SECTION 7: POLICIES

Conflict of Interest Policy

1.1 Conflicts of interest affect all types and size of organisations. In the charity context, a conflict of interest can inhibit free discussion, and can lead to decisions which are not in the best interests of the charity and which are invalid or open to challenge. Conflicts of interest can also be damaging to a charity’s reputation and to the public’s confidence and trust in charities in general.

1.2 Charity trustees have a primary duty in terms of S.66 of the Charities and Trustee Investment (Scotland) Act 2005 to act in the best interests of the charity at all times.

1.3 All those who are members of the Presbytery of [ the Presbytery.] (“the Presbytery”) are the charity trustees of The Presbytery recognises that its trustees can find themselves in a situation that may give rise to conflicts of interest, whether potential or actual, perceived or alleged. Where trustees can identify a conflict and measures can be put in place to prevent the conflict affecting decision-making then the harmful effects of a conflict of interest can be prevented. The proper handling of conflicts of interest is an essential part of good decision-making by trustees.

1.4 The Presbytery has developed this policy to provide guidance to all trustees regarding conflicts of interest in order to avoid any actual or potential conflicts of interest, perception of bias or misuse of authority, and to ensure and evidence that all decisions by individual trustees on behalf of the Presbytery are taken only in the best interests of the Presbytery at all times.

2. Scope and Purpose

2.1 This policy applies to all trustees of the Presbytery and to all bodies, groups and committees meeting under the auspices of the Presbytery. All individuals in the Presbytery who are involved in management of its affairs to a greater or lesser extent but are not members of the Presbytery can be seen as “shadow trustees” and are subject to the same duties as the trustees. Where the word “trustee” is used in this policy it covers both charity trustees and shadow trustees.

2.2 The Presbytery is committed to ensuring that all trustees act in its best interests at all times. This policy aims to provide guidance to those involved in management and decision-making and seeks to ensure that all trustees are seen to be acting in accordance with well recognised rules of good governance.

2.3 It is inevitable that conflicts of interest will arise. This policy aims to ensure that any conflict is identified and managed appropriately.

2.4 It is the responsibility of each individual to recognise situations in which he or she has a conflict of interest, or might reasonably be seen by others to have a conflict, to disclose that conflict to the appropriate person and to take such further steps as may be appropriate as set out in more detail under the procedure below.

2.5 If an individual is uncertain about how this policy might affect his or her activities or has any questions about its application, he or she should contact the Presbytery Clerk or the Law Department for further advice.

3. Conflict of Interest

3.1 What is a conflict of interest?

3.1.1 A conflict of interest is any situation in which a trustee’s personal interests or loyalties could, or could be seen to, prevent the trustee from making a decision only in the best interests of the Presbytery.

3.1.2 A conflict of interest arises when the interests of a trustee (or a person closely connected to them, whether by family or business) are incompatible or in competition with the interests of the Presbytery. Such situations present a risk that trustees will make a decision based on external influences and that such a decision will not be in the best interests of the Presbytery.

The most common types of conflict include:

• direct financial interest – where there is, or appears to be, an opportunity for personal financial gain.

• indirect financial interest – the financial gain of a close relative or close friend or business associate. The level of financial interest should not be a determining factor in deciding whether a conflict should be disclosed. The Presbytery expects disclosure of any financial interest, however small.

• non-financial or personal conflicts – a non-financial interest can take many forms and is generally one where there is, or appears to be, an opportunity for personal benefit, advantage or enhancement to prospects for the individual (direct), or similar gains to someone in their immediate family or a person with whom the individual has a close personal relationship (indirect).

• Conflicts of loyalties – a particular type of conflict of interest in which a trustee’s loyalty or duty to another person or organisation could prevent the trustee from making a decision only in the best interests of the Presbytery.

3.1.3 A conflict of loyalty may arise where a trustee is also a charity trustee or member of another body (such as, for example, another Church court or a local community group) if that could (or could be seen to) interfere with their ability to make decisions only in the best interests of the Presbytery. In such circumstances, a trustee must act at all times only in the best interests of the Presbytery in carrying out their trustee role, regardless of how decisions made in that role may impact on the other body.

3.1.4 A conflict of interest may arise where a trustee is also an employee of the Presbytery or of another body. Employment by the Presbytery does not confer membership of the Presbytery upon any individual. Presbytery will normally appoint employees to be corresponding members of Presbytery. Except where expressly agreed by the Presbytery, no employee of the Presbytery may be a member of any Committee of the Presbytery.

3.1.4 The interests of the Presbytery and such other body will for the most part be consistent, or complementary, but it is inevitable that on occasion a conflict will arise.

Whether a conflict of loyalty is of such low risk that the affected trustee can participate in the decision is a judgement for the trustees and will depend on the particular decision and circumstances of the case. It will often be the case that the potential damage that could be caused by any conflict is so minimal that it can be managed without any difficulty. The trustees must take all relevant factors into account and be ready to explain their approach if asked to do so.

Recognising and disclosing conflicts of interest

3.2. 1 All trustees are required to recognise and disclose activities that might give rise to conflicts of interest, or the perception of conflicts of interest, at the earliest opportunity.

This allows the other trustees to consider the issue of the conflict of interest to ensure that any potential effect on decision-making is eliminated and to demonstrate that their decision was made only in the best interests of the Presbytery. If properly managed, activities can proceed as normal whilst at the same time upholding the trustees’ obligations to the Presbytery, meeting regulatory and other external requirements and protecting the integrity and reputation of the Presbytery and the wider Church. By contrast, conflicts which are not managed effectively may jeopardise the Presbytery’s public standing and may cause serious damage to the reputation of the Presbytery, of the individuals concerned and the wider Church. It is therefore the Presbytery’s policy to ensure that when conflicts or perceived conflicts of interest arise they are acknowledged and disclosed.

3.2.2 There can be situations in which the appearance of conflict of interest is present even when no conflict actually exists. It is important for all trustees when evaluating a potential conflict of interest to consider how it might be perceived by others. The duty to declare a possible conflict applies to the perception of the situation as much as to the actual existence of a conflict. When deciding whether such an interest is present, trustees should ask themselves whether a reasonable member of the public, with knowledge of all of the relevant facts of the situation, would think that their judgement might be prejudiced or influenced by their private or personal interest. This is an objective test. Trustees must not decide whether they would take a decision without prejudice, but whether they could be seen as doing so.

3.2.3 There may, exceptionally, be circumstances in which a conflict cannot be satisfactorily managed. In such circumstances the trustees should remove the conflict by not proceeding with a proposed course of action; by proceeding in a different way so that the conflict does not arise; or by not appointing a particular trustee or requiring the resignation of a trustee.

4. Procedure

4.1 It is the duty of every trustee to disclose any conflict of interest or any circumstances that might reasonably give rise to the perception of conflict of interest. The following procedure should be followed to ensure that conflicts of interest are identified at as early a stage as possible and that, once identified, action is taken to ensure that the conflict of interest does not give rise to a situation where decisions are taken by trustees which are, or could be perceived as being, not in the best interests of the Presbytery.

4.2 Register of interests

4.2.1 New trustees will be informed before they are appointed that they will be expected to adhere to this conflict of interest policy and a copy of the policy will be provided to them. Any potential conflict of interest should be discussed with the Presbytery Clerk prior to taking up the position.

4.2.2 On appointment, trustees will be required to complete a Declaration of Interests form (Appendix 1). A Register of Interests will be maintained by the Presbytery Clerk and updated when a material change occurs. Membership of a congregation within the bounds

of the Presbytery will not require disclosure in the Register of Interests. The Register of Interests must be reviewed and updated on an annual basis.

4.2.3 A copy of the policy will be provided to all current trustees, who will also be required to complete a Declaration of Interests form.

4.3 Disclosure

4.3.1 Any failure to disclose a potential, actual or perceived conflict of interest is a serious issue. A trustee who fails to disclose a potential, actual or perceived conflict will have failed to comply with their statutory duty.

4.3.2 There should be a standard agenda item at the beginning of each Presbytery meeting to declare any potential, actual or perceived conflicts of interest.

4.3.3 A trustee should declare any interest which he or she has in an item to be discussed, at the earliest possible opportunity and before any discussion of the item itself. If a trustee is uncertain whether he or she is conflicted he or she should err on the side of openness, declaring the issue and discussing it with the other trustees.

4.3.4 If a trustee is aware of an undeclared conflict of interest affecting another trustee they should notify the other trustees or the Moderator. All trustees have a collective responsibility to manage conflicts and to act clearly in the Presbytery’s best interests.

4.4 Managing conflicts of interest

4.4.1 If a potential, actual or perceived conflict of interest is identified the trustees must act only in the best interests of the Presbytery. This means the trustees must consider the issue of the conflict of interest so that any effect this may have on good decision-making is eliminated.

4.4.2 In deciding whether a conflict of interest exists trustees must consider the following:

• Has the decision been taken in the best interests of the Presbytery?

• Does the decision protect the reputation of the Presbytery?

• What impression does the decision have on those outside the Presbytery, including the wider Church?

• Can the trustees demonstrate that they have made the decision in the best interests of the Presbytery and independently of any competing interests?

• Does the presence of a conflicted trustee inhibit free discussion and influence the decision-making process in any way?

Recording

4.4.3 Where the trustees decide that there is a potential, actual or perceived conflict of interest the conflicted trustee should not participate in the decision-making process.

4.4.4 The conflicted trustee should withdraw from the meeting prior to discussion of the item.

4.4.5 The conflicted trustee should be given the opportunity before withdrawing from the meeting to provide any information necessary to help the remaining trustees make a decision in the best interests of the Presbytery. This process should be followed, for example, in a situation where Presbytery is considering a matter relating to a specific congregation or charge but without wider implications across the Presbytery; Presbyters who are members of the affected congregation/charge should withdraw from the meeting before discussion of and voting on the item. For the avoidance of doubt, this does not apply to discussion of and voting on the Presbytery Mission Plan unless what is being considered is a minor adjustment of the Plan affecting a small number of congregations/charges.

4.4.6 A conflicted trustee should not take part in any vote on the item which is the subject of the conflict.

Recording

4.5.1 In all instances where a potential, actual or perceived conflict of interest is disclosed at a trustees’ meeting the minutes of the meeting should record the trustees’ discussion and the decision taken.

4.5.2 If there is a discussion, the written record of the decision should include:

• the nature of the conflict

• which trustees were affected

• whether any conflicts of interest were declared in advance

• an outline of the discussion

• whether anyone withdrew from the discussion

• how the decision was taken in the best interests of the Presbytery

5. Consequences of breach

5.1 Where conflicts of interest are not identified or properly managed there can be serious consequences for both the affected trustee and the Presbytery. Decisions taken may not be valid and could be challenged, and can damage the reputation of the Presbytery, the wider Church and the trust of the public.

5.2 If the circumstances are sufficiently serious, a failure to disclose a conflict of interest could therefore result in a disciplinary process being engaged.

6. Review

6.1 This Policy will be reviewed by the Presbytery after one year and thereafter every three

years.

APPENDIX 1

REGISTER OF CHARITY TRUSTEES’ INTERESTS

1. CONFLICTS POLICY

The charity trustees of [INSERT NAME OF PRESBYTERY] have implemented a conflicts of interest policy under which they have agreed that a register will be kept of all interests declared by the charity trustees.

2. MAINTENANCE OF REGISTER

This register is maintained by the Presbytery Clerk, who must:

(a) record all conflicts, gifts and hospitality declared by the trustees in accordance with the policy; and

(b) circulate amendments or additions to the register (if any) to the trustees at the start of each charity trustee meeting.

3. REVIEWING THE REGISTER

As agreed in the policy, at least once in every 12-month period, all charity trustees must review the information relating to themselves contained in this register and declare that the information is correct or make a further declaration if necessary.

4. INSPECTION OF REGISTER

This register is available for inspection by any charity trustee and by any member of the Presbytery on request.

Register of Interests

Date notified Name of charity Brief details of interest notified Brief details of any action taken

 

Social Media Policy

2.1 Introduction congregations to:

The Presbytery of Perth welcomes the use of social media as it provides easier ways for

communicate instantly with members, keeping them informed and updated;

signpost involvement with the local community; and

forge relationships with individuals and the wider community that build trust and understanding.

Facebook, Twitter, Instagram and any online communication have the ability to achieve these outcomes but it is necessary to outline a few issues Presbyters should bear in mind when communicating online.

Websites and Social media pages should be up to date and current.

The Church of Scotland has produced detailed guidelines for Social Media use focussing on Facebook, Twitter and Instagram.

Choosing the right social media platform is important and involves consideration of who you are trying to reach and what you are trying to achieve.

Once you have chosen your platform you can start to create your congregational account.

Always ensure that there are two or more people who hold the login details and passwords for your social media accounts. If not, you will have to start from scratch when someone leaves.

2.2 Images

Ensure you use high quality, eye catching, non-watermarked images which fit the optimum size for each social media platform.

2.3 Facebook

Facebook is the most popular social networking site worldwide. Facebook offers three options; a profile, a page, or a group.

A profile represents a single individual and is for non-commercial use.

A page is a timeline for organisations and businesses.

Groups are effective in connecting family, peers, colleagues or people with a shared interest.

A Facebook page is recommended. A page will enable people to find you and explore the life of your congregation. This page can be used to advertise events and to share prayers, images, videos, thoughts and quotes.

You must already have a personal Facebook account that you can use to create a page.

You will then become the admin of the page. You should then assign other people as admins and editors. You can remove yourself as an admin for the page later if you no longer wish your Profile to be attached to the church page.

2.4 X (formerly Twitter)

X is often the first place news stories appear online. People also use X to hold global conversations, make friends and build support for campaigns. Yet X is one of the most difficult social platforms for congregations to maintain. Tweets fly so fast and furiously, that on average they have a lifespan of around 10 minutes. So how do congregations use X effectively? If you want to keep up an X profile, you will need to sustain a steady flow of tweets. This may seem overwhelming, but your congregation is potentially already producing enough content to be used.

When choosing your X username (also known as your handle), you are limited to 15 characters. It should be something relevant, unique and easy to remember. Usernames are preceded by the @ symbol (@ChurchScotland). If you are planning on setting up an

Instagram account as well, you will want to check that the username is available on both platforms. Your display name (note: different from username) can be up to 50 characters and therefore you should be able to include your congregation’s full name.

2.5 Instagram

Instagram, users can connect with a global community which shares millions of photos and videos every day. This social platform works best on your mobile phone, and it is a wonderful place to explore the world and find like-minded individuals. Instagram has become an indispensable social media outlet, particularly for engaging with young people.

2.6 Safeguarding

Adults should think twice and consider speaking to a parent before adding/following children under 16 on social media. Always obtain consent from parents before using images of children on social media. Congregations address this in different ways. Some have a blanket consent form which parents sign before their children take part in activities. Other congregations choose not to include photographs of children on their social media accounts at all. Consult the Church of Scotland safeguarding resources for further guidance.

2.7 Personal View Sharing

Church of Scotland personnel are to be mindful of their status as a Minister, Deacon, Parish Worker or Elder of the Church of Scotland and for such reasons should consider carefully before engaging with local news agencies and on social media platforms ensuring that they consider that what they are sharing is appropriate.

2.8 Confidentiality

Be sensitive about confidentiality and the risk of intrusion. Social media does not change our fundamental understanding about confidentiality across the whole life of the Church.

When telling a story about a situation which involves someone else, always ask yourself: is this my story to tell? Would it cause distress, inconvenience, upset or embarrassment to others if they found out you had shared in this way? If in any doubt, do not share it online.

2.9 Privacy and Security

Be mindful of your own security. Be careful about the personal details you share online.

Assume anything you share about yourself is in the public domain. Do not assume anything electronic is secure. You might be able to delete or recall an email but there’s no guarantee the recipient will. Equally, your privacy settings on your social media tools might mean only your accepted “friends” or “followers” can see the things you say, but there is no guarantee that they will not pass them on outside your trusted circles.

Whistleblowing Policy

3.1 Purpose and Scope

The Presbytery is committed to the principles of openness, probity and accountability. In line with that commitment we expect anyone who has a serious concern about any aspect of our presbyterial life to voice those concerns in good faith and in line with the following procedure without fear of victimisation, subsequent discrimination or disadvantage.

The purpose of this policy is to provide a procedure which enables concerns to be raised if there are reasonable grounds for believing there is serious malpractice occurring or likely to occur. It applies to all employees, contractors, consultants, temporary casual and agency workers within the direct employ of Presbytery and the word “employee” is used in this policy to cover all such individuals. It also applies to members and corresponding members of the Presbytery. Matters of concern should be raised responsibly through the procedures and guidance as detailed in this policy.

3.2 Definition

Whistleblowing is when someone knows, or suspects, that there is some wrongdoing involving illegal and/or underhand practices occurring within the congregation and alerts the right person within the congregation, or the relevant authority, accordingly.

Employees who engage in whistleblowing are, in certain circumstances, protected by the

Public Interest Disclosure Act 1998.

3.3 Purpose and Scope

This policy is designed to deal with concerns raised in relation to the specific issues which are in the public interest and are detailed below), and which fall outside the scope of other procedures (such as a grievance procedure).

The policy does not apply to personal grievances concerning an employee’s terms and conditions of employment or other aspects of the working relationship, complaints of bullying or harassment, or disciplinary matters. Such complaints will be dealt with under existing procedures on grievance, bullying and harassment and discipline and misconduct.

The policy deals with specific concerns which are in the public interest in circumstances where an employee or a member/adherent has the reasonable belief:

that a criminal offence has been committed, is being committed, or is likely to be committed (including financial malpractice or acts of bribery);

that a person has failed, is failing, or is likely to fail to comply with a legal obligation to which they are subject;

that the health and safety of any individual has been, is being, or is likely to be endangered;

that the congregation is attempting to suppress or conceal any information relating

to any of the above.

If, in the course of investigation, any concern raised in relation to the above matters appears to relate more appropriately to grievance, bullying or harassment, or discipline, those procedures will be invoked. If the matter is of a less serious nature the employee should always talk to his or her line manager in the first instance.

3.4 Roles and Responsibilities

Concerns must be raised without malice and in good faith, and the individual must reasonably believe that the information disclosed, and any allegations contained in it, are substantially true. The disclosure must not be made for purposes of personal gain, and in all the circumstances it must be reasonable to make the disclosure.

If an employee knows, or suspects, that some wrongdoing is occurring, he or she should raise the matter immediately with their line manager. If the wrongdoing or suspected wrongdoing involves the employee’s line manager, or if the concern is raised by a member, the concern should be referred to the Presbytery Clerk of the Presbytery (or to the Convener of the Business Committee if the disclosure relates to the Presbytery Clerk in any respect). Anyone who is informed of potential wrongdoing must take immediate action to ensure the situation is investigated and dealt with as quickly as possible.

Efforts must be made to maintain the anonymity of the individual who has made the allegation of wrongdoing.

3.5 Procedures and Process

Concerns may be raised verbally or in writing and whilst individuals are not expected to prove beyond doubt the truth of an allegation they will be required to demonstrate that there are reasonable grounds for their concern.

It is suggested that individuals making a disclosure should set out (One) the background and history of the concern (including relevant dates); and (Two) the reason they are particularly concerned about the situation.

Wherever possible, within ten working days the person to whom the disclosure is made should write to the employee or to the member/adherent with the following information:

an acknowledgment that the concern has been raised;

an indication of the anticipated method of investigation and resolution if applicable;

an estimation of how long it will take for the individual to be provided with a final response noting that all investigations shall be completed as quickly as may be practicable in the circumstances;

advice as to what, if any, initial enquires have been made and what anticipated further investigations will take place.

If an investigation is deemed to be required, the Presbytery Clerk (or Convener of the Business Committee if appropriate) shall nominate an individual or individuals to consider the concern and take any steps they deem necessary to investigate the matter. This individual or individuals will conduct a full and thorough investigation. The form the investigation takes will be determined by the nature of the concern. The findings of the investigation will be shared with the Complaints Committee which will then decide if there is a case to answer and what procedure to follow. This may include taking steps with a competent authority, such as the police, for further investigation. The decision may also be that the matter would be more appropriately handled under existing procedures for grievance, bullying and harassment, or discipline. If it is determined that it would not be appropriate to proceed with an investigation or, following an investigation it is determined not to do so, the decision will be explained as fully as possible to the individual who raised the concern, giving the reasons not to take it further. If not satisfied with the decision, it is then open to the individual to make the disclosure to the Principal Clerk who may take action if appropriate. This may include appointing an investigator, taking action under Church legislation and/or referring the matter on to another authority, such as the police or local authority.

It is recommended that the Church’s Law Department is also contacted so that guidance can be provided if required. If urgent action is required, this may be taken prior to an investigation being undertaken. The employee or member may be invited to one or more meetings during the investigation depending on the nature of the matter raised, the potential difficulties involved and the clarity of the information provided. The employee may be accompanied by a work colleague or certified trade union representative during any such meetings; a member may be accompanied by a companion of their choosing.

Any other employees that are invited to provide statements should abide by the same principles as the employee or the member raising the concern.

If the concern involves an employee or employees the employee(s) will be told at an early stage of the investigation and of the evidence supporting it, and will be provided with an opportunity to respond during the investigation.

Employees and members raising concerns under this policy need to be assured that the matter has been properly addressed and so they will be kept informed of procedural progress and the outcome of the investigation. It may not always be appropriate to disclose full detail of any action that is taken, but the employee will be informed if action is taken.

3.6 Alerting Outside Bodies to a Potential Wrongdoing

Employees and members should always, in the first instance, follow this internal procedure about a potential wrongdoing. If they are not satisfied with the response, they are entitled to contact a relevant external body to express the concerns. In doing this they should:

have a reasonable belief that the allegation is based on correct facts;

not be making any personal gain from the revelations; and

make the disclosure to a relevant body.

Disclosures to OSCR should be made via the Church’s Law Department. If an employee or a member/adherent is dissatisfied with the Presbytery’s response under this policy and considers that any matter should be reported to OSCR he or she should contact the Law Department at lawdept@churchofscotland.org.uk in order to take this forward.

3.7 Contacting the Media

The media is not a relevant external body. Employees and members should never contact the media with allegations. Employees should be mindful that they must maintain the confidentiality of the employer so far as possible.

3.8 Protection against Detriment

Any employee who makes a protected disclosure in terms of the Public Interest Disclosure Act 1998 will be protected from any detriment in relation to any allegations that are made. If the employee does not follow the procedure set out above, which encompasses the requirements of the Public Interest Disclosure Act 1998, the protection against detriment may not apply.

Disclosing information in an inappropriate way (e.g. contacting the media or contacting a regulatory body without first raising the matter with the employer as set out in this policy) will constitute gross misconduct and could result in disciplinary action up to and including dismissal being taken against the employee.

3.9 Review

This policy will be kept under review by the Presbytery. Any questions regarding its operation should be directed to the Presbytery Clerk in the first instance.

Privacy Notice

Purpose of this Notice

This Privacy Notice outlines the way in which the Presbytery will use personal information provided to us. Personal information includes any information that identifies you personally, such as your name, address, email address or telephone number.

The Presbytery recognises the importance of your privacy and personal information and we have therefore outlined below how we collect, use, disclose and protect this information. The Presbytery is the data controller, because we decide how your data are processed and for what purpose. Contact details for us are provided below.

How we use information

We use the information you give to us:

to administer membership records;

for pastoral care purposes;

for the general oversight of Church of Scotland congregations within the Presbytery;in relation to participation in Presbytery activities including the training and supervision of ministers, candidates for the ministry and probationers;

to provide you with information about news, events, and activities within the Presbytery or the wider Church of Scotland;

to fulfill contractual or other legal obligations;

to manage our employees;

to further our charitable aims, for example through fundraising activities;

to maintain our accounts and records (including the processing of Gift Aid applications);

if CCTV is in place we have this for the prevention and detection of crime.

Disclosure of information

The Presbytery will only share your personal information where this is necessary for the purposes set out above. Information will not be shared with any third party outwith the Church of Scotland without your consent unless we are obliged or permitted to do so by law.

Basis for processing personal information

The Presbytery processes your information in the course of its legitimate activities, with appropriate safeguards in place, as a not-for-profit body with a religious aim and on the basis that our processing relates solely to members, former members or people who have regular contact with us, and that this information is not disclosed to any third party without your consent.

We also process information where this is necessary for compliance with our legal obligations; where processing is necessary for the purposes of our legitimate interests and such interests are not overridden by your interests or fundamental rights and freedoms; and where you have given consent to the processing of your information for a particular purpose.

Storage and security of personal information

The Presbytery will strive to ensure that personal information is accurate and held in a secure and confidential environment. We will keep your personal information for as long as you are a member or adherent of a congregation within the Presbytery or have regular contact with us or so long as we are obliged to keep it by law or may need it in order to respond to any questions or complaints or to show that we treated you fairly. We may also keep it for statistical purposes but if so we will only use it for that purpose. When the information is no longer needed it will be securely destroyed or permanently rendered anonymous.

Getting a copy of your personal information

You can request details of the personal information which the Presbytery holds about you by contacting us using the contact details given below.

Inaccuracies and Objections

If you believe that any information the Presbytery holds about you is incorrect or incomplete or if you do not wish your personal information to be held or used by us, please let us know. Any

information found to be incorrect will be corrected as quickly as possible.

You have the right to object to our use of your personal information, or to ask us to remove or stop using your personal information if there is no need for us to keep it. There may be legal or other reasons why we need to keep or use your data, but please tell us if you think that we should not be using it.

If we are processing your data on the basis of your explicit consent, you can withdraw your consent at any time. Please contact us if you want to do so.

Contact us

You can contact us by getting in touch with the Presbytery Clerk (or Depute Clerk) at:

The Presbytery of Perth

Presbytery Office

Suite F/3

Riverview House

Friarton Road

Perth

PH2 8DF.

Tel. 07596 868064

How to complain

You have the right to complain to the Information Commissioner’s Office about anything relating

to the processing of your personal information by the Presbytery. You can contact the ICO via its

website at www.ico.org.uk or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

Data Security Breach Management Policy

This policy covers all congregations within the Presbytery.

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data.

If it appears that a data security breach has occurred, a report must immediately be made to the Presbytery Clerk. The following breach management plan will then be implemented.

1. Containment and recovery

1.1 The Presbytery Clerk as Data Protection Compliance Officer will take the lead in responding to the breach, and in investigating the nature and cause of the breach and the extent of the harm that could result. He or she may elect to carry out all necessary investigation him or herself or alternatively may appoint someone else to do so. As a first step, the Clerk will establish who needs to be made aware of the breach and will inform them of what they are expected to do to assist in the containment exercise. This could be, for example, finding a lost document or piece of equipment.

1.2 Steps will be taken to establish whether there is anything which can be done to recover any losses and limit the potential damage arising from the breach. As well as the physical recovery of equipment, this could involve the use of back up tapes to restore lost or damaged data or ensuring that people recognise when someone tries to use stolen data to access accounts.

1.3 The Clerk will determine the identity of the data controller for the purposes of the breach, bearing in mind that there may be more than one data controller where shared services are involved. If it appears that the breach has been caused by another data controller, or by the data processor, the terms of the contract with that third party will be checked with a view to determining whether a claim may lie for breach of a specific obligation, breach of confidence or a failure to take reasonable skill and care; and whether the breach gives rise to a right to terminate the contract.

1.4 An immediate report of the breach must be made by the Clerk to the Solicitor of the Church.

1.5 Consideration should be given to whether or not it is appropriate to inform the police.

2. Assessing the risks

2.1 Some data security breaches will not lead to risks beyond possible inconvenience to those who need the data to do their job. Before deciding on what steps are necessary beyond immediate containment, the Clerk will assess the risks which may be associated with the breach. Perhaps most important is an assessment of potential adverse consequences for individuals; how serious or substantial these are; and how likely they are to happen.

2.2 The following points will be borne in mind when making this assessment:

What type of data is involved?

How sensitive is it? Some data is sensitive because of its very personal nature (e.g. information about health) while other data is sensitive because of what might happen if it is misused (e.g. bank account details)

If data has been lost or stolen, are there any protections in place such as encryption?

What has happened to the data? If data has been stolen, it could be used for purposes which are harmful to the individuals to whom the data relates; if it has been damaged, this poses a different type and level of risk

Regardless of what has happened to the data, what could the data tell a third party about the individual? Sensitive data could mean very little to an opportunistic laptop thief while the loss of apparently trivial snippets of information could help a determined fraudster build up a detailed picture of other people

How many individuals’ personal data are affected by the breach? It is not necessarily the case that the biggest risks will accrue from the loss of large amounts of data but this is an important determining factor in the overall risk assessment

Who are the individuals whose data has been breached? Whether they are staff, volunteers or suppliers, for example, will to some extent determine the level of risk posed by the breach and, therefore, the appropriate actions in attempting to mitigate those risks

What harm can come to those individuals? Are there risks to physical safety or reputation, of financial loss or a combination of these and other aspects of their life?

Are there wider consequences to consider such as a loss of public confidence or reputation?

If individuals’ bank details have been lost, the banks themselves could be contacted for advice on anything they can do to help prevent fraudulent use.

3. Notification of breaches

3.1 Informing people and organisations of the data security breach can be an important element in a breach management strategy, but this is not an end in itself. Notification should have a clear purpose, whether this is to enable individuals who may have been affected to take steps to protect themselves or to allow the appropriate regulatory bodies to perform their functions, provide advice and deal with complaints.

3.2 All decisions on notification will be taken by the Solicitor of the Church, in discussion with the Clerk. The Solicitor will be responsible for notifying the Information Commissioner’s Office (“ICO”) where this is appropriate. The Clerk will be responsible for notifying affected individuals, where appropriate.

3.2 If it is likely that there will be a risk to people’s rights and freedoms, the breach must be reported to the ICO. If such a risk is unlikely then it does not have to be reported. If a decision is taken not to report the breach, this decision and the reasons for it must be documented.

Notifiable breaches must be reported to the ICO without undue delay, but not later than 72 hours after we become aware of it. If we take longer than this, we must give reasons for the delay.

3.3 If a breach is likely to result in a high risk to the rights and freedoms of individuals, those concerned must be informed without undue delay. In other words, this should take place as soon as possible. A ‘high risk’ means that the threshold for informing individuals is higher than for notifying the ICO. It will be necessary to assess both the severity of the potential or actual impact on individuals as a result of a breach and the likelihood of this occurring. If the impact of the breach is more severe, the risk is higher; if the likelihood of the consequences is greater, the risk is higher. In such cases, we must promptly inform those affected, particularly if there is a need to mitigate an immediate risk of damage to them.

3.4 The following considerations will be taken into account in assessing the likelihood and severity of the risks and deciding whether to notify:

The type of breach

The nature, sensitivity and volume of the data involved

Ease of identification of individuals

Severity of consequences

The number of affected individuals

Are there any legal or contractual requirements to do so, for example if a regulatory body is involved (is a report of a serious incident to OSCR required?)

Can notification help the individual? Bearing in mind the potential effects of the breach, could individuals act so as to mitigate risks, for example by cancelling a credit card or changing a password?

Special characteristics of the individual

How notification can be made appropriate for particular groups of individuals, for example vulnerable adults

Is there a danger of ‘over notifying’? Not every incident will warrant notification and notifying a large number of people about an issue affecting only a small number may well cause disproportionate enquiries and work

3.5 Bear in mind that it may also be appropriate to notify insurers of potential claims.

3.6 Consideration will also be given to what should be said to any person or body to whom notification is made, and how that message is to be communicated. This will depend to a large extent on the nature of the breach but the following points will be taken into account:

There are a number of different ways to notify those affected. The most appropriate one will be used, bearing in mind the security of the medium as well as the urgency of the situation

Notification will include a description of how and when the breach occurred; what data was involved; and what has already been done to respond to the risks posed by the breach

When notifying individuals specific and clear advice will be given on the steps they can take to protect themselves and also what the Church is willing to do to help them

Information will be provided about how individuals can obtain further information or ask questions about what has occurred

4. Evaluation and response

4.1 It is important not only to investigate the causes of the breach but also to evaluate the effectiveness of the Presbytery’s response to it. If it is established that existing procedures could lead to another breach, improvements to those procedures will be identified. Questions

to be asked will include:-

Was the data protection policy, and in particular its security provisions, followed?

Does action need to be taken to raise security compliance standards?

What are the weak points in existing security measures?

Should disciplinary steps be taken against any staff members?

Have adequate training and guidance been provided?

Are adequate contractual safeguards in place?

Where do the biggest risks lie? Risks will arise when sharing data with or disclosing

to others.

Are the methods of transmission secure?

Is only the minimum amount of data necessary being disclosed or shared?

5. Recording breaches

5.1 Alll breaches must be recorded, regardless of whether or not they need to be reported

to the ICO.

5.2 The facts relating to the breach, its effects and the remedial action taken must all be recorded. Consideration should be given to whether or not the breach was a result of human error or a systemic issue and how a recurrence might be prevented, whether through better processes, further training or other corrective steps.