The Derby Railway Engineering Society (DRES / The Society) needs to gather and use certain information about its members.
This policy describes how members’ personal data is collected, handled, stored to meet the requirements of the General Data Protection Regulations 2018.
The Policy is founded on eight principles of data protection. These are that data must:
- Be processed fairly and lawfully
The data that DRES holds has come from members, primarily through the completion of either the paper membership application form or the online version. It is held only for the purposes of the Society and will not be passed to third parties without the consent of the individual. - Be obtained only for specific, lawful purposes
The data is used for the purpose of keeping a record of membership status including payment of any subscription due and for communication with members. - Be adequate, relevant and not excessive
The scope of data held on an individual member will be kept to a minimum and will be reviewed by the management committee from time to time to ensure it is still necessary and relevant to the continued efficient operation of the Society. - Be accurate and kept up to date
Individuals should notify DRES of any changes, to enable personnel records to be updated accordingly. It is the responsibility of the Society to act upon notification of changes to data, amending them where relevant. Members are also able to update their personal records securely via the DRES website. It is the responsibility of each member to keep the combination of username and password private to themselves. - Not be held for any longer than necessary
The names and duration of membership of those who have ceased to be members will be maintained for archive purposes. Contact data will be destroyed within, at most, one year of cessation of membership of an individual. - Processed in accordance with the rights of data subjects
All members have the right to be informed of the data held on them and any such request will be fulfilled within 40 days of the request. There will be no charge for supplying this data and the Society will act proptly in the event of any errors being notified to it (see 4 above). - Be protected in appropriate ways
The data relating to members will be stored on an encrypted online website hosted in the United Kingdom. A copy of the membership data may also be held on a password protected computer by the Membership Secretary. - Not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection
Particular attention will be paid to any data posted on the Society’s website (https://www.dres.org.uk/) as it is recognised that this is accessible to individuals and organisations outside of the EEA.
