Outmore NI is committed to protecting the privacy and security of the personal information that we collect and process in connection with our activities. This policy outlines how we collect, use, and safeguard personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
In this policy, we explain the types of personal data we collect, the reasons why we collect it, how we use it, and the measures we take to protect it. It also outlines your rights regarding the personal data we hold and how you can exercise those rights.
This policy applies to:
Outmore NI is committed to ensuring compliance with the GDPR and safeguarding the privacy of all individuals whose personal data we collect and process. This section outlines the responsibilities of various roles within our organisation regarding data protection and privacy.
The Data Protection Officer (DPO) is responsible for overseeing the organisation’s data protection strategy and its implementation to ensure compliance with GDPR requirements.
2. Senior Management Team
The Senior Management Team (SMT) is responsible for supporting the implementation of data protection practices across the organisation and ensuring that sufficient resources are allocated to GDPR compliance.
3. All Employees
Every employee, contractor, and volunteer has a responsibility to ensure the protection of personal data and to comply with the GDPR principles.
4. Third Party Providers
Third parties who process data on behalf of Outmore NI (e.g., mailing list services) must comply with GDPR.
Outmore NI adheres to the following six principles as outlined by the UK GDPR, which form the foundation of how we handle personal data.
We process personal data in a lawful, fair, and transparent manner, ensuring that individuals understand how their data is to be used.
2. Purpose Limitation
We collect data for specified, explicit, and legitimate purposes and do not process it beyond those purposes unless required by law.
3. Data Minimisation
We ensure that the data we collect is adequate, relevant, and limited to what is necessary for processing.
4. Accuracy
We take all reasonable steps to ensure that the personal data we hold is accurate and kept up to date, promptly correcting or deleting any inaccurate data.
5. Storage Limitation
We do not retain personal data for longer than is necessary for the purposes for which it was collected.
6. Integrity and Confidentiality
We securely handle personal data by implementing appropriate technical and organisational measures to protect it from unauthorised access, loss or damage.
The reasons we collect data include:
We collect information to deliver high-quality services, such as managing events, workshops, and programmes. Understanding your preferences enables us to tailor our services to better meet your needs and interests.
2. To keep you informed
We gather data to communicate with you, providing updates, newsletters, ezines, and information about projects and events.
3. To improve your experience
By collecting data on how you interact with our website, services and events we gain insights into what works well and what can be improved. This enables us to enhance the overall user experience, ensuring that our content, websites and programmes are user-friendly and engaging
4. To develop and plan future projects
We gather insights from surveys, feedback and participation data, so we can better understand needs and preferences. This information guides us in planning and developing new initiatives, projects, and programmes that align with public interest.
5. To fulfil legal and regulatory obligations
We are required to collect certain types of data to comply with legal obligations. This includes maintaining accurate financial records, adhering to health and safety regulations and following data protection laws.
6. To measure and report on our impact
We use data to evaluate the effectiveness of our programmes and activities, demonstrating our impact to stakeholders, councils and funding bodies. This information helps us secure support and resources to continue promoting outdoor recreation throughout Ireland.
We collect personal data including, but not limited to:
How do we collect data?
We collect data in the following ways:
Under the General Data Protection Regulation (GDPR), we are required to have a legal basis for processing personal data. The legal bases we rely on for processing personal data include:
We will process your personal data only when you have given clear and explicit consent for us to do so. For example, if you sign up for one of our newsletters or participate in surveys, we will process your data based on the consent you have provided. You have the right to withdraw your consent at any time by contacting us.
2. Contractual Necessity (Article 6(1)(b) GDPR)
Processing may be necessary for fulfilling a contract to which you are a party. This includes situations where we process data to deliver services you have requested or manage events and programmes you have registered for.
3. Legal Obligation (Article 6(1)(c) GDPR)
In certain cases, we may be required to process personal data to meet legal obligations. This includes data we are legally required to keep for tax, financial reporting, or other regulatory requirements.
4. Legitimate Interests (Article 6(1)(f) GDPR)
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Our legitimate interests might include improving our services, understanding how users engage with our website or promoting safety and security. We will always consider your rights and perform a balancing test to ensure that our interests do not unduly impact your rights and freedoms.
5. Vital Interests (Article 6(1)(d) GDPR)
In rare situations, we may use personal data to safeguard an individual’s vital interests. For instance, this may apply if we need to contact emergency services during a medical emergency at an event or activity.
6. Public Task (Article 6(1)(e) GDPR)
We may need to process data when it is necessary to perform a task carried out in the public interest. This basis is less common and would only apply if we are fulfilling duties assigned by government bodies. For example, we may need to collect data from community members to understand barriers to participating in outdoor recreation. This information can then be used to inform government-funded initiatives aimed at improving access to green and blue spaces.
We are committed to securely storing and protecting your personal data. We have implemented a range of technical, physical and organisational measures to safeguard your information. Here is how we accomplish this:
understand and adhere to our data protection policies.
We keep personal data only for as long as it is necessary to fulfil the purpose for which it was collected, or to comply with legal, regulatory or contractual requirements. Our data retention periods vary depending on the type of data and the reason for its collection. Here’s how we determine how long we keep your data:
We keep data related to event registrations, participation and attendance records for one year after the event has concluded. This helps us to manage follow-up communication, gather feedback, and plan for future events. After this period, the data is securely deleted or anonymised.
2. Public Consultations
We retain data collected during consultations until the results have been analysed, and reported, and any necessary actions or decisions have been made. This period typically might be 6 months to 1 year after the conclusion of the consultation. In some cases, data may need to be kept until the project is completed, and this may exceed one year. After this time, the data is either securely deleted or anonymised.
3. Newsletter and Marketing Communications
We retain your contact information for as long as you are subscribed to our newsletters, ezines and marketing communications. If you decide to unsubscribe, we will promptly remove your data from our marketing lists. However, we may keep a record of your request to ensure you do not receive further marketing communications.
4. Survey and Feedback Data
Data collected through surveys and feedback forms is kept for one year to analyse results, improve our services, and plan future projects. After this period, the data is anonymised or securely deleted.
5. Financial and Transactional Data
We retain data related to payments, invoices and other financial transactions for seven years, as required by tax and accounting regulations. After this period, the data is securely archived or deleted.
6. Website Interaction and Analytics Data
Information collected through website cookies and other tracking technologies is retained for one year, after which it is deleted or anonymised. You can manage your cookie preferences through your browser at any time.
7. Legal and Compliance Obligations
In some situations, we may be required to retain data for an extended period to meet legal obligations, resolve disputes, or enforce agreements. When this occurs, the data is securely stored until it is no longer needed for these purposes.
We value your privacy and are committed to keeping your personal data secure. We only share your personal data with third parties when it is necessary to provide our services, fulfil our legal obligations, or if you have given us your explicit consent. Below we outline the circumstances under which we may share your personal data:
We may share your personal data with trusted service providers, sub-contractors, and partners who assist us in delivering our services. This includes companies that provide IT services, event management, marketing and analytics services.
These third parties are only permitted to process your data according to our instructions and must adhere to strict data protection regulations to ensure the security and confidentiality of your information.
2. Clients, Councils and Funding Bodies
We may share your personal data with clients, councils and funding bodies for project reporting purposes. In most cases, the information shared will be anonymised or aggregated.
3. Event Co-Organisers and Sponsors
If you participate in an event, public consultation, or workshop that we organise in collaboration with partners or sponsors, we may share your information with them for logistical purposes and to provide you with relevant information about the event.
We will inform you at the time of registration if your data will be shared with event partners and give you the option to opt-out where appropriate.
4. Marketing and Advertising
We do not sell or share your personal information with third parties such as marketing agencies and platforms for targeted advertising.
5. Legal Compliance and Obligations
We may disclose your personal data when required by law or to comply with legal processes, court orders, or government regulations. This includes sharing data with law enforcement agencies when necessary to protect the rights, properties, or safety of Outmore NI, our stakeholders, clients, or other connected persons.
6. Research and Analysis
We may share anonymised or aggregated data that does not identify you with third parties for research, statistical analysis, or promotional purposes. This helps us better understand our audience and improve our services, without compromising your privacy.
Under the General Data Protection Regulations (GDPR), you have specific rights concerning your personal data. Outmore NI is committed to respecting your rights and ensuring that you can easily access, update, or manage your information. Below, we outline your rights as a data subject and explain how you can exercise them:
You have the right to request access to the personal data we hold about you. This allows you to receive a copy and verify that it is being processed lawfully.
2. Right to Rectification
If you believe that any of the information we hold about you is inaccurate or incomplete, you have the right to request its correction or update.
3. Right to Erasure (Right to Be Forgotten)
You have the right to request the deletion of your personal data if we no longer need to keep it, or if you have withdrawn your consent that was previously the legal basis for processing.
4. Right to Restrict Processing
You have the right to ask us to restrict or suspend the processing of your personal data under certain circumstances, such as if you dispute the accuracy of the data or if you object to our processing.
5. Right to Data Portability
You have the right to request the transfer of your personal data to another organization or directly to you, in a structured, commonly used, and machine-readable format.
6. Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis for processing, or when your data is used for direct marketing purposes.
7. Right to Withdraw Consent
If we are processing your personal data with your consent, you have the right to withdraw your consent at any time. Withdrawing consent will not affect the lawfulness of any processing we carried out before your withdrawal.
8. Right to Lodge a Complaint
If you believe that your data protection rights have been violated, you have the right to file a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO), and in Ireland, it is the Data Protection Commission (DPC).
To exercise any of the above rights, please send your request to the contact information at the end of the policy. We may need to verify your identity before processing your request to ensure the security of your information. We aim to respond to all legitimate requests within 30 days.
Outmore NI makes every effort to protect the personal data we collect and use. While we strive to implement robust security measures, we understand that data breaches can happen. This section outlines our procedures for managing data breaches and ensuring compliance with our legal obligations under GDPR.
1. Definition of a data breach
A data breach occurs when there is unauthorised access, loss, disclosure, alteration, or destruction of personal data. Examples include data being lost or stolen, accessed by unauthorised parties, or accidentally shared.
2. Preventive Measures
We implement a variety of technical and organisational measures to secure personal data, such as encryption, firewalls, and access controls. Regular audits and security reviews are conducted to minimise the risk of data breaches.
3. Response to Data Breaches
In the event of a data breach, we will take immediate steps to contain and assess the breach, including:
4. Notification of Affected Individuals
If a data breach poses a high risk to your rights and freedoms, we will notify you as soon as possible. This notification will include:
5. Notification to Supervisory Authorities
In compliance with GDPR, we will report any data breaches that may risk individuals’ rights and freedoms to the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, if possible.
If it is not possible to report within 72 hours, we will provide the reasons for the delay when making the report.
6. Documentation of Data Breach
We keep detailed records of all data breaches and any near misses, regardless of their impact. This documentation includes the nature of the breach, its cause, the steps taken to address it, and any communications with affected individuals and supervisory authorities.
We use cookies to monitor how you interact with our website. This helps us to understand your usage patterns, allowing us to enhance our website and improve our products and services to better meet your needs and preferences. For more information, please refer to our Cookie Policy
We may update this policy periodically to reflect changes in our practices and legal requirements, or for other operational, legal, or regulatory reasons.
If we make any significant changes, we will notify you through appropriate communication channels.
We will provide a clear explanation of what has changed and how it may impact your data.
Minor updates or adjustments that do not impact your rights or the way we process your personal data may be made without direct notification. However, we will always update the “last updated” date at the top of this policy.
We have appointed a Data Protection Officer who is responsible for privacy-related matters. If you have any questions about this policy, please contact the Data Protection Officer using the details provided below.
Data Protection Officer’s Name: Roisin Gallagher
Address: The Stableyard, Barnetts Demesne, Malone Road, Belfast, BT9 5PB.
Email Address: Roisin@out-scape.com
Phone Number: 028 90303930