Borders Community Action is a Charity and Company Limited by Guarantee with charity status, although the organisation is exempt to register as a Data processor with the Information Commissioners Office (ICO), Borders Community Action adheres to the principles of the General Data Protection Regulations for best practice in managing information. This policy applies to all Trustees, Employees, and Volunteers of Borders Community Action and covers our commitment to meeting our requirements to protect personal data under the Data Protection Act 2018 (also known as the UK GDPR) and the General Data Protection Regulation (GDPR). “Personal data” means any information relating to an identified or identifiable living individual.
Borders Community Action will ensure that all personal data that it holds will be:
To ensure processing of data is lawful, fair and transparent, Borders Community Action shall keep and maintain Data Audits to record where and why we process personal data. The Data Audits will be kept up to date and fully reviewed every year. The Data Audits will record our lawful bases (our reasons) for processing any personal data, this must be one of the following as required by legislation:
The way in which we process personal data is detailed within our privacy notices, which are all freely on our website. Our privacy notices will be kept up to date and fully reviewed every year. Borders Community Action is fully committed to meeting the data protection principle of lawfulness, fairness and transparency.
Borders Community Action will record the purposes of processing data and show these purposes in our Data Audits and include details in our public privacy notices. We will not use the personal data for any other purpose unless this is compatible with our original purpose, or we get consent, or we have a clear obligation or function set out in law.
We will make sure that the personal data we are processing is:
Borders Community Action will take all reasonable steps to ensure the personal data we hold is not incorrect or misleading as to any matter of fact. We may need to keep the personal data updated, although this will depend on what we are using it for. If we discover that personal data is incorrect or misleading, we will take reasonable steps to correct or erase it as soon as possible.
Borders Community Action will not keep personal data for longer than we need it. How long we keep personal data will depend on our purposes for holding the data. We have a separate document retention policy which records how long we keep personal data for and how it will be erased, anonymised, or removed from our systems. We may keep personal data for longer than we need it for public interest archiving, scientific or historical research, or for statistical purposes.
Borders Community Action takes the security of personal data extremely seriously. We do this in a variety of technical and organisational security measures, including but not limited to:
Our security measures are regularly updated, tested and reviewed to make sure that we keep personal data secure and confidential.
Individuals have the right to access their personal data and any such requests made to Borders Community Action shall be dealt with in line with legal requirements, with some limited exceptions. The UK GDPR provides the following rights for individuals in relation to their personal data:
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. All trustees, staff and volunteers must be able to identify a suspected personal data breach. A breach could include:
Where a member of staff discovers or suspects a personal data breach, this should be reported to the DPO as soon as possible. Where there is a likely risk to individuals’ rights and freedoms, the DPO will report the personal data breach within 72 hours of Borders Community Action being aware of the breach. Where there is also a likely high risk to individuals’ rights and freedoms, we will inform those individuals without undue delay. The DPO will keep a record of all personal data breaches reported and follow up with appropriate measures and improvements to reduce the risk of reoccurrence.
Privacy by design is an approach that promotes privacy and data protection compliance from the beginning. When relevant, and when it does not have a negative impact on an individual, privacy settings will be set to the most private by default. Trustees, Staff and Volunteers must become familiar with this policy and include privacy and good data protection practices as core within any new project design or any material change to an existing project/work.
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
If you wish to talk through anything in our privacy policy, find out more about your rights or obtain a copy of the information we hold about you, please contact info@borderscommunityaction.org.uk. This document was last updated: June 2023