This website is operated by the Sheku Bayoh Public Inquiry. We are an independent public inquiry exercising statutory functions in the public interest, established under the Inquiries Act 2005 (“2005 Act”).
We are the controller of your personal data, which means that we are legally responsible for how we hold and use your personal data.
This Policy explains how we will use your personal data that you provide to us when you use or communicate with us via our website, who it may be shared with and your rights. If you are a core participant then we will issue you with a separate privacy notice, which sets out how we handle and use your personal data and special category data for that purpose. Our privacy notices can be found on the Key Documents page of this website.
We have appointed a Data Protection Officer (“DPO”), Thornton’s Law. If you have any questions about this policy or how we hold or use your personal data, please contact the DPO by e-mail at firstname.lastname@example.org.
You can contact us by e-mail at email@example.com.
1. What personal data do we process about you?
Our website is a place for you to find out more about the Inquiry and how you can get involved in the Inquiry.
We may process personal data and special category data about you when you contact us by telephone, e-mail or letter, or report a problem with our website. This may include your name and contact details and any information about your interest in the Inquiry, if you choose to provide this to us.
2. Why do we process this personal data about you?
We use the personal data and special category data you provide to:
⦁ respond to your queries;
⦁ provide you with the information that you have requested about the Inquiry;
⦁ allow us to consider your comments, enquiries, complaints and suggestions and respond, if necessary; and
⦁ make improvements to our website in response to your feedback.
3. What is our legal basis for processing your personal data?
We rely on legitimate interest to process your personal data as outlined above. It is in our and your legitimate interest that we process your personal data to respond to your queries, provide you with information requested or otherwise deal with your comments etc. It is in our legitimate interest to process your personal data to make improvements to our website in response to your feedback, if appropriate. In considering whether we have a legitimate interest in processing your personal data, we will take into account any impact of our processing of your personal data on you and what steps we can take to minimise any such impact.
4. Who do we share your personal data with?
We may need to share your personal data with our service providers, who host and maintain our website and the systems on which your personal data is stored.
We may also be required to share your personal data with government bodies, the Police and law enforcement agencies in certain circumstances, for example, where an offence has been committed.
5. Will your personal data be sent outside the UK?
Our IT service and document management service providers may be based or may make use of data storage facilities that are located outside the United Kingdom.
Their handling and use of your personal data will involve us and / or them transferring it outside the United Kingdom. When we and / or they do this, we will ensure similar protection is afforded to it by:
only transferring it or permitting its transfer to countries that provide an adequate level of protection for personal data under data protection laws; or
using specific contracts with such organisations, which are approved for use in the United Kingdom, and which give your personal data the same protection it has in the United Kingdom after it is transferred.
Please contact our DPO for further information on the specific mechanism used by us when transferring your personal data outside the United Kingdom.
6. How long do we keep your personal data?
We will only keep your personal data for as long as we need to for the purposes described in section 2 of this Policy, including to meet any legal or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal or other requirements.
Depending on the nature of your query, we may keep your personal data until the end of the Inquiry, at which point, some of the personal data (where it is to form part of the historic record of the Inquiry) will be transferred to the Keeper of the Records of Scotland.
7. How the Inquiry keeps personal data secure
The security of your personal data is important to us and we have appropriate technical and organisational measures to safeguard your personal data. We also have procedures in place to deal with any suspected data security breach. We will notify you and the Information Commissioner’s Office (“ICO”) of a suspected data security breach where legally required to do so.
8. What rights do you have in relation to your personal data that we process?
It is important that the personal data that we process about you is accurate and current. Please keep us informed of any changes by contacting our DPO. Under certain circumstances, the law gives you the right to:
⦁ Access a copy of your personal data and to check that we are processing it in accordance with legal requirements.
⦁ Correct any inaccurate or complete any incomplete personal data that we process about you.
⦁ Delete your personal data where there are no grounds for us continuing to process it. You also have the right to ask us to do this where you object to us processing your personal data.
⦁ Restrict our processing of your personal data, for example, if you contest the accuracy of your personal data.
⦁ Object to us processing your personal data where we rely on public task or legitimate interests where we rely on public task or legitimate interests.
⦁ Request a copy in structured, commonly used and machine-readable format of any personal data you have provided to us on a consent basis and have this transferred to another organisation.
Please contact our DPO if you wish to make any of the above requests. When you make a request, we may ask you for specific information to help us confirm your identity for security reasons. You will not need to pay a fee when you make any of the above requests, but we may charge a reasonable fee or refuse to comply if your request for access is clearly unfounded or excessive.
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making
9. Third party links
10. Feedback and complaints
We welcome your feedback on how we process your personal data, and this can be sent to our DPO.
You have the right to make a complaint to the ICO, the UK regulator for data protection, about how we process your personal data. The ICO’s contact details are as follows:
Telephone: 0303 123 1113
If you would like to receive this Policy in alternative format, for example, audio, large print or braille, please contact us.
11. Updates to this Policy
We may update this Policy at any time, and you should check our website occasionally to ensure you are aware of the most recent version that will apply each time you access our website.
Last updated: September 2023