General Data Protection Regulation (GDPR)

St Mary’s Church, Leigh

Data Privacy, Confidentiality & Data Protection Policy

1. Purpose of This Policy

St Mary’s Church, Leigh is committed to protecting the privacy, rights and wellbeing of all individuals whose personal information we hold. This policy sets out how we collect, use, store and share personal data, and how we manage confidential information, including safeguarding and domestic abuse disclosures.

The Parochial Church Council (PCC) is the data controller for the purposes of the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

2. Personal Data

Personal data is information relating to a living individual who can be identified from that data. St Mary’s Church processes personal data for a range of pastoral, administrative, safeguarding and legal purposes.

3. Principles of Data Processing

St Mary’s Church is committed to processing personal data lawfully, fairly and transparently. We ensure that personal data is:

  • accurate and kept up to date
  • stored and destroyed securely
  • limited to what is necessary
  • protected from loss, misuse, unauthorised access or disclosure

We use personal data for the following purposes:

  • communicating news, events, activities and services
  • administering membership and electoral roll records
  • fundraising and promoting the interests of the Church
  • maintaining financial records, including Gift Aid
  • managing volunteers
  • supporting pastoral care and safeguarding responsibilities

4. Legal Basis for Processing Personal Data

We process personal data only when one or more of the following apply:

  • Consent – e.g. to send newsletters or event information
  • Legal obligation – e.g. Gift Aid, Church Representation Rules
  • Safeguarding necessity – to protect children or vulnerable adults
  • Substantial public interest – including preventing or detecting unlawful acts or protecting individuals from harm

5. Confidentiality

St Mary’s Church respects the confidentiality of information shared with us. However, confidentiality cannot always be guaranteed, particularly where safeguarding or domestic abuse concerns arise.

Where information relates to domestic abuse or risk of harm:

  • individuals will be encouraged to disclose concerns to the appropriate authorities
  • consent to share information will be sought wherever possible
  • information may be shared without consent if necessary to:
    • protect a child or adult from significant harm
    • prevent, detect or prosecute a serious crime
    • support an ongoing investigation
    • prevent increased risk to an individual

Decisions to share information without consent must be based on necessity and proportionality, weighing the risks of sharing against the risks of not sharing. Guidance should be sought from the Diocesan Safeguarding Adviser (DSA) or Diocesan Registrar when needed.

6. Sensitive Personal Data

Sensitive personal data includes information relating to health, sexual life, or the commission or alleged commission of an offence. Such data is subject to stricter controls.

It may be shared without consent only when:

  • necessary to prevent or detect unlawful acts
  • required to protect the public from malpractice or improper conduct
  • necessary for confidential counselling, advice or support
  • seeking consent would place someone at risk or prejudice an investigation

7. Sharing Personal Data

Personal data is treated as strictly confidential. It will only be shared:

  • with other church members where necessary for church-related purposes
  • with third parties outside the parish only with explicit consent, unless required by law or safeguarding obligations

8. Retention of Personal Data

We follow the Church of England’s guidance “Keep or Bin: Care of Your Parish Records”. Specifically:

  • Electoral Roll data is kept while current
  • Gift Aid declarations and related paperwork are kept for six years
  • Parish registers (baptisms, marriages, funerals) are kept permanently
  • Safeguarding records are stored securely in accordance with Safeguarding Records: Joint Practice Guidance

9. Storage of Confidential Records

All confidential records, whether or not they contain personal data, are stored safely and securely. Access is restricted to authorised personnel only, in line with Church of England safeguarding guidance.

10. Your Rights

Unless an exemption applies, individuals have the right to:

  • request a copy of the personal data held about them
  • request correction of inaccurate or outdated information
  • request restriction of processing where accuracy is disputed
  • request erasure of data no longer required
  • withdraw consent at any time
  • object to the processing of their data
  • lodge a complaint with the Information Commissioner’s Office (ICO)

11. Further Processing

If personal data needs to be used for a new purpose not covered by this policy, a new privacy notice will be issued and consent sought where required.

12. Contact Details

For concerns or queries about how your data is held or used, please contact: Gill Bennie Email: [email protected] Tel: 07845 445716