STAINES RUGBY FOOTBALL CLUB LIMITED
DATA PROTECTION POLICY 2024
1. Policy Statement
Staines Rugby Football Club Limited (“Staines RFC” or “the Club”) is committed
to ensuring that personal data held by the Club about its employees, players, the parents and guardians of junior players, directors and officers of the Club, suppliers and other individuals involved with the Club is processed fairly and lawfully. The Club will take all reasonable steps to implement this policy, and to put in place procedures to ensure that the Club complies with all relevant statutory requirements. These procedures will be monitored periodically to ensure ongoing compliance.
2. Data Protection Act 1998 and the Data Protection Principles
The Club will implement and comply with the eight Data Protection Principles contained in the Data Protection Act 1998 (“the Act”) and subsequent amendments. These principles state that personal data (as defined in the Act) must be:
a. processed fairly and lawfully (for example, the individual should be made aware that their personal data is being processed or stored);
b. used only for the purpose or purposes for which it was obtained and not in any manner which is incompatible with that purpose or those purposes;
c. adequate, relevant, and not excessive in relation to the purpose or purposes for which they are used or processed;
d. accurate and, where necessary, kept up to date;
e. kept only as long as necessary for the purpose or purposes for which it is used;
f. processed in line with the rights of the data subject or subjects under the Act;
g. kept secure at all times in order to prevent unauthorised or unlawful processing or accidental disclosure, destruction, or damage of the personal data; and
h. not be transferred outside the European Economic Area (EEA) without the data subject’s permission unless that country has an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
3. Responsibilities and Implementation
The Club has a responsibility to ensure that personal data obtained by the club in the course of its business is handled in accordance with statutory requirements. The attention of all staff, players, coaches, managers, and volunteers is drawn to the data protection procedures adopted by the Club as contained in this document, and as adopted from time to time in future.
Data Protection is a responsibility shared by all officers of the Club. The Chairman has overall responsibility for Data Protection within the Club, with particular responsibility being delegated to the following individuals:
• Player records (Senior) Director of Rugby
• Player records (Junior) Rugby Manager Junior
• Membership records Club Secretary/Membership Secretary
• Staff records Director of Finance
• Supplier records Director of Finance
• Other third party records Director of Finance
The Executive Management Board (“EMB”) will ensure that all Club members, staff members,
players, coaches, managers, directors and officers with responsibility for handling personal data are made aware of the Club’s Data Protection Policy and procedures. The EMB will review periodically the adequacy and suitability of the Club’s Data Protection Policy and procedures.
The EMB may instigate disciplinary action against any Club member, staff member, player, coach, manager, director, or officer who fails to comply with the Club’s Data Protection Policy and procedures, and will determine the appropriate action to be taken in the event of any breaches of data security.
Staines Rugby Football Club Limited – Data Protection Policy
4. The Club’s Data Protection Policy
• All personal data held by the Club will be treated as strictly confidential.
• Personal data collected by the Club will not be disclosed to anyone outside the Club unless the individual concerned has consented to such disclosure. The Club will not ask for more information than the Club needs for the purposes for which the Club is collecting it.
• The Club will update its records when an individual data subject informs the Club that his or her personal details have changed.
• The Club will adopt appropriate procedures to review and assess the quality and accuracy of personal data held by it.
• The Club will implement and adhere to information retention policies relating to personal data and will ensure that personal data is securely disposed of at the end of the appropriate retention period.
• The Club will observe the rights granted to data subjects under applicable data protection legislation and will ensure that requests relating to personal data are promptly and transparently dealt with.
• The Club will train relevant officers and staff on the obligations of the Club under the Act and under any other relevant Data Protection legislation.
• The Club will ensure that it has appropriate physical and technological security measures to protect personal data regardless of where it is held.
• The Club will ensure that where any processes involving personal data are outsourced the supplier has appropriate security measures in place and will contractually require the supplier to comply with this Policy and procedures.
• The Club will ensure that suitable safeguards are in place before personal data is transferred to other countries.
5. Security of Personal Data
• Personal data must not be disclosed to anyone outside the Club without the written consent of the individual concerned, or (in exceptional circumstances) on the specific instruction of the Chairman of the Club.
• Personal data must not be disclosed to any unauthorised officer, member, or staff member of the Club.
• User passwords may be issued to officers and staff of the Club who deal with computerised personal data. User passwords are not to be disclosed to any third party or to any other member, officer, or staff member of the Club.
• Any actual or potential security breaches resulting in unauthorised access to or unauthorised disclosure of personal data must be reported to the Chairman, or to the relevant responsible Officer (as identified in Section 3 above).
• The EMB will review periodically the Club’s data security arrangements, monitoring the risk of exposure to major threats to data security, reviewing and monitoring any data security incidents, and establishing and implementing initiatives to enhance and improve the Club’s data security.
• The EMB will agree the appropriate action to be taken in the event of any actual or potential breaches of data security. This may include disciplinary action against any Club member, staff member, player, coach, manager, director, or officer found to be responsible for a breach of data security.
• The EMB will ensure that all Club members, staff members, players, coaches, managers, directors and officers with responsibility for handling personal data are made aware of the guidelines contained in Appendix 1 regarding the handling and security of personal data.
• All data no longer required must be securely disposed of.
6. Requests by Data Subjects
• Individual data subjects will have the right, on written request, to obtain a copy of such personal data held by the Club relating to the data subject, in accordance with the requirements of the Data Protection Act 1998.
• All requests by individuals for information about personal data held by the Club must be referred as soon as possible following receipt of the request to the Chairman or to the relevant responsible Officer (as identified in Section 3 above), who will co-ordinate the provision of the response to the individual.