GDPR – DATA PROTECTION
Introduction
New legislation concerning Data Protection, The General Data Protection Regulation (GDPR), was introduced with effect from 25th May 2018, and is intended to strengthen and unify data protection for all individuals and to give them control over their personal data.
Whenever personal data is processed, collected, recorded, stored or disposed of it must be done within the terms of the GDPR. The GDPR and other information rights laws set out individual’s rights regarding their personal information.
Policy statement
The Trust is committed to a policy of protecting the rights and privacy of its grant applicants as well as its own trustees or employees, and any third parties who come into contact with the Trust, in accordance with the GDPR.
What we collect
We may collect any or all of the following information in respect of grant applications:
- Name and title
- Contact information
- Postal address
- Telephone and/or email address
- Bank account details
- Original or copy communications (electronic or paper) between individuals and The Trust
Purpose of data held by The Trust
Data may be held by The Trust for any of the following purposes:
- Consideration of grant applications
- Communications by The Trust to and from grant applicants, trustees and employees, or with any other individuals, including, e.g. suppliers, contractors, lawyers or accountants
- Internal record keeping
- Employment details
- Data bank administration
Data Protection Principles
In terms of the GDPR, The Trust is the ‘Data Controller’, and as such determines the purpose for which, and the manner in which, any personal data is, or is to be, processed. We will ensure that we have
1 Fairly and lawfully processed personal data
We will always identify ourselves in any communications with grant applicants, or any other individuals.
2 Processed for limited purpose
We will not use data for a purpose other than those set out above.
3 Adequate, relevant and not excessive
The Trust will hold the data relevant for our purposes, ensuring we hold neither too much nor too little data in respect of the individuals about whom the data is held. If data given or obtained is excessive for such purpose, it will be immediately deleted or destroyed.
4 Accurate and up to date
We will only keep grant applicants’ data indefinitely. We will also hold electronic data including spreadsheets, minutes and lists for grant administration purposes indefinitely. All amendments will be made immediately, and data no longer required will be deleted or destroyed. The same will apply to Trustees and/or employee records (employee records must be kept for a minimum of 3 tax years as per HMRC rules). Other financial data will need to be kept for a minimum of 6 tax years as per HMRC rules.
5 Processed in accordance with the individual’s rights
Upon request to the Data Officer, all grant applicants or other individuals have the right to the removal and/or correction of any inaccurate data about them.
6 Security
The ongoing administration of data is the responsibility of the Data Processor, which is the Grants Manager. The Trust’s General Data Protection is the responsibility of the Data Officer, which is the Chair of Trustees.
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of data through secure two-stage factor authentication.
7 Not shared with or given to any other organisation
Data will only be used for The Trust’s business and communication with grant applicants or employees. Data will not be shared with any other organisation, unless required to do so by law or by a regulatory body.
Chris Davis
Chair of the Trustees & Data Officer
Policy last reviewed: November 2025