Data Protection Policy
Epping Archers Data Protection Policy
Commitment and Legislation
Epping Archers is fully committed to compliance with the latest data protection legislation.
“Data Protection Legislation” means (i) unless and until the GDPR is no longer directly applicable in the UK, the General Data Protection Regulation ((EU) 2016/679) and any national implementing laws, regulations and secondary legislation, as amended or updated from time to time, in the UK and then (ii) any successor legislation to the GDPR or the Data Protection Act 1998.
Handling Personal Information
Epping Archers needs to collect and use certain types of information about its members. This personal information must be dealt with appropriately however it is collected, recorded and used; this principle applies whether on paper, on a computer or recorded by other means. There are safeguards to ensure this in the General Data Protection Regulations. (GDPR)
Epping Archers regards the lawful and correct handling of personal information as essential and therefore ensures that personal information is treated with sensitivity at all times. To this end Epping Archers fully adheres to the Principles of the Data Protection as detailed in the Regulations
These specify that personal data must be:
- Processed fairly and lawfully;
- Obtained for specified and lawful purposes;
- Be adequate, relevant and not excessive;
- Be accurate and kept up-to-date;
- Not be kept any longer than necessary;
- Be processed in accordance with the data subject’s (the individual’s) rights;
- Be kept secure; and
- Not be transferred outside the European Economic Area unless the recipient country ensures an adequate level of protection.
Epping Archers will through appropriate management:
- Fully observe the conditions regarding the fair collection and use of the information;
- Meet its legal obligations to specify the purpose for which the information is used;
- Collect and process only that information which is required in order to fulfil operational needs or the compliance of legal requirements;
- Ensure the quality of all information used;
- Apply checks to determine the length of time information is held;
- Ensure the rights of people about whom information is held can be fully exercised under the Regulations that includes the right to be informed that processing is being undertaken, the right of access to one’s personal information, the right to prevent processing in certain circumstances and the right to correct, rectify, block or erase information which is regarded as wrong information;
- Ensure that appropriate technical and organisational security measures are in place to safeguard such personal information;
- Ensure that no transfer of information is made abroad without suitable safeguards being in place;
- Treat people impartially and fairly irrespective of their age, religion, disability, gender, sexual orientation or ethnicity when dealing with requests for information; and
- Have in place clear procedures for responding to requests for information.
In addition to the above, Epping Archers will ensure that:
- There is a committee member with specific responsibility for Data Protection;
- All members responsible for managing and handling personal information understand that they are responsible to follow good data protection practice;
- Procedures are in place so that anybody wanting to make enquiries about handling personal information knows what to do;
- Methods of dealing with personal information are clearly described;
- The way personal information is held, managed and used is periodically reviewed;
Subject Access Requests and Complaints
Completion of a Subject Access Request is required to obtain the information and should be submitted to the club secretary in writing.
Epping Archers will attempt to reply to subject access requests as quickly as possible and in all cases within the 1 calendar month set out in the GDPR
All complaints should be written, dated and should include details of the complainant as well as a detailed account of the nature of the problem. Epping Archers will attempt to complete internal investigations within 10 working days and in any case the person will receive an acknowledgement of the complaint as soon as possible.
Complaints should be sent to the club secretary.
This policy was last updated 28/02/18
