To ensure transparency, here is the LCI policy determining how your data may be used and stored.

Purpose

Leeds Church Institute is committed to protecting the privacy and rights of individuals whose data we collect and process. The organisation complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) and the Computer Misuse Act 1990.

Scope

This policy applies to all trustees, staff, freelancers, contractors, and anyone working on behalf of the charity.

Principles of Data Protection

Leeds Church Institute adheres to the following principles:

  • Lawfulness, fairness, and transparency

  • Purpose limitation

  • Data minimisation

  • Accuracy

  • Storage limitation

  • Integrity and confidentiality

  • Accountability

Lawful Bases for Processing

Leeds Church Institute processes personal data under one or more of the following lawful bases:

  • Consent

  • Contract

  • Legal obligation

  • Vital interests

  • Public task

  • Legitimate interests

Individual Rights

Data subjects have the right to:

  • Be informed

  • Access their data

  • Rectify inaccuracies

  • Erase data (“right to be forgotten”)

  • Restrict processing

  • Data portability

  • Object to processing

  • Avoid automated decision-making

Data Collection and Use

Leeds Church Institute collects personal data only for specified, legitimate purposes, such as:

  • Managing staff, freelancers and contractors

  • Communicating with donors and beneficiaries

  • Mailing Leeds Church Institute publications

  • Running campaigns and events

Data Retention

Personal data is retained only as long as necessary. We maintain a retention schedule and review data regularly in compliance with legal and regulatory requirements, as well as best practice.

Data Security

Leeds Church Institute implements appropriate technical and organisational measures to protect data, including:

  • Password protection

  • Secure cloud storage in a safe location e.g. UK or European Union

  • Access controls

  • Regular backups

Data Breaches

  • Any data breach will be reported immediately to the Leeds Church Institute Data Protection Officer within 24 hours of identifying the breach - this includes weekends. In the absence of the Data Protection Officer the breach must be reported to the Director within the same time period of 24 hours.

  • Leeds Church Institute will maintain an incident log and follow ICO reporting procedures and time restrictions.

Third Party Access

Leeds Church Institute will ensure that any third-party processors comply with UK GDPR and have appropriate data protection agreements in place.

Safe Email Use Guidance

To comply with the GDPR, PECR and the Computer Misuse Act 1990, and to avoid common data breaches, Leeds Church Institute staff, trustees and anyone working on behalf of the charity will follow:

  • General Email Practices

    • Use Leeds Church Institute email accounts for all LCI communications.

    • Avoid sending sensitive personal data via email unless encrypted.

    • Include a confidentiality notice in email footers.

    • Keep software and antivirus protection up to date.

    • Lock devices when unattended and avoid using public Wi-Fi for sensitive communications

  • Bulk Emailing

    • not use BCC for bulk emails containing sensitive data, but instead use:

    • Mail merge tools

    • secure bulk email platforms (e.g., Mailchimp)

    • encrypted file sharing and secure data transfer services for attachments

  • Handling Personal Data via Email

    • Do not send sensitive personal data (e.g. health, ethnicity, sexual orientation) via email unless absolutely necessary and encrypted.

    • Use password-protected attachments and share passwords via a separate channel.

    • Avoid forwarding emails containing personal data unless required and permitted.

  • Email Content Best Practices

    • Include a confidentiality notice in email footers.

    • Use clear, respectful language.

    • Avoid sharing personal email addresses without permission.

    • Include an unsubscribe option in bulk or marketing emails.

  • Consent for Email Marketing

    • Under PECR and GDPR, Leeds Church Institute must:

      • Obtain explicit, informed consent before sending marketing emails.

    • Keep records of:

      • When and how consent was given

      • What type of communication was agreed to

      • Ensure consent is freely given, specific, and unbundled from other terms

  • Email Security Tips

    • Enable two-factor authentication on email accounts.

    • Train staff and volunteers on phishing and email safety.

    • Avoid clicking suspicious links or downloading unknown attachments.

Review

This policy will be reviewed annually by the Board of Trustees, or by parties delegated this responsibility by the Board, or sooner if legislation changes, operational needs evolve, when

significant changes occur in social media platforms or feedback indicates a need for revision. In all cases the Board of Trustees will issue final approval of this, and all policies.

Privacy Notice