MANCHESTER ACTIVE DATA SHARING TERMS AND CONDITIONS
GENERAL
1. These terms relate to the sharing of any Personal Data between Manchester Active and you/your organisation. Each party is legally responsible for ensuring that their use of personal data is lawful, properly controlled and upholds the rights of individuals. Evidencing these controls and safeguards (in the form of ‘who, what, where, when and how’) provides assurance that data sharing is:
- consistent with all relevant legislation, professional and industry codes
- in compliance with the principles relating to processing of personal data under Article 5 of the General Data Protection Regulation and documents the party’s respective responsibilities for compliance under GDPR Article 26
- governed by strict rules designed to protect the security and confidentiality of the personal data throughout the data sharing life cycle (privacy by default and design).
- overseen and monitored by accountable senior managers responsible for ensuring compliance and that staff are properly trained.
- respectful of individual privacy and the rights of individuals
PURPOSE
2. These terms outlines Manchester Active’s and your intentions and agreement when sharing the Specified Personal Data for the purpose of administrating the Manchester Active membership scheme. This includes:
- the purpose and legal gateway permitting the sharing
- the Specified Personal Data to be shared
- how the Specified Personal Data is to be shared
The legislative and information standards governing the sharing, security, use and retention of disclosed information, including governance controls, security and security breach notification requirements and the rights of Data Subjects
3. Each party is a separate controller responsible in Law for determining the purposes for which and the manner in which any Personal Data are or are to be processed.
4. These terms does not of itself make the sharing of Personal Data lawful. Nor does the existence of a legal gateway override the need to comply with the Common Law Duty of Confidence and other relevant Law.
5. These terms evidence how these legal requirements are to be addressed providing the parties with assurance that agreed governance controls are in place to ensure that Personal Data sharing is managed appropriately and in conformance with the Law.
PURPOSE AND LEGAL BASIS FOR DATA SHARING
6.The parties agree to only process Specified Personal Data, as described in these terms, for the following purpose(s)
- To monitor and report on funded programmes of activity
- To gain insight and intelligence on participation rates of activity across Manchester to ensure resources and funding is appropriately spent
- To analyse and provide insight for the Programme where appropriate in particular on underrepresented groups and gaps in provision
- To correspond when required with Programme Participants to aid and increase their activity levels
- To facilitate the administration of booking between users and third parties
- To ensure health and safety of participants is a robust as possible when taking part in activity
7. The purpose(s) will serve to benefit Manchester Active members by ensuring the continued provision and growth of activity opportunities across the city . The parties shall not process Shared Personal Data in any way that is incompatible with the purposes described in these terms
SPECIFIED PERSONAL DATA
8. For the purpose of these terms, the Specified Personal Data referred to that may be shared between the parties are:
| Data Type | Data Fields |
|---|---|
| Type of Personal Data |
|
| Type of Special Categories of Personal Data |
|
| Type of Personal Data relating to criminal convictions and offences or related security measures | N/A |
| Categories of Data Subject | Members of the public who have joined the Manchester Active membership scheme |
9. No more than the absolute minimum necessary Specified Personal Data will be shared observing the “need to know” principle taking account of the nature and circumstances in which the Personal Data were obtained.
LAWFULLNESS, FAIRNESS, TRANSPARENCY
10. Each party shall ensure that it processes the Specified Personal Data fairly and lawfully in accordance with clause 11
11. Each party shall ensure that it has legitimate grounds under the Data Protection Legislation for the processing of Specified Personal Data
12. At the earliest point of contact the Data Subject will receive a Privacy Notice from the party disclosing the data in accordance with Data Protection Legislation ensuring that they are informed about the information collected and recorded about them, the persons or organisations with whom it may be shared, and the purposes of the sharing.
TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
13. The Parties shall ensure that irrespective of whether Specified Personal Data is in transit or at rest, it is handled in compliance with all relevant legislation and recognised industry information security standards.
14. Appropriate technical, security and organisational measures shall be taken to safeguard against unauthorised or unlawful Processing of the Specified Personal Data and against accidental loss or destruction of, or damage to, the Specified Personal Data.
15. These measures shall cover all aspects of information governance, data handling and information security addressing organisational and technical controls such as physical security, system specific security, access privileges, staff reliability and training, including but not limited to ensuring:
- the controls deployed (including the method to be agreed for securely exchanging the Specified Personal Data) are appropriate to the harm which might result from any unauthorised or unlawful Processing, accidental loss, destruction or damage to the Specified Personal Data based on the nature and sensitivity of the Specified Personal Data;
- access to Specified Personal Data complies with the “need to know” principle
- where the Specified Personal Data is held on portable devices, appropriate encryption is deployed
- where Specified Personal Data is stored or transported in paper form physical security safeguards are in place.
- all reasonable steps are taken to establish the reliability of employees (including permanent, temporary, placements, agency staff, consultants or volunteers) authorised to access the Specified Personal Data (including appropriate vetting of prospective employees, in accordance with recognised industry practice).
- employees authorised to access Specified Personal Data have received appropriate training in the Law of data protection and information security.
- contracts and/or organisational policies and codes ensure employees understand their duty of care and confidentiality obligations, including the circumstances in which unauthorised access or inappropriate disclosure of Personal Data may give rise to:
- disciplinary measures if confidentiality is breached or Specified Personal Data information is knowingly or recklessly processed in a manner in contravention of the Law
- the commission of a criminal offence under s.170 or s171 of the DPA 2018 if accessing or obtaining Personal Data without authorisation.
- reasonable steps are taken to maintain and audit compliance with above measures
16. Where a Party engages a Processor to process the Specified Personal Data it will ensure that the Processor provides sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the requirements of the Data Protection Legislation and ensure the protection of the rights of the Data Subject.
SECURE METHOD OF TRANSFER
17. Specified Personal Data shall be transferred by a secure method to be agreed between the Parties. This agreed secure method will be documented.
DATA QUALITY AND ACCURACY
18. Each Party is responsible for the quality and accuracy of the Specified Personal Data it obtains, uses and discloses.
19. If a Party later discovers information is inaccurate, it will take reasonable steps to inform other recipients to enable the correction or updating of their records/case management systems.
OTHER USES / DISCLOSURE
20. No Specified Personal Data will be used for purposes other than those outlined in these terms or disclosed to a third party unless permitted or required by Law.
21. In no circumstances will Specified Personal Data be used/disclosed for the purpose of marketing unsolicited products and/or services.
22. The Specified Personal Data shall not be retained longer than is necessary.
23. Once no longer required for the purpose, the Specified Personal Data shall be securely disposed of in accordance with each Party’s documented retention and disposal policies.
SECURITY BREACH PROCEDURES AND NOTIFICATIONS
24. Each Party confirms it has established Incident Reporting and Management procedures consistent with the Data Protection Legislation and the Information Commissioner’s guidance for investigating and handling security breaches.
25. In the event of a breach of security or confidentiality resulting in the compromise of any Specified Personal Data, urgent remedial measures will be implemented, including notifying the Party from whom the Specified Personal Data has been obtained.
26. Where required by Data Protection Legislation, the Parties acknowledge that it may be necessary to notify Data Subjects and/or relevant regulatory bodies of the breach.
SUBJECT ACCESS RIGHTS AND COMPLAINTS
27. Under Data Protection Legislation, Data Subjects are entitled to know what information is held about them, by whom and for what purpose and, if it is not accurate to ask for it to be corrected. They can also ask for Processing to be restricted where they believe the information is inaccurate or being inappropriately processed and for automated decisions to be reviewed.
28. In the event of a request concerning any Data Subject right under Data Protection Legislation or a complaint relating to the Processing of Specified Personal Data, the receiving Party will in accordance with the Data Protection Legislation take steps to notify and consult with the Party from whom the Specified Personal Data was obtained. The Parties acknowledge that a Data Subject may exercise his or her rights under the Data Protection Legislation against either Party.
29. Each Party acknowledges their responsibility to ensure adequate resources are committed to handling data protection related requests and that these are processed within statutory time limits and/or in line with local customer services and complaint policies.
MAIN CONTACTS – RESPONSIBILITIES
30. Each Party shall ensure it has a Lead Officer who is the main point of contact for the other Party.
31. The Lead Officers will liaise on operational arrangements and in line with clause 30 will establish the method for securely exchanging Specified Personal Data
FREEDOM OF INFORMATION
32. As Manchester Active is subject to the FoIA, the parties to these terms acknowledge Manchester Active’s responsibilities in relation to handling requests for information.
33. You shall cooperate with Manchester Active in the event requests for information are received relating to these Terms.
DEFINITION AND INTERPRETATION
34. Annex 1 outlines the relevant definitions applicable to these Terms.
35. All data protection terms shall be interpreted in accordance with the meaning ascribed to them in the Data Protection Legislation.
36. Once Specified Personal Data is lawfully and securely transferred, the recipient assumes the responsibilities as Controller for ensuring that Specified Personal Data is processed in accordance with the data protection principles in the Data Protection Legislation identified in Annex 2.
COMMENCEMENT AND TERMINATION
37 These terms shall continue in force from such time as you indicate acceptance to them pursuant to our site until such time as either party gives written notice of termination to the other
ENTIRE AGREEMENT
38. These Terms, including any legal notices and disclaimers contained on this site, constitute the entire agreement between Manchester Active and you in relation to your use of this site, and supersede all prior agreements and understandings with respect to the same.
APPLICABLE LAW
39. These terms, their subject matter and their formation are governed by English law. We both agree to the exclusive jurisdiction of the courts of England and Wales.
ANNEX 1 – DEFINITIONS
| Term | Definition |
|---|---|
| Common Law Duty of Confidence | An obligation or expectation of confidence is not absolute, and information may be lawfully disclosed:
|
| Controller | means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of personal data |
| Data Protection Legislation |
|
| Data Subject | an identified or identifiable natural person who can be identified, directly or indirectly from the personal data. |
| DPA 2018 | Data Protection Act 2018. |
| FoIA | Freedom of Information Act 2000. |
| GDPR | General Data Protection Regulation (Regulation (EU) 2016/679) |
| Law | Law: means any law, subordinate legislation within the meaning of Section 21(1) of the Interpretation Act 1978, bye-law, enforceable right within the meaning of Section 2 of the European Communities Act 1972, regulation, order, regulatory policy, mandatory guidance or code of practice, judgment of a relevant court of law, or directives or requirements with which either Party is bound to comply |
| LED | Law Enforcement Directive (Directive (EU) 2016/680) |
| Personal Data | means personal data within the meaning of the Data Protection Legislation which relates to a Data Subject in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. |
| Privacy Notice | notices which are used to inform Data Subjects how their Personal Data is to be used and with whom it will be shared and why. This ensures that the Processing is undertaken lawfully, fairly and in a transparent manner. |
| Processing | means any operation or set of operations which is performed on Personal Data, by computer or any other means such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction |
| Section 45 FoIA Code | means the Code of Practice on the discharge of public authorities’ functions under Part I of the Freedom of Information Act 2000 |
| Special Categories of Personal Data | means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the Processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. |
| Specified Personal Data | means the Personal Data and Special Categories of Personal Data identified in clause |
ANNEX 2 – DATA PROTECTION PRINCIPLES
Article 5 – Principles relating to processing of personal data.
1. Personal data shall be:
(a) processed lawfully, fairly and in a transparent manner in relation to the Data Subject (‘lawfulness, fairness and transparency’).
(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’).
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e) kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the Data Subject (‘storage limitation’);
(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful Processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).

