GDPR
The churches in our benefice adhere to GDPR as recommended in the advice below.
Complying with the UK GDPR (General Data Protection Regulation) is important for churches as data controllers, ensuring the responsible and ethical handling of personal data belonging to members, staff, and other individuals associated with the church. key aspects:
1. Principles of good data handling
The foundation of GDPR lies in seven key principles that dictate how personal data should be processed:
Lawfulness, fairness, and transparency: Be clear and honest about how you collect, use, and store personal data.
Purpose limitation: Data should only be collected for specified, explicit, and legitimate purposes and not used in any way incompatible with those purposes.
Data minimization: Only collect the data that is necessary, adequate, and relevant for the defined purpose.
Accuracy: Keep personal data accurate and up to date, promptly correcting or erasing any inaccuracies.
Storage limitation: Do not keep personal data for longer than is necessary for the purposes for which it was collected.
Integrity and confidentiality (security): Implement appropriate technical and organizational measures to ensure the security of personal data, protecting it against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Accountability: The church as the data controller is responsible for and must be able to demonstrate compliance with these principles.
2. Lawful basis for processing data
Before processing any personal data, you must identify a valid lawful basis for doing so. Common bases for churches include:
Consent: Individuals explicitly and freely agree to the processing of their data for a specific purpose.
Legal obligation: Processing is necessary to comply with the law, like Gift Aid declarations or safeguarding requirements.
Legitimate interests: Processing is necessary for the legitimate interests of the church (e.g., maintaining membership lists or rotas) provided the individual's rights and freedoms are not overridden.
3. Practical steps for compliance
Conduct a data audit: Review the personal data your church collects, stores, and processes. Determine what you need, how it's stored, and the lawful basis for each type of data.
Develop a privacy notice: Inform individuals about the personal data you collect, why you collect it, how you use it, who you share it with, and their rights.
Obtain clear consent where needed: Ensure consent is specific, informed, and unambiguous. Especially for sensitive data or information about children, consent must be explicit.
Secure data: Implement security measures appropriate to the data you hold (e.g., password protection, locked cabinets).
Respect data subject rights: Be prepared to handle requests from individuals regarding their data (e.g., access, rectification, erasure).
Manage data breaches: Develop and implement a procedure for detecting, reporting (to the ICO and affected individuals, if necessary, within 72 hours), and managing data breaches.
Train your team: Ensure anyone handling personal data understands and follows your data protection policies and procedures.
4. Key considerations
Children's Data: Exercise extra care when handling children's data and generally obtain parental consent for processing, especially for activities like youth groups or Sunday school.
Special Category Data: Processing information revealing religious beliefs is considered processing special category data, notes the ICO. This requires identifying an additional condition under Article 9 of the UK GDPR for lawful processing.
Important note
This guide provides a basic overview. It is important to remember that GDPR compliance is ongoing. It is advisable to consult the Information Commissioner's Office (ICO) website and relevant guidance from your denomination or other reliable sources for the most up-to-date and specific advice tailored to your church's particular circumstances.
Confidential Lists
-
Names/contact details on the Electoral Roll.
-
Names/contact details of those who donated at the Easter Giving Day.
-
Baptism/Marriage/Burial Registers.
-
Attendees of Toddler Group.
-
Circulation list for the church services.
-
Banking/Gift Aid /Church donations details.
-
Bellringers names and contact details.