GDPR Policy

1. Introduction

This Data Protection Policy outlines the Music Relief Foundation’s (MRF) commitment to ensuring the lawful, fair, and transparent processing of personal data in compliance with the General Data Protection Regulation (GDPR).

2. Scope

This policy applies to all staff and volunteers involved in MRF’s services, activities, training, and overall operations.

3. Policy Details

  • Operational Date: 24/05/2019
  • Prepared by: Olga Shaumyan
  • Reviewed/Amended: 01/02/2026
  • Next Review Date: 01/02/2027

4. Distribution

  • Available on the MRF website and staff shared drive.
  • All trustees and staff must read it upon appointment or review.
  • A summary of key policies is included in the volunteer handbook, with clear signposting to the full document.
  • Volunteers will be informed of any updates affecting their roles.

5. Definitions

  • Charity: Music Relief Foundation (MRF), a registered charity.
  • GDPR: General Data Protection Regulation.
  • Responsible Person: The designated Data Protection Officer.
  • Register of Systems: A record of all data processing systems used by MRF.

6. Data Protection Principles

MRF is committed to processing personal data in line withGDPR Article 5, ensuring that data is:

  • Processed lawfully, fairly, and transparently.
  • Collected for specific, legitimate purposes and not used in incompatible ways.
  • Adequate, relevant, and limited to necessity.
  • Accurate and kept up to date.
  • Retained only for as long as necessary.
  • Processed securely to prevent unauthorised access, loss, or damage.

7. General Provisions

  • This policy applies to all personal data processed by MRF.
  • The Responsible Person ensures compliance with this policy.
  • The policy is reviewed at least annually.
  • MRF is registered with the Information Commissioner’s Office (ICO).

8. Lawful, Fair, and Transparent Processing

  • MRF maintains a Register of Systems to track data processing.
  • The register is reviewed at least annually.
  • Individuals can access their personal data, and requests are handled promptly.

9. Lawful Basis for Processing

MRF processes data under one of the following legal bases:

  • Consent
  • Contractual necessity
  • Legal obligation
  • Vital interests
  • Public task
  • Legitimate interests

Where consent is required:

  • Evidence of opt-in consent is maintained.
  • Individuals can withdraw consent at any time, with systems in place to reflect this.

10. Data Minimisation

  • MRF ensures data collection is relevant and limited to necessity.
  • Wherever possible, personal data will not be recorded.

11. Accuracy

  • Reasonable steps are taken to ensure data accuracy.
  • Data is updated when necessary.

12. Data Retention and Archiving

  • MRF has an archiving policy to determine what data should be retained, for how long, and why.
  • This policy is reviewed annually.

13. Security Measures

  • Personal data is stored securely using modern, up-to-date software.
  • Access is restricted to authorised personnel.
  • Data deletion is performed securely to prevent recovery.
  • Backup and disaster recovery measures are in place.

14. Data Breaches

In the event of a data breach:

  • MRF will assess the risk to individuals’ rights and freedoms.
  • If required, MRF will report the breach to the ICO following regulatory guidelines.

15. Compliance and Review

  • This policy is reviewed regularly to ensure continued compliance with GDPR.
  • Any updates will be communicated to relevant stakeholders.

Contact the Data Protection Officer Magdalene Usikaro FRSA, for more information.