1. Purpose of the policy
1.1 Total Insight Theatre is committed to protecting personal information and being transparent about what information we hold. We, therefore, comply with legislation including:
(a) the General Data Protection Regulation (“the GDPR”) and any related legislation which applies in the UK, including, without limitation, any legislation derived from the Data Protection Bill 2017;
(b) the Privacy and Electronic Communications Regulations (2003) and any successor or related legislation, including without limitation, E-Privacy Regulation 2017/0003; and
(c) all other applicable laws and regulations relating to the processing of personal data and privacy, including statutory instruments and, where applicable, the guidance and codes of practice issued by the Information Commissioner’s Office (“ICO”) or any other supervisory authority.
(together “the Legislation”)
1.2 This policy sets out what we do to protect individuals’ personal data.
1.3 Anyone who handles personal data in any way on behalf of Total Insight Theatre will ensure that we comply with this policy. Section 3 of this policy describes what comes within the definition of “personal data”. Any breach of this policy will be taken seriously and may result in disciplinary action or more serious sanctions.
1.4 This policy may be amended from time to time to reflect any changes in legislation, regulatory guidance or internal policy decisions.
2. About this policy
2.1 The types of personal data that we may handle include details of Staff, Volunteers, Freelancers, Service Users or Donors. We collect and store personal and non-personal data that individuals may volunteer as part of working with us, booking activities, making donations, visiting our website, visitor surveys or in connection with a specific project or event. By disclosing personal information to us via http://www.totalinsighttheatre.com, in writing or by phone, individuals are giving us consent to collect, store and process personal information in the manner described in this policy. The information we hold will be accurate and up-to-date within our knowledge.
2.2 Personal information we collect may include:
(a) Full name and title and date of birth;
(b) Postal address, email address and phone number;
(c) IP (internet protocol) address;
(d) Gift Aid status;
(e) Bank details;
(f) Payment card details; and
(g) Contact and communication preferences.
2.3 Non-personal information we collect includes:
(a) IP addresses (the location of the computer on the internet);
(b) web pages accessed; and files downloaded. This helps us to determine how many people use our website, how regularly they visit, and how popular our webpages are. This information does not tell us anything about who individuals are and only discloses which country individuals live in, helping us monitor and improve our service.
2.4 We are particularly committed to safeguarding children, young people and vulnerable adults and do all we can to ensure that all who work at or with Total Insight Theatre, including volunteers, whether on stage or joining an education project, are safe and inspired by their experience. An important part of doing this is to protect their privacy. Therefore, if individuals are aged 16 or under and participate in any of our projects, we ensure that we obtain their parent or guardian’s permission every time before they provide any personal information; we will always require their parent or guardian’s signature on any documentation before signing up to a Total Insight Theatre project. We will always require the carer’s signature on similar documentation relating to vulnerable adults.
2.5 When fundraising, we may undertake research to explore shared interests with potential supporters. We will not use third-party profiling companies but may use profiling and screening techniques ourselves to analyse any personal data and create a profile of individuals’ or business’ interests and preferences if these are publicly available (for example through LinkedIn, Companies House, Charity Commission).
2.6 While we cannot ensure or guarantee that loss, misuse or alteration of data will not occur when it is under our control, we will use our best efforts to prevent this. In case of any questions regarding this policy, please get in touch. Any questions or concerns about this policy should be referred in the first instance to info[at]totalinsighttheatre.com.
3. Definitions of key terms
3.1 The following terms will be used in this policy and are defined below:
3.2 Data Subjects include all living individuals about whom we hold personal data, for instance an employee or a supporter. A data subject need not be a UK national or resident. All data subjects have legal rights in relation to their personal data.
3.3 Personal Data means any information relating to a living person who can be identified directly or indirectly from that information (or from that information and other information in our possession). Personal data can be factual (such as a name, address or date of birth) or it can be an opinion (such as a performance appraisal). It can also include an identifier such as an identification number, location data, an online identifier specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
3.4 Data Controllers are the people who, or organisations which, decide the purposes and the means for which, any personal data is processed. They have a responsibility to process personal data in compliance with the Legislation. Total Insight Theatre is the data controller of all personal data that we manage in connection with our work and activities.
3.5 Data Processors include any person who processes personal data on behalf of a data controller. Employees of data controllers are excluded from this definition but it could include other organisations such as website hosts, fulfilment houses or other service providers which handle personal data on our behalf.
3.6 European Economic Area includes all countries in the European Union as well as Norway, Iceland and Liechtenstein.
3.7 ICO means the Information Commissioner’s Office (the authority which oversees data protection regulation in the UK).
3.8 Processing is any activity that involves use of personal data, whether or not by automated means. It includes but is not limited to:
(f) adapting or altering;
(h) disclosing by transmission;
(i) disseminating or otherwise making available;
(j) alignment or combination;
(l) erasing; or
(m) destruction of personal data.
3.9 Sensitive Personal Data (which is defined as “special categories of personal data” under the GDPR) includes information about a person’s:
(a) racial or ethnic origin;
(b) political opinions;
(c) religious, philosophical or similar beliefs;
(d) trade union membership;
(e) physical or mental health or condition;
(f) sexual life or orientation;
(g) genetic data;
(h) biometric data; and
(i) such other categories of personal data as may be designated as “special categories of personal data” under the Legislation.
4. Data protection principles
4.1 When processing personal data we comply with the six data protection principles set out in the GDPR. We are required to comply with these principles (summarised below), and show that we comply, in respect of any personal data that we deal with as a data controller.
4.2 Personal data should be:
(a) processed fairly, lawfully and transparently;
(b) collected for specified, explicit and legitimate purposes and not further processed in a way which is incompatible with those purposes;
(c) adequate, relevant and limited to what is necessary for the purpose for which it is held;
(d) accurate and, where necessary, kept up to date;
(e) not kept longer than necessary; and
(f) processed in a manner that ensures appropriate security of the personal data.
5. Processing data fairly and lawfully
5.1 The first data protection principle requires that personal data is obtained fairly and lawfully and processed for purposes that the data subject has been told about. Processing will only be lawful if certain conditions can be satisfied, including where the data subject has given consent, or where the processing is necessary for one or more specified reasons, such as where it is necessary for the performance of a contract or agreement.
5.2 To comply with this principle, when we receive personal data about a person directly from that individual, which we intend to keep, we will provide that person with “the fair processing information”. In other words we will tell them:
(a) the type of information we will be collecting (categories of personal data concerned);
(b) who will be holding their information, i.e. Total Insight Theatre including contact details and the contact details of our Data Protection Officer (if we have one);
(d) the legal basis for collecting their information (for example, are we relying on their consent, or on our legitimate interests or on another legal basis);
(e) if we are relying on legitimate interests as a basis for processing what those legitimate interests are;
(f) whether the provision of their personal data is part of a statutory or contractual obligation and details of the consequences of the data subject not providing that data;
(g) the period for which their personal data will be stored or, where that is not possible, the criteria that will be used to decide that period;
(h) details of people or organisations with whom we will be sharing their personal data;
(i) if relevant, the fact that we will be transferring their personal data outside the EEA and details of relevant safeguards; and
(j) the existence of any automated decision-making including profiling in relation to that personal data.
5.3 Where we obtain personal data about a person from a source other than the person themself, we will provide that individual with the following information in addition to that listed under 5.2 above:
(a) the categories of personal data that we hold;
(b) the source of the personal data and whether this is a public source; and
(c) why we have collected their information and what we intend to do with it.
5.4 In addition, in both scenarios, (where personal data is obtained both directly and indirectly) we will also inform individuals of their rights outlined in section 9 below, including the right to lodge a complaint with the ICO and, the right to withdraw consent to the processing of their personal data.
5.5 This fair processing information can be provided in a number of places including on web pages, in mailings or on application forms. We will ensure that the fair processing information is concise, transparent, intelligible and easily accessible.
6. Processing data for the original purpose
6.1 The second data protection principle requires that personal data is only processed for the specific, explicit and legitimate purposes that the individual was told about when we first obtained their information.
6.2 This means that we will not collect personal data for one purpose and then use it for another. If it becomes necessary to process a person’s information for a new purpose, the individual will be informed of the new purpose beforehand For example, if we collect personal data such as a contact number or email address, in order to update a person about our activities it will not then be used for any new purpose, for example to share it with other organisations for marketing purposes, without first getting the individual’s consent.
7. Personal data should be adequate and accurate
7.1. The third and fourth data protection principles require that personal data that we keep should be accurate, adequate and relevant. Data will be limited to what is necessary in relation to the purposes for which it is processed. Inaccurate or out-of-date data will be destroyed securely, and we will take every reasonable step to ensure that personal data which is inaccurate is corrected.
8. Not retaining data longer than necessary
8.1. The fifth data protection principle requires that we should not keep personal data for longer than we need to for the purpose it was collected for. This means that the personal data that we hold will be destroyed or erased from our systems when it is no longer needed. If individuals think that we are holding out-of-date or inaccurate personal data, we ask them to speak to get in touch.
8.2. For guidance on how long particular types of personal data that we collect will be kept before being destroyed or erased, please get in touch or seek legal advice.
9. Rights of individuals under the GDPR
9.1 The GDPR gives people rights in relation to how organisations process their personal data. These include (but are not limited to) the right:
(a) to request a copy of any personal data that we hold about them (as data controller), as well as a description of the type of information that we are processing, the uses that are being made of the information, details of anyone to whom their personal data has been disclosed, and how long the data will be stored (known as subject access rights);
(b) to be told, where any information is not collected from the person directly, any available information as to the source of the information;
(c) to be told of the existence of automated decision-making;
(d) to object to the processing of data where the processing is based on either the conditions of public interest or legitimate interests;
(e) to have all personal data erased (the right to be forgotten) unless certain limited conditions apply;
(f) to restrict processing where the individual has objected to the processing;
(g) to have inaccurate data amended or destroyed; and
(h) to prevent processing that is likely to cause unwarranted substantial damage or distress to themselves or anyone else.
10. Data security
10.1. The sixth data protection principle requires that we keep secure any personal data that we hold.
10.2 We put in place procedures to keep the personal data that we hold secure, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
10.3 When we are dealing with sensitive personal data, more rigorous security measures are likely to be needed, for instance, if sensitive personal data (such as details of an individual’s health, race or sexuality) is held on a memory stick or other portable device it will always be encrypted.
10.4 When deciding what level of security is needed, our starting point is to look at whether the information is sensitive or highly confidential and how much damage could be caused if it fell into the wrong hands.
10.5 The following security procedures and monitoring processes will be followed in relation to all personal data processed by us: encryption of personal data; measures to restore availability and access to data in a timely manner in event of physical or technical incident; process for regularly testing, assessing and evaluating effectiveness of security measures; entry controls (any stranger seen in entry-controlled areas should be reported); staff will ensure that individual monitors do not show confidential information to passers-by and that they log off from their PC when it is left unattended; paper documents will be shredded, memory sticks, CD-ROMs and other media on which personal data is stored will be physically destroyed when they are no longer required; personal data will always be transferred in a secure manner (the degree of security required will depend on the nature of the data – the more sensitive and confidential the data, the more stringent the security measures should be) to ensure confidentiality, integrity, availability and resilience of processing systems; desks and cupboards will be kept locked if they hold confidential information of any kind (personal information is always considered confidential) and staff will keep data secure when travelling or using it outside the offices.
11. Processing sensitive personal data
11.1 On some occasions we may collect information about individuals that is defined by the GDPR as special categories of personal data, and special rules will apply to the processing of this data. In this policy we refer to “special categories of personal data” as “sensitive personal data”. The categories of sensitive personal data are set out in the definition in Section 3.9.
11.2 Purely financial information is not technically defined as sensitive personal data by the GDPR. However, particular care will be taken when processing such data, as the ICO will treat a breach relating to financial data very seriously.
11.3 In most cases, in order to process sensitive personal data, we must obtain explicit consent from the individuals involved. As with any other type of information we will also have to be absolutely clear with people about how we are going to use their information.
11.4 It is not always necessary to obtain explicit consent. There are a limited number of other circumstances in which the GDPR permits organisations to process sensitive personal data. If individuals are concerned that we are processing sensitive personal data and are not able to obtain explicit consent for the processing, we ask them to get in touch.
12.1 We recognise that whilst there is no obligation for us to make an annual notification to the ICO under the GDPR, we will consult with the ICO where necessary when we are carrying out “high risk” processing.
12.2 We will report breaches (other than those which are unlikely to be a risk to individuals) to the ICO where necessary, within 72 hours. We will also notify affected individuals where the breach is likely to result in a high risk to the rights and freedoms of these individuals.
13. Monitoring and review of the policy
13.1 This policy is reviewed annually to ensure that it is achieving its objectives.