To ensure transparency, here is the LCI policy determining how your data may be used and stored.
Purpose
Leeds Church Institute is committed to protecting the privacy and rights of individuals whose data we collect and process. The organisation complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) and the Computer Misuse Act 1990.
Scope
This policy applies to all trustees, staff, freelancers, contractors, and anyone working on behalf of the charity.
Principles of Data Protection
Leeds Church Institute adheres to the following principles:
Lawfulness, fairness, and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability
Lawful Bases for Processing
Leeds Church Institute processes personal data under one or more of the following lawful bases:
Consent
Contract
Legal obligation
Vital interests
Public task
Legitimate interests
Individual Rights
Data subjects have the right to:
Be informed
Access their data
Rectify inaccuracies
Erase data (“right to be forgotten”)
Restrict processing
Data portability
Object to processing
Avoid automated decision-making
Data Collection and Use
Leeds Church Institute collects personal data only for specified, legitimate purposes, such as:
Managing staff, freelancers and contractors
Communicating with donors and beneficiaries
Mailing Leeds Church Institute publications
Running campaigns and events
Data Retention
Personal data is retained only as long as necessary. We maintain a retention schedule and review data regularly in compliance with legal and regulatory requirements, as well as best practice.
Data Security
Leeds Church Institute implements appropriate technical and organisational measures to protect data, including:
Password protection
Secure cloud storage in a safe location e.g. UK or European Union
Access controls
Regular backups
Data Breaches
Any data breach will be reported immediately to the Leeds Church Institute Data Protection Officer within 24 hours of identifying the breach - this includes weekends. In the absence of the Data Protection Officer the breach must be reported to the Director within the same time period of 24 hours.
Leeds Church Institute will maintain an incident log and follow ICO reporting procedures and time restrictions.
Third Party Access
Leeds Church Institute will ensure that any third-party processors comply with UK GDPR and have appropriate data protection agreements in place.
Safe Email Use Guidance
To comply with the GDPR, PECR and the Computer Misuse Act 1990, and to avoid common data breaches, Leeds Church Institute staff, trustees and anyone working on behalf of the charity will follow:
General Email Practices
Use Leeds Church Institute email accounts for all LCI communications.
Avoid sending sensitive personal data via email unless encrypted.
Include a confidentiality notice in email footers.
Keep software and antivirus protection up to date.
Lock devices when unattended and avoid using public Wi-Fi for sensitive communications
Bulk Emailing
not use BCC for bulk emails containing sensitive data, but instead use:
Mail merge tools
secure bulk email platforms (e.g., Mailchimp)
encrypted file sharing and secure data transfer services for attachments
Handling Personal Data via Email
Do not send sensitive personal data (e.g. health, ethnicity, sexual orientation) via email unless absolutely necessary and encrypted.
Use password-protected attachments and share passwords via a separate channel.
Avoid forwarding emails containing personal data unless required and permitted.
Email Content Best Practices
Include a confidentiality notice in email footers.
Use clear, respectful language.
Avoid sharing personal email addresses without permission.
Include an unsubscribe option in bulk or marketing emails.
Consent for Email Marketing
Under PECR and GDPR, Leeds Church Institute must:
Obtain explicit, informed consent before sending marketing emails.
Keep records of:
When and how consent was given
What type of communication was agreed to
Ensure consent is freely given, specific, and unbundled from other terms
Email Security Tips
Enable two-factor authentication on email accounts.
Train staff and volunteers on phishing and email safety.
Avoid clicking suspicious links or downloading unknown attachments.
Review
This policy will be reviewed annually by the Board of Trustees, or by parties delegated this responsibility by the Board, or sooner if legislation changes, operational needs evolve, when
significant changes occur in social media platforms or feedback indicates a need for revision. In all cases the Board of Trustees will issue final approval of this, and all policies.
Privacy Notice