Like all organisations who collect and use personal data, Sport England is subject to the requirements set out in the General Data Protection Regulation (‘GDPR’). We take our responsibility to look after personal data very seriously and we ensure that respecting privacy is at the heart of all we do. Our privacy statement explains how Sport England collects, uses and looks after personal data. Personal data is any information relating to an identified or identifiable living person. This definition of this may be found in the Data Protection Act 2018.
We have robust policies and procedures in place, including a Data Protection Policy and File Retention Schedule. We have also adopted a ‘Privacy by Design’ approach across the organisation and this helps to ensure that we consider the privacy implications of all our projects, IT systems, and day-to-day work. In addition, Sport England has an appointed a Data Protection Officer to oversee our approach to data protection and privacy. Our DPO can be contacted by emailing firstname.lastname@example.org.
The Data Protection Principles
The GDPR includes six principles that organisations must apply when they collect and use personal data. These principles are:
- Personal data must be processed in a manner which is lawful, fair and transparent. This means that when we collect and use personal information we must have a lawful basis for doing so, we must consider the rights and interests of the person the data is about, and provide clear information about our use of the data
- Personal data must be collected for specified, explicit and legitimate purposes and not used in any ways which are incompatible with those purposes. When we collect personal data we must be very clear about why we need it and what we will do with it. If we collect personal data for one purpose may not use it for an unconnected purpose.
- Personal data we collect must be adequate, relevant and limited to what is necessary for the purposes for which it is used. This means must make sure that we only collect and use personal data that is strictly necessary for our stated purpose or purposes.
- Personal data must be accurate, and where necessary, kept up to date. We are required to take all reasonable steps to ensure that the personal data held is correct and kept up to date. This means that from time to time, we will review the personal data we hold and we may contact you to make sure the personal data we have about you is current and does not contain any errors.
- Personal data must be kept in a format which allows identification for no longer than is necessary for the purposes for which it is used. In some cases, it may only necessary for us to be able to directly identify an individual for a short period of time. When we no longer need to be able to identify an individual we will anonymise the personal data. Where personal data is anonymised and the data subject in no longer identifiable that data will cease to be personal data.
- Personal data must be used in a manner that ensures appropriate security of the data. This means that our policies, procedures, systems and working practices must ensure that personal data is protected from unlawful access and is kept secure at all times.
Before we collect and use personal data, Sport England must be able to demonstrate that there is a lawful basis for us to do so. GDPR provides six lawful bases for processing personal data:
- Consent: when you have explicitly told us that we may collect and use your personal data – for example by asking us to add you to one of our mailing lists.
- Contract: when we need to collect and use personal data to enter into or perform a contract – for example if you receive funding from us.
- Legal obligation – when we need to collect and use personal data to carry out our legal duties – for example to respond to a request for information under the Freedom of Information Act.
- Vital interests: when we need to collect and use personal data to protect your vital interests or the vital interests of another person – for example by contacting the relevant authorities if we believe an individual is likely to come to immediate harm.
- Public task: when we need to collect and use personal data to carry out one of our official tasks, or a task that is in the public interest – for example when we carry out surveys about sports participation to create official statistics.
- Legitimate interests: when we need to collect and use personal data to pursue the legitimate interests of Sport England or a third party, unless doing so would interfere with your rights and freedoms – for example when we are dealing with complaints about an organisation we have funded.
Our lawful basis for collecting and using personal data varies depending on why we have collected it and what we will do with it. Whenever Sport England collects personal data directly from you we will set out our lawful basis as clearly as we can using pop-up messages, or links to the information you need. If we receive personal data about you from a third party, we will use reasonable efforts to identify our lawful basis where it is possible and practical for us to do so.
Why we need to collect personal data
Sport England collects and uses personal data for a variety of purposes including:
- Staff selection and recruitment
- Grant application submission and assessment
- Grant monitoring and evaluation
- Research into physical activity
- Responding to correspondence from members of the public
- Managing requests to be added to a Sport England mailing list
- Complying with regulatory and financial requirements
When we collect personal data directly from you, we will provide specific and detailed information about why we need to do so.
About the personal data we collect and use
Sport England collects a range of personal data including:
- Names and contact details (including postal and email addresses and telephone numbers)
- Biographical information such as participation in sport, membership of sports clubs and interest in, or opinions.
- Information about ethnicity, sexual orientation, health related data or other special category personal data where it is necessary and relevant for a specific purpose.
When we collect and use personal data directly from you, we will provide specific and detailed information about the categories of personal data involved.
Collecting personal data about children
We do not knowingly collect personal data about children under the age of 13 via our website. If you become aware that a child has provided us with their personal data without the consent of the parent or guardian we would ask you to contact our Data Protection Officer straightaway so that we can address the matter.
How we share personal data
Relevant Sport England colleagues, suppliers and subcontractors will have access to your personal data for the purpose(s) it was collected for. When suppliers and subcontractors have access to your personal data, Sport England will still be responsible for decisions about how your personal data is used.
In some cases, where there is a lawful basis for us to do so we may share personal data with third parties such as the Department for Digital Culture Media Sport, external auditors, the Information Commissioner’s Office, or the Parliamentary and Health Service Ombudsman. Where possible we will tell you if your personal data will be shared, and the third parties the data be shared with, at the time we collect your personal data.
If we are required by law to disclose personal data we will do so, in keeping with our obligations.
We do not routinely transfer personal data outside to any third countries outside the European Economic Area (or ‘EEA’). However, if you have asked us to send you one of our newsletters we use a third party to administer the mailouts. This third party is currently based in the USA.
Sport England never sells personal data to third parties for any purpose, and we do not collect or compile personal data for dissemination to third parties for marketing purposes.
How we look after your personal data
We have a number of ICT and Information Governance procedures in place which set out the technical and organisational measures we take when collecting and using personal data. If you would like to find out more about these policies and procedures please contact our Data Protection Officer.
Personal data is held securely within Sport England’s IT environment, or in our trusted third-party hosting providers’ secure systems. Where personal data is held on third party hosting providers’ secure systems it is stored according to our instructions and in accordance with the contracts we have in place.
How long we keep personal data
All the personal data that we collect and hold is kept in accordance with our File Retention Schedule. This Schedule is guided by the legislative and regulatory frameworks we are subject to and helps us to ensure that we do not keep personal data for longer than is necessary for the purpose(s) it was collected for.
The GDPR gives individuals a number of rights in relation to any personal data an organisation holds about them and it is Sport England’s policy to make it as easy as possible for people to exercise these rights.
Under GDPR all individuals are entitled to be told what personal data an organisation holds about them, and to receive copies of that information, free of charge, within one month.
You can make a subject access request to Sport England by contacting the Information Governance Manager:
Rectification and erasure
If you believe that Sport England is holding inaccurate information about you, you are entitled to ask us to rectify that data. In addition, if you believe that Sport England no longer has a lawful basis to use your personal data, you can ask us to delete it.
The right to rectification and erasure is not absolute, but we will consider any requests carefully and comply with such requests where it is appropriate for us to do so. You can ask to have your personal data rectified or erased by contacting the Information Governance Manager:
If our lawful basis for collecting and using your personal data was consent, then you are entitled to withdraw that consent at any time. You do not need to give a reason for withdrawing your consent and we are required to comply promptly. You can inform us that you wish to withdraw consent by contacting the information Governance Manager:
If you are in any way dissatisfied with the way we have handled your personal data, Sport England provides a Complaints Procedure. In addition, regardless of whether you make a complaint under our Procedure you are entitled to lodge a complaint about our data handling practices with the Information Commissioner by writing to:
The Information Commissioner’s Office
Changes to our Privacy Statement
We keep our approach to privacy under close review, and this means we may update our Privacy Statement from time to time. Updates to the Privacy Statement are published on our website.