Data Protection and Privacy Policy
- Policy Statement
Runners Media CIC is committed to protecting the privacy and personal information of everyone who engages with our organisation. We recognise that trust is fundamental to our work and that personal data must be handled lawfully, fairly, securely and transparently. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable UK privacy legislation. This policy explains how personal data is collected, used, stored, shared and protected throughout our activities. - Purpose
The objectives of this policy are to:
Comply with UK data protection legislation.
Protect the rights and freedoms of individuals.
Promote transparency and accountability.
Minimise the risk of data breaches.
Ensure secure handling of personal information.
Maintain public confidence in Runners Media CIC. - Scope
This policy applies to:
Directors
Employees
Volunteers
Freelancers
Contractors
Consultants
Project participants
Service users
Donors
Funders
Partner organisations processing data on behalf of Runners Media CIC
It covers all personal information held in:
Electronic systems
Email
Cloud storage
Paper records
Audio recordings
Video recordings
Photographs
Social media platforms
Mobile devices - Definitions
Personal Data
Any information relating to an identified or identifiable living person.
Special Category Data
Sensitive personal information including:
Racial or ethnic origin
Political opinions
Religious beliefs
Trade union membership
Health information
Biometric data
Genetic data
Sexual orientation
Sex life
Processing
Any activity involving personal data, including collecting, recording, storing, using, sharing
or deleting information.
Data Subject
The individual whose personal information is being processed.
Data Controller
Runners Media CIC.
Data Processor
A third party processing information on behalf of Runners Media CIC. - Data Protection Principles
Runners Media CIC will ensure personal data is:
Processed lawfully, fairly and transparently.
Collected for specified, explicit and legitimate purposes.
Limited to what is necessary.
Accurate and kept up to date.
Retained only as long as necessary.
Kept secure through appropriate technical and organisational measures.
Processed in a manner that demonstrates accountability. - Lawful Bases for Processing
We process personal data under one or more of the lawful bases defined by UK GDPR:
Consent
Contract
Legal obligation
Legitimate interests
Vital interests
Public task (where applicable)
Special Category Data will only be processed where an additional lawful condition applies. - Types of Information We Collect
Depending on our activities, we may collect:
Name
Postal address
Email address
Telephone number
Date of birth where required
Emergency contact details
Volunteer applications
Employment information
DBS information where applicable
Attendance records
Photographs
Audio recordings
Video recordings
Website analytics
Cookies
Social media interactions
Funding monitoring information
Equality and diversity monitoring information where appropriate
We only collect information that is necessary for legitimate organisational purposes. - Media, Photography and Filming
As a community media organisation, we regularly produce photographs, audio recordings and
video content.
We will:
Obtain appropriate consent where required.
Respect requests not to be photographed where practical.
Obtain parental or guardian consent for children where legally required.
Explain how media will be used.
Store media securely.
Remove content where legally required or appropriate.
Editorial journalism may be subject to exemptions under UK data protection law where applicable. - Data Security
We will protect personal information by:
Using password-protected systems.
Applying multi-factor authentication where available.
Encrypting sensitive information where appropriate.
Restricting access to authorised personnel.
Locking paper files securely.
Using secure cloud storage.
Maintaining anti-virus and software updates.
Securely disposing of confidential information.
Regularly reviewing security arrangements. - Sharing Personal Data
We do not sell personal information.
We may share data where necessary with:
Funding organisations
Professional advisers
Payroll providers
Cloud service providers
IT support providers
Banks
Insurance providers
Regulators
Law enforcement agencies
Local authorities
Safeguarding agencies
Any sharing will only occur where there is a lawful basis.
Where third parties process data on our behalf, appropriate contractual safeguards will be in place. - International Transfers
Where personal data is transferred outside the UK, Runners Media CIC will ensure
appropriate safeguards are in place in accordance with UK GDPR. - Individual Rights
Individuals have the right to:
Be informed.
Access their personal information.
Correct inaccurate information.
Request erasure where applicable.
Restrict processing.
Object to processing.
Request data portability where applicable.
Withdraw consent where consent is relied upon.
Complain to the Information Commissioner’s Office (ICO).
Requests should normally be responded to within one calendar month. - Data Retention
Personal information will only be retained for as long as necessary.
Typical retention periods include:
Record Type Retention Period
Employee records Six years after employment ends
Volunteer records Six years after volunteering ends
Financial records Six years plus current financial year
Funding records As required by funding agreements (normally six years)
DBS records In accordance with DBS guidance
Safeguarding records As required by safeguarding legislation and guidance
Mailing list data Until consent is withdrawn or no longer required
Secure destruction methods will be used when retention periods expire. - Data Breaches
Any actual or suspected data breach must be reported immediately to the Director or
nominated Data Protection Lead.
The organisation will:
Investigate the incident.
Contain any ongoing risk.
Maintain breach records.
Notify affected individuals where appropriate.
Report notifiable breaches to the Information Commissioner’s Office within 72 hours
where legally required. - Children’s Data
Where activities involve children or young people, additional safeguards will apply.
We will:
Obtain appropriate consent where required.
Collect only necessary information.
Protect children’s privacy.
Follow safeguarding procedures alongside this policy. - Responsibilities
Directors
Responsible for:
Overall compliance.
Reviewing this policy.
Ensuring appropriate resources.
Monitoring data protection risks.
Data Protection Lead
Responsible for:
Advising the organisation.
Managing Subject Access Requests.
Coordinating breach responses.
Supporting staff.
Maintaining compliance.
Staff, Volunteers and Contractors
Everyone handling personal data must:
Follow this policy.
Keep information secure.
Report breaches immediately.
Complete required training.
Only access information needed for their role. - Training
Appropriate data protection training will be provided for staff and volunteers handling
personal information.
Training may include:
UK GDPR principles
Confidentiality
Password security
Recognising phishing attacks
Secure handling of personal information
Subject Access Requests
Data breach reporting - Monitoring and Compliance
Compliance will be monitored through:
Internal reviews
Policy audits
Incident reporting
Staff training records
Risk assessments
Where appropriate, corrective actions will be implemented promptly. - Related Policies
This policy should be read alongside:
Privacy Notice
Safeguarding Policy
Information Security Policy
Data Retention Policy
Equality, Diversity and Inclusion Policy
Social Media Policy
Complaints Policy
Volunteer Policy
Whistleblowing Policy - Policy Review
This policy will be reviewed every two years or sooner if:
Legislation changes.
ICO guidance changes.
Organisational practices change.
Significant data protection incidents occur. - Policy Statement
Runners Media CIC recognises that protecting personal information is essential to
maintaining the trust of our staff, volunteers, participants, funders, partners and the wider
community.
We are committed to processing personal data responsibly, securely and transparently,
ensuring that privacy rights are respected while enabling us to deliver high-quality
community media, education and engagement activities.
Approved By
Rumana Afroze Rakhi – Director
Runners Media CIC (Reg: 15283707)

