Complaints Policy
more

Complaints Policy

Issued By Executive Pastor

1. Purpose

Kingdom Faith Church is committed to protecting personal information and ensuring compliance with:

  • UK General Data Protection Regulation (UK GDPR);
  • Data Protection Act 2018;
  • Data (Use and Access) Act (DUAA);
  • applicable safeguarding and charity law obligations.

This procedure sets out how individuals may raise complaints concerning the handling, processing, storage, sharing, retention, or security of personal data by Kingdom Faith Church.

The purpose of this procedure is to:

  • provide a clear process for reporting data protection concerns;
  • ensure complaints are handled fairly and promptly;
  • minimise risks to individuals and the church;
  • support transparency and accountability;
  • ensure legal compliance with UK data protection legislation.

2. Scope

This procedure applies to complaints relating to:

  • unauthorised disclosure of personal information;
  • loss or theft of personal data;
  • inaccurate personal records;
  • misuse or unlawful processing of personal data;
  • inappropriate sharing of personal information;
  • failure to comply with subject access requests;
  • breaches of confidentiality;
  • excessive retention of personal information;
  • failure to maintain adequate data security;
  • unauthorised access to church records or systems.

This procedure applies to all personal information processed by Kingdom Faith Church, whether held electronically, on paper, or verbally communicated.


3. Definitions

For the purposes of this procedure:

Personal Data means any information relating to an identified or identifiable individual.

Special Category Data includes information concerning:

  • religious beliefs;
  • health;
  • ethnicity;
  • safeguarding matters;
  • criminal allegations or convictions.

Data Breach means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.


4. Reporting a Complaint

Individuals who believe their personal data has been mishandled may submit a complaint in writing to:

Data Protection Officer
Kingdom Faith Church
Foundry Lane
Horsham
West Sussex
RH13 5PX

Email: info@kingdomfaith.com
Telephone: 01293 851543

Complaints should include:

  • the complainant’s name and contact details;
  • a description of the concern;
  • relevant dates and circumstances;
  • copies of supporting evidence where available;
  • details of any harm or impact suffered.

Complaints should normally be submitted as soon as reasonably possible after the issue becomes known.


5. Immediate Reporting of Data Breaches

Any church leader, employee, volunteer, or contractor who becomes aware of a suspected data breach must report it immediately to the Data Protection Lead.

Urgent action may be required to:

  • contain the breach;
  • recover lost information;
  • prevent further unauthorised access;
  • assess risks to affected individuals;
  • comply with legal reporting obligations.

6. Acknowledgement of Complaint

The church will acknowledge receipt of the complaint within seven (7) working days.

The acknowledgement will normally include:

  • confirmation that the complaint has been received;
  • details of the investigation process;
  • expected timescales;
  • contact information for the investigating officer.

7. Investigation Procedure

The church will investigate complaints promptly and proportionately.

The investigation may include:

  • reviewing records and systems;
  • interviewing relevant individuals;
  • assessing technical and organisational security measures;
  • reviewing compliance with church policies and legal obligations;
  • obtaining legal or specialist advice where necessary.

The church will maintain written records of:

  • the nature of the complaint;
  • actions taken;
  • findings;
  • remedial measures implemented.

Investigations will normally be completed within twenty-eight (28) working days where reasonably practicable.


8. ICO Notification and Regulatory Reporting

Where a personal data breach presents a risk to the rights and freedoms of individuals, Kingdom Faith Church will assess whether notification to the Information Commissioner’s Office (ICO) is required.

Where legally required, the church will:

  • notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach;
  • notify affected individuals where there is a high risk to their rights and freedoms.

The church will maintain a record of all personal data breaches, regardless of whether notification is required.


9. Outcomes and Remedial Action

Following investigation, the church may:

  • uphold the complaint;
  • partially uphold the complaint;
  • determine that no breach occurred;
  • identify procedural or security weaknesses requiring improvement.

Actions may include:

  • apology and corrective action;
  • updating inaccurate records;
  • restricting or correcting data access;
  • staff or volunteer training;
  • disciplinary action;
  • policy or system changes;
  • enhanced security measures;
  • referral to safeguarding or regulatory authorities where appropriate.

The complainant will receive a written response summarising the outcome, subject to legal and confidentiality obligations.


10. Confidentiality and Information Security

All complaints and investigations will be handled confidentially and securely.

Information relating to complaints will only be shared with individuals who require access for legitimate operational, safeguarding, legal, or regulatory purposes.

Kingdom Faith Church will implement appropriate technical and organisational measures to protect complaint-related information from:

  • unauthorised access;
  • accidental disclosure;
  • alteration;
  • loss or destruction.

11. Rights of Individuals

Individuals may exercise their rights under UK data protection legislation, including:

  • the right of access;
  • the right to rectification;
  • the right to restriction of processing;
  • the right to object;
  • the right to lodge a complaint with the Information Commissioner’s Office (ICO).

Further information is available from: Information Commissioner’s Office (ICO)


12. Appeals

If dissatisfied with the outcome of a complaint, the complainant may submit a written appeal within fourteen (14) working days.

Appeals should state:

  • the reasons for dissatisfaction;
  • any procedural concerns;
  • any additional evidence.

Appeals will normally be reviewed by an individual not previously involved in the matter.

The appeal decision will be final.


13. Retention of Records

Records relating to data protection complaints and breaches will be retained securely in accordance with:

  • legal obligations;
  • safeguarding requirements;
  • insurance requirements;
  • church retention schedules.

Records will be securely destroyed when no longer required.


14. Monitoring and Review

This policy is reviewed regularly by the Church Leadership and Trustees to ensure ongoing compliance with UK data protection legislation and best practice.