Effective as of 17th November 2022 Who we are “Data controllers” are the people or organisations that determine the purposes for which, and the manner in which, any Personal Data is processed, and make independent decisions in relation to the Personal Data and/or who/which otherwise control that Personal Data. For the purposes of the GDPR, Saoirse Housing Association Clg. (‘SDVS’’) is the data controller with regard to the Personal Data described in this Data Protection Notice. The mission of Saoirse Domestic Violence Services is to reach and support an ever-increasing number of families in Irish Society, who deserve respect, dignity, safety, and freedom from domestic violence. Through our team of professional, caring and committed people our primary focus remains our commitment to continuous improvement in all aspects of our operations and the services we offer to our clients and the community. Data Protection queries can be directed to: XpertDPO Email Address: dpo@xpertdpo.com Address: 20 Harcourt St, Saint Kevin’s, Dublin, D02 H364, Ireland Telephone Number: +353 1 678 8997 Purpose and Scope of this Notice The purpose of this Data Protection Notice is to provide you, as our data subject, with a statement regarding the Data Protection and Privacy practices and obligations of SDVS and an explanation of your rights as a data subject. This Notice applies to our organisational practices and our website, which is accessible from https://sdvs.ie/. Please note a separate Data Protection Notice is given to clients with further information contained within it. As SDVS is established in the Republic of Ireland, this document is written in the vein of Irish Data Protection Law, and SDVS falls under the jurisdiction of the Irish Data Protection Commission. This Data Protection Notice sets out what Personal Data we collect and process about you in connection with the services and functions of the Organisation. We are not responsible for the content or the privacy notices for any websites to which we may provide external links. Laws that apply to us: • General Data Protection Regulation (EU Regulation 679/2016) • Irish Data Protection Acts 1988 to 2018 • Regulations flowing from DPA 2018 • ePrivacy Regulations 2011 implementing EU Privacy and Electronic Communications Directive 2002/58/EC on Privacy and Electronic Communications, otherwise known as ePrivacy Directive (ePD)
Why and how do we ensure compliance? Data protection and privacy laws provide rights to individuals with regard to the use of their Personal Data by organisations, including our organisation. Irish and EU laws on data protection govern all activities we engage in with regard to our collection, storage, handling, disclosure and other uses of Personal Data. We must comply with data protection and privacy laws because the law requires us to but we also would like you to have confidence in dealing with us, and compliance with data protection law helps us to maintain a positive reputation in relation to how we handle Personal Data. We are required to demonstrate accountability for our data protection obligations. This means that we must be able to show how we comply with the applicable data protection and privacy laws, and that we have in fact complied with the laws. We do this, among other ways, by our written policies and procedures, by building data protection and privacy compliance into our systems and business rules, by internally monitoring our data protection and privacy compliance and keeping it under review, and by acting if our representatives, including employees or contractors, fail to follow the rules. We also have certain obligations in relation to keeping records about our data processing. Who must comply? All Staff (Full time, part time and temporary) Third-Party contractors and clients are required to comply with our Data Protection Policies and Procedures which inform this Data Protection Notice when they process Personal Data on our behalf. What are the data protection principles and rules? We aim to comply with the following principles found in Data Protection Law:
What types of personal data will we process? Personal Data We will collect personal data with you in accordance with the purposes outlined in this Notice. This will be data used to facilitate a service relationship usually your name and contact details and other forms of data as listed below depending on your engagement with our service. Any personal information which you volunteer to SDVS through the use of our web form or via email will be treated with the highest standards of security and confidentiality, strictly in accordance with the Data Protection Acts, 1988 to 2018 and the General Data Protection Regulation (GDPR). The types of Data we collect Information which may be sought and recorded at the time of first engagement and may be collated and compiled during the course of our engagement with you. Please note a separate Data Protection Notice is given to clients. These records may include:
For organisations and donors, we may also collect:
How and why we use your data
Legal Bases for processing your data We use your personal data for the purposes outlined above. In doing so we rely on a number of separate and overlapping legal bases to lawfully process your personal data. These may include:
How long do we keep your data We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. By law we have to keep basic information (including Contact, Identity, Financial and Transaction Data) for 6 years in order to be compliant with relevant legislation. Third Parties and Disclosures of your Personal Data SDVS will only share your data where we have a lawful purpose to do so. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. SDVS has a duty to report any issues relating to child protection or adult safeguarding if we believe that either you or someone else is at risk of significant harm. We may also disclose data where there is another legal reason or requirement to disclose your personal information, such as a court order or serious case review. Any criminal conviction or offence data is shared in line with the Law Enforcement Directive (2016). We may also share your data for the purposes of fraud prevention. With your consent, we may also share your data with other parties, including but not limited to:
International Transfers Where there are external third parties we use who are based outside the EU / European Economic Area (EEA), SDVS ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA. Security features Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so. If you have concerns about a potential data confidentiality breach, please contact us on dpo@xpertdpo.com. SDVS stores data in a secure setting, and our data is only accessible to personnel who are authorised to use it. Employees are required to maintain the confidentiality of any data to which they have access.
By consenting, where this is the appropriate and identified lawful basis for processing, to our processing your Personal Data in line with our Data Protection Notice you are giving us permission to process your Personal Data. You may withdraw consent at any time by providing an unambiguous indication of your wishes by which you, by a statement or by a clear affirmative action, signify withdrawal of consent to the processing of Personal Data relating to you. If you have any queries relating to withdrawing your consent, please contact our Data Protection Officer using the contact details set out below. Withdrawal of consent shall be without effect to the lawfulness of processing based on consent before its withdrawal. Your Rights Under certain circumstances, and dependent on legal basis under which your personal data is processed, by law you have the right to:
We monitor compliance with our data protection obligations with this Notice and our related policies. If you have any questions about this Notice or about our data protection compliance, please contact our Data Protection Officer. If you wish to exercise your rights, please contact our Data Protection Officer who will respond to the request within one calendar month. Data Protection queries can be directed to: XpertDPO Email Address: dpo@xpertdpo.com Address: 20 Harcourt St, Saint Kevin’s, Dublin, D02 H364, Ireland Telephone Number: +353 1 678 8997 Your Right to Lodge a Complaint You as the Data Subject have the right to complain at any time to a supervisory authority in relation to any issues related to our processing of your Personal Data. We would like to hear from you first if you have a complaint about how we use your data so that we may rectify the issue. As our organisation is located in Ireland and we conduct our data processing here, we are regulated for data protection purposes by the Irish Data Protection Commissioner. You can contact the Data Protection Commissioner as follows: Website: www.dataprotection.ie Phone: +353 57 8684800 or +353 (0)761 104 800 Email: info@dataprotection.ie Address: Data Protection Office – Canal House, Station Road, Portarlington, Co. Laois, R32 AP23. Or 21 Fitzwilliam Square Dublin 2. D02 RD28 Ireland Updates Our practices as described in this Data Protection Notice may be changed, but any changes will be posted, and changes will only apply to activities and information on a going forward, not retroactive basis. You are encouraged to review this Notice periodically to make sure that you understand how any personal information you provide will be used. Any changes to this Data Protection Notice will be posted on this website so you are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it.