Data Protection (GDPR) Policy for Cruden Bay Life
Last Updated: 22 August 2026
1. Introduction and Purpose
Cruden Bay Life (the “Hub”) operates as a central digital community platform for the residents, clubs, organisations, and businesses of Cruden Bay, Aberdeenshire. In executing our community objectives (under the Cruden Bay Community Action Plan 2024), we collect and process certain personal data.
This Data Protection Policy outlines our commitment to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It establishes the operational rules and standards that our website administrators, editors, and volunteers must follow when handling personal information.
2. Our Data Protection Principles
We ensure that all personal data is processed in accordance with the core principles of the UK GDPR:
- Lawfulness, Fairness, and Transparency: We only process data where we have a valid legal basis (typically consent or legitimate interests). We are open and transparent with individuals about how their data is used through our public-facing Privacy Policy.
- Purpose Limitation: Data is collected for specified, explicit, and legitimate community-hub purposes (e.g., maintaining the directory, coordinating local history updates) and is not processed in any manner incompatible with those purposes.
- Data Minimisation: We only collect and retain the minimum amount of personal data necessary to perform our services (e.g., we do not ask for home addresses if only an email is required to manage a directory listing).
- Accuracy: We take reasonable steps to ensure that personal data is kept up to date and corrected without delay when inaccuracies are reported to us via together@crudenbay.life.
- Storage Limitation: We do not keep personal data in a form that identifies individuals for longer than is necessary. Directory data is removed when a business or group deregisters.
- Integrity and Confidentiality (Security): We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, accidental loss, alteration, or destruction.
- Accountability: We take responsibility for how we handle personal data and maintain records to demonstrate our compliance with these principles.
3. Roles and Responsibilities
Since Cruden Bay Life is a community-run initiative, administrative responsibilities are shared among the core steering team:
- Data Protection Contact: The administrators of the together@crudenbay.life inbox serve as the primary point of contact for data protection matters.
- Website Administrators/Editors: Any volunteer granted backend access to the WordPress website or the contact email inbox must adhere strictly to this policy, use strong passwords, and handle personal data confidentially.
4. Operational Procedures for Data Subject Rights
The UK GDPR grants individuals specific rights regarding their personal data. Cruden Bay Life is committed to addressing requests promptly and free of charge:
A. Subject Access Requests (SARs)
- Right: Individuals have the right to ask what personal data we hold about them and receive a copy.
- Procedure: Upon receiving a request at together@crudenbay.life, we will verify the identity of the requester and provide the relevant data in a structured, electronic format within one calendar month.
B. Rectification and Erasure (“Right to be Forgotten”)
- Right: Individuals can request the correction of inaccurate data or the complete deletion of their personal information.
- Procedure: We will update or delete directory listings, volunteer attributes, or email records within 14 business days of receiving a valid request, and confirm the action back to the user.
5. Security Measures
To maintain data security, we enforce the following guidelines:
- Encryption: The website must maintain active SSL encryption (HTTPS) to secure all data in transit.
- Access Control: Administrative and editor access to WordPress must be limited only to active, trusted volunteers.
- Password Policy: All admin and editor accounts must utilise unique, strong, system-generated passwords. Multi-Factor Authentication (MFA) should be enabled where supported.
- Data Minimisation in Local Storage: Personal data (such as CSV exports of directory registrations) must not be stored on personal computers or shared drives longer than necessary to complete an administrative update.
6. Personal Data Breach Management
A personal data breach refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
In the event of a suspected or actual data breach (e.g., unauthorized website backend access or an email inbox compromise):
- Containment & Recovery: The administrators will immediately limit the breach (e.g., by changing compromised passwords, revoking active sessions, or locking out affected IP addresses).
- Assessment: We will assess the potential risk to affected individuals (e.g., risk of identity theft, fraud, or reputational damage).
- Notification to the ICO: If the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of it.
- Notification to Individuals: If the breach is likely to result in a high risk to individuals’ rights and freedoms, we will notify all affected individuals directly without undue delay so they can take protective steps.
7. Review and Maintenance
This Data Protection Policy is a living document. We will review it annually (or sooner if relevant data protection laws or our administrative procedures change) to ensure it remains accurate and legally compliant.