Data Retention Policy

MARY MACARTHUR HOLIDAY TRUST
2020

1. Introduction

This Policy sets out the obligations of Mary Macarthur Holiday Trust CharityTo Number 209989 of Unite House, 1 Cathedral Road, Cardiff CF11 9SD, (“the Charity”) regarding retention of personal data collected, held, and processed by the Charity in accordance with EU Regulation 2016/679 General Data Protection Regulation (“GDPR”).

The GDPR defines “personal data” as any information relating to an identified or identifiable natural person (a “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

The GDPR also addresses “special category” personal data (also known as “sensitive” personal data). Such data includes, but is not necessarily limited to, data concerning the data subject’s race, ethnicity, politics, religion, trade union membership, genetics, biometrics (if used for ID purposes), health, sex life, or sexual orientation.

Under the GDPR, personal data shall be kept in a form which permits the identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. In certain cases, personal data may be stored for longer periods where that data is to be processed for archiving purposes that are in the public interest, for scientific or historical research, or for statistical purposes (subject to the implementation of the appropriate technical and organisational measures required by the GDPR to protect that data).

In addition, the GDPR includes the right to erasure or “the right to be forgotten”. Data subjects have the right to have their personal data erased (and to prevent the processing of that personal data) in the following circumstances:

  1. Where the personal data is no longer required for the purpose for which it was originally collected or processed (see above);
  2. When the data subject withdraws their consent;
  3. When the data subject objects to the processing of their personal data and the Charity has no overriding legitimate interest;
  4. When the personal data is processed unlawfully (i.e. in breach of the GDPR);
  5. When the personal data has to be erased to comply with a legal obligation; or
  6. Where the personal data is processed for the provision of information society services to a child.

 

This Policy sets out the types) of personal data held by the Charity for its charitable purposes the periods for which that personal data is to be retained, the criteria for establishing and reviewing such periods and when and how it is to be deleted or otherwise disposed of.

For further information on other aspects of data protection and compliance with the GDPR, please refer to the Charity’s Data Protection Policy.

2. Aims and Objectives

2.1 The primary aim of this Policy is to set out limits for the retention of personal data and to ensure that those limits, as well as further data subject rights to erasure, are complied with. By extension, this Policy aims to ensure that the Charity complies fully with its obligations and the rights of data subjects under the GDPR.

2.2 In addition to safeguarding the rights of data subjects under the GDPR, by ensuring that excessive amounts of data are not retained by the Charity, this Policy also aims to improve the speed and efficiency of managing data.

3. Scope

3.1 This Policy applies to all personal data held by the Charity.

3.2 Personal data, as held by the Charity is stored in the following ways and in the following locations:

  1. A Computer permanently located in the Charity’s premises at Unite House, 1 Cathedral Road, Cardiff, CF11 9SB;
  2. Laptop computers owned by the Charity’s Treasurer and Administrator.
  3. Physical records stored in Unite House, 1 Cathedral Road, Cardiff, CF11 9SB and 22 Priory Gardens, Old Basing, Basingstoke RG24 7DS

4. Data Subject Rights and Data Integrity

All personal data held by the Charity is held in accordance with the requirements of the GDPR and data subjects’ rights thereunder, as set out in the Charity’s Data Protection Policy.

5. Data Disposal

Upon the expiry of the data retention periods set out below in Part 7 of this Policy, or when a data subject exercises their right to have their personal data erased, personal data shall be deleted, destroyed, or otherwise disposed of as follows:

5.1 Personal data stored electronically (including any and all backups thereof) shall be deleted.

5.2 Personal data stored in hardcopy form shall be shredded.

6. Data Retention

6.1 As required by law, the Charity shall not retain any personal data for any longer than is necessary in light of the purposes for which that data is collected, held, and processed.

6.2 When establishing and/or reviewing retention periods, the following shall be taken into account:

  1. The objectives and requirements of the Charity;
  2. The type of personal data in question;
  3. The purposes for which the data in question is collected, held, and processed;
  4. The Charity’s legal basis for collecting, holding, and processing that data;
  5. The category or categories of data subject to whom the data relates;


6.3 The retention periods are:

Data Ref. Type of Data Purpose of Data Retention Period
1
Applications for and decisions on grants.
To maintain a record of the Charity’s activities.
7 years from last correspondence with the applicant/beneficiary.
2
Financial Records
To record the financial transactions of the Charity
7 financial years
3
Correspondence with Donors and Potential Donors
To record the Charity’s fund raising activities.
7 years from the last correspondence
4
Details of and correspondence with members of the Committee of Management (Charity Trustees)
To record the Charity Trustees activities
7 years from the date the member ceased to be

7. Roles and Responsibilities

7.1 The Charity’s Data Protection Officer is Cheryl Andrews.

7.2 The Data Protection Officer shall be responsible for overseeing the implementation of this Policy and for monitoring compliance with this Policy, the Charity’s other Data Protection-related policies (including, but not limited to, its Data Protection Policy), and with the GDPR and other applicable data protection legislation.

7.3 The Data Protection Officer shall be directly responsible for ensuring compliance with the above data retention periods.

7.4 Any questions regarding this Policy, the retention of personal data, or any other aspect of GDPR compliance should be referred to the Data Protection Officer.

8. Implementation of Policy

This Policy shall be deemed effective as of 2020.

This Policy has been approved and authorised by the Committee of Management.

 

Signed:

Position: Chair of Trustees

Date: 2020

Due for Review by: August 2023