General Data Protection Regulation

General Data Protection Regulation

The General Data Protection Regulation (GDPR) and Data Protection Act 2018 enables organisations to collect personal information, provided it is required for a specific purpose and disposed of when no longer needed or relevant. For varying reasons local churches, circuits and districts find themselves holding a variety of personal data and it is important that they ensure they remain complaint with the law. There is a legal responsibility to ensure that churches, circuits and districts are keeping the data and personal information of individuals up to date and safe.

The Trustees for Methodist Church Purposes (TMCP) act as the Data Controller for local Methodist churches, circuits and districts and provide information and guidance on Data Protection in the Methodist Church. This guidance helps the Managing Trustees to identify what personal data is, how to hold it securely and understand the purposes that personal data can be used. This includes Circuit and District directories.

As part of this, managing trustees of churches, circuits and districts are required to complete a GDPR Annual Checklist which acts as an annual data review and is submitted to TMCP as part of their role as Data Controller to support compliance with the regulations.

Please click here for a brief guide relating to GDPR and church/circuit responsibilities.

Please also visit the TMCP website for further information and guidance.

Eight Key Principles of Data Protection

Openness

Be open about personal data practices

Collection Limited

Collection of personal data must be limited, lawful and fair

For a Specific Purpose

Purpose of collection and disclosure must be specified

Use Limited

Use of data must be for the purpose specified

Security

Personal data must be subject to appropriate safeguards

Data Quality

Personal data must be relevant, accurate and up-to-date

Access and Correction

People must be able to access and correct their data

Accountability

Data controllers must comply with the data protection principles

Seven Golden Rules of Information Sharing

Necessary

Remember that the Data Protection Act is not a barrier to sharing information

Proportionate

Be open and honest

Relevant

Seek advice where necessary

Adequate

Share with consent where possible and respect the wishes of those who do not wish to consent if appropriate

Accurate

Always consider safety and wellbeing; of the individual and others

Timely

Ensure information shared meets these principles

Secure

Record your decision; whether this is to share or not