Home Plaistow Youth Club

Privacy Policy

Reviewed 1 April 2019

Signed
Chair: Victoria Campling

Plaistow Youth Club

Winterton Hall, Plaistow, West Sussex, RH14 OPX

Registered Charity No: 305407

Policy Statement

Plaistow Youth Club (PYC) Data Protection Policy aims to ensure compliance with the Data Protection Act 1998 and the General Data Protection Regulation, which refers to computerised and manual records of personal data.

PYC is registered with the Information Commissioner’s Office registration number

The Data Protection Officer is responsible for overseeing the implementation of this policy and for monitoring compliance with this policy and any other linked policies & procedures.

Control of data collected and stored

Any personal data collected by PYC shall be stored and processed fairly and lawfully, and only for the purposes for which it has been collected. Data will be maintained accurately and updated regularly and will not be held any longer than necessary. It shall not exceed the purposes for which it is required. Specifically, personal data will be collected and stored to:

  • maintain and process personnel and payroll records of employees
  • maintain records of relevant personal details of staff, directors, volunteers and trainees
  • maintain contact details for affiliated clubs, emails and records of visits
  • maintain contact details for suppliers, contractors and clients
  • maintain personal details of clients/young people using the services/activities provided by

PYC as required by staff (paid or unpaid) to safely and efficiently carry out the service/activity.

Job applications are stored for 12 months and then disposed of confidentially.

Details of young people are stored for the duration of the time that the young person has expressed an interest to attend PYC. Once a young person leaves JYC their data is re-collected for them to move to Senior Youth Club.

Records of incidents / accidents, employee records and financial data may be retained for up to seven years or longer if deemed necessary.

Special efforts will be made to ensure that sensitive data, such as that on health, ethnic origin, trade union membership etc. will not be kept in such a way that the subject’s identity is revealed inadvertently to anyone not authorised to use the data for personnel or payroll purposes.

Employee records

The Youth worker is employed via WSCC and all data is secured via them.

Secure storage

All personal data held by PYC shall be stored securely at all times in locked filing cabinets.

Disclosure

No personal information shall be disclosed to another person or agency except with the express permission of the person concerned. The only exceptions to this relates to matters where PYC are legally bound to pass on information, for example, in relation to any Child Protection issues to the relevant statutory agency or authority.

Data Security

PYC will ensure that the following measures are taken with respect to all communications and other transfers involving personal data:

  • Personal data must never be included within the subject line or message body of an email. access by the recipients or our staff only.
  • Where personal data is to be transferred in hardcopy form it should be passed directly to the recipient or sent using Special Delivery post and in a suitable container marked “confidential”.


PYC will ensure that the following measures are taken with respect to the storage of personal data:

  • All hardcopies of personal data, along with any electronic copies stored on physical, removable media should be stored securely in a locked box, drawer, cabinet, or similar.
  • No personal data should be stored on any mobile device (including, but not limited to, laptops, tablets, and smartphones), whether such device belongs to PYC or otherwise without approval of the appropriate member of the Data Protection Officer and, in the event of such approval, strictly in accordance with all instructions and limitations described at the time the approval is given, and for no longer than is absolutely necessary.
  • No personal data should be transferred to any personal device belonging to an employee, and personal data may only be transferred to devices belonging to agents, contractors, or other parties working on behalf of PYC where the party in question has agreed to comply fully with this policy and all Data Protection Legislation.
  • When any personal data is to be erased or otherwise disposed of for any reason (including where copies have been made and are no longer needed), it should be securely deleted and disposed of.
  • All paper copies of records should be disposed of by use of a cross-cut shredder or sent to a suitable processor for destruction.


Data should be protected at all times, this includes practical approaches such as locking away laptops when not in use and being careful who has access to where data is stored.

Any loss of personal data is a security breach and all breaches, near-misses and incidents must be reported immediately to the Data Protection Officer.

The Data Protection Officer must ensure that the Information Commissioner’s Office is informed of any significant breach without delay, and in any event, within 72 hours after being made aware of it.

In the event that a personal data breach is likely to result in a high risk to the rights and freedoms of data subjects, the Data Protection Officer will ensure that all affected data subjects are informed of the breach directly and without undue delay.


Use of Email Tracking Pixels

All emails sent by the system contain a tracking pixel. This is used to track whether each email has been opened by the recipient, and when. This information can be viewed by those users of the system with permission to view email delivery reports. We do not display any information regarding the location of the recipient. Note that the tracking pixel is only activated if the recipient chooses to download images into their email client.

Data Processor

We, Plaistow Youth Club, make use of the myClubhouse software supplied by Simmetrics Ltd to process personal data we include on our myClubhouse website in accordance with our privacy policy set out above. Simmetrics Ltd processes your personal data on our behalf and they can only do so in accordance with our written instructions. You can find the details of our data processor’s privacy policy here: http://www.myclubhouse.co.uk/Home/PrivacyPolicy.

{"HeaderName":"RequestVerificationToken","RequestToken":"CfDJ8OsS_Wov3ttNiFG_9PCxeElUoQ8A8q2QaNg5ANjaXV6MgpJOUMTdswyFyQhKrb8_7vEMGTA0nfd6QHRscIA815bEQsuT_b3eePNX47HJKcskvoleznmo4ERtLxsQKDRDedQlfDD4purGjjF_vbYjl7A"}