1. Introduction
Aged Christian Friend Society of Scotland (the Society) are committed to ensuring the secure and safe management of data held by the Society In relation to tenants, and other Individuals. The Society, any staff or any other third-party that the Society contract with in fulfilment of our landlord obligations have a responsibility to ensure compliance with the terms of this policy, and to manage Individuals’ data In accordance with the procedures outlined In this policy and documentation referred to herein.
We need to gather and use certain Information about Individuals. These can include customers (tenants) and other Individuals that we have a contractual relationship with. We manage a significant amount of data, from a variety of sources. This data contains “personal data” and “sensitive personal data” (known as “special categories of personal data” under the GDPR).
This policy sets out our duties in processing that data, and the purpose of this policy is to set out the procedures for the management of such data.
2. Data
2.1 We hold a variety of data relating to tenants, and staff and others (also referred to as “data subjects”) which is known as personal data. The personal data held and processed by the Society is detailed within the “fair processing notice” (FPN) at Appendix 2 hereto.
2.1.1 Personal data is that from which a living Individual can be Identified either by that data alone, or in conjunction with other data held by the Society.
3. Processing of personal data
3.1 We are permitted to process personal data on behalf of data subjects provided we are doing so on one of the following grounds:
• processing with the consent of the data subject (see clause 3.3 hereof);
• processing is necessary for the performance of a contract between the data subject and the Society, or for entering into a contract with the data subject.
• processing is necessary for the Society’s compliance with a legal obligation.
• processing is necessary to protect the vital Interests of the data subject or another person; or
• processing is necessary for the purposes of legitimate Interests.
3.2 Fair processing notice
3.2.1 The Society have produced a fair processing notice (FPN) which we are required to provide to all tenants, housing applicants and staff whose personal data Is held by the Society. The FPN must be provided to tenants, housing applicants and staff from the outset of processing their personal data and they should be advised of the terms of the FPN when it is provided to them.
3.2.2 The FPN at Appendix 1 sets out the personal data processed by the Society and the basis for that processing. This document is provided to all the Society’s tenants, housing applicants and staff at the outset of processing their data.
3.3 Consent
Consent as a ground of processing will require to be used from time to time by the Society when processing personal data. It should be used by the Society where no other alternative ground for processing is available. In the event that the Society require to obtain consent to process a data subject’s personal data, the Society shall obtain that consent In writing. The consent provided by the data subject must be freely given and the data subject will be required to sign a relevant consent form if willing to consent. Any consent to be obtained by the Society must be for a specific and defined purpose (I.e. general consent cannot be sought).
3.4 We will comply with all requirements for processing your personal data, as set out In the FPN.
4. Data sharing
4.1 The Society share your data with various third parties for numerous reasons In order that day-to-day activities are carried out In accordance with our relevant policies and procedures. In order that the Society can monitor compliance by these third parties with data protection laws, the Society will require the third-party organisations to enter into an agreement with the Society to govern the processing of data, security measures to be implemented and responsibility for breaches.
4.2 Data sharing
4.2.1 Personal data is from time to time shared amongst the Society and third parties who require to process personal data that the Society process as well. Both the third party and the Society will be processing that data in their Individual capacities as data controllers.
4.3 Data processors
A “data processor” Is a third-party entity that processes personal data on behalf of the Society and is frequently engaged If certain parts of our work are outsourced (e.g. maintenance and repair works).
4.3.1 A data processor must comply with data protection laws. The Society’s data processors must ensure they have appropriate technical security measures in place, maintain records of processing activities and notify the Society if a data breach is suffered.
4.3.2 If a data processor wishes to sub-contact their processing, the Society’s prior written consent must be obtained. Upon a sub-contracting of processing, the data processor will be liable in full for the data protection breaches of their sub-contractors.
4.3.3 Where the Society contract with a third party to process personal data held by them, the Society shall require the third party to enter in to a data processing agreement with them In accordance with the terms of the model data processing agreement set out In Appendix 2 to this policy. Should they not enter into this, the Society will provide them with the data protection statement of requirements for data processors. This will outline what the Society require from them as a data processor, acting on the Society’s behalf.
5. Data storage and security
All personal data held by the Society must be stored securely, whether electronically or in paper format.
5.1 Paper storage
If personal data is stored on paper it will be kept in a secure place where unauthorised personnel cannot access it. When the personal data is no longer required, it must be disposed of by the Society so as to ensure its destruction. If the personal data requires to be retained on a physical file then the Society will ensure that It is affixed to the file which is then stored In accordance with the Society’s storage provisions.
5.2 Electronic storage
Personal data stored electronically must also be protected from unauthorised use and access. Personal data should be password protected when being sent internally or externally to our data processors. If personal data Is stored on removable media (CD, DVD, USB memory stick) then that removable media will be stored securely at all times when not being used. Personal data will not be saved directly to mobile devices and will be stored on designated drivers and servers.
6. Breaches
6.1 A data breach can occur at any point when handling personal data and the Society have reporting duties In the event of a data breach or potential breach occurring. Breaches which pose a risk to the rights and freedoms of the data subjects who are subject of the breach require to be reported externally In accordance with Clause 6.3 hereof.
6.2 Internal reporting
The Society take the security of data very seriously and in the unlikely event of a breach, the Society will take the following steps:
• as soon as the breach or potential breach has occurred, the Society must consider (I) the breach and Its nature; (II) how It occurred; and (III) what the likely Impact of that breach Is on any data subject(s);
• The Society must seek to contain the breach by whatever means available.
• The Society must consider whether the breach is one, which requires to be reported to the ICO and data subjects affected and do so In accordance with clause 6.
• The Society will notify third parties In accordance with the terms of any applicable data sharing agreements.
6.3 Reporting to the ICO
The Society are required to report any breaches which pose a risk to the rights and freedoms of the data subjects who are subject of the breach to the ICO within 72 hours of becoming aware of the breach occurring. The Society must also consider whether it is appropriate to notify those data subjects affected by the breach.
7. Data subject rights
7.1 Certain rights are provided to data subjects under the GDPR. Data subjects are entitled to view the personal data held about them by the Society, whether in written or electronic form.
7.2 Data subjects have a right to request a restriction of processing their data, a right to be forgotten and a right to object to the Society processing their data. These rights are notified to tenants, housing applicants and staff in the Society’s fair processing notice.
7.3 Subject access requests
Data subjects are permitted to view their data held by the Society upon making a request to do so (a subject access request). Upon receipt of a request by a data subject, the Society must respond to the subject access request within one month of the date of receipt of the request.
7.3.1 The Society must provide the data subject with an electronic or hard copy of the personal data requested unless any exemption to the provision of that data applies in law.
7.3.2 Where the personal data comprises data relating to other data subjects, the Society must take reasonable steps to obtain consent from those data subjects to the disclosure of that personal data to the data subject who has made the subject access request.
7.3.3 Where the Society do not hold the personal data sought by the data subject, the Society must confirm that they do not hold any personal data sought by the data subject as soon as practicably possible, and In any event, not later than one month from the date on which the request was made.
7.4 The right to be forgotten
7.4.1 A data subject can exercise their right to be forgotten by submitting a request in writing to the Society seeking that the Society erase the data subject’s personal data In Its entirety.
7.4.2 Each request received by the Society will require to be considered on its own merits and legal advice will require to be obtained In relation to such requests from time to time. The Society will then have the responsibility for accepting or refusing the data subject’s request In accordance with this clause and will respond in writing to the request.
7.5 The right to restrict or object to processing
7.5.1 A data subject may request that the Society restrict the Society processing of the data subject’s personal data, or object to the processing of that data.
7.5.1.1 The Society will not share, sell or distribute any of the information you provide to us without your consent.
7.5.2 Each request received by the Society will require to be considered on its own merits and legal advice will require to be obtained In relation to such requests from time to time. The Society will then have responsibility for accepting or refusing the data subject’s request In accordance with clause 7.5 and will respond in writing to the request.
8. Data protection Impact assessments (DPIAs)
8.1 These are a means of assisting the Society in Identifying and reducing the risks that the Society’s operations have on personal privacy of data subjects.
8.2 The Society shall carry out a DPIA before undertaking a project or processing activity, which poses a high risk to an Individual’s privacy. High risk can include, but Is not limited to, activities using Information relating to health or race, or the Implementation of a new IT system for storing and accessing personal data.
8.2.1 In carrying out a DPIA, the Society shall include a description of the processing activity, its purpose, an assessment of the need for the processing, a summary of the risks Identified and the measures that they will take to reduce those risks, and details of any security measures that require to be taken to protect the personal data
8.3 The Society will require to consult the ICO In the event that a DPIA identifies a high level of risk, which cannot be reduced. The Society will be responsible for such reporting where such a high level of risk is identified.
9. Archiving, retention and destruction of data
The Society cannot store and retain personal data indefinitely. The Society will ensure that personal data is only retained for the period necessary. The Society shall ensure that all personal data is archived and destroyed timeously and at the point that the Society no longer need to retain that personal data In accordance with the periods specified within the table at Appendix 3 hereto.
List of appendices
GDPR Fair Processing Notice
HOW WE USE YOUR PERSONAL INFORMATION
We, the Aged Christian Friend Society of Scotland (ACFSOS), are the controller of the personal information that we hold about you, which means that we are legally responsible for how we hold and use personal information about you. It also means that we are required to comply with data protection laws when holding and using your personal information. As you know we take the issue of security and data protection seriously and strictly adhere to guidelines published in the Data Protection Act of 2018 and the General Data Protection Regulation (EU) 2016/679, together with any domestic laws subsequently enacted.
We have appointed a Privacy Officer, John Buchanan (Manager) Colinton Cottage Homes, who ensures that we comply with data protection laws. If you have any questions about this statement or how we hold or use your personal information. Please contact our Privacy Officer by e-mail: john@colintoncottages.org ; telephone on 0131-441-2286; or in writing to: The Privacy Officer, Colinton Cottage Homes, 4A Redford Road, Edinburgh, EH13 0AA
Your attention is particularly drawn to section 2 of this statement, which confirms that you consent to your personal information being held and used by us as described in section 1 of this statement.
1. What personal information do we hold and use about you and why?
As part of your tenancy agreement with us, we hold and use the personal information that you provided to us in your housing application form and the information that you completed on your Tenant Profile and other personal information that we may obtain from you.
We use such personal information for the following purposes:
We hold a copy of your housing application for a tenancy with Colinton Cottage Homes.
This information is transferred from hard copy to Colinton Cottage Homes data base system, which is password, protected and the hard copy is stored in a fire resistant filing cabinet accessed by a password code. When you advise us that you no longer wish to be on the waiting list then your application is deleted from our database and the hard copy disposed of safely by the Society.
Tenant Profile detailing;
This information is held on Colinton Cottage Homes database and is shared as described further in this statement. When your tenancy ends the information is held for a period of 6 months then deleted from Colinton Cottage Homes database.
As part of your tenancy agreement, we share your:
With ACFSOS’s Secretaries & Treasurers, Johnston Smillie Ltd, Chartered Accountants, 6 Redheughs Rigg, Edinburgh EH12 9DQ for the preparation and management of your tenancy agreement. Johnston Smillie hold your personal information in compliance with their regulator who are the Institute of Chartered Accountants of Scotland (ICAS).
As part of your tenancy agreement, we share your:
With Hanover Telecare, 95 McDonald Road, Edinburgh EH7 4NS who provide you with a 24hr emergency alarm call system in line with your Tenancy agreement. Hanover Telecare will hold your information in compliance with their retention policy.
As part of your tenancy agreement we, share your:
With the undernoted as required for your safety and comfort and to ensure compliance with landlord and other regulatory requirements.
2. What is our legal basis for holding and using your personal information?
By providing us with your personal information, you consent to it being used by us as described in section 1 of this statement.
Our basis in law for holding and using your personal information is your explicit consent and performance of the tenancy agreement that you have entered into with us. You have the right to withdraw your consent to our holding and using your personal information by contacting CCH Privacy Officer, John Buchanan. Once you have withdrawn your consent, we will no longer use your personal information for the purpose(s) you originally agreed to, unless we have another legal basis for doing so.
3. Who do we share your personal information with?
We share your personal information with the following for the purposes described in section I of this statement:
Unless required to do so by law, we will not otherwise share, sell or distribute any of the information you provide to us without your consent.
5. How long do we keep your personal information?
5. What rights do you have in relation to your personal information that we hold and use?
It is important that the personal information that we hold about you is accurate and current. Please keep us informed of any changes by contacting our Privacy Officer. Under certain circumstances, the law gives you the right to request:
You can also object to us holding and using your personal information where our legal basis is a legitimate interest, (either our legitimate interests or those of a third party as described in section 1).
Please contact our Privacy Officer if you wish to make any of the above requests. When you make a request, we may ask you for specific information to help us confirm your identity for security reasons.
6. Feedback and complaints
You have the right to make a complaint to the:
Information Commissioner’s Office – Scotland,
45 Melville Street,
Edinburgh,
EH3 7HL
Telephone: 0131 244 9001
Email: scotland@ico.org.uk
You can also use Colinton Cottage Homes Complaints Form.
The accuracy of your information is important to us – please help us keep our records updated by informing us of any changes to your personal information.
7. Security
When you give us information, we take steps to make sure that your personal information is kept secure and safe. We have an IT Consultant who ensures that our online communications with any third parties listed in this agreement are sent and received securely and are password protected. Information stored on Colinton Cottage Homes computers are password protected. Hard copies of your personal information are held in a heavy duty, fire resistant filing cabinet accessed by a password code.
8. Updates to this statement
We may update this statement at any time, and we will provide you with an updated version when are required to do so by law.