Pembrokeshire Mencap Ltd
Data Protection Privacy Notice
Introduction – The Society has reviewed it Policy on Data Protection in the light of the General Data Protection Regulations (GDPR) that came into effect in May 2018. In general terms this has required that we publish a schedule of information we hold and our reason for holding it. The way in which we deal with that data and the level of security we employ are largely as exercised under previous legislation and the key points are summarised below. In all respects we will endeavour to follow the terms of the Regulations, full details of which are available on the Information Commission’s Web Site at http://ico.org.uk
- Key Points of the Society’s Policy are as follows
- The Society will have a Privacy Notice on Public Display that will identify the following,
- What we collect
- Why we collect it
- The Authority under which it is collected – where appropriate e.g. HMRC, etc
- For how long we keep personal data
- Who to contact for further information
- Information we hold shall be purely for the effective operation of the Society.
- Information will be held for the minimum period of time commensurate with good practice and any legal requirements.
- Information will not be passed to third parties for the purposes of marketing.
- The Society will have a Privacy Notice on Public Display that will identify the following,
- Storage of personal data will be with the agreement of the person involved.
- Requests from individuals for copies of the personal information we hold shall be dealt with promptly and within the 1-month time scale referred to in the GDPR.
- Storage of personal records will be held in an appropriately secure manner. If on computer, they will be password protected, and if on paper copy they will be in filing cabinets with limited access in secure premises.
- In the event that information is passed to third parties (e.g. wages & salaries), the Society will ensure that the level of security of data is at least equal to that provided in-house.
- Individuals shall have a right to lodge a complaint. In the first instance it is preferred if the individual follows the Society’s complaints procedure, but they should also be advised that they may refer an issue to the Information Commissioner on worker@ico.org.uk
GDPR 2018 Schedule
General Data Protection Regulations 2018
In accordance with the 2018 GDPR the Society records below the status of information held by the Society.
Group | Data Controller | Data Processor | Reason for holding | Method of storage | Duration of storage |
Employees | Pembrokeshire Mencap | Rees and Hayden | Compliance with employment law and HMRC requirements | Computer disc password protected in secured office premises | 7 years minimum |
Employees | Pembrokeshire Mencap | Pembrokeshire Mencap | Personal details for purposes of holiday and sickness records, staff appraisals & H and S needs | Mix of paper and computer records in secure storage or password protected computer | 6 years minimum |
Students | Pembrokeshire College | Pembrokeshire Mencap | For the provision of appropriate training and health and safety requirements | Mix of paper and computer records in secure storage or password protected computer | 6 years minimum |
CLIENTS | Pembrokeshire County Council, Carmarthen CC, Bramble Bay Care, Elliots Hill Care | Pembrokeshire Mencap | For the provision of appropriate training and care and health and safety requirements | Mix of paper and computer records in secure storage or password protected computer | 6 years minimum |
Volunteers | Pembrokeshire Mencap | Pembrokeshire Mencap | For appropriate communication and H & S needs and DBS requirements | Mix of paper and computer records in secure storage or password protected computer | 6 years minimum |
Trustees | Pembrokeshire Mencap | Pembrokeshire Mencap | For appropriate communication and effective operation of the charity and requirments of companies house and charities commission | Mix of paper and computer records in secure storage or password protected computer | For 6 years after ceasing to practice as a trustee |
Public 1 | Pembrokeshire Mencap | Pembrokeshire Mencap | For operation of gift aid comprising name and address only | Mix of paper and computer records in secure storage or password protected computer | For 7 years for the purpose of meeting any HMRC audit |
Customer | Pembrokeshire Mencap | Pembrokeshire Mencap | Credit card transactions | Boxed file of copy receipts held in secured office | 3 months |
Members 200 Club | Pembrokeshire Mencap | Pembrokeshire Mencap | Administation of Lottery | Mix of paper and computer records in secure storage or password protected computer | 12 months |
Notes
- Duration may be extended in the case of any issue being subject of a legal proceeding or insurance claim
- A copy of the Society’s Data Protection Policy can be made available on request