Privacy Policy

Data Protection Policy

Scope

This policy is provided for all staff, trustees, volunteers, contractors and participants of Birmingham TreePeople.

Protecting your privacy

Your privacy is important to us.

Birmingham TreePeople is committed to safeguarding the personal information you provide to us and to protecting your privacy.

The purpose of this privacy statement is to assist you in understanding how we use personal information collected, and the choices you can make about how your personal information is used.

Birmingham TreePeople may occasionally be required by law to collect and use certain types of information to comply with the requirements of government departments or awarding bodies.

This information is collected, recorded and used with safeguards to ensure this complies with the Data Protection Act 2018 and the General Data Protection Regulations.

The information we collect

We may collect personal information about you when you register with us through the use of paper and electronic registration forms.

This information includes name, address, email address and preference information to enable personalisation. We will also collect health information and emergency contact details to ensure you are safe when taking part in training and activities.

How the information is used

Birmingham TreePeople will ensure data is:

  • Processed lawfully, fairly and in a transparent manner in relation to individuals
  • Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
  • accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals; and
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

We collect information on our users for a variety of purposes:

  • To help us improve and provide a personalised service to you.
  • To conduct research.
  • To reply to your enquiries more efficiently through the services we provide.
  • So that we can send you information relevant to your interests.

We fully endorse and adhere to the Principles of data protection, as set out in the Data Protection Act 2018. The Principles require that personal information:

  • Shall be processed fairly and lawfully and, in particular, shall not be processed unless specific conditions are met;
  • Shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes;
  • Shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed;
  • Shall be accurate and, where necessary, kept up to date;
  • Shall not be kept for longer than is necessary for the specified or legal purpose(s);
  • Shall be processed in accordance with the rights of data subjects under the Act;
  • Should be subject to appropriate technical and organisational measures to prevent the unauthorised or unlawful processing of personal data, or the accidental loss, destruction, or damage to personal data;
  • Shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

Birmingham TreePeople will ensure:

  • All workers responsible for collecting and processing data have been trained so as to comply with the rules set out above.
  • Procedures for collecting data have been approved by Trustees to ensure all personal information collected complies with the rules set out above.

The Right to be Informed

The General Data Protection Regulations gives data subjects 8 rights in regard to their personal data. These rights are:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability

Allowing access to data

At Birmingham TreePeople we follow rights for individuals:

  • the right to be informed;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restrict processing;
  • the right to data portability;
  • the right to object; and the right not to be subject to automated decision-making including profiling

All information will be provided free of charge within one month.

We will inform the individual within one month of the receipt of the request and explain why the extension is necessary.

We will verify the identity of the person making the request, using ‘reasonable means’.

The GDPR gives a specific right to withdraw consent. We explain to all about their right to withdraw and offer them easy ways to withdraw consent at any time.

Disposal of any IT equipment or paperbased forms is done securely.

Data Controllers

Birmingham TreePeople has a named data controller who determines the purposes and the means of processing personal data.

Our data controller determines the purposes for which, and the manner in which, any personal data are, or are to be, processed.

Our Operations Manager is tasked with monitoring compliance with the GDPR and other data protection laws, your data protection policies, awareness-raising, training and audits.

Our Operations Manager acts as a contact point for the ICO.

Updating your personal information

Please keep us informed of any changes in your personal details by emailing birminghamtreepeople@gmail.com

Breaches of Data Protection

Any breaches of personal data need to be reported to the ICO within 72 hours of becoming aware of the breach.

If the breach is likely to result in a high risk of adversely affecting individual’s rights, you must also inform those individuals without delay. Birmingham TreePeople will keep a record of any personal data breaches, regardless of whether they are required to notify.

Data breaches can include:

  • Access by an unauthorised third party
  • Deliberate or accidental action (or inaction) by a controller or processor;
  • Sending personal data to an incorrect recipient;
  • Computing devices containing personal data being lost or stolen;
  • Alteration of personal data without permission; and
  • Loss of availability of personal data.

Recital 87 of the GDPR states that when a security incident takes place, we will establish whether a personal data breach has occurred and, if so, promptly take steps to address it, including telling the ICO if required.

When reporting a breach, we will provide:

  • A description of the nature of the personal data breach including, where possible
  • The categories and approximate number of individuals concerned
  • The categories and approximate number of personal data records concerned
  • The name and contact details of the data protection officer (if your organisation has one) or other contact point where more information can be obtained
  • A description of the likely consequences of the personal data breach
  • A description of the measures taken, or proposed to be taken, to deal with the personal data breach including where appropriate the measures taken to mitigate any possible adverse effects.

If a worker needs to report a breach to the ICO they can call them on 0303 123 1113 or follow the link below to report it through their website using the following link: https://ico.org.uk/for-organisations/report-a-breach

And Provide the following details:

  • The name and contact details of the data protection officer or other contact point where more information can be obtained;
  • A description of the likely consequences of the personal data breach;
  • A description of the measures taken or proposed to be taken to deal with the personal data breach and including, where appropriate, of the measures taken to mitigate any possible adverse effects.

Changes to the privacy information

Birmingham TreePeople will regularly review and, where necessary, update our Data Protection policy and this will be briefed to all workers and made available on our website.