Data Protection Policy
This policy explains how we protect personal information, following the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025. We are dedicated to handling all personal data responsibly, transparently, and within the law.
Scope
This policy covers everyone who works for us — staff, contractors, volunteers and third parties — whenever they handle personal data on our behalf, wherever that data is stored or processed. The Data (Use and Access) Act 2025 adds detailed rules on how data can be used, shared, and accessed in the UK and internationally.
Staff and Volunteer Details
We collect and use personal details about staff and volunteers for essential functions such as hiring, payroll, training, supervision, ensuring health and safety, and meeting legal requirements. This may include names, contact details, job or volunteer history, references, background checks, payroll information, and emergency contacts.
Only authorised people can access this information, and it is used solely for our organisational needs. We keep all details accurate, up to date, and only as long as necessary. Sensitive data, like health information or criminal record checks, is handled with extra care and only when absolutely required. Staff and volunteers are informed about their data rights, including access, correction, or deletion of their information, and the right to object to certain uses.
Fundraising Data
We keep data on fundraising, including applications, responses, reporting and any criteria. Where the data includes information on individuals we apply additional security measures and only hold the data for as long as necessary (this will include different bases including potentially legal, consent and legitimate interest).
Principles of Data Protection
- Lawfulness, fairness, and transparency: we process personal data legally and openly.
- Purpose limitation: we collect data only for specific, clear, and legitimate reasons, and do not use it for other purposes.
- Data minimisation: we only collect what is needed for our purposes.
- Accuracy: we ensure personal data is correct and kept up to date.
- Storage limitation: we do not keep personal data longer than necessary.
- Integrity and confidentiality: we protect data from unauthorised access, loss, or damage.
- Accountability: we take responsibility for our data practices and can demonstrate compliance.
Data Subject Rights
People whose data we process have the right to:
- Be informed about how their data is used
- Access their data
- Correct mistakes in their data
- Ask for their data to be deleted in certain cases
- Object to certain uses of their data
- Be protected from automated decisions and profiling
Data Security
We use technical and organisational measures to keep personal data secure from unauthorised access, change, disclosure, or destruction. All staff must follow data handling rules and report any breaches immediately. The Data (Use and Access) Act 2025 requires us to keep records of who accesses data and to audit our security regularly.
Data Sharing and Transfers
We only share personal data with others when it is legal to do so and when proper safeguards are in place. When data is transferred outside the UK or EEA, we ensure it is protected according to the law. The Data Use and Access Act sets strict conditions for sharing and requires clear agreements with third parties.
Data Breach Procedures
In the unlikely event of a data breach, we will follow a set plan, including notifying anyone affected and the relevant authorities, as required by law. We will document and review all incidents to prevent future breaches.
Data Protection Complaints
In line with the ICO's guidance and the Data (Use and Access) Act 2025, we have a dedicated process for handling complaints relating to personal data. Anyone who believes we have not handled their personal information appropriately may raise a data protection complaint with us.
We will:
- Provide a clear and accessible way for individuals to submit data protection complaints.
- Acknowledge receipt of such complaints within 30 calendar days.
- Take appropriate steps to investigate the complaint without undue delay, including making necessary enquiries and keeping the complainant informed throughout.
- Communicate the outcome of the complaint promptly and clearly, explaining any actions taken or decisions made.
All complaints will be handled fairly, transparently, and in accordance with our obligations under the Data Protection Act. If the complainant remains dissatisfied, they may escalate the matter to the Information Commissioner's Office (ICO).
Contact
If you have any questions about this policy or your rights, please contact our CEO, Jessica Berry on mast@thisismast.org, +44 (0) 7768 080105 or 22 Wycombe End, Beaconsfield, Buckinghamshire HP9 1NB.
Version Control - Approval and Review
This policy will be reviewed annually, or following an incident, change in legislation, or other significant factors.
| Version No | Approved By | Approval Date | Main Changes | Review Period |
|---|---|---|---|---|
| 1.0 | Board | 17/03/26 | Debated at the AGM 17th March 2026 | Annually |
| 2.0 | Board | Complaints policy |