From a937cdf65c674c6b1555e78f45b41463e7c0cc42 Mon Sep 17 00:00:00 2001 From: Imran Hussain Date: Mon, 30 Apr 2018 12:16:24 +0100 Subject: [PATCH 1/4] Add the draft Data policy with grammar corrections pointed out by ~vectre --- static/About/Data.txt | 131 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 131 insertions(+) create mode 100644 static/About/Data.txt diff --git a/static/About/Data.txt b/static/About/Data.txt new file mode 100644 index 0000000..de654d6 --- /dev/null +++ b/static/About/Data.txt @@ -0,0 +1,131 @@ +

Swansea University Computer Society Data Policy

+ +

Date: May 2018

+ +

GDPR (EU regulation 2016/679) replaces the Data Protection Directive +(EU directive 95/46/EC) on 25/05/2018. As per articles 12, 13, and 14 here is +our policy on data.

+ +

This is aimed to be the one and only place with regards to data within +Swansea University Computer Society, henceforth refereed to as SUCS. +This is written in as simple language as possible therefore may include some +informal phrasing.

+ +

Clarifications:

+ +

Interested groups:

+ +


+
+ +

+

+

Data:

+

Non-members:

+

SUCS stores data about your interactions with our systems as per +Article 6, Paragraph 1, Point F, Recital 49 of GDPR. It is not used +for purposes other than described in Recital 49.

+

Such data is exempt from Right To Be Forgotten (Article 17) +requests as per Article 17, Paragraph 3, Point E.

+

It may be shared with Swansea University ISS Networking Team and +Law Enforcement upon request.

+

No other data is stored.

+

Members:

+

SUCS stores data about all your interactions with our systems as +per Article 6, Paragraph 1, Point F, Recital 49 of GDPR. It is not +used for purposes other than described in Recital 49.

+

Such data is exempt from Right To Be Forgotten (Article 17) +requests as per Article 17, Paragraph 3, Point E.

+

It may be shared with Swansea University ISS Networking Team and +Law Enforcement upon request.

+

SUCS only starts to store other personal data until a member has +created a account on our systems.

+

Once you have created a account we hold the following personal +data that you give us:

+ +

SUCS username is used to identify and address you.

+

SUCS UID is used in reference to GDPR Recital 49.

+

Swansea University ID is used to verify membership eligibility and +linkage when interfacing with Swansea University Students’ Union +and Swansea University.

+

CCTV is used in a non-monitoring fashion, history is only accessed +by staff when there is reasonable need. CCTV may be shared with +Swansea University (Estates and Facilities – Security) and law +enforcement.

+

Other stored details are used for contact purposes. They are not +shared with any third party outside of SUCS. However, they may be +shared with law enforcement when required.

+

We do not share data with third parties, that includes the +Students’ Union unless otherwise stated.

+

Data Requests:

+

Non-members:

+

You may send data requests for your data to admin@sucs.org

+

Members: +

+

You may send data requests for your data to admin@sucs.org

+

Students’ Union Staff:

+

We do not share data directly, if you would like some data please +speak to us at admin@sucs.org

+

Swansea University Staff:

+

ISS Networking Team - You may send data requests to admin@sucs.org

+

Estates Security - You may send data requests to admin@sucs.org

+

Other – We do not share data directly.

+

Law Enforcement:

+

You may send data requests to admin@sucs.org. +If you wish to have a specific person to liaise with, please say so +in the original email.

\ No newline at end of file -- GitLab From 8d2c5a583d95fccb39aaf47fcd9496892f93be84 Mon Sep 17 00:00:00 2001 From: Imran Hussain Date: Sun, 20 May 2018 10:51:14 +0100 Subject: [PATCH 2/4] Update data policy reflecting that DPOs aren't required or need to be registered with ICO --- static/About/Data.txt | 28 +++++++++------------------- 1 file changed, 9 insertions(+), 19 deletions(-) diff --git a/static/About/Data.txt b/static/About/Data.txt index de654d6..48a6abd 100644 --- a/static/About/Data.txt +++ b/static/About/Data.txt @@ -18,32 +18,22 @@ informal phrasing.

  • Swansea University Computer Society (SUCS). SUCS is not a legal entity. We are a ‘group’ of unpaid volunteers within a - larger charity. SUCS does not have a data protection officer and is - not registered with the ICO as we fall under the Students Union, and - are their problem. However we are able to deal with data related - queries directly via the email address admin@sucs.org

    + larger charity. SUCS does not have a data protection officer. We are able to + deal with data related queries directly via the email address + admin@sucs.org

    In this document we consider “our” stuff to be any computer system or network we manage, even if we do not directly own such system or network.

  • Swansea University Students' Union (Charity number: 1149941). Is the organisation we are a part of, legally no - difference between us (SUCS) and them. They are not registered with - the ICO as of 29/04/2018.

    -

    As of 29/04/2018 https://www.swansea-union.co.uk/website/cookies/ - says -

    -

    “Unless otherwise specified on the form, no personal - information will be shared with any third party outside of Swansea - University Students' Union. In addition all personal information - collected and/or processed by Swansea University Students' Union is - held in accordance with the provisions of the Data Protection Act - 1998.

    -

    If you have any general queries, or need more information about a - particular form, please contact info@swansea-union.co.uk

    + difference between us (SUCS) and them. You may contact them via + info@swansea-union.co.uk for + any queries.

  • -

    Swansea University (Charity Number: 1138342). They are - registered with the ICO, Registration Number: Z6102454.

    +

    Swansea University (Charity Number: 1138342). You may contact them via + dataprotection@swansea.ac.uk + for any queries.

  • You, the ‘data subject’, just by reading this (it’s only available via our website) we have collected personal data on -- GitLab From e45818f2fb96f5f9fcb70e3625fdf61bc86a8e1f Mon Sep 17 00:00:00 2001 From: Imran Hussain Date: Sun, 20 May 2018 10:55:42 +0100 Subject: [PATCH 3/4] Update formatting of the file Regulations.txt --- static/About/Regulations.txt | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/static/About/Regulations.txt b/static/About/Regulations.txt index 3c770d5..542434b 100644 --- a/static/About/Regulations.txt +++ b/static/About/Regulations.txt @@ -1 +1,18 @@ -

    Below are links to the Rules and Regulations of the society:

    Conditions of Membership

    All SUCS members must adhere to the society's Terms and Conditions, which incorporate the JANET acceptable use policy governing use of the SUCS network connection.

    Room Rules

    There is an additional set of rules covering the use of the SUCS Computer Room. Please take note of the Rules of the Room if you plan to make use of this facility.

    Constitution

    The SUCS Constitution states the aims and objectives of the society, along with basic rules about how it is run.

    \ No newline at end of file +

    Below are links to the Rules and Regulations of the society:

    +

    Conditions of Membership

    +

    + All SUCS members must adhere to the society's + Terms and Conditions, which incorporate the + JANET + acceptable use policy governing use of the SUCS network connection. +

    + +

    Room Rules

    +

    + There is an additional set of rules covering the use of the + SUCS Computer Room. Please take note of the + Rules of the Room if you plan to make use of this + facility.

    Constitution

    The SUCS + Constitution states the aims and objectives of the society, along with + basic rules about how it is run. +

    \ No newline at end of file -- GitLab From 2a4789e5ed864d4cc6b3646c77f385c70f251358 Mon Sep 17 00:00:00 2001 From: Imran Hussain Date: Sun, 20 May 2018 10:59:20 +0100 Subject: [PATCH 4/4] Add a link to the data policy in the regs sections --- static/About/Regulations.txt | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/static/About/Regulations.txt b/static/About/Regulations.txt index 542434b..4ab99cd 100644 --- a/static/About/Regulations.txt +++ b/static/About/Regulations.txt @@ -1,4 +1,11 @@

    Below are links to the Rules and Regulations of the society:

    + +

    Data/Privacy Policy/Notice

    +

    + SUCS stores and processes data, details of which can be found in our + Data Policy. +

    +

    Conditions of Membership

    All SUCS members must adhere to the society's -- GitLab