
Supporting Recovery
Across Scotland

Privacy Policy
The RCA Trust is committed to providing an efficient, effective and confidential service where service users are central to the service provision. Therefore we are fully committed to adhering to the new standards of legislation as set out by the GDPR from May 25th2018.
The 8 data protection principles which we adhere to are :
One
Personal information must be processed fairly and lawfully.
Three
Personal information must be adequate, relevant and not excessive.
Five
Personal information must not be kept for longer than is necessary.
Seven
Personal information must be secure.
Two
Personal information must be processed fairly and lawfully.
Four
Personal information must be accurate and up to date.
Six
Personal information must be processed in line with the data subjects’ rights.
Eight
Personal information must not be transferred to other countries without adequate protection.
GDPR
The GDPR builds on existing data protection laws. It gives enhanced protection for personal data and imposes stricter obligations on those who process personal data. The new obligations include:
When an individual’s personal data is collected, they must be given more information about how it will be used through enhanced privacy notices.
Transparency
Individuals will have much stronger rights to have their personal data corrected, erased and/or provided to them.
Rights
What is personal data?
Personal data is any information that relates to an identified or identifiable living person (e.g. staff member, member of the public, or customer). It generally includes their name, address, phone number, date of birth, place of birth, place of work, dietary preferences, opinions, opinions about them, whether they are members of a trade union, their political beliefs, ethnicity, religion or sexuality (as well as other information about them). Information which indirectly identifies a person will also be personal data. This would be the case where a single piece of information could not be used to identify a person but could do so in combination with other data or identifiers.
Under the new GDPR regulations the individual using the service have the following rights :
One
The right to be informed.
Three
The right of rectification
Five
The right to restrict processing
Seven
The right to object
Two
The right of access
Four
The right to erasure
Six
The right to data portability
Eight
The right not to be subject to automated decision-making including profiling.