General Data Protection Regulation
The General Data Protection Regulation (GDPR) and Data Protection Act 2018 enables organisations to collect personal information, provided it is required for a specific purpose and disposed of when no longer needed or relevant. For varying reasons local churches, circuits and districts find themselves holding a variety of personal data and it is important that they ensure they remain complaint with the law. There is a legal responsibility to ensure that churches, circuits and districts are keeping the data and personal information of individuals up to date and safe.
The Trustees for Methodist Church Purposes (TMCP) act as the Data Controller for local Methodist churches, circuits and districts and provide information and guidance on Data Protection in the Methodist Church. This guidance helps the Managing Trustees to identify what personal data is, how to hold it securely and understand the purposes that personal data can be used. This includes Circuit and District directories.
As part of this, managing trustees of churches, circuits and districts are required to complete a GDPR Annual Checklist which acts as an annual data review and is submitted to TMCP as part of their role as Data Controller to support compliance with the regulations.
Please click here for a brief guide relating to GDPR and church/circuit responsibilities.
Please also visit the TMCP website for further information and guidance.
Eight Key Principles of Data Protection
Openness
Be open about personal data practices
Collection Limited
Collection of personal data must be limited, lawful and fair
For a Specific Purpose
Purpose of collection and disclosure must be specified
Use Limited
Use of data must be for the purpose specified
Security
Personal data must be subject to appropriate safeguards
Data Quality
Personal data must be relevant, accurate and up-to-date
Access and Correction
People must be able to access and correct their data
Accountability
Data controllers must comply with the data protection principles
Seven Golden Rules of Information Sharing
Necessary
Remember that the Data Protection Act is not a barrier to sharing information
Proportionate
Be open and honest
Relevant
Seek advice where necessary
Adequate
Share with consent where possible and respect the wishes of those who do not wish to consent if appropriate
Accurate
Always consider safety and wellbeing; of the individual and others
Timely
Ensure information shared meets these principles
Secure
Record your decision; whether this is to share or not
