Friends of the Elderly Ireland
Data Protection Policy
1. Purpose
Friends of the Elderly Ireland (Little Brothers) Limited (‘FOTE’) is committed to protecting the rights and privacy of individuals per the General Data Protection Regulation (‘the GDPR’) and the Data Protection Act 1988 – 2018 (‘the DPA’). The DPA compliments the GDPR and deals extensively with how the GDPR is enforced in Ireland. Throughout this policy, ‘Data Protection Laws’ should be taken as referring to the GDPR, the DPA and any amending legislation. Data Protection Laws give rights to individuals about the privacy of their personal data. Data Protection Laws also place responsibilities on those persons holding and processing such data. FOTE collects, stores and processes certain personal data to carry out its functions. Personal data means any information relating to an identified or identifiable living individual.
Processing covers a wide range of operations performed on personal data, including by manual or automated means. It includes the:
- Collection
- Recording
- Organisation
- Structuring
- Storage
- Adaptation or alteration
- Retrieval
- Consultation
- Use
- Disclosure by transmission
- Sharing otherwise making available
- Alignment or combination
- Restriction
- Erasure or destruction of personal data.
This Data Protection policy provides information about how FOTE collects, stores and uses personal data relating to individuals.
2. Scope
This policy applies to the FOTE Board of Directors, employees and volunteers. All individuals or groups who engage in any data handling activities on behalf of FOTE have a responsibility to follow this policy.
3. Data Protection Legislation
The GDPR came into force on 25 May 2018 and significantly changed data protection law in Europe, strengthening the rights of individuals and increasing the obligations of organisations. The GDPR is designed to give individuals more control over their data.
The fundamental principles relating to the processing of personal data under the GDPR are:
- Lawfulness
- Fairness
- Transparency
- Limiting what it can be used for
- Limiting what can be collected and used for
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability (Article 5 of the GDPR)
Although the GDPR is directly applicable as a law in all European Union member states, it allows for certain issues to be given further effect in national law. In Ireland, the national law, which, amongst other things, gives further effect to the GDPR, is the Data Protection Act 2018 (‘the 2018 Act’).
4. Data Protection Principles
FOTE is committed to following and showing compliance with the following principles relating to the processing of personal data as set out in Data Protection Laws.
Personal data will be:
- Processed lawfully, fairly and transparently
- Collected for specific, explicit and legitimate purposes
- Adequate, relevant and limited to what is necessary for processing
- Accurate and, where necessary, kept up to date
- Kept in a form such that the data subject can be identified only as long as is necessary
- Processed in a manner that ensures appropriate security.
5. Rights of individuals whose data is collected
FOTE is committed to designing and maintaining appropriate policies and procedures to protect the rights of individuals as set out in Data Protection Laws to:
- Access their personal data
- Correct their personal data
- Erase their personal data
- Restrict processing of their personal data
- Transfer their personal data
- Object to the processing of their personal data
- Withdraw consent (where FOTE relies on consent to process data).
None of the rights mentioned above are absolute, and certain situations may arise when individuals cannot enact them in particular circumstances. If this situation arises, the individual will be given a detailed explanation of why.
6. Data Controller and Data Protection Officer Contact Information
The data controller decides why and how the personal data is processed. In this instance, FOTE is the Controller for the personal data it processes. You can contact FOTE in the ways set out below.
FOTE has appointed the General Manager as its Data Protection Officer. The data protection officer can be contacted using the below methods with correspondence addressed to the: Data Protection Officer, care of the General Manager.
Letter: General Manager, Friends of the Elderly, 25 Bolton Street, Dublin 1. D01 V6H9
Email: info@friendsoftheelderly.ie
Telephone: 01-873 1855 (Our opening hours are Monday to Friday, 9.00 am to 5.00 pm.)
Website: Use the ‘Contact Us’ section of this website.
7. Legal basis for collecting and processing personal data
The legal basis for the processing of personal data by FOTE will depend on what we do as set out in our governing legislation, the Charities Act 2009, and why the processing is being carried out.
Where FOTE is processing personal data to conduct its legal functions, it must meet at least one of the requirements in Article 6 of the GDPR. Each of these requirements and examples of them are expanded on below:
Consent
The data subject has given consent to processing his or her personal data for one or more specific purposes. Consent is likely to be the appropriate ground where an organisation wants to offer a real choice to individuals – for example, whether they want to receive newsletters. Organisations must give consideration when utilising consent, as the data subject can always withdraw consent. Additionally, if a relationship between the Data Controller and data subject has a power imbalance (such as employment or during processing by a public authority), it may be difficult to establish valid legal consent.
Performance of a contract
Processing is necessary for the performance of a contract to which the data subject is party or to take steps at the data subject’s request before entering into a contract. The execution of a contract between two or more parties often involves some processing of personal data. This would include FOTE processing the personal data of staff to ensure that they receive payment in line with their employment contracts.
Legal Obligations
Processing is necessary for compliance with a legal obligation to which the controller is subject. For this section to be applicable, any data processing must have a basis in EU or Irish law. A few examples of this would be sharing employee data with the Revenue Commissioners, processing data under money laundering regulations or disclosing data as a result of a court order.
Vital Interests
Processing is necessary to protect the vital interests of the data subject or another natural person. The definition of vital interest is “an interest which is essential for the life of the data subject or that of another natural person.” This means that we can only process data under this article in a life-or-death situation and when the processing is necessary for the survival of the data subject. This is likely to only be applicable in emergency situations. This can also be applied to large-scale situations, including the processing of personal data for humanitarian purposes, including monitoring epidemics and their spread.
Performance of a task carried out in the public interest
Processing is necessary to perform a task in the public interest or in exercising official authority vested in the controller. For this section to apply, data processing must have a clear basis in law.
Legitimate Interests
Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require protection of personal data, in particular where the data subject is a child.
Legitimate Interest would apply to data processing whenever an organisation uses personal data in a way that the data subject would expect their data to be used. The conditions of Legitimate Interest would apply when the processing isn’t required by law, but there is
- A clear benefit to it
- Little risk of the processing infringing on the data subjects’ privacy
- The data subject should reasonably expect their data to be used in that way.
For example, FOTE gives an IT company access to its online platforms to ensure that the IT safeguards are sufficient and the proper safeguards are in place.
8. Data Collection
FOTE will collect and use data from various stakeholders in accordance with relevant laws and regulations for the following purposes:
- To update and maintain the databases of FOTE members (service users).
- To update and maintain the databases of volunteers.
- The recruitment of staff, payment to staff, pension administration, sharing employee personal data with tax authorities, etc.
- Fundraising, marketing, advertising, direct recruitment and public relations exercises.
- Ensure quality control and improvement of services provided by FOTE.
- To gather and use statistics on the age, gender, and location of members and volunteers to enable the charity to deliver its services.
- Capturing images and sounds using CCTV cameras in FOTE’s premises for the purpose of crime prevention and assisting with advancing any crimes or suspected crimes and to ensure the safety and well-being of any person on FOTE premises.
- Providing training to staff and volunteers.
To provide services that meet members’ needs and advance the charitable purpose of FOTE, for example, when organising classes, clubs and/or outings for members. - To promote and monitor the health, safety and general well-being of members, staff and volunteers.
- To provide referrals to other charitable and advocacy organisations in situations where FOTE does not or is unable to provide a service, or to the HSE, An Garda Síochana or other appropriate state bodies where FOTE believes a person may need their assistance or where FOTE believes there is a risk to a person’s health or well-being.
9. Data Sharing
FOTE takes all reasonable steps to ensure personal data is protected and that staff are aware of their information security obligations. FOTE limit access to personal data to those who have a business need to know it. Before any personal data is shared, FOTE ensures that the relevant data-sharing agreements and safeguards are in place.
FOTE may share personal data with trusted third parties when there is a lawful reason to do so, including:
- Service providers for the FOTE IT system
- Service providers issuing FOTE newsletter or invites to events
- Carrying out our necessary functions with government agencies including, but not limited to, Revenue Commissioners, An Garda Síochana,
- The HSE, the Charities Regulator and the Companies Registration Office
Financial Institutions for the processing of payments. - Other charities and/or advocacy groups that are better able to provide a service that FOTE may not be able to provide. This is only done with the prior consent of the data subject.
10. Data Retention
Retention refers to how long FOTE will keep personal data. The retention periods for personal data held by FOTE are based on the requirements of the data protection legislation and the purpose for which the personal data is collected and processed. The retention periods FOTE applies to personal data which it processes are also, in certain circumstances, based on legal and regulatory requirements to retain information for a specified period and on the relevant limitation periods for taking legal action.
FOTE will:
- Only hold personal data to the extent that it is adequate, relevant and not excessive.
- Retain personal data for no longer than is necessary or up to one year.
- Retain personal data for more than one year in circumstances where a member is currently engaged with and/or accessing services with FOTE, a staff member is still employed by FOTE, a person is still volunteering with FOTE, or the law requires retention for longer than one year such as with donors.
- Take appropriate security measures against unauthorised access to, alteration, destruction or accidental loss of personal data.
Ensure personal data is retained is accurate, complete and up to date.
11.Access
FOTE will ensure data subjects can exercise their rights under data protection legislation to access their data when requested. Data subjects can access their personal data retained by FOTE by submitting a Subject Access Request Form. You may obtain a ‘Subject Access Request Form’ using one of the contact methods summarized at section 6 above. You may be required to verify your identity before releasing any data to you.
Subject Access Requests will be responded to within one month of receipt or, where difficulty arises in verifying a data subject’s identity, within one month of identity verification.
A data subject may also seek to have any of his or her Personal Data corrected. This will be done within forty days of the request being made, provided reasonable evidence supports the need for correction or erasure. Data subjects must advise FOTE what information is incorrect and what should be replaced. We will inform recipients to whom that Personal Data have been disclosed (if any) unless this proves impossible or has a disproportionate effort.