Key details
Policy prepared by: Everyman Theatre Cardiff
Approved by management on: 24.05.18
Policy became operational on: 5.05.18
Reviewed on 07 June 2021
Next review date: 04 Oct 2021
Introduction
Everyman Theatre Cardiff is a registered charity which needs to gather and use certain information about individuals.
These can include customers, suppliers, business contacts, members and other people the organisation has a relationship with or may need to contact.
This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law.
Why this policy exists
This data protection policy ensures Everyman Theatre Cardiff
- Complies with data protection law and follow good practice
- Protects the rights of customers, partners and members
- Is open about how it stores and processes individuals’ data
Protects itself from the risks of a data breach
Data protection law (See GDPR Policy)
The Data Protection Act 1998 describes how organisations — including Everyman Theatre Cardiff must collect, handle and store personal information.
These rules apply regardless of whether data is stored electronically, on paper or on other materials.
To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully.
The Data Protection Act is underpinned by eight important principles. These say that personal data must:
1. Be processed fairly and lawfully
2. Be obtained only for specific, lawful purposes
3. Be adequate, relevant and not excessive
4. Be accurate and kept up to date
5. Not be held for any longer than necessary
6. Be processed in accordance with the rights of data subjects
7. Be protected in appropriate ways
8. Not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection
People, risks and responsibilities
Policy scope
When you book tickets to see Everyman Theatre Cardiff productions you provide us and our partners who act as booking agencies with some basic personal information in order to process your booking.
The information you provide is held by us to process your booking and payment and to notify you if anything changes in relation to your booking, for example if a performance is cancelled.
At the time of your booking we or our partners will also ask you if you wish to receive information about forthcoming Everyman productions at Chapter Arts Centre, the Cardiff Open Air Theatre Festival and Everyman touring productions at other venues.
If you provide your consent, then we will occasionally contact you with this information.
We will not share your details with any other theatrical organisation nor will we pass your information on to third parties except to facilitate our mailing to you.
We will offer you the opportunity to opt out of future mailings at every contact either by email or by telephone.
This policy applies to:
All board members, individuals who are paid members and volunteers of Everyman Theatre Cardiff
All contractors, suppliers and other people working on behalf of Everyman Theatre Cardiff
It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the Data Protection Act 1998. This can include:
- Names of individuals
- Postal addresses
- Email addresses
- Telephone numbers
Any other information relating to individuals
Data protection risks
This policy helps to protect Everyman Theatre Cardiff from some very real data security risks, including:
- Breaches of confidentiality. For instance, information being given out inappropriately.
- Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
- Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.
Responsibilities
All board members, paid members and volunteers of Everyman Theatre Cardiff has some responsibility for ensuring data is collected, stored and handled appropriately.
Each individual that handles personal data must ensure that it is handled and processed in line with this policy and data protection principles.
However, these people have key areas of responsibility:
The board of Everyman Theatre is ultimately responsible for ensuring that Everyman Theatre Cardiff meets its legal obligations.
The board of Everyman Theatre is responsible for:
- Keeping the board updated about data protection responsibilities, risks and issues.
- Reviewing all data protection procedures and related policies, in line with an agreed schedule.
- Arranging data protection training and advice for the people covered by this policy.
- Handling data protection questions from staff and anyone else covered by this policy.
- Dealing with requests from individuals to see the data Everyman Theatre Cardiff holds about them (also called ‘subject access requests’).
Checking and approving any contracts or agreements with third parties that may handle the company’s sensitive data.
The board of Everyman Theatre is responsible for:
- Ensuring all systems, services and equipment used for storing data meet acceptable security standards.
- Performing regular checks and scans to ensure security hardware and software is functioning properly.
Evaluating any third-party services the company is considering using to store or process data. For instance, cloud computing services.
The board of Everyman Theatre is responsible for:
- Approving any data protection statements attached to communications such as emails and letters.
- Addressing any data protection queries from journalists or media outlets like newspapers.
Where necessary, working with members, volunteers and partners to ensure marketing initiatives abide by data protection principles.
Change Record
Date of Change: | Changed By: | Comments: |
25/05/2021 | Matty | Updated from original to include textural and formatting changes only. |
07/06/2021 | N/A | Policy approved by the Trustees |