Data Protection and Privacy Policy

  1. Policy Statement
    Runners Media CIC is committed to protecting the privacy and personal information of everyone who engages with our organisation. We recognise that trust is fundamental to our work and that personal data must be handled lawfully, fairly, securely and transparently. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable UK privacy legislation. This policy explains how personal data is collected, used, stored, shared and protected throughout our activities.
  2. Purpose
    The objectives of this policy are to:
     Comply with UK data protection legislation.
     Protect the rights and freedoms of individuals.
     Promote transparency and accountability.
     Minimise the risk of data breaches.
     Ensure secure handling of personal information.
     Maintain public confidence in Runners Media CIC.
  3. Scope
    This policy applies to:
     Directors
     Employees
     Volunteers
     Freelancers
     Contractors
     Consultants
     Project participants
     Service users
     Donors
     Funders
     Partner organisations processing data on behalf of Runners Media CIC
    It covers all personal information held in:
     Electronic systems
     Email
     Cloud storage
     Paper records
     Audio recordings
     Video recordings
     Photographs
     Social media platforms
     Mobile devices
  4. Definitions
    Personal Data
    Any information relating to an identified or identifiable living person.
    Special Category Data
    Sensitive personal information including:
     Racial or ethnic origin
     Political opinions
     Religious beliefs
     Trade union membership
     Health information
     Biometric data
     Genetic data
     Sexual orientation
     Sex life
    Processing
    Any activity involving personal data, including collecting, recording, storing, using, sharing
    or deleting information.
    Data Subject
    The individual whose personal information is being processed.
    Data Controller
    Runners Media CIC.
    Data Processor
    A third party processing information on behalf of Runners Media CIC.
  5. Data Protection Principles
    Runners Media CIC will ensure personal data is:
     Processed lawfully, fairly and transparently.
     Collected for specified, explicit and legitimate purposes.
     Limited to what is necessary.
     Accurate and kept up to date.
     Retained only as long as necessary.
     Kept secure through appropriate technical and organisational measures.
     Processed in a manner that demonstrates accountability.
  6. Lawful Bases for Processing
    We process personal data under one or more of the lawful bases defined by UK GDPR:
     Consent
     Contract
     Legal obligation
     Legitimate interests
     Vital interests
     Public task (where applicable)
    Special Category Data will only be processed where an additional lawful condition applies.
  7. Types of Information We Collect
    Depending on our activities, we may collect:
     Name
     Postal address
     Email address
     Telephone number
     Date of birth where required
     Emergency contact details
     Volunteer applications
     Employment information
     DBS information where applicable
     Attendance records
     Photographs
     Audio recordings
     Video recordings
     Website analytics
     Cookies
     Social media interactions
     Funding monitoring information
     Equality and diversity monitoring information where appropriate
    We only collect information that is necessary for legitimate organisational purposes.
  8. Media, Photography and Filming
    As a community media organisation, we regularly produce photographs, audio recordings and
    video content.
    We will:
     Obtain appropriate consent where required.
     Respect requests not to be photographed where practical.
     Obtain parental or guardian consent for children where legally required.
     Explain how media will be used.
     Store media securely.
     Remove content where legally required or appropriate.
    Editorial journalism may be subject to exemptions under UK data protection law where applicable.
  9. Data Security
    We will protect personal information by:
     Using password-protected systems.
     Applying multi-factor authentication where available.
     Encrypting sensitive information where appropriate.
     Restricting access to authorised personnel.
     Locking paper files securely.
     Using secure cloud storage.
     Maintaining anti-virus and software updates.
     Securely disposing of confidential information.
     Regularly reviewing security arrangements.
  10. Sharing Personal Data
    We do not sell personal information.
    We may share data where necessary with:
     Funding organisations
     Professional advisers
     Payroll providers
     Cloud service providers
     IT support providers
     Banks
     Insurance providers
     Regulators
     Law enforcement agencies
     Local authorities
     Safeguarding agencies
    Any sharing will only occur where there is a lawful basis.
    Where third parties process data on our behalf, appropriate contractual safeguards will be in place.
  11. International Transfers
    Where personal data is transferred outside the UK, Runners Media CIC will ensure
    appropriate safeguards are in place in accordance with UK GDPR.
  12. Individual Rights
    Individuals have the right to:
     Be informed.
     Access their personal information.
     Correct inaccurate information.
     Request erasure where applicable.
     Restrict processing.
     Object to processing.
     Request data portability where applicable.
     Withdraw consent where consent is relied upon.
     Complain to the Information Commissioner’s Office (ICO).
    Requests should normally be responded to within one calendar month.
  13. Data Retention
    Personal information will only be retained for as long as necessary.
    Typical retention periods include:
    Record Type Retention Period
    Employee records Six years after employment ends
    Volunteer records Six years after volunteering ends
    Financial records Six years plus current financial year
    Funding records As required by funding agreements (normally six years)
    DBS records In accordance with DBS guidance
    Safeguarding records As required by safeguarding legislation and guidance
    Mailing list data Until consent is withdrawn or no longer required
    Secure destruction methods will be used when retention periods expire.
  14. Data Breaches
    Any actual or suspected data breach must be reported immediately to the Director or
    nominated Data Protection Lead.
    The organisation will:
     Investigate the incident.
     Contain any ongoing risk.
     Maintain breach records.
     Notify affected individuals where appropriate.
     Report notifiable breaches to the Information Commissioner’s Office within 72 hours
    where legally required.
  15. Children’s Data
    Where activities involve children or young people, additional safeguards will apply.
    We will:
     Obtain appropriate consent where required.
     Collect only necessary information.
     Protect children’s privacy.
     Follow safeguarding procedures alongside this policy.
  16. Responsibilities
    Directors
    Responsible for:
     Overall compliance.
     Reviewing this policy.
     Ensuring appropriate resources.
     Monitoring data protection risks.
    Data Protection Lead
    Responsible for:
     Advising the organisation.
     Managing Subject Access Requests.
     Coordinating breach responses.
     Supporting staff.
     Maintaining compliance.
    Staff, Volunteers and Contractors
    Everyone handling personal data must:
     Follow this policy.
     Keep information secure.
     Report breaches immediately.
     Complete required training.
     Only access information needed for their role.
  17. Training
    Appropriate data protection training will be provided for staff and volunteers handling
    personal information.
    Training may include:
     UK GDPR principles
     Confidentiality
     Password security
     Recognising phishing attacks
     Secure handling of personal information
     Subject Access Requests
     Data breach reporting
  18. Monitoring and Compliance
    Compliance will be monitored through:
     Internal reviews
     Policy audits
     Incident reporting
     Staff training records
     Risk assessments
    Where appropriate, corrective actions will be implemented promptly.
  19. Related Policies
    This policy should be read alongside:
     Privacy Notice
     Safeguarding Policy
     Information Security Policy
     Data Retention Policy
     Equality, Diversity and Inclusion Policy
     Social Media Policy
     Complaints Policy
     Volunteer Policy
     Whistleblowing Policy
  20. Policy Review
    This policy will be reviewed every two years or sooner if:
     Legislation changes.
     ICO guidance changes.
     Organisational practices change.
     Significant data protection incidents occur.
  21. Policy Statement
    Runners Media CIC recognises that protecting personal information is essential to
    maintaining the trust of our staff, volunteers, participants, funders, partners and the wider
    community.
    We are committed to processing personal data responsibly, securely and transparently,
    ensuring that privacy rights are respected while enabling us to deliver high-quality
    community media, education and engagement activities.
    Approved By
    Rumana Afroze Rakhi – Director
    Runners Media CIC (Reg: 15283707)