1. Introduction
This policy sets out the principles and processes that Arts for Dementia should apply to ensure that, in respect of all records that it keeps, as far as reasonably possible it complies with the law on data privacy, and acts in accordance with the wider expectations of our many stakeholders. Failure to manage data securely and appropriately may cause harm to staff, donors, clients and other stakeholders, and to the reputation and status of Arts for Dementia.
2. Applicability
2.1 Arts for Dementia’s policy on data protection and privacy applies to trustees, staff, contractors, volunteers and others who handle and store Personal Data on behalf of Arts for Dementia.
2.2Data Controller
2.3 Data Processor
In relation to Personal Data, any person or organisation (other than an employee of the data controller), such as Donorfy, who processes the data on behalf of the data controller.
3. Collecting and processing Personal Data
3.1 Legitimate purposes
3.2 Individuals will be asked to Consent to their Personal Data being held. We will be transparent about how we will use the data, and give individuals appropriate privacy notices when collecting their Personal Data.
3.3 If Consent is withdrawn Arts for Dementia will promptly remove the relevant Personal Data from its records.
3.4 Data records will be reviewed periodically (at least annually) to identify data, including Personal Data, that is no longer required for the purposes set out above. It may be necessary to re-confirm details with the individuals concerned and this can also be used to update Consent.
4. Additional Conditions for processing Sensitive Personal Data
4.1
a) the individual whom the sensitive Personal Data is about has given explicit Consent to the processing; and
b) one or more of the following:
5. Storing Personal Data
5.1 Personal Data will normally be permanently held in an online database (e.g. Donorfy) as this is considered more secure, as well as more useful than on a laptop.
5.2 Where Personal Data is held in spreadsheets or other structured documents on a laptop then the application should be password protected.
5.3 Personal Data held on laptops or in hard-copy should only be held for as long as required and should be deleted or destroyed when that purpose has been served, if necessary after making necessary changes to the master data.
5.4 If Personal Data for which Arts for Dementia is responsible is transferred to a private computer, the person responsible should apply good practice in relation to the security of that computer.
5.5 If Personal Data is processed or shared in e-mails, spreadsheets or other documents, care should be taken not to copy these documents wider than necessary for that purpose.
5.6 Arts 4 Dementia will take appropriate action in the event of a breach of data by recording the breach, notifying the Information Commissioner without delay and notifying the individual concerned where there is a high risk to their rights and freedoms.
7. Requests for Copies of Information held
7.1 GDPR gives any individual the right to find out what information an organisation stores about them. All requests should be passed to the Chief Executive and should only be accepted in writing.
7.2 Normally Arts for Dementia will endeavour to provide a copy of any record containing Personal Data without charge, but a charge of £10 may be made at the Chief Executive’s discretion, to be paid in advance, if significant effort is required to assemble the information or to discourage frivolous or vexatious requests.
7.3 Arts for Dementia will respond to requests for information held as soon as practicable and at most within one month.
8. Contracts with data processors and other third party providers
8.1 Realistically Arts for Dementia is not in a position to dictate contract terms to large service providers, such as those who may act as Data Processor. Nevertheless it is important that we are aware of the terms on which services are provided and the risks that may follow. The Chief Executive should, to their reasonable satisfaction, ensure that the third party provides processes and systems that manage Personal Data for which Arts 4 Dementia is responsible in a manner consistent with GDPR.
8.2 Where practicable, contractors should be notified that compliance with GDPR is a requirement of our contractual relationship and failure to comply will be grounds for termination by us for breach of contract.
9. Personal Data relating to Staff and Trustees
9.1 Information collected for recruitment and selection will only be used for that purpose. It will only be retained so long as there is a clear need for it. DBS (Disclose and Barring Service) procedures will be followed where checks need to be made and Arts for Dementia will make a record only that a satisfactory/ unsatisfactory check was made, not hold detailed information on file.
9.2 Arts for Dementia will not collect or retain information that is irrelevant or excessive to the purpose for which it is collected. Information will be deleted and documents destroyed when there is no longer a clear business need for them to be retained.
9.3 Personal information on staff and trustees will always be labelled as confidential, stored securely and handled with respect.
9.4 Staff and Trustee Personal Data will not be disclosed to another organisation without express permission of the individual concerned, unless covered by the statutory exceptions listed in sections 4 and 5 above. Requests for references will only be given with that persons’ consent.
9.5 Only the Chief Executive will have access to confidential records with the following exceptions:
– the Chairman will normally hold confidential information relating to the Chief Executive and to Trustees;
– the Payroll provider and treasurer will have access to payroll information;
– the size of the charity is such that individual’s remuneration will be apparent from financial information prepared for the Trustees.
If you use the website to submit event listings please see the additional policy below:
Our website address is: https://artsfordementia.org.
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
If you request a password reset, your IP address will be included in the reset email.
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website, we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Visitor comments may be checked through an automated spam detection service.