TECH50K — خمسون ألف تقاني وتقانية سورية

Syrian British Professionals Network

Privacy Policy

SBPN commits to protecting privacy and managing personal data per UK GDPR and the Data Protection Act 2018 requirements.

Effective Date: 24/02/2025

1. Introduction

The Syrian British Professionals Network (SBPN) commits to protecting privacy and managing personal data per UK GDPR and the Data Protection Act 2018 requirements.

2. Scope

This framework applies to all SBPN staff, offices, committees, volunteers, members, and external parties handling organizational data.

3. Data Protection Principles

SBPN follows these core standards:

  • Lawfulness and Transparency: Data processing occurs lawfully and openly.
  • Purpose Limitation: Information collected for specific, explicit purposes only.
  • Data Minimisation: Only essential information is gathered.
  • Accuracy: Records remain current and correct.
  • Storage Limitation: Data retained no longer than necessary.
  • Integrity and Confidentiality: Secure processing prevents unauthorized access.

4. Legal Basis for Processing Personal Data

Processing relies on:

  • Explicit consent from individuals
  • Fulfilling contractual obligations
  • Meeting legal requirements
  • Pursuing legitimate organizational interests (when individual rights aren't overridden)

5. Data Collection and Processing

SBPN collects information for:

  • Membership administration
  • Event coordination
  • Member communication
  • Regulatory compliance

Collection occurs via the official website using HTTPS/SSL encryption.

6. Data Security Measures

Protections include:

  • Limiting access to authorized personnel
  • Secure physical and digital storage
  • File encryption and password protection
  • Data and files are stored on Google Cloud and Google Drive using industry-standard AES-256 encryption
  • Restricting member data access to registered directors and guarantors
  • Ongoing staff security training

7. Data Sharing and Disclosure

Information sharing occurs only when:

  • Service providers have data processing agreements in place
  • Legal authorities require disclosure
  • Individual consent is provided for specific purposes

8. Individual Rights

UK GDPR grants these protections:

  • Access to held personal information
  • Correction of inaccurate or incomplete records
  • Deletion of data (subject to legal obligations)
  • Temporary processing restrictions
  • Data transfer to other organizations
  • Objection to interest-based processing
  • Consent withdrawal when applicable

9. Data Breach Reporting

Upon breach detection, SBPN will:

  • Evaluate severity and impact
  • Report serious breaches to the Information Commissioner's Office (ICO) within 72 hours
  • Notify impacted individuals when necessary
  • Execute preventive corrective measures

10. Data Retention Policy

Retention timelines:

  • Membership records: 5 years post-membership
  • Financial records: 6 years (UK tax compliance)
  • Event data: 2 years
  • Email communications: Up to 1 year (unless extended)

11. Responsibilities

  • Board of Trustees: Ensures legal compliance oversight.
  • Data Protection Officer: Manages security, incident response, and compliance.
  • Staff and Volunteers: Must follow policies and report breaches.

12. Contact and Complaints

Address inquiries to the Data Protection Officer at Syrian British Professionals Network (SBPN).

For unresolved concerns, file complaints with the Information Commissioner's Office at www.ico.org.uk.

13. Policy Review

Annual review occurs or as needed with UK data protection law changes.

Approval: Founding Committee of SBPN · Date: 07/03/2025