← Back to Policies
Sporting Rugby FC is committed to protecting and respecting the privacy of our members, staff, volunteers, and all individuals we interact with. This policy outlines our commitment to compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 in the United Kingdom.
1. Purpose
The purpose of this policy is to:
- Ensure compliance with GDPR and the Data Protection Act 2018.
- Protect the rights and privacy of individuals.
- Outline how we collect, use, store, and protect personal data.
2. Scope
This policy applies to all personal data processed by Sporting Rugby FC, including that of members, staff, volunteers, partners, and other stakeholders. It covers all data collection, processing, and storage activities.
3. Data Protection Principles
Sporting Rugby FC adheres to the following principles when processing personal data:
- Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and transparently.
- Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data Minimisation: Data collected is adequate, relevant, and limited to necessary information.
- Accuracy: Data is accurate and, where necessary, kept up to date.
- Storage Limitation: Data is kept in a form that permits identification of individuals for no longer than necessary.
- Integrity and Confidentiality: Data is processed to ensure appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage.
4. Data Collection
Sporting Rugby FC collects personal data for the following purposes:
- Membership registration and management.
- Communication and updates regarding club activities.
- Financial transactions and fee management.
- Health and safety records.
- Marketing and promotional activities.
5. Legal Basis for Processing
Sporting Rugby FC processes personal data based on one or more of the following legal bases:
- Consent: Where individuals have given explicit consent for processing.
- Contract: Where processing is necessary for the performance of a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation.
- Legitimate Interests: Where processing is necessary for the club's legitimate interests, provided the individual's rights and interests do not override these interests.
6. Your Rights
Individuals have the following rights regarding their personal data:
Right to be Informed
You have the right to be informed about how we collect and use your personal data.
Right of Access
You can access your personal data and supplementary information held by us.
Right to Rectification
You have the right to have inaccurate or incomplete personal data corrected.
Right to Erasure
You can request that your personal data be erased in certain circumstances.
Right to Restrict Processing
You can request the restriction or suppression of your data.
Right to Data Portability
You can obtain and reuse your data across different services.
Right to Object
In certain circumstances, you have the right to object to the processing of your data.
Automated Decision Making
You have rights related to automated decision-making and profiling.
7. Data Security
Sporting Rugby FC implements appropriate technical and organisational measures to ensure the security of personal data, including:
- Access controls and authentication measures.
- Encryption of data in transit and at rest.
- Regular security assessments and audits.
- Staff training on data protection and security practices.
8. Data Retention
In accordance with our data retention policy, personal data is retained only for as long as necessary to fulfil the purposes for which it was collected. Data that is no longer required is securely deleted or anonymised.
9. Data Breaches
In the event of a data breach, Sporting Rugby FC will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach if it risks individuals' rights and freedoms.
- Inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Document the breach, its effects, and the remedial actions taken.
10. Review and Updates
This policy is reviewed annually and updated to ensure ongoing compliance with data protection laws and best practices.