DATA PRIVACY NOTICE

ENGLAND POLICE Rugby Football Club (also referred to in this document as ‘the Club’, ‘we’ or ‘us’) is committed to full compliance with the requirements of the General Data Protection Regulation (‘GDPR’). We need to collect and use information about people with whom we engage in order to operate and carry out our core function of facilitating the playing of rugby union football. We regard the lawful and appropriate treatment of personal information as being integral to our

operations and to maintaining the confidence of all those with whom we engage. We will endeavour to deal appropriately and in accordance with the principles of GDPR with all personal information we use however it is recorded and collected and whether it is on paper, in electronic records or any other format.

The purpose of this document is to set out the policies and processes we will adopt to ensure that all of us who have access to any personal data held be us as data users are cognisant with and will abide by the obligations imposed by GDPR.

The GDPR Principles

In summary, to comply with the six basic principles of GDPR the way we process personal data must be:

1. Fair, lawful and transparent;

2. For a legitimate purpose;

3. Adequate, relevant and limited;

4. Accurate and up to date;

5. Such as to ensure that data is kept only as long as is necessary; and 6. Such as to ensure that it is kept secure.

How do we use your data?

ENGLAND POLICE RFC uses your personal data to manage and administer its membership and your involvement with its teams and club, and to keep in contact with you for these purposes. Some data is shared with the Rugby Football Union (‘ the RFU’), who use your data to regulate, develop and manage the game. Data is also shared with the Northumberland Rugby Union (‘the NRU’) as our Constituent Body to which some aspects of the development and management of the game are delegated. Where we, the RFU or NRU rely on your consent, such as any consent we seek for email marketing, we will do this specifically and you can withdraw this consent at any time. Amongst the data we collect from you may be medical (including injury) information. We will hold this where you (or your parent) have given consent, so that we can ensure that we are aware of your condition and that you are supported appropriately. Where you work in a particular role within the game, you may be required to undergo a Disclosure & Barring Service (‘DBS’) check using the RFU’s eDBS system. The result of this check will be input into your Game Management Service (GMS) record.

ENGLAND POLICE RUGBY FOOTBALL CLUB

ENGLAND POLICE GDPR Policy Statement version 1.2

What does this policy cover?

We will make use of the data we handle in relation to our members, players, supporters, sponsors, suppliers and anyone else with whom we engage in carrying out our core functions including our use of  GMS.  The policy also describes the RFU’s use of data on GMS. It also describes your data protection rights,  including your right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the ‘What rights do you have?’ section below.

What information do we collect?

We collect and process personal data from you or your parent when you join and when we carry out annual reviews and renewals of your membership. This includes:

your name your gender, your date of birth, your RFU ID (as assigned in GMS) your home address, email address and phone number; your type of membership and involvement in particular teams, or any key role you may have been allocated, such as Chair, Safeguarding Lead, Membership Secretary etc.; your payment and/or bank account details, where you provide these to pay for membership or to enable us to fulfil other contractual obligations to you; your marketing preferences, including any consents you have given us; your medical conditions or disability information, where you provide this to us with your consent (or your parent’s consent) to ensure we are aware of any support we may need to provide to you.

Some information will be generated as part of your involvement with us, in particular data about your performance, involvement in particular matches in match reports and details of any disciplinary issues or incidents you may be involved in on or off the pitch, such as within health and safety records.

What information do we receive from third parties?

Sometimes, we receive information about you from third parties. For example, if you are a child, we may be given information about you by your parents.

We may receive information relating to your existing registrations with other clubs or rugby bodies or disciplinary history from the RFU through GMS. Additionally, for certain role holders or those working with children, we may receive information from the Disclosure and Barring Service and  RFU  on the status of any  DBS  check you have been required to take.

How do we use this information, and what is the legal basis for its use?

We process this personal data for the following purposes:

1. As required by the Club to conduct our business and pursue our legitimate interests, in particular:

ENGLAND POLICE RUGBY FOOTBALL CLUB.

ENGLAND POLICE GDPR Policy Statement version 1.3

we will use your information to manage and administer your membership and your involvement with its teams and club, and to keep in contact with you for these purposes; we will also use data to maintain records of our performances and history, including match reports, score lines and team sheets; where we use CCTV cameras to maintain the security of our premises we may use the footage for the purpose of investigating any apparent breaches of security at the premises. we may choose to send you promotional materials and offers by post or by phone, or by email where we want to send you offers relating to similar products and services that you have previously bought. Before doing so we will expressly seek your consent. we may use the data of some individuals to invite them to  take  part  in market research;

2. To fulfil a contract, or take steps linked to a contract: this is relevant where you make a payment for your membership and any merchandise,  or enter a competition. This includes: taking payments;  communicating with you;  providing and arranging the delivery or other provision of products, prizes or services; 

3. Where you give us consent: we will send you direct marketing or promotional material by email; we may handle medical or disability information you or your parent provides to us, to ensure we support you appropriately; on other occasions where we ask you for consent, we will use the data for the purpose which we explain at that time.

4. For the purposes of fulfilling any legal obligations to which we are subject: we maintain records such as health and safety records and accounting records in order to meet specific legal requirements; we ensure, where you will work with children, that you have undergone an appropriate DBS check – this is also carried out with your consent. where you hold a  role at the  Club requiring us to check your right to work, we may process information to meet our statutory duties; we may respond to requests by government or law enforcement authorities conducting an investigation.

ENGLAND POLICE RUGBY FOOTBALL CLUB.

ENGLAND POLICE GDPR Policy Statement version 1.4

How does the RFU use any of my information?

The RFU provides GMS, but make its own use of the following information: your name; your gender; your date of birth; your RFU ID (as assigned in GMS); your home address, email address and phone number; and your type of membership and involvement in particular teams at the Club, or any key role you may have been allocated, such as Chair, Safeguarding Lead, Membership Secretary etc.

The RFU uses this information as follows: As required by the RFU to conduct its business and pursue its legitimate interests, in particular: o communicating with you or about you where necessary to administer Rugby in England, including responding to any questions you send to the RFU about GMS; o administering and ensuring the eligibility of players, match officials and others involved in English rugby – this may involve the receipt of limited amounts of sensitive data in relation to disabled players, where they are registered for a disabled league or team, or in relation to antidoping matters; o maintaining records of the game as played in England, in particular maintaining details of discipline and misconduct; o monitoring use of GMS, and using this to help it monitor, improve and protect its content and services and investigate any complaints received from you or from others about GMS; o maintaining statistics and conducting analysis on the make- up of rugby’s participants; o ensuring compliance with the current World Rugby and RFU Rules and Regulations including those on the affiliation of clubs, Referee Societies, Constituent Bodies and other rugby bodies, and registration of players; and o communicating with you to ask for your opinion on RFU initiatives. For purposes which are required by law: o The RFU will ensure, where you will work with children and where this is required, that you have undergone an appropriate DBS check – this is also carried out with your consent. o The RFU may respond to requests by government or law enforcement authorities conducting an investigation.

ENGLAND POLICE RUGBY FOOTBALL CLUB

ENGLAND POLICE GDPR Policy Statement version 1.5

Withdrawing consent or otherwise objecting to direct marketing

Wherever we rely on your consent you will always be able to withdraw that consent unless we have other legal grounds for processing your data for other purposes, such as those set out above. In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below in the ‘How do I get in touch with you or the RFU?’ section below.

Who will we share this data with, where and when?

In addition to sharing data with the RFU, we may share your data with other third parties where to do would be consistent with the GDPR principles.

Some limited information may be shared with other stakeholders in rugby, such as other clubs, Constituent Bodies, Referee Societies, League Organisers, so that they can maintain appropriate records and assist us in organising matches and administering the game.

Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if required for the legal protection of our or the RFU’s legitimate interests in compliance with applicable laws.

Personal data will also be shared with third-party service providers, who will process it on our behalf for the purposes identified above. Such third parties include the RFU as the provider of GMS and other providers of data processing services such as Pitchero.

What rights do you have?

You have the right to ask us for a copy of your personal data; to correct, delete or restrict (stop any active) processing of your personal data; and to obtain the personal data you provide to us for a contract or with your consent in a structured, machine-readable format.

In addition, you can object to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement, or where we are using the data for direct marketing).

These rights may be limited, for example, if fulfilling your request would reveal personal data about another person, or if you ask us to delete information that we are required by law to keep or have compelling legitimate interests in keeping. You have the same rights for data held by the RFU for its own purposes on GMS. To exercise any of these rights, you can get in touch with us or, as appropriate, the RFU or its Data Protection Officer using the details set out below. If you have any

unresolved concerns, you have the right to complain to the Information Commissioner’s Office.

Much of the information listed above must be provided on a  mandatory basis so that we can make the appropriate legal checks and register you as required by RFU Rules and Regulations. We will inform you

ENGLAND POLICE RUGBY FOOTBALL CLUB

ENGLAND POLICE GDPR Policy Statement version 1.6

which information is mandatory when it is collected. Some information is optional, particularly information such as your medical information. If this is not provided, we may not be able to provide you with appropriate assistance, services or support. How do you get in touch with us or the RFU?

We hope that we can satisfy any queries you may have about the way we process your data. If you have any concerns about how we process your data, or would like to opt out of direct marketing, you can get in touch with us at dick.pattimore@southyorks.pnn.police.uk

or by writing to The Hon. Secretary, ENGLAND POLICE RFC, If you have any concerns about how the RFU processes your data, you can get in touch at legal@rfu.com or by writing to The Data Protection Officer, Rugby Football Union, Twickenham Stadium, 200 Whitton Road, Twickenham TW2 7BA.

How long will we retain your data?

We process the majority of your data for as long as you are an active member of the Club and for 3 years after this.

Where we process personal data for marketing purposes or with your consent, we process the data for 3 years unless you ask us to stop, when we will only process the data for a short period after this to comply with your requests. We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your wishes in future.

Where we process personal data in connection with performing a contract or for a competition, we keep the data for 6 years from your last interaction with us.

We will retain information held to maintain statutory records in line with appropriate statutory requirements or guidance.

The RFU will maintain records of individuals who have registered on GMS, records of DBS checks and the resulting outcomes and other disciplinary matters for such period as is set out in the RFU’s privacy notice which is set out at www.englandrugby.com. Records of your involvement in a particular match, on team sheets, on results pages or in match reports may be held indefinitely both by us and the RFU in order to maintain a record of the