Data Protection Policy
How River of Life Church meets its duties under the Cyber and Data Protection Act: who is responsible, the rules every Leader follows, and how we handle requests, new uses of data and breaches.
Version 1.0 · Effective [date of publication]
1. Purpose and scope
This policy sets out how River of Life Church protects personal information in line with the Cyber and Data Protection Act [Chapter 12:07] ("the CDPA") and its regulations. Our Privacy Policy explains the same commitments to members.
It applies to every pastor, staff member, Leader and volunteer who handles personal information for the Church, on paper or in Faith Connect, and to our data processors.
2. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Church leadership (data controller) | Accountable for compliance; holds the POTRAZ data controller licence ([POTRAZ data controller licence number]) and approves this policy. |
| Data Protection Officer ([Data Protection Officer name]) | Monitors compliance, advises Leaders, handles data subject requests, leads breach response, is the contact for POTRAZ, and arranges training. |
| Safeguarding Lead ([Safeguarding Lead name]) | Decides when information must be shared to protect a Child or vulnerable adult. |
| Platform Operator ([platform operator name]) | Processes data only on the Church's written instructions, keeps it secure, and reports breaches to the DPO without delay. |
| Leaders and volunteers | Follow this policy and the Security Policy, and report any concern or breach to the DPO at once. |
3. Our data protection principles
Everyone handling personal information for the Church follows these principles:
- 3.1Lawful and fair. We process information only on a lawful basis, and tell people how we use it.
- 3.2Specific purpose. We collect information for clear church purposes and do not use it for unrelated ones.
- 3.3Only what we need. We collect the minimum information needed for each purpose.
- 3.4Accurate. We keep information up to date, and members can correct theirs in the app.
- 3.5Kept no longer than needed. We follow the retention periods in our Privacy Policy, and delete or anonymise information after them.
- 3.6Secure. We protect information against loss, misuse and unauthorised access, as set out in our Security Policy.
- 3.7Accountable. We keep records that show how we comply, including consents, audit logs and decisions on requests and breaches.
4. Sensitive data and Children's data
- Religious life, health and Children's information are Sensitive Data. We collect explicit consent for them, separately from the Terms & Conditions, and record when it was given or withdrawn.
- Parents and guardians give consent for their Children, including separate consents for photos, first aid, media and activities, and exercise their Children's rights under section 26 of the CDPA.
- Pastoral, welfare and safeguarding notes are restricted to authorised pastors and safeguarding leads.
- Information may be shared without consent only where the Safeguarding Lead or DPO decides it is needed to protect someone from serious harm, or where the law requires it. The decision and reason are recorded.
5. Handling data subject requests
- 5.1Receive. Requests to access, correct, delete or object may come to any Leader, and must be passed to the DPO ([DPO email]) the same day.
- 5.2Verify. The DPO confirms the person's identity, or a parent's or guardian's authority for a Child, before releasing anything.
- 5.3Respond. We respond within 30 days, free of charge, and explain any part we cannot meet and why (for example, giving records we must keep by law).
- 5.4Record. The DPO logs each request, the decision and the date of response.
6. New features and data protection impact assessments
Before Faith Connect adds a feature that uses personal information in a new way, especially Sensitive Data, Children's data or a new provider, the DPO carries out a data protection impact assessment. It records the purpose, the data used, the risks and the safeguards, and the feature goes live only once the DPO approves it.
7. Data processors and transfers
- Every provider that processes personal information for us signs a written agreement requiring it to act only on our instructions, keep the information confidential and secure, help us meet requests, and report breaches without delay.
- Our current processors are [platform operator name], Paynow Zimbabwe, Google Firebase Cloud Messaging and [email / SMS provider]. The DPO keeps this list up to date.
- Information is transferred outside Zimbabwe only where sections 28 and 29 of the CDPA are met. The DPO records the basis for each transfer.
8. Managing data breaches
- 8.1Report at once. Anyone who suspects a breach (such as a lost phone with admin access, a message sent to the wrong group, or unusual account activity) reports it to the DPO at [DPO email] immediately.
- 8.2Contain. The DPO and Platform Operator act to stop the breach, for example by revoking sessions, resetting passwords or removing access.
- 8.3Assess. The DPO assesses what information was affected, how many people, and the risk to them.
- 8.4Notify POTRAZ within 24 hours. The DPO notifies POTRAZ within 24 hours of the Church becoming aware of the breach.
- 8.5Tell the people affected within 72 hours. Where there is a high risk to them, we tell the people affected within 72 hours, with steps they can take.
- 8.6Learn. Every breach, including near misses, is recorded with what happened, the response and the changes made to prevent it happening again.
9. Training and review
- Leaders complete data protection and security training before they receive admin access, and a refresher each year.
- Leaders sign a confidentiality undertaking, and their access is removed when their role ends.
- The DPO reviews this policy at least once a year, and whenever the law or Faith Connect changes significantly.
- Breaking this policy may lead to removal of access and, where relevant, other action under the Church's procedures.