Data Protection Policy
Version 2 — Approved by the Trustee Board on 10/09/2026. Next review: 09/09/2027.
Data Protection Principles
Personal data shall be:
Processed lawfully, fairly and in a transparent manner
- There are several grounds on which data may be collected. We are clear about our lawful basis for processing data and obtain explicit consent to hold an individual's data where appropriate.
- For CCTV and video surveillance, the museum relies on Legitimate Interests (ensuring public safety, securing historic assets, and preventing crime) rather than consent.
- We are open and honest about how and why we collect data and individuals have a right to access their data.
Collected for specified, explicit and legitimate purposes and not used for any other purpose
- We clearly define what data we collect and its intended purpose. We only collect the minimum data necessary to fulfill that purpose.
- Data collected for a specific purpose will not be used for any other purpose without a valid legal basis or the explicit consent of the data subject.
Adequate, relevant and limited to what is necessary
- We collect all data required to fulfill our operational and security objectives, and none that we do not need.
Accurate and, where necessary, kept up to date
- We maintain processes and checks to ensure data accuracy for records requiring regular updates, such as beneficiary, staff, museum volunteer, or trustee records.
- We correct any recorded mistakes promptly upon notification.
Kept for no longer than is necessary
- We define retention periods for all data types, covering both hard copy and electronic formats.
- Some data must be retained for statutory periods (e.g., financial accounting, health and safety records).
- We enforce a secure destruction process for data that has reached the end of its retention lifecycle.
Processed to ensure appropriate security, not only to protect against unlawful use, but also loss or damage
- Access Control: Data is held securely. Physical paper documents are locked away. Access to digital folders on shared drives is strictly restricted via user permissions to authorised personnel only. IT systems and sensitive files are protected by strong passwords.
- Cyber Security: Our IT systems use regularly updated anti-virus and firewall protections. Staff and volunteers are trained on cyber-attack safeguards and must not write down or share passwords.
- Resilience: Data is recoverable via automated data back-up and disaster recovery processes.
Use of CCTV & Video Surveillance
- To safeguard our visitors, personnel, and historical collections, the museum operates a closed-circuit television (CCTV) system.
- Lawful Basis: The system is operated under the legal basis of Legitimate Interests to prevent and detect crime, protect museum property, and ensure public safety.
- Signage & Transparency: Clear, highly visible signs are placed at all public entrance points informing visitors that CCTV is in operation, stating the purpose of the system, and providing contact details for the museum.
- Privacy & Placement: Cameras are strictly focused on high-risk or public areas (exhibits, entry/exit points, tills). No cameras will ever be placed in areas where individuals have a heightened expectation of privacy (e.g., restrooms). Audio recording is disabled.
- Retention: CCTV footage is automatically overwritten on a strict 30-day retention cycle, unless a specific clip is required as evidence for an ongoing security incident, insurance claim, or law enforcement investigation.
- Access to Footage: Live and recorded feeds are restricted to designated security or management personnel. A written CCTV Access Log is maintained to record every instance of footage being viewed, searched, or exported.
Individual Rights
We recognise and support individuals' rights under data protection law, which include the right to be informed, the right of access (Subject Access Requests), and the rights to rectification, erasure, restriction of processing, data portability, and objection.
- CCTV Rights: Visitors have the right to request a copy of CCTV footage featuring themselves. Before releasing any footage, the museum will use redaction or pixelation software to obscure the faces and identifying features of any third parties to protect their privacy.
Use of Imagery/Video
All imagery is protected by copyright and cannot be used without the consent of the owner, usually the person who took the image. You may also need consent from the individuals in images of individuals and small groups, which may well fall within the Data Protection Act. Particular care is to be taken when using images of children or other vulnerable people.
Here are some questions that shall be considered when using imagery:
- For what purpose was the original image taken? If it was for one purpose, such as personal use, it cannot be used for another without the consent of the individuals concerned.
- Is the image sensitive personal data? If it is, do you have the individual's consent?
- When using images of children, or people who may not be competent, do you have valid consent?
- When using images of children or other vulnerable people, are you confident your use of the image will not place them at risk? Particularly, if it is to be used publicly, such as in the Media or on the web.
- When photographing groups, have the individuals been given a chance to opt out of the photograph?
- Has the person/people in the image been told how the image will be used?
- Are you using the image according to how the person/people were told it would be used?
Data Breach
A breach is more than only losing personal data. It is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
We will investigate the circumstances of any loss or breach, to identify if any action needs to be taken. Action might include changes in procedures, where there will help to prevent a re-occurrence or disciplinary or other action, in the event of negligence.
We will notify the ICO (Information Commissioner's Office) within 72 hours, of a breach if it is likely to result in a risk to the rights and freedoms of individuals. If unaddressed such a breach is likely to have a significant detrimental effect on individuals. For example:
- Result in discrimination.
- Damage to reputation.
- Financial loss.
- Loss of confidentiality or any other significant economic or social disadvantage.
Responsibilities & Governance
- Data Controller Status: The 384th Bombardment Group Museum is the Data Controller for all personal data processed under this policy. The Board of Trustees ultimately holds overall legal responsibility for ensuring data protection compliance.
- Daily Compliance & Operations: The Board has appointed Museum Secretary Helen Childs to manage day-to-day compliance. This role includes conducting periodic policy reviews, investigating potential breaches, handling Subject Access Requests (SARs), and serving as the primary point of contact for data inquiries.
Approval and Review
| Approval By | Date | Next Review Date |
|---|---|---|
| Trustee Board | 10/09/2026 | 09/09/2027 |
Contact Us
If you have any questions about this Data Protection Policy, or wish to make a Subject Access Request, please contact us at 384bgmuseum@gmail.com.