Data Protection and Privacy Policy (GDPR)
The Mid Somerset Festival (MSF) collects and processes personal information in order to organise and administer the Festival and its associated activities. The Festival is committed to protecting the privacy and security of the personal information it holds and to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The Festival collects and uses personal information (referred to in the UK GDPR as personal data) about committee members, volunteers, performers, parents or guardians of performers under the age of 18, teachers, members and other individuals who come into contact with the Festival. This information is required to enable the effective administration and operation of the Festival and, where applicable, to comply with legal obligations.
The Mid Somerset Festival is the Data Controller for the personal data it processes for these purposes.
The Trustees (members of the General Council) of the Mid Somerset Festival act as the Festival’s Data Protection Officers and may be contacted through the Festival Secretary.
The Festival provides Privacy Notices (also known as Fair Processing Notices) explaining what personal information is collected, why it is collected, how it is used, who it may be shared with, how long it is retained and the rights individuals have in relation to their personal data.
Purpose
This policy explains how the Mid Somerset Festival collects, uses, stores and protects personal information in accordance with the UK GDPR, the Data Protection Act 2018 and other relevant legislation.
This policy applies to all personal information collected, processed, recorded and stored by the Festival, whether held electronically or in paper records.
What is Personal Information (Personal Data)?
Personal data is any information relating to an identified or identifiable individual. Examples of personal information that the Festival may collect include:
- Emergency contact details
- Membership information
- Volunteer information
- Bank details where required for payments
- Photographs or video recordings where consent has been given or another lawful basis applies
MSF will only collect personal information necessary for the efficient administration of the Festival. We do not normally collect special category (sensitive) personal data unless there is a legitimate reason to do so, such as making reasonable adjustments for a competitor or complying with a legal obligation.
Data Protection Principles
MSF is committed to ensuring that personal data is:
- Processed lawfully, fairly and transparently.
- Collected for specified, explicit and legitimate purposes.
- Adequate, relevant and limited to what is necessary.
- Accurate and, where necessary, kept up to date.
- Kept only for as long as necessary.
- Processed securely using appropriate technical and organisational measures.
MSF accepts its responsibility to demonstrate compliance with these principles.
What Information We Collect
Personal information may be collected when individuals:
- enter classes in the Festival;
- become Members or Friends of the Festival;
- volunteer as stewards or helpers;
- contact the Festival;
- complete surveys or provide feedback.
Only information necessary to administer the Festival will be requested.
How We Use Personal Information
MSF uses personal information to:
- administer Festival entries;
- organise classes, schedules and adjudication;
- communicate with competitors, parents, teachers, volunteers and members;
- administer memberships and Friends of the Festival;
- process payments where necessary;
- meet safeguarding, insurance and legal obligations;
- produce Festival programmes;
- publish Festival results;
- maintain appropriate financial and administrative records.
Access to personal information is restricted to those trustees and authorised volunteers responsible for administering the Festival.
Lawful Basis for Processing
MSF processes personal information under one or more of the following lawful bases:
- performance of a contract (for example, administering Festival entries);
- legitimate interests in operating and promoting the Festival;
- compliance with legal obligations; and
- consent where this is required.
Where consent is relied upon, individuals have the right to withdraw that consent at any time.
Publication of Names
As part of the normal operation of the Festival:
- competitors’ names may appear in the Festival programme;
- class winners’ names may be published on the Festival website and in other Festival communications.
Anyone who does not wish their name to be published should notify the Festival at the time of entry, and MSF will respect that request wherever reasonably practicable.
Sharing Personal Information
MSF will not sell or disclose personal information to third parties for marketing purposes.
Personal information will only be shared where necessary to administer the Festival or where required by law. This may include:
- trustees and authorised Festival volunteers;
- adjudicators where appropriate;
- payment processing providers;
- professional advisers;
- regulatory or legal authorities where required.
Online Entries and Payments
Where online entries are used, payment processing is carried out through a secure third-party provider.
MSF does not retain credit or debit card details.
Data Security
MSF will:
- ensure only authorised trustees and volunteers have access to personal information;
- store electronic records securely using password-protected systems where appropriate;
- store paper records securely;
- regularly review the accuracy of personal information held;
- securely destroy information when it is no longer required;
- take reasonable steps to protect personal information from loss, theft, unauthorised access or disclosure.
International Transfers
MSF does not routinely transfer personal information outside the United Kingdom.
Where an external service provider stores or processes data outside the UK, MSF will ensure appropriate safeguards are in place in accordance with UK GDPR.
Retention of Information
Personal information will only be retained for as long as necessary to administer the Festival, comply with legal and financial obligations, and maintain appropriate historical records.
Retention periods will be reviewed regularly, and information that is no longer required will be securely destroyed.
Individual Rights
Individuals have the right to:
- be informed about how their personal information is used;
- request access to their personal data;
- request correction of inaccurate information;
- request deletion where appropriate;
- request restriction of processing in certain circumstances;
- object to certain types of processing;
- withdraw consent where consent is the lawful basis.
Requests should be made to the Festival General Secretary
Data Breaches
Any actual or suspected personal data breach must be reported immediately to the Festival Chair or General Secretary.
MSF will investigate all breaches and, where required, report them to the Information Commissioner’s Office (ICO) and affected individuals in accordance with UK GDPR.
Complaints
Complaints concerning the handling of personal information should first be directed to the Festival General Administrative Secretary.
Individuals also have the right to complain to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: www.ico.org.uk
Festival Website
The Festival website may contain links to external websites.
This policy applies only to the Mid Somerset Festival website. Users should read the privacy notices of any external websites they visit.
Responsibilities
The Trustees are responsible for ensuring that:
- this policy is implemented and reviewed regularly;
- only authorised volunteers have access to personal information;
- appropriate security measures are maintained;
- volunteers understand their responsibilities when handling personal information;
- personal information is processed in accordance with UK GDPR.
Review
This policy will be reviewed every three years, or sooner if legislation or Festival procedures change.
Approved by: Mid Somerset Festival Trustees (General Council)
Review Date: July 2026
Next Review: July 2029
Appendix A – Data Retention Schedule
The Mid Somerset Festival will retain personal information only for as long as it is necessary to fulfil the purpose for which it was collected, to comply with legal obligations, or to protect the legitimate interests of the Festival.
| Record | Typical Retention Period | Reason |
| Festival entry forms and online entry records | Current Festival year plus 1 year | Administration of entries, queries and future planning |
| Competitor results, awards and trophies | Permanently | Historical record of the Festival |
| Festival programmes | Permanently | Historical archive |
| Membership and Friends records | Duration of membership plus 2 years | Administration and accounting |
| Volunteer contact details | Duration of volunteering plus 2 years | Administration and insurance purposes |
| Financial records, invoices and Gift Aid records | 7 years | Charity Commission and HMRC requirements |
| Bank payment records | 7 years | Financial audit requirements |
| Correspondence relating to entries | Up to 1 year after the Festival unless required for an ongoing matter | Administration |
| Complaints records | 3 years after resolution | Good governance and legal protection |
| Safeguarding records (where applicable) | In accordance with the Festival’s Safeguarding Policy and current safeguarding guidance | Safeguarding obligations |
| Data protection requests and data breach records | 6 years | Demonstrating compliance with UK GDPR |
Disposal of Information
When personal information is no longer required:
- paper records will be shredded or otherwise securely destroyed;
- electronic records will be permanently deleted from Festival systems where practicable;
- any third-party providers used by the Festival will be expected to dispose of data securely in accordance with their own data protection obligations.
The Trustees will periodically review retained information to ensure records are not kept longer than necessary.
- Trustees – overall responsibility for compliance with UK GDPR.
- Secretary – day-to-day management of personal data, handling Subject Access Requests and acting as the main contact for data protection matters.
- Accounts Manager– responsible for financial records containing personal data.
- All volunteers – responsible for keeping any personal information they handle confidential and secure.