CLUB DATA PROTECTION ACT
General
The Data Protection Act 1998 came into force on 1 March 2000.
Scope
The Data Protection Act 1998 sets out rules for processing personal information, and it applies to:
1. personal data held in structured manual files (Paper records)
2. computerized personal data .
The Act gives individuals certain rights, and imposes obligations on those who record and use personal information to be open about how information is used and to follow eight data protection principles:
Data Protection Principles
Personal data must be processed following these principles so that data are:
1. processed fairly and lawfully
2. obtained for specified and lawful purposes
3. adequate, relevant and not excessive
4. accurate and, where necessary, kept up-to-date
5. not kept for longer than necessary
6. processed in accordance with the subject's rights
7. kept secure
8. not transferred abroad without adequate protection
NOTIFICATION AND DATA SECURITY
A new requirement is that notification must include a general description of the measures taken to comply with the 7th principle, concerning security.
Legal Obligations
This short checklist helps to comply with the Data Protection Act:
1 Do I really need this information about an individual?
2 Do I know what I’m going to use it for?
3 Do the people whose information I hold know that I’ve got it, and are they likely to understand what it will be used for?
4 If I’m asked to pass on personal information, would the people, who I hold information on, expect me to do this?
5 Am I satisfied the information is being held securely, whether it’s on paper or on computer?
6 Am I sure the personal information is accurate and up to date?
7 Do I delete / destroy personal information as soon as I have no need for it?
8 Are all members of the organization aware of their duties and responsibilities under the DPA, and are they putting them into practice?
NOTIFICATION AND DATA SECURITY
Principle 7 of the 1998 Data Protection Act states "appropriate technical and organizational measures shall be taken against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."
White Cliffs Rangers Football Club is committed to protecting the privacy of individuals whilst maximizing the availability of data for use by medical personnel or a first aider in the event of a player or club official requiring emergency medical attention following an incident / accident.
To comply with the 7th principle, all club members will be made aware of the following:
All personal data that has been provided by parents / guardians for each child that is registered with White Cliffs Rangers Football Club shall be securely filed. The data provided will be kept confidential, with access authorized to club officials. Personnel other than club officials will be granted access to the data on a need to know basis providing, it aids and protects the child. These personnel will usually include Emergency medics, First aiders, Doctors and the Football Association.
In the event of Child Protection issues, data will be made available to personnel in order to aid and protect the child, which will include Social Services, the Police, Doctors, Hospital Personnel and the Football Association.
All personal data that has been provided by a club official registered with White Cliffs Rangers Football Club shall be securely filed. The data provided will be kept confidential, with access authorized to club officials. Personnel other than club officials will be granted access to the data on a need to know basis providing, it aids and protects the club official. These personnel will usually include Emergency medics, First aiders, Doctors and the Football Association.
In the event of an incident / accident, two copies of an ‘Accident Report Form’ will be completed. One copy will be given to the injured persons parent / guardian or spouse, and the other copy will be handed to the club secretary, where it will be securely filed.
Personal data will be gathered for club registration purposes, where a contact number will be required so that personnel can be contacted in the event of match or training cancellations and other communications regarding the persons involvement with the club.
Personal data will be gathered in the form of a medical questionnaire for use in the event of a medical emergency.
Personal data for club registration and a medical questionnaire will be updated annually. These will also need to be updated at other times during the year if changes occur.
No personal data will be kept on an internet web site.
No personal data will be kept on a shared computer.
No personal data held in structured manual files (paper records) will be left unattended in a public place where unauthorized personal can gain access to the data.
When personal data held in structural manual files (paper records) are no longer required or are out of date, they will be destroyed using a shredder or incinerator.
When personal data held on computer are no longer required or are out of date, they will be permanently deleted.