Data Protection & Privacy Policy
Issued By Executive Pastor
1.1 Data Protection Principles
We ensure that personal information is:
- Processed lawfully, fairly and transparently
- Collected for specified, explicit and legitimate purposes
- Adequate, relevant and limited to what is necessary
- Accurate and kept up to date
- Stored securely with appropriate safeguards
- Retained only for as long as necessary
- Processed in accordance with individuals’ legal rights
1.2 Individual Rights
Individuals have the following rights under UK data protection law:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure (where applicable)
- Right to restrict processing
- Right to object
- Right to data portability
- Right to withdraw consent
- Rights relating to automated decision-making and profiling
- Right to complain to the ICO
1.3 Contact Details
Data Protection Officer
Kingdom Faith Church
Foundry Lane
Horsham
West Sussex
RH13 5PX
Email: info@kingdomfaith.com
Telephone: 01293 851543
2. Background
2.1 Kingdom Faith Church Trust processes personal data in accordance with UK GDPR and the Data Protection Act 2018.
2.2 We act as a Data Controller for personal data processed for our organisational purposes.
2.3 We process data relating to church members, visitors, event attendees, partners, employees, volunteers, contractors, and suppliers.
2.4 Key Definitions
Personal Data: Any information relating to an identified or identifiable individual.
Special Category Data: Sensitive data including religious belief, health, ethnicity, sexual orientation, political opinions, or biometric data.
Processing: Any operation performed on personal data (collection, storage, use, sharing, deletion, etc.).
Controller: The organisation determining purposes and means of processing.
Processor: A third party processing data on our behalf.
DPO: The individual responsible for overseeing data protection compliance.
3. Purpose of This Policy
This policy:
- Explains how we handle personal data
- Sets standards for lawful processing
- Applies to all staff, volunteers, and contractors
- Ensures compliance with UK data protection law
- May be updated to reflect legal or operational changes
Breaches of this policy may result in disciplinary action and/or legal consequences.
4. Lawful Basis for Processing
We process personal data only where a lawful basis applies, including:
- Consent
- Contract
- Legal obligation
- Legitimate interests
- Vital interests
- Public task (where applicable)
Special category data is processed only where an additional lawful condition applies.
5. Use of Personal Information
We may use personal information for:
- Church administration and pastoral care
- Event and conference management
- Donations and Gift Aid processing
- Communication of church activities
- Employment and volunteer management
- Safeguarding responsibilities
- Customer/service delivery
- Legal and regulatory compliance
- Responding to enquiries or complaints
Marketing communications are only sent where legally permitted, and individuals may opt out at any time.
6. Cookies and Online Technologies
6.1 Our website uses cookies and similar technologies for functionality, security, analytics and user experience.
6.2 Strictly necessary cookies may be used without consent where legally permitted.
6.3 Optional cookies are only used with valid consent in accordance with PECR and UK GDPR.
6.4 Users can manage cookie settings via browser or site controls.
7. Data Security
We apply appropriate technical and organisational measures including:
- HTTPS encryption
- Access controls and authentication
- Secure storage systems
- Confidentiality requirements
- Cybersecurity monitoring
- Secure disposal of records
Data is only shared with processors under appropriate contractual safeguards.
8. International Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including adequacy regulations or approved transfer mechanisms.
9. Data Retention
We retain personal data only as long as necessary for:
- Legal obligations
- Safeguarding
- Financial/accounting requirements
- Operational needs
Data is securely deleted or destroyed when no longer required.
10. Individual Rights & Requests
Individuals may exercise their rights by contacting the Data Protection Officer.
Requests may include:
- Access to personal data
- Correction of inaccurate data
- Deletion (where applicable)
- Restriction or objection to processing
- Withdrawal of consent
11. Subject Access Requests (SARs)
We will respond to valid SARs within one calendar month in line with UK GDPR requirements.
12. Data Breaches
All suspected or actual breaches must be reported immediately.
Examples include:
- Loss or theft of devices
- Unauthorised access or disclosure
- Cyberattacks or ransomware
- Misdirected communications
- Credential compromise
- Accidental destruction of data
We will investigate and report breaches to the ICO where legally required.
13. Responsibilities
All staff, volunteers and contractors must:
- Follow data protection policies
- Keep data secure and confidential
- Complete required training
- Report breaches immediately
Managers are responsible for ensuring compliance within their teams.
14. Complaints Procedure
We handle data protection complaints fairly and promptly.
We will:
- Acknowledge complaints
- Investigate thoroughly
- Take corrective action where needed
- Respond in line with legal requirements
Individuals may also complain to the ICO at any time. Click here to view our full complaints policy.
15. Automated Decision-Making & AI
We do not normally use automated decision making that produces legal or significant effects.
Where AI, profiling, or automated tools are used:
- Processing is lawful, fair, and transparent
- Safeguards are in place
- Individuals may request information about processing
16. Recognised Legitimate Interests
We may process data under legitimate interests including:
- Church administration
- Safeguarding
- Security and fraud prevention
- Communications
- Operational management
- Record keeping
- IT and network security
17. ICO Cooperation
We fully cooperate with the ICO, including:
- Information requests
- Investigations and audits
- Breach reporting
- Corrective actions
- Record keeping obligations
19. Policy Review
This policy is reviewed regularly and updated to reflect:
- Legal changes
- ICO guidance
- Operational requirements
- UK GDPR and DUAA developments
20. Legal Interpretation
This policy shall be interpreted in accordance with:
- UK GDPR
- Data Protection Act 2018
- PECR
- Data (Use and Access) Act 2025 (DUAA)
- ICO guidance and codes of practice
We will maintain ongoing compliance with evolving UK data protection law.
Version 2: 01/07/2026 SRC