Swiss Railways Society (CLBG) – Data Protection Policy – v2.0
- PURPOSE
To define the Swiss Railways Society (SRS) Company Limited by Guarantee (CLBG) approach to data protection in general and, specifically, the General Data Protection Regulation (GDPR).
- LEGAL DISCLAIMER
The information and advice contained herein is based on the General Data Protection Regulation (GDPR) 2018 and is correct to the best of our knowledge. The UK Government has implemented this regulation into law as the Data Protection Act 2018.
- APPLICABILITY
All Directors, Members and Branches.
- GUIDANCE
Definitions (as specified in the Regulation)
Owner, owner of data This refers to the individual person;
Personal Data Any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier;
Data Controller The organisation collecting the information (in this case the SRS) that determines the purposes and means of processing personal data;
Data Protection Officer This role is not required by the SRS.
Legal Requirements
From 25 May 2018 the Data Protection Act 1998 was replaced by the Data Protection Act 2018 which implemented the EU General Data Protection Regulation 2018. Whilst this Regulation derives from EU legislation, the UK Government has stated that it will be carried forward as a United Kingdom National Law beyond March 2019 irrespective of ‘Brexit’.
Failure to comply with the regulation may lead to financial penalties.
Principal Requirements
All individuals who give their Personal Data to organisations have the right to determine how it should be used. Organisations collecting personal data, for whatever reason must state the reason why it is being collected and seek the individual’s permission to use it in those ways.
This legislation applies to all personal data records either paper or computer based and to all organisations irrespective of whether they are, or need to be, registered with the Information Commissioner.
Achieving Compliance
The SRS needs to follow the following steps to demonstrate compliance:
- Create a Data Protection Policy;
- Obtain Consent where required;
- Keep the data provided secure.
- Data Protection Policy
This should include the following items:
- Type of data being collected;
- How data is stored;
- Use of data, (e.g. to administer the organisation, to circulate items of interest);
- Who data is shared with outside of the organisation;
- Who data is shared with inside the organisation (e.g., membership lists);
- When data is deleted for example when a member resigns or after non-payment of membership fees, how a member chooses how their data is used;
- What the process is for ensuring any information held is up to date. The data held should be the minimum necessary for the organisation to discharge its business.
There is nothing in the Regulation which precludes data from being used purely for the administration of the organisation, e.g., sending notification of meetings, or membership renewal falling due, but see section ‘C’ below regarding e-mails.
- Obtaining consent
It is a fundamental requirement of the Regulation that the person has to give positive consent as to how their Personal Data is used. Presenting the person with a pre-ticked box for them to untick is not acceptable. They may be presented with a menu to choose from, or boxes they have to complete.
Having made their choice, it is their responsibility to vary the permissions; the organisation is under no obligation to seek permission periodically and if statements of preferences, compliant with this Regulation are already held, they may continue to be relied upon.
The SRS Permission request wording is shown in Appendix A.
- Data Security
The organisation, as Data Controller, has a general duty to ensure the security of all personal data. Whilst the SRS is the Data Controller, there needs to be a specific responsibility on one of the SRS Directors for data protection. Unless notified elsewhere, this will be the Company Secretary.
Society Membership lists
It is common practice for some societies to circulate detailed membership lists giving postal and e-mail address amongst their members. For a variety of reasons, the SRS has historically chosen to forbid such distribution. Continuing this policy will ease compliance with GDPR.
Communication by e-mail
When the organisation is sending an e-mail to more than one addressee this must be done using the ‘BCC’ address line, unless the owner has specifically consented to their e-mail address being shared with other members.
Board Members’ Consent
All Directors of SRS have given their agreement to their details being publicised, whether in SRS publications, the website, the mobile application, official SRS e-mails and on the official register at Companies House.
Disclosure of information
The organisation is required to disclose all data held on an individual should they request it.
Deletion of Information
Individuals have the ‘right to be forgotten’, i.e., the ability to request their details be deleted from wherever held. A process needs to be in place for this.
In parallel, data may only be kept for as long as it is required, whether for practical or legal reasons. As such, data deletion processes (e.g., after membership expiry) must be in place.
Accuracy of Information
All data held must be accurate (or accurate to the best of the Society’s knowledge in that a member cannot expect us to know of changes without being told!).
Contact Details on Websites
Any information put on a website such as the name and contact details of persons within the organisation requires the specific agreement of those individuals. This does not apply if only a nonspecific e-mail address is shown such as Chairman@swissrailsoc.org.uk
Storage of Information
All personal information, physical or electronic, must be held securely.
Given the sensitivity of data stored by the SRS, standard home security should be sufficient. As this may depend on other occupiers, a guide might be to keep the data as secure as your cheque book.
Use of USB ‘thumb’ drives for electronic data is not recommended due to the ease of loss.
Most mainstream Cloud storage solutions should be sufficiently secure as long as the access security has been set-up securely (which may not be the default setting of the product).
Financial Information
The SRS does not collect or process Payment Card data & bank account details, instead using third parties (e.g., PayPal) to process payments & direct debits. The SRS must not process or store Payment Card data as we would then be subject to PCI-DSS (Payment Card Information – Data Security Standard) requirements.
Should a member give us their card details for a specific transaction, the card details should be thoroughly destroyed after use including any electronic copy. However, members should be actively discouraged from giving this information.
Cheques are processed using either the traditional cheque clearing process or since April 2018 the Image Clearing Service. Cheque payments handled using the ICS method will be held until payment is cleared through our bank and then destroyed within 3 months.
Sales & e-commerce
A member or non-member may provide information (name, address, email, contact telephone number) to allow the processing of a purchase from the SRS shop. Related financial information must be destroyed once the transaction is known to be complete (e.g., fully delivered and paid for). However, any information which may be required for tax / legal purposes will be retained as required for auditing purposes and legislation.
The SRS has implemented the facility to accept online orders for its sales products (i.e., e-commerce). Use of the site is open for members and non-members. This adds further requirements around ensuring all data is kept safe. Note that it remains a requirement that payment card information is never seen or stored in a way accessible to the SRS.
Accounts – A sales record is automatically created during the checkout process holding name, address, email address, telephone number. The website will allow customers to create an account during the checkout process if they so wish, which will give them access to all sales records. A purchaser’s personal information (name, address, email address, telephone number) will be associated with each transaction once an account is created. Therefore, automatic deletion of personal details on transactions is deleted after 24 months.
The society website does not hold or store payment details, these are processed separately by 3rd parties.
App Profile – a website account holder can create or expand their personal information on the App to populate fields including a photo. Likewise a right to delete must be offered on the App to the same extent as offered elsewhere (I.e. not including some financial sales data). This is achieved by offering members an email address to send that request to. The App complies with this requirement as of 26/04/25
Transaction records – These can be pending, failed, cancelled or completed. With the exception of completed orders, automated deletion is performed after 24 months. Completed orders should be kept as long as required for auditing & tax purposes. This is likely to be until the end of the following year’s accounting period.
Where these are covered by settings on the website or App, the settings should be reviewed at the same time as this document. The most recent settings are included as Appendix B of this document.
Suppliers and trade exhibitors
Suppliers will usually provide company information which is outside GDPR. However, we should treat the contact information securely as details provided to us might include, for example, personal mobile phone numbers. However, there will be legal / tax requirements around data retention and there will be a commercial need to keep details for repeat orders.
Exhibitors
, Where non-member’s data is held, we should treat it as securely as a members’ data. Data destruction should be within three months of two years after the data was last used (which could include a request to exhibit which was not taken up).
This would include non-members providing film shows / talks to the SRS (including branches).
Branches
Whilst our branches tend to be informal, they may hold personal data related to the SRS in the form of e-mail and postal addresses. As such, SRS Branches must also follow this policy.
However, given the small amount of data, this can be kept simple. Each Branch should follow this guidance:
- Confirm that the owners of all e-mail addresses held are still in agreement with the Branch using them and if this is not received, the e-mail address should be deleted. This need only be done once;
- The ‘blind copy’ option should be used on all e-mails to multiple members;
- It should be clear to new Branch members that the provision of an e-mail address is voluntary and that it will only be used for news of Branch activities;
- Where external speakers are used, the advice for exhibitors should be followed;
- If suppliers are used, such as for room hire, then the advice for suppliers should be followed.
- Virtual Branch meetings. Members should be advised by way of joining they give permission for the Society to ‘publish’ that recording in an archive open to the general public. Likewise presenters need to give permission that their presentation copyright is their own and that publication after the meeting will occur. Lastly, as a comment we need to be wary of any presentation where a member says I don’t have permission to use these images/I took them from the internet – and then we publish the presentation in the archive, that seems to set us and the presenter up for problems if anyone gets possessive of their images being reused.
- POLICY
The Swiss Railways Society (CLBG) will comply with the requirements of the General Data Protection Regulation 2018.
- Type of data collected
The SRS will collect the following data for each member:
- Name of member;
- Postal address (requirement for distribution of Swiss Express);
- E-mail address and telephone number if provided.
- Member photo, where a member chooses to add it to the website or app profiles.
The SRS will collect the following data for each sales transaction:
- Name of purchaser (and recipient if different);
- Postal address of purchaser (and delivery address if different);
- E-mail address and contact telephone number.
The SRS will collect the following data for each Supplier, exhibitor or trade exhibitor:
- Name of contact;
- Postal address;
- E-mail address and contact telephone number.
- Bank account details (For suppliers to the Society)
- Storage of data
The data specified above is held on Computers: (both SRS owner, SRS member owned, and Cloud based)
- Use of data
The SRS uses the collected data to administer the organisation and provide services to the members.
- In addition, the e-mail addresses of the member are used to circulate notices of SRS organised events.
- Email newsletters to members who have opted in.
- Notices of events organised by SRS Branches are distributed to the member’s e-mail address.
- The SRS’s primary method of contact is by email.
Additionally, the SRS will collect data to support sales transactions, purchasing from suppliers and organising private and trade exhibitors at exhibitions.
- Sharing data outside of the SRS
The SRS does not share data outside of the SRS excepting as required for the printing and distribution of Swiss Express & operation of its services. In this case an edited list of only the data necessary for the purpose.
- Sharing data within the SRS
No membership list will be available outside the SRS Board. Certain board members & advisors may have copies of the membership list but other Board members will not usually receive copies. All Directors are required to destroy any membership lists in their possession (physically or electronically) when standing down from the Board.
- Deletion of Data
A member may cease to belong to the SRS either
(a) through non-renewal of their membership, or
(b) when a member resigns by giving notice to the Membership Secretary, or their membership is terminated under the provisions of Clause 16.1 of the Articles of Association.
The SRS will use best endeavours to ensure data is removed from all e-mail lists, and all other live personal data records held by the SRS within 3 months of one year after their resignation, ending or termination of their paid membership, whichever is the latest, excepting as may be required for tax / legal purposes. (The period of ‘one year’ is because a member’s legal liability as a member of the CLBG remains for one year after their membership ceases.)
Supplier and trade exhibitor information will be kept for as long as tax and accounting rules require or while repeat business is expected.
Non-member Exhibitor information will be deleted within 3 months of two years after last contact.
- Payment Card Information & Bank details
The SRS will not collect such Information. Instead, this will be processed by third-parties (e.g., PayPal on the SRS website) on our behalf. Members will be discouraged from sending such information to the SRS, being directed to the SRS website.
- Member’s choice of use of Data
Every member has the right to instruct the SRS on how their personal data is used. On joining, each member will be asked to agree that their information may be used as per this policy and future revisions of it.
A member may contact the Company Secretary or Membership Secretary to have their permissions changed.
- Ensuring Data Accuracy
It is the responsibility of the member to ensure that they advise the Membership Secretary promptly of any changes to the data held by the SRS.
The SRS will, as part of the membership renewal process, endeavour to check postal and e-mail addresses and telephone numbers of members against the completed Renewal Data.
- Secure Data Storage
Hard copy and electronic data must be stored securely. Given the sensitivity of data stored by the SRS, standard home security should be sufficient for physical information and electronic storage mediums (e.g., external drives) including PCs.
Where is data is held on the website or App it is using reputable industry standard, commercial software. If Cloud storage solutions are used they must be configured securely to prevent unauthorised access (this may not be the default security setting).
- Data Protection Officer
The SRS does not have a Data Protection Officer.
However, the Company Secretary is the officer who holds the responsibility for ensuring that this policy is complied with. The e-mail address is Secretary@swissrailsoc.org.uk.
The membership records are maintained by the Membership Secretary and in the first instance he should be contacted at membership@swissrailsoc.org.uk
- FURTHER INFORMATION
The following websites give further information:
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr
- PUBLICATION INFORMATION
Version 1.0 of this policy was written by Neil Wheelwright. It was approved by the Board on 21 July 2018 and issued on 22 July 2018. It was subsequently reviewed by the Board in April 2021 and July 2022.
The policy was reviewed again by Board members in a meeting on 30 April 2025. It was subsequently updated to reflect current SRS activities.
The updated version 2.0 of this policy was approved by the Board and issued on 23 May 2025
Hywel Rees, SRS Company Secretary.
APPENDIX A
Use of data consent for administering society membership.
The Swiss Railways Society (CLBG) holds information on all members which is used for the administration of your membership.
Your Name and Address are required so that we can process your membership and send you copies of our magazine, Swiss Express.
You may also give us your telephone number which would only be used to contact you in case of a query about your membership.
You may also give us your e-mail address which could be used to send details of SRS (including Branches) events, news items, etc. in support of your membership of the SRS.
You have the right to determine how personal data is used by SRS. If you have any queries about how your data is used, you wish to check or amend your records, please contact the Membership Secretary either by e-mail at membership@swissrailsoc.org.uk or by post to the current address published in Swiss Express.