Statement of Policy and Procedures
Data Protection Policy
Policy date: 2026. Approved by the NIURA committee.
"The NIURA committee are committed to compliance with all UK law in respect of personal and sensitive data, and to protecting the rights and privacy of individuals. This includes any potential partner organisations, volunteers and others in accordance with the Data Protection Act 2018 ("DPA 2018") and the UK General Data Protection Regulation ("UK GDPR"). To comply with the law, information about individuals must be collected and used properly, stored securely and not disclosed unlawfully to any third party."
Legislation update (applying from 1 January 2021)
The UK exited the EU after 31 December 2020. The EU GDPR no longer applies directly in the UK, however since the DPA 2018 enacted the EU GDPR in law, its requirements must still be complied with. The UK government issued a statutory instrument, "The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019". This amended the DPA 2018 and merges with the requirements of the EU GDPR to form a data protection regime that works in a UK context post Brexit. The new regime is known as UK GDPR, and this policy reflects that name.
1. Introduction
1.1 NIURA collects and uses certain types of personal information about members and other users of our services and other individuals. By law NIURA is required to collect and use certain information in order to meet its legal obligations. This policy sets out how NIURA will meet its obligations to deal with personal information properly and securely in accordance with UK GDPR and other relevant legislation.
1.2 UK GDPR applies to all digitally held data and any manual system if it comes within the definition of a filing system. A filing system is any system where data is held in a structured way, so it can be used on the basis of a particular field such as an individual's name.
2. Personal data
2.1 Personal data means any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.
2.2 There are seven classes of Special Category Data which are given additional protection and have further requirements when being processed. The special categories are:
- Race or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Physical or mental health
- An individual's sex life or sexual orientation
- Genetic or biometric data
3. The data protection principles
UK GDPR requires that the six data protection principles are followed at all times. Personal data must be:
- Processed lawfully, fairly and in a transparent manner in relation to individuals;
- Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the initial purposes;
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
- Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, subject to the safeguards required by UK GDPR for archiving, research or statistical purposes; and
- Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
4. Use of personal data
All personal data held by NIURA must be treated in accordance with the data protection principles set out above.
4.1 External individuals. All personal information held by NIURA about external individuals shall only be held in accordance with the data protection principles and shall not be kept longer than necessary.
4.2 Committee / volunteers. The personal data about volunteers may include contact details, date of birth, nationality and address details. The data is used to comply with any relevant legal obligations placed on NIURA. Any volunteer wishing to limit or object to the uses of their personal data should notify the Data Protection Officer in writing, who will ensure this is recorded and adhered to when appropriate. Personal data cannot be restricted where it is held for legal requirements.
5. Security of personal data
5.1 NIURA will take reasonable steps to ensure personal data is held securely both electronically and manually, and it will only be accessible to committee members where it is necessary for them to carry out their assigned roles and duties.
5.2 All committee members shall take all reasonable steps to ensure personal information is held securely and not disclosed to unauthorised persons.
5.3 Further information on security of electronic data is within the NIURA privacy policy.
6. Disclosure of personal information
6.1 NIURA will only disclose personal information to a third party for legal or contractual reasons.
7. Subject access rights
7.1 Any individual who makes a valid subject access request is entitled to be:
- told whether their personal data is being processed;
- given a description of the personal data, reason for processing and whether it has been shared with any other organisations or persons;
- given details of the source of the data (where this is available); and
- given a copy of the information comprising the data.
Individuals are entitled only to their own personal data, and not to information relating to other people unless they are acting on behalf of that person. In these circumstances, written consent will be required.
7.2 Exempt information. NIURA may not be able to release some information. Information which is exempt from a subject access request includes: personal data where disclosure could prejudice the prevention or detection of crime; legal professional privilege (advice received from solicitors, for example); and personal data identifying another person whose details cannot be disclosed without their permission.
7.3 Handling a request. A subject access request must be emailed to niultrarunning@gmail.com. If a request is received it must be passed to the Data Protection Officer within 3 working days of receipt and must be dealt with without delay and at the latest within one month of receipt. Proof of identification may be requested to ensure the personal information requested is provided to the right person. Two forms of ID will be required: one name identification (e.g. driving licence, passport or birth certificate) and one form of address identification dated in the last three months.
8. Other rights of individuals
8.1 NIURA has an obligation to comply with other rights under the law: data portability, erasure, rectification, and objection to processing.
8.2 Data portability. Where an individual requests that NIURA sends their information to another organisation as a result of it being processed by consent or under contract, NIURA must do so in a structured, commonly used and machine-readable format. Requests should always be sent to the Data Protection Officer within 3 working days.
8.3 Erasure. Individuals have the right to have data permanently erased without delay where:
- the data is no longer required for the purpose for which it was collected;
- consent is withdrawn and there is no other legal basis to hold the data (most commonly via the unsubscribe facility on emails);
- information is being unlawfully processed;
- a legitimate objection has been raised to processing;
- there is a legal requirement to delete the data.
Requests should always be sent to the Data Protection Officer within 3 working days.
8.4 Right to rectification. An individual has a right to seek the rectification of inaccurate data. Any request received should be passed to the Data Protection Officer within 3 working days and they shall arrange for the information to be corrected without undue delay. The individual must provide evidence of the correct data and the Data Protection Officer will notify the individual when it has been completed. In the event of a dispute over the accuracy of the information, the request and reasons for refusal shall be noted alongside the data and the individual informed.
8.5 Right to object to processing. An individual has the right to object to their data being processed on the grounds of pursuit of legitimate interest or public interest where they do not believe those grounds are made out. An objection must be sent to the Data Protection Officer within 3 working days of receipt and the Data Protection Officer will assess if there are grounds that override the interests, rights and freedoms of the individual, or whether the information is needed for legal proceedings. The individual shall be notified of the decision within 20 working days of receipt of their objection.
9. Breach of any requirement of UK GDPR
9.1 All volunteers shall report any breach of UK GDPR, including the data protection principles, as soon as it is discovered to the Data Protection Officer.
9.2 Once informed, the Data Protection Officer shall determine:
- the extent of the breach;
- the risks to the data subjects as a consequence of the breach;
- any security measures in place that will protect the information;
- any measures that can be taken to reduce the risk.
9.3 The Data Protection Officer shall report the breach to the Information Commissioner's Office within 72 hours of the breach coming to NIURA's attention, unless there is unlikely to be any risk to an individual from the breach.
Contact
For any data protection question or request, email niultrarunning@gmail.com.
