<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.ilovefreegle.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jc4freegle</id>
	<title>Freegle Wiki - User contributions [en-gb]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ilovefreegle.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jc4freegle"/>
	<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/Special:Contributions/Jc4freegle"/>
	<updated>2026-05-10T18:22:01Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.0</generator>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47854</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47854"/>
		<updated>2018-04-04T14:03:49Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Useful Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Protection Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle system directly from the system. In addition members may request other data Freegle may have about, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Age Restrictions&#039;&#039;&#039; - We will not maintain children&#039;s personal data, as we would then require some way to ensure that guardians consented to this. The definition of children in this respect is taken as 13 years old. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership, and up to 6 months after membership has ceased as part of our anti-SPAM measures. However, during these 6 months these details will not be visible. Should members wish to have their data removed immediately this can be arranged via the Data Protection Officer DPO@ilovefreegle.org &amp;lt;br&amp;gt;&lt;br /&gt;
Freegle Volunteers who correspond with others in relation to Freegle and its activities are advised to do so via the Freegle Direct system if possible. Freegle policy on correspondence outside of the FD system is also subject to a 6 month retention period unless the volunteer obtains consent from the correspondent that they may keep the information for an agreed longer period.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques (e.g. access restriction, encryption, taking backups etc) to ensure that data we hold will be kept safe from unauthorised access or loss on its system. We also advise all volunteers who store personal information to keep it secure with access limited to known individuals, . &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Notification of Data Breaches&#039;&#039;&#039; - Freegle will notify the relevant authorities of any data breach it detects. Unless there is an important reason, such as to aid law enforcement, Freegle will inform all individuals impacted by any breach and the membership in general on the details of the breach. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Protection Officer&#039;&#039;&#039; - due to the nature of Freegle we are  not legally obliged to have a Data Protection Officer [DPO]. However, we have a volunteer who undertakes this role who can be reached via email at DPO@ilovefreegle.org&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Detail of Freegle&#039;s use and protection of Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47851</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47851"/>
		<updated>2018-04-04T13:59:12Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Ongoing Tasks on Freegle Data Protection Compliance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 4th April 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || This will be emails to the Board and mod groups that point to Wiki informational pages. &amp;lt;br&amp;gt;Completed - initial information out to the board/mods &amp;lt;br&amp;gt; Next - Complete the policy and request approval/amendment from the board.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Use &amp;amp; Protection Wiki Page || This has been created and its mostly complete. &lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || Complete - We have chosen to use &amp;quot;Legitimate Interest&amp;quot; as out legal basis. Have also included a Legitimate Interest Assessment [LIA] as suggested by the ICO guidance.&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Legal Basis &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;- Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47848</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47848"/>
		<updated>2018-04-04T13:58:33Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || This will be emails to the Board and mod groups that point to Wiki informational pages. &amp;lt;br&amp;gt;Completed - initial information out to the board/mods &amp;lt;br&amp;gt; Next - Complete the policy and request approval/amendment from the board.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Use &amp;amp; Protection Wiki Page || This has been created and its mostly complete. &lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || Complete - We have chosen to use &amp;quot;Legitimate Interest&amp;quot; as out legal basis. Have also included a Legitimate Interest Assessment [LIA] as suggested by the ICO guidance.&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Legal Basis &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;- Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47845</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47845"/>
		<updated>2018-04-04T13:51:35Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Corresponding with Members&#039;&#039;&#039; - We advise that you try to correspond with members using the chat function on the Freegle Direct system. If you do keep a copy of correspondence in your own email store, we ask that you keep Freegle messages in a separate folder. We advise that you have an email client that allows you to search for users to assist with requests for data, and a way of deleting data that is older than the Freegle retention policy limit. See [[Data Protection Policy]].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request [SAR]. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com around a particular scope or topic that has been cited in the SAR. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. It should be noted that correspondence around disputes would be available to a member should they submit a subject access request around this scope of infomation. Therefore, only write down things you would be happy for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - What Personal Data Freegle keeps and how it uses it&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47842</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47842"/>
		<updated>2018-04-04T13:26:16Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Personal Data Protection Policy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Protection Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle system directly from the system. In addition members may request other data Freegle may have about, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Age Restrictions&#039;&#039;&#039; - We will not maintain children&#039;s personal data, as we would then require some way to ensure that guardians consented to this. The definition of children in this respect is taken as 13 years old. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership, and up to 6 months after membership has ceased as part of our anti-SPAM measures. However, during these 6 months these details will not be visible. Should members wish to have their data removed immediately this can be arranged via the Data Protection Officer DPO@ilovefreegle.org &amp;lt;br&amp;gt;&lt;br /&gt;
Freegle Volunteers who correspond with others in relation to Freegle and its activities are advised to do so via the Freegle Direct system if possible. Freegle policy on correspondence outside of the FD system is also subject to a 6 month retention period unless the volunteer obtains consent from the correspondent that they may keep the information for an agreed longer period.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques (e.g. access restriction, encryption, taking backups etc) to ensure that data we hold will be kept safe from unauthorised access or loss on its system. We also advise all volunteers who store personal information to keep it secure with access limited to known individuals, . &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Notification of Data Breaches&#039;&#039;&#039; - Freegle will notify the relevant authorities of any data breach it detects. Unless there is an important reason, such as to aid law enforcement, Freegle will inform all individuals impacted by any breach and the membership in general on the details of the breach. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Protection Officer&#039;&#039;&#039; - due to the nature of Freegle we are  not legally obliged to have a Data Protection Officer [DPO]. However, we have a volunteer who undertakes this role who can be reached via email at DPO@ilovefreegle.org&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47839</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47839"/>
		<updated>2018-04-04T13:07:13Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Freegle&amp;#039;s Legitimate Interest Assessment */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Freegle&#039;s Legitimate Interest Assessment ==&lt;br /&gt;
&lt;br /&gt;
The Information Commissioner&#039;s Office suggest that if you use a Legitimate Interest basis of processing, you should conduct a Legitimate Interest Assessment [LIA]. An LIA is a type of light-touch risk assessment based on the specific context and circumstances. It will help ensure that our processing is lawful. Having an LIA will also help Freegle demonstrate compliance in line with it&#039;s accountability obligations under Articles 5(2) and 24. Therefore here below is our LIA.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Identify the legitimate interest(s)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Why do you want to process the data – what are you trying to achieve? &#039;&#039;&#039;Freegle Answer [FA] &amp;gt;&amp;gt;&#039;&#039;&#039; To enable individuals who have joined Freegle to gain reuse of their unwanted items to others in their locality. &amp;lt;br&amp;gt;&lt;br /&gt;
Who benefits from the processing? In what way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The individual Freegle member in enabling reuse of their items and the environment as less waste goes to landfill or incineration. &amp;lt;br&amp;gt;&lt;br /&gt;
Are there any wider public benefits to the processing? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is a wider public benefit that reuse aids the environment and can reduce volumes of landfill that are an expense to the public to process. &amp;lt;br&amp;gt;&lt;br /&gt;
How important are those benefits? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; In the UK there is a shortage of landfill so the work of Freegle are important to tackling the environmental impact of waste. &amp;lt;br&amp;gt;&lt;br /&gt;
What would the impact be if you couldn’t go ahead? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Many hundreds of tonnes of waste would be added to the waste stream that ends up in Landfill. &amp;lt;br&amp;gt;&lt;br /&gt;
Would your use of the data be unethical or unlawful in any way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Freegle&#039;s use of personal data would not be unlawful or unethical, as our community depends heavily on the trust of its members. Freegle has data protection policies to ensure it is used responsibly and only for the stated aims of the organisation individuals are a member of. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the Processing Necessary&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Does this processing actually help to further that interest?  - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The processing of a very limited set of personal data (email address and location) helps people advertise unwanted items for re-use to others in their locality. Not processing this information would render the service of much less use to the individuals who joined Freegle and therefore the the environment for the public more generally. &amp;lt;br&amp;gt; &lt;br /&gt;
Is it a reasonable way to go about it? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; This limited and focused processing is entirely reasonable and in line with the expectations of the individuals that join Freegle. &amp;lt;br&amp;gt;&lt;br /&gt;
Is there another less intrusive way to achieve the same result? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is no less intrusive way to effectively enable the exchange of items for reuse between members. As without this basic information posts to offer items would not be able to be replied to nor the seeker know where the item was. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the processing balanced against individual rights ?&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
What is the nature of your relationship with the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; All individuals are members of the Freegle service by choice, as they sign up to further enable them to gift or seek items for reuse. &amp;lt;br&amp;gt;&lt;br /&gt;
Is any of the data particularly sensitive or private? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No, there is no sensitive data kept. &amp;lt;br&amp;gt;&lt;br /&gt;
Would people expect you to use their data in this way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Individuals join Freegle specifically for this services, so they would expect their data to be used in this way. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you happy to explain it to them? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Yes we are very happy to explain it to them. This is mostly done by information on open Wiki pages (including this one) detailing everything we do. Additionally, we have also assigned a Data Protection Officer role despite not being required to due to not keeping sensitive data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are some people likely to object or find it intrusive? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Having reviewed our use we cannot foresee any reasonable objections to the use of the data in the way we process it. &amp;lt;br&amp;gt;&lt;br /&gt;
What is the possible impact on the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The most serious impact we can foresee with the release of data, is the a member who has not posted an item could possibly be identified by name and area they live. This could happen if they have their real name in their email address and it is associated with their postal area. &amp;lt;br&amp;gt;&lt;br /&gt;
How big an impact might it have on them? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; A member may feel that their privacy is impacted, although as most members would make this information public when they post an item it would be a risk they are likely comfortable with. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you processing children’s data? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Our policy is not to process children&#039;s data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are any of the individuals vulnerable in any other way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No the freegle system does not make individuals vulnerable in any way greater than normal use of the internet. &amp;lt;br&amp;gt;&lt;br /&gt;
Can you adopt any safeguards to minimise the impact? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; As this is the only basic personal data we keep there are no other safeguards beyond our internal security measure that we can take. &amp;lt;br&amp;gt;&lt;br /&gt;
Can you offer an opt-out? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; If the individual is a member then we cannot offer an opt-out of the standard processing we do. There are settings that members have control of to opt in or out of mailing lists and the scope of what they can see when logged into the service. However there is no barrier to individuals leaving the service. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47836</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47836"/>
		<updated>2018-04-04T13:03:13Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Freegle&amp;#039;s Legitimate Interest Assessment */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Freegle&#039;s Legitimate Interest Assessment ==&lt;br /&gt;
&lt;br /&gt;
The Information Commissioner&#039;s Office suggest that if you use a Legitimate Interest basis of processing, you should conduct a Legitimate Interest Assessment [LIA]. An LIA is a type of light-touch risk assessment based on the specific context and circumstances. It will help ensure that our processing is lawful. Having an LIA will also help Freegle demonstrate compliance in line with it&#039;s accountability obligations under Articles 5(2) and 24. Therefore here below is our LIA.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Identify the legitimate interest(s)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Why do you want to process the data – what are you trying to achieve? &#039;&#039;&#039;Freegle Answer [FA] &amp;gt;&amp;gt;&#039;&#039;&#039; To enable individuals who have joined Freegle to gain reuse of their unwanted items to others in their locality. &amp;lt;br&amp;gt;&lt;br /&gt;
Who benefits from the processing? In what way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The individual Freegle member in enabling reuse of their items and the environment as less waste goes to landfill or incineration. &amp;lt;br&amp;gt;&lt;br /&gt;
Are there any wider public benefits to the processing? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is a wider public benefit that reuse aids the environment and can reduce volumes of landfill that are an expense to the public to process. &amp;lt;br&amp;gt;&lt;br /&gt;
How important are those benefits? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; In the UK there is a shortage of landfill so the work of Freegle are important to tackling the environmental impact of waste. &amp;lt;br&amp;gt;&lt;br /&gt;
What would the impact be if you couldn’t go ahead? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Many hundreds of tonnes of waste would be added to the waste stream that ends up in Landfill. &amp;lt;br&amp;gt;&lt;br /&gt;
Would your use of the data be unethical or unlawful in any way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Freegle&#039;s use of personal data would not be unlawful or unethical, as our community depends heavily on the trust of its members. Freegle has data protection policies to ensure it is used responsibly and only for the stated aims of the organisation individuals are a member of. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the Processing Necessary&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Does this processing actually help to further that interest?  - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The processing of a very limited set of personal data (email address and location) helps people advertise unwanted items for re-use to others in their locality. Not processing this information would render the service of much less use to the individuals who joined Freegle and therefore the the environment for the public more generally. &amp;lt;br&amp;gt; &lt;br /&gt;
Is it a reasonable way to go about it? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; This limited and focused processing is entirely reasonable and in line with the expectations of he individuals that join Freegle. &amp;lt;br&amp;gt;&lt;br /&gt;
Is there another less intrusive way to achieve the same result? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is no less intrusive way to effectively enable the exchange of items for reuse between members. As without this basic information posts to offer items would not be able to be replied to nor the seeker know where the item was. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the processing balanced against individual rights ?&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
What is the nature of your relationship with the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; All individuals are members of the Freegle service by choice, as they sign up to further enable them to gift or seek items for reuse. &amp;lt;br&amp;gt;&lt;br /&gt;
Is any of the data particularly sensitive or private? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No, there is no sensitive data kept. &amp;lt;br&amp;gt;&lt;br /&gt;
Would people expect you to use their data in this way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Individuals join Freegle specifically for this services, so they would expect their data to be used in this way. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you happy to explain it to them? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Yes we are very happy to explain it to them. This is mostly done by information on open Wiki pages (including this one) detailing everything we do. Additionally, we have also assigned a Data Protection Officer role despite not being required to due to not keeping sensitive data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are some people likely to object or find it intrusive? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Having reviewed our use we cannot foresee any reasonable objections to the use of the data in the way we process it. &amp;lt;br&amp;gt;&lt;br /&gt;
What is the possible impact on the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The most serious impact we can foresee with the release of data, is the a member who has not posted an item could possibly be identified by name and area they live. This could happen if they have their real name in their email address and it is associated with their postal area. &amp;lt;br&amp;gt;&lt;br /&gt;
How big an impact might it have on them? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; A member may feel that their privacy is impacted, although as most members would make this information public when they post an item it would be a risk they are likely comfortable with. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you processing children’s data? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Our policy is not to process children&#039;s data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are any of the individuals vulnerable in any other way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No the freegle system does not make individuals vulnerable in any way&lt;br /&gt;
Can you adopt any safeguards to minimise the impact? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; As this is the only basic personal data we keep there are no other safeguards beyond our internal security measure that we can take. &lt;br /&gt;
Can you offer an opt-out? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; If the individual is a member then we cannot offer an opt-out of the standard processing we do. There are settings that members have control of to opt in or out of mailing lists and the scope of what they can see when logged into the service. However there is no barrier to individuals leaving the service. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47833</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47833"/>
		<updated>2018-04-04T13:01:30Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Freegle&amp;#039;s Legitimate Interest Assessment */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Freegle&#039;s Legitimate Interest Assessment ==&lt;br /&gt;
&lt;br /&gt;
The Information Commissioner&#039;s Office suggest that if you use a Legitimate Interest basis of processing, you should conduct a Legitimate Interest Assessment [LIA]. An LIA is a type of light-touch risk assessment based on the specific context and circumstances. It will help ensure that our processing is lawful. Having an LIA will also help Freegle demonstrate compliance in line with it&#039;s accountability obligations under Articles 5(2) and 24. Therefore here below is our LIA.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Identify the legitimate interest(s)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Why do you want to process the data – what are you trying to achieve? &#039;&#039;&#039;Freegle Answer [FA] &amp;gt;&amp;gt;&#039;&#039;&#039; To enable individuals who have joined Freegle to gain reuse of their unwanted items to others in their locality. &amp;lt;br&amp;gt;&lt;br /&gt;
Who benefits from the processing? In what way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The individual Freegle member in enabling reuse of their items and the environment as less waste goes to landfill or incineration. &amp;lt;br&amp;gt;&lt;br /&gt;
Are there any wider public benefits to the processing? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is a wider public benefit that reuse aids the environment and can reduce volumes of landfill that are an expense to the public to process. &amp;lt;br&amp;gt;&lt;br /&gt;
How important are those benefits? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; In the UK there is a shortage of landfill so the work of Freegle are important to tackling the environmental impact of waste. &amp;lt;br&amp;gt;&lt;br /&gt;
What would the impact be if you couldn’t go ahead? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Many hundreds of tonnes of waste would be added to the waste stream that ends up in Landfill &amp;lt;br&amp;gt;&lt;br /&gt;
Would your use of the data be unethical or unlawful in any way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Freegle&#039;s use of personal data would not be unlawful or unethical, as our community depends heavily on the trust of its members. Freegle has data protection policies to ensure it is used responsibly and only for the stated aims of the organisation individuals are a member of. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the Processing Necessary&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Does this processing actually help to further that interest?  - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The processing of a very limited set of personal data (email address and location) helps people advertise unwanted items for re-use to others in their locality. Not processing this information would render the service of much less use to the individuals who joined Freegle and therefore the the environment for the public more generally. &amp;lt;br&amp;gt; &lt;br /&gt;
Is it a reasonable way to go about it? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; This limited and focused processing is entirely reasonable and in line with the expectations of he individuals that join Freegle. &amp;lt;br&amp;gt;&lt;br /&gt;
Is there another less intrusive way to achieve the same result? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; There is no less intrusive way to effectively enable the exchange of items for reuse between members. As without this basic information posts to offer items would not be able to be replied to nor the seeker know where the item was. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the processing balanced against individual rights ?&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
What is the nature of your relationship with the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; All individuals are members of the Freegle service by choice, as they sign up to further enable them to gift or seek items for reuse. &amp;lt;br&amp;gt;&lt;br /&gt;
Is any of the data particularly sensitive or private? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No, there is no sensitive data kept. &amp;lt;br&amp;gt;&lt;br /&gt;
Would people expect you to use their data in this way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Individuals join Freegle specifically for this services, so they would expect their data to be used in this way. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you happy to explain it to them? - &#039;&#039; FA &amp;gt;&amp;gt;&#039;&#039;&#039; Yes we are very happy to explain it to them. This is mostly done by information on open Wiki pages (including this one) detailing everything we do. Additionally, we have also assigned a Data Protection Officer role despite not being required to due to not keeping sensitive data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are some people likely to object or find it intrusive? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Having reviewed our use we cannot foresee any reasonable objections to the use of the data in the way we process it. &amp;lt;br&amp;gt;&lt;br /&gt;
What is the possible impact on the individual? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; The most serious impact we can foresee with the release of data, is the a member who has not posted an item could possibly be identified by name and area they live. This could happen if they have their real name in their email address and it is associated with their postal area. &amp;lt;br&amp;gt;&lt;br /&gt;
How big an impact might it have on them? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; A member may feel that their privacy is impacted, although as most members would make this information public when they post an item it would be a risk they are likely comfortable with. &amp;lt;br&amp;gt;&lt;br /&gt;
Are you processing children’s data? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; Our policy is not to process children&#039;s data. &amp;lt;br&amp;gt;&lt;br /&gt;
Are any of the individuals vulnerable in any other way? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; No the freegle system does not make individuals vulnerable in any way&lt;br /&gt;
Can you adopt any safeguards to minimise the impact? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; As this is the only basic personal data we keep there are no other safeguards beyond our internal security measure that we can take. &lt;br /&gt;
Can you offer an opt-out? - &#039;&#039;&#039;FA &amp;gt;&amp;gt;&#039;&#039;&#039; If the individual is a member then we cannot offer an opt-out of the standard processing we do. There are settings that members have control of to opt in or out of mailing lists and the scope of what they can see when logged into the service. However there is no barrier to individuals leaving the service. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47830</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47830"/>
		<updated>2018-04-04T12:18:32Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Freegle&amp;#039;s Legitimate Interest Assessment */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Freegle&#039;s Legitimate Interest Assessment ==&lt;br /&gt;
&lt;br /&gt;
The Information Commissioner&#039;s Office suggest that if you use a Legitimate Interest basis of processing, you should conduct a Legitimate Interest Assessment [LIA]. An LIA is a type of light-touch risk assessment based on the specific context and circumstances. It will help ensure that our processing is lawful. Having an LIA will also help Freegle demonstrate compliance in line with it&#039;s accountability obligations under Articles 5(2) and 24. Therefore here below is our LIA.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Identify the legitimate interest(s)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Why do you want to process the data – what are you trying to achieve? Freegle Answer [FA] &amp;gt;&amp;gt; To enable individuals who have joined Freegle to gain reuse of their unwanted items to others in their locality. &amp;lt;br&amp;gt;&lt;br /&gt;
Who benefits from the processing? In what way? - FA &amp;gt;&amp;gt; The individual Freegle member in enabling reuse of their items and the environment as less waste goes to landfill or incineration. &amp;lt;br&amp;gt;&lt;br /&gt;
Are there any wider public benefits to the processing? - FA &amp;gt;&amp;gt; There is a wider public benefit that reuse aids the environment and can reduce volumes of landfill that are an expense to the public to process. &amp;lt;br&amp;gt;&lt;br /&gt;
How important are those benefits? - FA &amp;gt;&amp;gt; In the UK there is a shortage of landfill so the work of Freegle are important to tackling the environmental impact of waste. &amp;lt;br&amp;gt;&lt;br /&gt;
What would the impact be if you couldn’t go ahead? - FA &amp;gt;&amp;gt; Many hundreds of tonnes of waste would be added to the waste stream that ends up in Landfill &amp;lt;br&amp;gt;&lt;br /&gt;
Would your use of the data be unethical or unlawful in any way? - FA &amp;gt;&amp;gt; Freegle&#039;s use of personal data would not be unlawful or unethical, as our community depends heavily on the trust of its members. Freegle has data protection policies to ensure it is used responsibly and only for the stated aims of the organisation individuals are a member of. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the Processing Necessary&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Does this processing actually help to further that interest?  - FA &amp;gt;&amp;gt; The processing of a very limited set of personal data (email address and location) helps people advertise unwanted items for re-use to others in their locality. Not processing this information would render the service of much less use to the individuals who joined Freegle and therefore the the environment for the public more generally. &amp;lt;br&amp;gt; &lt;br /&gt;
Is it a reasonable way to go about it? - FA &amp;gt;&amp;gt; This limited and focused processing is entirely reasonable and in line with the expectations of he individuals that join Freegle. &amp;lt;br&amp;gt;&lt;br /&gt;
Is there another less intrusive way to achieve the same result? - FA &amp;gt;&amp;gt; There is no less intrusive way to effectively enable the exchange of items for reuse between members. As without this basic information posts to offer items would not be able to be replied to nor the seeker know where the item was. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the processing balanced against individual rights ?&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
What is the nature of your relationship with the individual? - FA &amp;gt;&amp;gt; All individuals are members of the Freegle service by choice, as they sign up to further enable them to gift or seek items for reuse. &amp;lt;br&amp;gt;&lt;br /&gt;
Is any of the data particularly sensitive or private?&lt;br /&gt;
Would people expect you to use their data in this way?&lt;br /&gt;
Are you happy to explain it to them?&lt;br /&gt;
Are some people likely to object or find it intrusive?&lt;br /&gt;
What is the possible impact on the individual?&lt;br /&gt;
How big an impact might it have on them?&lt;br /&gt;
Are you processing children’s data?&lt;br /&gt;
Are any of the individuals vulnerable in any other way?&lt;br /&gt;
Can you adopt any safeguards to minimise the impact?&lt;br /&gt;
Can you offer an opt-out?&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47827</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47827"/>
		<updated>2018-04-04T10:52:08Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Completed Tasks -  Freegle Data Protection Compliance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || This will be emails to the Board and mod groups that point to Wiki informational pages. &amp;lt;br&amp;gt;Completed - initial information out to the board/mods &amp;lt;br&amp;gt; Next - Complete the policy and request approval/amendment from the board.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Consent &amp;amp; Notices &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;- Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Use &amp;amp; Protection Wiki Page || This has been created and its mostly complete. &lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || Complete - We have chosen to use &amp;quot;Legitimate Interest&amp;quot; as out legal basis. Have also included a Legitimate Interest Assessment [LIA] as suggested by the ICO guidance.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47824</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=47824"/>
		<updated>2018-04-04T10:38:19Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || This will be emails to the Board and mod groups that point to Wiki informational pages. &amp;lt;br&amp;gt;Completed - initial information out to the board/mods &amp;lt;br&amp;gt; Next - Complete the policy and request approval/amendment from the board.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Consent &amp;amp; Notices &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;- Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 22nd March 2018 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Use &amp;amp; Protection Wiki Page || This has been created and its mostly complete. &lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || Complete - We have chosen to use &amp;quot;Legitimate Interest&amp;quot; as out legal basis. DPO will look for standard wording to expand out &amp;quot;Balancing statement&amp;quot; and see if we can get a DPO savvy legal eye over it.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47821</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47821"/>
		<updated>2018-04-04T10:37:29Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Freegle&#039;s Legitimate Interest Assessment ==&lt;br /&gt;
&lt;br /&gt;
The Information Commissioner&#039;s Office suggest that if you use a Legitimate Interest basis of processing, you should conduct a Legitimate Interest Assessment [LIA]. An LIA is a type of light-touch risk assessment based on the specific context and circumstances. It will help ensure that our processing is lawful. Having an LIA will also help Freegle demonstrate compliance in line with it&#039;s accountability obligations under Articles 5(2) and 24. Therefore here below is our LIA.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Identify the legitimate interest(s)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Why do you want to process the data – what are you trying to achieve? &lt;br /&gt;
Who benefits from the processing? In what way?&lt;br /&gt;
Are there any wider public benefits to the processing?&lt;br /&gt;
How important are those benefits?&lt;br /&gt;
What would the impact be if you couldn’t go ahead?&lt;br /&gt;
Would your use of the data be unethical or unlawful in any way?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the Processing Necessary&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Does this processing actually help to further that interest?&lt;br /&gt;
Is it a reasonable way to go about it?&lt;br /&gt;
Is there another less intrusive way to achieve the same result?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Is the processing balanced against individual rights ?&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
What is the nature of your relationship with the individual?&lt;br /&gt;
Is any of the data particularly sensitive or private?&lt;br /&gt;
Would people expect you to use their data in this way?&lt;br /&gt;
Are you happy to explain it to them?&lt;br /&gt;
Are some people likely to object or find it intrusive?&lt;br /&gt;
What is the possible impact on the individual?&lt;br /&gt;
How big an impact might it have on them?&lt;br /&gt;
Are you processing children’s data?&lt;br /&gt;
Are any of the individuals vulnerable in any other way?&lt;br /&gt;
Can you adopt any safeguards to minimise the impact?&lt;br /&gt;
Can you offer an opt-out?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47800</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47800"/>
		<updated>2018-04-02T12:33:43Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Personal Data Protection Policy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Protection Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle system directly from the system. In addition members may request other data Freegle may have about, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Age Restrictions&#039;&#039;&#039; - We will not maintain children&#039;s personal data, as we would then require some way to ensure that guardians consented to this. The definition of children in this respect is taken as 13 years old. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership, and up to 6 months after membership has ceased as part of our anti-SPAM measures. However, during these 6 months these details will not be visible. Should members wish to have their data removed immediately this can be arranged via the Data Protection Officer DPO@ilovefreegle.org &amp;lt;br&amp;gt;&lt;br /&gt;
Freegle Volunteers who correspond with others in relation to Freegle and its activities are advised to do so via the Freegle Direct system if possible. Freegle policy on correspondence outside of the FD system is also subject to a 6 month retention period unless the volunteer obtains consent from the correspondent that they may keep the information for an agreed longer period.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques (e.g. access restriction, encryption, taking backups etc) to ensure that data we hold will be kept safe from unauthorised access or loss on its system. We also advise all volunteers who store personal information to keep it secure with access limited to known individuals, . &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Protection Officer&#039;&#039;&#039; - due to the nature of Freegle we are  not legally obliged to have a Data Protection Officer [DPO]. However, we have a volunteer who undertakes this role who can be reached via email at DPO@ilovefreegle.org&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47797</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=47797"/>
		<updated>2018-04-02T12:21:43Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully, this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There are links at the bottom to other pages relevant to Data Protection such as our Policy.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Legal Basis for Processing || GDPR legislation requires that organisations have a legal basis for processing data.  There are six basis that can be used a. Consent, b. Contract, c. Legal obligation, d. Vital Interest, e. Public task, f. Legitimate Interest || Freegle will use Legitimate Interest as the legal basis for Processing&lt;br /&gt;
|-&lt;br /&gt;
| Legitimate Interest || We believe this legal basis balances the rights of our members with the benefits that Freegle brings to society and the environment.  || Freegle has chosen legitimate interest as a legal basis as we we only keep a very limited personal data, we use this only in ways directly related to providing a way to facilitate re-use transactions between members. Members have ways to see all data we keep and have the ability to remove themselves and their data from the system without hinderance.&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47728</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47728"/>
		<updated>2018-03-26T21:01:07Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Guidelines for Volunteer Moderators */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Corresponding with Members&#039;&#039;&#039; - We advise that you try to correspond with members using the chat function on the Freegle Direct system. If you do keep a copy of correspondence in your own email store, we ask that you keep Freegle messages in a separate folder. We advise that you have an email client that allows you to search for users to assist with requests for data, and a way of deleting data that is older than the Freegle retention policy limit. See [[Data Protection Policy]].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request [SAR]. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com around a particular scope or topic that has been cited in the SAR. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
 TBC - Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. Even correspondence around disputes would be available to a member should they submit a subject access request, so only write down things you would be O.K for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - What Personal Data Freegle keeps and how it uses it&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47725</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47725"/>
		<updated>2018-03-26T20:56:36Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Guidelines for Volunteer Moderators */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Corresponding with Members&#039;&#039;&#039; - We advise that you try to correspond with members using the chat function on the Freegle Direct system. If you do keep a copy of correspondence in your own email store, we ask that you keep Freegle messages in a separate folder. We advise that you have an email client that allows you to search for users to assist with requests for data, and a way of deleting data that is older than the Freegle retention policy limit. See [[Data Protection Policy]].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
Practically we would advise you to maintain a separate folder for Freegle emails and periodically reviewing what you have in that folder. Our guidance would be to delete email that is over XX years old. You may wish to keep information you are sure will be needed longer term in a separate folder so it doesn&#039;t get lost in any general periodic deletions. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
 TBC - Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. Even correspondence around disputes would be available to a member should they submit a subject access request, so only write down things you would be O.K for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - What Personal Data Freegle keeps and how it uses it&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47722</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47722"/>
		<updated>2018-03-26T20:48:26Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
Practically we would advise you to maintain a separate folder for Freegle emails and periodically reviewing what you have in that folder. Our guidance would be to delete email that is over XX years old. You may wish to keep information you are sure will be needed longer term in a separate folder so it doesn&#039;t get lost in any general periodic deletions. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
 TBC - Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. Even correspondence around disputes would be available to a member should they submit a subject access request, so only write down things you would be O.K for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - What Personal Data Freegle keeps and how it uses it&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47719</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47719"/>
		<updated>2018-03-26T20:29:45Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Personal Data Policy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Protection Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle system directly from the system. In addition members may request other data Freegle may have about, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership, and up to 6 months after membership has ceased as part of our anti-SPAM measures. However, during these 6 months these details will not be visible. Should members wish to have their data removed immediately this can be arranged via the Data Protection Officer DPO@ilovefreegle.org &amp;lt;br&amp;gt;&lt;br /&gt;
Freegle Volunteers who correspond with others in relation to Freegle and its activities are advised to do so via the Freegle Direct system if possible. Freegle policy on correspondence outside of the FD system is also subject to a 6 month retention period unless the volunteer obtains consent from the correspondent that they may keep the information for an agreed longer period.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques to ensure that data we hold will be kept safe from unauthorised access or loss on its system. We also advise all volunteers to maintain personal information to keep it secure with access limited to known individuals. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Protection Officer&#039;&#039;&#039; - due to the nature of Freegle we are  not legally obliged to have a Data Protection Officer [DPO]. However, we have a volunteer who undertakes this role who can be reached via email at DPO@ilovefreegle.org&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47716</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=47716"/>
		<updated>2018-03-26T20:22:52Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Useful Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
Practically we would advise you to maintain a separate folder for Freegle emails and periodically reviewing what you have in that folder. Our guidance would be to delete email that is over XX years old. You may wish to keep information you are sure will be needed longer term in a separate folder so it doesn&#039;t get lost in any general periodic deletions. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. Even correspondence around disputes would be available to a member should they submit a subject access request, so only write down things you would be O.K for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - What Personal Data Freegle keeps and how it uses it&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47713</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47713"/>
		<updated>2018-03-26T20:19:48Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Personal Data Policy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle system directly from the system. In addition members may request other data Freegle may have about, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership, and up to 6 months after membership has ceased as part of our anti-SPAM measures. However, during these 6 months these details will not be visible. Should members wish to have their data removed immediately this can be arranged via the Data Protection Officer DPO@ilovefreegle.org&lt;br /&gt;
Freegle Volunteers who correspond with others in relation to Freegle and its activities are advised to delete&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques to ensure that data we hold will be kept safe from unauthorised access or loss on its system. We also advise all volunteers to maintain personal information to keep it secure with access limited to known individuals. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Protection Officer&#039;&#039;&#039; - due to the nature of Freegle we are  not legally obliged to have a Data Protection Officer [DPO]. However, we have a volunteer who undertakes this role who can be reached via email at DPO@ilovefreegle.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47710</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47710"/>
		<updated>2018-03-26T19:12:14Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Personal Data Policy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To maintain the trust of our membership by keeping data safe and only using it as members would expect&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated [[Freegle Aims|aims]] of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle systems&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership. Should members wise to have their data removed from the Freegle system they can delete their membership.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques to ensure that data we hold will be kept safe from unauthorised access or loss.&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47585</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47585"/>
		<updated>2018-03-18T17:37:47Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Personal Data Policy ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Policy aims :&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* To keep the trust of our membership&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope of Personal Data held&#039;&#039;&#039; - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use of Data&#039;&#039;&#039; - Freegle will only use members personal data to help aid the purpose of furthering to stated aims of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Members Access to Data&#039;&#039;&#039; - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle systems&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Data Retention&#039;&#039;&#039; - Freegle will maintain data for the period of membership. Should members wise to have their data removed from the Freegle system they can delete their membership.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - Freegle will use industry standard techniques to ensure that data we hold will be kept safe from unauthorised access or loss.&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47582</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47582"/>
		<updated>2018-03-18T17:35:22Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Policies for dealing with Personal Data */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Policies for dealing with Personal Data ==&lt;br /&gt;
&lt;br /&gt;
Personal Data Policy &lt;br /&gt;
&lt;br /&gt;
Policy aims :&lt;br /&gt;
&lt;br /&gt;
* To keep the trust of our membership&lt;br /&gt;
* To comply with all UK laws on Data Protection&lt;br /&gt;
* To be open about all of the data we have associated to members, allowing them to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Definition of Personal Data - Any data that separately or in combination with other elements may identify a living individual.&lt;br /&gt;
&lt;br /&gt;
Scope of Personal Data held - Freegle will aim to minimise the amount of data it keeps to only that necessary to deliver the services to members. &lt;br /&gt;
&lt;br /&gt;
Use of Data - Freegle will only use members personal data to help aid the purpose of furthering to stated aims of Freegle in the communities it serves. These are the reuse of materials and sharing local charity events and volunteer opportunities. &lt;br /&gt;
&lt;br /&gt;
Allowing Members Access to Data - Freegle will allow its members to see all the personal data (and other associated data if possible) we have on the Freegle systems&lt;br /&gt;
&lt;br /&gt;
Data Retention - Freegle will maintain data for the period of membership. Should members wise to have their data removed from the Freegle system they can delete their membership.&lt;br /&gt;
&lt;br /&gt;
Storing Data Securely - Freegle will use industry standard techniques to ensure that data we hold will be kept safe from unauthorised access or loss.&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47579</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=47579"/>
		<updated>2018-03-18T15:46:41Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Policies for dealing with Personal Data */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Policies for dealing with Personal Data ==&lt;br /&gt;
&lt;br /&gt;
Personal Data Policy &lt;br /&gt;
&lt;br /&gt;
Policy aims :&lt;br /&gt;
&lt;br /&gt;
* To keep the trust of our membershipminimum person&lt;br /&gt;
&lt;br /&gt;
Definition of Personal Data - &lt;br /&gt;
&lt;br /&gt;
Obtaining Consent&lt;br /&gt;
&lt;br /&gt;
Allowing Access to Data&lt;br /&gt;
&lt;br /&gt;
Deleting Data - Right to be forgotten&lt;br /&gt;
&lt;br /&gt;
Minimising Data retained - Review and retention rules&lt;br /&gt;
&lt;br /&gt;
Storing data securely&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45990</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45990"/>
		<updated>2017-11-26T20:48:09Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* What about groups that are on Yahoo Groups */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle Yahoo groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45912</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45912"/>
		<updated>2017-11-05T22:42:58Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Definition of Personal Data&#039;&#039;&#039; - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, postal address and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Obtaining Consent&#039;&#039;&#039; - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Allowing Access to Data&#039;&#039;&#039; - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com. This would include any correspondence about them, even if it wasn&#039;t address to them. Volunteers may feel that their commentary or notes about a member should remain private if it wasn&#039;t correspondence shared with the member. By law this is not the case unless covered by legal exemptions (the Data Protection Officer will clarify at the time of request), for example if it pertains to criminal investigation. Exemptions can be seen here [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Deleting Data&#039;&#039;&#039; - Right to be forgotten - If anyone asks Freegle to delete their data, we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimising Data Retained&#039;&#039;&#039; - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
Practically we would advise you to maintain a separate folder for Freegle emails and periodically reviewing what you have in that folder. Our guidance would be to delete email that is over XX years old. You may wish to keep information you are sure will be needed longer term in a separate folder so it doesn&#039;t get lost in any general periodic deletions. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Storing Data Securely&#039;&#039;&#039; - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
Essentially the guidance above for volunteers should cover most of what national volunteers do as well. Please be aware that any data you retain will be in scope of a &amp;quot;Subject Access Request&amp;quot;. Even correspondence around disputes would be available to a member should they submit a subject access request, so only write down things you would be O.K for the subject of the correspondence to read.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for the Data Protection Officer ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The Data Protection Officer Role&#039;&#039;&#039; - Your role is to advise the board of Freegle as to the extent of the organisation&#039;s compliance with Data Protection legislation. You, nor the role, is the responsible party for compliance. you are there to provide a level of objective review of operations and advise on how Freegle may change to ensure compliance is maintained. &lt;br /&gt;
&lt;br /&gt;
To do this you must periodically review the data being held by the different parts of the Freegle organisation and how it is stored and processed. Each time this is done it would be wise to record the outcome of this investigation to show any external body the process and the work done from that. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Subject Access Request [SAR] processing&#039;&#039;&#039;- You should be the gatekeeper for the process. You need to try to respond in a timely manner to requests, review with those who would have the data any exemptions that would apply, then formally request all relevant parties to supply the data. You will then have to return the data in a common format to the requester. You may also have to ensure that the access request fee is received should Freegle impose a fee on this process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Communications&#039;&#039;&#039; - It is your role to periodically update the board and membership on 1. works to do with Data Protection (i.e. surveys, or changes to teh Freegle system for DP reasons); 2. Concerns or issues that you have discovered [These must be formally raised with the Board]; changes to the law that it would be helpful for The Baord and membership to know&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45909</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45909"/>
		<updated>2017-11-05T21:30:09Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Key Elements of GDPR and what Freegle are doing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle will be doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45906</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45906"/>
		<updated>2017-11-05T21:29:33Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* How does Freegle Process this data */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data? ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45762</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45762"/>
		<updated>2017-10-22T19:13:00Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Guidelines for Volunteer Moderators */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle [[Data Protection Policy]] sections  &lt;br /&gt;
&lt;br /&gt;
Definition of Personal Data - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, location and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
Obtaining Consent - you are not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context for which is was sent.&lt;br /&gt;
&lt;br /&gt;
Allowing Access to Data - All personal information you retain for your role in Freegle could be in scope of a Subject Access Request. This is where anyone can ask for a copy of all the information about them that Freegle (including its moderators) hold. These requests would come through the Data Protection Officer to ensure that they were reasonable and to give you search criteria to use to find it. For instance we may ask you to send us all information you have pertaining to fred.bloggs@hotmail.com. This would include any correspondence about them, even if it wasn&#039;t address to them. &lt;br /&gt;
&lt;br /&gt;
Deleting Data - Right to be forgotten - If anyone asks Freegle to delete their data we have by law to ensure we do this. Typically this will be by deleting their user from a group. Due to the service we offer we will only do this in line with our published policy, so we may have their posts on the group visible for some time until they expire due to our data retention policy. However, if we do get a request under this law asking for all data to be deleted we will ask that moderators try to delete information in line with search criteria the Data Protection Officer will send to them. i.e. please can you delete all information you have on fred.bloggs@hotmail.com&lt;br /&gt;
&lt;br /&gt;
Minimising Data Retained - However tempting it is to keep everything you&#039;ve ever had about Freegle we recommend that you only retain information that is essential for you fulfilling the role you have.&lt;br /&gt;
Practically we would advise you to maintain a separate folder for Freegle emails and periodically reviewing what you have in that folder. Our guidance would be to delete email that is over XX years old. You may wish to keep information you are sure will be needed longer term in a separate folder so it doesn&#039;t get lost in any general periodic deletions. &lt;br /&gt;
&lt;br /&gt;
Storing data securely - You should keep the access to all personal data you hold to only those with a legitimate need to see it. So if you have emails in a mailbox or file store (e.g. Google Docs), ensure that access is password protected. Where the mailbox or file store is a group one, ensure that only those that should be able to see it can have access by periodically checking who has rights and changing passwords when moderators leave the group.&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
Its assumed that &lt;br /&gt;
&lt;br /&gt;
Guidelines for the Data Protection Officer&lt;br /&gt;
&lt;br /&gt;
&amp;quot;How To&amp;quot; Section for Users&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45759</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45759"/>
		<updated>2017-10-22T18:36:33Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* This Page will contain Guidelines for the implementation of Data Protection Policies */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Volunteer Moderators ==&lt;br /&gt;
&lt;br /&gt;
This guidance is aligned to the freegle Data Protection Policy sections [[Data Protection Policy]] &lt;br /&gt;
&lt;br /&gt;
Definition of Personal Data - This is anything that can identify a living person. In your role as a moderator it will typically be things like their email address, location and possibly other things they write in emails.&lt;br /&gt;
&lt;br /&gt;
Obtaining Consent - We don&#039;t expect you to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, as good practice you should not use this information outside of the Freegle context.&lt;br /&gt;
&lt;br /&gt;
Allowing Access to Data - &lt;br /&gt;
Deleting Data - Right to be forgotten&lt;br /&gt;
Minimising Data retained - Review and retention rules&lt;br /&gt;
Storing data securely&lt;br /&gt;
&lt;br /&gt;
Keeping Personal Data - If you keep data on any system, be it you PC, Yahoo group files, Google Docs or written in a note book  you must take responsibility to do the following&lt;br /&gt;
&lt;br /&gt;
1. Keep only what is necessary to effectively run the group. Although it may be tempting to keep everything that has ever been emailed to you about Freegle this means you may have out of date information&lt;br /&gt;
2. Everything you have kept about anyone who was or is a member will be in scope of a subject access request &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Guidelines for Functional Groups (i.e. freegle Growth, Freegle Media etc ) ==&lt;br /&gt;
&lt;br /&gt;
Its assumed that &lt;br /&gt;
&lt;br /&gt;
Guidelines for the Data Protection Officer&lt;br /&gt;
&lt;br /&gt;
&amp;quot;How To&amp;quot; Section for Users&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45756</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45756"/>
		<updated>2017-10-22T18:06:14Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* How does Freegle Process this data */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the user&#039;s Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || Creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45475</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45475"/>
		<updated>2017-10-08T19:33:48Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle Process this data ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Processing by Freegle direct (In summary)&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Functions || Maintaining settings and groups aligned with a member;&amp;lt;br&amp;gt; Aligning logins from other systems (Google, Yahoo, Facebook) with the Freegle membership &lt;br /&gt;
|-&lt;br /&gt;
| Emailing Members|| sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns &lt;br /&gt;
|-&lt;br /&gt;
| Collated member information || creates a summary set of information about members so other members can see their previous activity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45472</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45472"/>
		<updated>2017-10-08T18:08:39Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* What Personal Data does Freegle keep on its system? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. &amp;lt;br&amp;gt;&lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers, who run things for Freegle that aren&#039;t directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn&#039;t expect it to be. &amp;lt;br&amp;gt; So we don&#039;t share data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing) and never sell it. &amp;lt;br&amp;gt;Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthened the consent needed, so organisations can&#039;t assume that you consent to them keeping your data; they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving Freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it&#039;s appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it&#039;s more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45342</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45342"/>
		<updated>2017-09-17T19:44:56Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members it wouldn&#039;t expect to be. &amp;lt;br&amp;gt; So we never share or sell data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing). &amp;lt;br&amp;gt;Freegle fully complys with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45339</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45339"/>
		<updated>2017-09-17T19:43:51Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || There will be a few items posted out as we work through the different elements, however most information will be via the notifications that point to Wiki informational pages.&lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || DPO will look for standard wording and see if we can get a DPO savvy legal eye over it.&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Consent &amp;amp; Notices &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;- Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45336</id>
		<title>Data Protection Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Guidelines&amp;diff=45336"/>
		<updated>2017-09-17T19:43:12Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: Created page with &amp;quot;== This Page will contain Guidelines for the implementation of Data Protection Policies ==  Guidelines for System Owners  Guidelines for Volunteers  Guidelines for the Data Pr...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== This Page will contain Guidelines for the implementation of Data Protection Policies ==&lt;br /&gt;
&lt;br /&gt;
Guidelines for System Owners&lt;br /&gt;
&lt;br /&gt;
Guidelines for Volunteers&lt;br /&gt;
&lt;br /&gt;
Guidelines for the Data Protection Officer&lt;br /&gt;
&lt;br /&gt;
&amp;quot;How To&amp;quot; Section for Users&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45333</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45333"/>
		<updated>2017-09-17T19:34:49Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || There will be a few items posted out as we work through the different elements, however most information will be via the notifications that point to Wiki informational pages.&lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || DPO will look for standard wording and see if we can get a DPO savvy legal eye over it.&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Consent &amp;amp; Notices &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;The DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45330</id>
		<title>Data Protection Compliance - Volunteer Task list</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Compliance_-_Volunteer_Task_list&amp;diff=45330"/>
		<updated>2017-09-17T19:33:03Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: Created page with &amp;quot;== Ongoing Tasks on Freegle Data Protection Compliance ==  As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are o...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Ongoing Tasks on Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Tasks&lt;br /&gt;
! Task Status&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Raising the awareness of the Board, Volunteers and Membership of Freegle to the GDPR implications || There will be a few items posted out as we work through the different elements, however most information will be via the notifications that point to Wiki informational pages.&lt;br /&gt;
|-&lt;br /&gt;
| Document Freegle&#039;s Legal Basis for Data Processing &amp;amp; National Jurisdiction || DPO will look for standard wording and see if we can get a DPO savvy legal eye over it.&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Policy Document || This will clearly spell out Freegle&#039;s policy on :&amp;lt;br&amp;gt;- Consent &amp;amp; Notices &amp;lt;br&amp;gt;- Subject Access requests&amp;lt;br&amp;gt;- Notification of Data Breaches&amp;lt;br&amp;gt;- Children&#039;s accounts and guardian consent&amp;lt;br&amp;gt;Design of Data Protection&amp;lt;br&amp;gt;- User requested data deletion&amp;lt;br&amp;gt;- Data Retention Policy || DPO to draft initial policy and work with system owners (Freegle Direct, Norfolk, TrashNothing) to ensure there is clarity&lt;br /&gt;
|-&lt;br /&gt;
| Create Data Protection Guidance || This will explain how the policies can be operated. This will be for the System owners and Volunteers&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Completed Tasks -  Freegle Data Protection Compliance ==&lt;br /&gt;
&lt;br /&gt;
As of 17th Sept 2017 the volunteer who is dealing with Data Protection compliance has the following tasks that are ongoing&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Ongoing Task&lt;br /&gt;
! Completion comments&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Assign Data Protection Officer || Although its not a legal or regulatory requirement for an organisation such as Freegle to have a DPO, we have a Volunteer assigned. There is also a generic email address for this function which is DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Use &amp;amp; Protection]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45327</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45327"/>
		<updated>2017-09-17T18:51:16Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members it wouldn&#039;t expect to be. &amp;lt;br&amp;gt; So we never share or sell data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing). &amp;lt;br&amp;gt;Freegle fully complys with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=45309</id>
		<title>Data Protection Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Protection_Policy&amp;diff=45309"/>
		<updated>2017-09-15T19:44:34Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: Details of the Policies Freegle has around dealing with Personal Data&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Policies for dealing with Personal Data ==&lt;br /&gt;
&lt;br /&gt;
Definition of Personal Data - &lt;br /&gt;
&lt;br /&gt;
Obtaining Consent&lt;br /&gt;
&lt;br /&gt;
Allowing Access to Data&lt;br /&gt;
&lt;br /&gt;
Deleting Data - Right to be forgotten&lt;br /&gt;
&lt;br /&gt;
Minimising Data retained - Review and retention rules&lt;br /&gt;
&lt;br /&gt;
Storing data securely&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45306</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45306"/>
		<updated>2017-09-15T19:40:19Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Useful Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members it wouldn&#039;t expect to be. &amp;lt;br&amp;gt; So we never share or sell data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing). &amp;lt;br&amp;gt;Freegle fully complys with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Data Protection Policy]] - Policies for dealing with Personal Data&lt;br /&gt;
*[[Data Protection Guidelines]] - Guidelines for Volunteers&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]] [[category: Data Protection]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45303</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45303"/>
		<updated>2017-09-15T19:21:48Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* How does Freegle ensure it complies with Data Protection Law? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members it wouldn&#039;t expect to be. &amp;lt;br&amp;gt; So we never share or sell data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing). &amp;lt;br&amp;gt;Freegle fully complys with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45300</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45300"/>
		<updated>2017-09-15T19:20:32Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* How does Freegle ensure it complies with Data Protection Law? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members it wouldn&#039;t expect to be. &amp;lt;br&amp;gt; So we never share or sell data with other organisations (other than to run groups with Yahoo &amp;amp; TrashNothing). &amp;lt;br&amp;gt;We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45297</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45297"/>
		<updated>2017-09-15T19:17:17Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Where does Freegle keep data? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 600px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45294</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45294"/>
		<updated>2017-09-15T19:16:39Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* What about groups that are on Yahoo Groups */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 800px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Freegle groups that use Yahoo Groups system only&#039;&#039;&#039;  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Freegle groups that are linked to the Freegle System&#039;&#039;&#039; - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45291</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45291"/>
		<updated>2017-09-15T19:01:15Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* How does Freegle ensure it complies with Data Protection Law? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 800px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work.&amp;lt;br&amp;gt; Therefore, it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register our organisation. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.&lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
1. Freegle groups that only use Yahoo and no other system, and &lt;br /&gt;
2. freegle groups that use Yahoo Groups linked to the Freegle system.&lt;br /&gt;
&lt;br /&gt;
1. Freegle groups that use Yahoo Groups system only  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
2. Freegle groups that are linked to the Freegle System - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45288</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45288"/>
		<updated>2017-09-15T18:59:39Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: /* Where does Freegle keep data? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 800px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work. Therefore it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions. &lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
1. Freegle groups that only use Yahoo and no other system, and &lt;br /&gt;
2. freegle groups that use Yahoo Groups linked to the Freegle system.&lt;br /&gt;
&lt;br /&gt;
1. Freegle groups that use Yahoo Groups system only  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
2. Freegle groups that are linked to the Freegle System - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45285</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45285"/>
		<updated>2017-09-15T18:31:33Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 100px;&amp;quot; | Area &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 800px;&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; style=&amp;quot;width: 300px;&amp;quot; | Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries and other  may keep information about how the group is running. We are currently (Sept 2017) looking into what local groups typically keep so we can advise them and come up with the appropriate guidance and policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work. Therefore it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions. &lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
1. Freegle groups that only use Yahoo and no other system, and &lt;br /&gt;
2. freegle groups that use Yahoo Groups linked to the Freegle system.&lt;br /&gt;
&lt;br /&gt;
1. Freegle groups that use Yahoo Groups system only  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
2. Freegle groups that are linked to the Freegle System - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45282</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45282"/>
		<updated>2017-09-15T18:20:31Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Area &lt;br /&gt;
! Description&lt;br /&gt;
! Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries and other  may keep information about how the group is running. We are currently (Sept 2017) looking into what local groups typically keep so we can advise them and come up with the appropriate guidance and policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work. Therefore it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions. &lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
1. Freegle groups that only use Yahoo and no other system, and &lt;br /&gt;
2. freegle groups that use Yahoo Groups linked to the Freegle system.&lt;br /&gt;
&lt;br /&gt;
1. Freegle groups that use Yahoo Groups system only  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
2. Freegle groups that are linked to the Freegle System - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
	<entry>
		<id>https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45279</id>
		<title>Data Use &amp; Protection</title>
		<link rel="alternate" type="text/html" href="https://wiki.ilovefreegle.org/index.php?title=Data_Use_%26_Protection&amp;diff=45279"/>
		<updated>2017-09-15T18:19:15Z</updated>

		<summary type="html">&lt;p&gt;Jc4freegle: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, it terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for freegle volunteers and members. &lt;br /&gt;
There is also a link to our Data Protection Policy which is more detailed and it so we can show our compliance to relevant data protection legislation.&lt;br /&gt;
&lt;br /&gt;
== Where does Freegle keep data? ==&lt;br /&gt;
&lt;br /&gt;
There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Area &lt;br /&gt;
! Description&lt;br /&gt;
! Personal Data types held&lt;br /&gt;
|-&lt;br /&gt;
| 1. The Freegle System || The majority of data freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].&amp;lt;br&amp;gt; This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn&#039;t keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)&amp;lt;br&amp;gt; Address Book (Postcode  &amp;amp; user supplied directions text)&lt;br /&gt;
|-&lt;br /&gt;
| 2. National volunteers || The national volunteers who run things for Freegle that aren&#039;t directly for a local groups, they keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)&amp;lt;br&amp;gt; Board Member &amp;amp; Shareholders postal details&lt;br /&gt;
|-&lt;br /&gt;
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries and other  may keep information about how the group is running. We are currently (Sept 2017) looking into what local groups typically keep so we can advise them and come up with the appropriate guidance and policy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What Personal Data does Freegle keep on its system? ==&lt;br /&gt;
&lt;br /&gt;
Freegle keeps little personal data, and nothing that would be called sensitive.&lt;br /&gt;
&lt;br /&gt;
Personal Data on Freegle Direct :&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function&lt;br /&gt;
! Personal data recorded&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Membership Detail || - email address &amp;lt;br&amp;gt;- User name&amp;lt;br&amp;gt;- Post code&lt;br /&gt;
|-&lt;br /&gt;
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)&amp;lt;br&amp;gt;- Directions - Often this will contain the user&#039;s address and other detail to help others navigate to their address)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Although this information may not directly identify an individual, it may do if their real name was in their email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How does Freegle ensure it complies with Data Protection Law? ==&lt;br /&gt;
&lt;br /&gt;
Freegle relies on trust to continue to work. Therefore it takes its responsibilities seriously around data protection. We fully comply with current UK law in this area, even though we are not required by the Information Commissioner&#039;s Office to register. &lt;br /&gt;
&lt;br /&gt;
We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short that takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions. &lt;br /&gt;
&lt;br /&gt;
== Key Elements of GDPR and what Freegle are doing ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! GDPR Area&lt;br /&gt;
! What this means&lt;br /&gt;
! What Freegle are doing&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| Consent || GDPR has strengthen the consent needed, so organisations can&#039;t assume that you consent to them keeping your data, they &amp;lt;br&amp;gt; must get positive confirmation from you to retain it, and they need to tell you what they will use if for in plain language. &amp;lt;br&amp;gt; Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the, has clear information about how it will be used, buttons that clearly allow consent or not (usually &amp;quot;OK xxxxx&amp;quot; or &amp;quot;cancel&amp;quot;) and a way to later withdraw consent (this may be leaving freegle).&lt;br /&gt;
|-&lt;br /&gt;
| Right to Access &amp;amp; Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle will be adding in a function under the settings tab to enable you to download all of your personal data and settings.&lt;br /&gt;
|-&lt;br /&gt;
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time its appropriate.&lt;br /&gt;
|-&lt;br /&gt;
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.&lt;br /&gt;
|-&lt;br /&gt;
| Breach Notification ||  Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach or hack as its more commonly known we will let our members know via email and the UK Data Protection Authority. Luckily we don&#039;t keep anything sensitive, and therefore its unlikely to risk anyone&#039;s rights or freedoms.&lt;br /&gt;
|-&lt;br /&gt;
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn&#039;t be able to function.&lt;br /&gt;
|-&lt;br /&gt;
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn&#039;t require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== What about groups that are on Yahoo Groups ==&lt;br /&gt;
&lt;br /&gt;
There are two types of groups that use the Yahoo Groups system. &amp;lt;br&amp;gt;&lt;br /&gt;
1. Freegle groups that only use Yahoo and no other system, and &lt;br /&gt;
2. freegle groups that use Yahoo Groups linked to the Freegle system.&lt;br /&gt;
&lt;br /&gt;
1. Freegle groups that use Yahoo Groups system only  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners. &lt;br /&gt;
&lt;br /&gt;
2. Freegle groups that are linked to the Freegle System - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and  guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.&lt;br /&gt;
&lt;br /&gt;
== What about groups on the Norfolk Freegle system? ==&lt;br /&gt;
&lt;br /&gt;
The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]&lt;br /&gt;
&lt;br /&gt;
== What about users of TrashNothing? ==&lt;br /&gt;
&lt;br /&gt;
Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address &amp;amp; Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
*[[Spam]] - further explanation to counter accusations that we spam!&lt;br /&gt;
*[[Basic Information]]&lt;br /&gt;
*[[Admin]]&lt;br /&gt;
&lt;br /&gt;
[[category:Admin]] [[category:Freegle Direct]]&lt;/div&gt;</summary>
		<author><name>Jc4freegle</name></author>
	</entry>
</feed>