Data Protection Policy

1) Definitions

1. Personal data is information about a person which is identifiable as being about them. It
can be stored electronically or on paper and includes images and audio recordings as
well as written information.
2. Data protection is about how we, as a society, ensure we protect the rights and privacy of individuals, and comply with the law, when collecting, storing, using, amending, sharing, destroying or deleting personal data.
1. Overall and final responsibility for data protection lies with the committee, who are
responsible for overseeing activities and ensuring this policy is upheld.
2. All committee members are responsible for observing this policy, and relatedprocedures, in all of their activities for the society.

3) Overall policy statement

1. Hartfield & District Horticultural Society needs to keep personal data about its

committee and members in order to carry out the society’s activities.

  1. We will collect, store, use, amend, share, destroy or delete personal data only in wayswhich protect people’s privacy and comply with the General Data Protection Regulation(GDPR) and other relevant legislation.
  2. We will only collect, store and use the minimum amount of data that we need for clearpurposes, and will not collect, store or use data we do not need.
  3. We will only collect, store and use data for:
  • purposes for which the individual has given explicit consent, or
  • purposes that are in the society’s legitimate interests, or
  • to comply with legal obligations, or
  • to protect someone’s life, or
  • to perform public tasks.

5. We will provide individuals with details of the data we have about them when requested

by the relevant individual.

  1. We will delete data if requested by the relevant individual, unless we need to keep it forlegal reasons.
  2. We will endeavour to keep personal data up-to-date and accurate.
  3. We will store personal data securely.
  4. We will keep clear records of the purposes of collecting and holding specific data, toensure it is only used for these purposes.
  1. We will not share personal data with third parties without the explicit consent of the relevant individual, unless legally required to do so.
  2. We will endeavour not to have data breaches. In the event of a data breach, we will endeavour to rectify the breach by getting any lost or shared data back. We will evaluate our processes and understand how to avoid it happening again. Serious data breaches which may risk someone’s personal rights or freedoms will be reported to the individual concerned.