Sign Up for the newsletter...

Impact Trust Data Protection and Privacy Policy

1. Introduction

The Impact Trust (“the Trust”), a charity registered in England and Wales (Registration
Number 1167011), is committed to protecting the privacy and security of personal data. This
policy outlines how the Trust collects, uses, stores, and protects personal data, ensuring
compliance with the UK General Data Protection Regulation (GDPR), the Data Protection
Act 2018, and other relevant legislation.

2. Scope

This policy applies to:

3. Data Protection Principles

The Trust will ensure that personal data is:

4. Lawful Basis for Processing

The Trust will only process personal data where there is a lawful basis, including:

Where consent is required, it will be sought in a clear, accessible way, and individuals will be
informed of their right to withdraw consent at any time.

5. Categories of Personal Data

Personal data processed by the Trust may include:

6. Purposes of Data Processing

The Trust collects and processes personal data for purposes including:

7. Data Sharing

Personal data may be shared with:

Where data is shared regularly, a data sharing agreement will be in place. Data subjects will
be informed of any sharing in the Trust’s Privacy Notice.

8. Data Security

The Trust will:

9. Data Retention

The Trust will retain personal data only as long as necessary for the purposes for which it
was collected, in line with its Records Retention Schedule. Data will be securely deleted or
destroyed when no longer required.

10. Individual Rights

Data subjects have rights under the GDPR, including:

Requests to exercise these rights can be made to the Trust’s Data Protection Lead.

11. Data Breaches

Any suspected data breach must be reported immediately to the Data Protection Lead. The
Trust will investigate all breaches and notify the Information Commissioner’s Office (ICO)
and affected individuals where required.

12. Data Protection by Design

The Trust will integrate data protection into all processing activities and projects, including
conducting Data Protection Impact Assessments (DPIAs) where processing is likely to result
in high risk to individuals’ rights and freedoms.

13. Training and Awareness

All staff, trustees, and volunteers will receive regular training appropriate to their roles to
ensure understanding of their data protection responsibilities.

14. Monitoring and Review

The Trust will regularly audit compliance with this policy and review it annually or in
response to legislative changes or identified weaknesses.

15. Contact

For any queries or to exercise your rights under this policy, please contact info@impacttrust.org