Data Use & Protection: Difference between revisions
Jc4freegle (talk | contribs) |
Wiki revamp: restructure & modernise |
||
| (30 intermediate revisions by 5 users not shown) | |||
| Line 1: | Line 1: | ||
This page explains what personal data Freegle keeps, why, and how it's processed, protected and deleted. It aims to be a straightforward explanation for volunteers and members. Links to other relevant pages, including our formal Policy, are at the bottom. | |||
This page | |||
== Where does Freegle keep data? == | == Where does Freegle keep data? == | ||
There are three areas | There are three areas to consider when thinking about where the Freegle organisation keeps personal data: | ||
{| class="wikitable" | {| class="wikitable" | ||
! scope="col | ! scope="col" | Area | ||
! scope="col | ! scope="col" | Description | ||
! scope="col | ! scope="col" | Personal data types held | ||
|- | |- | ||
| 1. The Freegle | | 1. The Freegle system || Most of Freegle's data is kept in the system we call Freegle Direct - see [http://ilovefreegle.org]. This is where all communities are held and posts are shown. Freegle Direct also lets members log in using Google, Facebook or Apple credentials, authenticated by those services; the data those companies keep, and their compliance with data protection law, is up to them. || Membership details (email and postcode)<br>Address book (postcode and user-supplied directions text) | ||
|- | |- | ||
| 2. National volunteers || | | 2. National volunteers || National volunteers, who run things for Freegle that aren't specific to one community - such as finance, media and IT development - keep limited personal data about their own areas of work. A survey of these volunteers found this is mainly email addresses and occasionally postal addresses, usually kept in local or group email accounts and in Google Docs with restricted access. || Email contacts (email address)<br>Board member and shareholder postal details | ||
|- | |- | ||
| 3. Local | | 3. Local community volunteers || Local volunteers tend to hold only the personal data of their own members, such as email addresses, for dealing with queries. || Membership details (email addresses) | ||
|} | |} | ||
== What | == What personal data does Freegle keep on its system? == | ||
Freegle keeps little personal data, and nothing that | Freegle keeps very little personal data, and nothing that counts as sensitive in legal terms - nothing like health or financial data. | ||
{| class="wikitable" | {| class="wikitable" | ||
! Function | ! Function | ||
! Personal data recorded | ! Personal data recorded | ||
|- | |- | ||
| Address | | Membership detail || Email address, user name, postcode | ||
|- | |||
| Address book || Postcode (a member can enter one different to the one on their membership); directions text, which will often include the member's address and other detail to help others find them | |||
|} | |} | ||
This information may not directly identify someone on its own, but it may do if their real name appears in their email address and is combined with their postcode. | |||
== How does Freegle | == How does Freegle process this data? == | ||
{| class="wikitable" | {| class="wikitable" | ||
! Function | ! Function | ||
! Processing by Freegle | ! Processing by Freegle Direct (summary) | ||
|- | |- | ||
| Membership | | Membership functions || Maintaining settings and communities linked to a member; matching logins from other systems (Google, Facebook, Apple) to the member's Freegle membership | ||
|- | |- | ||
| Emailing | | Emailing members || Sending emails in line with member preferences: community posts, automatic prompts, local moderator admin messages and national campaigns | ||
|- | |- | ||
| Collated member information || | | Collated member information || Creating a summary of a member's activity so other members can see it | ||
|} | |} | ||
== How does Freegle | == How does Freegle comply with data protection law? == | ||
Freegle relies on trust to | Freegle relies on trust to keep working. It takes its data protection responsibilities seriously, not just to comply with the law but so it doesn't use data in a way members wouldn't expect. We don't share data with other organisations (other than to run communities with TrashNothing) and we never sell it. Should a community wish to move its membership away from Freegle to another organisation, we will work with the volunteers who own that community. Freegle's advice to community owners is to ensure all members get the chance to opt in to the new organisation and its data protection policies; limited membership data will be made available to help with any such move, in line with the [[Disaffiliation Procedure]]. | ||
Freegle fully complies with current UK law in this area, even though the Information Commissioner's Office doesn't require us to register the organisation. | |||
Freegle reviewed its practices ahead of the General Data Protection Regulation (GDPR) [https://gdpr-info.eu/], which took effect on 25 April 2018. The UK government transferred GDPR into UK law, so it has continued to apply since Brexit. | |||
== Key | == Key elements of GDPR and what Freegle does == | ||
{| class="wikitable" | {| class="wikitable" | ||
! GDPR | ! GDPR area | ||
! What this means | ! What this means | ||
! What Freegle | ! What Freegle does | ||
|- | |- | ||
| | | Legal basis for processing || GDPR requires organisations to have a legal basis for processing data. There are six possible bases: consent, contract, legal obligation, vital interest, public task, or legitimate interest. || Freegle uses legitimate interest as its legal basis for processing. | ||
|- | |- | ||
| | | Legitimate interest || This legal basis balances members' rights with the benefits Freegle brings to society and the environment. || Freegle keeps only very limited personal data, used solely to facilitate reuse between members. Members can see all the data we keep and can remove themselves and their data from the system without hindrance. | ||
|- | |- | ||
| Right to | | Right to access & data portability || You can ask an organisation to confirm whether it's processing your personal data, and get a copy of it in a standard electronic format so you can transfer it elsewhere. || Members can see and download everything Freegle holds about them, in a machine-readable format, from '''Download your data''' (in Settings, or [https://www.ilovefreegle.org/mydata ilovefreegle.org/mydata]). | ||
|- | |- | ||
| | | Right to be forgotten || You have the right to have your personal data erased on request, or once it's no longer relevant to the purpose it was collected for. || Members can erase the personal data held in their Address Book, and can delete their membership login entirely via Settings, which removes their account (see [[Trouble unsubscribing]]). Policy and guidance ensure we keep only the minimum data needed, for only as long as it's needed. | ||
|- | |- | ||
| | | Privacy by design || Systems holding personal data must be designed to keep only the minimum data needed (data minimisation), and to limit access to those who need it. || Freegle Direct has access controls in place and keeps as little personal data as possible to deliver its services. | ||
|- | |- | ||
| | | Breach notification || Under GDPR, notification is mandatory where a data breach is likely to "result in a risk for the rights and freedoms of individuals", within 72 hours of first becoming aware of it. Organisations must also notify affected people "without undue delay". || If Freegle became aware of a breach (a hack), we would let members know by email and notify the UK Data Protection Authority. We don't keep anything sensitive, so the risk to anyone's rights or freedoms is low. | ||
|- | |- | ||
| Data Protection Officer || | | Penalties || An organisation that breaches GDPR can be fined up to 4% of its annual global turnover. || This is aimed at large corporations, but Freegle takes it just as seriously - without members' trust, Freegle couldn't function. | ||
|- | |||
| Data Protection Officer || GDPR only makes a Data Protection Officer mandatory for organisations whose core activity involves large-scale, regular and systematic monitoring of people, or processing special categories of data. || Although the law doesn't require it, Freegle has a volunteer Data Protection Officer role. Contact DPO@ilovefreegle.org. | |||
|} | |} | ||
== Freegle's Legitimate Interest Assessment == | |||
The Information Commissioner's Office suggests that anyone using legitimate interest as a basis for processing should carry out a Legitimate Interest Assessment (LIA) - a light-touch risk assessment based on the specific context. It helps ensure processing is lawful, and helps Freegle demonstrate compliance with its accountability obligations under Articles 5(2) and 24. Here is ours. | |||
== | === Identifying the legitimate interest === | ||
* '''Why do we want to process the data?''' To let people who've joined Freegle pass on unwanted items to others nearby. | |||
* '''Who benefits, and how?''' The Freegle member, by reusing their items, and the environment, as less waste goes to landfill or incineration. | |||
* '''Are there wider public benefits?''' Yes - reuse helps the environment and can reduce the volume of landfill, which is costly for the public to process. | |||
* '''How important are those benefits?''' The UK has a shortage of landfill, so Freegle's work is important in tackling the environmental impact of waste. | |||
* '''What would happen if we couldn't go ahead?''' Many hundreds of tonnes of waste a year would be added to landfill. | |||
* '''Would our use of the data be unethical or unlawful?''' No. Our community depends on members' trust, and our data protection policies ensure data is used responsibly and only for Freegle's stated aims. | |||
=== Is the processing necessary? === | |||
''' | * '''Does this processing actually further that interest?''' Yes - processing a very limited set of personal data (email address and location) lets people advertise unwanted items for reuse locally. Without it, the service would be far less useful to members and to the environment more generally. | ||
* '''Is it a reasonable way to do it?''' Yes - this limited, focused processing is entirely reasonable and matches what members expect when they join. | |||
* '''Is there a less intrusive way to achieve the same result?''' No - without this basic information, posts couldn't be replied to and the person offering an item wouldn't know where the item was. | |||
== | === Is the processing balanced against individual rights? === | ||
* '''What's the nature of our relationship with the individual?''' All members join Freegle by choice, to give or seek items for reuse. | |||
* '''Is any of the data particularly sensitive or private?''' No, we don't keep any sensitive data. | |||
* '''Would people expect us to use their data this way?''' Yes - people join Freegle specifically for this service. | |||
* '''Are we happy to explain it to them?''' Yes - mostly through open wiki pages like this one, detailing everything we do. We've also created a Data Protection Officer role, despite not being legally required to. | |||
* '''Are some people likely to object or find it intrusive?''' Having reviewed our use of data, we can't foresee any reasonable objections. | |||
* '''What's the possible impact on the individual?''' The most serious impact we can foresee is that a member who hasn't posted an item could still be identified by name and area, if their real name is in their email address and it's linked to their postal area. | |||
* '''How big an impact might that have?''' A member might feel their privacy is affected, though most members make this information public anyway when they post an item, so it's a risk they're likely comfortable with. | |||
* '''Do we process children's data?''' No - our policy is not to process children's data. | |||
* '''Are any individuals vulnerable in any other way?''' No, Freegle doesn't make individuals any more vulnerable than normal internet use. | |||
* '''Can we adopt safeguards to minimise the impact?''' As this is already the minimum data we keep, there are no further safeguards beyond our internal security measures. | |||
* '''Can we offer an opt-out?''' Not from the standard processing while someone remains a member, but members can control what mailing lists and visibility settings they opt into, and there's no barrier to leaving the service. | |||
== What about users | == What about TrashNothing users? == | ||
[[TrashNothing]] is a system that fronts Freegle. If you have a TrashNothing account, TrashNothing keeps your membership details (email address and postcode), and any Freegle community it connects you to also holds this data. TrashNothing has its own data protection mechanisms - see [https://trashnothing.com/privacy their privacy policy]. | |||
== Useful links == | |||
* [[Data Protection Policy]] - policies for handling personal data | |||
* [[Data Protection Guidelines]] - guidelines for volunteers | |||
* [[Data Protection Compliance - Volunteer Task list]] - ongoing and completed tasks | |||
* [[Spam]] - explaining why Freegle isn't spamming members | |||
* [https://discourse.ilovefreegle.org/t/msc-students/7806/37 Discourse conversation about how we treat data] (30 August 2024) | |||
* [[Basic Information]] | |||
* [[Admin]] | |||
* [https://discourse.ilovefreegle.org/t/brexit-and-data-protection-gdpr/2570 Message from the DPO on leaving the EU on 31 December 2020] | |||
Related legislation: the Online Safety Act - see Ofcom's [https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/roadmap-to-regulation/ roadmap to regulation] for the implementation timetable. | |||
[[ | [[Category:Members, Discourse & App]] | ||
Latest revision as of 12:00, 17 July 2026
This page explains what personal data Freegle keeps, why, and how it's processed, protected and deleted. It aims to be a straightforward explanation for volunteers and members. Links to other relevant pages, including our formal Policy, are at the bottom.
Where does Freegle keep data?
There are three areas to consider when thinking about where the Freegle organisation keeps personal data:
| Area | Description | Personal data types held |
|---|---|---|
| 1. The Freegle system | Most of Freegle's data is kept in the system we call Freegle Direct - see [1]. This is where all communities are held and posts are shown. Freegle Direct also lets members log in using Google, Facebook or Apple credentials, authenticated by those services; the data those companies keep, and their compliance with data protection law, is up to them. | Membership details (email and postcode) Address book (postcode and user-supplied directions text) |
| 2. National volunteers | National volunteers, who run things for Freegle that aren't specific to one community - such as finance, media and IT development - keep limited personal data about their own areas of work. A survey of these volunteers found this is mainly email addresses and occasionally postal addresses, usually kept in local or group email accounts and in Google Docs with restricted access. | Email contacts (email address) Board member and shareholder postal details |
| 3. Local community volunteers | Local volunteers tend to hold only the personal data of their own members, such as email addresses, for dealing with queries. | Membership details (email addresses) |
What personal data does Freegle keep on its system?
Freegle keeps very little personal data, and nothing that counts as sensitive in legal terms - nothing like health or financial data.
| Function | Personal data recorded |
|---|---|
| Membership detail | Email address, user name, postcode |
| Address book | Postcode (a member can enter one different to the one on their membership); directions text, which will often include the member's address and other detail to help others find them |
This information may not directly identify someone on its own, but it may do if their real name appears in their email address and is combined with their postcode.
How does Freegle process this data?
| Function | Processing by Freegle Direct (summary) |
|---|---|
| Membership functions | Maintaining settings and communities linked to a member; matching logins from other systems (Google, Facebook, Apple) to the member's Freegle membership |
| Emailing members | Sending emails in line with member preferences: community posts, automatic prompts, local moderator admin messages and national campaigns |
| Collated member information | Creating a summary of a member's activity so other members can see it |
How does Freegle comply with data protection law?
Freegle relies on trust to keep working. It takes its data protection responsibilities seriously, not just to comply with the law but so it doesn't use data in a way members wouldn't expect. We don't share data with other organisations (other than to run communities with TrashNothing) and we never sell it. Should a community wish to move its membership away from Freegle to another organisation, we will work with the volunteers who own that community. Freegle's advice to community owners is to ensure all members get the chance to opt in to the new organisation and its data protection policies; limited membership data will be made available to help with any such move, in line with the Disaffiliation Procedure.
Freegle fully complies with current UK law in this area, even though the Information Commissioner's Office doesn't require us to register the organisation.
Freegle reviewed its practices ahead of the General Data Protection Regulation (GDPR) [2], which took effect on 25 April 2018. The UK government transferred GDPR into UK law, so it has continued to apply since Brexit.
Key elements of GDPR and what Freegle does
| GDPR area | What this means | What Freegle does |
|---|---|---|
| Legal basis for processing | GDPR requires organisations to have a legal basis for processing data. There are six possible bases: consent, contract, legal obligation, vital interest, public task, or legitimate interest. | Freegle uses legitimate interest as its legal basis for processing. |
| Legitimate interest | This legal basis balances members' rights with the benefits Freegle brings to society and the environment. | Freegle keeps only very limited personal data, used solely to facilitate reuse between members. Members can see all the data we keep and can remove themselves and their data from the system without hindrance. |
| Right to access & data portability | You can ask an organisation to confirm whether it's processing your personal data, and get a copy of it in a standard electronic format so you can transfer it elsewhere. | Members can see and download everything Freegle holds about them, in a machine-readable format, from Download your data (in Settings, or ilovefreegle.org/mydata). |
| Right to be forgotten | You have the right to have your personal data erased on request, or once it's no longer relevant to the purpose it was collected for. | Members can erase the personal data held in their Address Book, and can delete their membership login entirely via Settings, which removes their account (see Trouble unsubscribing). Policy and guidance ensure we keep only the minimum data needed, for only as long as it's needed. |
| Privacy by design | Systems holding personal data must be designed to keep only the minimum data needed (data minimisation), and to limit access to those who need it. | Freegle Direct has access controls in place and keeps as little personal data as possible to deliver its services. |
| Breach notification | Under GDPR, notification is mandatory where a data breach is likely to "result in a risk for the rights and freedoms of individuals", within 72 hours of first becoming aware of it. Organisations must also notify affected people "without undue delay". | If Freegle became aware of a breach (a hack), we would let members know by email and notify the UK Data Protection Authority. We don't keep anything sensitive, so the risk to anyone's rights or freedoms is low. |
| Penalties | An organisation that breaches GDPR can be fined up to 4% of its annual global turnover. | This is aimed at large corporations, but Freegle takes it just as seriously - without members' trust, Freegle couldn't function. |
| Data Protection Officer | GDPR only makes a Data Protection Officer mandatory for organisations whose core activity involves large-scale, regular and systematic monitoring of people, or processing special categories of data. | Although the law doesn't require it, Freegle has a volunteer Data Protection Officer role. Contact DPO@ilovefreegle.org. |
Freegle's Legitimate Interest Assessment
The Information Commissioner's Office suggests that anyone using legitimate interest as a basis for processing should carry out a Legitimate Interest Assessment (LIA) - a light-touch risk assessment based on the specific context. It helps ensure processing is lawful, and helps Freegle demonstrate compliance with its accountability obligations under Articles 5(2) and 24. Here is ours.
Identifying the legitimate interest
- Why do we want to process the data? To let people who've joined Freegle pass on unwanted items to others nearby.
- Who benefits, and how? The Freegle member, by reusing their items, and the environment, as less waste goes to landfill or incineration.
- Are there wider public benefits? Yes - reuse helps the environment and can reduce the volume of landfill, which is costly for the public to process.
- How important are those benefits? The UK has a shortage of landfill, so Freegle's work is important in tackling the environmental impact of waste.
- What would happen if we couldn't go ahead? Many hundreds of tonnes of waste a year would be added to landfill.
- Would our use of the data be unethical or unlawful? No. Our community depends on members' trust, and our data protection policies ensure data is used responsibly and only for Freegle's stated aims.
Is the processing necessary?
- Does this processing actually further that interest? Yes - processing a very limited set of personal data (email address and location) lets people advertise unwanted items for reuse locally. Without it, the service would be far less useful to members and to the environment more generally.
- Is it a reasonable way to do it? Yes - this limited, focused processing is entirely reasonable and matches what members expect when they join.
- Is there a less intrusive way to achieve the same result? No - without this basic information, posts couldn't be replied to and the person offering an item wouldn't know where the item was.
Is the processing balanced against individual rights?
- What's the nature of our relationship with the individual? All members join Freegle by choice, to give or seek items for reuse.
- Is any of the data particularly sensitive or private? No, we don't keep any sensitive data.
- Would people expect us to use their data this way? Yes - people join Freegle specifically for this service.
- Are we happy to explain it to them? Yes - mostly through open wiki pages like this one, detailing everything we do. We've also created a Data Protection Officer role, despite not being legally required to.
- Are some people likely to object or find it intrusive? Having reviewed our use of data, we can't foresee any reasonable objections.
- What's the possible impact on the individual? The most serious impact we can foresee is that a member who hasn't posted an item could still be identified by name and area, if their real name is in their email address and it's linked to their postal area.
- How big an impact might that have? A member might feel their privacy is affected, though most members make this information public anyway when they post an item, so it's a risk they're likely comfortable with.
- Do we process children's data? No - our policy is not to process children's data.
- Are any individuals vulnerable in any other way? No, Freegle doesn't make individuals any more vulnerable than normal internet use.
- Can we adopt safeguards to minimise the impact? As this is already the minimum data we keep, there are no further safeguards beyond our internal security measures.
- Can we offer an opt-out? Not from the standard processing while someone remains a member, but members can control what mailing lists and visibility settings they opt into, and there's no barrier to leaving the service.
What about TrashNothing users?
TrashNothing is a system that fronts Freegle. If you have a TrashNothing account, TrashNothing keeps your membership details (email address and postcode), and any Freegle community it connects you to also holds this data. TrashNothing has its own data protection mechanisms - see their privacy policy.
Useful links
- Data Protection Policy - policies for handling personal data
- Data Protection Guidelines - guidelines for volunteers
- Data Protection Compliance - Volunteer Task list - ongoing and completed tasks
- Spam - explaining why Freegle isn't spamming members
- Discourse conversation about how we treat data (30 August 2024)
- Basic Information
- Admin
- Message from the DPO on leaving the EU on 31 December 2020
Related legislation: the Online Safety Act - see Ofcom's roadmap to regulation for the implementation timetable.
