Torrevieja u3a

Data Protection Policy

Introduction

This Data Protection Policy ensures that Torrevieja u3a (hereafter referred to as ‘the u3a’):

  • Complies with the General Data Protection Regulation (GDPR) and follows good practice.
  • Protects the rights of members.
  • Is open about how it stores and processes members’ data.
  • Protects itself from the risks of a data breach.

This policy should be read in conjunction with the u3a Privacy Policy.

General Guidelines

  • The only persons able to access personal data covered by this policy are u3a Committee Members, Advisors, Group Leaders, Event organisers, Email Marketing Tool Provider and Website host for the management of the u3a administration process including communication with members.
  • The u3a will ensure that Committee Members, Advisors, Group Leaders, Event organisers, Email Marketing Tool Provider and Website host understand and comply with their responsibilities when handling members’ personal data.
  • Committee Members, Advisors, Group Leaders, Event organisers, Email Marketing Tool Provider and Website host shall keep all members’ personal data secure by:
    • a. Using strong passwords; never sharing passwords.
    • b. Not sharing or disclosing personal data with any other person or organisation without the written, prior consent of the Member and the knowledge of the Committee.
    • c. Only using the personal data for the purpose that it was provided for.
    • d. Securely destroying/deleting personal data that is no longer required i.e. lapsed membership, or when requested by the member.

Data Protection Principles

The General Data Protection Regulation identifies 8 data protection principles:

  1. Lawfulness, fairness and transparency: Personal data should be processed lawfully, the lawful basis for use is consent by the member.  The u3a only collects the data needed to manage and communicate with members.
  2. Purpose limitation: Personal data should be collected solely for specified, explicit and legitimate purposes defined as membership administration and communicating with members about the u3a.
  3. Data minimisation: Personal data should be adequate, relevant and limited to what is necessary. This means the minimum data required to carry out membership administration and to enable email contact with u3a members.
  4. Accuracy: Personal data stored and managed should be accurate and, where necessary, kept up to date. Members’ data is renewed annually as part of the membership renewal process. Members can request to see, update, or remove their data at any time.
  5. Storage limitation: Personal data should be kept no longer than is necessary for the purposes for which it was collected.  Members’ data is removed and deleted on lapse of membership after a period of grace not exceeding 12 months, or when instructed by a member.
  6. Individuals’ rights: Personal data must be processed in accordance with the individuals’ rights.
  7. Integrity and confidentiality: Personal data should be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and/or organisational measures.
  8. Transfer of personal data: Personal data shall not be transferred to a country or territory outside the European Union unless that country or territory ensures an adequate level of protection for the rights and freedoms of individuals in relation to the processing of personal data.

Individual Member’s Rights Under GDPR

The u3a will ensure that member’s information is managed in such a way as not to infringe an individual member’s rights, which include:

  • The right to be informed - what data is held by the u3a.
  • The right of access - entitled to have access to your data held by the u3a.
  • The right to rectification - amend or correct the data held by the u3a.
  • The right to erasure - to remove, delete all reference to, i.e. be forgotten.
  • The right to restrict processing - to limit some aspects of how data is used.
  • The right to data portability - to be able to forward data to another.
  • The right to object - to question current use and/or seek resolution.

Access Request

u3a members are entitled to request access to the information held by the u3a about them.  An ‘access request’ can be submitted by the member, at any time, to the Membership Secretary torreviejau3amembership@gmail.com.  On receipt, the request will be acknowledged and dealt with. The u3a will provide a written response detailing all information held about the member and a record will be kept of the dates of the request and the response.

Photos/images (including video)

Photos/images are classified as personal data. Any person can object and request at any time to have a published photo/image removed, providing the u3a can verify the request is authentic and relates to the individual, by contacting the Groups Liaison Officer u3agroupsliaison@gmail.com.

Accountability and Governance

The GDPR requires that the u3a demonstrates that it complies with the data protection principles set out above and respects the rights of the individual by:

  • Requiring members to provide written consent for their personal data to be stored and used by the u3a.  The u3a shall maintain a record of the members’ consent.
  • Implementing appropriate technical and/or organisational measures to ensure the security and appropriate use of the personal data held.
  • Maintaining Data Protection and Privacy Policies and ensuring that Committee Members, Group Leaders, Event organisers and Website host adhere to the principals set out in these policies.

Data Breach Notification

  • If a data breach occurs, action shall be taken to minimise the harm by ensuring all Committee Members are aware that a breach has taken place and take steps to identify how the breach occurred.
  • The Committee shall seek to rectify the cause of the breach as soon as possible to prevent any further breaches.
  • If a u3a member believes there has been a data breach they should inform the u3a President in writing at u3apresidentpshaw@gmail.com, outlining their concerns. 
  • All reported breaches will be fully investigated and records kept detailing the type of breach, the date it occurred and the person(s) involved.

October 2024

Welcome    About Us    Gallery    Membership    Groups    Social Events    Welfare    Charity    What's On   Archives

X