DATA PROTECTION AND PRIVACY POLICY

Last updated: 1st May 2024.

This document outlines how the Ameet Jogia campaign processes and manages personal data and:

1. Data Controller

The Data Controller is Hendon Conservative Association.

2. Contact

If you have any questions about this policy or for more information about how we use your data or would like to exercise any of your rights please get in touch with the campaign at: [email protected], or the Hendon Conservative Association.

3. Lawful basis for processing

All processing is carried out by consent or either under the legitimate interest of Ameet Jogia, or public interest. These cover processing to conduct casework, campaigning and communication. Where processed under the lawful basis of a task carried out in the public interest, it is to support or promote democratic engagement. This includes fundraising activity in order to support democratic engagement.

4. Data sources

Data held is that provided by you when you contact us and correspondence with third parties in response to cases taken up on your behalf. We may also hold data that you provide when we contact you – for instance, if we ask you to participate in a survey or petition. If you do not wish for us to contact you by telephone please do not provide this information.

5. Data Security

We take the security of personal data seriously. We use security technology, including firewalls, password protection and encryption to safeguard information and have procedures in place to ensure that our paper and computer systems and databases are protected against unauthorised disclosure, use, loss and damage. We have processes in place to deal with a data breach in the unlikely event one should occur.

We only use third party service providers where we are satisfied that they provide adequate security for your personal data.

6. Special category data

Special category data will be processed under the lawful basis indicated in section 3, as is permitted in clauses 22, 23 and 24 of schedule 1 of the Data Protection Act, covering political parties and elected representatives.

7. Transferring your data outside of the European Economic Area

The EU GDPR adequacy decision means that data can continue to flow between the UK and the European Economic Area (EEA). Some service providers are located outside of the EEA and therefore it may be necessary to transfer your personal data outside of the EEA. Where the transfer of your data outside of the EEA takes place we will make sure that it is protected in the same way as if the data was inside the EEA, and it only occurs with your consent. We will use one of the following safeguards to ensure this:
Where the European Commission has issued an adequacy decision determining that a non-EEA country or organisation ensures an adequate level of data protection.
A contract is put in place with the recipient of the data obliging them to protect the data to the same standards as the EEA. Legally it is not permitted to transfer certain types of data, such as Electoral Register Data, outside of the EEA, and we honour that obligation.

9. Subject Access Requests

We will request verification of the identity of any individual making a request, ask for further clarification and details if needed and respond within one calendar month once we have confirmed it is a legitimate request. In accordance with ICO guidelines, we keep a log of Subject Access Requests that contains details of the request, including that which can identify you personally, indefinitely. Data subjects have the right to the following: To be told whether any personal data is being processed To be given a description of the personal data, the reasons it is being processed and whether it will be given to another organisations or people. To be given a copy of the information comprising the data, and given details of the source of the data where this is available.

10. Will we share your data with anyone else?

We will never sell your data but sometimes it is necessary to share your information, either within the wider Conservative Party, or with our service providers, data controllers and data processors. Data is only ever shared where we have a party reason and when the law allows us to do so.

We share data with:

Where we use a third-party data processor, in other words an organisation that processes data on our behalf and under our instruction, we ensure that this processing is governed by a legally enforceable data processing agreement which sets out their responsibilities for protecting your data and your rights. Where we share data with a third party controller, an organisation that determines how data will be processed, we ensure that this is governed by a Controller to Controller data sharing agreement.

Where we share data with the wider Conservative Party we ensure that the recipient of the data agrees to a terms and conditions that they will use the data only for the purposes for which it was provided and will take necessary measures to ensure its security. Members of the wider Party receive training on data protection.

11. Data Rights

At any point you have the right to:

12. Making a complaint

If you are unhappy with the way that we have processed or handled your data then you have a right to complain to the Information Commissioner’s Office (ICO). The ICO is the supervisory body authorised by the Data Protection Act 2018 to regulate the handling of personal data within the United Kingdom. The contact details for the ICO are: • Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF

Telephone: 0303 123 1113

Website: https://ico.org.uk/concerns/

13. Changes to This Policy

We reserve the right to update or modify this Data Protection and Privacy Policy at any time. Any changes will be effective immediately upon posting on this page. We encourage you to review this page periodically for any updates.

14. Contact Us

If you have any questions or concerns about this Data Protection and Privacy Policy or our data practices, please contact us at [email protected].

By using our website, you agree to the terms outlined in this policy. Thank you for trusting Ameet Jogia with your personal information.