Data Protection Guidelines: Difference between revisions
No edit summary |
Wiki revamp: restructure & modernise |
||
| Line 1: | Line 1: | ||
== Guidelines for | == Guidelines for volunteer moderators == | ||
This guidance is aligned to the | This guidance is aligned to the sections of the Freegle [[Data Protection Policy]]. | ||
'''Definition of Personal Data''' - | '''Definition of Personal Data''' - Anything that can identify a living person. In your role as a moderator, this will typically be things like a member's email address, postal address, and possibly other things they write in messages. | ||
'''Corresponding with | '''Corresponding with members''' - We advise that you correspond with members using the chat function on the Freegle system where possible. If you do keep a copy of correspondence in your own email store, please keep Freegle messages in a separate folder. We advise using an email client that lets you search for users, to help with data requests, and that lets you delete data older than the Freegle retention policy limit. See [[Data Protection Policy]]. | ||
'''Obtaining | '''Obtaining consent''' - You're not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, good practice is not to use it outside the Freegle context it was sent for. | ||
'''Allowing | '''Allowing access to data''' - All personal information you hold in your role for Freegle could be in scope of a Subject Access Request (SAR). This is where anyone can ask for a copy of all the information Freegle - including its moderators - holds about them. These requests come through the Data Protection Officer, who checks they're reasonable and gives you search criteria to use to find the data. For instance, we may ask you to send us all information you have relating to fred.bloggs@hotmail.com within a particular scope or topic cited in the SAR. This includes any correspondence about them, even if it wasn't addressed to them. Volunteers may feel their commentary or notes about a member should stay private if it wasn't correspondence shared with the member, but by law this generally isn't the case, unless a legal exemption applies (the Data Protection Officer will clarify at the time of the request) - for example, if it relates to a criminal investigation. Exemptions are set out here: [https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/ ICO guide to exemptions]. | ||
'''Deleting | '''Deleting data - the right to be forgotten''' - If someone asks Freegle to delete their data, we're legally required to do so. Typically this means deleting their user information from a group. Because of the service we offer, we'll do this in line with our published policy, so their posts on the group may remain visible for a while until they expire under our data retention policy. If we receive a request under this law asking for all data to be deleted, moderators should try to delete information in line with the search criteria the Data Protection Officer sends them - for example, "please delete all information you have on fred.bloggs@hotmail.com". | ||
'''Minimising | '''Minimising data retained''' - However tempting it is to keep everything you've ever had relating to Freegle, we recommend only retaining information that's essential to fulfilling your role. | ||
'''Storing | '''Storing data securely''' - Keep access to all personal data you hold limited to those with a legitimate need to see it. If you have emails in a mailbox or file store (for example, Google Docs), make sure access is password protected. Where the mailbox or file store is shared by a group, make sure only those who should be able to see it have access, by periodically checking who has rights and changing passwords when moderators leave the group. | ||
== Guidelines for | == Guidelines for functional groups and teams (for example, Freegle Central, Freegle Development, GAT, Mentors) == | ||
The guidance above for volunteers covers most of what national volunteers do too. Be aware that any data you retain is in scope of a Subject Access Request. Correspondence around disputes would be available to a member if they submit a Subject Access Request covering that scope of information. So only write down things you'd be comfortable with the subject of the correspondence reading. | |||
== Guidelines for the Data Protection Officer == | == Guidelines for the Data Protection Officer == | ||
'''The Data Protection Officer | '''The Data Protection Officer role''' - Your role is to advise the Freegle Board on the extent of the organisation's compliance with data protection legislation. Neither you nor the role is the responsible party for compliance - you provide an objective review of operations and advise on how Freegle should change to maintain compliance. | ||
To do this you must periodically review the data | To do this, you must periodically review the data held by different parts of the Freegle organisation, and how it's stored and processed. Each time you do this, it's wise to record the outcome, to show any external body the process and the work done. | ||
'''Subject Access Request | '''Subject Access Request (SAR) processing''' - You're the gatekeeper for the process. You need to respond to requests in a timely manner, review any applicable exemptions with those who hold the data, then formally request all relevant parties to supply the data. You then return the data to the requester in a common format. You may also need to ensure any access request fee is collected, if Freegle imposes one on the process. | ||
'''Communications''' - It | It's essential to familiarise yourself with ICO guidance on Subject Access Requests, found in the [https://ico.org.uk/media/for-organisations/documents/2014223/subject-access-code-of-practice.pdf ICO Code of Practice]. | ||
* | |||
* Concerns or issues | '''Communications''' - It's your role to periodically update the Board and membership on: | ||
* Changes to the law that | * Work relating to Data Protection (for example, surveys, or changes to the Freegle system for data protection reasons) | ||
* Concerns or issues you've discovered (these must be formally raised with the Board) | |||
* Changes to the law that the Board and membership should know about | |||
== Useful Links == | == Useful Links == | ||
*[[Data Protection Policy]] - Policies for dealing with | * [[Data Protection Policy]] - Policies for dealing with personal data | ||
*[[Data Use & Protection]] - What | * [[Data Use & Protection]] - What personal data Freegle keeps and how it's used | ||
*[[Data Protection Guidelines]] - Guidelines for | * [[Data Protection Guidelines]] - Guidelines for volunteers | ||
*[[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks | * [[Data Protection Compliance - Volunteer Task list]] - Ongoing and completed tasks | ||
*[[Spam]] - | * [[Spam]] - Further explanation to counter accusations that we spam | ||
*[[Member Notes]] | * [[Member Notes]] | ||
*[[Basic Information]] | * [[Basic Information]] | ||
*[[Admin]] | * [[Admin]] | ||
[[ | [[Category:Councils, Partnerships & Data Protection]] | ||
Latest revision as of 12:00, 17 July 2026
Guidelines for volunteer moderators
This guidance is aligned to the sections of the Freegle Data Protection Policy.
Definition of Personal Data - Anything that can identify a living person. In your role as a moderator, this will typically be things like a member's email address, postal address, and possibly other things they write in messages.
Corresponding with members - We advise that you correspond with members using the chat function on the Freegle system where possible. If you do keep a copy of correspondence in your own email store, please keep Freegle messages in a separate folder. We advise using an email client that lets you search for users, to help with data requests, and that lets you delete data older than the Freegle retention policy limit. See Data Protection Policy.
Obtaining consent - You're not expected to ask for consent to use emails people send you. However, if information is sent to you clearly only about Freegle, good practice is not to use it outside the Freegle context it was sent for.
Allowing access to data - All personal information you hold in your role for Freegle could be in scope of a Subject Access Request (SAR). This is where anyone can ask for a copy of all the information Freegle - including its moderators - holds about them. These requests come through the Data Protection Officer, who checks they're reasonable and gives you search criteria to use to find the data. For instance, we may ask you to send us all information you have relating to fred.bloggs@hotmail.com within a particular scope or topic cited in the SAR. This includes any correspondence about them, even if it wasn't addressed to them. Volunteers may feel their commentary or notes about a member should stay private if it wasn't correspondence shared with the member, but by law this generally isn't the case, unless a legal exemption applies (the Data Protection Officer will clarify at the time of the request) - for example, if it relates to a criminal investigation. Exemptions are set out here: ICO guide to exemptions.
Deleting data - the right to be forgotten - If someone asks Freegle to delete their data, we're legally required to do so. Typically this means deleting their user information from a group. Because of the service we offer, we'll do this in line with our published policy, so their posts on the group may remain visible for a while until they expire under our data retention policy. If we receive a request under this law asking for all data to be deleted, moderators should try to delete information in line with the search criteria the Data Protection Officer sends them - for example, "please delete all information you have on fred.bloggs@hotmail.com".
Minimising data retained - However tempting it is to keep everything you've ever had relating to Freegle, we recommend only retaining information that's essential to fulfilling your role.
Storing data securely - Keep access to all personal data you hold limited to those with a legitimate need to see it. If you have emails in a mailbox or file store (for example, Google Docs), make sure access is password protected. Where the mailbox or file store is shared by a group, make sure only those who should be able to see it have access, by periodically checking who has rights and changing passwords when moderators leave the group.
Guidelines for functional groups and teams (for example, Freegle Central, Freegle Development, GAT, Mentors)
The guidance above for volunteers covers most of what national volunteers do too. Be aware that any data you retain is in scope of a Subject Access Request. Correspondence around disputes would be available to a member if they submit a Subject Access Request covering that scope of information. So only write down things you'd be comfortable with the subject of the correspondence reading.
Guidelines for the Data Protection Officer
The Data Protection Officer role - Your role is to advise the Freegle Board on the extent of the organisation's compliance with data protection legislation. Neither you nor the role is the responsible party for compliance - you provide an objective review of operations and advise on how Freegle should change to maintain compliance.
To do this, you must periodically review the data held by different parts of the Freegle organisation, and how it's stored and processed. Each time you do this, it's wise to record the outcome, to show any external body the process and the work done.
Subject Access Request (SAR) processing - You're the gatekeeper for the process. You need to respond to requests in a timely manner, review any applicable exemptions with those who hold the data, then formally request all relevant parties to supply the data. You then return the data to the requester in a common format. You may also need to ensure any access request fee is collected, if Freegle imposes one on the process.
It's essential to familiarise yourself with ICO guidance on Subject Access Requests, found in the ICO Code of Practice.
Communications - It's your role to periodically update the Board and membership on:
- Work relating to Data Protection (for example, surveys, or changes to the Freegle system for data protection reasons)
- Concerns or issues you've discovered (these must be formally raised with the Board)
- Changes to the law that the Board and membership should know about
Useful Links
- Data Protection Policy - Policies for dealing with personal data
- Data Use & Protection - What personal data Freegle keeps and how it's used
- Data Protection Guidelines - Guidelines for volunteers
- Data Protection Compliance - Volunteer Task list - Ongoing and completed tasks
- Spam - Further explanation to counter accusations that we spam
- Member Notes
- Basic Information
- Admin
