Data Protection Policy
This privacy policy applies between you, the User of this Website and Jeannie Lymath trading as
Data Protection Policy
| Responsible Officer | Jeannie Lymath |
| Effective Date | 30/05/26 |
| Approved by | SEG |
| Review date | 30/05/27 |
PURPOSE:
To set out the approach of Solecare Academy of Healing in relation to protecting all people who are involved with the activities of SAH.
INTRODUCTION:
This document contains a policy statement (Part One) and procedural guidance (Part Two). The functions of each are set out briefly below.
Part One – Policy Statement. The policy statement sets out the broad framework of principles of GDPR and Data Protection. It sets out SAH broad style and approach to the issue, including any aims and guiding principles.
Part Two – Procedural Guidance. The procedural guidance sets out the details that all members should take to ensure the objectives of the policy are achieved. It also sets out the specific tasks involved in undertaking this and identifies who is responsible for carrying them out.
Members in this document, is to include directors, volunteers, employees.
PART ONE – POLICY STATEMENT
Data Protection is the term used to ensure the lawful processing of personal data about an identified or identifiable living individual.
“Processing”, in relation to information, means an operation or set of operations which is performed on information, or on sets of information, such as—
(a) collection, recording, organisation, structuring or storage,
(b) adaptation or alteration,
(c) retrieval, consultation or use,
(d) disclosure by transmission, dissemination or otherwise making available,
(e) alignment or combination, or
(f) restriction, erasure or destruction,
SAH needs to process information about all people who are involved with the activities of SAH and those on our mailing lists.
When we process information, we need to adhere to the principles of the General Data Protection Regulation (GDPR) and Data Protection Act 2018.
The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR) which ensures that everyone who is responsible for using personal data has to follow strict rules called ‘data protection principles’. They must make sure the information is:
- used fairly, lawfully and transparently
- used for specified, explicit purposes
- used in a way that is adequate, relevant and limited to only what is necessary
- accurate and, where necessary, kept up to date
- kept for no longer than is necessary
- handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
There is stronger legal protection for more sensitive information, such as:
- race
- ethnic background
- political opinions
- religious beliefs
- trade union membership
- genetics
- biometrics (where used for identification)
- health
- sex life or orientation
In particular, we need to make sure that we process information in line with principles of data protection described in the Act.
The Data Protection Act sets limits on the way we collect, store and use information, this is commonly referred to as processing. The Act controls:
- What information we can process – our lawful basis for processing
- Additional conditions for lawfully processing special category data and criminal offence data – data that is more sensitive due to its nature
- How we file information – ensuring that data is not sent outside the European Union without adequate safeguards
- How we access information – including who can access individual’s information
- How we pass information on to other organisations and individuals – whether with or without consent; and
- How and when we destroy information we are storing.
The act provides the following rights for individuals:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- The right to object
- Rights in relation to automated decision making and profiling.
The Act says that organisations that process information need to register with the Information Commissioner’s Office.
THE ICO’S WEBSITE STATES EXEMPTIONS FOR:
- Organisations that only processes personal information for:
- staff administration (including payroll);
- advertising, marketing and public relations (in connection with their own business activity); and
- accounts and records;
- Some not-for-profit organisations;
- Organisations that process personal data only for maintaining a public register;
- Organisations that do not process personal information on computer.
SAH Directors have management responsibility for ensuring compliance with this policy, and reports to the SAH chair(s), who have overall responsibility for ensuring that SAH works in line with the Data Protection Act.
SAH Executive Directors, SAH members and any others who process personal information on behalf of SAH must comply with the principles of the Act.
SAH’s Responsibilities
SAH want to protect the right of individuals to privacy.
We will respect the privacy of individuals when processing personal information.
We will take appropriate measures to make sure that the data we hold is stored securely.
We will establish a lawful basis for processing each type of data we process, and when using Legitimate Interests as our basis complete a Legitimate Interests Assessment.
If there is a data breach we will assess the likely risk to individuals of significant economic or social disadvantage, and notify the Information Commissioner if required.
We will complete Data Protection Impact Assessments for uses of personal data that are likely to result in high risk to individuals’ interests.
We will ensure that there are written contracts in place for organisations that process personal data on our behalf.
SAH Directors have overall responsibility for making sure that SAH meets the terms of the Data Protection Act.
SAH Directors have a responsibility to make sure that members process information in line with the terms of the Act.
Members Responsibilities
Members are responsible for the security of the information they process.
Members must not pass on information to anyone who is not entitled to it.
Members must only use personal data in authorised ways.
Members must immediately inform an executive Committee member of any requests from any individual wanting to exercise their rights.
Right of access
SAH, members and people who are involved with the activities of SAH have the right to access personal information SAH holds about them, whether in electronic or paper form.
People who want to access information held about them should contact the SAH Directors.
The principles of data protection
The Data Protection Act states that anyone who processes personal information must comply with six principles. These state that information must be:
a) processed lawfully, fairly and in a transparent manner in relation to individuals;
b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals; and
f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures
Appendix 1 – Being open about how we will use information that individuals give us
The Data Protection Act says that we need to explain to people how we will use the personal information they give us.
We provide individuals with all the following privacy information:
- The name and contact details of our group.
- The name and contact details of our representative (if applicable).
- The contact details of our data protection officer (if applicable).
- The purposes of the processing.
- The lawful basis for the processing.
- The legitimate interests for the processing (if applicable).
- The categories of personal data obtained (if the personal data is not obtained from the individual it relates to).
- The recipients or categories of recipients of the personal data.
- The details of transfers of the personal data to any third countries or international organisations (if applicable).
- The retention periods for the personal data.
- The rights available to individuals in respect of the processing.
- The right to lodge a complaint with a supervisory authority.
- The source of the personal data (if the personal data is not obtained from the individual it relates to).
- The details of whether individuals are under a statutory or contractual obligation to provide the personal data (if applicable, and if the personal data is collected from the individual it relates to).
- The details of the existence of automated decision-making, including profiling (if applicable).
When to provide it
We provide individuals with privacy information at the time we collect their personal data from them by way of our membership form.
How to provide it
We provide the information in a way that is:
- concise;
- transparent;
- intelligible;
- easily accessible; and
- uses clear and plain language.
Changes to the information
We regularly review and, where necessary, update our privacy information.
If we plan to use personal data for a new purpose, we update our privacy information and communicate the changes to individuals before starting any new processing.
Appendix 2 – Passing on information
Information you give SAH will be used by us alone to tell you about SAH, and to give you information on issues relevant to you. SAH will communicate with you by telephone, letter, email, or in any other reasonable way. You can ask for a copy of the information we hold about you, and if the information isn’t accurate, you can ask us to correct it. If you do not want to receive letters, emails and telephone calls from us in the future, please tell us in writing.
With your permission SAH will pass on information about you including your contact details to other organisations who are running services of use to you. We will only pass your information on without your permission if we have concerns for a child or vulnerable adult.
We will never pass your contact details on to salespeople, or to private organisations.
If you have any questions about how SAH will use your information please talk to one of our directors.
General guidelines:
- SAH may pass contact information on to agents enrolled with SAH to carry out a particular task (for example, asking a committee member to contact people on our database by telephone)
- SAH may not pass on contact information for individuals to private sector organisations wishing to sell services or goods
- SAH may not pass on information about an individuals’ without permission from that individual unless there is a safeguarding concern
Appendix 3 – InformationSecurity
Personal information relating to individuals affiliated with SAH is stored securely. This information is considered sensitive.
SAH endeavours to operate paper-free and any information that is received in hard copy are scanned as soon as possible so the original can be destroyed.
- Any paper notes are shredded once they have been processed
- Only authorised members can access records. Sensitive information is password protected
- The information is backed up
- When a member leaves the group all passwords will be changed immediately for any protected documents
- Should hard copies of sensitive information be required they will be stored in a lockable filing cabinet until they can be scanned and shredded
When people are new to SAH, the following checklist will be issued to them. This is intended to act as an overview to Information Security, and does not negate the need for all members with access to sensitive information to read and comply with this policy.
How does Information Security relate to me?
The underpinning principles of Information Security are best presented as a checklist of do’s and don’ts. These should be read in conjunction with SAH Data Protection Policy.
| Do: | Don’t |
| Seek advice from your section lead if you are unclear about any aspect of information security. | Disclose your password to anyone. |
| Change your password if you have any suspicion that it may have been compromised. | Undermine or seek to undermine the security of stored information. |
| Comply with the law and SAH Data Protection policies. | Provide access to SAH information or systems to those who are not entitled to access. |
| Do assume that Information Security is relevant to you. | Do not use personally owned equipment to store sensitive information. |
| Always ensure hard copies of confidential information are attended or secured. | |
| Only save sensitive information in a secure location. | |
| Delete any scanned documents immediately and regularly empty your recycle bin |
Appendix 4 – Editing or Removing Data
An individual can request that information held by SAH is amended or removed if it is inaccurate, offensive, inappropriate, infringing someone else’s copyright or using their image or name without permission (i.e. putting a picture of them on our social media). Any member of staff receiving such as request, should:
- Without delay inform a director of the request, who will decide if the information/content should be removed or amended
Appendix 5 – Retention Periods
The following retention periods are set for the different categories of personal data that SAH holds:
| Type of Data / Data Subject | Retention Period |
| Service user records | 12 years from the last date of engagement with any of our services |
| Subject Access Requests | 2 years from the date of the request being fulfilled |
| Complaints | 2 years from the date of the last correspondence |
| Membership Applications (for those who do not engage only) | 1 year from the date of appointment |
