Stafford Harriers Privacy and Data Protection Policy statement (to comply with EU General Data Protection Regulations 2018)
- The following statement sets out how Stafford Harriers will use the personal data that we collect from you
- For any personal data you provide for the purposes of your membership, Stafford Harriers is the Data Controller and is responsible for storing and processing that data in a fair, lawful, secure and transparent way
- If you have any questions you can contact our Data Protection Officer (DPO) at email@example.com
Section 1: The types of personal data we collect and use
On applying for membership of Stafford Harriers and on joining Stafford Harriers we will collect from you only information that we need.
This will include your title, name, date of birth, gender, address, email address, telephone number, URN, and details of any coaching or officiating licenses you hold (Athletics Data). This will be recorded and stored securely on our membership file.
We will not collect from you any medical information unless you consider it necessary for certain club officials (e.g. coaches) to be aware of a medical condition that may possibly affect you while engaged in activities with or on behalf of Stafford Harriers. We will only collect this medical information with your explicit consent which will need to be given at the point of collection.
We will not collect from you emergency contact information, unless you wish to supply this information for possible use while you are engaged in activities with or on behalf of Stafford Harriers. We will only collect this emergency contact information with your explicit consent which will need to be given at the point of collection.
We undertake to:
- Process and store your personal data securely
- Record and update it accurately
- Limit its use only to what the club needs
- Use it only for the purpose for which it is collected
Changes to your personal details can be notified to the club at any time at firstname.lastname@example.org and those changes will be recorded on the club membership file.
Section 2: Why we ask you to provide personal data
Our lawful basis for processing your personal data is that we have a contractual obligation to you as a member to provide the services you are registering for. Any data that we collect is for a number of purposes:
- To administer your membership of Stafford Harriers including the processing of membership forms and payments
- So that we can contact you directly and keep you involved and informed about what is happening in your club
- To deal with any requests and enquiries you may have about Stafford Harriers
- To connect you with those individuals and organisations detailed in Section 3
- To facilitate the organisation of club activities, teams, and social events
- To send out an invitation for members to vote for Runners of the Year
- To monitor trends within the club membership so we can plan for the future
- To report on the club website and elsewhere details of your participation in athletic and other club events that you undertake, your placing in races and PBs. Your explicit consent will be required for this
- Sometimes images of club members will be used for promotional purposes and for posting on the club website and in published race reports. You will be asked to give separate consent for use of your images for these purposes
- On occasion we may collect personal data from non-members (e.g. such as any non-member who fills in a health disclaimer or form at a taster event). This information will be stored for 52 weeks after an event and then destroyed securely. Our lawful basis for processing data is consent. Therefore we will need explicit consent for non-members to process this data which we will ask for at the point of collection
Section 3: Who we share your personal data with
The information that you provide will only be shared as is necessary for the purposes for which it is provided. Your personal data will not be shared with a third party for marketing purposes or shared with any third party, other than those stated below, without your explicit consent.
We will require your explicit consent for it to be shared with any of the following:
- club coaches or club officials to administer training sessions and other activities
- club team managers to enter events
- club officials engaged in the processing of membership forms and payments
- committee members to provide information about club activities, membership renewals, monitoring of club trends, invitation to social events
- leagues, county associations (and county schools’ associations) and other competition providers for entry in events
- Anonymised data shared with any funding partner as a condition of grant funding e.g. Local Authority
- Published reports of race and competition performances and results
- Club members responsible for management of the club website(s)
- England Athletics – see note below
Members who joined before 1st January 2019
When you become a member of the Club, you will also automatically be registered as a member of England Athletics Limited. We will provide England Athletics Limited with your Athletics Data which they will use to enable access to the MyAthletics portal. England Athletics Limited will contact you to invite you to sign into and update your MyAthletics portal. You can set and amend your privacy settings from the MyAthletics portal. If you have any questions about the continuing privacy of your personal data when it is shared with England Athletics Limited, please contact email@example.com.
Members who join after 1st January 2019
When you become a member of or renew your membership with Stafford Harriers you can also choose to be registered as a member of England Athletics (you will have to register with England Athletics if you ever compete for the club in competition Under UKA Rules). If you tick the box below we will provide England Athletics with your personal data which they will use to enable access to an online portal for you (called myAthletics). England Athletics will contact you to invite you to sign into and update your MyAthletics portal (which, amongst other things, allows you to set and amend your privacy settings). If you have any questions about the continuing privacy of your personal data when it is shared with England Athletics, please contact firstname.lastname@example.org.
If you select not to join England Athletics and then decide to compete for the club, we will need to register you with England Athletics and we will inform you at that time. In becoming a member of EA, EA will collect certain information about you which will include your name, date of birth, gender, URN number, email address, address, telephone number, names of the EA affiliated clubs that you are a member of and details of any coaching or officiating licenses you hold (Athletics Data).
In addition to having your data sent to EA you can request to receive it again by emailing email@example.com)
Acceptance by Stafford Harriers of your membership application will be dependent upon you giving your explicit consent to your data being shared as is detailed above.
Section 4: How your personal data is stored
The club’s data processing requires your personal data to be transferred outside the UK for the purpose of cloud hosting, cloud email and cloud storage. Where the club does transfer your personal data overseas it is with the appropriate safeguards in place to ensure the security of that personal data.
Access to these files is password protected and restricted to those club officials appointed by the committee of Stafford Harriers.
You can access further details of the privacy and security policies of the cloud hosting, email and storage at the following web addresses:
Any breach in security that is detected will be notified to any member affected within 72 hours. Any breach in security will be reported to the Information Commissioners Office within 72 hours as is required by GDPR legislation.
Your personal data will not be kept longer than is necessary for the purpose for which it was collected. Athlete data is updated every year on annual membership forms. Any personal data we hold on you will be securely destroyed after four years of inactivity on that member’s account in line with England Athletics’ retention policy.
Section 5: Your rights regarding the personal data we collect
Under GDPR legislation you have the right to request a copy of any personal data (Subject Access Request) that Stafford Harriers holds upon you. You can request a copy by contacting our Data Protection Officer (DPO) at firstname.lastname@example.org.
We will meet such a request within one calendar month as is required by legislation. All such requests will be logged by Stafford Harriers as is required by legislation.
Your other rights include:
- to object to processing of your personal data that is likely to cause or is causing damage or distress;
- to prevent processing for direct marketing
- to object to decisions being taken by automated means
- to have inaccurate personal data rectified, blocked, erased or destroyed
- to claim compensation for damages caused by a breach of data protection legislation
- If you have any concerns or complaints in relation to how Stafford Harriers collects and/or processes your personal data, you should contact Stafford Harriers’ data protection officer in the first instance. If you are dissatisfied with how your concern/complaint is dealt with by Stafford Harriers, you have the right to report your concern/complaint to the Information Commissioners Office (www.ico.org.uk)
You can access full information about your rights under GDPR legislation at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
Section 6: Junior members
- Stafford Harriers will collect and use the Athletics data detailed in Section 1 for each junior athlete applying for membership or renewal of membership of Stafford Harriers. Explicit consent of a parent or legal guardian will be required for this.
- We will share this personal data only with those individuals and organisations detailed in Section 3. Explicit consent of a parent or legal guardian will be required for this.
- Juniors have the same rights as adults over their personal data. These include the rights to access their personal data; request rectification; object to processing and have their personal data erased. Where a child is not considered to be competent, an adult with parental responsibility may exercise the child’s data protection rights on their behalf.
- The explicit consent of parent or legal guardian will be required for Stafford Harriers to use images of junior members for promotional purposes and for posting on the club website and in published race reports.
- England Athletics will require confirmation from the parent or legal guardian of any junior registering with England Athletics that their child is capable of taking part in athletics.
- We will not collect for any junior member medical information unless a parent or legal guardian considers it necessary for certain club officials (e.g. coaches) to be aware of a medical condition that may possibly affect their child while engaged in activities with or on behalf of Stafford Harriers. We will only collect this medical information with the explicit consent of a parent or legal guardian which will need to be given at the point of collection.
- Stafford Harriers consider it important to have emergency contact information for any junior member for possible use while they are engaged in activities with or on behalf of the club. We will not however collect from a parent or legal guardian emergency contact information, which is also classed as special category personal data, unless they wish to supply this information. We will only collect this emergency contact information with the explicit consent of a parent or legal guardian which will need to be given at the point of collection.
Section 7: Website and social media
The website is maintained by Stafford Harriers. For the purposes of data protection legislation, Stafford Harriers is the data controller.
Stafford Harriers is the owner of www.staffordharriers.org and www.staffordharriers.co.uk and we are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR) on and from 25 May 2018.
Stafford Harriers will not publish on its website any personal data other than details of your athletic performances and involvement in other club activities without your explicit consent.
Section 8: Other data
We call Data other than Personal Data “Other Data”. We collect Other Data through a variety of sources. One of our sources for Other Data is cookies and other technologies that record Data about the use of our websites.
Other Data that we may collect include:
- Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language;
- Transaction data, such as purchases, purchase amount, date of purchase, and payment method;
- Cookie and tracking technology data, such as time spent on the Services, pages visited, language preferences, and other anonymous traffic data;
- Credit card transactions are handled by Stripe.com. We don’t hold credit card numbers, security codes, expiry date.
- Race reports and race results. We publish race results that we collect at our events, and that are published by other event organisers. We publish race reports that are written or sent in by our members and are a personal view of the event.
Section 9: Consent
(These statements will either need tick-boxes or YES/NO on the membership application/renewal form)
- I have read Stafford Harriers Data Protection Policy statement YES/NO
- By submitting my personal data I give consent to Stafford Harriers to use it for those purposes detailed in Section 2 of this Privacy and GDPR statement YES/NO
- I give consent for my images to be used for those purposes stated in Section 2 of this statement YES/NO
- I give consent for my data to be shared with those individuals and organisations detailed in Section 3 of this statement YES/NO
- I give consent for my data to be shared with England Athletics as detailed in Section 3 of this statement YES/NO
- I give consent for Stafford Harriers to collect and store details of the following medical conditions I have and for that information to be shared only with those club officials who need to be aware of them YES/NO
- I give consent for Stafford Harriers to collect and store the following emergency contact details for me YES/NO
Emergency Contact details:
The following will need to be completed by a parent or legal guardian of any junior who is a member or is applying for membership of Stafford Harriers:
- By submitting personal data on behalf of my son or daughter I give consent to Stafford Harriers to use it for those purposes detailed in Section 2 of this Privacy and GDPR statement YES/NO
- I give consent for images of my son or daughter to be used for those purposes stated in Section 6 of this statement YES/NO
- I give consent for my son or daughter’s data to be shared with those individuals and organisations detailed in Section 3 of this statement YES/NO
- I give consent for my son or daughter’s data to be shared with England Athletics as detailed in Section 3 of this statement YES/NO
- I give consent for Stafford Harriers to collect and store details of the following medical conditions which my son or daughter has and for that information to be shared only with those club officials who need to be aware of them YES/NO
- I give consent for Stafford Harriers to collect and store the following emergency contact details for my son or daughter YES/NO
Emergency Contact details:
- I give consent for details of my son or daughter’s athletic performances and involvement in other club activities to be published on the club website and in race reports and race results published elsewhere YES/NO
If consent to any of the above is not given, Stafford Harriers unfortunately may have to decline an application for membership.
Some additional information regarding GDPR legislation
The following advice is from England Athletics and will need to be noted for Stafford Knot and Stafford relays and any other events organised by the club:
Race organisers should include the following wording on race entry forms:
“You agree that we may publish your Personal Information as part of the results of the Event and may pass such information to the governing body or any affiliated organisation for the purpose of insurance, licences or for publishing results either for the event alone or combined with or compared to other events. Results may include (but not be limited to) name, any club affiliation, race times, occupation and age category.”