Lawful basis
Before we collect and use personal data, Sport England must be able to demonstrate that there is a lawful basis for us to do so. GDPR provides six lawful bases for processing personal data:
- Consent: when you have explicitly told us that we may collect and use your personal data – for example by asking us to add you to one of our mailing lists.
- Contract: when we need to collect and use personal data to enter into or perform a contract – for example if you receive funding from us.
- Legal obligation – when we need to collect and use personal data to carry out our legal duties – for example to respond to a request for information under the Freedom of Information Act.
- Vital interests: when we need to collect and use personal data to protect your vital interests or the vital interests of another person – for example by contacting the relevant authorities if we believe an individual is likely to come to immediate harm.
- Public task: when we need to collect and use personal data to carry out one of our official tasks, or a task that's in the public interest – for example when we carry out surveys about sports participation to create official statistics.
- Legitimate interests: when we need to collect and use personal data to pursue the legitimate interests of Sport England or a third party, unless doing so would interfere with your rights and freedoms – for example when we're dealing with complaints about an organisation we have funded.
Our lawful basis for collecting and using personal data varies depending on why we have collected it and what we'll do with it. Whenever Sport England collects personal data directly from you we aim to set out our lawful basis as clearly as we can using pop-up messages, or links to the information you need. If we receive personal data about you from a third party, we'll use reasonable efforts to identify our lawful basis and to inform you of this where it's possible and practical for us to do so.
Why we need to collect personal data
Sport England collects and uses personal data for a variety of purposes including:
- Staff selection and recruitment
- Grant application submission and assessment
- Grant monitoring and evaluation
- Research into physical activity
- Responding to correspondence from members of the public
- Managing requests to be added to a Sport England mailing list
- Complying with regulatory and financial requirements
- Promoting and encouraging participation in sport and physical activity.
When we collect personal data directly from you, we'll provide specific and detailed information about why we need to do so.
About the personal data we collect and use
Sport England collects a range of personal data including:
- Names and contact details (including postal and email addresses and telephone numbers)
- Biographical information such as participation in sport, membership of sports clubs and interest in, or opinions.
- Information about ethnicity, sexual orientation, health related data or other special category personal data where it's necessary and relevant for a specific purpose
- Photographs, including for publicity or promotional purposes.
When we collect and use personal data directly from you, we aim to provide specific and detailed information about the categories of personal data involved.
Collecting personal data about children
We do not knowingly collect personal data about children under the age of 13. If you become aware that a child has provided us with their personal data without the consent of the parent or guardian we would ask you to contact our Data Protection Officer straightaway so that we can address the matter.
How we share personal data
Relevant Sport England colleagues, suppliers and subcontractors will have access to your personal data for the purpose(s) it was collected for. When suppliers and subcontractors have access to your personal data, Sport England will still be responsible for decisions about how your personal data is used.
In some cases, where there is a lawful basis for us to do so we may share personal data with third parties such as the Department for Digital, Culture, Media and Sport, external auditors, the Information Commissioner’s Office, the Parliamentary and Health Service Ombudsman or other trusted partners, including NGBs and funded organisations. Where possible we'll tell you if your personal data will be shared, and the third parties the data be shared with, at the time we collect your personal data.
If we're required by law to disclose personal data we will do so, in keeping with our obligations.
We do not routinely transfer personal data outside to any third countries outside the European Economic Area (or ‘EEA’). However, if you've asked us to send you one of our newsletters, we use a third party to administer the mailouts. This third party is currently based in the USA.
Sport England never sells personal data to third parties for any purpose, and we do not collect or compile personal data for dissemination to third parties for marketing purposes.
How we look after your personal data
We have a number of ICT and Information Governance procedures in place which set out the technical and organisational measures we take when collecting and using personal data. If you'd like to find out more about these policies and procedures please contact our Data Protection Officer.
Personal data is held securely within Sport England’s IT environment, or in our trusted third-party hosting providers’ secure systems. Where personal data is held on third party hosting providers’ secure systems, it's stored according to our instructions and in accordance with the contracts we have in place.
How long we keep personal data
All the personal data that we collect and hold is kept in accordance with our File Retention Schedule. This Schedule is guided by the legislative and regulatory frameworks we are subject to and helps us to ensure that we do not keep personal data for longer than is necessary for the purpose(s) it was collected for.
Your rights
The GDPR gives individuals a number of rights in relation to any personal data an organisation holds about them and it is Sport England’s policy to make it as easy as possible for people to exercise these rights.
Subject access
Under GDPR all individuals are entitled to be told what personal data an organisation holds about them, and to receive copies of that information, free of charge, within one month.
You can make a subject access request to Sport England by contacting the Information Governance Manager:
dpo@sportengland.org
Rectification and erasure
If you believe that Sport England is holding inaccurate information about you, you're entitled to ask us to rectify that data. In addition, if you believe that Sport England no longer has a lawful basis to use your personal data, you can ask us to delete it.
The right to rectification and erasure is not absolute, but we will consider any requests carefully and comply with such requests where it's appropriate for us to do so. You can ask to have your personal data rectified or erased by contacting the Information Governance Manager:
dpo@sportengland.org
Withdrawing consent
If our lawful basis for collecting and using your personal data was consent, then you're entitled to withdraw that consent at any time. You do not need to give a reason for withdrawing your consent and we are required to comply promptly. You can inform us that you wish to withdraw consent by contacting the information Governance Manager:
dpo@sportengland.org
Complaints
If you're in any way dissatisfied with the way we have handled your personal data, Sport England provides a Complaints Procedure, which can be found towards the bottom of this page.
In addition, regardless of whether you make a complaint under our Procedure you're entitled to lodge a complaint about our data handling practices with the Information Commissioner by writing to:
The Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
www.ico.org.uk
Changes to our privacy statement
We keep our approach to privacy under close review, and this means we may update our privacy statement from time to time. Updates to the privacy statement are published on our website.