Wave Community Bank logo

Data Protection Policy

Click Here

WCB Data Protection Policy

Purpose & Objectives

· to ensure that WCB directors, managers, staff and volunteers are aware of obligatory requirements, comply with data protection law and follow good practice

· to provide a baseline from which to acquire, configure and audit our internal systems and processes

· to protect the rights of WCB, staff, volunteers, members and partners

· to protect WCB and its members against the risks of a data breach

Data protection law and General Data Protection Regulation (UKGDPR)

The General Data Protection Regulation (GDPR) expanded the rights of individuals and how much control they exert over their personal data to an extent never seen before. This new law came into effect on 25th May 2018.

Following the transition period after Brexit, in June 2021 the EU and the UK Government agreed to continue to allow the free flow of data into and out of the country. This is because the UK has very similar laws to the EU Directive on Data Protection.

Although this may change in the future, it is expected that the arrangement will continue until at least 2025.

Article 5 of the UKGDPR requires that personal data shall be:

“a) processed lawfully, fairly and in a transparent manner in relation to individuals;

b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;

c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;

d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;

e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the UKGDPR in order to safeguard the rights and freedoms of individuals; and

f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.”

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-UKGDPR/principles/

Responsibilities

· Although all WCB managers, staff members and volunteers are responsible for ensuring data is collected, stored and handled properly and members are aware of their rights and allowed to exercise their consent as per UKGDPR; the following people have key areas of responsibility:

2. The Board of Directors is responsible for ensuring that WCB meets its legal obligations.

3. The Board of Directors has delegated to the Chief Executive responsibility for:

· keeping the board up to date with data protection responsibilities, risk and issues

· reviewing all data protection policies and procedures in line with an agreed schedule

· arranging data protection advice and training

· handling data protection

· handling Member Access Requests

· checking and approving any agreements or contracts with 3rd parties that may handle WCB’s sensitive data.

· Ensuring members rights and consents are adhered to

4. The IT Manager/Provider, SCIP, is responsible for:

· ensuring all systems, equipment and services meet acceptable security standards

· performing regular checks and scans to make sure security software and hardware is functioning properly

· Evaluating any 3rd-party IT services WCB is considering using to process or store data.

5. The Data Processors (Progress System & VIVA IT) are responsible for:

· Ensuring WCB data is held securely

· Access to WCB data is limited to those who have authorisation to do so

· Comply with UKGDPR regulations

See the following Appendices

Appendix1 – The use of personal information

Appendix2 – Members’ Rights

Appendix1

The use of personal information

East Sussex Credit Union processes and transfers and/or shares personal information in the following ways:

For legal reasons

· confirm identity

· perform activity for the prevention of financial crime

· carry out internal and external auditing

· record basic information about the applicants on a register of members

For performance of our contract with a member

· deal with member account(s) or run any other services provided

· consider any applications made

· carry out credit checks and to obtain and provide credit references

· undertake statistical analysis, to help evaluate the future needs of our members and to help manage our business

· To send members statements, new terms & conditions (including changes to this privacy statement), information about changes to the way member account(s) operate and notification of our annual general meeting.

For our legitimate interests

To recover any debts owed to WCB

With consent

· maintain a relationship with members including marketing and market research (if agreed to by the member and regularly reviewed)

Sharing personal information

WCB will disclose information outside the credit union:

· to third parties to help confirm identity to comply with money laundering legislation

· to credit reference agencies and debt recovery agents who may check the information against other databases – private and public – to which they have access to

· to any authorities if compelled to do so by law (e.g. to HM Revenue & Customs to fulfil tax compliance obligations)

· to fraud prevention agencies to help prevent crime or where fraud is suspected;

· to any persons, including, insurers, who provide a service or benefits to members in connection with member account(s)

· To suppliers, in order for them to provide relevant services

· to anyone in connection with a reorganisation or merger of the credit union’s business

· other parties for marketing purposes (if agreed by the member)

· A bank account checking service with the member’s consent

Where WCB sends personal information

While countries in the European Economic Area all ensure rigorous data protection laws, there are parts of the world that may not be quite so rigorous and do not provide the same quality of legal protection and rights when it comes to your personal information.

The credit union does not directly send information to any country outside of the European Economic Area, however, any party receiving personal data may also process, transfer and share it for the purposes set out above and in limited circumstances this may involve sending personal information to countries where data protection laws do not provide the same level of data protection as the UK.

For example, when complying with international tax regulations we may be required to report personal information to the HM Revenue and Customs which may transfer than information to tax authorities in countries where you or a connected person may be tax resident.

Retaining personal information

The credit union will need to hold personal information for various lengths of time depending on what we use the data for. In many cases, we will hold this information for a period of time after the member has left the credit union.

The timescale for retention of documents is in the Document Retention Procedure

Credit rating agencies

In order to process credit applications personal information will be supplied to credit reference agencies (CRAs)s to assess creditworthiness and product suitability, check identity, manage member accounts, trace and recover debts and prevent criminal activity, and on an ongoing basis. including information about settled accounts and any debts not fully repaid on time.

Appendix 2

Members’ Rights

In compliance with UKGDPR, WCB will allow the following rights to members under data protection regulations:

The right to access –

Members and loan applicants have the right to access their personal data and details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, WCB will supply to the individual a copy of their personal data.

The right of rectification – Members and loan applicants have the right to have any inaccurate personal data about them corrected and, taking into account the purposes of the processing, to have any incomplete personal data completed.

The right to erasure-

In some circumstances, members have the right to the erasure of their personal data without undue delay. Those circumstances include:

· the personal data is no longer needed for the purpose it was originally processed

· the member withdraws consents they previously provided to process the information

· the member objects to the processing under certain rules of data protection law

· the processing is for marketing purposes

· the personal data was unlawfully processed

WCB will not erase this data where it is needed to meet a legal obligation or where it is necessary for the establishment, exercise or defence of legal claims.

The right to restrict processing-

In some circumstances, members have the right to restrict the processing of their personal data. Those circumstances are:

· the accuracy of the personal data is contested;

· processing is unlawful but the member opposes erasure;

· WCB no longer need the personal data for the purposes of it’s processing, but the member requires personal data for the establishment, exercise or defence of legal claims; and

· The member has objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, WCB may continue to store the member’s personal data.

WCB will only otherwise process it:

· with the member’s consent;

· for the establishment, exercise or defence of legal claims; or

· for the protection of the rights of another natural or legal person;

The right to data portability

To the extent that the legal basis for our processing of the member’s personal data is:

consent; or that the processing is necessary for the performance of our contract with them,

Members have the right to receive their personal data from WCB in a commonly used and machine-readable format or instruct WCB to send this data to another organisation. This right does not apply where it would adversely affect the rights and freedoms of others.

The right to object to processing

Members have the right to object to WCB processing of their personal data on grounds relating to their particular situation, but only to the extent that the legal basis for the processing is that the data is necessary for the purposes of the legitimate interests pursued by WCB or by a third party.

If a member makes such an objection, WCB will cease to process the personal information unless WCB can demonstrate compelling legitimate grounds for the processing which override the member’s interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.

Members have the right to object to WCB’s processing of their personal data for direct marketing purposes (including profiling for direct marketing purposes). If the member makes such an objection, WCB will cease to process the member’s personal data for this purpose.

Rights related to automatic processing

WCB may use an automated decision- making process for processing members’ loan applications. Members have the right to have the decision reviewed by a member of staff, express their point of view, and obtain an explanation of the decision and challenge it.

Right to withdraw consent

To the extent that the legal basis for WCB processing of the member’s personal information is their consent, the member has the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.

The right to complain to the Information Commissioner’s Office

The member has the right to complain to the Information Commissioner’s Office.

 

Wave Community Bank
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.