Art Branches CIC is committed to protecting the privacy and personal data of its staff, members, and users of its services. This Data Protection Policy outlines how we collect, use, and safeguard personal data to ensure compliance with the UK GDPR and other applicable data protection laws.
This policy applies to the following individuals and groups:
• Art Branches staff, including both paid and unpaid personnel.
• Art Branches service users.
• Art Branches Directors.
Art Branches is dedicated to upholding the principles of data protection as outlined in the UK GDPR. Personal data will be:
• Obtained and processed lawfully, transparently, and for specified, explicit, and legitimate purposes.
• Adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
• Accurate and, where necessary, kept up to date.
• Retained for no longer than is necessary for the intended purposes.
• Processed in accordance with the rights of data subjects.
• Kept secure from unauthorised access, accidental loss, or destruction.
• Not transferred outside of the United Kingdom unless the recipient country ensures an equivalent level of data protection.
All staff who process personal information must adhere to these principles at all times. Any staff member who believes that this procedure has not been followed should report it to the Data Protection Officer (DPO). If the matter remains unresolved, it should be raised as a formal grievance. Service users should follow the organisation's complaints procedure for data protection concerns.
All individuals have the following rights regarding their personal data:
• The right to be informed about what data Art Branches holds and the purposes for processing it. • The right to access their personal data.
• The right to rectify inaccuracies in their personal data.
• The right to erasure (the right to be forgotten) under certain circumstances.
• The right to restrict processing under certain circumstances.
• The right to data portability.
• The right to object to processing under certain circumstances.
• The right not to be subject to automated decision-making, including profiling.
Art Branches will ensure that personal and sensitive information is stored securely. Access to this information will be limited to authorised personnel and protected with passwords if stored electronically. When transmitting data electronically, additional security measures will be taken to ensure that only authorised recipients have access.
• Personal Information: Any information related to an identifiable individual, including but not limited to names, addresses, email addresses, and telephone numbers.
• Sensitive Information: Data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, sexual orientation, and criminal records. The processing of sensitive information requires explicit consent from the data subject or must be authorised by law.
Art Branches has appointed a Data Protection Officer (DPO) (Stephanie Hartick) responsible for ensuring compliance with data protection laws, monitoring data protection activities, and acting as a point of contact for data subjects and supervisory authorities.
Art Branches will review and update this policy regularly, at least biennially, or as needed to ensure alignment with current data protection legislation and organisational needs.