DATA PROTECTION & PRIVACY POLICY
Contents
1. Purpose of the policy
1.1 Bankside Open Spaces Trust is committed to complying with privacy and data protection laws, including:
-The UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
-The Privacy and Electronic Communications Regulations 2003 (PECR), as amended.
-Other applicable laws and regulations concerning the processing of personal data and privacy, including guidance from the Information Commissioner’s Office (ICO) or other relevant supervisory authorities.
1.2 This policy outlines how BOST protects individuals’ personal data and ensures compliance with UK data protection law.
1.3 Anyone who handles personal data in any way on behalf of Bankside Open Spaces Trust must ensure that we comply with this policy. Section 3 of this policy describes what comes within the definition of “personal data”. Any breach of this policy will be taken seriously and may result in disciplinary action or more serious sanctions.
1.4 This policy may be amended from time to time to reflect any changes in legislation, regulatory guidance, or internal policy decisions.
2. About this policy
2.1 Anyone handling personal data on behalf of BOST must ensure compliance with this policy. Personal data is defined in Section 3 of this policy. Any breach of this policy may result in disciplinary action or sanctions.
2.2 This policy may be updated to reflect changes in legislation, regulatory guidance, or internal policy changes.
2.3 BOST handles personal data relating to employees, beneficiaries, volunteers, trustees, donors, supporters, and partners.
2.4 The CEO is responsible for overseeing compliance with the UK GDPR and this policy. Concerns or questions should be directed to the CEO or Data Protection Officer (if applicable) at info@bost.org.uk
3. Definitions of data protection terms
3.1 Data Subject: A living individual whose personal data is processed. All data subjects have rights concerning their data.
3.2 Personal Data: Information that identifies a living individual, directly or indirectly. This includes names, contact details, or any other identifiers like location data.
3.3 Data Controller: The organisation or individual that decides how and why personal data is processed. BOST is the data controller for the personal data it processes.
3.4 Data Processor: An individual or organisation processing personal data on behalf of the data controller.
3.5 UK GDPR: The UK’s data protection legislation that sets out the legal requirements for processing personal data.
3.6 ICO: The UK’s Information Commissioner’s Office, the authority overseeing data protection in the UK.
3.7 Processing: Any operation involving personal data, including collection, storage, or destruction.
3.8 Sensitive Personal Data (Special Categories): Data that requires extra protection, such as racial or ethnic origin, political beliefs, religious beliefs, health data, or sexual orientation.
4. Data protection principles
4.1 Anyone processing personal data must comply with the seven data protection principles set out in the UK GDPR. We are required to comply with these principles (summarised below) and show that we comply, in respect of any personal data that we deal with as a data controller.
4.2 Personal data should be:
Fairness, Lawfulness, and Transparency: Data must be processed legally, fairly, and transparently.
Purpose Limitation: Data must be collected for specified, legitimate purposes and not further processed for incompatible purposes.
Data Minimisation: Data must be adequate, relevant, and limited to what is necessary.
Accuracy: Personal data must be accurate and kept up to date.
Storage Limitation: Data must not be kept longer than necessary.
Integrity and Confidentiality: Data must be processed securely to protect against unauthorised or unlawful processing and accidental loss.
Accountability: BOST must be able to demonstrate compliance with all data protection principles through appropriate policies, procedures, records and governance arrangements
5. Processing data fairly and lawfully
5.1 Personal data must be processed fairly and lawfully, ensuring individuals are informed about how their data is collected and used. Processing is lawful if it meets specific conditions, such as the individual’s consent or a legal obligation.
5.2 BOST will identify and document an appropriate lawful basis under Article 6 UK GDPR before processing personal data and will maintain records of the lawful basis relied upon.
5.3 BOST will maintain appropriate records of its processing activities to demonstrate compliance with data protection legislation.
5.4 BOST will provide individuals with clear information, including:
The type of data collected.
Who will hold the data (i.e., BOST).
The purpose of data collection.
The legal basis for processing.
Any sharing of data with third parties.
Data retention periods.
Rights under the UK GDPR.
6. Processing data for the original purpose
6.1 Personal data must only be processed for the purposes specified at the time of collection. Any new purpose will require informing the individual and obtaining consent where necessary.
7. Personal data should be adequate and accurate
7.1 Data must be accurate and relevant for the intended purpose. BOST will take reasonable steps to ensure data accuracy and to delete or correct inaccurate or outdated data.
8. Not retaining data longer than necessary
8.1 Data will be retained only for as long as necessary. BOST will maintain a Data Retention Schedule setting out retention periods for each category of personal data and the lawful basis for retaining it.
Personal data will be securely destroyed when no longer required.
9. Rights of individuals under the GDPR
9.1 Individuals have rights concerning how their data is processed, including:
-Access to their personal data (subject access request).
-Correction of inaccurate data.
-Erasure of their data (right to be forgotten).
-Restriction of processing.
-Data portability.
-Objection to data processing, particularly for direct marketing.
-Individuals also have the right to lodge a complaint with the Information Commissioner’s Office if they believe their personal data has been processed unlawfully.
9.2 Individuals can exercise these rights by contacting BOST at info@bost.org.uk
9.3 BOST will undertake a Data Protection Impact Assessment where processing is likely to result in a high risk to the rights and freedoms of individuals.
10. Data Security
10.1 All staff will receive appropriate data protection training. Access to personal data will be restricted to those with a legitimate business need and reviewed regularly.
10.2 BOST will implement appropriate security measures to protect personal data from unauthorised access, loss, or destruction.
10.3 Security measures include encryption, secure storage, access controls, and regular data backups.
10.4 Sensitive data will be subject to additional security measures, such as encryption of portable devices.
11. Transferring data outside the UK
11.1 Transfers of personal data outside the UK will only take place where there are adequate safeguards, such as:
Transfers to countries with adequate data protection laws.
Use of approved contractual clauses or consent from individuals.
11.2 For more information, contact the person responsible for data protection compliance.
12. Processing sensitive personal data
12.1 Sensitive personal data will only be processed with explicit consent or if processing is necessary for a specific legal purpose.
12.2 Financial data, though not classified as sensitive, will be processed with extra care to ensure its security.
13. Data Breaches and Notification
13.1 BOST will report data breaches to the ICO within 72 hours of becoming aware, where the breach poses a risk to individuals’ rights and freedoms.
13.2 Affected individuals will be notified if there is a high risk of harm.
14. Monitoring and review of the policy
14.1 This policy will be reviewed annually by the board of trustees or sooner if processing practices change.
This revised policy is designed to align closely with UK law and current ICO guidelines, ensuring that Bankside Open Spaces Trust maintains compliance and adequately protects personal data.

