Data Protection Policy
Clonmel Baptist Church
This policy is intended for use by Clonmel Baptist Church as they carry out their data protection responsibilities.
The policy includes:
- Full Privacy Notice
- Guidelines for Data Processors
- Information Register
- Subject Access Policy
- Breach Notification Policy
- Sample Consent Form
- Sample Privacy Notices
Data Protection Principles
The Clonmel Baptist Church complies with the General Data Protection Regulation (GDPR) as implemented in May 2018. We aim to ensure that, when processing information belonging to individuals, we will use that data with integrity, appropriately, and sparingly. We will endeavour to ensure such data is accurate, not kept forever, and stored securely. Training in data protection is recommended for all our staff and volunteers who store and/or use people’s information. We will post this Privacy Notice on our website. We will review this policy every three years.
You have data protection rights that you can exercise over the information you give us. These rights include: to be informed how your data is being used; to have access to the information we hold about you; to have inaccuracies corrected; to have your information erased; to object to or restrict the ways we process your information, and; data portability (to receive your digital information in a useful format). There may be some legal restrictions on these rights, which we will explain as appropriate. If you feel your rights haven’t been upheld please contact the Elders of Clonmel Baptist Church
Our Contact Details
If you need to get in touch with us please contact:
Pastor Matthew Brennan
Phone: 0861527663 E-mail: email@example.com
We may record and process some or all of the following personal information about you:
- contact details (address, phone numbers, e-mail address)
- date of birth
- photographs/video recordings
- financial giving to the church
- religious beliefs
- health and medication
We use this data so that we might:
- encourage you in your discipleship and provide pastoral care to you as part of the church family, eg by visiting at your home, calling your telephone, or sending a text message or e-mail
- keep you informed about life in the church family, eg by sending you occasional notices by post, e-mail or text message.
- process your involvement in activities of the church family, including groups that meet regularly as well as residential and other special trips
- facilitate the organisation of the church , eg by creating rotas
Legal Bases for Processing
Our legal bases for processing your data are ‘legitimate interests’ (for activities related to the everyday functioning of the church) [GDPR Article 6.1(f)] and ‘consent’ (for everything else) [Article 6.1(a)]. In a small number of instances we rely on ‘contract’ (for example, if we are your employer) and ‘legal obligation’ (for example, in relation to safeguarding issues).
When using ‘legitimate interests’ as the legal basis for using the information you have given us we will ensure it is for a genuine purpose, necessary for the smooth running of the church family, and not invasive to your privacy. For all other purposes we will ask for your positive consent before processing your details.
We are able to process ‘special categories of personal data’ (such as your health or religious beliefs) in the course of our legitimate activities because we are a not-for-profit body with a religious aim relating to you as a member, former member, or person with whom we have regular contact [Article 9.2(d)].
Sharing Your Data
Only people appointed to specific roles within the church (for example, elders and secretary) can access your details, and what they can see is limited to what they need in order to carry out their role.
If you are appointed to a specific role within the life of the church we may publish your details (eg in announcement sheets, annual reports or our web presence) or share them directly so members and other relevant individuals/organisations can contact you. This will cease when you step down from the role.
We occasionally post photographs and/or video taken at church events on our website (clonmelbaptist.ie and/or other online platforms eg. facebook).
If you donate money to us using the Irish Charities Donations Scheme we will send details of those gifts to the Revenue Commissioners.
We will not share your information with any other third parties without your permission unless we have a legal obligation to do so. However, we may need to share your details as follows:
- to comply with our Safeguarding policy when you volunteer with children and vulnerable adults.
Security and Retention
- To prevent unauthorised disclosure of your information, our paper-based records are kept in a locked cabinet/briefcase/safe when not in use. Electronic and portable memory devices are protected by passwords or equivalent security measures. Membership software and digital documents containing personal data are either encrypted or password-protected.
- Other than our permanent records (like Membership, Baptism and Church minutes) or details that need to be kept for legal compliance (such as Safeguarding notes ), we will remove your information from our systems when no longer required after your last personal contact with us.
- One-off consent forms (such as for annual group membership or booking for trips etc) will be destroyed/erased one year after their use.
Subject Access Request
You have the right to ensure our use of your data is lawful, and that the data we hold is accurate. If you would like to access the data we process about you, please write to us at:
Clonmel Baptist Church
or e-mail: firstname.lastname@example.org
In order to locate the information you are requesting and to ensure proof of your identity, please send us:
- Your name (including any names by which you used to be known) and Date of Birth
- Address (incl postcode), e-mail address(es), telephone number(s)
- Two pieces of identification that between them clearly show your name, date of birth and current address (eg passport, photocard driving license, birth certificate, recent bank statement/utility bill)
In response, and within one month at the latest, we will send to you:
- The personal data we hold on record for you
- The types of processing we do with your data
- The people/groups with whom your data will have been shared (or will be in the future)
- Our intentions regarding how long we might store your data
- OR our reasons for not providing your data
We will not charge for this service unless you make multiple requests within a short space of time.
You can learn about Data Protection principles, your rights, and more – including making a complaint about our handling of your data – from the Data Protection Commissioner (DPC) in the Republic of Ireland [visit www.dataprotection.ie, call (0761) 104 800 or write to The Data Protection Commissioner, Canal House, Station Road, Portarlington, Co. Laois R32 AP23].