Introduction
Stapleford Baptist Church (SBC) uses personal data about living individuals for the purpose of general church administration and communication.
SBC recognises the importance of the correct and lawful treatment of personal data. All personal data, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the General Data Protection Regulation.
SBC fully endorses and adheres to the seven principles of the UK GDPR. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data. Employees and any others who obtain, handle, process, transport and store personal data for SBC must adhere to these principles.
The seven Principles applicable to personal data
- Processed lawfully, fairly and transparently
- Purpose limitation: specific, explicit, legitimate.
- Data minimisation: relevant and limited to what is necessary.
- Accuracy: kept up to date as necessary
- Storage limitation: not kept for longer than is necessary for that purpose.
- Integrity and confidentiality: kept secure from unauthorised or unlawful processing and protected against accidental loss, destruction or damage by using the appropriate technical and organisational measures
- Accountability: able to demonstrate we comply with the above.
How we collect data and information about you
We collect personal information each time you are in contact with us. For example, when you:
- Visit our website;
- Register your details and your family details on a contact form or via any embedded form on our website or social media
- Make a donation, by completion of offering envelopes, text, via our website or electronic means;
- Register for a conference or other Church event;
- Provide your contact details, in writing or orally, to Church staff or volunteers;
- Purchase goods or services (e.g., an event ticket, or a book purchase)
- Communicate with the Church by means such as email, letter, telephone;
- Face to face meetings with staff and volunteers;
- Access social media platforms such as Facebook, YouTube, WhatsApp, Twitter, Instagram where these are in the name of SBC, church staff or appointed leaders, or authorised by SBC.
Maintaining Confidentiality
SBC will treat all your personal information as private and confidential and not disclose any data about you to anyone other than the elders/leadership and ministry team leaders/co-coordinators of the church in order to facilitate the administration and day-to-day ministry of the church.
All SBC staff and volunteers who have access to Personal Data will be required to agree to sign to hold it confidentially in accordance with a Data Protection Policy.
There are four exceptional circumstances to the above permitted by law:
- Where we are legally compelled to do so.
- Where there is a duty to the public to disclose.
- Where disclosure is required to protect your interest.
- Where disclosure is made at your request or with your consent.
Use of Personal Information
SBC will use your data for three main purposes:
- The day-to-day administration of the church; e.g., pastoral care and oversight including calls and visits, preparation of ministry rotas, maintaining financial records of giving for audit and tax purposes.
- Contacting you to keep you informed of church services, activities, resources and events.
- Statistical analysis; gaining a better understanding of church and group attendance and demographics.
N.B. although collated church data may be passed to a third party, such as numbers attending services, numbers of small groups or small group attendance, no personal data will be disclosed.
Data security
Information held will not be used for any other purposes than set out in in paragraph 3 above.
- Access to the information is password protected for digital storage otherwise in a locked cupboard.
- Only persons authorised by the leadership have access to data; in the case of Team/Group Leaders the access is limited to their group.
- People who will have secure and authorised access to data include SBC Church Elders/Trustees, Staff, Team/Group Leaders.
- Under UK GDPR, data we hold cannot be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
Disclosure
Personal information will not be passed onto any third parties outside of the church environment. We do not sell or pass any of your personal information to any other organisations and/or individuals without your express consent, with the following exceptions:
By providing us with your details you are giving the Church your express permission to use service providers and web-based programmes including mailing houses, such as Mail Chimp, to enable SBC to operate the relationship between us. Where a service provider used by SBC for collection storage or other processing of data is based outside the EU, we will take all reasonable steps to ensure personal data is treated as securely as it would be if that data was within the UK or EU under GDPR.
Sensitive Personal Information. The Church may collect and store sensitive personal information such as health information, or religious information (church attendance) when you and/or your family attend or register for church events and conferences. Your personal information will be kept strictly confidential. It is never sold, given away, or otherwise shared with anyone, unless required by law.
Legitimate Interest
Legitimate interest is a basis for processing data which we use for enabling small groups in church to be administered by their leaders.
Your Rights
Subject to limited exceptions under GDPR you have the following rights:
- To request a copy of the personal data SBC holds about you
- To request we correct any personal data we hold which is inaccurate or out of date
- To request erasure of personal data where it is no longer necessary for SBC to hold it
- To withdraw consent to processing at any time
- To request SBC to provide you with your personal data and to transmit that data to another data controller (data portability)
- To restrict data processing
- To object to processing (in limited circumstances)
- To complain to the Information Commissioner’s Office (details below)
SBC aims to deal with requests for access to personal information or complaints as quickly as possible but will normally do so within 30 days, unless there is good reason for delay. In such cases, the reason for delay will be explained in writing to the individual making the request. Any request or complaint will be dealt with only by an elder appointed to do so. Please contact us first. A specimen letter you could use can be downloaded from www.ico.gov.uk.
Our contact details are:
FAO: The Administrator
Stapleford Baptist Church
Albert Street
Stapleford
NG9 9DB (or email sbc.office.2017@gmail.com)
The Information Commissioner is at Wycliffe House, Wilmslow, SK9 5AF.