1) Definitions
- Personal data is information about a person which is identifiable as being about them. It can be stored electronically or on paper.
- Data protection is about how we, as an organisation, ensure we protect the rights and privacy of individuals, and comply with the law, when collecting, storing, using, amending, sharing, destroying or deleting personal data.
2) Responsibility
- Overall and final responsibility for data protection lies with the management committee, who are responsible for overseeing activities and ensuring this policy is upheld.
- All volunteers are responsible for observing this policy, and related procedures, in all areas of their work for the group.
3) Overall policy statement
- We will collect, store, use, amend, share, destroy or delete personal data only in ways which protect people’s privacy and comply with the General Data Protection Regulation (GDPR) and other relevant legislation.
- We will only collect, store and use the minimum amount of data that we need for clear purposes, and will not collect, store or use data we do not need.
- We will only collect, store and use data for:
- purposes for which the individual has given explicit consent, or
- purposes that are in our club’s legitimate interests, or
- contracts with the individual whose data it is, or
- to comply with legal obligations, or
- to protect someone’s life, or
- to perform public tasks.
- We will provide individuals with details of the data we have about them when requested by the relevant individual.
- We will delete data if requested by the relevant individual after they have left the club and after the end of the Membership year for insurance and police purposes, with basic data (name, club membership dates, contact details) retained for a further period to enable compliance with requests by lawful UK authorities. Competition participation, results and related non-sensitive data may be retained as part of the club's historical records.
- We will endeavour to keep personal data up-to-date and accurate.
- We will store personal data securely.
- We will not share personal data with third parties without the explicit consent of the relevant individual, unless legally required to do so.
- We will endeavour not to have data breaches. In the event of a data breach, we will endeavour to rectify the breach by getting any lost or shared data back. Serious data breaches which may risk someone’s personal rights or freedoms will be reported to the Information Commissioner’s Office within 72 hours.
- To uphold this policy, we will maintain a set of data protection procedures for our committee and volunteers to follow.
- Upon an application to join the club, details will be shared with Thames Valley Police for a basic background check.
4) Request for data
Club members may apply for a copy of the data we hold on them at any time by applying in writing to the Secretary WRC at the address on our contact page. Depending upon the nature of any request, and the administrative burden generated, a fee may be payable; this will be discussed, on a case-by-case basis, with the applicant.
5) Review
We aim to review this policy every two years. The last review was 5th Jan. 2026.