Everyman Theatre Cardiff
Data protection policy

Key details

Policy prepared by:  Everyman Theatre Cardiff

Approved by management on:  24.05.18

Policy became operational on: 5.05.18           

Reviewed on 07 June 2021
Next review date: 04 Oct 2021               


Everyman Theatre Cardiff is a registered charity which needs to gather and use certain information about individuals.

These can include customers, suppliers, business contacts, members and other people the organisation has a relationship with or may need to contact.

This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law.

Why this policy exists

This data protection policy ensures Everyman Theatre Cardiff

  • Complies with data protection law and follow good practice
  • Protects the rights of customers, partners and members
  • Is open about how it stores and processes individuals’ data

Protects itself from the risks of a data breach

Data protection law (See GDPR Policy)

The Data Protection Act 1998 describes how organisations — including Everyman Theatre Cardiff must collect, handle and store personal information.

These rules apply regardless of whether data is stored electronically, on paper or on other materials.

To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully.

The Data Protection Act is underpinned by eight important principles. These say that personal data must:

1.     Be processed fairly and lawfully

2.     Be obtained only for specific, lawful purposes

3.     Be adequate, relevant and not excessive

4.     Be accurate and kept up to date

5.     Not be held for any longer than necessary

6.     Be processed in accordance with the rights of data subjects

7.     Be protected in appropriate ways

8.     Not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection

People, risks and responsibilities

Policy scope

When you book tickets to see Everyman Theatre Cardiff productions you provide us and our partners who act as booking agencies with some basic personal information in order to process your booking.

The information you provide is held by us to process your booking and payment and to notify you if anything changes in relation to your booking, for example if a performance is cancelled.

At the time of your booking we or our partners will also ask you if you wish to receive information about forthcoming Everyman productions at Chapter Arts Centre, the Cardiff Open Air Theatre Festival and Everyman touring productions at other venues.

If you provide your consent, then we will occasionally contact you with this information.

We will not share your details with any other theatrical organisation nor will we pass your information on to third parties except to facilitate our mailing to you.

We will offer you the opportunity to opt out of future mailings at every contact either by email or by telephone.

This policy applies to:

All board members, individuals who are paid members and volunteers of Everyman Theatre Cardiff

All contractors, suppliers and other people working on behalf of Everyman Theatre Cardiff

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the Data Protection Act 1998. This can include:

  • Names of individuals
  • Postal addresses
  • Email addresses
  • Telephone numbers

Any other information relating to individuals

Data protection risks

This policy helps to protect Everyman Theatre Cardiff from some very real data security risks, including:

  • Breaches of confidentiality. For instance, information being given out inappropriately.
  • Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
  • Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.


All board members, paid members and volunteers of Everyman Theatre Cardiff has some responsibility for ensuring data is collected, stored and handled appropriately.

Each individual that handles personal data must ensure that it is handled and processed in line with this policy and data protection principles.

However, these people have key areas of responsibility:

The board of Everyman Theatre is ultimately responsible for ensuring that Everyman Theatre Cardiff meets its legal obligations.

The board of Everyman Theatre is responsible for:

  • Keeping the board updated about data protection responsibilities, risks and issues.
  • Reviewing all data protection procedures and related policies, in line with an agreed schedule.
  • Arranging data protection training and advice for the people covered by this policy.
  • Handling data protection questions from staff and anyone else covered by this policy.
  • Dealing with requests from individuals to see the data Everyman Theatre Cardiff holds about them (also called ‘subject access requests’).

Checking and approving any contracts or agreements with third parties that may handle the company’s sensitive data.
The board of Everyman Theatre is responsible for:

  • Ensuring all systems, services and equipment used for storing data meet acceptable security standards.
  • Performing regular checks and scans to ensure security hardware and software is functioning properly.

Evaluating any third-party services the company is considering using to store or process data. For instance, cloud computing services.
The board of Everyman Theatre is responsible for:

  • Approving any data protection statements attached to communications such as emails and letters.
  • Addressing any data protection queries from journalists or media outlets like newspapers.

Where necessary, working with members, volunteers and partners to ensure marketing initiatives abide by data protection principles.

Change Record

Date of Change: Changed By: Comments:
25/05/2021 Matty Updated from original to include textural and formatting changes only.
07/06/2021 N/A Policy approved by the Trustees

Our Partners

Arts And Business Cymru Logo
Chapter Logo
Hynt Logo
Ticketsource Logo
Wcva Logo
Welsh Government Logo