The Preston Minster Parish of Saint John, Saint Matthew and Saint James Church Privacy Notice

1. Introduction

This Privacy Notice explains how we, the Parochial Church Council (PCC) of The Preston Minster Parish of Saint John, Saint Matthew and Saint James (“we”, “us”), collect, use, store, and protect your personal data. We are committed to handling your information in accordance with applicable Data Protection Law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR).

When we talk about personal data, we use the definition within Data Protection Law: “Personal data”, means any information relating to a living individual who can be identified from that data.

2. Who We Are

In data protection terms, usually there is one organisation responsible for deciding how and how personal data is used. However, in our case, the following organisations work together to deliver the ministry and mission of the Church of England in this parish, jointly deciding how and why personal data is used; an arrangement like this is called “Joint Data Controllers”:

  • The PCC of The Preston Minster Parish

  • The Incumbent (Rector) of the parish

  • The Bishop of Blackburn and the Diocese of Blackburn

  • The Blackburn Diocesan Board of Finance (DBF)

Each of these bodies has different responsibilities for carrying out the Church’s mission. Where required, we share information between us to fulfil legal, pastoral, safeguarding, and administrative functions.

A high-level description of responsibilities is as follows:

Data Controller

Responsibilities

  • PCC

  • Electoral roll, parish administration, events, volunteers, fundraising, communications, premises hire, financial and HR governance

  • Incumbent / Clergy

  • Pastoral care, services (baptisms, weddings, funerals), visitations

  • Diocese / DBF

  • Safeguarding oversight, human resources and financial support, diocesan administration

  • Contact details for the PCC are provided at the end of this notice.

 

3. What Personal Data We Collect

Data Protection Law is based on principles, and we adhere to a principle called “data minimisation”, which means we only process the data necessary to achieve the purpose. The types of personal data we process could include:

Identity & Contact Data

  • Names, titles, aliases

  • Postal address, email addresses, telephone numbers

  • Photographs (e.g., events, rotas, website images)

Demographic & Family Information

  • Date of birth

  • Marital status and family details relevant to pastoral services (e.g., weddings, baptisms and other events)

  • Children or dependant’s information in order to deliver children’s services and for safeguarding purposes

Pastoral, Ecclesiastical, and Membership Information

  • Participation in church activities

  • Electoral roll information

  • Notes related to pastoral care (kept proportionately)

Financial and Transactional Data

  • Donation records

  • Transaction records

  • Gift Aid declarations

  • Bank details (for payments you authorise)

Special Category Data

As a church, the fact you engage with us at all could reveal your religious belief, which Data Protection Law defines as special category data; deserving more protection.
Other special category personal data we may process includes:

  • Health or disability information (e.g. pastoral visits, safeguarding concerns, accessibility needs, allergens)

  • Criminal offence data (e.g. safeguarding disclosures or DBS checks)

  • Ethnicity

  • Information provided by you in the context of pastoral care

  • Information relating to sexual orientation.

We do not routinely collect information about political opinions, trade union membership, genetic data, or biometric identifiers unless required for safeguarding or legal purposes.

CCTV

We use CCTV for the security of people and property, and the prevention or detection of crime. 

4. Why We Use Your Personal Data

We process your data for the following purposes:

  • To meet legal obligations under Canon Law, charity law, safeguarding law, and the Church Representation Rules (e.g., maintaining and publishing the electoral roll)

  • To administer pastoral, ecclesiastical, and spiritual support (e.g., baptisms, funerals, weddings)

  • To deliver the Church’s mission and charitable objectives within the parish

  • To administer rotas, volunteer records, and church groups

  • To manage parish events, groups, and activities

  • To process donations and Gift Aid

  • To maintain parish accounts and financial administration

  • To manage building hire

  • To administer safeguarding concerns and investigations

  • To communicate with you about services, events, and activities (subject to PECR obligations)

  • To ensure the safety and security of people and property (CCTV)

  • To assess and process applications for roles within the parish

5. Our Legal Bases for Processing

When processing personal data, organisations need a lawful reason to process data. We rely on the following lawful bases, in accordance with the UK GDPR:

5.1 Legitimate Interests

Most internal church administration functions rely on legitimate interests pursued by the church, which are balanced to make sure your rights and freedoms aren’t overridden. Examples of processing include:

  • Running groups and volunteer rotas

  • Day-to-day parish administration

  • Pastoral care

5.2 Legal Obligations

Some of our processing of personal data is done because we have obligation under different legislation. Examples of processing includes:

  • Publishing banns of marriage

  • Maintaining the electoral roll

  • Safeguarding duties under the Children Act and statutory guidance

  • HMRC requirements (Gift Aid, financial records)

5.3 Performance of a Contract

In some cases, we may be processing personal data where a contract manages the relationship we have. Examples of processing include:

  • Managing the relationship with our staff

  • Other organisations using the church building

  • Event administration where payment is made

5.4 Consent

In very limited circumstances, we may rely on consent, but this needs to be freely given, unambiguous and specific to a clear purpose. Examples might include:

  • Email newsletters, other forms of electronic communications, fundraising communications (unless the soft opt-in applies – see Section 6)

  • Use of photographs, video or audio for promotional purposes

Whenever consent has been given, you are free to withdraw that consent at any time.

5.5 Special Category Data (Article 9 UK GDPR)

As special category personal data deserves more safeguards, we need to justify that processing in accordance with Data Protection Law. We rely on the following conditions for processing within the UK GDPR:

  • Article 9(2)(d) – processing by a not-for-profit religious organisation of members or regular contacts, including the day-to-day pastoral and spiritual care of those members and contacts

  • Article 9(2)(g) – substantial public interest, including safeguarding

Criminal offence data is processed only in accordance with Schedule 1 DPA 2018 (e.g., safeguarding, DBS checks).

6. Communications and Marketing

Keeping people up to date with everything that happens in the life of the church seems pretty normal communication, but Data Protection Law defines this as marketing. We only send electronic communications (emails, SMS, instant messaging) about the life of the church, events, or fundraising when:

  • you have given consent, or

  • you have previously supported us or expressed an interest in our work (for example by donating, attending, or signing up), the message is sent only to further the charitable purposes of the church (such as fundraising, or news about the life and mission of the church), and you were given the chance to opt out both when we first collected your details and in every message we have sent since. This is known as the “soft opt-in”.

You can opt out of these communications at any time by using the unsubscribe option in our messages or by contacting us using the details in Section 12.

7. Sharing Your Personal Data

We share your data only where necessary with:

  • Other joint data controllers (see section 2)

  • Clergy, lay ministers, and authorised volunteers

  • Third-party service providers who support parish administration (e.g., newsletter systems, IT providers)

  • Other churches involved in joint events

  • Statutory bodies (e.g., police, safeguarding authorities) where legally required

  • HMRC for Gift Aid purposes

We require all third parties to protect your information.

8. International Transfers

Where data is transferred outside the UK (e.g., cloud storage or mailing services), we make sure that international transfer is only conducted when equivalent protection as we have in the UK is provided. Examples of international transfer safeguards include:

  • UK adequacy decisions (where the UK Government has determined that another country has the same type of data protection controls as the UK)

  • UK International Data Transfer Agreements (IDTA – contracts that legally bind organisations to data protection best practice)

  • The EU Standard Contractual Clauses, used together with the UK International Data Transfer Addendum (the “UK Addendum”) issued by the ICO.

 

9. Data Retention

We only keep your personal data for as long as is reasonably necessary to fulfil the purposes for which we collected it, including to meet any legal, safeguarding, accounting or reporting requirements. We set our retention periods by reference to applicable UK law, guidance from the Information Commissioner’s Office and relevant Church of England records management guidance and best practice.

 

We review the personal data we hold on a periodic basis and securely delete or anonymise it when it is no longer required for those purposes.

If you would like more information about how long we keep particular categories of information, you can contact us using the details in Section 12.

 

10. Your Rights

You have a number of rights under data protection law. These include the right to:

  • Access your personal data and receive a copy

  • Rectification – ask us to correct inaccurate or incomplete information

  • Erasure – ask us to delete your data in certain circumstances

  • Restriction – ask us to limit how we use your data in certain circumstances

  • Object to certain types of processing (particularly where we rely on legitimate interests or send you marketing communications)

  • Data portability – in some cases, ask us to transfer your data to another organisation or to you

  • Withdraw consent where we rely on consent (this does not affect the lawfulness of processing before consent was withdrawn)

  • Complain to the Information Commissioner’s Office (ICO) if you are unhappy with how we have handled your data. We explain this more in Section 11.

We may need to verify your identity before we can respond to a request. This helps us keep your information safe.

 

11. Making a complaint

We aim to handle your personal information responsibly, but if you feel we’ve fallen short, you have the right to make a complaint with us.

Under Section 164A of the Data Protection Act 2018, you have a right to lodge a complaint directly with us if you believe your data protection rights have been infringed.

If you were to lodge a complaint with us, we will acknowledge your complaint within 30 days, investigate and keep you informed of progress, and communicate the outcome once the investigation is complete.

You can also complain to the Information Commissioner’s Office (ICO) in the UK at any time. We would encourage you to raise your concern with us first, so that we have the opportunity to put things right, but you do not have to do so before contacting the ICO.

12. Contact Details

The Data Controller – PCC of The Preston Minster Parish
Preston Minster, Church Street, Preston, PR1 3BT
Email: office@prestonminster.org

You may also contact:
Information Commissioner’s Office
www.ico.org.uk / 0303 123 1113