This policy applies to everyone involved in any way with the British Motorsports Marshals Club (BMMC), irrespective of role or capacity.
BMMC recognises its responsibility under the Data Protection Act 2018 (DPA) including the provisions made in the UK General Data Protection Regulations (UK GDPR), and believes that breaches are preventable. To operate effectively, and to meet our obligations, we process personal data relating to present, past and potential members. This may include data about children and their parents/guardians.
We will identify any potential data risks and put in place appropriate controls.
Personal data refers to any information that could identify someone directly or indirectly. This includes things like name, address, email, birth date, bank details etc. The DPA also defines personal data to include elements such as location data or other online identifiers such as IP address.
The DPA also identifies so called “Special Category” data which is considered to be more sensitive, and so requires further protection. BMMC does not currently record this type of data.
To ensure effective implementation of this policy we will ensure data is:
BMMC will review this policy annually, as well as following a major regulatory change or in the event of any breach.
This policy will be communicated to all our member’s and organisations working on our behalf, on our external website, and made available to third parties.
The Policy Owner, shown at the bottom of this page, is responsible for implementing this policy on behalf of the BMMC Directors who will monitor its effectiveness.
The BMMC is a data controller and a data processor. We are not required to formally appoint a Data Protection Officer (DPO). The National Secretary is responsible for privacy and data.
Ensuring personal data is collected and held in an appropriate manner is key to the successful operation of the BMMC.
In order to achieve this, the Club will:
BMMC will only process personal data if it falls under one of the legal reasons set out by the Information Commissioner’s Office: Consent; Contract; Legal obligation; Vital interests; Public task; Legitimate interests.
Children aged 12 and over e.g. (cadets) have the right to be informed and manage their own data. The same lawful bases as listed above also apply to children. (For children under 12, parental consent to process is required). The rights and freedoms of children are the same as for adults, including the requests covered later in this document.
All role holders are obliged to:
All role holders should ensure that personal data is:
Role holders should be aware that any information linked to an individual can be requested by that individual. Therefore, any remarks and annotations related to individuals should be appropriate, justified and relevant.
The DPA / GDPR provides the following rights for individuals:
Requests should be made in writing to the National Secretary. BMMC will reply within one calendar month. Should there be a direct conflict of interest, the National Secretary may, by exception, request another Director’s assistance.
All records (including electronic, printed and handwritten) must be held securely to prevent unauthorised or unlawful processing or disclosure of data. Appropriate measures should be taken to minimise the possibility of accidental loss, destruction or damage to personal data. Role holders must not store Club data on, mobile phones or other personal storage equipment. Access to data must be limited to legitimate users only. Access to electronic records will be controlled through password protection and varying levels of access. Records should be kept only for as long as is necessary.
A personal data breach is defined as: “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.”
The Club is responsible for ensuring appropriate and proportionate security for the personal data that we hold. The Club makes every effort to avoid personal data breaches, however, it is possible that data breaches will occur. Examples of personal data breaches include:
If a data protection breach occurs, the Club is required in most circumstances to report this as soon as possible to the Information Commissioner’s Office, and not later than 72 hours after becoming aware of it. All breaches of this policy and data protection legislation must be reported immediately to the 3 National Officers, and role holders must take the action requested of them – such as complying with an investigation, contacting the IT Co-ordinator for support to secure an account, or informing others of virus or phishing attacks. A breach by a third party may result in a termination of contract.
Data breaches are serious offences. Anyone found breaching this policy may face disciplinary actions or even criminal prosecution if they knowingly misuse personal information for their own purposes outside of legitimate BMMC purposes.
BMMC could also be fined for non-compliance with the Regulations.
All emails sent by the system contain a tracking pixel. This is used to track whether each email has been opened by the recipient, and when. This information can be viewed by those users of the system with permission to view email delivery reports. We do not display any information regarding the location of the recipient. Note that the tracking pixel is only activated if the recipient chooses to download images into their email client.
We, British Motorsports Marshals' Club, make use of the myClubhouse software supplied by Simmetrics Ltd to process personal data we include on our myClubhouse website in accordance with our privacy policy set out above. Simmetrics Ltd processes your personal data on our behalf and they can only do so in accordance with our written instructions. You can find the details of our data processor’s privacy policy here: http://www.myclubhouse.co.uk/Home/PrivacyPolicy.