In order to operate, Godalming Choral Society needs to gather, store and use certain forms of information about individuals.

These can include members, employees, contractors, suppliers, volunteers, audiences and potential audiences, business contacts and other people the group has a relationship with or regularly needs to contact.

This policy explains how this data should be collected, stored and used in order to meet Godalming Choral Society’s data protection standards and comply with the law.

Why is this policy important?

This policy ensures that Godalming Choral Society:
• Protects the rights of our members, volunteers and supporters
• Complies with data protection law and follows good practice
• Protect the group from the risks of a data breach

Who and what does this policy apply to?

This applies to all those handling data on behalf of Godalming Choral Society, e.g.:
• Trustees
• Volunteers
• Members
• 3rd-party suppliers

It applies to all data that Godalming Choral Society holds relating to individuals, including:

•  Names
•  Email addresses
• Postal addresses
• Phone numbers
• Any other personal information held (e.g. financial)

Roles and responsibilities

Everyone who has access to data as part of Godalming Choral Society has a responsibility to ensure that they adhere to this policy.

Data control

The Trustees, are responsible for why data is collected and how it will be used. Any questions relating to the collection or use of data should be directed to the Chairman or Treasurer.

1. We fairly and lawfully process personal data

Godalming Choral Society will only collect data where lawful and where it is necessary for the legitimate purposes of the group.

• A member’s name and contact details will be collected when they first join the group, and will be used to contact the member regarding group membership administration and activities. Other data may also subsequently be collected in relation to their membership, including on their payment history for ‘subs’.

• The name and contact details of volunteers, committee members, employees and contractors will be collected when they take up a position, and will be used to contact them regarding group administration related to their role.

Further information, including personal financial information and criminal records information may also be collected in specific circumstances where lawful and necessary (in order to process payment to the person or in order to carry out a DBS check).

• An individual’s name and contact details will be collected when they make a booking for an event. This will be used to contact them about their booking and to allow them entry to the event.

• An individual’s name, contact details and other details may be collected at any time (including when booking tickets or at an event), with their consent, in order for Godalming Choral Society to communicate with them about group activities, and/or for Direct Marketing. See ‘Direct Marketing’ below.

2. We only collect and use personal data for specified and lawful purposes.

When collecting data, Godalming Choral Society will always explain to the subject why the data is required and what it will be used for, e.g.
“Please enter your email address in the form below. We need this so that we can send you email updates for group administration including about rehearsal and concert schedules, subs payments and other business.”

We will never use data for any purpose other than that stated or that can be considered reasonably to be related to it. For example, we will never pass on personal data to 3rd parties without the explicit consent of the subject.

3. We ensure any data collected is relevant and not excessive

Godalming Choral Society will not collect or store more data that the minimum information required for its intended purpose.
E.g. we need to collect telephone numbers from members in order to be able to contact them about group administration, but data on their marital status or sexuality will not be collected, since it is unnecessary and excessive for the purposes of group administration.

4. We ensure data is accurate and up-to-date

Godalming Choral Society will ask members, volunteers and staff to check and update their data on an annual basis.
Any individual will be able to update their data at any point by contacting the Trustees.

5. We ensure data is not kept longer than necessary

Godalming Choral Society will keep data on individuals for no longer than 12 months after our involvement with the individual has stopped, unless there is a legal requirement to keep records (e.g. for HMRC purposes).

6. We process data in accordance with individuals’ rights

The following requests can be made in writing to the Trustees:

• Members, volunteers and supporters can request to see any data stored on about them. Any such request will be actioned within 28 days of the request being made.

• Members and supporters can request that any inaccurate data held on them is updated. Any such request will be actioned within 28 days of the request being made.

• Members and supporters can request to stop receiving any marketing communications. Any such request will be actioned within 28 days of the request being made.

• Members and supporters can object to any storage or use of their data that might cause them substantial distress of damage or any automated decisions made based on their data. Any such objection will be considered by the Trustees, and a decision communicated within 30 days of the request being made

7. We keep personal data secure

Godalming Choral Society will ensure that data held by us is kept secure.

• Electronically-held data will be held within a password-protected and secure environment

• Passwords for access to electronic data files will be removed when an individual with data access leaves their role/position and generic logins e.g. used to access data will be updated with new passwords.

• Physically-held data (e.g. membership forms, or Gift Aid declarations) will be held at their home address with the relevant trustee and not transported unless absolutely necessary. The policy of the society will be to hold the minimum amount of data in paper form. All physically held data will be handed over to the nominated officer when a person resigns their position.

• Access to data will only be given to relevant trustees/ members/contractors where it is clearly necessary for the running of the group. The Trustees will decide in what situations this is applicable and will keep a master list of who has access to data

8. Transfer to countries outside the EEA

Godalming Choral Society will not transfer data to countries outside the European Economic Area (EEA), unless the country has adequate protection for the individual.

We only share members’ data with other members with the subject’s prior consent
As a membership organisation Godalming Choral Society encourages communication between members.

To facilitate this:

• Godalming Choral Society will from time to time issue by email a members list with the name, address, telephone number and email of other members. The name of the member will only be included where they have provided consent for inclusion. Data will be sent via a password protected document. The password will be provided separately.

Godalming Choral Society will regularly collect data from consenting supporters for marketing purposes. This includes contacting them to promote concerts, updating them about group news, fundraising and other group activities.

Any time data is collected for this purpose, we will provide:

• A clear and specific explanation of what the data will be used for (e.g. ‘Tick this box if you would like Godalming Choral Society to send you email updates with details about our forthcoming events, fundraising activities and opportunities to get involved’)

• A method for users to show their active consent to receive these communications (e.g. a ‘tick box’)

Data collected will only ever be used in the way described and consented to (e.g. we will not use email data in order to market 3rd-party products unless this has been explicitly consented to).

Every marketing communication will contain a method through which a recipient can withdraw their consent (e.g. an ‘unsubscribe’ link in an email). Opt-out requests such as this will be processed within 14 days.

A cookie is a small text file that is downloaded onto ‘terminal equipment’ (e.g. a computer or smartphone) when the user accesses a website. It allows the website to recognise that user’s device and store some information about the user’s preferences or past actions.
Godalming Choral Society will be implementing cookies on the website during 2018 in order to monitor and record their activity. This allows us to improve users’ experience of our website by, for example, allowing for a ‘logged in’ state, and by giving us useful insight into how users as a whole are engaging with the website.

The cookies will only be used for Google Analytics and there will be no ability to track individual users as we will be utilising the ‘anonymised’ data version.

Any queries can be addressed to:

Last updated May 2018