Festival Privacy Policy - MSF
23110
wp-singular,page-template-default,page,page-id-23110,wp-theme-stockholm,wp-child-theme-stockholm-child,sp-easy-accordion-enabled,stockholm-core-2.4.5,select-child-theme-ver-1.1.2,select-theme-ver-9.12,ajax_fade,page_not_loaded,,qode_menu_center,wpb-js-composer js-comp-ver-7.9,vc_responsive
Title Image

Festival Privacy Policy

Data Protection and Privacy Policy (GDPR)

 

The Mid Somerset Festival (MSF) collects and processes personal information in order to organise and administer the Festival and its associated activities. The Festival is committed to protecting the privacy and security of the personal information it holds and to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The Festival collects and uses personal information (referred to in the UK GDPR as personal data) about committee members, volunteers, performers, parents or guardians of performers under the age of 18, teachers, members and other individuals who come into contact with the Festival. This information is required to enable the effective administration and operation of the Festival and, where applicable, to comply with legal obligations.

The Mid Somerset Festival is the Data Controller for the personal data it processes for these purposes.

The Trustees (members of the General Council) of the Mid Somerset Festival act as the Festival’s Data Protection Officers and may be contacted through the Festival Secretary.

The Festival provides Privacy Notices (also known as Fair Processing Notices) explaining what personal information is collected, why it is collected, how it is used, who it may be shared with, how long it is retained and the rights individuals have in relation to their personal data.

Purpose

This policy explains how the Mid Somerset Festival collects, uses, stores and protects personal information in accordance with the UK GDPR, the Data Protection Act 2018 and other relevant legislation.

This policy applies to all personal information collected, processed, recorded and stored by the Festival, whether held electronically or in paper records.

What is Personal Information (Personal Data)?

Personal data is any information relating to an identified or identifiable individual. Examples of personal information that the Festival may collect include:

 

  • Emergency contact details
  • Membership information
  • Volunteer information
  • Bank details where required for payments
  • Photographs or video recordings where consent has been given or another lawful basis applies

MSF will only collect personal information necessary for the efficient administration of the Festival. We do not normally collect special category (sensitive) personal data unless there is a legitimate reason to do so, such as making reasonable adjustments for a competitor or complying with a legal obligation.

 

Data Protection Principles

MSF is committed to ensuring that personal data is:

  1. Processed lawfully, fairly and transparently.
  2. Collected for specified, explicit and legitimate purposes.
  3. Adequate, relevant and limited to what is necessary.
  4. Accurate and, where necessary, kept up to date.
  5. Kept only for as long as necessary.
  6. Processed securely using appropriate technical and organisational measures.

MSF accepts its responsibility to demonstrate compliance with these principles.

 

What Information We Collect

Personal information may be collected when individuals:

  • enter classes in the Festival;
  • become Members or Friends of the Festival;
  • volunteer as stewards or helpers;
  • contact the Festival;
  • complete surveys or provide feedback.

Only information necessary to administer the Festival will be requested.

 

How We Use Personal Information

MSF uses personal information to:

  • administer Festival entries;
  • organise classes, schedules and adjudication;
  • communicate with competitors, parents, teachers, volunteers and members;
  • administer memberships and Friends of the Festival;
  • process payments where necessary;
  • meet safeguarding, insurance and legal obligations;
  • produce Festival programmes;
  • publish Festival results;
  • maintain appropriate financial and administrative records.

Access to personal information is restricted to those trustees and authorised volunteers responsible for administering the Festival.

Lawful Basis for Processing

MSF processes personal information under one or more of the following lawful bases:

  • performance of a contract (for example, administering Festival entries);
  • legitimate interests in operating and promoting the Festival;
  • compliance with legal obligations; and
  • consent where this is required.

Where consent is relied upon, individuals have the right to withdraw that consent at any time.

Publication of Names

As part of the normal operation of the Festival:

  • competitors’ names may appear in the Festival programme;
  • class winners’ names may be published on the Festival website and in other Festival communications.

Anyone who does not wish their name to be published should notify the Festival at the time of entry, and MSF will respect that request wherever reasonably practicable.

Sharing Personal Information

MSF will not sell or disclose personal information to third parties for marketing purposes.

Personal information will only be shared where necessary to administer the Festival or where required by law. This may include:

  • trustees and authorised Festival volunteers;
  • adjudicators where appropriate;
  • payment processing providers;
  • professional advisers;
  • regulatory or legal authorities where required.

Online Entries and Payments

Where online entries are used, payment processing is carried out through a secure third-party provider.

MSF does not retain credit or debit card details.

 

 

Data Security

MSF will:

  • ensure only authorised trustees and volunteers have access to personal information;
  • store electronic records securely using password-protected systems where appropriate;
  • store paper records securely;
  • regularly review the accuracy of personal information held;
  • securely destroy information when it is no longer required;
  • take reasonable steps to protect personal information from loss, theft, unauthorised access or disclosure.

International Transfers

MSF does not routinely transfer personal information outside the United Kingdom.

Where an external service provider stores or processes data outside the UK, MSF will ensure appropriate safeguards are in place in accordance with UK GDPR.

Retention of Information

Personal information will only be retained for as long as necessary to administer the Festival, comply with legal and financial obligations, and maintain appropriate historical records.

Retention periods will be reviewed regularly, and information that is no longer required will be securely destroyed.

Individual Rights

Individuals have the right to:

  • be informed about how their personal information is used;
  • request access to their personal data;
  • request correction of inaccurate information;
  • request deletion where appropriate;
  • request restriction of processing in certain circumstances;
  • object to certain types of processing;
  • withdraw consent where consent is the lawful basis.

Requests should be made to the Festival General Secretary

Data Breaches

Any actual or suspected personal data breach must be reported immediately to the Festival Chair or General Secretary.

MSF will investigate all breaches and, where required, report them to the Information Commissioner’s Office (ICO) and affected individuals in accordance with UK GDPR.

Complaints

Complaints concerning the handling of personal information should first be directed to the Festival General Administrative Secretary.

Individuals also have the right to complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Website: www.ico.org.uk

Festival Website

The Festival website may contain links to external websites.

This policy applies only to the Mid Somerset Festival website. Users should read the privacy notices of any external websites they visit.

Responsibilities

The Trustees are responsible for ensuring that:

  • this policy is implemented and reviewed regularly;
  • only authorised volunteers have access to personal information;
  • appropriate security measures are maintained;
  • volunteers understand their responsibilities when handling personal information;
  • personal information is processed in accordance with UK GDPR.

Review

This policy will be reviewed every three years, or sooner if legislation or Festival procedures change.

Approved by: Mid Somerset Festival Trustees (General Council)

 

Review Date: July 2026

Next Review: July 2029

 

Appendix A – Data Retention Schedule

The Mid Somerset Festival will retain personal information only for as long as it is necessary to fulfil the purpose for which it was collected, to comply with legal obligations, or to protect the legitimate interests of the Festival.

Record Typical Retention Period Reason
Festival entry forms and online entry records Current Festival year plus 1 year Administration of entries, queries and future planning
Competitor results, awards and trophies Permanently Historical record of the Festival
Festival programmes Permanently Historical archive
Membership and Friends records Duration of membership plus 2 years Administration and accounting
Volunteer contact details Duration of volunteering plus 2 years Administration and insurance purposes
Financial records, invoices and Gift Aid records 7 years Charity Commission and HMRC requirements
Bank payment records 7 years Financial audit requirements
Correspondence relating to entries Up to 1 year after the Festival unless required for an ongoing matter Administration
Complaints records 3 years after resolution Good governance and legal protection
Safeguarding records (where applicable) In accordance with the Festival’s Safeguarding Policy and current safeguarding guidance Safeguarding obligations
Data protection requests and data breach records 6 years Demonstrating compliance with UK GDPR

Disposal of Information

When personal information is no longer required:

  • paper records will be shredded or otherwise securely destroyed;
  • electronic records will be permanently deleted from Festival systems where practicable;
  • any third-party providers used by the Festival will be expected to dispose of data securely in accordance with their own data protection obligations.

The Trustees will periodically review retained information to ensure records are not kept longer than necessary.

  • Trustees – overall responsibility for compliance with UK GDPR.
  • Secretary – day-to-day management of personal data, handling Subject Access Requests and acting as the main contact for data protection matters.
  • Accounts Manager– responsible for financial records containing personal data.
  • All volunteers – responsible for keeping any personal information they handle confidential and secure.