Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.
Privacy Notice
1. About this Privacy Notice
The purpose of this privacy notice is to explain how Christ Church (“we”, “our”, “us”) holds and uses personal data about alumni, donors and supporters (“you”), and how we use it for alumni and supporter relations, and fundraising purposes. You can read Christ Church’s privacy notices relating to other activities and relationships here.
Development and Alumni Relations teams across the collegiate University work closely together and have aligned our policies around data privacy and our privacy notices to provide clarity for our alumni, donors and supporters. You can read the University’s privacy notices here.
2. What we do
Christ Church’s Alumni Relations and Development team exists to establish and develop lifelong relationships with and amongst our alumni, donors and supporters. We’re here to help you stay connected with each other, with Christ Church and with the University of Oxford. Our communications with you will include news, research developments, events, exhibitions, collections and resources, reunions, volunteering opportunities, fundraising priorities and progress updates that are important to you.
We fundraise to ensure that, thanks to the incredible generosity of our donors, Christ Church can ensure an open and competitive admissions process based on merit, preserve the tutorial system, promote scholarship and research at all levels and honour our obligations to the buildings of the college.
3. Information we collect
We, Christ Church, collect information from you in three ways: directly from you during your ongoing relationship with us or with the University of Oxford; from publicly available sources; and/or from third parties providing us with services or acting on our behalf.
The amount of data we collect and hold depends on the frequency and nature of your interactions and engagement with us. Information may be gathered across the lifetime of our relationship with you and from many different forms of interaction.
We may hold and process the following types of personal data about you:
Biographical information, which may include:
Details of our ongoing relationship and your engagement with us, which may include:
Information about your giving, which may include:
Information relating to your willingness or financial capacity to support our charitable objectives, which may include:
Sensitive personal data, which may include:
4. How we use your data
Your personal data are used by us for the following purposes in support of alumni and supporter relations, and fundraising:
If you do not wish your data to be used in any of the ways listed above, or have any questions, please contact us using the details here.
5. When and how we share your data
We may, from time to time, need to share your personal data within the collegiate University of Oxford or with third-parties working on our behalf. We will only do this in appropriate circumstances, by secure means, and with the relevant data sharing agreements in place. We do not, and will not, sell your data.
Third parties will only process your personal data on our instructions and where they have agreed to treat your data confidentially and to keep it secure. We only permit them to process your personal data for specified purposes. We do not allow our third-party service providers to use your personal data for their own purposes nor to keep your data after the processing is complete. All our third-party service providers are required to take appropriate security measures to protect your personal information in line with our policies.
Whenever your information is shared, we will always seek to share the minimum amount of information necessary to fulfil the purpose, this includes the use of anonymised or pseudonymised data where that is sufficient.
Your data may be shared in the following ways:
We benefit from a network of organisations and individuals who volunteer their support to Christ Church. We may share relevant data with them, in appropriate circumstances, by secure means, and with the relevant data sharing agreements in place. These may include:
The following organisations enable tax-efficient giving to Christ Church and/or the collegiate University of Oxford, from outside of the UK. Data may be shared by us with these organisations where it relates specifically to donations you have made, or have pledged to donate via these organisations.
With third-party organisations engaged by Christ Church to provide services. These include but are not limited to:
6. How we protect your data
Christ Church takes precautions to safeguard your personal information against loss, theft and misuse, unauthorized access, disclosure and destruction through the use of appropriate administrative, physical and technical security measures.
All departments within the college have drawn up Information Asset Registers which include information on the measures in place to protect both physical and digital data during its collection, processing, and destruction (if relevant). These Information Asset Registers (or Records of Processing Activities) will be made available on the website.
Access to your personal data is limited to those who need to process it. As far as possible, paper records are kept in locked cabinets or cupboards which are themselves behind access-controlled doors. The whole site is monitored during the day by custodial staff and CCTV is used in public areas. Digital files are always password-protected and encryption is encouraged when personal data is moved. Servers are protected by firewalls and security software. When data is deleted, every effort is made to ensure the deletion of all copies.
Where you have provided us with your credit or debit card information, over the phone, or on a printed giving form, that data is stored securely and destroyed after your payment has been processed. Bank details used for processing Direct Debits are stored under the Direct Debit Guarantee Scheme. Online donations are processed via our third-party payment service providers and your credit or debit card information is not collected or stored by us.
Transfers of your data outside of the European Economic Area (EEA) - although most of the information we collect, store and process stays within the UK, some information may be transferred to countries outside of the European Economic Area (EEA). This may occur if, for example, one of our third-party partners’ servers are located in a country outside of the EEA. This may also occur where staff in our international offices access DARS, our shared relationship-management system.
Transfers outside of the EEA will only take place if one of the following applies:
7. How long we keep your data
Christ Church considers its relationship with alumni, donors and supporters to be life-long and we will retain much of your data indefinitely unless you request otherwise. When determining how long we should retain your personal data we take into consideration our legal obligations and tax or accounting rules. If you have pledged a legacy gift, it will be necessary to retain your data until your gift is received, so that we can identify the gift against that pledge. When we no longer need to retain personal information, we ensure it is securely disposed of. We may keep anonymised statistical data indefinitely, but you cannot be identified from such data.
8. The legal basis for processing your data
We will only use your personal data where the law allows us to do so. Most commonly we rely on the following legal bases for processing your personal data:
Where we have a legitimate interest to do so for purposes listed within this privacy notice. Where we use legitimate interest as the basis for our processing we have carefully considered each of the ways we process your data to ensure that we carry out our activities with a focus on the interests of our alumni, donors and supporters, and in the most efficient and effective way.
Where we need to perform the contract we have entered into with you. Information processed for this purpose includes, but is not limited to, the information you provide when you register for an event, or to enable us to process a donation.
Where we are required to comply with our legal obligations, such as for: reclamation of Gift Aid on your donations; statutory returns to the Office for Students (OfS), the Charity Commission or ICO; participation in the HESA Graduate Outcomes Survey; responses to the Charity Commission or ICO in relation to audits or official investigations; responses to FOI Requests, under the Freedom of Information Act 2000.
Where your consent is required, for example where sensitive personal data is recorded. You can withdraw your consent at any time and we will stop any processing of your personal data requiring your consent. See section 9: “Your legal rights and choices in connection with your personal data”.
Change of purpose
We will only process your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another related reason and that reason is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will seek your consent to use it for that new purpose. Please note that we may process your data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
9. Your legal rights and choices in connection with your personal data
Under certain circumstances, by law you have the right to:
Depending on the circumstances and the nature of your request it may not be possible for us to do what you have asked, for example, where there is a statutory or contractual requirement for us to process your data and it would not be possible to fulfil our legal obligations if we were to stop. However, where you have consented to the processing, you can withdraw your consent at any time by emailing us. In this event, we will stop the processing as soon as we can. If you choose to withdraw consent it will not invalidate past processing.
If you want to exercise any of the rights described above or are dissatisfied with the way we have used your information, please contact the Database Manager[OT1] . We will seek to deal with your request without undue delay, and in any event in accordance with the requirements of the GDPR. Please note that we may keep a record of your communications to help us resolve any issues which you raise.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office.
10. Contact us
If you have any questions about this privacy notice or about your personal data, or if you want to provide updates to your data, make any changes to your communication preferences or exercise any of your rights as outlined above, please contact us in the Development Office.
11. Changes to this Privacy Notice
This privacy notice was last updated on 24th May 2018.
We reserve the right to update this privacy notice at any time. Any changes to this privacy notice will be posted to this page.
Privacy Policy
Christ Church Data Privacy Notice
1. Introduction
Christ Church is committed to protecting the privacy and security of personal data.
This Privacy Notice explains in detail the types of personal data we may collect about you when you interact with us. It also explains how we store and handle that data, and keep it safe.
“Personal data” is information relating to you as a living, identifiable individual.
“Processing” your data includes various operations that may be carried out on your data, including collecting, recording, organising, using, disclosing, storing and deleting it.
The law requires us:
We know that there is a lot of information here but we want you to be fully informed about your rights, and how Christ Church uses your data.
We hope the following sections will answer any questions you have but if not, please do get in touch with us.
It is likely that we will need to update this Privacy Notice from time to time. Notification of any significant changes will be posted on our website, but you are welcome to come back and check it whenever you wish.
Christ Church has two data controllers: the Governing Body of Christ Church, and the Dean and Canons of Christ Church.
2. What is Christ Church?
Christ Church is, formally, the Cathedral Church of Christ of the Foundation of King Henry VIII in Oxford. It was founded by Henry VIII in 1546 as a joint establishment of college of the University of Oxford and as the cathedral of the Diocese of Oxford. It is governed by statutes ratified by the Christ Church Oxford Act of 1867, and most recently updated in 2015.
3. Explaining the legal bases we rely on
The law on data protection sets out a number of difference reasons for which a company may collect and process your personal data. When collecting your personal data, we will always make clear to you which data is necessary for each purpose or type of data. Most commonly, we will process your data on the following lawful grounds:
Special category data
"Special categories" of particularly sensitive personal data require higher levels of protection. We need to have further justification for collecting, storing and using this type of personal data. We aim to collect and process special category data as little as possible and, when we do, it is usually to do with your health and well-being. Christ Church has documented all incidents of our processing of special category data in our Information Asset Registers, and will be preparing a separate document itemising all of these, with reasons, having conducted assessment on each occasion.
The Special Categories of personal data consist of data revealing:
They also consist of the processing of:
We may process special categories of personal data in the following circumstances:
Further legal controls apply to data relating to criminal convictions and allegations of criminal activity. We may process such data on the same grounds as those identified for “special categories” referred to above.
4. When do we collect your personal data?
5. What sort of personal data do we collect?
Depending on your relationship with Christ Church, we may collect the following personal data:
NB. This list is not exclusive. Christ Church will collect more data on some subjects than on others.
For example: a tourist purchasing a ticket at the Visitor Centre will provide minimal personal details and may be recorded on CCTV whereas the personal data collected and processed on members of staff and on students is much more extensive. Christ Church aims, as part of its Data Protection compliance, to collect only what is necessary and to retain that information only for as long as it is needed.
6. How and why do we use your personal data?
Christ Church collects personal data in order to manage its functions as college, cathedral, and tourist destination:
7. How we protect your personal data
Christ Church makes every effort to keep your personal data safe. All departments within college and cathedral have drawn up Information Asset Registers which include information on the measures in place to protect both physical and digital data during its collection, processing, and destruction (if relevant). These Information Asset Registers (or Records of Processing Activities) are under constant review to ensure they are correct and current. Enquiries should be directed to the Data Protection Officer at the address below.
Access to your personal data is limited to those who need to process it. As far as possible, paper records are kept in locked cabinets or cupboards which are themselves behind access-controlled doors. The whole site is monitored during the day by custodial staff and CCTV is used in public areas. Digital files are always password-protected and encryption is encouraged when personal data is moved. Servers are protected by firewalls and security software. When data is deleted, every effort is made to ensure the deletion of all copies.
8. How long will we keep your personal data?
Data Protection legislation requires that personal data is only retained for as long as it is necessary, and all Information Asset Registers include retention periods. In some cases, personal data will be kept in perpetuity, and these Registers will indicate the types of data which are archived for historical or statistical purposes. Regular reviews will ensure that retention schedules are followed.
9. With whom do we share your personal data?
Christ Church will not sell your data to third parties. We may sometimes share your personal data with trusted third parties if we are allowed or required to do so by law. We do not allow third parties to use your data for their own purposes. Third parties may include:
Data Protection legislation requires that data sharing agreements are acquired from each of these third parties, and that the companies guarantee that they comply with the data protection legislation. This list is designed to indicate the possible recipients of your personal data, not to suggest that your personal data will be shared with any or all. A data sharing form will soon be added here, which gives further information on the types of personal data that may be shared and the reasons for doing so.
10. Where your personal data may be processed
Data Protection legislation does not allow the transfer of data outside the EEA without consent or without guarantees from those countries that there is adequate data protection legislation in place.
Christ Church has students, staff, and visitors from all over the world, and every effort will be made to ensure that no personal data is transmitted to any country without relevant and adequate legislation without your consent. Data which may be transferred outside the EEA is noted on the Information Asset Registers.
11. What are your rights over your personal data?
You have the right to request, in most circumstances:
You can contact us to exercise these rights at any time by contacting the Data Protection Officer at the address below.
If you wish to make an access request for data collected by CCTV, contact the Steward of Christ Church, Ms Pauline Linières-Hartley, at pauline.linières-hartley@chch.ox.ac.uk or on 01865 286580.
If you have given consent for Christ Church to collect and process your personal data, you have the right to change your mind at any time and to withdraw that consent.
When Christ Church relies on legitimate interest to collect and process your data, you may ask for processing to be stopped. If, however, Christ Church believes it has a legitimate and over-riding reason to collect and process your personal data, we may continue to do so.
12. Contacts
The Data Protection Officer (DPO) at Christ Church is Mr James Lawrie. He can be reached at Christ Church, Oxford, OX1 1DP or at james.lawrie@chch.ox.ac.uk or on 01865 276177.
If you feel that your data has not been handled correctly, then you may lodge a complaint with the Information Commissioner’s Office on 0303 123 1113 or on their website.
13. If you live outside the UK
If you love outside the UK, then complaints can be lodged with the relevant office in your own country.
14. Any questions?
If there is anything you would like to ask about the handling of your personal data, please contact the DPO at the address above in section 12.