Always treat people’s personal information with integrity and confidentiality. Don’t hand out personal details just because someone asks you to.
- Where personal data exists as hard copy, it should be stored in a locked box, drawer, or cabinet, and not left where anyone could access it.
- The loss or theft of any device should be reported as soon as possible to the DPO.
- Take care to email the intended recipient (especially where email address autocomplete is turned on). Use the ‘bcc ‘ field for emailing several people where using ‘to’ or ‘cc’ is not needed.
- Exact procedures for gathering and processing personal data in specific situations (e.g., for marketing or events) will be detailed and highlighted to staff in the planning of each situation.
- In addition, staff should be aware of and adhere to RSS’s IT Policy, and any other guidance issued in relation to cyber security and the use of personal data.
Rights of data subjects
Under data protection laws, data subjects have certain rights:
- Right to be informed.
The right to be told how their personal data is used in clear and transparent language.
- Right of access.
The right to know and have access to the personal data we hold about them.
- Right to data portability.
The right to receive their data in a common and machine-readable electronic format.
- Right to be forgotten.
The right to have their personal data erased.
- Right to rectification.
The right to have their personal data corrected where it is inaccurate or incomplete.
- Right to object.
The right to complain and to object to processing.
- Right to purpose limitation.
The right to limit the extent of the processing of their personal data.
- Rights related to automated decision-making and profiling.
The right not to be subject to decisions without human involvement.
- RSS will uphold individuals’ rights under data protection laws and allow them to exercise their rights over the personal data we hold about them. Privacy information will acknowledge these rights and explain how individuals can exercise them. Most rights are not absolute, and the individual will be able to exercise them depending on the circumstances, and exemptions may apply in some cases.
- Any request in respect of these rights should preferably be made in writing to RSS, but we will also accept verbal requests.
- There is no fee for facilitating a request, unless it is ‘manifestly unfounded or excessive’, in which case administrative costs can be recovered.
- Requests that are ‘manifestly unfounded or excessive’ can be refused.
- We will take reasonable measures to require individuals to prove their identity where it is not obvious that they are the data subject.
- We will respond to the request within one month from the date of request or being able to identify the person unless it is particularly complex (in which case we will respond in no longer than 90 days).
- The DPO will ensure that required actions are taken and that the appropriate response is facilitated within the deadline.
- The DPO will draw up procedures for responding to requests where necessary, for example, for facilitating Subject Access Requests.
- Reporting of breaches
- A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- All members of RSS staff should be vigilant and able to identify a suspected personal data breach. A breach could include:
- loss or theft of devices or data, including information stored on USB drives or on paper;
- hacking or other forms of unauthorised access to a device or email account;
- disclosing personal data to the wrong person, through wrongly addressed emails, or bulk emails that inappropriately reveal all recipients email addresses; or
- alteration or destruction of personal data without permission.
- Where a member of staff discovers or suspects a personal data breach, this should be reported to the DPO as soon as possible.
- Where there is a likely risk to individuals’ rights and freedoms, the CEO will report the personal data breach to the ICO within 72 hours of the organisation being aware of the breach.
- Where there is also a likely high risk to individuals’ rights and freedoms, RSS will inform those individuals without undue delay.
- The DPO will keep a record of all personal data breaches reported and follow up with appropriate measures and improvements to reduce the risk of reoccurrence.