Parish Privacy Statement
Who are we?
Sandyford Parish is part of the Catholic Archdiocese of Dublin. The parish is a registered charity (charity no. CHY7424) and our address is Sandyford Parish St. Mary’s Sandyford, Sandyford Village Dublin 16. The Parish Priest is the data controller for the parish, in other words he is the person responsible for making sure your data is safe and secure.
Your personal data – what is it?
Personal data relates to a living individual who can be identified from that data. Identification can be through the information alone or in conjunction with other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation or the GDPR and the Data Protection Act (2018).
Who does this Privacy Notice apply to?
This Privacy notice is for all those whose personal information is dealt with in any way by the parish including parishioners, clergy, staff, volunteers, contractors, suppliers and visitors and there may be others.
What is the lawful basis for processing your personal data?
The GDPR requires specification in the Privacy Notice of the lawful basis for processing personal data. Below are the lawful bases which are relevant to our processing activities;
- Where consent has been obtained. This can be withdrawn at any time.
- Compliance with a legal obligation
- Performance of a contract, or to take steps to enter into a contract
- To protect a person’s vital interests
- Legitimate interests – this includes any activities that involve advancing and maintaining the Roman Catholic religion.
- Where processing is carried out by a not-for-profit body with a religious aim provided: –
- the processing relates only to members of the congregation or former members (or those who have regular contact with it in connection with those purposes); and
- there is no disclosure to a third party without consent.
What personal data do we process?
The parish will process some or all of the following types of data, where necessary to perform our duties;
- Contact details – telephone numbers, addresses, email addresses;
- Information about the Sacraments of Baptism, Confirmation, Marriage and Holy Orders;
- Information relating to donations as required for audit purposes and the Charities Act (2009 & 2016);
- Safeguarding information on staff, clergy and volunteers as required by the National Safeguarding Office;
- Information relating to gender, age, date of birth, marital status;
- Information gathered for the furtherance of faith development supports and services;
- Information relating to education/work histories, academic professional qualifications;
- Some of the personal data we process will fall under the category of sensitive personal data as it will identify your religious belief. There may be other categories of sensitive personal data processed including information on health (e.g. pilgrimage requirements), details of injuries (e.g. legal claim), trade union membership (for a staff member).
How does the Parish process personal information?
We use your personal data for purposes included among the following;
- to enable us to meet all legal and statutory obligations;
- to deliver the Church’s mission to our parish community and to carry out other voluntary/charitable activities for the benefit of our parish community;
- to minister to our parishioners and provide you with pastoral and spiritual care (such as visiting the sick or the bereaved);
- to organise and facilitate ecclesiastical liturgies for our parishioners including baptism, confirmations, weddings and funerals;
- to promote and assist the mission and growth of the Church in the Diocese of Dublin;
- to carry out comprehensive Safeguarding procedures in accordance with best; safeguarding practice with the aim of ensuring that all children and vulnerable adults are provided with safe environments;
- for those involved in the management of the parish we use the personal information you provided to enable both the parish and you to carry out your role effectively (e.g. members of the pastoral council, finance committee etc.);
- for lay people who assist in all aspects of parish life including the creation of rosters, being involved in parish sacramental teams etc., we use your information to assist you in your various roles. Without such information it would not be possible for you to function effectively in your role in our parish;
- To fundraise and promote the interests of the parish and process donations e.g. information supplied by donors to use in supporting our work
- To maintain our own accounts and records e.g. putting agreements in place, invoicing and making payments. Personal data held in this regard forms part of our contractual arrangements with you;
- To send you the parish newsletter; [if you send your newsletter via email you will need consent from the parishioner to do this]
- To deal with your request;
- To manage our staff, volunteers and contractors;
- Our processing may also include the taking of photographs, live streaming via the webcam, or capturing images in our CCTV;
- On occasion the parish has to share your personal data with the Diocesan offices. To enable this to happen compliantly a Data Processing Agreement has been put in place which is signed by the Parish Priest/Administrator/Moderator and counter-signed by the Archbishop. Examples of this sharing include contact with Chancellery in relation to sacramental issues; HR in relation to employment issues; Finance in relation to tax on donations and other areas affected by the Charities Regulation; Child Safeguarding for Vetting and Safe-guarding issues; Office for Liturgy regarding workshops/seminars that maybe of interest to Ministers of the Word/Eucharist/Choirs; Education Secretariat regarding Boards of Management and training events; Lourdes Pilgrimage in relation to parishioners travelling with them for the September pilgrimage; Evangelisation regarding those taking place in events such as Faithfest, World Youth Day and other seminars and workshops; and Archives in relation to GDPR request. The information will never be used for any purpose other than what it was gathered for.
Sharing your personal data
Your personal data will be treated as strictly confidential and will only be shared where appropriate;
- Information may be shared with statutory or church bodies for tax relief purposes or for law enforcement agencies for the prevention and detection of crime;
- Information may be shared with third parties who assist us with our work;
- We reserve the right to release personal data without your consent where permitted by law or to meet a legal obligation.
How long do we keep your personal data?
We keep your personal data for as long as it is need and in line with our Retention/Disposition schedule. Some records are permanently kept and these will be placed in the Parish/Diocesan Archives.
How is our information kept safe and secure?
The Parish complies with its obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
Your rights and your personal data
Unless subject to an exemption under the GDPR you have the following rights with respect to your personal data: –
- Right of Access – you can request a copy of your personal data from the Parish;
- Right of Correction – you have the right to request that the Parish corrects any personal data if it is found to be inaccurate, incomplete or out of date;
- Right of Erasure – You have the right, in certain circumstances, to ask for the data we hold on you to be destroyed. This is known as the Right to be Forgotten;
- Right to Restriction of Processing – where certain conditions apply, you have the right to restrict the processing of your personal data;
- Right to Data Portability – you can request that the Parish transfer your data directly to another data controller where we hold the data in an electronic format;
- Right to Object –you have the right to object to certain types of processing;
- Right to Lodge a Complaint with the Office of the Data Protection Commission.
When exercising any of the above rights and in order to facilitate your request, we may need to verify your identification for security purposes.
Transfer of Data Abroad
Some of our servers are UK located.
This Parish reserves the right to review and amend this statement at any time without notice.
Please contact the Parish if you have any questions about this Privacy Statement or the information we hold about you or to exercise all relevant rights, queries or complaints.
Phone: 01 295 6414
You can contact the Data Protection Commissioners Office on 00353 57 8684800 or Lo-Call 1890 252 231 or by email at email@example.com.
The postal addresses are:
Data Protection Commissioner
R32 AP23 Co. Laois
21 Fitzwilliam Square
What personal data we collect and why we collect it
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
If you leave a comment on our site you may opt in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
Who we share your data with
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Visitor comments may be checked through an automated spam detection service.