- B3Living /
- About us /
- Publications /
- Legal and policies /
- Key policies and compliance /
- Data Protection Policy
Data Protection Policy
| Who owns this policy? | Executive Director (Corporate Services) |
| Who approved this policy? | Data Protection Working Group |
| Next review date | November 2027 |
1. Introduction
1.1 B3Living is committed to compliance with all relevant Data Protection Legislation. B3Living will maintain a suite of policy and procedure documents setting out how it intends to implement management controls sufficient to ensure legal compliance with data protection legislation.
1.2 B3Living will ensure that the organisation works within the 7 data protection principles and that it will implement sufficient controls to ensure that it is able to demonstrate compliance with the data protection legislation including the keeping of sufficient records of data processing activities, risk assessments and relevant decisions relating to data processing activities.
1.3 B3Living will uphold the rights and freedoms of people by the data protection legislation. It will ensure that those rights and freedoms are appropriately taken into account in the decisions it takes which may affect people and will ensure that it has sufficient controls in place to assist people who wish to exercise their rights.
1.4 This policy applies to all of B3Living’s activities or operations which involve the processing of personal data.
2. Scope
2.1 The Data Protection Policy sets out B3Living’s commitment and approach to data protection.
The policy’s objectives are:
► To provide a clear frame of reference for employees to determine the organisation’s standards, aims, and ideals in respect of data protection compliance.
► To provide information to data subjects, data processors, and the regulatory authorities about how the organisation approaches data protection compliance.
2.2 Unless otherwise stated this document applies to all personal data processed by B3Living. It applies to any person who processes personal data for or on behalf of B3Living including employees, volunteers, casual and temporary employees, external organisations employed as processors and any external organisations or individuals with whom B3Living shares or discloses personal data. It also applies where B3Living is a joint controller or where relevant, acts as a processor for another controller.
3. Background
3.1 The processing of personal data in the United Kingdom is regulated by law, principally the United Kingdom General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“the Act”). Other laws inter-relate with the Act and the UK GDPR including but not limited to the Privacy and Electronic Communications Regulations (2003) (“PECR”). In addition, various guidelines, codes of practice, and case law contribute to the data protection legislation.
3.2 The data protection legislation sets out legal responsibilities on all organisations processing personal data and provides for legal rights for the people whose data are being processed. It also sets out the offences, penalties and remedies.
There are a number of criminal offences set out in the data protection legislation and individuals can be held accountable and be sentenced by the courts for offences under the data protection legislation.
3.3 This Policy is B3Living’s approach to complying with its legal responsibilities in the data protection legislation and how it enables individual rights to be upheld and exercised.
4. Aims and objectives
4.1 Fair, Lawful and Transparent Processing
4.1.1 The processing of all personal data by the organisation will only be undertaken in a fair, lawful and transparent manner meaning:
► Fairness – no data collection activities will be undertaken or commissioned without an appropriate privacy notice being provided to the person from whom data is being collected and to the people who the data is about if personal data is collected from sources other than the data subject. All privacy information and any changes to privacy information must be approved by the Data Protection Officer (DPO).
► Lawfulness – no data collection activities will be undertaken or commissioned without there being a lawful basis for the data processing activities intended to be applied to the personal data. The DPO in conjunction with managers is responsible for determining the lawful grounds for processing. Where the lawful grounds are consent, consent must be freely given. Where the lawful grounds are legitimate interests a legitimate interests assessment (LIA) will be undertaken
and documented. Where the lawful grounds are a legal obligation, the relevant legislation shall be cited and appropriately documented.
► Transparency – the organisation will endeavour to provide sufficient
information about how personal data are being processed to enable sufficient transparency about its handling of personal data.
4.2 Data Processing Purposes
4.2.1 Personal data shall only be collected, created or otherwise obtained for specific, explicit and legitimate purposes.
4.2.2 No data processing shall be undertaken or commissioned without the approval of the DPO who shall maintain a register of data processing activities and their purpose.
4.2.3 Process owners are responsible for ensuring that all of the data processing activities that they undertake and/or commission have been approved by the DPO.
4.2.4 No personal data shall be used for any purpose other than that which it was collected and/or created for without the approval of the DPO.
4.3 Data Minimisation
4.3.1 B3Living will strive to use a minimum of personal data in its data processing activities and will periodically review the relevance of the information that is collects.
4.3.2 Process owners are responsible for ensuring that no un-necessary, irrelevant or unjustifiable personal data is collected or created either directly or indirectly through the data processing activities they are responsible for and/or engage in.
4.3.3 The DPO will provide advice regarding the justification of personal data collected or created.
4.4 Data Accuracy
4.4.1 B3Living recognises that the accuracy of data is important, and that some data is more important to keep up to date than others.
4.4.2 The organisation will use its reasonable endeavours to maintain data as accurate and up to date as possible, in particular data which would have a detrimental impact on data subjects if it were inaccurate or out-of-date.
4.4.3 Process owners are responsible for ensuring that personal data they have collected or created either directly or indirectly through the data processing activities they are responsible for and/or engage in are maintained accurate and up-to-date and that personal data whose accuracy cannot reasonably be assumed to be accurate and up to date are treated appropriately through erasure or anonymisation.
4.4.4 The DPO will provide advice regarding data accuracy.
4.5 Data Retention
4.5.1 B3Living will ensure that it does not retain personal data for any longer than is necessary for the purposes for which they were collected and will apply appropriate measures at the end of data’s useful life such as erasure or anonymisation.
4.5.2 Process owners are responsible for determining the retention period for personal data under their control and the DPO shall maintain a data retention schedule setting out approved retention periods and end of life treatment. Data retention is a vitally important issue as both the over-retention and underretention of personal data could have a detrimental impact on both the data subject and the organisation.
4.6 Information Security
4.6.1 B3Living will ensure that any personal data that it processes or commissions the processing of is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
4.6.2 The Chief Digital and Technology Officer will be responsible for ensuring that suitable and sufficient measures are used to protect the data held electronically. They will also be responsible for any relevant policies and procedures around information security.
4.6.3 The Facilities Manager will ensure the physical security of office buildings and the storage of physical files.
4.6.4 All staff are responsible for maintaining desks and storage areas in a manner so as to keep personal data secure at all times against unauthorised access.
4.7 Children’s Data
4.7.1 Where personal data is processed relating to children under the age of 13, B3Living will take special measures around privacy and information rights requests.
4.7.2 Where digital services are offered to or might be used by children under the age of 18, the organisation will consider the applicability of the UK Children’s Code (Age-Appropriate Design Code) and make provisions accordingly.
4.8 Personal Data Relating to Criminal Convictions and Offences
4.8.1 If B3Living processes personal data relating to criminal convictions and offences, it shall implement suitable measures that satisfies the requirements of the Data Protection Act 2018 Schedule 1 Parts 3 and 4.
4.9 Special Categories of Personal Data
4.9.1 Special categories of personal data is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
4.9.2 The organisation shall not process special categories of personal data unless it is necessary. Where the processing of special categories of personal data is necessary, the DPO shall ensure that the lawful grounds for such processing are documented and shall maintain a periodic review of the necessity to processing the special categories of personal data.
4.10 Consent
4.10.1 The organisation will interpret consent to be as defined in the UK GDPR and that any consent shall not be valid unless:
► there is a genuine choice of whether or not to consent.
► it has been explicitly and freely given, and represents a specific, informed and unambiguous indication of the data subject’s wishes that signifies agreement to the processing of personal data relating to them.
► the consent was given through statement made by the data subject or by a clear affirmative action undertaken by them.
► the organisation can demonstrate that the data subject has been fully informed about the data processing to which they have consented and is able to prove that it has obtained valid consent lawfully.
► a mechanism is provided to data subjects to enable them to withdraw consent, and which makes the withdrawal of consent in effect as easy as it was to give and that the data subject has been informed about how to exercise their right to withdraw consent;
4.10.2 B3Living recognises that consent may be rendered invalid in the event that any of the above points cannot be verified or if there is an imbalance of power between the data controller and the data subject. The organisation recognises that consent cannot be considered to be forever and will determine a consent refresh period for every instance where consent is the lawful condition for processing.
4.11 Record Keeping and Accountability
4.11.1 In order to fulfil its responsibility to be able to demonstrate compliance with data protection legislation as well as in support the policy on transparency B3Living will maintain records of the processing activities that it controls, undertakes or otherwise commissions as required by the data protection legislation. This is called the Register of Processing Activities (ROPA).
4.11.2 The DPO shall be responsible for maintaining the ROPA and providing them to the Information Commissioner’s Office on demand.
4.11.3 The organisation shall strive to maintain additional documentation capable of demonstrating accountability as necessary: the DPO shall be responsible for determining what records should be kept, for how long and in what format in order to support its accountability.
4.12 Information Rights Procedure
4.12.1 B3Living recognises the legal rights of those whose data it is processing or intends to process and will ensure that appropriate information is provided to them advising them of their rights, and that policies and procedures are maintained to ensure that the organisation is able to recognise information rights requests and handle them appropriately when they are exercised.
4.12.2 These rights include:
► Right to information about data processing operations
► Right of access to personal data
► Right to portability of personal data
► Right of rectification of personal data
► Right of erasure of personal data
► Right to restriction of processing
► Right to object to direct marketing
► Right to object to data processing operations under some circumstances
► Right not to be subject to decisions made by automated processing under some circumstances.
► Right of complaint about the organisation’s processing of personal data and the right to a judicial remedy and compensation
4.12.3 The DPO has set out a procedure on how information rights requests are to be dealt with.
4.13 Personal Data Breaches
4.13.1 B3Living will maintain a Data Breach Reporting Procedure and will ensure that all employees and those with access to personal data are aware of it.
4.13.2 All employees and individuals with access to personal data for which the organisation is either data controller or processor must report all personal data breaches to an appropriate individual as set out in the Data Breach Reporting Procedure as soon as they become aware of the breach.
4.13.3 B3Living will log all personal data breaches and will investigate each incident without delay. Appropriate remedial action will be taken as soon as possible to isolate and contain the breach, evaluate and minimise its impact, and to recover from the effects of the breach.
4.13.4 Data protection near misses will also be recorded and investigated in the same manner as data protection breaches. The Data Breach Reporting Procedure sets out responsibilities, decision-making criteria and timescales for notifying data subjects, the Information Commissioner and the media about a personal data breach.
4.14 Data Processors
4.14.1 The organisation reserves the right to contract out data processing activities or operations involving the processing of personal data in the interests of business efficiency and effectiveness. No third-party data processors may be appointed who are unable to provide satisfactory assurances that they will handle personal data in accordance with the Data Protection Legislation.
4.14.2 Staff wishing to appoint a data processor will ensure that appropriate due diligence is undertaken on the proposed data processor in the field of information governance and data protection compliance prior to their appointment. The DPO shall provide advice and guidance in respect of this.
4.14.3 A written agreement shall be implemented between the organisation and the data processor which at least meets the requirements of the Data Protection Legislation. The DPO shall ensure that a register of such agreements/arrangements is maintained. The data processor agreement will specify what is to happen to personal data upon termination of the data processing agreement.
4.14.4 No employee is permitted to commission or appoint a third party to process data on behalf of the organisation without adhering to this policy. The DPO shall maintain operational instructions on the steps to take to appoint a data processor.
4.15 B3Living as a Data Processor
4.15.1 Where B3Living acts as a data processor it shall ensure it retains records of processing activities which record at least the information required under UK GDPR for each controller it acts on behalf of. The organisation shall ensure that it has an appropriate agreement in place with each data controller and shall ensure that its employees, volunteers, staff and contractors, receive appropriate training to enable them to ensure compliance with the instructions and contractual terms of each data controller.
4.16 Data Sharing, Disclosure and Transfer
4.16.1 B3Living will only share personal data with or otherwise disclose personal data to other organisations and third parties where there is a legal basis for doing so and the data sharing is necessary for specified purposes.
4.16.2 No data sharing or disclosure is permitted to occur without a suitable legally enforceable agreement satisfying the requirements for such agreements as set out in the Data Protection Legislation being in place.
4.16.3 Data sharing agreements must be approved by the DPO who will maintain a register of all such agreements. This policy extends to appointing others to process personal data on our behalf, sharing personal data with organisations, and providing information to ad-hoc requests for information such as those which may be received from the police and other authorities.
4.17 International Transfers of Personal Data
4.17.1 The organisation will neither transfer nor process nor will it permit personal data to be transferred or processed outside the United Kingdom without the conditions laid down in the data protection legislation being met to ensure that the level of protection of personal data are not undermined. Any transfer or processing of personal data that the organisation undertakes or commissions whether directly or indirectly must be approved by the DPO and may only take place if one of the following is satisfied.
► The territory into which the data are being transferred is one approved by the UK’s Information Commissioner.
► The territory into which the data are being transferred is within the European Economic Area.
► The territory into which the data are being transferred has an adequacy decision issued by the European Commission and/or by the Information Commissioner.
► The transfer is made under the unaltered terms of the standard contractual clauses issued by the European Commission for such purposes.
► The transfer is made under the provision of binding corporate rules which have been approved and certified by the European Commission.
► The transfer is made in accordance with one of the exceptions set out in the Data Protection Legislation.
4.17.2 Where necessary the DPO shall ensure that a risk assessment is carried out on any third country the organisation intends to transfer personal data to and that any supplementary measures are implemented as necessary to ensure adequate protection of personal data
4.18 Risk Assessment
4.18.1 B3Living will adopt a risk-based approach to processing personal data ensuring that it assesses any risks to privacy or to the rights and freedoms of people before commencing or commissioning or changing data processing activities. Where necessary it shall, as a minimum, ensure that a data protection impact assessment (DPIA) is undertaken where required by data protection legislation and/or when one is deemed to be desirable by the DPO.
4.18.2 The organisation will maintain a procedure setting out how data protection impact assessments are to be carried out and documented and ensure that appropriate resources are available to advise on DPIA’s.
4.18.3 A record of DPIA’s carried out by B3Living will be maintained.
4.19 Training and Awareness
4.19.1 The Organisation will ensure that all those who it engages to process personal data either directly or indirectly are provided with appropriate training in the application of this and other data protection policies and procedures and in their data protection responsibilities.
4.19.2 It will also undertake data protection awareness raising activities from time to time to keep data protection front of mind. All training and awareness raising activities will be logged. Refresher training will be provided periodically. Process owners shall determine the training needs of those people within their sphere of control and that appropriate data protection awareness and training is provided, measured and reported.
4.20 Continuous Improvement, Audit and Compliance Checking
4.20.1 B3Living will undertake periodic compliance checks to test whether its policies and procedures are being adhered to and to test the effectiveness of its control measures.
4.20.2 Corrective action will be required where non-conformance is found. Records will be kept of all such audits and compliance checks including corrective action requests raised. Disciplinary action will be taken against individuals who fail to act upon the reasonable corrective action requests properly formulated and raised through data protection audits. The Audit and Risk Committee will be provided with a summary of audit findings periodically.
4.21 Data Protection by Design and Default
4.21.1 B3Living shall strive to foster a culture of data protection by design and by default in all of its data processing activities. It shall ensure that measures are in place to encourage all those involved in data processing activities to adopt a model of continuous improvement to the technical and organisational measures that implement the data protection principles and safeguards into processing activities.
4.21.2 B3Living shall strive to ensure that by default, only personal data which are necessary for each specific purpose of the processing are processed and that the extent of the processing, period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
5. Equality, diversity and inclusion
This policy applies to all colleagues and customers. Safeguards will be applied to protected characteristics. An EIA has been completed for this policy, which has not identified any negative impact on different equality groups considered as part of B3Living’s equality impact assessment process. A full assessment is not required.
6. Data protection and information security
B3Living and its partners and contractors who share and process data will do so in line with the points set out in this policy.
7. Customer voice
We aim to process personal data in a way that protects the rights and freedoms of individuals.
8. Compliance
This policy complies with all relevant data protection legislations and guidance issued by the Information Commissioners Office (ICO).
9. Linked policies, procedures and guidance
- CCTV Policy
- Document and Data Retention Policy
10. Responsibilities
10.1.1 Data Controller – B3Living is the legal data controller under the data protection legislation
10.1.2 Chief Executive Officer – is the accountable officer responsible for the management of the organisation and ensuring appropriate mechanism are in place to support service delivery. Protecting data and confidentiality is pivotal to B3Living being able to operate.
10.1.3 Executive Directors, Managers and Supervisors - Each Executive Director in their respective areas of responsibility, must ensure that all staff members are aware of this policy, other relevant policies and procedures, and their responsibilities concerning the processing of personal data. Each Executive Director must ensure this policy is adhered to. Managers and supervisory staff are responsible for ensuring that all data processing operations under their control or area of responsibility or commissioned by them are undertaken in compliance with this policy and other relevant data protection policies. They are responsible for ensuring that anyone processing data is sufficiently aware of this policy and how it applies to their job role and sufficiently trained to carry out their duties in compliance with this policy.
10.1.4 Data Protection Officer (DPO) – B3Living has appointed a DPO who shall be responsible for maintaining the policies, guidance and training needed to ensure that B3Living is compliant with data protection legislation. The DPO shall monitor and report to the senior management in respect of compliance with data protection legislation, arrange for the investigation of any breaches or security incidents, and maintain suitable records of processing activities. The DPO shall monitor the evolution of the Data Protection Legislation, case law, guidance, and codes of practice and incorporate relevant changes into the Organisation’s policy.
10.1.5 Process Owners - Data processing activities are managed by job roles or individuals. The process owner has primary operational responsibility for compliance with data protection legislation and good practice in respect of assigned processing activities. Process owners are responsible for understanding what personal data are used in their business area and how it is used, who has access to it and why. As a result, they are able to understand and address risks to the data and the organisation. Where the nature of the organisation’s activities is such that personal data are processed as part of a single business process across a number of separate business areas then, responsibility for the business process as a whole may be assigned to one named process owner.
10.1.6 Data Protection Working Group – B3Living has a Data Protection Working Group, the group is responsible for reviewing and agreeing data protection policies and procedures and to keep under review any breaches and requests made by individuals in relation to their rights.
10.1.7 Chief Digital and Technology Officer – shall be responsible for information security in relation to any IT systems and data held electronically.
10.1.8 All employees including temporary or casual posts and any volunteers - Anyone who is directly engaged by B3Living to undertake data processing activities, involved in the receipt, handling or communication of personal data must adhere to this policy. Anyone who is not confident in or has concerns about data handling practices that they are undertaking, or witnessing should contact the DPO. Individuals are expected to complete appropriate training from time to time. Everyone within the Organisation has a duty to respect data subjects’ rights to confidentiality. Disciplinary action could be instigated on staff for non-compliance with relevant policies and legislation.
10.1.9 Partner and Third-Party Responsibilities - Any Partner or third-party organisation that is commissioned to process data or receives data from B3Living or is able to access any personal data which is within the custody of B3Living must enter into a legally enforceable agreement with B3Living the nature of which will be determined by the level of involvement with the data that is held/shared/accessed.