u3a

Aughton and Ormskirk

Data Protection Policy

1. Scope of the policy 

This policy applies to the work of Aughton & Ormskirk u3a. The policy sets out the requirements that we have to collect and process information for membership purposes. The policy details how personal information will be collected, stored and managed in line with data protection principles and the General Data Protection Regulation (GDPR) and the Data (Use and Access) Act (DUAA). The policy is reviewed on an ongoing basis by the Trustees to ensure that our u3a remains compliant. 

It is recommended that this Data Protection Policy is read in conjunction with the following:

  • Privacy Policy 
  • Communications Policy
  • Website Terms of Use (a link to this can be found at the foot of each web page)

2. Why this policy exists 

This data protection policy ensures our u3a: 

  • Complies with data protection law and follows good practice;
  • Protects the rights of members;
  • Is open about how it stores and processes members’ data;
  • Protects itself from the risks of a data breach.

3. General guidelines 

The only people able to access personal data are those who need to communicate with or provide a service to our members. The majority of those able to access data are Trustees and group leaders. No one is given access to data or records that they don’t need.

We provide induction training to those who have access to data to help them understand their responsibilities when handling it. Every person is required to sign a confidentiality agreement before access to Beacon (our membership system) is granted.

Those with access to data should keep all data secure by taking sensible precautions and following the guidelines below:

  • Strong passwords must be used, and they should never be shared;
  • Data should not be shared outside of the u3a unless with prior consent and/or for specific and agreed reasons. Examples would include Gift Aid information provided to HMRC, or information provided to the distribution company for the Trust publications;
  • Member information should be refreshed periodically.  

4. Data protection principles 

The GDPR identifies key data protection principles: 

Principle 1 - Personal data shall be processed lawfully, fairly and in a transparent manner. 

Principle 2 - Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes. 

Principle 3 - The collection of personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. 

Principle 4 – Personal data held should be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.  

Principle 5 – Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for the which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals.

Principle 6 - Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.  

5. Lawful, fair, and transparent data processing 

We request personal information from potential members and members for membership applications and for sending communications regarding members’ involvement with the u3a. Members will be informed as to why the information is being requested and what the information will be used for. The lawful basis for obtaining member information is due to the legitimate interest relationship that the u3a has with individual members. See details in Appendix 1.

If members are asked to provide consent for additional processing purposes and they subsequently wish for their data not to be used for these purposes, they should contact the Membership Secretary. Where these requests are received, they will be acted upon promptly and the member will be informed as to when the action has been taken.

6. Processed for specified, explicit and legitimate purposes 

Members will be informed as to how their information will be used and the Trustees will seek to ensure that member information is not used inappropriately. Appropriate use of information provided by members will include: 

  • Communicating with members about our events and activities;
  • Group leaders communicating with group members about specific group activities;
  • Sending members information about Third Age Trust events and activities;
  • Communicating with members about their membership and/or renewal of their membership;
  • Communicating with members about specific issues that may have arisen during the course of their membership; 

Our u3a will ensure that members’ information is managed in such a way as to not infringe an individual member’s rights which include: 

  • The right of access  
  • The right to rectify
  • The right to erasure  
  • The right to restrict the use
  • The right to data portability  
  • The right to object  
  • The right to withdraw consent
  • The right to complain

7. Adequate, Relevant and Limited Data Processing

Members will only be asked to provide information that is relevant for membership purposes. This will include: 

  • Name 
  • Home address 
  • Email address 
  • Telephone number 

8. Accuracy of data and keeping data up to date 

We have a responsibility to ensure members' information is kept up to date.

To ensure the information we hold is accurate and up to date, members need to inform us of any changes to their personal information. This can be done via the members’ portal or by contacting the Membership Secretary.

9. Accountability and governance 

The Trustees are responsible for ensuring that our u3a remains compliant with data protection requirements and can evidence that it has. 

Trustees will ensure that new Trustees receive an induction into the requirements of GDPR and the implications for their role. They will also ensure that group leaders (via Group Support) are made aware of their responsibilities in relation to the data they hold and process. 

Trustees will stay up to date with guidance and practice within the u3a movement and will seek advice from the Third Age Trust National Office should any uncertainties arise. 

Trustees will review data protection requirements on an ongoing basis as well as reviewing who has access to data and how data is stored and deleted. 

When Trustees and group leaders relinquish their roles, they will be asked to either pass on data to those who need it and/or delete data. 

10. Secure Processing 

Trustees have a responsibility to ensure that data is both securely held and processed. This will include: 

  • Using strong passwords;
  • Not sharing passwords;
  • Restricting access to member information to those who need to communicate with members on a regular basis;
  • Using password protection on laptops and PCs that contain personal information;
  • Using password protection, a membership database or secure cloud systems when sharing data;
  • Antivirus software should be in place on devices used for processing member data. 

11. Subject Access Request 

Members are entitled to request access to the information that is held by our u3a. The request needs to be received in the form of a written request to the Membership Secretary. On receipt of the request, the request will be formally acknowledged and dealt with expediently (the legislation requires that information should generally be provided within one month) unless there are exceptional circumstances as to why the request cannot be granted. A written response detailing all information held on the member will be provided. A record shall be kept of the date of the request and the date of the response. 

12. Data Breach Notification 

If a data breach occurs, action will be taken to minimise the harm. This will include ensuring that all Trustees are made aware that a breach has taken place and how the breach occurred. The Trustees shall then seek to rectify the cause of the breach as soon as possible to prevent any further breaches. The Chair will contact National Office as soon as possible after the breach has occurred to notify of the breach. A discussion will take place between the Chair and National Office as to the seriousness of the breach, action to be taken and, where necessary, the Information Commissioner's Office would be notified. The Chair shall also contact the relevant u3a members to inform them of the data breach and actions taken to resolve the breach. 

Where a member feels that there has been a breach by the u3a, they should contact the Chair who will ask the member to provide an outline of the breach. If the initial contact is by telephone, they will ask the member to follow this up with an email or a letter detailing their concern. The alleged breach will then be investigated by a Trustee who is not in any way implicated in the breach. The u3a member should also be informed that they can report their concerns to National Office if they don't feel satisfied with the response from the u3a. Breach matters will be subject to a full investigation, records will be kept and all those involved notified of the outcome.

13. Adoption and Review

This policy was adopted on: 27th May 2025

Last review date: July 2026

Next review date: July 2027

Changes since last version (between May 2025 and July 2026):

  • Reference to the Data (Use and Access) Act 2025 (DUAA) added to the Introduction.
  • Reference to Social Media Policy amended to Communications Policy in the Introduction.
  • Appendix 1 added to show why Legitimate Interest is the legal basis for using members’ data.

This Legitimate Interest Assessment has been compiled to set out the reasons why Aughton & Ormskirk u3a (we) process membership information, and thus show why ‘Legitimate Interest’ is the legal basis for using members’ personal data.

We request personal data to be able to register individuals for membership of our u3a. The personal data provided will also be used to communicate with members regarding the activities of our u3a and to keep members informed regarding any groups or activities that they undertake with us. The information will also be used to inform members about the Annual General Meeting and notify them when renewal is due. Member information is shared with a third party processor for the supply of the Trust publication – Third Age Matters (TAM), where members have opted to receive this publication. Membership information is securely held and access is restricted to those who need to process data for membership purposes. Storage and processing of membership data is done in line with GDPR and safeguarding requirements. We operate with a data protection policy and privacy policy and have sought advice from the Third Age Trust in developing guidance in respect of our practice in relation to data protection.

We request minimal information from potential members which includes personal details and contact details. This information is proportionate to the requirements of the u3a fulfilling its responsibilities in relation to being able to communicate effectively with its membership. We would not be able to register members or process applications without the provision of a certain amount of membership information. We have a duty of care to our membership and need to retain a certain amount of personal information in order to know who our members are and which members are paid up members. This is necessary for meeting the requirements of the insurance provision for u3a members.

The personal data requested is that which is needed for registering and processing individuals as members of our u3a. The data requested is minimal personal data and that which is needed for communicating with members. All the data gathered is from individuals who provide the information as part of their application to join us. Membership is for a 12 month period and members are encouraged to update their personal information at renewal time. The reasons for collecting personal information is documented on the new member form and on the joining page of the website so potential members can see this before they join. A copy of our Privacy Policy and Data Protection Policy is available on our website for anyone who wishes to have further details about how their information is used and who it is shared with. We hold information securely and it will only be accessed by those who need to see it. Membership data will not be processed for any purpose other than in connection with an individual’s membership. Communications sent will be relevant and targeted to the individual’s membership activities. Additionally, enews is sent to members once per month with general information but members can opt out of receiving this if they wish. Members will not be sent marketing materials or information that does not relate to our u3a. Group leaders will be informed of the importance of restricting their communications with members to that which is needed for organisation of the group. All those who process membership information for the u3a will receive an induction into the requirements of GDPR and the restrictions around data processing. In addition, volunteers will be informed of the need to keep data secure and restricted to those who need access to it.

Through compilation of this assessment Aughton & Ormskirk u3a considers that it has a legitimate interest to collect, hold and process membership information. This assessment is an appendix to the Data Protection Policy and will, therefore, be reviewed every year in order to ensure that legitimate interest remains the most appropriate lawful basis for gathering membership information.