Data Protection Policy: Difference between revisions
Jc4freegle (talk | contribs) |
Wiki revamp: restructure & modernise |
||
| (9 intermediate revisions by 3 users not shown) | |||
| Line 1: | Line 1: | ||
== Personal Data Policy == | == Personal Data Protection Policy == | ||
'''Policy aims :''' | '''Policy aims:''' | ||
* To maintain the trust of our membership by keeping data safe | * To maintain the trust of our membership by keeping data safe. | ||
* To comply with all UK laws on Data Protection | * To comply with all UK laws on Data Protection. | ||
* To be open about all | * To be open about all the data we hold associated with members, so they can check it's accurate. | ||
'''Definition of Personal Data''' - Any data that, separately or in combination with other elements, may identify a living individual. | |||
''' | '''Scope of Personal Data held''' - Freegle aims to minimise the amount of data it keeps to only what's necessary to deliver its services to members. | ||
''' | '''Use of Data''' - Freegle will only use members' personal data to help further the stated [[Freegle Aims|aims]] of Freegle in the communities it serves. | ||
''' | '''Allowing members access to data''' - Freegle allows members to see all the personal data (and other associated data, where possible) held on the Freegle system, directly from the system. In addition, members may request other data Freegle holds, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org | ||
''' | '''Age restrictions''' - We do not maintain children's personal data, as we would then need some way to ensure guardians had consented to this. "Children" in this context means under 13 years old. | ||
'''Data | '''Data retention''' - Freegle keeps data for the period of membership, and for up to 6 months after membership has ceased, as part of our anti-spam measures. During these 6 months, these details are not visible. Members who want their data removed immediately can arrange this via the Data Protection Officer at DPO@ilovefreegle.org | ||
Freegle volunteers who correspond with others about Freegle and its activities are advised to do so via the Freegle system where possible. Correspondence outside that system is also subject to the same 6-month retention period, unless the volunteer obtains consent from the correspondent to keep the information for an agreed longer period. Volunteers who leave the Freegle platform are subject to the same consent expectations. | |||
'''Storing | '''Storing data securely''' - Freegle uses industry-standard techniques (for example, access restriction, encryption, and taking backups) to keep the data we hold safe from unauthorised access or loss. We also advise all volunteers who store personal information to keep it secure, with access limited to known individuals. | ||
'''Notification of data breaches''' - Freegle will notify the relevant authorities of any data breach it detects. Unless there's an important reason not to, such as aiding law enforcement, Freegle will inform everyone affected by a breach, and the membership in general, of the details. | |||
'''Data Protection Officer''' - Because of the nature of Freegle, we're not legally required to have a Data Protection Officer (DPO). However, we have a volunteer who takes on this role, and who can be reached by email at DPO@ilovefreegle.org | |||
== Useful Links == | |||
* [[Data Use & Protection]] - Detail of Freegle's use and protection of personal data | |||
* [[Data Protection Guidelines]] - Guidelines for volunteers | |||
* [[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks | |||
* [[Spam]] - Further explanation to counter accusations that we spam | |||
* [[Basic Information]] | |||
* [[Admin]] | |||
[[Category:Councils, Partnerships & Data Protection]] | |||
Latest revision as of 12:00, 17 July 2026
Personal Data Protection Policy
Policy aims:
- To maintain the trust of our membership by keeping data safe.
- To comply with all UK laws on Data Protection.
- To be open about all the data we hold associated with members, so they can check it's accurate.
Definition of Personal Data - Any data that, separately or in combination with other elements, may identify a living individual.
Scope of Personal Data held - Freegle aims to minimise the amount of data it keeps to only what's necessary to deliver its services to members.
Use of Data - Freegle will only use members' personal data to help further the stated aims of Freegle in the communities it serves.
Allowing members access to data - Freegle allows members to see all the personal data (and other associated data, where possible) held on the Freegle system, directly from the system. In addition, members may request other data Freegle holds, such as correspondence with volunteers, via a Subject Access Request made to DPO@ilovefreegle.org
Age restrictions - We do not maintain children's personal data, as we would then need some way to ensure guardians had consented to this. "Children" in this context means under 13 years old.
Data retention - Freegle keeps data for the period of membership, and for up to 6 months after membership has ceased, as part of our anti-spam measures. During these 6 months, these details are not visible. Members who want their data removed immediately can arrange this via the Data Protection Officer at DPO@ilovefreegle.org Freegle volunteers who correspond with others about Freegle and its activities are advised to do so via the Freegle system where possible. Correspondence outside that system is also subject to the same 6-month retention period, unless the volunteer obtains consent from the correspondent to keep the information for an agreed longer period. Volunteers who leave the Freegle platform are subject to the same consent expectations.
Storing data securely - Freegle uses industry-standard techniques (for example, access restriction, encryption, and taking backups) to keep the data we hold safe from unauthorised access or loss. We also advise all volunteers who store personal information to keep it secure, with access limited to known individuals.
Notification of data breaches - Freegle will notify the relevant authorities of any data breach it detects. Unless there's an important reason not to, such as aiding law enforcement, Freegle will inform everyone affected by a breach, and the membership in general, of the details.
Data Protection Officer - Because of the nature of Freegle, we're not legally required to have a Data Protection Officer (DPO). However, we have a volunteer who takes on this role, and who can be reached by email at DPO@ilovefreegle.org
Useful Links
- Data Use & Protection - Detail of Freegle's use and protection of personal data
- Data Protection Guidelines - Guidelines for volunteers
- Data Protection Compliance - Volunteer Task list - Ongoing and completed tasks
- Spam - Further explanation to counter accusations that we spam
- Basic Information
- Admin
