Privacy

ST STEPHEN’S CHURCH

GENERAL PRIVACY NOTICE

YOUR PERSONAL DATA — WHAT IS IT?

Personal data is information that identifies, or could identify, a living individual, such as a name, photograph, email address or postal address. We process personal data in accordance with the UK GDPR, the Data Protection Act 2018 and other applicable legislation.

WHO ARE WE?

The Parochial Church Council (PCC) of St Stephen’s, Tonbridge is the data controller responsible for the personal data processed by St Stephen’s Church.

The PCC is responsible for ensuring personal data is processed in accordance with UK data protection legislation.

The Operations Manager is the Church’s Data Protection Lead and oversees compliance with data protection legislation, including responding to requests and managing data breaches.

As part of the Church of England, we may share personal data with diocesan and other Church of England bodies where necessary to fulfil legal, safeguarding, administrative or pastoral responsibilities.

WHAT PERSONAL DATA DO WE PROCESS?

We may process the following categories of personal data where appropriate:

  • Names, titles, photographs and video;
  • Contact details;
  • Demographic information where relevant to our work;
  • Financial information relating to donations, payments or bookings;

Some of the data we process is  special category personal data because, as a church, the fact that we process your data at all may be suggestive of your religious beliefs.

WHY DO WE PROCESS YOUR PERSONAL DATA?

We process personal data for purposes including:

  • To deliver the church’s mission and charitable activities;
  • To provide pastoral care and organise services such as baptisms, weddings and funerals;
  • To enable us to meet all legal and statutory obligations (which include maintaining and publishing our electoral roll in accordance with the Church Representation Rules);
  • To carry out comprehensive safeguarding procedures (including due diligence and complaints handling) in accordance with best safeguarding practice from time to time with the aim of ensuring that all children and adults-at-risk are provided with safe environments;
  • To administer the parish, deanery, archdeaconry and diocesan membership records;
  • To fundraise and promote the interests of the church and charity;
  • To maintain financial and administrative records;
  • To process a donation that you have made (including Gift Aid information);
  • To seek your feedback;
  • To keep you informed about church services, events and activities;
  • To send you communications which you have requested and that may be of interest to you. These may include information about campaigns, appeals, other fundraising activities;
  • To process a grant or application for a role;
  • To enable us to provide a voluntary service for the benefit of the public in a particular geographical area as specified in our constitution;

WHAT IS THE LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA?

We will only process your personal data where there is a lawful basis under the UK General Data Protection Regulation (UK GDPR).  Depending on why we are using your information, we may rely on one or more of the following lawful bases:

Legitimate interests

Most personal data is processed under our legitimate interests in carrying out the church’s ministry and administration. Before relying on this basis, we balance our interests against your rights and freedoms.  Examples include:

  • administering church membership and activities
  • providing pastoral care
  • communicating with members of the congregation
  • managing volunteers
  • safeguarding children and adults at risk
  • maintaining church records.

Legal Obligation

We also process personal data where required by law, for example to maintain financial records, administer Gift Aid and meet safeguarding and statutory obligations.

Contract

We process personal data where necessary to fulfil contracts, such as employment, premises hire or services you request.

Public Task

In limited circumstances, we process personal data because we are carrying out tasks in the public interest or exercising official authority vested in the Church of England.

Consent

We rely on consent where required, for example for certain communications or the use of photographs and videos. Consent may be withdrawn at any time.

Special Category Personal Data

As a church, some of the personal data we process may constitute special category personal data because processing your information may reveal, or allow others to infer, your religious beliefs.

Where this occurs, we process that information only where an appropriate condition under Article 9 of the UK GDPR and, where required, Schedule 1 of the Data Protection Act 2018 applies. We take additional measures to protect this information.

SHARING PERSONAL DATA

All personal data will be treated as strictly confidential.

We only share personal data where there is a lawful basis, including with Church of England bodies and trusted service providers acting on our behalf.

Where third parties process data on our behalf, appropriate agreements are in place to ensure compliance with data protection requirements.

HOW LONG DO WE KEEP YOUR PERSONAL DATA?

We retain personal data only for as long as necessary and in accordance with our Data Retention Schedule, which is based on legal requirements and Church of England guidance.

HOW DO WE PROTECT YOUR DATA?

We take appropriate technical and organisational measures to protect personal data from loss, unauthorised access and misuse. Access is restricted to those who need it for their role, and third-party processors are required to meet UK data protection standards.

We regularly review our technical and organisational security measures and undertake Data Protection Impact Assessments where appropriate.

We maintain appropriate policies, procedures and records to demonstrate compliance with UK data protection legislation, including records of processing activities where required by Article 30 of the UK GDPR. Further information about how we manage and protect personal data can be found in our Data Handling Policy.

YOUR RIGHTS AND YOUR PERSONAL DATA

You have rights under the UK GDPR, including the right to access, correct, erase, restrict or object to processing, request data portability, withdraw consent where processing is based on consent, and not be subject to solely automated decision-making.

Subject Access Requests may be made verbally or in writing. We will normally respond within one month, although this may be extended where permitted by law.

AUTOMATED DECISION-MAKING

We do not make decisions based solely on automated processing or profiling.

INTERNATIONAL TRANSFERS

Personal data transferred outside the UK will only be transferred where appropriate safeguards are in place in accordance with UK data protection legislation, such as an adequacy decision or approved contractual safeguards.

FURTHER PROCESSING

If we use your personal data for a new purpose, we will provide further information and obtain your consent where required.

CONTACT DETAILS

Please contact us if you have any questions about this Privacy Notice or the information we hold about you or to exercise all relevant rights, queries or complaints at:

Data Protection Lead

St Stephen’s Church Office

35 Waterloo Road

Tonbridge

Kent TN9 2SW

office@ststephens.org.uk

If you are dissatisfied with how we have handled your personal information, you have the right to complain to the Information Commissioner’s Office (ICO).

The Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow  

Cheshire SK9 5AF

0303 123 1113 or https://ico.org.uk/global/contact-us/email/