Data Protection Policy¶
| Field | Value |
|---|---|
| Reference | POL-001 |
| Type | Policy |
| Version | 1.00 |
| Status | Approved |
| Owner | Data Protection Lead |
| Approver | Board |
| Approval Record | |
| Effective Date | 2026-08-05 |
| Next Review | 2027-08-05 |
| Review Requirements | As defined in STD-001 |
| Classification | Internal |
Purpose¶
This policy defines BRSA's commitment to protecting personal data and ensuring that information is handled responsibly, securely and transparently.
The purpose of this policy is to establish the principles and responsibilities that apply when BRSA collects, stores, uses or otherwise processes personal data.
Scope¶
This policy applies to:
- Board members.
- Committee members.
- Volunteers.
- Any person authorised to access or handle BRSA personal data.
It applies to personal data processed by BRSA, regardless of the system or method used.
Policy Statement¶
BRSA is committed to protecting personal data and processing information lawfully, fairly and transparently.
BRSA will handle personal information responsibly, respecting the rights of individuals and maintaining appropriate safeguards to protect confidentiality, integrity and availability.
Principles¶
BRSA will process personal data in accordance with the following principles:
Lawfulness, Fairness and Transparency¶
Personal data must be processed lawfully, fairly and in a way that individuals can understand.
Purpose Limitation¶
Personal data must only be used for legitimate and defined purposes.
Data Minimisation¶
BRSA will only collect and retain personal data that is necessary for its activities.
Accuracy¶
Reasonable efforts must be made to ensure personal data remains accurate and current.
Storage Limitation¶
Personal data should not be retained longer than necessary.
Security and Confidentiality¶
Personal data must be protected against unauthorised access, loss, misuse or disclosure.
Accountability¶
BRSA must be able to demonstrate appropriate responsibility and governance over personal data.
Requirements¶
BRSA must:
- Maintain appropriate oversight of personal data processing activities.
- Ensure access to personal data is limited to authorised individuals.
- Ensure personal data is handled only for legitimate organisational purposes.
- Consider privacy and data protection requirements when introducing new systems or processes.
- Ensure individuals handling personal data understand their responsibilities.
- Respond appropriately to requests from individuals exercising their data protection rights.
- Address suspected personal data breaches promptly and appropriately.
Roles and Responsibilities¶
| Role | Responsibility |
|---|---|
| Board | Provides governance oversight and approves this policy. |
| Data Protection Lead | Maintains this policy and provides guidance on data protection responsibilities. |
| Committee Members and Volunteers | Handle personal data responsibly and follow applicable BRSA policies and procedures. |
Compliance and Exceptions¶
Compliance with this policy is the responsibility of all individuals who handle BRSA personal data.
Any proposed exception to this policy must be documented and approved by an appropriate authority before implementation.
Related Documents¶
- POL-004 Privacy Policy
- POL-007 Records Retention Policy
- PROC-003 Data Breach and Incident Response
- PROC-004 Data Subject Access Requests
- REG-002 Technology and Service Register
Review Requirements¶
This policy should be reviewed:
- At least annually.
- When relevant legislation or guidance changes.
- Following significant changes to BRSA systems or processes.
- Following significant data protection incidents or lessons learned.
Change History¶
| Version | Date | Author | Summary |
|---|---|---|---|
| 0.10 | 2026-07-08 | DJC | Initial draft reviewed |
| 0.50 | 2026-07-24 | DC | Version -> 0.50; Status -> Review |
| 1.00 | 2026-08-05 | DC | Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |