Skip to content

Data Protection Policy

Field Value
Reference POL-001
Type Policy
Version 1.00
Status Approved
Owner Data Protection Lead
Approver Board
Approval Record
Effective Date 2026-08-05
Next Review 2027-08-05
Review Requirements As defined in STD-001
Classification Internal

Purpose

This policy defines BRSA's commitment to protecting personal data and ensuring that information is handled responsibly, securely and transparently.

The purpose of this policy is to establish the principles and responsibilities that apply when BRSA collects, stores, uses or otherwise processes personal data.


Scope

This policy applies to:

  • Board members.
  • Committee members.
  • Volunteers.
  • Any person authorised to access or handle BRSA personal data.

It applies to personal data processed by BRSA, regardless of the system or method used.


Policy Statement

BRSA is committed to protecting personal data and processing information lawfully, fairly and transparently.

BRSA will handle personal information responsibly, respecting the rights of individuals and maintaining appropriate safeguards to protect confidentiality, integrity and availability.


Principles

BRSA will process personal data in accordance with the following principles:

Lawfulness, Fairness and Transparency

Personal data must be processed lawfully, fairly and in a way that individuals can understand.

Purpose Limitation

Personal data must only be used for legitimate and defined purposes.

Data Minimisation

BRSA will only collect and retain personal data that is necessary for its activities.

Accuracy

Reasonable efforts must be made to ensure personal data remains accurate and current.

Storage Limitation

Personal data should not be retained longer than necessary.

Security and Confidentiality

Personal data must be protected against unauthorised access, loss, misuse or disclosure.

Accountability

BRSA must be able to demonstrate appropriate responsibility and governance over personal data.


Requirements

BRSA must:

  • Maintain appropriate oversight of personal data processing activities.
  • Ensure access to personal data is limited to authorised individuals.
  • Ensure personal data is handled only for legitimate organisational purposes.
  • Consider privacy and data protection requirements when introducing new systems or processes.
  • Ensure individuals handling personal data understand their responsibilities.
  • Respond appropriately to requests from individuals exercising their data protection rights.
  • Address suspected personal data breaches promptly and appropriately.

Roles and Responsibilities

Role Responsibility
Board Provides governance oversight and approves this policy.
Data Protection Lead Maintains this policy and provides guidance on data protection responsibilities.
Committee Members and Volunteers Handle personal data responsibly and follow applicable BRSA policies and procedures.

Compliance and Exceptions

Compliance with this policy is the responsibility of all individuals who handle BRSA personal data.

Any proposed exception to this policy must be documented and approved by an appropriate authority before implementation.


  • POL-004 Privacy Policy
  • POL-007 Records Retention Policy
  • PROC-003 Data Breach and Incident Response
  • PROC-004 Data Subject Access Requests
  • REG-002 Technology and Service Register

Review Requirements

This policy should be reviewed:

  • At least annually.
  • When relevant legislation or guidance changes.
  • Following significant changes to BRSA systems or processes.
  • Following significant data protection incidents or lessons learned.

Change History

Version Date Author Summary
0.10 2026-07-08 DJC Initial draft reviewed
0.50 2026-07-24 DC Version -> 0.50; Status -> Review
1.00 2026-08-05 DC Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05