Any interaction with any business inevitably involves some form of transfer of information, be that as simple as sending an email which means that your email address is supplied, or more detailed information being supplied. Our basic principle is that the information will only be used in a way which you have authorised.
Under the Data Protection Legislation, all organisations which handle personal information must comply with a number of important principles regarding the privacy and disclosure of this information.
We believe that the lawful and correct treatment of personal information is critical to our successful operation, and to maintaining our members' confidence in us. We recognise that, to maintain our reputation and integrity as an open and professional organisation, we must be fully compliant with this legislation.
In the United Kingdom and the European Economic Area (EEA), "Data Protection Legislation" means all applicable data protection and privacy legislation or regulations including The Privacy and Electronic Communications (EC Directive) Regulations 2003 (also known as PECR) and any guidance or codes of practice issued by the European Data Protection Board or the Information Commissioner, together with:
• prior to 25 May 2018, the UK Data Protection Act 1998; and
• from 25 May 2018 onwards Regulation (EU) 2016/679 (the "General Data Protection Regulation" or "GDPR”), as amended by the UK Data Protection Bill.
Outside of the EEA, "Data Protection Legislation” means local, territorial data protection and privacy legislation that governs the processing of Personal Data.
Therefore, we fully endorse and adhere to the principles of data protection set out in the Data Protection legislation and will:
• fully observe the conditions regarding the fair collection and use of personal information
• meet our legal obligations to specify the purposes for which we use personal information
• only collect and process the personal information needed to carry out our business or to comply with any legal requirements
• ensure that the personal information we use is as accurate as possible
• ensure that we don't hold personal information any longer than is necessary
• ensure that people know about their rights to see the personal information we hold about them
• take appropriate technical and organisational security measures to safeguard personal information; and
• ensure that personal information is not transferred abroad without suitable safeguards.
In addition, we will ensure that:
• there is someone with specific responsibility for data protection in the organisation
• we regularly review and audit how we handle personal information
• the ways we handle personal information are clearly described
• everyone handling personal information understands that they are responsible for following good practice
• everyone handling personal information is appropriately trained and properly supervised
• we regularly assess the performance of people who handle personal information
• anybody wanting to make enquiries about handling personal information knows what to do; and
• queries about handling personal information are deal with promptly and courteously
You have the right to request a copy of the personal information that we hold about you. To do so please write to McGregor Bond, 9/10 St Andrew Square, Edinburgh EH2 2AF . We charge a £10 fee for this service.