Data Use & Protection: Difference between revisions

From Freegle Wiki
Wiki revamp: restructure & modernise
 
(29 intermediate revisions by 5 users not shown)
Line 1: Line 1:
 
This page explains what personal data Freegle keeps, why, and how it's processed, protected and deleted. It aims to be a straightforward explanation for volunteers and members. Links to other relevant pages, including our formal Policy, are at the bottom.
This page is to explain what personal data Freegle keeps, why it keeps it and what it does with it, in terms of processing, protecting and deleting it. Hopefully this is a straight forward explanation for Freegle volunteers and members. <br>
There is also a link to our Data Protection Policy which is more detailed, so we can show our compliance to relevant data protection legislation.


== Where does Freegle keep data? ==
== Where does Freegle keep data? ==


There are three areas that we need to consider when we talk about where the Freegle organisation keeps personal data:
There are three areas to consider when thinking about where the Freegle organisation keeps personal data:


{| class="wikitable"
{| class="wikitable"
! scope="col" style="width: 100px;" | Area  
! scope="col" | Area
! scope="col" style="width: 600px;" | Description
! scope="col" | Description
! scope="col" style="width: 300px;" | Personal Data types held
! scope="col" | Personal data types held
|-
|-
| 1. The Freegle System || The majority of data that Freegle has is kept in the system we call Freegle Direct see [http://ilovefreegle.org].<br> This is where all groups are held (apart from those in Norfolk [http://www.norfolkfreegle.org/] and the few groups still only on Yahoo groups) and the Freegle posts are shown. As Freegle Direct works with Yahoo groups where they can co-exist then Yahoo does keep other data that Freegle itself doesn't keep. Also Freegle Direct allows users to login using their Google, Yahoo or Facebook credentials that are authenticated by those services, so the data kept and the compliance of those companies with the legislation is up to them.|| Membership Details (email and Postcode)<br> Address Book (Postcode  & user supplied directions text)
| 1. The Freegle system || Most of Freegle's data is kept in the system we call Freegle Direct - see [http://ilovefreegle.org]. This is where all communities are held and posts are shown. Freegle Direct also lets members log in using Google, Facebook or Apple credentials, authenticated by those services; the data those companies keep, and their compliance with data protection law, is up to them. || Membership details (email and postcode)<br>Address book (postcode and user-supplied directions text)
|-
|-
| 2. National volunteers || The national volunteers, who run things for Freegle that aren't directly for a local groups, keep data about their areas such as finance, media and IT development etc. We surveyed these volunteers and essentially they keep limited personal data such as email addresses and in some cases postal addresses. These tend to be kept in local or group email accounts and in Google docs with restricted access. || Email contacts (email address)<br> Board Member & Shareholders postal details
| 2. National volunteers || National volunteers, who run things for Freegle that aren't specific to one community - such as finance, media and IT development - keep limited personal data about their own areas of work. A survey of these volunteers found this is mainly email addresses and occasionally postal addresses, usually kept in local or group email accounts and in Google Docs with restricted access. || Email contacts (email address)<br>Board member and shareholder postal details
|-
|-
| 3. Local groups volunteers || Local volunteers tend to only have personal data of local members such as their email addresses for when they are dealing with queries. || Membership details (email addresses)
| 3. Local community volunteers || Local volunteers tend to hold only the personal data of their own members, such as email addresses, for dealing with queries. || Membership details (email addresses)
|}
|}


== What Personal Data does Freegle keep on its system? ==
== What personal data does Freegle keep on its system? ==


Freegle keeps little personal data, and nothing that would be called sensitive in legal terms, so nothing like health or financial data.
Freegle keeps very little personal data, and nothing that counts as sensitive in legal terms - nothing like health or financial data.


Personal Data on Freegle Direct :
{| class="wikitable"
{| class="wikitable"
! Function
! Function
! Personal data recorded
! Personal data recorded
|- valign="top"
| Membership Detail || - email address <br>- User name<br>- Post code
|-
|-
| Address Book || - Post Code (user could enter a different one to that stored with the membership detail)<br>- Directions - Often this will contain the user's address and other detail to help others navigate to their address)
| Membership detail || Email address, user name, postcode
|-
| Address book || Postcode (a member can enter one different to the one on their membership); directions text, which will often include the member's address and other detail to help others find them
|}
|}


Although this information may not directly identify an individual, it may do if their real name was in their email address and if combined with their post code.
This information may not directly identify someone on its own, but it may do if their real name appears in their email address and is combined with their postcode.


== How does Freegle Process this data? ==
== How does Freegle process this data? ==


{| class="wikitable"
{| class="wikitable"
! Function
! Function
! Processing by Freegle direct (In summary)
! Processing by Freegle Direct (summary)
|- valign="top"
|-
| Membership Functions || Maintaining settings and groups aligned with a member;<br> Aligning logins from other systems (Google, Yahoo, Facebook) with the user's Freegle membership  
| Membership functions || Maintaining settings and communities linked to a member; matching logins from other systems (Google, Facebook, Apple) to the member's Freegle membership
|-
|-
| Emailing Members|| Sending emails in line with member specified preferences containing: groups posts, automatic prompts, local moderator admin messages and national campaigns  
| Emailing members || Sending emails in line with member preferences: community posts, automatic prompts, local moderator admin messages and national campaigns
|-
|-
| Collated member information || Creates a summary set of information about members so other members can see their previous activity
| Collated member information || Creating a summary of a member's activity so other members can see it
|}
|}


== How does Freegle ensure it complies with Data Protection Law? ==
== How does Freegle comply with data protection law? ==


Freegle relies on trust to continue to work.<br> Therefore, it takes its responsibilities seriously around data protection, not just to comply legally but also not to use data in a way that members wouldn't expect it to be. <br> So we don't share data with other organisations (other than to run groups with Yahoo & TrashNothing) and never sell it. <br>Freegle fully complies with current UK law in this area, even though we are not required by the Information Commissioner's Office to register our organisation.  
Freegle relies on trust to keep working. It takes its data protection responsibilities seriously, not just to comply with the law but so it doesn't use data in a way members wouldn't expect. We don't share data with other organisations (other than to run communities with TrashNothing) and we never sell it. Should a community wish to move its membership away from Freegle to another organisation, we will work with the volunteers who own that community. Freegle's advice to community owners is to ensure all members get the chance to opt in to the new organisation and its data protection policies; limited membership data will be made available to help with any such move, in line with the [[Disaffiliation Procedure]].


Freegle fully complies with current UK law in this area, even though the Information Commissioner's Office doesn't require us to register the organisation.


We are currently reviewing what we do to ensure that we are compliant with the new EU laws called the General Data Protection Regulation, commonly known as GDPR [http://http://www.eugdpr.org/] for short, which takes effect from 25th April 2018. The UK government have stated that they will be transferring GDPR into UK law, so it will be relevant post any Brexit decisions.
Freegle reviewed its practices ahead of the General Data Protection Regulation (GDPR) [https://gdpr-info.eu/], which took effect on 25 April 2018. The UK government transferred GDPR into UK law, so it has continued to apply since Brexit.


== Key Elements of GDPR and what Freegle will be doing ==
== Key elements of GDPR and what Freegle does ==


{| class="wikitable"
{| class="wikitable"
! GDPR Area
! GDPR area
! What this means
! What this means
! What Freegle are doing
! What Freegle does
|- valign="top"
| Consent || GDPR has strengthened the consent needed, so organisations can't assume that you consent to them keeping your data; they <br> must get positive confirmation from you to retain it, and they need to tell you what they will use it for in plain language. <br> Plus they need to give you the ability to withdraw consent. || Freegle is ensuring that all the personal data you are asked for is the minimum required to run the service, has clear information about how it will be used, buttons that clearly allow consent or not (usually "OK xxxxx" or "cancel") and a way to later withdraw consent (this may be leaving Freegle).
|-
|-
| Right to Access & Data Portability || You can obtain confirmation from an organisation if they are processing your personal data. You also have the right to get a copy of any personal data held in a standard electronic format, so you can transfer it to other organisations. || Freegle Direct will be adding in a function under the settings tab to enable you to download all of your personal data and settings.
| Legal basis for processing || GDPR requires organisations to have a legal basis for processing data. There are six possible bases: consent, contract, legal obligation, vital interest, public task, or legitimate interest. || Freegle uses legitimate interest as its legal basis for processing.
|-
|-
| Right to be forgotten || This means that you have the right to have your personal data erased on request, or if it is no longer relevant to the processing that consent was given for. || Freegle will enable you to have erased the personal data in the Address Book function. However if you want to erase your membership data then it will mean that your membership login will be deleted. In addition policy and guidance will ensure that we keep the minimum data needed only for the time it's appropriate.
| Legitimate interest || This legal basis balances members' rights with the benefits Freegle brings to society and the environment. || Freegle keeps only very limited personal data, used solely to facilitate reuse between members. Members can see all the data we keep and can remove themselves and their data from the system without hindrance.
|-
|-
| Privacy by Design || This means that the systems your data is held on need to be designed to keep the minimum data necessary for the completion of its duties (data minimisation), as well as limiting the access to personal data to those needing to act out the processing. || Freegle already has access protection in for its Freegle Direct system and keeps the least personal data possible to deliver the Freegle services.
| Right to access & data portability || You can ask an organisation to confirm whether it's processing your personal data, and get a copy of it in a standard electronic format so you can transfer it elsewhere. || Members can see and download everything Freegle holds about them, in a machine-readable format, from '''Download your data''' (in Settings, or [https://www.ilovefreegle.org/mydata ilovefreegle.org/mydata]).
|-
|-
| Breach Notification || Under the GDPR, breach notification will become mandatory where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach. Organisations will also be required to notify their customers “without undue delay” after first becoming aware of a data breach. || If Freegle became aware of any breach, or hack as it's more commonly known, we will let our members know via email and the UK Data Protection Authority. Luckily we don't keep anything sensitive, and therefore its unlikely to risk anyone's rights or freedoms.
| Right to be forgotten || You have the right to have your personal data erased on request, or once it's no longer relevant to the purpose it was collected for. || Members can erase the personal data held in their Address Book, and can delete their membership login entirely via Settings, which removes their account (see [[Trouble unsubscribing]]). Policy and guidance ensure we keep only the minimum data needed, for only as long as it's needed.
|-
|-
| Penalties || If an organisation violates the GDPR regulations it can be fined up to 4% of its annual global turnover || We at Freegle understand this is aimed at big corporations so they take it seriously. We too take it seriously as without the trust of our members Freegle wouldn't be able to function.
| Privacy by design || Systems holding personal data must be designed to keep only the minimum data needed (data minimisation), and to limit access to those who need it. || Freegle Direct has access controls in place and keeps as little personal data as possible to deliver its services.
|-
|-
| Data Protection Officer || The GDPR law DPO appointment will be mandatory only for those controllers and processors whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale or of special categories of data or data relating to criminal convictions and offences. ||Although the law doesn't require organisations like Freegle to appoint a Data Protection Officer we will be having a volunteer position to look at this areas for us. They can be contacted by email at DPO@ilovefreegle.org
| Breach notification || Under GDPR, notification is mandatory where a data breach is likely to "result in a risk for the rights and freedoms of individuals", within 72 hours of first becoming aware of it. Organisations must also notify affected people "without undue delay". || If Freegle became aware of a breach (a hack), we would let members know by email and notify the UK Data Protection Authority. We don't keep anything sensitive, so the risk to anyone's rights or freedoms is low.
|-
| Penalties || An organisation that breaches GDPR can be fined up to 4% of its annual global turnover. || This is aimed at large corporations, but Freegle takes it just as seriously - without members' trust, Freegle couldn't function.
|-
| Data Protection Officer || GDPR only makes a Data Protection Officer mandatory for organisations whose core activity involves large-scale, regular and systematic monitoring of people, or processing special categories of data. || Although the law doesn't require it, Freegle has a volunteer Data Protection Officer role. Contact DPO@ilovefreegle.org.
|}
|}


== What about groups that are on Yahoo Groups ==
== Freegle's Legitimate Interest Assessment ==
 
The Information Commissioner's Office suggests that anyone using legitimate interest as a basis for processing should carry out a Legitimate Interest Assessment (LIA) - a light-touch risk assessment based on the specific context. It helps ensure processing is lawful, and helps Freegle demonstrate compliance with its accountability obligations under Articles 5(2) and 24. Here is ours.
 
=== Identifying the legitimate interest ===


There are two types of groups that use the Yahoo Groups system. <br>
* '''Why do we want to process the data?''' To let people who've joined Freegle pass on unwanted items to others nearby.
* '''Who benefits, and how?''' The Freegle member, by reusing their items, and the environment, as less waste goes to landfill or incineration.
* '''Are there wider public benefits?''' Yes - reuse helps the environment and can reduce the volume of landfill, which is costly for the public to process.
* '''How important are those benefits?''' The UK has a shortage of landfill, so Freegle's work is important in tackling the environmental impact of waste.
* '''What would happen if we couldn't go ahead?''' Many hundreds of tonnes of waste a year would be added to landfill.
* '''Would our use of the data be unethical or unlawful?''' No. Our community depends on members' trust, and our data protection policies ensure data is used responsibly and only for Freegle's stated aims.


'''1. Freegle groups that use Yahoo Groups system only'''  - These groups come under the policies of Yahoo in terms of compliance with Data Protection Laws, however we expect the Freegle volunteers who run these groups to comply with any policies and guidance for Data Protection published by the Freegle board. So for instance Yahoo would need to supply a way of users having access to their records (Right to access), however we would expect the group volunteers to deal with issues such as ensuring members were notified about a breach if Yahoo were first to tell group owners.
=== Is the processing necessary? ===


'''2. Freegle groups that are linked to the Freegle System''' - These groups will utilise the functions of both Yahoo and Freegle systems to comply with the regulations. This may cause some members a little confusion if they are registered with both systems. So volunteers will be asked to ensure that policy and guidance is followed in instances such as deleting data (The right to be forgotten) that members are reminded to delete from both systems. Where practical the Freegle system will take deletions made in Yahoo as a signal to remove the user data from the Freegle system, however this does not work the other way around.
* '''Does this processing actually further that interest?''' Yes - processing a very limited set of personal data (email address and location) lets people advertise unwanted items for reuse locally. Without it, the service would be far less useful to members and to the environment more generally.
* '''Is it a reasonable way to do it?''' Yes - this limited, focused processing is entirely reasonable and matches what members expect when they join.
* '''Is there a less intrusive way to achieve the same result?''' No - without this basic information, posts couldn't be replied to and the person offering an item wouldn't know where the item was.


== What about groups on the Norfolk Freegle system? ==
=== Is the processing balanced against individual rights? ===


The Norfolk system is a separate system from the main Freegle system. Therefore, it will have its own mechanisms to satisfy the Data Protection laws whilst coming under the general Freegle Data Protection policies. For more information on the Norfolk system you can click here [https://norfolkfreegle.org/Home/Terms]
* '''What's the nature of our relationship with the individual?''' All members join Freegle by choice, to give or seek items for reuse.
* '''Is any of the data particularly sensitive or private?''' No, we don't keep any sensitive data.
* '''Would people expect us to use their data this way?''' Yes - people join Freegle specifically for this service.
* '''Are we happy to explain it to them?''' Yes - mostly through open wiki pages like this one, detailing everything we do. We've also created a Data Protection Officer role, despite not being legally required to.
* '''Are some people likely to object or find it intrusive?''' Having reviewed our use of data, we can't foresee any reasonable objections.
* '''What's the possible impact on the individual?''' The most serious impact we can foresee is that a member who hasn't posted an item could still be identified by name and area, if their real name is in their email address and it's linked to their postal area.
* '''How big an impact might that have?''' A member might feel their privacy is affected, though most members make this information public anyway when they post an item, so it's a risk they're likely comfortable with.
* '''Do we process children's data?''' No - our policy is not to process children's data.
* '''Are any individuals vulnerable in any other way?''' No, Freegle doesn't make individuals any more vulnerable than normal internet use.
* '''Can we adopt safeguards to minimise the impact?''' As this is already the minimum data we keep, there are no further safeguards beyond our internal security measures.
* '''Can we offer an opt-out?''' Not from the standard processing while someone remains a member, but members can control what mailing lists and visibility settings they opt into, and there's no barrier to leaving the service.


== What about users of TrashNothing? ==
== What about TrashNothing users? ==


Trashnothing is a system that fronts Freegle and other systems such as Freecycle. If you have a TrashNothing account then the TrashNothing system keeps your membership details (email address & Postcode) and any Freegle group in connects you with also has this data. Trashnothing has its own Data Protection mechanisms, for more information see here [https://trashnothing.com/privacy].
[[TrashNothing]] is a system that fronts Freegle. If you have a TrashNothing account, TrashNothing keeps your membership details (email address and postcode), and any Freegle community it connects you to also holds this data. TrashNothing has its own data protection mechanisms - see [https://trashnothing.com/privacy their privacy policy].


== Useful links ==


* [[Data Protection Policy]] - policies for handling personal data
* [[Data Protection Guidelines]] - guidelines for volunteers
* [[Data Protection Compliance - Volunteer Task list]] - ongoing and completed tasks
* [[Spam]] - explaining why Freegle isn't spamming members
* [https://discourse.ilovefreegle.org/t/msc-students/7806/37 Discourse conversation about how we treat data] (30 August 2024)
* [[Basic Information]]
* [[Admin]]
* [https://discourse.ilovefreegle.org/t/brexit-and-data-protection-gdpr/2570 Message from the DPO on leaving the EU on 31 December 2020]


== Useful Links ==
Related legislation: the Online Safety Act - see Ofcom's [https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/roadmap-to-regulation/ roadmap to regulation] for the implementation timetable.
*[[Data Protection Policy]] - Policies for dealing with Personal Data
*[[Data Protection Guidelines]] - Guidelines for Volunteers
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks
*[[Spam]] - further explanation to counter accusations that we spam!
*[[Basic Information]]
*[[Admin]]


[[category: Admin]] [[category: Freegle Direct]] [[category: Data Protection]]
[[Category:Members, Discourse & App]]

Latest revision as of 12:00, 17 July 2026

This page explains what personal data Freegle keeps, why, and how it's processed, protected and deleted. It aims to be a straightforward explanation for volunteers and members. Links to other relevant pages, including our formal Policy, are at the bottom.

Where does Freegle keep data?

There are three areas to consider when thinking about where the Freegle organisation keeps personal data:

Area Description Personal data types held
1. The Freegle system Most of Freegle's data is kept in the system we call Freegle Direct - see [1]. This is where all communities are held and posts are shown. Freegle Direct also lets members log in using Google, Facebook or Apple credentials, authenticated by those services; the data those companies keep, and their compliance with data protection law, is up to them. Membership details (email and postcode)
Address book (postcode and user-supplied directions text)
2. National volunteers National volunteers, who run things for Freegle that aren't specific to one community - such as finance, media and IT development - keep limited personal data about their own areas of work. A survey of these volunteers found this is mainly email addresses and occasionally postal addresses, usually kept in local or group email accounts and in Google Docs with restricted access. Email contacts (email address)
Board member and shareholder postal details
3. Local community volunteers Local volunteers tend to hold only the personal data of their own members, such as email addresses, for dealing with queries. Membership details (email addresses)

What personal data does Freegle keep on its system?

Freegle keeps very little personal data, and nothing that counts as sensitive in legal terms - nothing like health or financial data.

Function Personal data recorded
Membership detail Email address, user name, postcode
Address book Postcode (a member can enter one different to the one on their membership); directions text, which will often include the member's address and other detail to help others find them

This information may not directly identify someone on its own, but it may do if their real name appears in their email address and is combined with their postcode.

How does Freegle process this data?

Function Processing by Freegle Direct (summary)
Membership functions Maintaining settings and communities linked to a member; matching logins from other systems (Google, Facebook, Apple) to the member's Freegle membership
Emailing members Sending emails in line with member preferences: community posts, automatic prompts, local moderator admin messages and national campaigns
Collated member information Creating a summary of a member's activity so other members can see it

How does Freegle comply with data protection law?

Freegle relies on trust to keep working. It takes its data protection responsibilities seriously, not just to comply with the law but so it doesn't use data in a way members wouldn't expect. We don't share data with other organisations (other than to run communities with TrashNothing) and we never sell it. Should a community wish to move its membership away from Freegle to another organisation, we will work with the volunteers who own that community. Freegle's advice to community owners is to ensure all members get the chance to opt in to the new organisation and its data protection policies; limited membership data will be made available to help with any such move, in line with the Disaffiliation Procedure.

Freegle fully complies with current UK law in this area, even though the Information Commissioner's Office doesn't require us to register the organisation.

Freegle reviewed its practices ahead of the General Data Protection Regulation (GDPR) [2], which took effect on 25 April 2018. The UK government transferred GDPR into UK law, so it has continued to apply since Brexit.

Key elements of GDPR and what Freegle does

GDPR area What this means What Freegle does
Legal basis for processing GDPR requires organisations to have a legal basis for processing data. There are six possible bases: consent, contract, legal obligation, vital interest, public task, or legitimate interest. Freegle uses legitimate interest as its legal basis for processing.
Legitimate interest This legal basis balances members' rights with the benefits Freegle brings to society and the environment. Freegle keeps only very limited personal data, used solely to facilitate reuse between members. Members can see all the data we keep and can remove themselves and their data from the system without hindrance.
Right to access & data portability You can ask an organisation to confirm whether it's processing your personal data, and get a copy of it in a standard electronic format so you can transfer it elsewhere. Members can see and download everything Freegle holds about them, in a machine-readable format, from Download your data (in Settings, or ilovefreegle.org/mydata).
Right to be forgotten You have the right to have your personal data erased on request, or once it's no longer relevant to the purpose it was collected for. Members can erase the personal data held in their Address Book, and can delete their membership login entirely via Settings, which removes their account (see Trouble unsubscribing). Policy and guidance ensure we keep only the minimum data needed, for only as long as it's needed.
Privacy by design Systems holding personal data must be designed to keep only the minimum data needed (data minimisation), and to limit access to those who need it. Freegle Direct has access controls in place and keeps as little personal data as possible to deliver its services.
Breach notification Under GDPR, notification is mandatory where a data breach is likely to "result in a risk for the rights and freedoms of individuals", within 72 hours of first becoming aware of it. Organisations must also notify affected people "without undue delay". If Freegle became aware of a breach (a hack), we would let members know by email and notify the UK Data Protection Authority. We don't keep anything sensitive, so the risk to anyone's rights or freedoms is low.
Penalties An organisation that breaches GDPR can be fined up to 4% of its annual global turnover. This is aimed at large corporations, but Freegle takes it just as seriously - without members' trust, Freegle couldn't function.
Data Protection Officer GDPR only makes a Data Protection Officer mandatory for organisations whose core activity involves large-scale, regular and systematic monitoring of people, or processing special categories of data. Although the law doesn't require it, Freegle has a volunteer Data Protection Officer role. Contact DPO@ilovefreegle.org.

Freegle's Legitimate Interest Assessment

The Information Commissioner's Office suggests that anyone using legitimate interest as a basis for processing should carry out a Legitimate Interest Assessment (LIA) - a light-touch risk assessment based on the specific context. It helps ensure processing is lawful, and helps Freegle demonstrate compliance with its accountability obligations under Articles 5(2) and 24. Here is ours.

Identifying the legitimate interest

  • Why do we want to process the data? To let people who've joined Freegle pass on unwanted items to others nearby.
  • Who benefits, and how? The Freegle member, by reusing their items, and the environment, as less waste goes to landfill or incineration.
  • Are there wider public benefits? Yes - reuse helps the environment and can reduce the volume of landfill, which is costly for the public to process.
  • How important are those benefits? The UK has a shortage of landfill, so Freegle's work is important in tackling the environmental impact of waste.
  • What would happen if we couldn't go ahead? Many hundreds of tonnes of waste a year would be added to landfill.
  • Would our use of the data be unethical or unlawful? No. Our community depends on members' trust, and our data protection policies ensure data is used responsibly and only for Freegle's stated aims.

Is the processing necessary?

  • Does this processing actually further that interest? Yes - processing a very limited set of personal data (email address and location) lets people advertise unwanted items for reuse locally. Without it, the service would be far less useful to members and to the environment more generally.
  • Is it a reasonable way to do it? Yes - this limited, focused processing is entirely reasonable and matches what members expect when they join.
  • Is there a less intrusive way to achieve the same result? No - without this basic information, posts couldn't be replied to and the person offering an item wouldn't know where the item was.

Is the processing balanced against individual rights?

  • What's the nature of our relationship with the individual? All members join Freegle by choice, to give or seek items for reuse.
  • Is any of the data particularly sensitive or private? No, we don't keep any sensitive data.
  • Would people expect us to use their data this way? Yes - people join Freegle specifically for this service.
  • Are we happy to explain it to them? Yes - mostly through open wiki pages like this one, detailing everything we do. We've also created a Data Protection Officer role, despite not being legally required to.
  • Are some people likely to object or find it intrusive? Having reviewed our use of data, we can't foresee any reasonable objections.
  • What's the possible impact on the individual? The most serious impact we can foresee is that a member who hasn't posted an item could still be identified by name and area, if their real name is in their email address and it's linked to their postal area.
  • How big an impact might that have? A member might feel their privacy is affected, though most members make this information public anyway when they post an item, so it's a risk they're likely comfortable with.
  • Do we process children's data? No - our policy is not to process children's data.
  • Are any individuals vulnerable in any other way? No, Freegle doesn't make individuals any more vulnerable than normal internet use.
  • Can we adopt safeguards to minimise the impact? As this is already the minimum data we keep, there are no further safeguards beyond our internal security measures.
  • Can we offer an opt-out? Not from the standard processing while someone remains a member, but members can control what mailing lists and visibility settings they opt into, and there's no barrier to leaving the service.

What about TrashNothing users?

TrashNothing is a system that fronts Freegle. If you have a TrashNothing account, TrashNothing keeps your membership details (email address and postcode), and any Freegle community it connects you to also holds this data. TrashNothing has its own data protection mechanisms - see their privacy policy.

Useful links

Related legislation: the Online Safety Act - see Ofcom's roadmap to regulation for the implementation timetable.