Data Protection and GDPR Compliance Pack
Last reviewed: 13 July 2026
This is the browser-readable governance pack for personal information handled through restorebritain.site and Restore Britain Croydon. It complements our Privacy Notice. It records the controls we require; it is not a claim of certification or legal approval.
Launch gates for expanded information
Expanded member profiles, emergency contacts, political polling and targeting must not launch until the accountable controller has confirmed:
- The controller or joint-controller arrangement in writing.
- An Article 6 lawful basis and, for political opinions or inferred beliefs, an Article 9 condition for every purpose.
- Approval of the data protection impact assessment.
- Article 28 terms for every processor and safeguards for any restricted transfer.
- Confidentiality, training and least-privilege access for every administrator.
- Successful exercises of rights handling, deletion, restoration and breach response.
Record of processing activities
| Activity | Information and purpose | Basis and recipients | Retention |
|---|---|---|---|
| Membership applications | Name, email, postcode, reason, consent and decision audit; used to assess applications. | Steps before contract; legitimate interests for fraud/security. Membership Managers and mail service. | Identity fields removed after decision; minimal audit 24 months. |
| Membership administration | Identity, contacts, status, fee and correspondence; used to provide membership. | Contract and legal obligation. Authorised membership/finance staff and payment provider when introduced. | Membership plus 24 months; statutory finance records six years. |
| Optional member profile | Age band, locality, skills, availability and communication choices; used to organise groups and volunteering. | Consent; legitimate interests only after a documented assessment. Purpose-specific organisers. | Annual review; deletion within 30 days of withdrawal or 12 months after membership. |
| Transport coordination | Driver/vehicle status, capacity, accessibility and radius; used to arrange voluntary transport. | Granular consent. Transport coordinators and matched participants only. | Refresh six-monthly; trip details 90 days. |
| Emergency contacts | Contact name, relationship and contact details; used only during a defined welfare emergency. | Vital interests where applicable or assessed legitimate interests. Welfare leads and emergency services where necessary. | Refresh six-monthly; delete on withdrawal or membership end. |
| Community | Account, posts, media, comments and moderation; used to operate the community safely. | Contract and legitimate interests. Visibility chosen by the member; authorised moderators. | Content until deletion/closure; moderation audit 24 months. |
| Polls | Answers, eligibility proof and minimal abuse signals; used to understand views and publish aggregates. | Explicit consent and an approved Article 9 condition for political opinions. Poll Managers; public sees thresholded aggregates only. | Normally 12 months; abuse signals 90 days. |
| Shop and donations | Contact, delivery, order, donation and payment-reference information; used for fulfilment, refunds and accounting. | Contract and legal obligation. Payment provider, finance staff and Inkthreadable or Two Fifteen for relevant orders. | Financial records six years; abandoned baskets 30 days. |
| Security, enquiries and complaints | Technical logs, correspondence and outcomes; used for security, support and dispute handling. | Legitimate interests and legal obligation/claims where applicable. Assigned staff and security administrators. | Routine logs 90 days; enquiries 12 months; complaints three years. |
Free-text fields require review because they may collect special-category or third-party information. Exact birth dates, live location, identity documents and medical details are prohibited unless separately shown to be necessary and approved through an updated assessment.
Data protection impact assessment
Profiles, locality, volunteering, transport, emergency contacts, community activity and political polls can combine into a detailed picture of a person. Misuse or compromise could cause discrimination, intimidation, fraud or physical harm.
- Use age bands and approximate locality unless exact values are essential.
- Keep expanded fields optional and state the purpose and visibility beside each field.
- Keep operational attributes private by default.
- Separate ballots from voter identity and suppress aggregate groups smaller than 10.
- Do not reuse information for incompatible purposes or make solely automated significant decisions.
- Use least privilege, privileged MFA, individual accounts, access reviews, audit records and prompt revocation.
- Require processor contracts, transfer evidence, encrypted backups and tested restoration.
Outcome: expanded processing is not approved until the launch gates above are signed. Any high residual risk that cannot be reduced requires consultation with the ICO before processing.
Retention and deletion schedule
- Application identity fields: remove after decision; minimal decision audit: 24 months.
- Active profiles: duration of membership with annual review; emergency/transport data: delete within 30 days of withdrawal or membership ending.
- Consent and suppression evidence: while relied on and, where needed to establish compliance, six years afterwards.
- Community content: until deletion or closure; moderation records: 24 months.
- Poll ballots: normally 12 months; abuse telemetry: 90 days.
- Orders, refunds, payments and donations: six years after the relevant financial year.
- Enquiries: 12 months; complaints: three years; routine security logs: 90 days.
- Encrypted rolling backups: no longer than 90 days; deletions must be reapplied after restoration.
Deletion covers live databases, media, exports, caches and processors. A quarterly report must identify overdue records and their deletion or justified legal hold.
Individual-rights procedure
- Accept requests at [email protected] without requiring legal terminology.
- Log the request, scope, proportionate identity check, systems searched, decisions, processor actions and completion.
- Search accounts, profiles, posts, applications, orders, mail, moderation, linkable polls, logs and relevant processors.
- Handle access, correction, erasure, restriction, objection, portability and consent withdrawal as the law requires. Direct-marketing objections are absolute.
- Respond without undue delay and normally within one month; explain any lawful extension, withholding and complaint route.
- Transfer information securely and notify relevant recipients of correction, restriction or erasure where required.
Personal-data breach procedure
Anyone discovering a suspected breach must immediately report it, preserve evidence and safely stop further exposure. The incident owner records the affected systems, information and people; containment; consequences; risk; processor involvement; decisions; notifications and remediation.
If a breach is likely to risk people’s rights and freedoms, the ICO must be notified without undue delay and, where feasible, within 72 hours of awareness. If high risk is likely, affected people must be told without undue delay. The reasoning is recorded even when notification is not required. The live incident register is restricted and is not published on this page.
Processor and international-transfer register
| Supplier | Purpose | Evidence required | Status |
|---|---|---|---|
| Cloudflare | Edge security and visitor connection data | DPA, subprocessors, retention and transfer safeguards | Evidence pending |
| Saturn administration | WordPress and operational data | Physical/access controls, encryption and restoration evidence | Controls to evidence |
| Mail service | Applications, accounts and service messages | Role/DPA, retention, access and routing locations | Evidence pending |
| WooCommerce | Local commerce application | Configuration, data map and extension register | In use |
| Inkthreadable / Two Fifteen | Order fulfilment | Terms/DPA, subprocessors, retention, security and transfer locations | Contract review pending |
| Payment provider | Transactions and payment tokens | DPA, PCI responsibilities, webhook security and transfers | Not selected |
| Telegram | Administrative publishing transport | Necessity, terms, transfer assessment and retention | Inactive pending approval; no personal member data |
No supplier is approved merely because it advertises GDPR compliance. Restricted transfers require the destination, contract, UK safeguard and risk assessment to be recorded.
Access, confidentiality and training
A restricted named register records each person’s role, system capabilities, approver, MFA, confidentiality acceptance, training, review and revocation. Shared administrator accounts are prohibited. Access is reviewed quarterly and after every role change.
Anyone with access must use information only for authorised purposes, prevent disclosure, report incidents immediately, avoid unnecessary copies, return or delete information on departure and remain bound by confidentiality afterwards.
Consent and legitimate interests
Consent must be freely given, specific, informed, unambiguous, separate from general terms and evidenced by its wording, version, time and action. Explicit consent for special-category information must be an express statement. Refusal or withdrawal must not remove an unrelated service; withdrawal must be as easy as giving consent.
Every reliance on legitimate interests must record the precise benefit, necessity, less intrusive alternatives, reasonable expectations, sensitivity, impact, safeguards, objection route, conclusion and approver.
Security and continuity evidence
- TLS and renewal monitoring; encryption of host volumes and backups; documented key custody.
- Privileged MFA, account recovery, least privilege and protected audit records.
- WordPress/plugin inventory, patching, vulnerability response and secure-code review.
- Firewall, segmentation, physical access, upload validation and penetration testing.
- Central logs, alerts and accurate time synchronisation.
- Encrypted independent backups and quarterly restoration tests.
- Controlled exports, no unmanaged removable media, annual training and incident exercises.
Evidence must identify its date, operator, result and remediation. A checkbox alone is not proof. Questions or rights requests should be sent to [email protected].