A UK chapter of The Outpouring Oasis family — visit the global site
Compliance

Policies & Privacy

How ComeAlive UK (The Outpouring Oasis UK) handles personal data and keeps its workers and volunteers safe.

Data Protection Policy

ComeAlive UK a.k.a. Outpouring Oasis UK

Purpose

The fellowship of ComeAlive UK is a "data controller" under GDPR regulation and personal data will be handled on behalf of the fellowship by Office Holders (Administrative Secretary and any Curates), and other members of staff (here collectively known as "Leaders", "we", "us").

The GDPR requires that personal data (relating to any living individual who can be identified from that data) shall be:

  1. processed lawfully, fairly and in a transparent manner;
  2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. This means that individuals should be told what we are going to do with their personal data before we use it, and consent to such use;
  3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are used;
  4. accurate and where necessary, kept up to date. Personal data that is found to be inaccurate should be deleted or corrected without delay. All personal data should be periodically checked to make sure that it remains up to date and relevant;
  5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
  6. kept securely. Personal data storage should be safe and secure — in lockable filing cabinets or in password protected computer files. Names and addresses of individuals should not be left unattended.

This Policy sets out how all Leaders are to ensure this, and what to do in the event of a breach. It is to be read in conjunction with the Fellowship's Privacy Notice.

Protecting Data

Where we hold personal data, Leaders will ensure that:

  • they do not share it outside the church except for legal reasons, or informed consent;
  • they respond promptly to data subject requests, including requests for removal, as directed by our data protection leader;
  • where kept on a computing device, there shall be at least one password or passcode in place to unlock the device, not to be shared with any other family member;
  • prayer requests relating to identifiable individuals are not published to a public written forum or publication, without informed consent (this does not stop spoken prayers in services, events or meetings);
  • where photographs or video of meetings or events are published to a public forum, individuals are not to be shown or identified unless informed consent is given. Where children are included, we will respect any parents' wishes that their child(ren) are not shown at all.

Additionally, we ask that wherever possible email communication to large church groups be done through the fellowship Information Management System, which applies any relevant do-not-communicate preferences, provides an audit trail, and ensures that personal contact details aren't inadvertently shared.

Where our fellowship Information Management System isn't used, Leaders are to use blind copy to groups, unless they have consent for all recipients to share their email address amongst the group. Where we hold information by data subject's consent, we aim to refresh every 5 years.

For sensitive personal data (records of pastoral conversations, financial information, details of disclosed criminal records, and data on children), Leaders will additionally ensure that they:

  • keep such data behind a second password or passcode (where held on a computing device), or in a locked cabinet;
  • securely hold or destroy such records as directed by the National Church guidance;
  • only share with other Leaders as approved or directed by the Director and church staff.

We request all Fellowship Leaders not to keep details of pastoral conversations, beyond purely factual matters, as we then don't need to register with the ICO and pay a yearly fee.

NB: this policy is overridden by any legal requirements, such as notes of conversations disclosing criminal or safeguarding matters.

We will require all staff and those volunteers who handle sensitive personal data to sign a copy of this Data Protection Policy, indicating that they have read it and agree to abide by it. Where someone requests a notice be included in our bulletin or other published forum that includes their contact details, we will consider this to include their informed consent.

Documentation

We will follow national guidance and keep a Register of Processing Activities (ROPA) which keeps "a written record of all your processing activities, security measures, and data retention practices", along with "the various types of processing" and "the purpose and legal basis" for it.

We will also document our compliance. To do this our Data Protection Officer will keep a Data Protection Log, briefly noting individual rights requests, training, new leaders inducted agreeing this policy, reviewing policies, and any breach details. This will be brought to the fellowship once a year, in the lead up to the Annual Congregational Meeting.

Data Breach

In the event of a "data breach" — the deliberate or accidental sharing with those not authorized, however small — Leaders shall immediately inform the Administrative Secretary, and then follow their guidance. This may include informing the Information Commissioner's Office (ICO) as well as the data subjects affected.

Further Information

To discuss any aspect of this, or to request training in handling data, please email comealiveuk@gmail.com.


Data Privacy Notice

ComeAlive UK a.k.a. Outpouring Oasis UK

Who are we?

ComeAlive UK ("we", "us") is the "data controller". This means we are responsible for how your personal data is processed and for what purposes.

Your personal data — what is it?

Personal data relates to data about or images of a living individual (the "data subject") who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller's possession or likely to come into such possession. The processing of personal data is governed by the Data Protection Act (1998) and the newer General Data Protection Regulations (GDPR) (2018).

How do we process your personal data?

The fellowship complies with its obligations under the GDPR by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorized access and disclosure; and by ensuring that appropriate technical measures are in place to protect personal data.

We use your personal data for the following purposes:

  • To enable us to provide a voluntary service for the benefit of the public in the particular geographical area as specified in our constitution;
  • Recording or live-streaming services from our church in order to reach out to those who are unable to attend in person, or who wish to participate in our services remotely;
  • To determine eligibility for elections to our local Church Councils and regional church bodies;
  • To administer membership records;
  • To fundraise and promote the interests of the charity;
  • To manage our employees and volunteers (including safeguarding check data);
  • To recruit new staff (including when required for safeguarding, information about other members of your household over 16);
  • To maintain our own accounts and records (including the processing of gift aid);
  • To inform you of news, events, activities and services organized by the Church.

What is the legal basis for processing your personal data?

The personal data held and processed by us is classed as sensitive because it relates to 'religious belief', either directly or indirectly. We can maintain and process personal data through several different authorizations, as defined by the ICO:

  • Processing is necessary for carrying out obligations under national church, employment, charity, tax, social security or social protection law, or a collective agreement;
  • Processing is carried out by a not-for-profit body with a religious aim provided the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes); and there is no disclosure to a third party without consent;
  • Explicit consent from the data subject — including signing a photo/media release form.

Sharing your personal data

Your personal data will be treated as strictly confidential and will only be shared with other members of the fellowship to carry out a service to other church members or for purposes connected with the church — for example our serving rotas.

We will only share your data with third parties outside of the fellowship with your consent, or where required to do so by law. This includes when required for safeguarding children or vulnerable adults, for public display of the Electoral Roll of names for a period before the Annual Parochial Church Meeting and then retention by the Church of England.

We will be sharing the recorded or live-streamed services with the general public, by uploading them to social media and other internet sites.

How long do we keep your personal data?

We keep data in accordance with the Church of England guidance. Specifically, we retain:

  • electoral roll data while it is still current (i.e. up to 7 years);
  • membership and involvement details between 2–6 years;
  • details of gift aid declarations and other financial gifts for up to 7 years after the tax year to which they relate;
  • safeguarding information as advised by Diocesan authorities;
  • parish registers (baptisms, marriages, funerals, banns, confirmations and services) permanently.

Your rights and your personal data

Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:

  • The right to request a copy of your personal data which the fellowship holds about you;
  • The right to request that the fellowship corrects any personal data if it is found to be inaccurate or out of date;
  • The right to request your personal data is erased where it is no longer necessary for the Church to retain such data;
  • The right to withdraw your consent to the processing at any time;
  • The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller (known as the right to data portability, where applicable);
  • The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
  • The right to object to the processing of personal data (where applicable);
  • The right to lodge a complaint with the Information Commissioner's Office.

Further processing

If we wish to use your personal data for a new purpose, not covered by this Data Protection Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.


Lone Working Policy

ComeAlive UK a.k.a. Outpouring Oasis UK

Policy

ComeAlive UK is committed to the health, safety and wellbeing of its leaders, staff and lay workers who, in the course of their work and ministry, may have to work alone, and this policy provides a framework for managing the risks presented by lone working, as well as identifying the responsibilities each person has in this situation.

This policy relates to all Fellowship personnel who work out in the community and/or in other people's homes, or who work alone in office and are physically isolated from colleagues or family, without access to immediate assistance.

Principles

Pastoral encounters are at the heart of much of the fellowship, undertaken by clergy and other lay church workers every day. We therefore recognize that lone working is an essential practice, though it carries additional risks. Therefore, one-to-one contact with individuals in the context of pastoral support must be properly planned, risk assessed and recorded in order to ensure that vulnerable people are protected and that workers can do so safely, and are not wrongly accused of abuse or misconduct. Such contact is normally done face-to-face, but at times will also be by phone, email or social media. This policy should therefore be read in conjunction with the good practice guidance given in the fellowship Safeguarding Handbook.

All workers and volunteers should avoid working alone if it is not necessary, and work with others where possible. However, when this is not feasible, they should be aware of the importance of personal safety, and take all reasonable precautions to safeguard themselves from harm, and false accusations, as they would in any other circumstances.

The fellowship Council is responsible for ensuring that all lone working activities within the office are formally identified, and appropriate risk assessments are undertaken in order to identify and reduce the risks which lone working presents. In drawing up and recording an assessment of risk, issues such as the place of meeting, security, the risk of violence and the nature of the task or activity should be considered alongside any other factors appropriate to the circumstances, such as the lone worker's health and fitness, age and gender. Where there is any reasonable doubt about the safety of a lone worker, we will consider other arrangements to complete the task or activity, such as ensuring individuals work in pairs.

The perception of risk can be seen differently by each individual, and, therefore, it is important that all lone workers receive relevant information about the identified risks within their role, in order that they are equipped to recognize these, and are enabled to take responsibility for their own safety and security.

We will have adequate insurance in place to cover all lone working activities which have been identified by a risk assessment.

All risks to workers identified as arising from lone working must be recorded in accordance with requirements of the Health and Safety at Work Act 1974, and the Management of Health and Safety at Work Regulations 1999. The following procedures capture the general risks, and set out best practice in mitigating those risks.

Procedures — Personal Safety

Whilst the fellowship has a responsibility to ensure their lone workers' health, welfare and safety, there are also a number of things individuals can do to take reasonable care of themselves:

  • Lone workers should never put themselves at risk. They should conduct their own risk assessment for new situations when they are working alone, which will help them to decide how safe a situation is and what action should be taken to avoid danger.
  • If a situation arises that they are unfamiliar with, or in which they feel unsafe, they should withdraw and seek further advice or assistance.
  • Lone workers must have access to a phone to call for help, and have set up facilities that can easily be set to trigger audible or remote alarms (e.g. using the "Hollie Guard" app).
  • Lone workers should be aware of themselves, their behaviour and the signals they may be giving, and to think about their body language, tone of voice and the choice of words they use with others that could be taken as confrontational or suggestive.
  • If an incident occurs — even if it is considered a minor incident — the worker should make their Group Leader or Safeguarding Officer know as soon as possible in order that the appropriate risk assessment and follow-up action can be taken.
  • Staff and volunteers should take every reasonable precaution to ensure that they do not disclose their personal details, such as address and telephone number or their private social networking profile, without good reason.

Working Alone in Office

All lone workers should:

  • Undertake a risk assessment on building safety to determine if the building needs extra security. For example, spy holes, door chains or outside lighting can all help to safely identify callers.
  • Lock the entrance door behind them, and feel able to refuse entry to callers.

All lone workers should not:

  • Plan to be alone in office with children or young people. However, if they should find themselves in this situation, it is important that another adult is made aware immediately. The worker should also assess the risks involved in sending the child or young person home, against the risks and vulnerability of being alone with them.

Pastoral Meetings, including Home Visits

Clergy, staff and lay workers may need to meet one-to-one with parishioners or group members. Where possible this should be done in a public place, e.g. a coffee shop. However, sometimes because of illness, infirmity, or where the parishioner is caring for children or relatives, this will need to be at their home. Many leaders will be well known to the visitor, and where there have been no previous concerns the level of risk to the visitor or leaders during visits will usually be low.

However, unexpected circumstances can be encountered, some of which may place the visitor at risk. For example, the unexpected presence in the home of a relative or friend with a history of violence or threatening behaviour.

Therefore, all leaders/staff and volunteers making one-to-one meetings should:

  • Give consideration to working in pairs on a first home visit.
  • Ensure that someone else, i.e. either their Group Leader and/or colleague/family member, is aware of their movements. This means providing them with the address of where they will be meeting, details of the person they are visiting, telephone numbers if known and expected arrival and departure times. At times it may be wise to arrange to receive a phone call checking all is OK 15 minutes after the start of the visit, with a pre-arranged codeword to indicate difficulty.
  • Record meetings, as clear and detailed record keeping may prevent problems in the future.
  • Never undertake a visit to a child or young person in their home unless another adult is present.
  • Be alert to any signs of potential danger during a home visit, and be prepared to leave immediately if they have any concerns. Confrontation should always be avoided, and lone workers should never assume that violence won't happen, as while there are many home visits made safely every day, personal safety is paramount. Any incidents should be reported to the Group Leader or fellowship Safeguarding Officer as soon as possible.
  • Ask the person they are visiting if they can secure any pets they may have which may present a safety risk.
  • Conduct home visits in the morning or early afternoon, rather than the evening or late afternoon, in order that lone workers can avoid travelling in the dark, particularly in areas that they don't know, or may feel uncomfortable in. If this is not feasible, consideration should be given to working in pairs.
  • Avoid calling unannounced — call by arrangement, if appropriate telephoning the person just before going.
  • Knock on the door before entering a room or home, respecting the person's home and possessions.

Record Keeping

Everything is confidential in pastoral ministry unless it is agreed it can be shared with the informed consent of the individual. However, if the individual's behaviour or situation threatens the wellbeing of themselves or others, disclosure to a relevant authority may be a necessity.

Questions about any of these policies? Email comealiveuk@gmail.com or contact us.
WhatsApp