This Policy applies to the operation of 4×4 RESPONSE WALES, and sets out its requirement to gather data for membership and club activity purposes.
It contains details of how personal data will be gathered, stored and managed in line with the data protection principles, and the General Data Protection Regulation (GDPR).
The Policy is reviewed on an ongoing basis by the 4×4 Response Wales Steering Group and Trustees to ensure compliance.
This Policy exists to ensure that 4×4 Response Wales:
- Complies with data protection law and follows good practice
- Protects the rights of members
- Is open about how it stores and processes members’ data
- Protects itself from the risks of a data breach
4×4 Response Wales has completed a Legitimate Interest Assessment and has determined that the lawful basis for holding and processing data on members is Legitimate Interest, is the best fit for our purpose, and that 4×4 Response Wales is a Data Controller. 4×4 Response Wales Steering Group is responsible for this policy and the contact is the 4×4 Response Wales Membership secretary, who can be contacted by email at firstname.lastname@example.org
The 4×4 Response Wales Steering Group is responsible for ensuring that 4×4 Response Wales remains compliant with data protection requirements, and can evidence that it is. Data protection, those who have access to data, and the type of data will be reviewed. New Steering Group members will be informed of how data protection is managed and the reasons.
Members will only be asked to provide information that is relevant for membership and organisation activity purposes. The forms used to request personal information will contain a Privacy Notice to explain why the data is collected, and how it will be used. The 4×4 Response Wales Steering Group will seek to ensure that member information is only used appropriately, and includes:
- Communicating with members about 4×4 Response Wales events, activities, membership, renewals, etc;
- Emailing members 4×4 Response Newsletters;
- Appropriate and suitable operation of the charity’s 4×4 Response function.
4×4 Response Wales has a responsibility to ensure members’ information is kept up to date, and members are asked to advise of any changes.
4×4 Response Wales does store members’ personal information relevant to the appropriate operation of the club. With responsibility for the secure holding and processing of data, and the consequences of loss, theft or unlawful processing, the following will apply:
Only those on the 4×4 Response Wales Steering Group, or Incident Controllers with the need to communicate with members, will be granted access to data.
Members’ personal data is stored on a secure computerised database. Access to this database is only permitted by 4×4 Response Wales membership secretary, trustees and steering group members.
Members may request that their data held on the 4×4 Response Wales database is removed when:-
- membership lapses
- or during a membership period on return of 4×4 Response Wales membership card and any equipment supplied by 4×4 Response Wales
Members’ personal information held on the 4×4 Response Wales database will be held until members request that the information is destroyed OR until 7 years after the membership has ceased.
Members’ personal information stored in paper format will be filed securely and is held until members request that the information is destroyed OR until 7 years after the membership has ceased.