This Privacy Policy was last revised on: 23 June 2026.

The Industrial Workers of the World (IWW) is committed to protecting the confidentiality and integrity of your personal data and will process all data in accordance with our responsibilities under the UK General Data Protection Regulation (UK GDPR), Data Protection Act (DPA) 2018, Privacy and Electronic Communications Regulations (PECR) 2003 and all other applicable laws.

This privacy policy explains:

  • who we are,
  • the types of information we hold,
  • how we use it,
  • who we share it with,
  • and how long we keep it.
  • It also informs you of certain rights you have regarding your personal information under current data protection laws.

This policy text is meant both to inform all persons whose data we collect and process (Data Subjects), as well as guide all persons who process personal data for the IWW (Authorised Data Handlers and Data Processors).

Anyone who processes data on the IWW’s behalf must read, understand and abide by this policy and any other IWW policies relevant to data processing. IWW Authorised Data Handlers and Data Processors should pay particular attention to sections and paragraphs set in bold or marked with a symbol.

All IWW members and non-members who use IWW communications and data processing platforms must also respect this and any other IWW policy about data processing with regard to how they treat other people’s personal data. Passages in bold indicate the essential parts of the policy that concern you as a Data Subject and how we process your personal data.


Contents


Policy Summary / Privacy Notice / Privacy Statement

We are committed to keeping your data secure and to never using it in ways you would not expect.

The IWW is the Data Controller for the personal information you provide when interacting with the IWW, participating in the IWW and using its services. We use this data to improve our work as a union.

Purposes and Lawful Bases of data processing

The principal lawful basis for our collecting and processing personal data is the IWW pursuing our legitimate interests as a trade union (namely, when we collect and process personal data from membership applicants and members, or when people contact us).

Some of the information we may collect — including information that reveals trade union membership; political, religious or philosophical beliefs; sexual orientation; health information; race/ethnicity — is classified under the UK GDPR as Special Category data, which carries greater protection under data protection law.

For Special Category data, in addition to identifying the pursuit of our legitimate interests as a trade union as our lawful basis for processing (under Article 6 of the UK GDPR personal data protection legislation), we additionally rely on a separate condition under Article 9(2) of the UK GDPR that permits a not-for-profit trade union to process special category data in the course of its legitimate activities, provided appropriate safeguards are in place. This means that we do not base our processing of such data solely on consent, but we still ensure that processing is lawful, fair, necessary, proportionate and transparent.

Some personal data we process may relate to criminal convictions and offences or related security measures, including allegations, investigations, proceedings and sentencing. The Union may process criminal-offence data in prison advocacy, workplace casework, staff matters, safeguarding and legal-rights work where necessary and lawful, and that retention will depend on the purpose and sensitivity of the material. Under UK data protection law, this data is not treated as “special category data” under Article 9 UK GDPR, but is subject to a separate regime under Article 10 UK GDPR and Schedule 1 to the Data Protection Act 2018.

Where the IWW processes such data, we identify:
(a) a lawful basis under Article 6 UK GDPR; and
(b) an applicable Article 10 / Schedule 1 DPA 2018 condition before the processing begins.

Depending on the context, the IWW may rely in particular on conditions relating to: processing by a not-for-profit body with a trade union aim; employment, social security and social protection; legal claims and legal rights; safeguarding; or the data subject’s consent to a specific disclosure or activity.

We do not maintain any comprehensive register of criminal convictions. We process such data only where it is necessary, proportionate, access-restricted, and relevant to union membership administration, prisoner solidarity work, safeguarding, representation, advice, casework, complaints, grievances or legal rights. 

In certain cases of supplementary personal data collection and processing, we will do so on the basis of your informed consent (in particular, when we collect new data that is considered sensitive and specially protected under data protection laws, or specific instances where we intend to process your data for new purposes not previously listed in our Privacy and Data Protection Policy and share and process that data through third-parties not previously listed in our Privacy and Data Protection Policy, or when we actively solicit data from non-members). 

Please click here to see the full list of personal data we may collect and how we may collect it.

Please click here to see the full list of purposes for which we may collect personal data.

As a trade union, we have a statutory requirement to keep an accurate register of members’ names and addresses. If you wish to be an IWW member, you must provide this information to us.

Cookies

As with most websites, the IWW uses cookies to improve our users’ experience. Cookies may also collect personally identifiable information. Our cookies policy explains which cookies we use and why, along with where you can find more information about cookies.

Disclosure and sharing

We may disclose information about you to IWW officers, staff, administrators, organisers, accredited IWW trainers, accredited IWW worker’s representatives (‘Reps’), or any other IWW Authorised Data Handlers and Data Processors, insofar as reasonably necessary for the lawful bases and purposes as set out in our Privacy and Data Protection Policy, our Rule Book and our Manual of Policies and Practices.

All IWW Authorised Data Handlers and Data Processors must sign a Data Processor Agreement or Data Protection Undertaking with us, in which they commit to comply with our Privacy and Data Protection Policy and with applicable UK data protection laws.

The IWW will not disclose any of your personally identifiable information to any third party unless it is justified by:

  • the lawful basis of pursuing our legitimate interests as a trade union, and the data is shared as described in the full text of the IWW WISE-RA Privacy and Data Protection Policy;
  • Article 9(2) of the UK GDPR that permits a not-for-profit trade union to process special category data in the course of its legitimate activities, provided appropriate safeguards are in place;
  • applicable conditions provided by Article 10 UK GDPR and sections 10 and 11 of the Data Protection Act 2018 concerning criminal offense and judicial data, before the processing begins;
  • or it is necessary to fulfil our contractual obligations;
  • or we have your explicit consent to do so;
  • or it is necessary to protect someone’s life;
  • or we are required to do so by law.

International data transfers

We do not routinely transfer your data outside of the UK or the European Economic Area (which share the same data protection standards). However, if it is necessary, we will ensure appropriate data protection measures (as applicable under UK law) are in place.

Your rights

You have rights as a data subject. These rights include: subject access; erasure; rectification; the right to restrict or object to processing; the right to data portability; and the right to complain to the Information Commissioner’s Office (ICO).

The IWW is fully committed to upholding these rights. If you believe we have not done so, please get in touch so that we can put things right.

Where you have given consent for the IWW to process your data, you may withdraw it at any time by contacting us, as well as exercise all your data subject rights listed above.

Where we collect and process your data on the basis of pursuing our legitimate interests or legitimate activities as a trade union (pursuant to UK GDPR Articles 6, 9 and 10 including specific conditions regarding the processing of special category data and criminal offence data), namely for members, you likewise can exercise all of your rights listed above, but keep in mind that as a Trade Union, we have statutory requirements as well as other lawful bases to hold and process certain essential elements of members’ personal data, without which their membership in the IWW cannot be maintained.

Subject access requests, the provision of data portability, requests of erasure, rectification, or to restrict or object to processing of your data may be refused or partially refused by the Data Protection Officer in certain cases as provided by the relevant legislation or regulatory authorities. These grounds for refusal are outlined for each type of request on the Information Commissioner’s Office Website. Data erasure requests and subject access requests, in particular, may be refused in part or in whole if the data are relevant to, or if you are subject to, any formal internal process reasonably requiring the data to be retained or refused, such as a formal complaint or investigation, only where such retention or refusal is lawful and compatible with the relevant legislation, or if the Data Protection Officer decides the data needs to be retained for any lawful reason compatible with the present Privacy Policy or as provided by the relevant legislation or regulatory authorities. Any decision to restrict, refuse or defer a request will be documented by the DPO or a delegated decision-maker with reference to the specific legal provision relied upon. 

You can opt-out/unsubscribe from receiving emails and communications from us at any time. Opt-out/unsubscription methods will be accessibly signposted in our regular communications. However, we will retain the right to send you a minimal number of important communications for the purposes of pursuing our legitimate interests or legitimate activities as a trade union (pursuant to UK GDPR Articles 6, 9 and 10 including specific conditions regarding the processing of special category data and criminal offence data) or meeting the statutory requirements of the IWW as a trade union (namely for union ballots and communicating our Annual Returns Statement).

Data security and confidentiality

We will keep your personal data confidential and will take appropriate measures to protect it against loss, theft or misuse and to safeguard your privacy. The IWW uses industry standard efforts to safeguard the confidentiality of your personally identifiable information

Data retention policy

We retain your data only for the period necessary to enable us to fulfil the purpose(s) for which we collected it, to comply with our legal obligations and/or whilst we maintain your consent or a legitimate interest in retaining it.

Personal data about members in good standing and any personal data we hold about non-members will be retained in our Membership Database and/or organising and casework records for as long as members remain in good standing or we maintain a lawful basis and purpose to retain it according to our Privacy and Data Protection Policy and the applicable legislation.

The IWW also maintains a retention schedule for Special Category Data and Criminal Offence Data. Criminal and judicial casework data will be retained only for as long as necessary for the relevant purpose, such as membership administration, prisoner solidarity work, safeguarding, representation, complaints, grievances, legal rights, audit and defence of legal claims, after which it will be securely deleted or anonymised unless the law requires longer retention.

The standard retention period is 7 years, In the IWW WISE-RA Membership Database and/or in our organising and casework records, for personal data about lapsed, cancelled or deceased members, and for personal data about non-members, where we no longer maintain a lawful basis and purpose for retaining the data longer according to our Privacy and Data Protection Policy or applicable laws. At the end of this standard retention period, the personal data will be erased (either deleted or anonymised so that it is no longer personally identifiable), except in rare cases where we maintain a lawful basis and purpose for retaining it for longer. If you make a legitimate personal data erasure request, your personal data may be erased (deleted or anonymised) sooner than this.

By default, contents that you have emailed, posted or uploaded yourself via IWW communications services (email accounts, email lists, internal chat, forum, file repository, etc.) will remain indefinitely stored and visible to users on those platforms, even if you are no longer a member, unless you delete them yourself or explicitly request their erasure (the default, when we apply such requests, is anonymisation).

Likewise, on third-party communications (or data processing) platforms where you have given your consent to the IWW to share your personal data in order to connect/subscribe you and communicate with you (e.g., Whatsapp or Signal chat groups, Slack Channels, Loomio, etc.), contents that you post may remain indefinitely stored there unless you take action to delete them yourself or request their erasure by that third party Data Controller. You can ask us us to remove the subscription / connection / contact-data, that you had initially given us to add/subscribe you to a third-party platform, and we will comply with your request (except in rare cases where we maintain a lawful basis to delay or refrain from doing so), but we cannot, on your behalf, erase the content you posted yourself from those platforms, and it is your responsibility to do so.

Personal data requests and contacting the Data Protection Officer

If you have any questions or concerns about our Data Protection and Privacy Policy or would like to request access, deletion or restricted use of your personal data directly from the Data Protection Officer, you can send an email to the IWW Data Protection Officer (click here); members can also do this by clicking here to submit a request via the members’ website contact form (password protected site) (select the ‘Personal data requests’ category), or by post at the following address:

Data Protection Officer, IWW, PO Box 111, Minehead, TA24 9DH, United Kingdom.


Purpose, scope and general provisions of this policy

The IWW WISE-RA (Wales, Ireland, Scotland and England Regional Administration) is committed to processing personal data in accordance with its responsibilities under UK law.

Core data protection objectives

The IWW recognises that its first priority in handling personal data is to avoid causing harm to individuals. In practice, this means keeping information in the right hands, maintaining accurate and good-quality information, preventing unauthorised or unnecessary disclosure, and ensuring that personal data is used only for legitimate union purposes.

The IWW will seek to give members, service users, staff, role holders, volunteers and other data subjects as much choice and control as is possible and reasonable over what personal data is held about them and how it is used, while recognising that some processing is necessary for membership administration, trade union representation, organising, safeguarding, legal obligations, democratic governance, security, and other legitimate union functions.

All IWW bodies, officers, reps, organisers, volunteers, staff, contractors and other persons authorised to handle personal data must treat data protection as part of their union responsibilities. Anyone who keeps contact lists, accesses membership records, handles casework information, processes communications data, or otherwise handles personal data on behalf of the Union must read, understand and comply with this Policy and any applicable Data Protection Undertaking, Data Processor Agreement, access-control rule, casework procedure, or security instruction.

The purpose of this policy is to:

  • Inform IWW members and other individuals whose data we collect and process about who we are, the types of information we collect, how and for what purposes we process it, who we share it with and how long we keep it;
  • Inform the reader of certain rights they have regarding their personal information under current data protection laws;
  • comply with the law in respect of the data the IWW holds about individuals;
  • follow good practice;
  • protect all persons whose personal data is processed by the IWW from data breaches or damage resulting from non compliance with the applicable legislation;
  • protect the IWW and its Authorised Data Handlers and Data Processors from liability, damage and other negative consequences resulting from failure to handle personal data correctly, or non compliance with the applicable legislation;
  • provide a framework of principles, rules and procedures for establishing compliance with all applicable legislation;
  • guide IWW Authorised Data Handlers and Data Processors, make sure that they understand their responsibilities with regard to data processing, and ensure that they are aware of, and comply with all our policies relevant to data protection and processing, as well as all applicable legislation.

This policy applies to the Wales, Ireland, Scotland and England Regional Administration (WISE-RA) of the Industrial Workers of the World. This includes:

  • All IWW WISE-RA Data Subjects: all members of the IWW WISE-RA, including affiliated Regional Organising Committees that are part of WISE-RA but based outside the UK and Ireland, and any members of other IWW Regional Administrations belonging to the IWW International Organisation whose data the IWW WISE-RA collects and processes (namely in the Interwob Forum), as well as any non-member whose data we collect and process.
  • ⚠ All associated IWW WISE-RA branches, groups, departments, committees or other IWW WISE-RA affiliated bodies.
  • ⚠ All IWW WISE-RA Authorised Data Handlers and Data Processors: all IWW WISE-RA role holders, officers, worker’s representatives (“Reps”), organisers, trainers, phonebankers, volunteers, staff, contractors, who are Authorised Data Handlers, and all third-party Data Processors, including members or Data Processors of non-WISE-RA IWW Regional Administrations who are authorised by IWW WISE-RA as administrators or moderators of data processing platforms that process personal data for which IWW WISE-RA is the Data Controller, as well as members or personnel of any other third-party Data Processor organisation who are authorised to process personal data on the IWW WISE-RA’s behalf.

⚠ This policy applies to all personal data we process regardless of the media on which that data is stored or whether it relates to past or present Data Subjects.

In so far as it is the Data Controller of the Personal Data concerned, the IWW WISE-RA retains ultimate responsibility for any personal data it shares or grants access to.

The IWW WISE-RA shall register with the Information Commissioner’s Office as an organisation that processes personal data.

⚠ This policy and its clauses, and any breach of this policy or other IWW WISE-RA policies relevant to data processing shall be governed by the law of England and Wales.

All IWW members, non-members and service users who use IWW WISE-RA communications and data processing platforms or any of our other services must also respect this and any other IWW WISE-RA policy about data processing with regard to how they treat other people’s personal data.

Anyone who processes data on the IWW WISE-RA’s behalf will be informed of the existence of this Policy and the availability of other related policies, procedures and guidelines.

⚠ Anyone who processes data on the IWW WISE-RA’s behalf must read, understand and comply with this policy and any other IWW WISE-RA policies relevant to data processing including the Technical and Organisational Measures and the terms of relevant Data Processor Agreements. IWW WISE-RA Authorised Data Handlers and Data Processors must implement appropriate practices, processes and controls as well as attend any trainings provided to ensure such compliance. Any breach of this or related Policies may result in disciplinary action.


We adhere to the principles relating to processing of personal data set out in the applicable legislation, which require personal data to be:

  • Processed lawfully, fairly and in a transparent manner in relation to individuals (Lawfulness, Fairness and Transparency).
  • Collected only for specified, explicit and legitimate purposes and not further Processed in a manner that is incompatible with those purposes (Purpose Limitation); further Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes.
  • Adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (Data Minimisation).
  • Accurate and where necessary kept up to date (Accuracy); every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
  • Not kept in a form which permits identification of Data Subjects for longer than is necessary for the purposes for which the data is processed (Storage Limitation); personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals.
  • Processed in a manner that ensures its security using appropriate technical and organisational measures to protect against unauthorised or unlawful processing and against accidental loss, destruction or damage (Security, Integrity and Confidentiality).
  • Not transferred to another country without appropriate safeguards being in place (Transfer Limitation).
  • Made available to Data Subjects, and Data Subjects allowed to exercise certain rights in relation to their personal data (Data Subject’s Rights and Requests).

    We are responsible for and must be able to demonstrate compliance with the data protection principles listed above (Accountability).



Policy updates

This policy shall be reviewed at least annually by the IWW WISE-RA Data Protection Officer (DPO), who will update it in accordance with any changes to the applicable legislation, or as judged necessary by the DPO, or as decided by the IWW WISE-RA Delegates’ Executive Council (DEC) or Annual Conference.

The Union’s IT Committee should hold regular meetings during which it ensures that all policy and procedure, inventory and guidance documentation relating to the administration of the Union’s IT infrastructure are maintained up-to-date.

Policy compliance and system audits

It is the DPO’s responsibility to review and propose amendments to the DEC or Annual Conference of any decision/motion relevant to data protection where the DPO deems the original form of the decision/motion incompatible with the applicable legislation.

We must also regularly test our systems and processes to assess compliance.

The DPO is responsible for regularly reviewing, testing and auditing all the systems and processes under our control to ensure they comply with this Privacy and Data Protection Policy, and check that adequate governance controls and resources are in place to ensure proper use and protection of personal data.

The DPO works with the IT Committee and Communications Administrator at regular IT Committee meetings to coordinate regular systems security audits and tests, or audits of organisational-processes relating to data processing.

The DPO and IT Committee will include the results of any audit, systems-testing or compliance review in their quarterly reports to the Union’s Delegates Executive Council.

Training, handover and role induction

⚠ We are required to ensure that all Union officers, staff, Authorised Data Handlers and Data Processors undergo adequate training to enable them to comply with data privacy laws.

The Data Protection Officer, with support from the relevant Union bodies, will ensure that officers, reps, organisers, staff, volunteers, contractors and other authorised persons are introduced to this Policy when they take up roles involving personal data.

The DPO will work with the IT Committee and Training Committee to produce and regularly update a Data Protection training course for the Union’s role holders. The DPO will that that data protection training sessions will be held at least annually.

⚠ Union officers, staff, Authorised Data Handlers and Data Processors must undergo any data protection-related training that is provided and deemed mandatory by the Union’s DPO.

Data protection and confidentiality responsibilities should be included in role handovers, reps training, organiser training, officer induction, IT access onboarding, and any other relevant training or certification process. Where a rep, organiser, officer or other role holder has received equivalent training elsewhere, they must still read and comply with the IWW’s own Privacy and Data Protection Policy, Data Protection Undertaking, access-control rules, casework confidentiality requirements, and security instructions before handling personal data on behalf of the Union.



Who we are

The Wales, Ireland, Scotland and England Regional Administration of the Industrial Workers of the World (IWW WISE-RA, also referred to in this document as “the Union”) is the Data Controller of your personal data.

The IWW is a certified independent trade union registered in the United Kingdom; Certification Officer List Number 790T.

As a Data Controller we are responsible for ensuring that we use your personal data, as the Data Subject, in compliance with data protection laws, making sure that we (including any Authorised Data Handlers or Data Processor we may entrust with your data) respect all your data protection rights. As the Data Controller, we are directly answerable to you and to the Information Commissioner’s Office for how we process your data. As a Data Controller we have a set of specific responsibilities towards you, your personal data, and the regulatory authorities, that we spell out in this Privacy & Data Protection Policy.


Personal Data: any information relating to an identified or identifiable natural person (Data Subject) as defined in Data Protection Legislation. Personal Data includes Special Category Data and Pseudonymised Personal Data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour.

Special Category Data: means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for uniquely identifying a person, data concerning health, data concerning a person’s sex life, or data concerning sexual orientation, as defined by Article 9 UK GDPR.

Criminal Offence Data: means personal data relating to criminal convictions and offences or related security measures, including the alleged commission of offences and criminal proceedings, including sentencing, prison and probation status as governed by Article 10 UK GDPR and sections 10 and 11 of the Data Protection Act 2018.

References in this policy to “Sensitive Data” mean, where the context requires, Special Category Data and/or Criminal Offence Data, each of which is subject to additional legal protections.

Pseudonymisation / Pseudonymised: replacing information that directly or indirectly identifies an individual with one or more artificial identifiers or pseudonyms so that the person, to whom the data relates, cannot be identified without the use of additional information which is meant to be kept separately and secure.

Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, as defined in Data Protection Legislation.

Data Subject / Service User: a Data Subject is an identified or identifiable natural person to whom Personal Data relate, who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, as defined in Data Protection Legislation. Here we use the terms “Data Subject” or “service user” interchangeably to refer to any individual (whether an IWW member or non-member) who submits their personal data to the IWW WISE-RA in the process of using the services provided by the IWW, communicating with the IWW, conducting business with the IWW, or having services provided on their behalf by the IWW, including, but not limited to: IWW members and membership applicants; IWW Personnel, officers, role holders, staff, employees or contractors; visitors or users of the IWW WISE-RA website; visitors or users of any Information Technology system, service or platform managed by the IWW WISE-RA; and/or any persons for whom the IWW WISE-RA engages to provide services or with whom the IWW WISE-RA enters into a contract for services, support contract, service agreement or data processor agreement (whether as a provider or receiver of the agreed services).

Authorised Data Handlers/Union or IWW officer(s)/role holder(s)/staff: means IWW officers, staff, reps, caseworkers, committee members, organisers, and approved volunteers or members who are authorised to process personal data under the IWW’s direct authority and instructions. They are part of the IWW’s controlled processing arrangements and are not separate Article 28 processors merely because they handle data for the IWW. Authorised Data Handlers acting under the IWW’s authority must sign an internal Data Protection Undertaking.

External Data Processor / Data Processor: means external organisations or individuals who process personal data on behalf of the IWW under Article 28 UK GDPR. External Data Processors must be subject to an Article 28-compliant Data Processing Agreement.

Data Processing: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, as defined in Data Protection Legislation, permutations such as “processing”, “process” or “processed” shall be interpreted accordingly.

Data Processor Agreement: a legally binding, UK GDPR Article 28-compliant document to be entered into between a Data controller (the IWW WISE-RA) and an External Data Processor in writing or in electronic form, which regulates the particularities of Data Processing – such as its scope and purpose – as well as the relationship between the Data Controller and the Data Processor.

Data Protection Undertaking: an internal confidentiality, security and authorised-processing agreement signed by Authorised Data Handlers. This may be referred to internally as a ‘Data Processor Agreement’ or ‘DPA’, but it is distinct from an Article 28 Data Processing Agreement with an external processor.

Applicable Law / Applicable Legislation: unless and until no longer directly applicable in the UK, any court order, or any common law, statute, statutory instrument, order, or regulation issued by a governmental body with authority over the IWW WISE-RA, IWW WISE-RA Data Processors, and/or IWW WISE-RA members and Data Subjects from time to time in the context of their relevant rights and obligations under this Policy including the Data Protection Legislation.

Data Protection Legislation: all applicable data protection laws including, without limitation: (i) the Data Protection Act 2018 (DPA 2018), which encompasses the UK General Data Protection Regulation (UK GDPR), consisting of the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council (EU GDPR) incorporating the amendments set out in the Keeling Schedule showing changes which would be affected by the Data Protection, Privacy and Electronic Communications (amendments etc)(EU exit) Regulations 2019 made on 28 February 2019 (as amended by the Data Protection, Privacy and Electronic Communications (amendments etc)(EU exit) Regulations 2020 laid on 14 October 2020); (ii) the Privacy and Electronic Communications (EC Directive) Regulations 2003; (iii), the Regulation of Investigatory Powers Act 2000; and (iv) all other laws, directives, regulations and industry guidelines having the force of law or codes of practice issued by the office of the Information Commissioner relating to the Processing of Personal Data or privacy, and/or any amendments thereto and re-enactments thereof and all rules, regulations and orders made under such legislation.

Regulatory Authority: the Information Commissioner’s Office (ICO), and any and all regulatory authorities that have responsibility for regulating Data Processing by the Union, the Union’s Data Processors, or the Union’s Service Users from time to time.

The Data Protection Officer & other roles involved in data protection

The IWW role holder responsible for overseeing data protection and data security matters is our Data Protection Officer (DPO)

The IWW WISE-RA’s Data Protection Officer is:

Keith Millar.

If you have any questions or concerns about our Data Protection and Privacy Policy or would like to request access, deletion or restricted use of your personal data, you can contact our Data Protection Officer as follows:

DATA PROTECTION OFFICER
IWW
PO Box 111,
Minehead,
TA24 9DH


According to the IWW WISE-RA rules and policies, The role and responsibilities of the DPO is by default held by the elected Membership Officer. However, in 2020 the Membership Officer opted to appoint and deputise another IWW WISE-RA member to hold the role of DPO, and the Delegate’s Executive Council decided to deputise the role to an elected role holder starting 2023.

The DPO is the person responsible for overseeing and advising on the IWW’s compliance with this policy, all other relevant IWW WISE-RA Policies concerning data protection, security and processing, and applicable data protection laws.

Other responsibilities of the DPO are to:

  • Monitor or perform specific data protection related processes as set out in this Policy, with the administrative support of the IWW WISE-RA Communications Administrator, such as: Data Protection Impact Assessments (DPIAs); Legitimate Interest Assessments (LIAs); the processing, retention & disposal of records; keeping a Register of Systems; managing Data Processor Agreements and Data Protection Undertakings with Authorised Data Handlers or Data Processors; data breach management and reporting, Data Protection Policy enforcement, completion of individual rights requests; reviewing and approving third-party data processors and third-party data processing platforms; completing regular system compliance tests and audits.
  • Act as a point of contact with the Information Commissioner’s Officer as required.
  • Act as a point of contact in responding to questions, requests and complaints relating to data protection and data handling.
  • Develop and regularly review Union data drotection and processing policies, in close coordination with the IWW WISE-RA Communications Administrator, Communications Department, IT Committee, Membership Officer, Administration Department, Organising department and DEC.
  • Increase IWW members’ and role holders’ awareness for data protection and puts in place adequate training tools and guidance papers (in coordination with the Training Committee).
  • Manage responses to data breaches and collaborate with the Information Commissioner’s Officer in the course of investigations.
  • Oversee the data protection and security related work of the IWW WISE-RA Communications Administrator and Membership Administrator as contractors.
  • Oversee and Work closely with the Communications Administrator, IT Committee Secretary, and IT Committee volunteers in maintaining and developing the union’s IT systems in way that safeguards and enhances the security of data held by the IWW.
  • Attend meetings of the IWW WISE-RA Administrative Department.
  • Report to the IWW WISE-RA Administrative Department and Delegates Executive Council on data protection matters.

The DPO is not personally liable for data protection compliance. The IWW WISE-RA as an organisation and as the data controller, remains responsible for complying with data protection laws.

The DPO oversees and works closely especially with the Communications Administrator, who takes care of the day-to-day technical and administrative aspects of handling data, maintaining the Union’s IT systems, and implementing the IWW’s data protection and data processing policies and the DPO’s decisions. The DPO also oversees data protection related aspects of the Membership Administrator’s work of managing member records on the IWW WISE-RA membership database.

The DPO also monitors and works closely with the IT Committee Secretary and IT Committee volunteers regarding technical work they implement on the Union’s IT systems that concern data protection and security.

When to contact the Union’s DPO if you’re a Authorised Data Handlers or Data Processor.

⚠ If you are an IWW WISE-RA officer, Authorised Data Handler or Data Processor, please contact the Union’s DPO with any questions about the operation of this Privacy and Data Protection Policy or any applicable legislation, or if you have any concerns that this Policy is not being or has not been followed. In particular, you must always contact the Union’s DPO in the following circumstances:

  • if you intend to collect or process personal data in any way, whether through IWW WISE-RA controlled platforms or non-IWW WISE-RA platforms (e.g., surveys) (see further details on collecting data here, here, and here);
  • If you intend to collect and process it in any way that implies sharing it with third parties (e.g., using any third-party online app or service not operated by the IWW)(see further details on sharing data here and here);
  • if you are unsure of the lawful basis which you are relying on to collect and process personal data (including the legitimate interests, UK GDPR Article 9 provisions, or consent bases used by the Union)(further details here);
  • if you need to rely on consent and/or need to capture explicit consent (further details here, and here);
  • if you need to draft Privacy Notices or Fair Processing Notices;
  • if you are unsure about the retention period for the personal data being processed;
  • if you are unsure about what security or other measures you need to implement to protect personal data;
  • if there has been a personal data breach, or you think this policy has not been complied with in any way;
  • if you are unsure on what basis to transfer personal data outside the UK;
  • if you need any assistance dealing with any rights invoked by a Data Subject (further details here, and here);
  • whenever you are engaging in a significant new, or a change in, processing activity which is likely to require a Data Protection Impact Assessment, or plan to use personal data for purposes other than what it was originally collected for;
  • If you plan to undertake any activities involving automated processing including profiling or automated decision-making;
  • If you need help complying with applicable law when carrying out direct marketing activities (e.g., non-members via mailings to promote the union); or
  • if you need help with any contracts, Data Protection Undertakings, Data Processor Agreements or other areas in relation to sharing personal data with third parties.

Your personal data rights and how to Update and access your information

The IWW will respect data subject rights in accordance with UK GDPR: 

  • You have the right to access the personal data we have kept on record about you.
  • You also have the right to correct the personal data we hold on you or change how we process your data or contact you.
  • You are entitled to restrict the data we use about you, and how we use it.
  • You can also ask us to erase all the personal data we hold about you.
  • Where you have given consent for the IWW to process your data, you may withdraw it at any time by contacting us, as well as exercise all your data subject rights listed above.
  • You have the right to object to any aspect of processing, in part or in ful, which applies in particular to processing based on legitimate interests or public task, subject to the applicable legal tests. The existence of an Article 9 or Article 10 condition does not itself create a separate freestanding right to object.

Where we collect and process your data on the basis of pursuing our legitimate interests or legitimate activities as a trade union (pursuant to UK GDPR Articles 6, 9 and 10, including specific conditions regarding the processing of special category data and criminal offense data), namely for members, you can exercise all of your rights listed above, but keep in mind that as a Trade Union, we have statutory requirements as well as other lawful bases to hold and process certain essential elements of members’ personal data, without which their membership in the IWW cannot be maintained.

Likewise, where we collect and process personal data on the basis of fulfilling our contractual obligations, continued validity of the contract may be contingent upon the continued retention and processing of certain essential elements of personal data.

Where the IWW receives personal data from a source other than the data subject, it will provide the information required by Article 14 UK GDPR unless an Article 14 exception or a valid statutory exemption applies.

You can opt-out/unsubscribe from receiving emails and communications from us at any time. Opt-out/unsubscription methods will be accessibly signposted in our regular communications. However, we will retain the right to send you a minimal number of critical communications for the purposes of pursuing the legitimate interests or meeting the statutory requirements of the IWW as a trade union (namely for union ballots and communicating our Annual Returns Statement).

IWW members can view, modify and download their membership data record as well as their Wobchat, InterWob Forum, IWW Owncloud file repository and IWW Email account data directly by visiting the ‘My Membership’ page of the IWW Members’ Area website (access to this area is restricted to members only and requires a password).

Members can also change the amount they are paying for their monthly dues by direct debit by visiting the ‘Change your direct debit’ page of the Members’ Area website, or they can cancel their direct debit by visiting the ‘Cancel your direct debit’ page (members can also cancel direct debit payments directly with their bank or via internet banking). (Access to the Members’ Area website is restricted to members only and requires a password).

You can also contact our Data Protection Officer to view or modify the data we have about you, or make any requests, enquiries, objections or complaints with regard to your personal data, how we process it, and your rights under data protection legislation. Links and methods for contacting the Data Protection officer are provided in the section of this policy just above, titled ‘who we are’ (click here).

Subject access requests, the provision of data portability, or requests of erasure, rectification, or to restrict or object to processing of your data may be refused or partially refused by the Data Protection Officer in certain cases as provided by the relevant legislation or regulatory authorities. These grounds for refusal are outlined for each type of request on the Information Commissioner’s Office Website. Data erasure requests and subject access requests, in particular, may be refused in part or in whole if the data are relevant to, or if you are subject to, any formal internal process reasonably requiring the data to be retained or refused, such as a formal complaint or investigation, only where such retention or refusal is lawful and compatible with the relevant legislation, or if the Data Protection Officer decides the data needs to be retained for any lawful reason compatible with the present Privacy Policy or as provided by the relevant legislation or regulatory authorities. Any decision to restrict, refuse or defer a request will be documented by the DPO or a delegated decision-maker with reference to the specific legal provision relied upon. 

You have the right to complain to the Information Commissioner’s Office if you think the IWW has breached your Data Protection and Privacy rights.


The IWW WISE-RA will ensure that we respect and fulfil the rights given to Data Subjects under the applicable legislation, regarding how we handle their personal data. These include rights to:

  • withdraw consent to processing at any time;
  • receive certain information about our processing activities as the Data Controller;
  • request access to their personal data that we hold;
  • prevent our use of their personal data for direct marketing purposes;
  • ask us to erase personal data if it is no longer necessary in relation to the purposes for which it was collected or processed or to rectify inaccurate data or to complete incomplete data;
  • restrict processing in specific circumstances;
  • challenge processing which has been justified on the basis of our legitimate interests, UK GDPR Article 9 provisions regarding the processing of special category data, or in the public interest;
  • request a copy of an agreement under which personal data is transferred outside of the EEA;
  • object to decisions based solely on automated processing, including profiling;
  • prevent processing that is likely to cause damage or distress to the Data Subject or anyone else;
  • be notified of a personal data breach which is likely to result in high risk to their rights and freedoms;
  • make a complaint to the ICO; and
  • in limited circumstances, receive or ask for their personal data to be transferred to a third party in a structured, commonly used and machine-readable format;


the Union and its Authorised Data Handlers or Data Processors will fulfil Data Subjects’ legitimate requests / Subject Access Requests (SARs) In compliance with the applicable legislation.

In the first instance, after receiving a Data Subject’s request or SAR, the Union’s Authorised Data Handlers or Data Processors should refrain from immediately responding. Only the DPO is authorised to make decisions concerning such requests. Prior to taking any action regarding the Data Subject’s request or SAR, Authorised Data Handlers or Data Processors must immediately forward any request they receive to the Union’s DPO and comply with the DPO’s instructions regarding the request/SAR response process. in most cases, the response process will be implemented by the Communications Administrator under direct instructions from the DPO.

The Union’s DPO must verify the identity of an individual requesting data under any of the rights listed in this section (Authorised Data Handlers or Data Processors must not allow third parties to persuade them into disclosing personal data without proper authorisation).

Subject access requests, the provision of data portability, or requests of erasure, rectification, or to restrict or object to processing of your data may be refused or partially refused by the Data Protection Officer in certain cases as provided by the relevant legislation or regulatory authorities. These grounds for refusal are outlined for each type of request on the Information Commissioner’s Office Website. Data erasure requests and subject access requests, in particular, may be refused in part or in whole if the data are relevant to, or if you are subject to, any formal internal process reasonably requiring the data to be retained or refused, such as a formal complaint or investigation, only where such retention or refusal is lawful and compatible with the relevant legislation, or if the Data Protection Officer decides the data needs to be retained for any lawful reason compatible with the present Privacy Policy or as provided by the relevant legislation or regulatory authorities. Any decision to restrict, refuse or defer a request will be documented by the DPO or a delegated decision-maker with reference to the specific legal provision relied upon.

Data Subjects shall have the right to obtain from the Union, as the Data Controller, confirmation as to whether or not personal data concerning them is being processed, and, where that is the case, obtain access to their personal data.

Information on how to access one’s personal data should be detailed in the Union’s relevant Privacy Notice or Data Protection Policy.

Data Subjects shall have the right to require the Union, without undue delay, to rectify any inaccurate or incomplete personal data concerning them.

Except where the data is held for purposes of legal obligation, Data Subjects shall have the right to require the Union, without undue delay, to erase any personal data concerning them. As a Trade Union, the IWW must meet statutory requirements to retain certain types of data on members, without which continued membership in the Union is not possible.

Where there is a dispute between the Data Subject and the Union about the accuracy, validity or legality of data held by the Union, the Data Subject shall have the right to require the Union to cease processing the data for a reasonable period of time to allow the dispute to be resolved.

Where data is held for purposes of consent or contract the Data Subject shall have the right to require the Union to provide them with a copy, in a structured, commonly used and machine-readable format, of the data which they have provided to the Union, and have the right to transmit that data to another Data Controller without hindrance.

the Union shall ensure that the IT platforms it provides will enable the provision of copies of personal data in commonly used and machine-readable file formats for the purposes outlined in the previous paragraph.

Data Subjects shall have the right to object, on grounds relating to their particular situation, at any time, to processing of personal data concerning them which is based on Legitimate Interest, including profiling based on those provisions. the Union shall no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

Where personal data is Processed for direct marketing purposes, the Data Subject shall have the right to object at any time to processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing

Where the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

At the latest at the time of the first communication with the Data Subject, the right referred to in the preceding two paragraphs shall be explicitly brought to the attention of the Data Subject and shall be presented clearly and separately from any other information.

Except where it is: a) based on the Data Subject ‘s explicit consent, or b) necessary for entering into, or performance of, a contract between the Data Subject and a Data Controller; the Data Subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Where the Union acts as the Data Processor for a third party Data Controller of the personal data concerned by the Data Subject’s request, the Union’s DPO will immediately notify the Data Controller and act in compliance with the Data Controller’s instructions.



Personal data we may collect and the purposes for which we process it

The IWW collects and processes personal data on members, and occasionally non-members, for the purposes of administering itself as an organisation and organising as a union.

‘Personal data’, or ‘personal information’, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

The personal data we collect, via our websites or via any other online or offline method, will only be used for the stated purposes (or closely related purposes) for which it was collected and according to the principles laid out in this Policy.


We may collect your personal information in the following ways:

  • Via website cookies, analytics tools, site logs, server logs, or other similar methods (see ‘Cookies’ section below).
  • Via our online or paper membership application forms.
  • Via online contact forms for submitting queries.
  • Via postal, email, SMS, mobile/online instant messaging, phone communications, or any other forms of communication you have with IWW role holders.
  • Via online or offline survey forms, questionnaire forms, email contact submission forms, casework consent forms, crowdsourcing or crowdfunding campaign forms, or petitions.
  • Via meetings or training sessions we may have with you, whether face to face or via video/voice teleconference.
  • Via any form of communication and documentation relating to payment processing for sending or receiving payments (for example, invoices, online payment forms, or phone calls where we collect payment details or bank account information), and via any online or offline payment platforms or payment methods, including third-party financial institutions such as banks and payment processors.
  • If you are an IWW staff member or contractor, or if you work for us in any other capacity, we may collect and process your relevant personal information as part of the normal purposes of administering your work for us.
  • When you log into and use the functionalities of the online platforms that we maintain for our members and role holders, and when you view, search, alter, post, send, save, or upload content containing personal or personally identifying information on/via those platforms. This includes usage logs, analytics data, or any messages or content that you post, upload, send or edit on/via:
    • The IWW.org.uk website and WordPress administration/editing platform for the website;
    • our online Members’ Area;
    • our chat.iww.org.uk Wobchat platform;
    • our forum.iww.org.uk Interwob forum platform;
    • our email accounts, webmail client site, email server, and email server management system;
    • our mailing lists;
    • our cloud.iww.org.uk cloud file storage platform;
    • our CiviCRM membership database site (and the Drupal Content management System used for the database user interface) and any online forms or data input sites linked to the database;
    • Our Matomo analytics system;
    • Any other online tool or platform we may use for our activites.
  • When you purchase items from our online shop.
  • From other unions or organisations with which we share formal organisational or collaborative ties with around the world, for example: if we have membership transferral agreements; or so that we can administer shared communications platforms (e.g., the Interwob forum). This will always be done in a manner that respects your data rights and privacy, and complies with UK and EU Data Protection laws as well as the data protection laws and standards of your organisation and country, if you reside outside the UK or EU.
  • From other potential third-party sources such as:
    • Your current or past employer (as part of the recruitment process for persons who work for the IWW or may potentially work for the IWW as staff, contractors or service providers; or in the case of our union members, only if and when the IWW supports you with casework or represents you to defend your rights and interests as a worker; we will never share your status as an IWW member with your employer or any third party without your prior consent unless that third-party is authorised by the IWW as a third-party data processor and bound by a Data Processor Agreement with the IWW).
    • Your current or past clients, other people you do business with, or your agent or representative, if you are a contractor or service provider we are looking to work with.
    • Public authorities, only if and when we must deal with public authorities to fulfil legal obligations.
    • Publicly available sources, only if strictly required to meet our legitimate interests as a trade union, or to fulfil our legal or contractual obligations. 

We may collect and process information about the following categories of persons or organisations: 

  • Visitors to our websites and users of our online platforms
  • IWW members and membership applicants
  • Current or prospective IWW staff members, employees, contractors, service providers, advisers, consultants, or other persons working for the IWW.
  • Employers of IWW members. (We will never inform your employer about your IWW membership, or interest in the IWW, or interactions with the IWW (including of non-members), without your prior agreement or consent.)
  • Enquirers and complainants.

We may collect and process personal information in the following broad contexts:

  • Membership administration: As part of the membership application process and as part of administering union membership. We will refer to this context with the shorthand notation: “Membership“. Where we make it optional for members to provide the data in this context, we denote it with the additional shorthand notation: “[optional]“.
  • Communications: in contexts where persons may willingly provide those categories of personal data to us by communicating with us, or by using or posting or sending information via our online platforms. This includes responses to surveys or petitions, customers buying items from our online shop, and members using our members-only online spaces/platforms. We will refer to this context with the shorthand notation: “Communications“. Not all the categories of personal data listed in the next sub-section as collected in the “Communications” context are necessarily always collected in that context.
  • Union organising and representation: In contexts where the IWW provides organising support, advice and/or representation to our union members in individual or collective cases or campaigns regarding work issues. In particular, it is often necessary to collect detailed personal data for the casework involved in accompanying, representing and defending individual workers (e.g., at meetings with employers, supporting members’ workplace grievances, supporting members facing disciplinary processes). We will refer to this organising and representation context with the shorthand notation: “Representation“. Not all the categories of personal data listed in the next sub-section as collected in the “Representation” context are necessarily always collected in that context.
  • Staff administration: in the context of managing persons who work for the union as elected officers, role holders, accredited workers’ representatives, or as paid personel, including contractors and third-party service providers or data processors. We will refer to this context with the shorthand notation: “Staff“. Not all the categories of personal data listed in the next sub-section as collected in the “Staff” context are necessarily always collected in that context.

We may collect the following categories of personal information, in the following contexts:

  • IP addresses of visitors and users on our online platforms. We may also retain server logs that include the IP address of every request to our servers. (Communications).
  • Information about users’/visitors’ use of IWW information and communications systems and online platforms, including but not limited to: cookies, usage logs, analytics logs, and any messages and other content and media that users post, upload, send or edit via IWW communications systems, websites or online platforms. (Communications).
  • The contents of any personal information that is provided to the IWW and/or Processed via IWW digital information and communications systems (via joining forms, correspondence, email, messaging, voice calls, teleconferencing, meetings, training sessions, online chat or forum posts, online file sharing, information or queries or complaints submitted via online contact forms, surveys, questionnaires, petitions, payment processing). (Communications).
  • Personal contact details for example: name, addresses (postal/residential address and country of residence), telephone numbers, and personal or work email addresses. (Membership; Communications; Representation; Staff).
  • Date of birth, age. (Communications; Representation; Staff).
  • Gender. (Membership [optional]; Communications; Representation; Staff).
  • Contact details of next of kin, guardian, carer, lawyer, representative or emergency contacts. (Communications; Representation; Staff).
  • IWW Membership details, including membership number, type of membership, membership commencement and end dates, union sections. (Membership; Communications; Representation; Staff).
  • Membership in other unions, including type of membership, membership commencement and end dates, name of union and union sections. (Membership [optional]; Communications; Representation; Staff).
  • Bank account, debit/credit card, or other details about means of payment. (Membership [optional]; Communications; Staff).
  • Information about general income bracket after tax. (Membership; Communications, Representation, Staff).
  • Information about income, salary or payments for services, payroll/invoice records, tax status information, annual leave, pension and benefits information. (Communications; Representation; Staff).
  • Compensation history. (Communications; Representation; Staff).
  • Information about attendance at IWW meetings, trainings, seminars, webinars, conferences, etc. (Membership; Communications; Staff).
  • IWW or other unions’ training certifications. (Membership; Communications; Representation; Staff).
  • Employment/work status; employer; job title; employer’s names and addresses (Membership; Communications; Representation; Staff).
  • Work contract type and terms. (Membership [optional]; Communications; Representation; Staff).
  • Start and end date of employment/work. (Communications; Representation; Staff).
  • Location of employment or workplace. (Membership [optional]; Communications; Representation; Staff).
  • Recruitment information (including copies of right to work documentation, references and other information included in a CV or cover letter). (Communications; Representation; Staff).
  • Immigration status. (Communications; Representation; Staff).
  • Copies of or data from identity documents, driving licence, passport, birth and marriage certificates. (Communications; Representation; Staff).
  • Work performance and appraisal information. (Communications; Representation; Staff).
  • Workplace disciplinary and grievance information. (Communications; Representation; Staff).
  • Secondary employment and volunteering information. (Membership [optional]; Communications; Representation; Staff).
  • Skills and qualifications. (Membership [optional]; Communications; Representation; Staff).
  • Family, lifestyle and social circumstances. (Communications; Representation).
  • Goods and services provided. (Communications, Representation, Staff).

Incidental personal data about non-members and third parties

In carrying out its functions as a trade union, the IWW may occasionally hold personal data about non-members or third parties. This may include workplace colleagues, employers, managers, witnesses, journalists, public officials, family members, emergency contacts, supporters, representatives, or other persons whose details arise incidentally in organising, representation, casework, campaigning, complaints, safeguarding, correspondence, or administration.

Where such information is held, it must be processed only where necessary and proportionate for the relevant union purpose, handled in accordance with this Policy, and not used for unrelated purposes. In casework and representation contexts, information about third parties should normally be limited to what is relevant to the member’s case, the Union’s legitimate functions, legal rights, safeguarding obligations, or other lawful purpose identified for the processing.

We may also collect the following categories of more sensitive personal information, in the following contexts (cf. definition for ‘Special Category data’ by clicking here, then clicking collapsed section on definitions of key terms):

  • Information about your race or ethnicity, religious beliefs, sexual orientation and political opinions. (Communications; Representation; Staff).
  • Trade union membership, including membership and roles in other trade unions than the IWW. (Membership [giving information about membership in other trade unions is optional]; Communications; Representation; Staff).
  • Information about your health, including any medical condition, health and sickness records, disability or accessibility requirements, accident book, first aid records, injury at work and third-party accident information. (Membership [information about disability status or accessibility requirements is requested but optional]; Communications; Representation; Staff).
  • information about criminal convictions and offences or related security measures, including allegations, investigations, proceedings and sentencing. (Membership [only in the context of Incarcerated members of our Prisoner Solidarity Network]; Communications; Representation; Staff).

We may use the personal data we collect for the following purposes:

  • To administer our websites and online platforms.
  • To enable your use of the services available on the IWW websites and online platforms.
  • To enable the functionalities available on our websites and online platforms.
  • To improve your browsing experience.
  • To prevent or detect any abuse of our websites and data processing systems and ensure data security.
  • To enable us or third parties to carry out technical or other functions on our behalf to improve our data processing systems.
  • To deal with enquiries and complaints made by you.
  • To process membership applications and membership data/records.
  • To provide IWW members with information and updates about the IWW’s activities, campaigns, and services.
  • To conduct our organising activities and campaigns as a union.
  • To conduct union elections and ballots.
  • to administer IWW branches, departments, committees and other IWW bodies.
  • To provide support, advice and/or representation in an individual or collective case regarding work issues (e.g., meetings with employers, supporting our members’ workplace grievances, supporting members facing disciplinary processes at work).
  • To perform the Union’s administrative work, and to administer our role holders and staff, including third party contractors or service providers.
  • To fulfil our contractual obligations with our members and users of our services.
  • To fulfil our contractual agreements with our staff, contractors or with third party service providers, data processors, or other organisations.
  • To serve or support our rights, property, legal obligations, contractual obligations and legitimate interests or legitimate activities as a trade union (pursuant to UK GDPR Articles 6, 9 and 10 including specific conditions regarding the processing of special category data and criminal offence data), as well as to serve or support the legitimate interests, legal obligations, contractual obligations, legal rights, property, and personal safety of our members, service users, role holders, staff, contractors, third party service providers, Authorised Data Handlers, External Data Processors or third party organisations with which we conduct business as part of pursuing our legitimate interests as a trade union.
  • To communicate with our members, service users, role holders, staff, contractors, third party service providers, Authorised Data Handlers or Data Processors or third party organisations with which we conduct business as part of our legitimate interests as a trade union.
  • To process membership subscription/dues payments.
  • To conduct an official IWW WISE-RA internal complaints process, mediation process or investigation.
  • To make and receive payments.
  • To process and ship anything you purchase from our shop.
  • To comply with legal requirements (e.g., ballots, annual audits of the union’s finances).
  • For research purposes to further the legitimate interests of the IWW.
  • To record any contact we have with persons whose data we process.
  • To process your personal data where we have collected your explicit and informed consent to do so.
  • For other trade union related purposes, objects or activities, including those set in the IWW Rule Book and Manual of Policies and Practices.

⚠ IWW role holders, staff, Authorised Data Handlers or Data Processors, members and service users must never use the personal data under the IWW WISE-RA’s care to:

  • to canvass for particular candidates, policies, or political aims within the
    IWW or outside it;
  • to recruit for non-IWW organisations;
  • to recruit for events and causes not endorsed by the IWW; or
  • to build up contact lists for such activities at a later date.

By joining or working with the IWW you should understand that we may use some or all of the personal data you have provided for the above purposes. Where other purposes apply, we will notify you when you provide your data.

Lawful bases for the collection and processing of personal data, and Privacy Notices specifying the purpose and lawful basis of data collection/processing

Legitimate Interest and other lawful bases:

The IWW relies on one or more lawful bases under Article 6 UK GDPR, depending on the purpose of the processing.

In most cases the principal lawful basis will be the IWW’s legitimate interests as a trade union under Article 6(1)(f).

In other. more specific cases, the IWW may rely instead on consentcontractlegal obligation, or vital interests, where those are the most appropriate bases for the processing in question. The specific lawful basis that is being relied up will be clearly specified for each instance of data collection/processing.

Special Category Data:

When we process data that is classified as special category data (such as trade union membership; political, religious or philosophical beliefs; sexual orientation; health information; race/ethnicity), we also rely on a condition under Article 9(2) of the UK GDPR. In particular, we rely on Article 9(2)(d), which permits a not-for-profit trade union to process special category data in the course of its legitimate activities, with appropriate safeguards. This is separate from — and in addition to — the lawful basis we identify under Article 6 above. Appropriate safeguards include organisational measures and data security controls, and we document these in our internal governance documentation.

Criminal Offence Data:

When we process data that is classified as criminal offence data (such as data relating to criminal convictions and offences or related security measures, including the alleged commission of offences and criminal proceedings, including sentencing), we also rely on conditions under Article 10 of the UK GDPR and sections 10 and 11 of the Data Protection Act 2018. This is separate from — and in addition to — the lawful basis we identify under Article 6 above. Depending on the context, the IWW may rely in particular on conditions relating to: processing by a not-for-profit body with a trade union aim; employment, social security and social protection; legal claims and legal rights; safeguarding; or the data subject’s consent to a specific disclosure or activity. Appropriate safeguards include organisational measures and data security controls, and we document these in our internal governance documentation.

⚠ These additional Article 9 and Article 10 conditions do not replace the Article 6 lawful basis; they are additional requirements. 

⚠ Where the data is special category data, the IWW identifies both:
(a) an Article 6 lawful basis; and
(b) an Article 9 condition.

⚠ Where the data is criminal offence data, the IWW identifies both:
(a) an Article 6 lawful basis; and
(b) an Article 10 authorising condition, usually through Schedule 1 DPA 2018.

⚠ The IWW will document the condition relied upon for each processing context, and maintain and review an Appropriate Policy Document covering those activities.

The lawful basis of consent (UK GDPR Article 6(1)(a)) may be used instead in specific cases outlined further below.

We will collect, store and process any personal data we collect according to the principles set out in this Privacy Policy.

We will only collect and process any of the personal information listed above if it is necessary to fulfil our legitimate purposes, or if we have obtained your explicit consent in specific cases set out further below, especially for sensitive categories of personal data. This means that we will avoid using any personal data, or minimise, or pseudonymise the personal data that we process, if that is sufficient to adequately achieve our purposes. It furthermore means that we will only collect or process personal data if one or more of the following apply:

  • It is necessary to administer the union and fulfil our legitimate interests as a trade union as provided under Article 6 of the UK GDPR; and/or
  • It is justified under Article 9(2) of the UK GDPR that permits a not-for-profit trade union to process special category data in the course of its legitimate activities, provided appropriate safeguards are in place;
  • It is justified under Article 10 UK GDPR and sections 10 and 11 of the Data Protection Act 2018 covering criminal offense and judicial data, before the processing begins;
  • We are required to do so by law; or
  • it is necessary to comply with our contractual obligations; or
  • we have your explicit consent to do so; or
  • we have taken reasonable steps to make you aware of this Privacy Policy and you willingly provide the information to us (for example, through your correspondence and communications with us, or by transmitting, posting, sending, or uploading it on/via/to any of the websites, communications systems, or online web services that we maintain) and the processing is necessary for one of the lawful bases identified above, such as legitimate interests, contract, legal obligation, consent, or vital interests; or
  • it is necessary to protect someone’s life.

Whenever you submit your personal information to our role holders via postal, email, SMS, messaging applications, voice calls, or any other form of communication, we will process that information in accordance with this Privacy Policy and the applicable lawful basis for the context, usually our legitimate interests as a trade union unless another lawful basis is more appropriate.

All emails sent by IWW role holders or persons contacting you on our behalf will contain a footer with a link clearly referring to this Privacy Policy.

Whenever we solicit personal information (whether from members or non-members) via forms, we will clearly explain our purposes for collecting the data, include a Privacy Notice, and explicitly refer to this Privacy Policy.

When we solicit personal data from non IWW members for the purposes of research, promoting the union (‘marketing’), surveys or petitions, we will ask the respondent to explicitly consent to the IWW processing their personal data according to this Privacy Policy and will therefore process their data on the lawful basis of consent.

When we solicit, collect and process data for those same purposes but from existing union members or staff (including role holders, contractors and any third party service providers or data processors), we will process the data on the lawful basis of our legitimate interests as a trade union (pursuant to UK GDPR Article 6) and where applicable, to additional separate conditions provided by UK GDPR Articles 9 and 10 regarding the processing of special category data and criminal offence data. 

Excluding cases specified in the following paragraph, whenever we solicit personal data, or use previously collected personal data to subscribe our Data Subjects, share their data with, or process their data using a third-party data processing service (only when this third-party has been mandated by the IWW or a constituent body of the IWW), where this processing is for new purposes not previously listed in our Privacy and Data Protection Policy, we will clearly explain our purposes for collecting or processing the data and ask the Data Subject to explicitly consent to the IWW processing and sharing their personal data according to this IWW Privacy Policy and the Privacy Policies of the third-party platform. In this context, we process the data on the lawful basis of consent, except in the cases specified below.

The legal basis of legitimate interest may be used, and consent not required, in cases where we collect and process personal data through the processing systems of third-party data processor organisations hired as service providers by the IWW, where the purposes of the processing were previously listed in our Privacy and Data Protection Policy, or where this data processing is bound by a lawful Data Processor Agreement between the IWW and the service provider, we may process and share the data on the The legal basis of legitimate interest may be used, and consent not required, in cases where we collect and process personal data through the processing systems of third-party data processor organisations hired as service providers by the IWW, where the purposes of the processing were previously listed in our Privacy and Data Protection Policy, or where this data processing is bound by a lawful Data Processor Agreement between the IWW and the service provider, we may process and share the data on the lawful basis of our legitimate interests as a trade union (pursuant to UK GDPR Article 6) and where applicable, to additional separate conditions provided by UK GDPR Articles 9 and 10 regarding the processing of special category data and criminal offence data. In such cases consent is not required.

When we share or grant access to personal data (including special category data) with third-party processors, this is done only where necessary to provide or support union activities and pursuant to appropriate contractual safeguards. For special category data, we ensure that access is limited, appropriate technical and organisational measures are in place, and that the processing remains within the purposes specified in this policy


Purpose limitations:

The applicable law restricts our actions regarding the processing of personal data to specified lawful purposes or bases. These restrictions are not intended to prevent processing, but rather to ensure that we process personal data fairly and without adversely affecting the Data Subject.

Personal data must be collected only for specified, explicit and legitimate purposes. It must not be processed in any manner incompatible with those purposes.

IWW Authorised Data Handlers or Data Processors cannot use personal data for new, different or incompatible purposes from those disclosed when it was first obtained unless we have informed the Data Subject of the new purposes and they have consented where necessary.

We should document our decision to rely on any specific lawful basis and ensure that we can justify our reasoning.

Legitimate Interest:

The IWW’s principal lawful basis for collecting, storing and processing data is the IWW pursuing our legitimate interests as a trade union for purposes where they are not overridden because the processing prejudices the interests or fundamental rights and freedoms of Data Subjects.

These legitimate interests and purposes are set out in the data processing purposes listed in this section, and are further characterised in the IWW WISE-RA’s wider set of rules, policies, activities and reasonable interests as a Union, and also by common, reasonable expectations regarding Trade Union activities, and as further defined by applicable laws relating to Trade Unions’ activities.

The processing must be necessary. If we can reasonably achieve the same result in another less intrusive way, Legitimate Interests will not apply.

We must balance our interests against the Data Subject’s. If they would not reasonably expect the Processing, or if it would cause unjustified harm, their interests are likely to override our Legitimate Interests.

Legitimate Interests also include serving or supporting the legitimate interests of our members, service users, role holders and staff, particularly in meeting our contractual or legal obligations towards them.

We performed a Legitimate Interest Assessment (LIA) in 2018, prior to producing the first iteration of this Privacy and Data Protection Policy. Before we start Processing any Personal Data on the basis of Legitimate Interest, we perform and record an LIA. An LIA is a type of risk assessment used to determine whether Legitimate Interest can lawfully apply. In performing the LIA we employ the three-part-test approach as described in the ICO’s website guidance on GDPR and Legitimate Interests. This three-part test consists in:

  • Identifying a legitimate interest;
  • showing that the Processing is necessary to achieve it; and
  • balancing it against the individual’s interests, rights and freedoms.

Additional conditions for special category and criminal offence data:

For special category data processed in the course of the IWW’s ordinary membership administration and legitimate trade-union activity, the IWW will ordinarily rely on Article 9(2)(d) where the statutory requirements of that condition are met. For casework, representation, equality, legal-rights or employment-rights situations, the IWW may instead rely on another Article 9 condition that better matches the purpose, including employment/social protection or legal claims.

For criminal offence data, the IWW will ordinarily consider whether the relevant condition is:

(a) Schedule 1 paragraph 31 DPA 2018 for processing by a not-for-profit body with a trade union aim, where the processing relates to members, former members or persons in regular contact with the union in connection with its purposes and is not disclosed outside the body without consent. We may rely on this condition where Criminal Offence Data is processed by the Union as a not-for-profit body with a trade union aim, in the course of its legitimate activities, with appropriate safeguards, and the processing relates to members, former members, prospective members or persons with regular contact with the Union in connection with its purposes. Personal data processed under this condition must not be disclosed outside the Union without the data subject’s consent unless another lawful basis and Schedule 1 condition applies.

(b) Schedule 1 paragraph 33 DPA 2018 where the processing is necessary in connection with legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights. We may rely on this condition where processing is necessary for the establishment, exercise or defence of legal claims, including employment, disciplinary, civil, administrative or other legal proceedings involving members or the Union.

(c) Schedule 1 paragraph 1 DPA 2018 where the processing is necessary for exercising rights or obligations in connection with employment, social security or social protection law. We may rely on this condition where processing is necessary for employment-related representation, workplace grievances, disciplinary cases, workplace investigations, or the exercise or defence of employment-related rights and obligations.

(d) Schedule 1 paragraph 18 DPA 2018 in safeguarding cases, where its statutory conditions are met. We may rely on this condition where processing is necessary to protect an individual at risk, including where an incarcerated member or other vulnerable person requires support, advocacy, welfare intervention, or safeguarding-related assistance.

(e) Schedule 1 paragraph 29 DPA 2018 where the data subject gives valid consent to the particular criminal-data processing or disclosure. We may rely on this condition where the data subject has given valid consent to the processing of Criminal Offence Data, including where an incarcerated member authorises the Union or its authorised representatives to contact prison authorities, HMPPS, the Ministry of Justice, employers, legal advisers or other relevant bodies on their behalf.

The IWW will document the condition relied upon for each processing context, and where required maintain and review an Appropriate Policy Document covering those activities.

Consent:

Here, “consent” means an agreement which must be freely given, specific, informed and be an unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear positive action, signify agreement to the processing of personal data relating to them. A Data Subject consents to processing of their personal data if they indicate agreement clearly either by a statement or positive action to the Processing. Consent requires affirmative action so silence, pre-ticked boxes or inactivity are not sufficient.

The IWW WISE-RA and its Authorised Data Handlers or Data Processors must record evidence of consent captured and keep records of all consents on the IWW WISE-RA Membership Database.

Where consent is relied upon as a lawful basis for processing data, evidence of opt-in consent shall be kept with the personal data.

Data Subjects must be easily able to withdraw consent to processing at any time and withdrawal must be promptly honoured.

Where communications are sent to individuals based on their consent, the option for the individual to revoke their consent should be clearly available and systems should be in place to ensure such revocation is reflected accurately in the Union’s systems.

Consent may need to be refreshed if you intend to process personal data for a different and incompatible purpose which was not disclosed when the Data Subject first consented.

For IWW members, while we can rely on Legitimate Interest as the basis of data processing, it is mandatory to clearly explain the purposes for collecting the data, and collecting explicit consent is strongly recommended for any supplementary/additional collection and processing of sensitive Special Category Data beyond and after the initial collection of personal data via the IWW WISE-RA membership (joining) form. The same applies for Automated Decision-Making and for cross border data transfers outside of the European Economic Area.

Clearly explaining the purposes for collecting the data, and collecting consent are mandatory whenever we solicit personal data from non-IWW IWW members for the purposes of research, promoting the union (‘marketing’), surveys or petitions.

Excluding cases specified in the following paragraph, for both IWW members and non-members, whenever we solicit, or use previously collected personal data with the intention of subscribing them, sharing their data with, or processing their data using third-party data processing services, it is mandatory to collect written consent after clearly explaining the purposes for collecting or processing the data and informing them of the Privacy Policies of the third-party platforms.

The lawful basis of legitimate interest may be used, and consent not required, in cases where we collect and process personal data through the processing systems of third-party data processor organisations hired as service providers by the IWW, and whose data processing are bound by Data Processor Agreements between the IWW and the service provider.

Contract, Legal Obligation, or Vital Interest:

In some contexts the IWW may rely on lawful bases other than legitimate interests. These bases are separate from, and not subsumed within, legitimate interests. Depending on the purpose and context, the IWW may rely on contract, legal obligation or vital interests where the conditions for those lawful bases are met.

By Contract: the Processing is necessary for the performance of a contract with the Data Subject. We can rely on this lawful basis if:

  • The Union has a contract with an individual or organisation and we need to process personal data to comply with our obligations under the contract.;
  • we have a contract with an individual or organisation and we need to process personal data so that we or they can comply with specific counter-obligations under the contract (e.g., processing payment details);
  • because an individual or organisation has asked us to do something before entering into a contract that is essential to the implementation of the contract (e.g., provide a quote); or
  • We have a contract or Data Processing Agreement with an individual or organisation that makes the IWW WISE-RA a Data Processor that processes the personal data of Data Subjects for which that individual or organisation acts as a Data Controller or higher-level Data Processor.

  • The processing on the basis of a contract must be necessary. If we could reasonably achieve the same ends by processing less data, or using personal Data in a less intrusive way, this basis will not apply.

By Legal Obligation: to meet our legal compliance obligations. This may include, but is not limited to:

  • Our legal and statutory obligations under laws applying to Trade Unions or labour and employment, including any obligations to share data with the Certification Officers of the UK or Northern Ireland, or with companies we hire to perform obligatory annual financial audits of the Union; or
  • legal obligations to collect, process and share personal data with HM Revenue & Customs that are relevant to the payment or payroll information on Union contractors, paid staff or employees; or
  • obligations to comply with any legally binding request for disclosure of the personal data by a judicial or law enforcement authority.

By Vital Interest: where it is necessary to protect a person’s vital interests.

The data protection legislation also defines Public Tasks as a possible lawful basis for data processing. The Union undertakes no Public Tasks that require the collection, holding and/or processing of personal data.

Transparency & Privacy Notices:

The applicable legislation requires Data Controllers to provide detailed, specific information to Data Subjects depending on whether the information was collected directly from Data Subjects or from elsewhere. Such information must be provided through appropriate Privacy Notices or Fair Processing. This Privacy and Data Protection Policy text, and more specifically, the top section providing the summary of this policy, constitutes an example of such a Privacy Notice.

The Privacy Notice must be concise, transparent, intelligible, easily accessible, and in clear and plain language so that a Data Subject can easily understand it.

Whenever we collect personal data from Data Subjects, we must provide the Data Subject with all the information required by the data protection laws, including the identity of the Data Controller and the Union’s DPO, how and why we will use, Process, disclose, protect and retain that Personal Data through a Fair Processing Notice which must be presented when the Data Subject first provides the personal data.

When personal data is collected indirectly (for example, from a third party or publicly available source), we must provide the Data Subject with all the information required by the applicable legislation as soon as possible after collecting/receiving the data (within one month) or if the data are used to communicate with the data subject, at the latest, when the first communication takes place; or if disclosure to another recipient is envisaged, at the latest, before the data are disclosed.

When personal data is collected indirectly, we must also make sure it was collected by the third party in accordance with the law and on a basis which is compatible with our proposed processing of that personal data.

For all the above purposes, the IWW WISE-RA and its Authorised Data Handlers or Data Processors will present the contents of the Summary section of this policy as our Privacy Notice (or in the case of emails sent by IWW role holders from IWW email accounts, a link to this policy webpage, in the email’s footer). The Privacy notice will be provided free of charge, to everyone from whom we collect, or on whom we hold and processes personal data. In addition, when it is presented in this way, the following information will be added within the Policy summary text or in any adjacent text that forms part of the Privacy Notice or data collection medium:

  • A link to this webpage containing the full policy.
  • the purpose of the data collection and processing, and any additional purposes, and specify the lawful basis used for the collection of data, as required.
  • Any intention to share the personal data with any third party, with a link to any third party’s Privacy Notice.
  • The source the personal data originates from and whether it came from publicly accessible sources (Not applicable if the data are being obtained directly from the data subject).
  • The categories of personal data concerned (not applicable if the data are obtained directly from the data subject).
  • Whether the provision of personal data is part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data (not applicable if the data are not obtained directly from the data subject).
  • Any signature field or tick box and accompanying explanation statement required for the collection of consent.

Data minimisation

The Union and its Authorised Data Handlers or Data Processors must ensure that only necessary personal data is collected, stored or processed; and personal data is not accessible to an indefinite number of people, but instead access to personal data is granted on a need-to-know basis. This is known as privacy by default.

Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.

Authorised Data Handlers or Data Processors may only process personal data where the performance of their role requires it. They cannot process personal data for any reason unrelated to their role.

The Union’s Authorised Data Handlers or Data Processors can only collect personal data that they require for their job: do not collect excessive data. Ensure any personal data collected is adequate and relevant for the intended purposes.

The Union, its DPO and its Authorised Data Handlers or Data Processors must ensure that when personal data is no longer needed for specified purposes, it is deleted or anonymised in accordance with the Union’s data retention guidelines.

Accuracy

Personal data must be accurate and, where necessary, kept up to date. It must be corrected or deleted without delay when inaccurate.

The Union’s Authorised Data Handlers or Data Processors must ensure that the personal data we use, and hold is accurate, complete, kept up to date and relevant to the purpose for which we collected it.

The Union’s Authorised Data Handlers or Data Processors must check the accuracy of any personal data at the point of collection and at regular intervals afterwards.

The Union, its DPO and its Authorised Data Handlers or Data Processors must take all reasonable steps to destroy or amend inaccurate or out-of-date personal data.

Register of Systems

The applicable legislation requires us to keep full and accurate records of all our data processing activities. The Union and its Authorised Data Handlers or Data Processors must keep and maintain accurate records reflecting our processing, including records of Data Subjects’ consents and procedures for obtaining consents.

The IWW WISE-RA Membership Database and other internal IT systems (e.g., the Interwob Forum, Members’ Area, Wobchat, Next Cloud, etc.) should serve as that record, or Register of Systems. This is why IWW WISE-RA Authorised Data Handlers or Data Processors should keep as much of the data processing activities as they can within IWW WISE-RA’s own data processing systems (namely, the Membership Database, Interwob Forum, Members’ Area, Wobchat, and Next Cloud) where possible, and keep a record on the Membership Database detailing any data processing that occurs outside those internal systems.

The DPO shall be responsible for keeping the Register of Systems up to date with the administrative and technical help, namely, of the Communications Administrator and Membership Administrator.

The Union shall record the appropriate lawful basis upon which personal data or sets of personal data are processed in the Register of Systems.

The Register of Systems should include, at a minimum, the name and contact details of the Data Controller and the Union’s Data Protection Officer, clear descriptions of the personal data types, data subject types, processing activities, processing purposes (i.e., lawful bases for Processing), third-party recipients of the personal data, personal data storage locations, personal data transfers, the personal data’s retention period, any related Data Processor Agreements or Data Protection Undertakings governing the processing, and a description of the security measures in place. In order to create such records, data maps should be created which should include the detail set out above together with appropriate data flows.

 ‘Privacy by Design’ 

We are required to implement ‘privacy by design’ measures when processing personal data by implementing appropriate Technical and Organisational Measures TOMs (like Pseudonymisation) in an effective manner, to ensure compliance with data privacy principles.

In particular the TOMs should ensure that the security and privacy of people’s personal data are embedded into the lifecycle of the Union’s services, applications, and procedures.

We must assess what ‘privacy by design’ measures can be implemented on all programs/systems/processes we deploy to process personal data, by taking into account the following:

  • the state of the art;
  • the cost of implementation;
  • the nature, scope, context and purposes of Processing; and
  • the risks of varying likelihood and severity for rights and freedoms of Data Subjects posed by the Processing.

Data Protection impact Assessments (DPIAs) 

Data Protection Impact Assessment (DPIA), definition: an assessment of the impact of the envisaged processing operations on the protection of personal data where, taking into account the nature, scope, context and purposes of the processing, the processing is likely to result in a high risk to the rights and freedoms of natural persons, as defined in the data protection legislation.

Data controllers must also conduct Data Protection impact Assessments (DPIAs) in respect to high-risk processing. In particular, where special category data processing or criminal-offence-data processing is high-risk, large-scale, novel, or involves vulnerable people such as prisoners or individuals at risk, the Union should consider whether a DPIA is required.

We should furthermore conduct a DPIA when implementing major system or procedure change programs involving the processing of personal data including:

  • use of new technologies (programs, systems or processes), or changing technologies (programs, systems or processes);
  • Automated Processing including profiling and automatic decision making;
  • large scale Processing of special category data; and
  • large scale, systematic monitoring of a publicly accessible area.

A DPIA must include:

  • a description of the Processing, its purposes and the lawful basis used for the processing (including the Data Controller’s legitimate interests if appropriate);
  • an assessment of the necessity and proportionality of the Processing in relation to its purpose;
  • an assessment of the risk to individuals; and
  • the risk mitigation measures in place and demonstration of compliance.

This section forms the IWW’s Appropriate Policy Document for the purposes of the Data Protection Act 2018 where an Appropriate Policy Document is required for the processing of Special Category Data or Criminal Offence Data. It also serves as the Union’s general accountability statement for such processing.

Scope of this Appropriate Policy Document

This Appropriate Policy Document applies to all processing by or on behalf of the IWW of Special Category Data and Criminal Offence Data where the Union relies on a Schedule 1 Data Protection Act 2018 condition that requires such a document, and may also be applied by the Union more broadly as a governance and accountability measure in relation to other Special Category Data and Criminal Offence Data processing.

Categories of data covered

This Appropriate Policy Document covers Special Category Data including, where relevant, data revealing trade union membership, political opinions, philosophical beliefs, health data, racial or ethnic origin, sexual orientation, sex life, biometric data used for identification and other Article 9 UK GDPR special category data.

It also covers Criminal Offence Data including data relating to criminal convictions, alleged offences, investigations, police records, court proceedings, sentencing, prison or probation status, prisoner numbers, prison location, bail or licence conditions, related security measures and similar information falling within Article 10 UK GDPR and the Data Protection Act 2018.

Lawful basis and conditions

Before processing Special Category Data, the IWW will identify and record the applicable Article 6 UK GDPR lawful basis and the applicable Article 9 UK GDPR condition. Before processing Criminal Offence Data, the IWW will identify and record the applicable Article 6 UK GDPR lawful basis and the applicable Schedule 1 Data Protection Act 2018 condition required by Article 10 UK GDPR.

Depending on the context, the IWW may rely in particular on:

Article 9 UK GDPR conditions including Article 9(2)(d) for processing by a not-for-profit body with a trade union aim in the course of its legitimate activities, together with any other applicable Article 9 condition; and

Schedule 1 DPA 2018 conditions including paragraph 1 (employment, social security and social protection), paragraph 18 (safeguarding of children and individuals at risk), paragraph 29 (consent), paragraph 31 (not-for-profit bodies), paragraph 33 (legal claims), and any other condition that more accurately reflects the purpose of the processing in the specific case.

Procedures for complying with the data protection principles

The IWW is committed to complying with the principles in Article 5 UK GDPR and applies the following procedures in respect of Special Category Data and Criminal Offence Data:

Lawfulness, fairness and transparency

The Union identifies and records the relevant lawful basis and condition before processing begins, or as soon as reasonably practicable where urgent circumstances make prior recording impracticable. The Union seeks to explain its processing in clear privacy information and in context-specific notices, forms, casework materials or correspondence where appropriate.

Purpose limitation

The Union processes Special Category Data and Criminal Offence Data only for specified, explicit and legitimate purposes connected with its trade union, employment, representational, safeguarding, administrative, campaigning, welfare, complaint-handling, legal-rights or other legitimate organisational functions. Such data must not be reused for unrelated purposes without a fresh assessment of lawful basis, applicable conditions and fairness.

Data minimisation

The Union processes only the minimum amount of Special Category Data or Criminal Offence Data that is reasonably necessary for the relevant purpose. Where the same purpose can reasonably be achieved without using Criminal Offence Data, or by using less intrusive information, the Criminal Offence Data must not be processed.

Accuracy

The Union takes reasonable steps to ensure that Special Category Data and Criminal Offence Data is accurate and, where necessary, kept up to date. Where such data is contested, unverified, alleged or incomplete, the Union will record that status where reasonably practicable and avoid presenting allegations as established fact.

Storage limitation

The Union will retain Special Category Data and Criminal Offence Data only for as long as is necessary for the relevant purpose, taking into account legal obligations, limitation periods, safeguarding requirements, the continuing needs of representation or campaigning, and any applicable retention schedules. Once no longer needed, the data will be securely deleted, destroyed, anonymised or irreversibly de-identified as appropriate.

Integrity and confidentiality

Access to Special Category Data and Criminal Offence Data will be restricted to those acting under the Union’s authority, or to external processors or controllers, only where access is necessary for the relevant function and subject to contractual, confidentiality and security requirements. The Union applies technical and organisational measures including access controls, least-privilege access, secure communications, record-keeping, confidentiality undertakings, data processing agreements where applicable, and incident-management procedures.

Accountability

The Union keeps records of the categories of sensitive data it processes, the purposes of processing, the lawful bases and conditions relied on, significant disclosures, access controls, retention decisions and compliance measures. The Union will carry out DPIAs where the processing is likely to result in a high risk to individuals’ rights and freedoms.

Access, authority and instructions

Special Category Data and Criminal Offence Data may be handled only by persons authorised by the IWW for the relevant purpose and acting under the Union’s authority and instructions, or by external processors engaged under an appropriate written contract. All such persons must comply with this policy, confidentiality obligations, security requirements and any specific casework or safeguarding procedures.

Sharing and disclosure

The IWW will share Special Category Data or Criminal Offence Data only where necessary and lawful, and only with the minimum information required. Before disclosing such data to a third party, the Union will consider the lawful basis, the relevant Article 9 or Schedule 1 condition, necessity, proportionality, confidentiality, data subject expectations, and any applicable legal or safeguarding obligations.

Retention and deletion policy

The Union’s retention periods for Special Category Data and Criminal Offence Data will be determined by reference to the purpose of the processing, the seriousness and sensitivity of the material, the needs of representation or support, any legal or safeguarding obligations, any limitation periods, and any applicable retention schedule adopted by the Union. Where precise periods cannot reasonably be stated in advance, the Union will record the criteria used to decide retention. The Union will record whether retention and deletion rules have been followed and, where they have not been followed, the reason why.

Review and availability

This Appropriate Policy Document will be reviewed at least annually and also when there are material changes to the law, the Union’s processing activities, retention schedules or security procedures. The document will be retained for as long as required by law and made available to the ICO on request.


Statutory data requirements

As a trade union, we have a statutory requirement to keep an accurate register of members’ names and addresses. If you wish to be an IWW member, you must provide this information to us.

If you choose to opt out from general information emails, we will retain the right to send you a minimal number of critical communications for the purposes of pursuing the legitimate interests or meeting the statutory requirements of the IWW as a trade union (namely information that we are legally required to send to our members: about union ballots and our Annual Returns Statement).


Cookies

Click here to see our full cookies policy.

Like most websites, the IWW uses cookies to improve our users’ experience. Our cookies policy explains which cookies we use and why, along with where you can find more information about cookies.

On our websites, data may be stored on a ‘cookie’. This is a tiny element of data that our site can send to your browser, which may then be stored on your hard drive. This small amount of information does not contain any private information stored on your computer.

You can prevent the setting of cookies by adjusting the settings on your browser (see your browser Help for how to do this). Be aware that disabling cookies will affect the functionality of this and many other websites that you visit. Disabling cookies will usually result in also disabling certain functionality and features of websites. Therefore it is recommended that you do not disable cookies. 


Storage of data & data retention

We retain your data only for the period necessary to enable us to fulfil the purpose(s) for which we collected it, to comply with our legal obligations and/or whilst we maintain your consent or a legitimate interest in retaining it.

Personal data about members in good standing and any personal data we hold about non-members will be retained in our Membership Database and/or organising and casework records for as long as members remain in good standing or we maintain a lawful basis and purpose to retain it according to our Privacy and Data Protection Policy and the applicable legislation.

Additionally, the standard retention period is 7 years, In the IWW WISE-RA Membership Database and/or in our organising and casework records, for personal data about lapsed, cancelled or deceased members, and for personal data about non-members, where we no longer maintain a lawful basis and purpose for retaining the data longer according to our Privacy and Data Protection Policy or applicable laws. At the end of this standard retention period, the personal data will be erased (either deleted, or anonymised so that it is no longer personally identifiable), except in rare cases where we maintain a lawful basis and purpose for retaining it for longer. If you make a legitimate personal data erasure request, your personal data may be erased (deleted or anonymised) sooner than this.

The IWW will maintain a retention schedule for Special Category Data and Criminal Offence Data. Criminal and judicial casework data will be retained only for as long as necessary for the relevant purpose, such as membership administration, prison solidarity work, safeguarding, representation, complaints, grievances, legal rights, audit and defence of legal claims, after which it will be securely deleted or anonymised unless the law requires longer retention.

By default, contents that you have emailed, posted or uploaded yourself via IWW communications services (email accounts, email lists, internal chat, forum, file repository, etc.) will remain indefinitely stored and visible to users on those platforms, even if you are no longer a member, unless you delete them yourself or explicitly request their erasure (the default, when we apply such requests, is anonymisation).

Likewise, on third-party communications (or data processing) platforms where you have given your consent to the IWW to share your personal data in order to connect/subscribe you and communicate with you (e.g., Whatsapp or Signal chat groups, Slack Channels, Loomio, etc.), contents that you post may remain indefinitely stored there unless you take action to delete them yourself or request their erasure by that third party Data Controller. You can ask us us to remove the subscription/connection/contact-data, that you had initially given us to add/subscribe you to a third-party platform, and we will comply with your request (except in rare cases where we maintain a lawful basis to delay or refrain from doing so), but we cannot, on your behalf, erase the content you posted yourself from those platforms, and it is your responsibility to do so.


Personal data must not be kept in an identifiable form for longer than is necessary for the purposes for which the data is processed.

The Union and its Authorised Data Handlers or Data Processors must not keep personal data in a form which permits the identification of the Data Subject for longer than needed for the legitimate purposes or purposes for which we originally collected it, including for the purpose of satisfying any legal, accounting or reporting requirements.

The Union will maintain retention policies and procedures, including Data Retention Schedules, to ensure personal data is deleted after a reasonable time for the purposes for which it was being held, unless a law requires such data to be kept for a minimum time. IWW Authorised Data Handlers or Data Processors must comply with the Union’s guidelines on Data Retention.

Where the Union acts as the Data Processor for a third party Data Controller or for a third-party, higher-level Data Processor, the terms and conditions of the Personal Data Retention period, Storage Limitation, and Data Disposal may be specified in a Contract for Services, Support Agreement, Service Agreement and/or Data Processor Agreement between the Union and that third-party.

To ensure that personal data is kept for no longer than necessary, the Union shall put in place an archiving policy for each area in which personal data is processed and review this process annually.

The Union and its Authorised Data Handlers or Data Processors will take all reasonable steps to destroy or erase from our systems all personal data that we no longer require in accordance with the Union’s applicable records retention schedules and policies. This includes requiring the Union’s Authorised Data Handlers or Data Processors, including third-party Data Processors, to delete such data where applicable.

The Union and its Authorised Data Handlers or Data Processors will ensure Data Subjects are informed of the period for which data is stored and how that period is determined in any applicable Privacy Notice or Fair Processing Notice.



Data security & confidentiality

We will keep your personal data confidential and will take appropriate measures to protect it against loss, theft or misuse and to safeguard your privacy.

IWW uses industry standard efforts to safeguard the confidentiality of your personally identifiable information, such as using robust access authentication methods, Access Control Lists, firewalls and SSL (secure socket layers). We make every effort to protect the loss, misuse and alteration of information under our control. However, data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet. Your IWW membership information is password protected so that only you can access it and view the information contained in your account. You are responsible for maintaining the secrecy of your passwords.

The IWW will restrict access to Special Category Data and Criminal Offence Data on a strict need-to-know basis and will not create a central searchable register of members’ criminal convictions or allegations beyond what is strictly necessary for the administration of specific cases and records. 

Confidentiality

Confidentiality is broader than data protection. Some confidential information may not be personal data, but must still be protected as Union confidential information. This may include organising plans, campaign strategy, internal union deliberations, supplier or contractor information, security information, unpublished documents, financial or operational information, and other information which the Union has a legitimate reason to keep confidential.

Data protection concerns the handling of information relating to identifiable living individuals. Confidentiality concerns the rules about who may know, use, disclose or discuss information, whether or not that information is personal data. Security concerns the technical and organisational measures used to maintain those confidentiality and data-protection boundaries.

All persons acting on behalf of the IWW must respect both data protection and confidentiality.

⚠ Information obtained through union roles, casework, organising, representation, complaints, safeguarding, administration, membership records, IT systems, or internal communications must not be used or disclosed for personal purposes, factional advantage, non-IWW organising, external recruitment, unauthorised campaigning, or any purpose not authorised by the Union.

Casework confidentiality

Members and other persons receiving casework assistance, representation, accompaniment, safeguarding support or advocacy should be informed, in a clear and appropriate way, how confidentiality will operate in their case.

The representative, caseworker, officer or volunteer handling the matter should explain, where relevant:

  • what information is being collected;
  • why it is needed;
  • who within the Union may need access to it;
  • when information may need to be shared with employers, authorities, advisers, representatives, safeguarding contacts, or other third parties;
  • what limits apply to confidentiality, including safeguarding, legal, regulatory, complaint-handling, or serious-risk situations; and
  • how the member or service user can raise data protection or confidentiality concerns.

Casework information must be shared internally only on a need-to-know basis and must not be used for unrelated union, political, personal, factional, campaigning or disciplinary purposes unless a separate lawful basis, condition and authorisation exist.


Data Security and TOMs principles and general terms.

Technical and Organisational Measures (TOMs) are the functions, processes, controls, systems, procedures and safeguards used to protect Personal Data, confidential Union Data and other sensitive information processed by the Union, whether the Union acts as a Controller or processes data on behalf of another Controller.

Personal data must be secured by appropriate Technical and Organisational Measures against unauthorised or unlawful processing, and against accidental loss, destruction or damage.

We will develop, implement, maintain and regularly review TOMs appropriate to the nature, scope, context and purposes of the Processing; the volume and sensitivity of the data; the likelihood and severity of risks to individuals; the state of technological development; implementation costs; and the Union’s size and available resources. Measures may include encryption, pseudonymisation, access controls, resilience, backup and recovery, logging, testing and other safeguards appropriate to the risk.

The objectives of the TOMs Policy are to:

  • Ensure that internal Authorised Data Handlers, External Individual Data Processors and authorised personnel of External Data Processor Organisations understand and implement the TOMs applicable to their role and legal status.
  • Provide a concrete framework of procedures for establishing suitable levels of information security for the Union’s information systems and to mitigate the risks associated with the theft, loss, misuse, damage or abuse of these systems.
  • Provide the principles and methods by which a safe and secure information-systems working environment can be established for Authorised Data Handlers, External Individual Data Processors, personnel of External Data Processor Organisations and service users.
  • Ensure that Authorised Data Handlers, External Individual Data Processors and authorised processor personnel understand their responsibilities for protecting the confidentiality, integrity and availability of the data they handle.
  • Protect the Union from liability or damage through the misuse of its IT facilities and other information processing media.
  • Maintain research data and other confidential information provided by suppliers and other third parties at a level of security commensurate with its classification, including upholding any legal and contractual requirements around information security.
  • Respond to changes in the context of the Union as appropriate, and to implement improved security and organisational measures as and when required.

The following information security principles provide overarching governance for the security and management of information within the Union:

  • Information will be classified according to an appropriate level of confidentiality, integrity and availability and in accordance with relevant legislative, regulatory and contractual requirements.
  • Authorised Data Handlers, External Individual Data Processors and authorised personnel of External Data Processor Organisations will handle information in accordance with its classification level and comply with the policies, procedures, system controls and applicable Data Protection Undertaking or Data Processing Agreement governing their Processing.
  • Information will be secure and available to those with a legitimate need for access in accordance with its classification. Access will be assigned on a documented need-to-know and least-privilege basis, limited to what is necessary for the person’s authorised role or processing task.

We will regularly evaluate and test the effectiveness of those safeguards to ensure security of our Processing of Personal Data.

IWW WISE-RA Authorised Data Handlers and Data Processors are responsible for protecting the Personal Data they handle. They must implement reasonable and appropriate security measures against unlawful or unauthorised processing of Personal Data and against the accidental loss of, or damage to, Personal Data. Particular care and enhanced controls must be applied to Special Category Data under Article 9 UK GDPR and Criminal Offence Data under Article 10 UK GDPR and the Data Protection Act 2018.

Authorised Data Handlers and Data Processors must follow the procedures and technologies established by the IWW to protect Personal Data throughout its lifecycle. Personal Data may be disclosed or made accessible only where the disclosure is authorised, necessary, proportionate and supported by an applicable lawful basis and, where relevant, an Article 9 or Article 10 condition. External processors must be appointed under an Article 28-compliant agreement. Disclosures to separate Controllers or other lawful recipients must be governed by the appropriate data-sharing, casework, legal, safeguarding or other documented arrangements; a Data Processing Agreement is not required merely because a lawful recipient receives Personal Data.

Authorised Data Handlers and Data Processors must maintain data security by protecting the confidentiality, integrity and availability of Personal Data, defined as follows:

  • Confidentiality means that only people who have a need to know and are authorised to use the personal data can access it.
  • Integrity means that personal data is accurate and suitable for the purpose for which it is processed.
  • Availability means that authorised users are able to access the personal data when they need it for authorised purposes.


⚠ TOMs General Provisions

Authorised Data Handlers, External Individual Data Processors and authorised personnel of External Data Processor Organisations must comply with the TOMs applicable to them and must not attempt to circumvent the administrative, physical or technical safeguards implemented by the IWW or an authorised processor.

For Personal Data controlled by IWW WISE-RA and for confidential internal WISE-RA business, IWW-controlled or specifically and formally IWW-mandated or authorised communications and Processing systems should be used for core union Data Processing functions. These functions include membership data and database administration; internal business, deliberation, democracy, elections and ballots; complaints and investigations; representation, casework and organising; long-term retention; and communications from and between IWW officers, role holders, Authorised Data Handlers, External Individual Data Processors and authorised personnel of External Data Processor Organisations containing Personal Data or confidential Union business information.

Where possible, non-commercial, open-source platforms, and/or highly secure platforms that minimise the sharing of IWW business data and IWW-processed personal data with third party sources, should be given preference for use as IWW controlled and mandated data processing and communications platforms.

Where required for an authorised role or processing task, the IWW may issue an official email account and grant role-based access to IWW-controlled or authorised systems, including the Membership Database, Interwob, Nextcloud and approved services operated by Data Processors. Access is not created by signing a DPU or DPA alone and must be separately approved, recorded and reviewed.

NARA, CanROC and other overseas IWW forum moderators may sign the IWW WISE-RA Individual Data Protection Undertaking as Authorised Data Handlers where they moderate or administer WISE-RA-controlled forum areas solely under WISE-RA instructions. The Undertaking applies only to Personal Data for which WISE-RA is Controller or otherwise responsible within WISE-RA-controlled systems (i.e., personal data, including the personal data of NARA members, when it is processed within the Interwob forum or other WISE-RA controlled data processing platforms). It does not govern NARA’s or another body’s independent Processing outside those systems. Forum data must not be exported to NARA-controlled or other external systems, or used for an independent organisational purpose, unless WISE-RA has separately authorised and legally assessed that Processing and any applicable restricted transfer.

In this section, “IWW” means IWW WISE-RA. “Authorised Data Handler” means a person acting under WISE-RA’s authority and instructions under an Individual Data Protection Undertaking. “External Individual Data Processor” means a separate natural person processing Personal Data on behalf of WISE-RA under an Individual Data Processing Agreement. “Personnel of an External Data Processor Organisation” means persons acting under the authority of an organisation bound by an organisation-to-organisation Data Processing Agreement. The applicable term must be used according to the person’s actual legal and operational role.

Where the IWW relies on consent, “informed and recorded consent” means a specific, informed, freely given and unambiguous affirmative indication that is recorded on an authorised IWW system (such as an IWW email account, via a Wobchat or Interwob post or Personal Message, or on the membership database). Before consenting, the Data Subject must be told what data will be processed or shared, the purposes, the principal methods, and the intended recipients or recipient categories. Processing must remain within the scope of that consent unless fresh consent is obtained or the IWW identifies and documents another lawful basis and any applicable Article 9 or Article 10 condition, and addresses transparency and purpose-compatibility requirements. Consent is not required merely because a lawful recipient has not signed an IWW DPU or DPA.



⚠ Specific Technical Security Measures Applying to Individual Authorised Data Handlers, External Individual Data Processors and Authorised Processor Personnel

⚠ This section specifies the baseline technical and organisational security measures that apply to individual physical persons who are authorised to access or process IWW WISE-RA data: internal Authorised Data Handlers, External Individual Data Processors, and named personnel of External Data Processor Organisations. Additional measures may be required by a role-specific instruction, access decision, risk assessment, DPU or DPA.

Throughout this sub-section, ‘IWW’ will stand for ‘IWW WISE-RA’.

When I process IWW data as an Authorised Data Handler, an External Individual Data Processor, or authorised personnel of an External Data Processor Organisation, I will comply with the following measures to the extent applicable to my role and Processing:

➤ General Device and Software Security

✦ Personal devices and supported systems:

If I am an Authorised Data Handler (or an authorised Data Processor and the IWW permits my use of a personal device to process IWW data), when I use a personal device, I will use only a device under my control that runs a currently supported operating system that receives ongoing functionality and security updates/patches. I will not use a rooted, jailbroken or otherwise security-compromised device. I will prevent family members and other users from accessing IWW accounts or data. I will disable any browser extensions and software integrations that are incompatible with these TOMs or that the IWW explicitly instructs me to remove. I will remove IWW accounts, credentials and locally stored data when access ends. I understand that the IWW may require proportionate evidence of compliance or restrict personal-device access in specific situations where the risk is too high.

✦ Device Protection:

  • I will ensure that every device (computer, tablet, mobile phone, Wi-Fi router, etc.) I use to access, collect, process or store IWW data is: protected by a strong password, PIN or biometric verification; automatically locks after a short period of inactivity; and uses robust, full-device encryption (including the device’s operating system, storage drives, and all the device’s data). When I connect to a home or office Wi-Fi for IWW Processing, I will make sure my router Wi-Fi is is protected with WPA2 or WPA3 encryption and a strong router password. I will keep devices in my control and configure notification previews so that Personal Data is not exposed on a locked screen.

✦ Device/Systems Configurations:

  • I will select the most secure settings for my devices and software, ensuring they are configured to provide optimal protection.
  • On devices, operating systems, desktop applications, and online/cloud applications I use for IWW Processing, I will disable optional settings that disclose content to service providers for advertising, personalisation, product improvement or AI model training, unless the IWW has expressly assessed and authorised that Processing.

✦ Regular Updates:

  • I will keep all devices and software up-to-date, use supported operating systems and software, and install updates promptly to address bugs and security vulnerabilities. Where an urgent vulnerability affects an IWW system or IWW authorised device (including my own personal devices), I will follow any shorter patching deadline issued by the IWW or the relevant Data Processor.

✦ Firewalls and Anti-Virus/Malware:

  • I will enable and maintain a device or network firewall (firewalls are usually included in anti-virus software) to protect my internet connection. I will install and maintain up-to-date, industry-standard anti-virus and anti-malware software on all my devices, or equivalent supported security controls adapted to my platform, configured to optimise security. I will enable real-time protection and automatic security updates on all my devices, to ensure that my firewall and antivirus / end-point security control software and antivirus definition files are always updated to the latest version. I will perform weekly virus/malware scans on any device (exception: weekly scans are not necessary for Linux/Open-BSD operating systems), and will perform scans following suspicious activity or as otherwise required by IWW instructions.

✦ Secure Disposal of Devices:

  • Before selling, disposing of, returning or repurposing a device or removable medium used for IWW Processing, I will remove IWW accounts and securely erase IWW data using an approved method appropriate to the device, such as cryptographic erase, a manufacturer-supported secure reset, secure overwrite where appropriate, or physical destruction where secure erasure is not possible. I will not rely on ordinary deletion or formatting where this would leave recoverable data. I will seek advice from the Communications Administrator or IT Committee where necessary. Modern smartphones with device encryption simply need to be factory reset, which wipes the encryption key and renders the data inaccessible. For PCs with encryption (e.g., BitLocker on Windows, FileVault on macOS, or Linux disk encryption) formatting the device or removing the encryption key makes the data effectively irretrievable. If the device is unencrypted or contains a hard drive / memory that is unencrypted (or even an unencrypted partition in the hard drive), it (or the unencrypted part of it) should be securely wiped using special multi-pass deletion software.

➤ Access Control

✦ Authorised Access Only:

  • I will ensure that only I and other specifically authorised persons can access IWW systems or data (local or online/remote). I will not allow an unauthorised person to use an unlocked device running active IWW sessions. I will not leave an unlocked and unsecured device unattended in a public place. I will not leave an unattended device unlocked while logged into an IWW system. Where another authorised person must use the same device, they must use their own approved account or a separately authorised profile wherever possible. Where I share a personal device with trusted non-IWW authorised persons (partners, family, flatmates), I will prevent them from accessing IWW accounts, and will, wherever possible, ensure that they use separate user accounts on the device.

✦ Password Strength and Management:

  • Passwords and passphrases must be unique, difficult to guess, be at least 16 characters long and include random combinations of numbers, uppercase and lowercase letters, and special characters. I will normally use a randomly generated password or a long passphrase and will not reuse an IWW password on another service.
  • I will store login credentials/passwords in a reputable and robust password manager (e.g., https://keepassxc.org/ or bitwarden) protected by a strong master passphrase and multi-factor authentication where supported. I will backup recovery information and credentials separately to robustly encrypted backup solutions so that loss of one device or account does not expose or lead to the loss of all credentials.

✦ No Password Sharing:

  • I will not share my personal or named-user credentials/passwords to IWW systems. Shared accounts (e.g., for co-role-holders) may be used only where the IWW has documented that separate user accounts are impracticable, approved the shared account, identified responsible users, enabled appropriate logging, established a secure method of secret distribution, and arranged prompt rotation when authorised users change.This means no unauthorised sharing of any passwords that directly or indirectly give access to systems that process IWW data: passwords or unlock-pins for the devices I use to process IWW data or access IWW online platforms, the master password for my password manager, passwords for IWW-assigned or authorised email accounts, the membership database, members’ area, Interwob Forum, Wobchat, IWW Nextcloud, etc.
  • Where an approved shared credential must be distributed: I will use an IWW-approved secure secret-sharing method such as encrypted Signal app messages ( see step-by-step instructions for this ); I will not retain the credential in chat histories, ordinary notes or email. I will promptly change the credentials if I retain access but my co-user no longer requires access, or when compromise is suspected.
  • I will never send passwords, recovery codes or authentication secrets through ordinary email, SMS, unencrypted messaging, voice calls or other unauthorised channels, including messages sent to myself as a “note to self”.

✦ Two-Factor Authentication:

  • I will enable Multi-Factor Authentication / Two-Factor Authentication (MFA / 2FA) wherever the system supports it, especially for systems containing membership, casework, complaints, safeguarding, Special Category or Criminal Offence Data.

✦ Secure Use of Public and Shared Devices:

  • I will never access IWW systems or data from public or shared devices, such as computers in libraries or internet cafés.

✦ Access Revocation:

  • I will promptly notify the Communications Administrator (commsadmin [at] iww [dot] org [dot] uk), when my role changes, ends, or no longer requires particular access, and when I discover access that appears excessive. My standing DPU may continue to apply to future authorised roles, but every system, dataset and permission must be separately authorised, reviewed and removed when no longer necessary.

➤ Data Handling and Storage

✦ Data Minimisation and Storage:

  • I will store IWW Personal Data or confidential Union Data locally on my devices only where strictly necessary for an authorised task. I will minimise the data to what is strictly essential to perform my assigned role or Processing purposes, use encrypted, password-protected and access-controlled drives or containers, prevent automatic upload to unauthorised services, and securely delete the local copy as soon as it is no longer required.
  • Wherever practicable, I will keep IWW data within the authorised central system intended for it, such as the Membership Database, Interwob or IWW Nextcloud, instead of creating separate personal copies.
  • If I run the Nextcloud app on my devices to synchronise file storage between the IWW Nextcloud and my device (or any other IWW authorised synchronisation application), I will synchronise only the folders necessary for my role, use an encrypted, password-protected and access-controlled device, prevent onward synchronisation to personal cloud services, and remove synchronised copies when no longer required.

✦ Backups:

  • I will regularly back up my personal device and non-IWW system configuration securely to password-protected, encrypted backup solutions of my choice, but I will not create an independent backup of IWW data to non-IWW controlled backup systems unless the IWW has expressly authorised me to do so. Backups for IWW data should normally be maintained on the approved central system (the IWW Nextcloud) or authorised Data Processor systems.
  • I will normally only back up IWW data to an IWW-controlled or specifically authorised backup system, i.e., the IWW NExtcloud. Personal hard drives, USB drives, memory cards and other removable media should only be used to back-up IWW data if strictly necessary, encrypted, inventoried where appropriate, securely stored and securely erased when no longer required.
  • I will never store, synchronise or back up IWW data to an unauthorised third-party cloud, email, file-sharing or backup service.
  • If my device automatically backs up or synchronises folders, photos, screenshots, messages or application data to a personal or third-party cloud service (e.g., Microsoft One Drive, Google Drive, Dropbox), I will exclude all folders or locations containing IWW data unless that service and Processing have been authorised by the IWW.
  • I may use third-party backup services for my non-IWW personal data, provided that I configure them so they cannot access or synchronise IWW data and protect them with strong credentials, Multi-Factor Authentication, and encryption where available.

✦ Data Retention Audits:

  • I will periodically review the IWW data stored on my devices and securely delete any data that is no longer necessary.

✦ Screenshots, printing, copying and local notes:

I will not make unnecessary screenshots, screen recordings, photographs, printouts or copies of IWW Personal Data or confidential Union Data. I will not paste such data into personal note applications, clipboard-history tools, dictation services, translation services, browser assistants or unapproved software. Where printing or a temporary copy is necessary and authorised, I will minimise the content, store it securely, prevent unauthorised viewing, and securely destroy or delete it promptly after use. I will check screen-sharing settings before meetings and avoid displaying unrelated Personal Data.

➤ Data Sharing, Communication and Transmission

✦ Secure Communication Channels:

  • I will use only communication methods, accounts, telephone numbers, email clients, messaging services, conferencing tools and other channels that the IWW or the relevant authorised Data Processor Organisation has approved for the type and sensitivity of information involved.
  • For example, I will only use authorised methods of communication (e.g., my allocated IWW email account) for all casework-related or complaints-process-related messages, or any communications relating to IWW internal business or an IWW Data Subject’s personal data; whether it is for communicating with any person on behalf of the IWW about their case or their personal data; communicating with their employer or co-workers about their case or personal data; or communicating with other IWW role holders about a case or personal data.
  • I will only transmit IWW Data or IWW Data Subjects’ personal data to a recipient and a recipient-contact-point (e.g., email address, phone number, etc.) that is authorised by the IWW or otherwise lawfully entitled to receive the information, and use an approved channel (for example: I can email IWW data from my IWW email to another Authorised Data Handler or Data Processor’s IWW email, but not to their personal gmail addresses). Informed and recorded consent may be used where appropriate, but it is not the only lawful route for disclosures made under a documented casework instruction, legal obligation, safeguarding decision, legal-rights purpose or other authorised basis.

✦ Data Sharing / Transmission Minimisation:

  • I will disclose or send IWW Personal Data or confidential Union Data only where the recipient is authorised by the IWW or the disclosure has been approved and documented under the IWW Privacy and Data Protection Policy, a casework or representation instruction, a safeguarding decision, a legal obligation, a legal-rights purpose, valid consent where relied upon, or another applicable lawful route, or the recipient has signed an IWW WISE-RA DPA/DPU. An external processor must be covered by the appropriate DPA, but a lawful Controller recipient does not become a processor merely by receiving data.
  • When sharing or transmitting Union Data with/to an authorised or lawful recipient, I will do so on a strictly need-to-know basis and only for the documented authorised purpose for which the data was collected or a compatible, documented purpose.
  • In every case, I will disclose only the minimum data necessary for that purpose, verify the recipient, and anonymise, pseudonymise or redact information where this is practicable and consistent with the authorised purpose.

✦ Encryption for Transmission:

  • I will use an authorised communication channel offering security appropriate to the risk. I understand that TLS protects data in transit between systems but does not necessarily provide end-to-end encryption. Particularly sensitive attachments or conversations may require end-to-end encrypted tools, encrypted files, a separate password channel, using IWW Nextcloud file sharing or another additional safeguard specified by the IWW.
  • I will always ensure that that my web browser uses HTTPS for all internet connections to systems processing IWW data. (HTTPS encrypts the data transmitted between the device and the server to protect sensitive information from unauthorised access).

✦ Public and Untrusted Networks:

  • I will avoid public or untrusted Wi-Fi when processing IWW data (e.g., at coffee shops, tube or train stations, airports). I will also avoid Wi-Fi networks that are not password-protected and WPA2/WPA3 encrypted. Where its use is unavoidable, I will use an IWW-approved or reputable, password-protected VPN service that guarantees a no-logging policy and employs industry-standard encryption protocols (e.g., OpenVPN, IKEv2). The VPN must be paid for by myself, the IWW or an authorised Data Processor organisation (free VPN services/apps are prohibited as they are not secure). I will not rely solely on a VPN to make an otherwise insecure or shared device acceptable.
  • I may use my personal Wi-Fi or the Wi-Fi provided by an authorised Data Processor organisation without a VPN, provided the Wi-Fi is WPA2/WPA3 encrypted.
  • I may also use my own mobile data connection (3G, 4G, 5G) without a VPN, or a mobile data plan provided by the IWW or an authorised Data Processor organisation.

✦ Email Security :

  • I may use an email client application on my mobile or PC (e.g., K9Mail, Thunderbird, Outlook) to manage my official email account, provided that: I set the correct server port configurations to use SSL/TLS to encrypt incoming (IMAP) and outgoing (SMTP) connections to the email server, thus ensuring that login credentials and email content are transmitted securely between my client and the server; the device is compliant with these TOMs; local mail storage is appropriately protected, and automatic forwarding, backup or synchronisation to unauthorised accounts is disabled. Guidance for configuring email clients can be found by clicking here. Ordinary email may be encrypted in transit but is not necessarily end-to-end encrypted.
  • I will not set a forwarder from my official email account to an email account hosted by an unauthorised third-party (e.g., forwarding to my personal gmail account)
  • I will never use an unauthorised email account to send emails using an email address alias of an official email account (e.g., I will not use my personal Gmail account to send emails using an IWW email address alias as the sender address).
  • When sending bulk emails, I will by default use the IWW Membership Database bulk mailer if I have access to it. If an ordinary authorised email client must be used, I will use the BCC field for all recipient email addresses, never the “To:” field. Whenever sending bulk emails via the Database mailer or the ordinary authorised email client, I will check attachments, message contents, and recipient lists carefully, to avoid exposing Data Subjects’ email addresses and other Personal Information to one another.

✦ Phishing Awareness:

  • I will remain vigilant against phishing, impersonation, malicious links, unexpected Multi-Factor Authentication prompts and account-recovery scams. I will report suspicious communications to the IWW WISE-RA Communications Administrator immediately (communications [at] iww [dot] org [dot] uk). I will not trust any emails (or SMS or Signal or Whatsapp messages, etc.) notifying me of issues with affecting my official accounts, especially if they ask me to enter my login details or provide any other sensitive data by clicking a link or responding to the email. If in doubt, I will consult the Communications Administrator. Legitimate emails about IWW email account management should only come from commsadmin [at] iww [dot] org [dot] uk or from an *@webarchitects.coop email address. If I ever suspect that I have clicked on a malicious link I will immediately update my antivirus definitions and perform an antivirus/malware scan; I will change all my passwords to systems that process IWW Data or that may indirectly provide access to those systems (including the master password for my password manager application), and inform the IWW Data Protection Officer (dataprotection [at] iww [dot] org [dot] uk). if I work for a third-party Data Processor Organisation, I will also inform its Data Protection Manager/Officer If I suspect that I may have surrendered a password to a likely phishing site for any system that directly or indirectly provides access to IWW Data, I will immediately reset that password and alert the IWW Data Protection Officer (dataprotection [at] iww [dot] org [dot] uk). if I work for a third-party Data Processor Organisation, I will also inform its Data Protection Manager/Officer. If I suspect that I may have surrendered any IWW Data Subject’s personal data, or sensitive IWW Business data to a likely phishing site, I will immediately alert the IWW Data Protection Officer (dataprotection [at] iww [dot] org [dot] uk).

➤ Approved communications tools and encryption requirements

✦ Approved messaging, calling and conferencing tools:

  • I may use the Jitsi application, or Zoom application accounts paid for by the IWW (or one of its branches or committees) for secure voice calls, voice-conferencing and videoconferencing calls to speak with Authorised Data Handlers or Data Processors or Data Subjects about IWW business or personal data concerning them. If I an agent or personnel of an authorised third-party Data Processor organisation, I may also use other secure and encrypted internet voice/video-conferencing or voice/video-calling-over-IP providers paid approved by the Union and paid for by the Service Provider.
  • I may use the IWW Wobchat application for secure instant-messaging or mobile messaging with other Authorised Data Handlers or Data Processors about IWW business/data or to communicate with IWW members about their personal data.
  • I may also use the Signal application for end-to-end encrypted messaging and voice calls, to communicate with other Authorised Data Handlers or Data Processors about IWW business/data or to communicate with IWW Data Subjects.
  • I will give the above-mentioned applications preference wherever possible over unencrypted mobile messaging and voice calls for these purposes.
  • If the above-mentioned applications cannot be used, Whatsapp may also be used, but for end-to-end encrypted voice calls only. Whatsapp should be avoided as far as possible for instant messaging for these purposes, except where individual Data Subjects provide recorded consent, or it is formally mandated as a means of group communications by an IWW Branch, and all members added to the Whatsapp group chat provide informed and recorded consent.
  • I will not use an unapproved messaging, calling or conferencing service for IWW Personal Data or confidential Union Data. A Data Subject’s preference or consent does not by itself override IWW security, procurement or platform-approval requirements.

✦ Limited Use of Unencrypted Channels:

  • I may use an official IWW email account for authorised communications, recognising that ordinary email may use encryption in transit but is not necessarily end-to-end encrypted. I will minimise sensitive content, verify recipients, apply additional protection to high-risk attachments where required, and never use an unauthorised email account.
  • If I am an internal Authorised Data Handler, including an embedded WISE-RA administrative contractor, I may use a personal telephone and number for authorised direct calls or SMS where an approved IWW service (namely, Wobchat or Signal) is unavailable or disproportionate, provided the device and account comply with these TOMs, the communication is necessary, the recipient is verified, the content is minimised and retained only as long as necessary.
  • If I am an External Individual Data Processor or personnel of an External Data Processor Organisation, I may use telephone or SMS only through a number, device or arrangement authorised in the applicable DPA or written IWW instruction. I must not introduce an unapproved communication provider or personal account into the Processing.
  • I will not retain call logs, contact details, recordings, transcripts or message content relating to IWW Data Subjects for longer than necessary for the authorised purpose and applicable retention rule. I will not record calls or meetings unless recording is separately authorised and participants are appropriately informed.

➤ Platform and System Use

✦ Authorised Systems Only:

  • I will use only devices, accounts, platforms, cloud services, AI services, social-media accounts, servers and other Processing systems that the IWW or the relevant authorised Data Processor Organisation has approved for the specific purpose and data involved.
  • I will keep data within the authorised system intended for it and avoid exports unless strictly necessary for my mandated Data Processing purposes or otherwise authorised by the IWW. I will not treat a Data Subject’s consent as sufficient authority to export data to an unapproved system. Any export must be necessary, minimised, authorised, securely protected and deleted when no longer required. For example: if I am given access to the Interwob moderator tools, I will only process the Data within Interwob and will not export it outside of Interwob without authorisation from the IWW or the Data Subject’s consent; or if I am given access to the IWW membership database I will not export or process the data outside the database unless otherwise authorised.
  • Where Processing in another system is authorised, I will use only the approved destination, minimise the data, apply anonymisation, pseudonymisation or redaction where practicable, record the transfer or export where required, and delete the destination copy when it is no longer necessary.
  • I may use an IWW-issued device or a device issued by an authorised Data Processor Organisation. I am also authorised to use my own personal devices (e.g., PCs, tablets and mobile phones) to access systems that process IWW Data, and to process that data. Any device I use to process IWW Data must comply with access-control, storage, overseas-access and other requirements in this Policy. Permission to use a personal device does not authorise personal cloud storage, personal email, unapproved applications or access to IWW Data by other device users.

✦ Social Media, Cloud, AI and other Third-Party Platforms:

  • I will not collect, submit, upload, expose, store, cross-reference or process IWW Personal Data or confidential Union Data, nor host, post, process or store IWW internal business or discussions through an unauthorised social-media platform, cloud service, collaboration suite, generative-AI system, AI meeting assistant, transcription bot, browser-integrated AI assistant, coding assistant, translation service, analytics service, plugin or browser extension (e.g., Google Drive, Google Docs, Google Spreadsheets, Open AI Chat GPT, Anthropic Claude, Microsoft Copilot, Dropbox, Survey Monkey, Facebook, Twitter/X, Discord, Instagram, etc.). This includes prompts, files, screenshots, recordings, logs and copied text.
  • Use of a third-party platform for IWW Personal Data requires documented IWW authorisation by the DPO, an assessment of the provider’s role and terms, an appropriate lawful basis and Article 9 or Article 10 condition where relevant, an Article 28 DPA where the provider is a processor, suitable security and transfer safeguards, and a DPIA where the Processing is likely to result in high risk. Additionally, there must be a formal mandate allowing use of the third-party platform, issued by the IWW WISE-RA body to which the Data Subjects belong, and each Data Subject concerned must be informed of the third-party platform’s privacy policy prior to their personal data being shared with it, and given the opportunity to opt-out (never opted-in by default without consent) ( click for more details on the procedures required to mandate and use third party data processing platforms ). A democratic mandate, opt-out notice or Data Subject consent does not by itself replace the first set of requirements.
  • I will use only formally authorised and mandated IWW social-media accounts for approved outreach or communications. I will minimise the collection of Personal Data through those accounts, follow the applicable privacy notice and retention rules, and move sensitive correspondence to an approved private channel where appropriate.
  • I will preferentially use of desktop applications, especially Open Source applications like Open Office or Libre Office for IWW document processing. I may use an authorised third-party online applications such as Google Docs and Spreasheets, or AI applications like Chat GPT or Claude, only for material that contains no Personal Data and no confidential, security-sensitive or otherwise restricted Union information. I will check that the material is genuinely non-identifying, disable optional provider training or product-improvement settings where possible, use the minimum content necessary and delete it when no longer required. Pseudonymised data remains Personal Data and is not covered by this exception.

✦ System Security for Authorised Platforms:

  • I will secure my access to every authorised third-party platform with a unique strong credential and Multi-Factor Authentication (MFA e.g., Two-Factor Authentication / 2FA) where supported. MFA is required for administrative or high-risk access unless a documented exception and compensating controls have been approved.


➤ Remote access, overseas access and travel for Authorised Data Handlers

If I am an Authorised Data Handler, I may access IWW-controlled systems while temporarily or routinely outside the UK where this is necessary for an authorised role, where the country and circumstances of access are permitted under these TOMs, and where I continue to act under IWW authority and instructions.

authorised remote overseas access does not permit me to export, copy, download, synchronise, store, disclose, transmit, upload or otherwise make IWW-controlled business data or personal data available to any overseas person, organisation, government agent, government body, public authority, platform, cloud service, AI service, email provider, storage provider, account, device or other third party unless the IWW has specifically authorised this and any required legal, contractual and security safeguards are in place.

Any official search, seizure, compelled access or legally required disclosure is governed by the section titled ‘Overseas legal demands, border examinations and compelled access’. Such an event does not become authorised overseas access merely because it is legally compelled and must be treated as a potential security incident.

When I access Union Data while outside the UK, I will apply the following overseas remote access rules and conditions:

  • I will access IWW-controlled personal data only through IWW-controlled or IWW-authorised systems;
  • I will use only my own IWW-authorised credentials;
  • I will use only devices under my own control and compliant with the IWW Technical and Organisational Measures;
  • I will use strong passwords, device encryption, account security and multi-factor authentication wherever available;
  • I will not use public or shared devices;
  • I will avoid public or untrusted networks unless using an approved secure connection;
  • I will not export, copy, download, screenshot, scrape, sync, back up or store personal data outside the authorised system unless necessary and authorised;
  • I will not use unauthorised cloud storage, personal email accounts, AI tools, social media platforms, messaging platforms, file-sharing platforms or other third-party systems to process IWW-controlled personal data;
  • I will not voluntarily permit or enable any other person to view, access, use or process IWW-controlled personal data through my device, account, credentials or physical environment;
  • I will report any suspected unauthorised data or device access, accidental disclosure, loss or theft, inspection, search, seizure, compelled unlocking, suspected copying, border-authority access or other compromise to the IWW DPO immediately, or, where immediate reporting is prohibited, impossible or unsafe, as soon as it is safe and lawful to do so.

If I access IWW-controlled systems while temporarily travelling outside my normal country of residence, I will take additional care to prevent unauthorised access by border officials, employers, family members, travel companions, accommodation providers, cyber cafés, libraries, public computers, untrusted Wi-Fi networks, device repair shops, cloud providers or other third parties.

Whenever I access IWW-controlled systems while temporarily travelling outside my normal country of residence, I will:

  • not access IWW-controlled personal data from public or shared devices;
  • not leave devices unattended if they are physically unsecured, unlocked, or logged into IWW systems;
  • restrict notification previews and screen visibility for IWW related data/communications;
  • not use automatic third-party cloud backup or synchronisation services for folders containing IWW data (but I will be able to use automatic synchronisation/backup to the IWW WISE-RA Nextcloud);
  • minimise local downloads of IWW data to my device and only do so if strictly necessary;
  • not download or retain personal data locally to unauthorised devices unless strictly necessary and authorised;
  • promptly and securely delete any temporary local copies of IWW data as soon as they are no longer needed and prior to border crossings.

If I expect to process IWW-controlled personal data while outside my normal country of residence for more than one month, I will notify the IWW WISE-RA Data Protection Officer at dataprotection [at] iww [dot] org [dot] uk before beginning or continuing that extended period of overseas processing.

➤ Special security measures before transiting through international borders representing a security or surveillance risk.

Regardless of the length of the trip, if I expect to cross, enter, leave or transit through a country or border designated by the IWW as presenting an increased legal, political, surveillance, security, operational or personal-safety risk, I will notify the DPO at dataprotection [at] iww [dot] org [dot] uk in advance of the travel and follow any specific risk-based instructions issued by the DPO or IT Committee.

Relevant risks include border authorities having legal powers or documented practices involving the inspection, access, detention, seizure, copying or forensic examination of electronic devices, or requesting access to email, social-media, cloud-storage or other online accounts.

The countries currently designated as presenting an extreme risk are:

  • Afghanistan;
  • Burkina Faso;
  • Central African Republic;
  • Conflict-affected parts of the Democratic Republic of the Congo and Cameroon;
  • Haiti;
  • parts of Iraq;
  • Libya;
  • Mali;
  • Myanmar;
  • Niger
  • North Korea;
  • Somalia;
  • Sudan;
  • South Sudan;
  • Yemen;
  • and countries subject to an FCDO “against all travel” warning.

No routine access to IWW-controlled systems or data is permitted while travelling in these countries unless permitted by prior written DPO authorisation following an individual risk assessment. Travellers must not carry locally stored IWW data or devices, credentials, tokens, certificates, synchronisation connections or password stores capable of providing direct or indirect access to IWW systems unless permitted by prior written DPO authorisation following an individual risk assessment

The countries currently designated as representing an increased border-search, surveillance, political, legal or security risk (namely if you plan to engage in, or are liable to be identified by authorities as involved in political/trade-union related activities) are:

  • Bahrain;
  • Belarus;
  • China (Mainland);
  • El Salvador;
  • Equatorial Guinea;
  • Eritrea;
  • Ethiopia;
  • Hong Kong;
  • Iran;
  • Israel and the Occupied Palestinian Territories;
  • Kazakhstan;
  • Nicaragua;
  • Russia;
  • Turkey;
  • Turkmenistan;
  • Uzbekistan;
  • the United Kingdom;
  • the United States;
  • Venezuela;
  • Vietnam;
  • Zimbabwe.

Full border-crossing TOMs should normally be observed for the above countries, depending on the purpose of the visit.

The countries currently designated as presenting a potential/conditional political/surveillance risk (if you plan to engage in local political/trade-union related activities) are:

  • Algeria;
  • Azerbaijan;
  • Bangladesh;
  • Bolivia;
  • Burundi;
  • Cambodia;
  • Cameroon outside conflict areas;
  • Colombia;
  • Cuba;
  • DRC outside conflict areas;
  • Ecuador;
  • Egypt;
  • Eswantini;
  • Guatemala;
  • Honduras;
  • India;
  • Indonesia;
  • Iraq;
  • Kyrgyzstan;
  • Marocco and Western Sahara;
  • Malaysia;
  • Mauritania;
  • Mexico;
  • Nigeria;
  • Pakistan;
  • the Philippines;
  • Qatar;
  • Rwanda;
  • Saudi Arabia;
  • Singapore;
  • Sri Lanka;
  • Thailand;
  • Tunisia;
  • Uganda;
  • United Arab Emirates;

Full or partial border-crossing TOMs may be recommended for these countries if you plan to engage in local political or trade-union activities.

✦ Full border-crossing TOMs for transiting through high-security risk-borders:

Before crossing such a border with a laptop, tablet, smartphone, removable storage device or other device that has been used to process IWW-controlled data, I will, wherever reasonably practicable:

  • notify the DPO in advance of the travel and follow any specific risk-based instructions issued by the DPO or IT Committee;
  • use a clean or specially prepared travel device wherever the sensitivity of the data, destination, route or personal risk makes this appropriate;
  • securely remove all locally stored IWW personal data, Special Category Data, Criminal Offence Data, casework information, membership information, organising records, correspondence, downloaded files, attachments, exports, screenshots, notes, temporary files and offline copies;
  • verify that IWW data has also been removed from local download folders, recent-file lists, application caches, email caches, messaging applications, document viewers, thumbnail caches, temporary folders and recycling or deleted-items folders;
  • pause and disconnect Nextcloud, email, calendar, contact, browser, password-manager and other automatic synchronisation services connected to IWW accounts;
  • ensure that no IWW files remain available through offline synchronisation or “available offline” settings;
  • log out of all IWW accounts, systems, websites, databases, forums, email accounts, messaging systems, cloud platforms and administrative interfaces;
  • revoke or remove locally stored login sessions, application passwords, access tokens, refresh tokens, API keys, SSH keys, client certificates and other credentials that could provide direct or indirect access to IWW systems;
  • remove IWW passwords and credentials from browser password stores, device password stores and locally accessible password-management applications;
  • close all browser tabs and applications connected to IWW systems and clear browser history, cookies, cached content, downloaded-file records, form data, active sessions and site-storage data associated with IWW platforms;
  • remove IWW member, worker, staff, officer, contractor, prisoner, supporter and other IWW-related contact information from the device’s locally stored contacts, recent-call lists, messaging histories and autocomplete records, where those records are not necessary for personal safety;
  • disable lock-screen previews and notifications that could reveal IWW messages, names, email addresses, calendar entries or other Union information;
  • remove any removable media, paper records, notebooks or printed documents containing IWW-controlled personal data or confidential Union information;
  • ensure that the device is protected by strong full-device encryption and a strong alphanumeric passcode, and is fully powered down rather than merely placed in sleep or standby mode while crossing the border;
  • avoid relying solely on biometric unlocking and, where appropriate and lawful, disable biometric unlocking before reaching the border so that the device is protected by its full passcode;
  • ensure that automatic connection to Wi-Fi, Bluetooth devices, mobile hotspots and nearby-sharing services is disabled;
  • ensure that no IWW data will be uploaded automatically to personal cloud accounts or other unauthorised storage when the device reconnects to a network;
  • carry only the minimum IWW-related device, information and access capability necessary for the journey; and
  • where these measures cannot be completed satisfactorily, refrain from carrying the affected device or from processing IWW-controlled personal data during the journey.

After crossing the border, unless otherwise authorised by the DPO or authorised IT personnel, I will not reconnect the device to IWW systems, or use affected credentials to access IWW-controlled data if:

  • the device was searched, inspected, connected to external equipment, taken out of my sight, detained, seized or temporarily retained;
  • I disclosed a device passcode, password, recovery key, authentication code or IWW credential;
  • an official accessed or attempted to access an IWW account or remotely stored information;
  • the device behaved unexpectedly following the examination; or
  • I have any other reason to suspect that the device, account or credentials may have been compromised.

In any such case, I will:

  • report the matter to the IWW DPO as soon as it is safe and lawful to do so;
  • provide a factual account of what occurred, including which devices, accounts or credentials may have been exposed;
  • follow instructions to revoke active sessions, reset passwords, rotate encryption or recovery keys, revoke tokens or certificates, or suspend affected accounts;
  • not use the affected device to access IWW systems until the DPO or authorised IT personnel have assessed the risk;
  • make the device available for security inspection, malware scanning, forensic review, secure wiping or reinstallation if instructed; and
  • treat any unauthorised access, copying, detention or suspected compromise as a potential personal data breach or security incident under the IWW’s incident-reporting procedures.

These measures are intended to minimise the amount of IWW-controlled data and access capability exposed during border transit. They do not authorise me to make false statements, conceal information in breach of applicable law, obstruct an examination, or deliberately frustrate a lawful border search. Where I am uncertain about my legal obligations, I will seek appropriate legal advice where reasonably practicable and notify the DPO as soon as it is safe and lawful to do so.

➤ Overseas legal demands, border examinations and compelled access

Authorised remote overseas access does not authorise me to disclose IWW-controlled business data or personal data, provide access to an IWW account or system, or surrender an IWW credential to a government agent, government body, border authority, law-enforcement authority, public authority or other third party.

If I receive, or reasonably believe that I may be subject to, a legal demand, order, requirement, search, inspection, seizure, device examination, compelled-unlocking request, compelled-access request or other exercise of official authority seeking access to IWW-controlled business data, personal data, devices, credentials, accounts or systems, I will treat the matter as a potential security incident and possible Personal Data Breach.

I understand that nothing in these TOMs requires me to:

  • make a false statement;
  • physically obstruct or deliberately frustrate an official examination;
  • disobey a legal requirement that applies to me;
  • place myself or another person at an unreasonable risk of detention, arrest, physical harm or other serious consequences; or
  • take any action that would be unsafe or unlawful in the circumstances.

Where it is reasonably practicable, safe and lawful to do so before any access or disclosure occurs, I will:

  • notify the IWW WISE-RA DPO immediately;
  • provide the DPO with the wording, scope and circumstances of the demand, where available;
  • ask the authority to direct the request to the IWW WISE-RA as the organisation responsible for the data;
  • explain, where appropriate, that the device or account contains confidential organisational information and personal data belonging to or controlled by the IWW;
  • request sufficient time to obtain instructions or appropriate legal advice;
  • seek verification of the identity, authority and legal basis of the person making the demand;
  • ask that the demand, search or access be limited to what is legally required; and
  • follow any lawful and safe instructions issued by the DPO or authorised IWW IT personnel.

Where advance notification or consultation is prohibited, impossible or unsafe, I will:

  • not voluntarily disclose or provide access beyond what I reasonably understand to be legally compelled;
  • not volunteer passwords, credentials, account details, information or access that have not been requested or required;
  • avoid providing access to unrelated IWW systems, accounts, data or devices;
  • request that the scope, method and duration of any search, access, copying, detention or seizure be limited and recorded, where it is safe and appropriate to do so;
  • avoid consenting to wider access where I am merely being asked for voluntary consent and am not legally compelled, provided that declining consent is lawful and safe in the circumstances; and
  • notify the DPO as soon as it is safe and lawful to do so.

Where lawful and reasonably practicable, I will make and preserve a factual record of:

  • the date, time and location of the incident;
  • the authority, agency or official involved;
  • the legal power or basis asserted, if stated;
  • the questions asked and instructions or demands made;
  • whether access was voluntary, requested, directed or compelled;
  • which devices, accounts, credentials, files or data were accessed or may have been accessed;
  • whether the device was connected to external equipment, unlocked, searched, copied, detained, seized or taken out of my sight;
  • whether any passwords, PINs, recovery keys, authentication codes or credentials were disclosed;
  • how long the access, search, detention or seizure lasted; and
  • any documents, receipts, reference numbers or contact details provided by the authority.

I understand that a demand or requirement made under the law of another jurisdiction does not automatically mean that the resulting disclosure is authorised by IWW policy or compliant with UK data-protection law. The IWW will assess any applicable legal obligations, international-transfer requirements, conflicts of law, risks to Data Subjects, notification duties and available legal, contractual or technical safeguards.

If a device has been searched, inspected, unlocked, connected to external equipment, taken out of my sight, detained, seized or temporarily retained, or if a password, PIN, recovery key, authentication code, IWW credential or other access information has been disclosed, I will:

  • treat the device, account and relevant credentials as potentially compromised;
  • not reconnect the affected device to IWW systems;
  • not use the affected device or credentials to access IWW-controlled data;
  • report the incident to the DPO as soon as it is safe and lawful to do so;
  • follow instructions to revoke sessions, reset passwords, rotate keys, revoke tokens or certificates, suspend accounts, inspect the device, securely wipe it or reinstall its operating system; and
  • comply with the post-border incident measures set out in the section titled “Full border-crossing TOMs for transiting through high-security risk borders”.

These obligations apply whether the official access occurs at an international border, airport, port, railway station, checkpoint, accommodation, workplace, police station or any other location outside the UK.

➤ Remote access, overseas access and travel for External Data Processors

If I am an External Individual Data Processor, any authorisation for me to access or process IWW-controlled data remotely from outside my normally authorised processing location, including while travelling, is subject to prior case-by-case written authorisation by the IWW WISE-RA.

The processing is governed by the Individual Data Processing Agreement between me and the IWW WISE-RA, together with any related contract, documented processing instructions, international-transfer arrangements and specific security requirements issued by the IWW.

If I am instead an employee, officer, contractor, agent or other authorised member of the personnel of an External Data Processor Organisation, my access is governed by the Organisation-to-Organisation Data Processing Agreement between that organisation and the IWW WISE-RA, together with the organisation’s obligations concerning its personnel and any individual confidentiality, security or access undertaking that the IWW requires me to accept. An individual undertaking does not replace the Organisation-to-Organisation Data Processing Agreement.

If I am an External Individual Data Processor based outside the UK, or an authorised member of the personnel of an External Data Processor Organisation based outside the UK, and I am given access to IWW-controlled Personal Data, that access may constitute a restricted transfer even where the data remains stored on an IWW-controlled server. The country or countries from which the Processing will take place, and any applicable international-transfer mechanism, adequacy basis, transfer assessment, contractual safeguard or supplementary measure, must therefore be assessed, approved and documented by the IWW before access is enabled.

Authorised overseas access does not authorise:

  • onward disclosure to any person, organisation or public authority;
  • access by any additional personnel;
  • appointment or use of any new sub-processor;
  • overseas storage, hosting, backup, synchronisation or local retention;
  • use of any unapproved platform, cloud service, AI service, email account, messaging service, storage provider, device or other third-party service; or
  • Processing from any country other than those specifically authorised by the IWW.

Any written authorisation for remote overseas Processing must identify or otherwise clearly define:

  • the country or countries from which access is authorised;
  • whether the authorisation is routine, temporary or limited to specified travel;
  • the authorised duration or review period;
  • the permitted Processing purposes;
  • the systems, accounts, datasets and categories of data that may be accessed;
  • the approved devices, communication methods and security measures;
  • whether local downloading, storage, printing, exporting or synchronisation is permitted;
  • any applicable border-transit or elevated-risk-country measures;
  • whether the access constitutes a restricted transfer under UK GDPR; and
  • any adequacy regulation, appropriate safeguard, transfer assessment, contractual measure or other lawful transfer arrangement required by the IWW.

Authorisation to access IWW-controlled systems from one country does not authorise access from another country. I will notify the IWW DPO and obtain further written authorisation before materially changing my Processing location, travel arrangements, devices, systems, purposes, personnel, sub-processors or other relevant circumstances.

If I am normally based in the UK and am authorised to access IWW-controlled data while travelling abroad, I will comply, at minimum, with the security and travel requirements applicable to internal IWW Authorised Data Handlers. The IWW may impose additional or more stringent requirements because I am acting as an External Data Processor, because the Processing involves Special Category Data or Criminal Offence Data, because the destination or transit route presents an elevated risk, or because an international-transfer mechanism or supplementary security measure is required.

Compliance with the internal Authorised Data Handler TOMs is a minimum security requirement and does not replace or reduce my obligations under the applicable Data Processing Agreement, UK GDPR, the Data Protection Act 2018, any applicable international-transfer arrangement, or the IWW’s documented instructions.

I will not begin or continue overseas Processing if the required authorisation, assessment, documentation or safeguards are absent, expired, withdrawn, no longer accurate, or cannot be complied with. I will notify the IWW DPO promptly if relevant circumstances change or if I am uncertain whether my authorisation continues to apply.

➤ Incident Management

  • I will report immediately to the IWW Data Protection Officer (dataprotection [at] iww [dot] org [dot] uk) any actual or suspected Personal Data Breach or security incident, including device or paper-record loss; account compromise; phishing; malware; misdirected email; accidental CC instead of BCC; exposed link permissions; unauthorised export or AI upload; excessive access; unauthorised screenshot or recording; or unauthorised overseas access. I will preserve relevant evidence, assist containment and investigation, and not notify the ICO or affected individuals independently unless instructed or legally required.

➤ Data Subject Requests:

  • I will immediately forward to the IWW Data Protection Officer (dataprotection [at] iww [dot] org [dot] uk) any request or complaint relating to Personal Data, including access, rectification, erasure, restriction, objection, portability, consent withdrawal or questions about Processing. I will not provide a substantive response on behalf of the IWW unless authorised.

➤ Training and Awareness

  • I will complete the data-protection and security training required for my role, including refresher or incident-specific training where required, and follow current IWW security alerts, approved-tools guidance and role-specific instructions.




⚠ Organisational TOMs Applying to IWW WISE-RA Data Processing

⚠ This section specifies the Technical and Organisational Measures that IWW WISE-RA as an organisation, and any IWW-authorised External Data Processor organisation is required to implement when processing IWW WISE-RA data and IWW Data Subjects’ Personal Data:

1. Information Security Policies
  • Policy Maintenance: Maintain and implement a documented information security policy that includes guidelines to safeguard the confidentiality, integrity, and availability of Union Data.
  • Documented Procedures: Ensure that these policies include specific and formally documented provisions and procedures for access control management, systems configuration and maintenance, data encryption, maintenance of information systems’ physical security, systems and network security and functionality monitoring, vulnerability and patch management, security incident management, and backup and recovery protocols.
    • The Union’s Data Protection Officer, IT Committee and Communications Administrator maintain a full set of policies & procedures, inventory, and guidance documentation covering all aspects of the Union’s IT Infrastructure and its administration in an IT Committee folder of the Nextcloud file repository and in the ‘IT Documentation’ and ‘IT Access & Privileges’ subsections of the ‘WISE-RA Wikis’ Section of the Interwob forum.
  • Enhanced Confidentiality Measures: Implement specific measures to protect all confidential information, ensuring it is not disclosed without prior written consent from the Data Controller.
    • These measures are implemented via standard IWW WISE-RA Data Processor Agreement (DPA) / Data Protection Undertaking contracts which are maintained by the IWW WISE-RA Data Protection Officer. The IWW DPA / Data Protection Undertaking for individual Authorised Data Handlers or Data Processors (individual physical persons) is an online form which can be found at https://nudb.iww.org.uk/node/1268; the template for the Organisational DPAs to be signed with third party Data Processor organisations is stored in the Data Protection folder of the Union’s Nextcloud file repository. Both DPA / Data Protection Undertaking documents are regularly updated as requirements change.
  • Regular Reviews: Review and update policies regularly, especially in response to changes in Union requirements or the Authorised Data Handlers / Data Processor’s role.
    • The Union’s Data Protection Officer works with the IT Committee and the Communications Administrator to review the “IWW Privacy and Data Protection Policy” document and all related sub-Policies and documents, including DPAs or Data Protection Undertakings. The Union’s IT Committee holds regular twice-monthly meetings during which it ensures that all policy and procedure, inventory and guidance documentation relating to the administration of the Union’s IT infrastructure are maintained up-to-date. The Union’s Data Protection and Data Security related policies are reviewed at least annually by the Data Protection Officer as provided in the section titled “Policy updates, system audits and training” in the “IWW Privacy and Data Protection Policy”
2. GDPR Compliance / Regular Audits and Compliance Reviews
  • Designated Data Protection Officer: Designate a Data Protection Officer responsible for overseeing and implementing these security measures. Provide the name and contact information of this individual to the Information Commissioner’s Office (ICO), the union membership, the public, IWW Data Subjects, and IWW Authorised Data Handlers or Data Processors.
    • The IWW WISE-RA Rulebook designates the union’s mandated Membership Officer as nominally holding the role of Data Protection Officer (or in the absence of a Membership Officer, the Union Secretary). The role may be delegated/deputised by the nominal DPO (or by a decision of the Union’s Delegates Executive Council) to an acting or elected DPO. The name, contact details and responsibilities of the current IWW WISE-RA DPO are detailed in the “IWW Privacy and Data Protection Policy” section titled “The Data Protection Officer & other roles involved in data protection”. This Policy document is accessible to the public on the IWW’s website. The current DPO is also named in all Data Processor Agreements and Data Protection Undertakings.
  • Compliance with Standards: Comply with security standards as required by the Data Protection Legislation and ICO.
    • The Union’s data security policy is detailed in the section titled “Data Security” in the “IWW Privacy and Data Protection Policy”
  • Internal Audits: Conduct regular internal audits of security practices and controls, particularly regarding the processing of Union Data.
    • The DPO is responsible for conducting & coordinating these regular audits. The DPO works with the IT Committee and Communications Administrator at regular IT Committee meetings to coordinate regular systems security audits, or audits of organisational-processes related to data processing. The Union’s data systems audits policy is detailed in the section titled “Policy updates, system audits and training” in the “IWW Privacy and Data Protection Policy”
  • Audit Reporting: Provide the Delegates Executive Council with the results of security audits or compliance reviews.
    • The IT Committee and Data Protection Officer each issue a quarterly report of their activities for each quarterly Delegates Executive Committee meeting which include the results of any audit or compliance review conducted.
  • Third-Party Audits: All IWW role holders, Authorised Data Handlers or Data Processors must allow for and contribute to audits and inspections conducted by the DPO or an auditor mandated by the DPO.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
  • Documentation Provision: All IWW role holders, Authorised Data Handlers or Data Processors must provide documentation and evidence upon request to the DPO to demonstrate compliance with the IWW’s Technical and Organisational Measures.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
  • Records of Processing Activities & Register of Systems: Maintain an accurate and regularly updated Register of Systems, including records of all categories of Processing activities carried out on behalf of the Data Controller, Processing purposes, third-party recipients of the Personal Data, data storage locations, Personal Data transfers, data retention period, any related Data Processor Agreements / Data Protection Undertaking governing the processing, and a description of the security measures in place.
    • The IWW’s Register of Systems is distributed across multiple documents and repositories, namely the “IWW Privacy and Data Protection Policy” and the included TOMs, the Union’s “IT Tools and Resources” document, the Union’s membership database system, and the Union’s Access Control List systems.
  • Assistance with DPIAs: All Authorised Data Handlers or Data Processors must assist the DPO in conducting Data Protection Impact Assessments when required under Article 35 of the UK GDPR, providing necessary information to the DPO about processing activities and potential risks.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
    • The procedures for conducting such DPIAs are detailed in the “IWW Privacy and Data Protection Policy” section titled “Using, and sharing data with third-party communications/data-processing platforms and services”.
  • Data Subject Rights Assistance: All Authorised Data Handlers or Data Processors must assist the DPO in responding to Data Subject requests under the UK GDPR, ensuring timely provision of information required to fulfil such requests.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
    • The procedures for dealing with Data Subject Requests are detailed in the “IWW Privacy and Data Protection Policy” section titled “Policy and procedures for handling Subject Access Requests and other requests by Data Subjects”.
  • DPO Cooperation: All Authorised Data Handlers or Data Processors must Cooperate with the DPO, providing access to necessary information to perform their duties effectively.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
  • Regulatory Cooperation: The DPO and all Authorised Data Handlers or Data Processors must cooperate fully with the Information Commissioner’s Office (ICO) or other relevant Regulatory Authorities in the performance of their tasks. Authorised Data Handlers or Data Processors must provide the DPO with rapid (and if possible, prior) notice of all communications from or investigations by the ICO or Regulatory Authorities unless otherwise mandated by legislation or the Regulatory Authority. Authorised Data Handlers or Data Processors must keep the DPO informed at all times of ongoing communications or cooperation with Regulatory Authorities.
    • This obligation is included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
3. Personnel and Data Access Policies
  • Security Awareness Training: Provide basic security awareness training as well as Security Incident response training for all personnel during onboarding and periodically thereafter.
    • The DPO will work with the IT Committee and Training Committee to produce and regularly update a data protection training course for the Union’s role holders. The DPO will ensure that these trainings are held at least annually. The Union’s data protection training policy is detailed in the section titled “Policy updates, system audits and training” in the “IWW Privacy and Data Protection Policy”
  • Termination Procedures: Implement appropriate access control and access termination procedures for personnel with access to information systems, ensuring access rights are promptly revoked upon termination or role change.
    • The IWW’s Access Control Policy is outlined in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Access Control Policy”.
    • Commencement and termination of data access for Authorised Data Handlers or Data Processors is robustly managed through the Union’s Access Control List systems, which are automatically and electronically linked to a registry of role holders on the IWW Membership Database which is actively maintained up to date by the IWW Communications Administrator. Only persons who are bound by a DPA or Data Protection Undertaking are granted access to Personal Data under the IWW’s care.
  • Access Control: Implement appropriate access control procedures for internal IWW Personnel and external parties granted access to information systems.
    • The same Access Control system as described above is used, and additionally. The IT Committee and Communications Administrator only grants credentials for systems access to authorised external parties who have signed DPAs or Data Protection Undertaking and Service Contracts with the IWW.
  • Confidentiality Agreements: Require all personnel, including employees and subcontractors, to sign confidentiality agreements to protect union data and ensure compliance with UK GDPR.
    • The “Privacy and Data Protection Policy” stipulates that all Authorised Data Handlers or are required to sign IWW WISE-RA Data Protection Agreement (DPA) / Data Protection Undertaking contracts which are maintained by the IWW WISE-RA Data Protection Officer with the help of the Communications Administrator, and recorded on the IWW Membership Database (for the online Data Processor Agreements / Data Protection Undertakings signed by individual Authorised Data Handlers or Data Processors) or the Data Protection folder of the Union’s Nextcloud file repository (for Organisational DPAs signed by third party Data Processor organisations).
    • The contents of IWW DPAs / Data Protection Undertakings are stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertaking. This obligation is enforced by the DPO.
  • Outsourcing Restrictions: Do not outsource information security functions or data processing functions to third parties without prior approval from the DPO.
    • The Union’s policy regarding sharing data processing and information security functions with third parties is detailed in the section titled “Sharing of information” of the “IWW Privacy and Data Protection Policy” and more specifically in the subsection titled “Using, and sharing data with third-party communications/data-processing platforms and services”. These sections outline stringent restrictions and conditions on any form of data sharing or outsourcing of data processing (including DPIAs, DPO approval, democratic mandates by the relevant IWW bodies, and data Subject Consent).
    • This policy is also outlined in all IWW Data Processor Agreements / Data Protection Undertakings, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings. This obligation is enforced by the DPO.
  • Liability Insurance: Maintain appropriate liability insurance, including cyber liability insurance, in addition to general liability insurance. The union maintains appropriate liability insurance.
    • The Union maintains a liability insurance policy which includes cyber liability insurance.
  • Geographical Compliance: Ensure that all employees/staff/personnel and physical office locations comply with UK Data Protection Legislation.
    • The “Privacy and Data Protection Policy”, particularly the section titled “Transfers overseas” in the “IWW Privacy and Data Protection Policy”, as well as all Union DPAs or Data Protection Undertaking outline geographical compliance requirements and the DPO regularly monitors for compliance.
4. Access Control
  • User Access Management: Ensure that access to Union Data is granted strictly based on role and necessity, particularly for sensitive Personal Data and Special Category Data.
    • The IWW’s Access Control Policy is outlined in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Access Control Policy”.
    • Commencement and termination of data access for Authorised Data Handlers or Data Processors is robustly managed through the Union’s Access Control List systems, which are automatically and electronically linked to a registry of role holders on the IWW Membership Database which is actively maintained up to date by the IWW Communications Administrator. Only persons who are bound by a DPA / Data Protection Undertaking are granted access to Personal Data under the IWW’s care.
  • Authentication/Verification Protocols: Use robust authentication methods, including multi-factor authentication (MFA), combined with Access Control Lists for systems that contain or control access to Union Personnel and Members’ Personal Data and platform permissions, preventing unauthorized actions.
  • Access Reviews: Regularly audit user access levels to ensure that only authorised Union personnel, members, and Authorised Data Handlers or Data Processor staff have appropriate access to sensitive areas.
  • Activity Logging and Monitoring: Log all administrative activities related to user permissions, data access, and system changes. Monitor these logs for unusual or unauthorised access.
5. Data Minimisation and Retention 6. Pseudonymisation and Anonymisation
  • Data Protection Techniques: Where applicable, implement pseudonymisation and anonymisation techniques for Personal Data within Union or Authorised Data Handler or Data Processor systems or during any data extraction, especially if used in analytics or reporting.
    • Measures concerning pseudonymisation and anonymisation are included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings.
    7. Data Encryption
    • Data at Rest: Encrypt all Union Data including data stored on servers and backups, using strong encryption standards (e.g., AES-256).
      • We ensure strong encryption standards for all data stored on Union controlled servers and backups. Specific measures for data encryption and the encryption of stored data are also included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings.
    • Data in Transit: Ensure all data transmitted between systems is protected using secure communication protocols such as TLS 1.2 or higher.
      • We ensure strong encryption standards for all data we transmit between systems, including TLS 1.2 or higher for SMTP and IMAP connections to email servers. Specific measures for data encryption and the encryption of transmitted data are also included in every Data Processor Agreement / Data Protection Undertaking that Authorised Data Handlers or Data Processors must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsections of the current TOMs section titled “Specific Technical Security Measures Applying to Individual Authorised Data Handlers or Data Processors (physical persons)” and “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings.
    • Cryptographic Protocols: Issue public key certificates and/or obtain them from approved service providers.
      • We meet this obligation for all our online websites, ensuring https:// connections. This obligation is also imposed via the Data Processor Agreements that third-party IWW Data Processor Organisations must sign, as stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy” and in the subsection of the current TOMs section titled “Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement”, which are included as part of all IWW DPAs or Data Protection Undertakings.
    8. Physical Security
    • Access Restrictions: For physical infrastructure managed by the Data Controller or Data Processor (e.g., data centres), ensure access is restricted to authorised personnel only. Use mechanisms like key cards, biometric access controls, and physical surveillance.
    • Secure Off-Site Backups: Maintain off-site backups in physically secure locations to protect against physical threats like theft, fire, or damage.
    9. System Configuration
    • System Inventory: Maintain an accurate and current documented inventory of system components. Review and update this inventory regularly.
    • Configuration Management: Document and approve deviations from established configuration settings. Restrict or prohibit the use of non-essential functions, ports, protocols, and services.
    10. System Maintenance
    • Maintenance Monitoring: Monitor all maintenance activities.
    • Tool Control: Control and monitor all information system maintenance tools.
    • Activity Records: Maintain records for all maintenance and diagnostic activities.
    • Authorized Personnel: Maintain a list of authorised maintenance personnel. Ensure they have the required access authorisations.
    11. Systems and Network Security Monitoring and Vulnerability and Patch Management
    • Risk Mitigation: Implement measures to mitigate any identified risks as determined by Data Processing Impact Assessments (DPIAs), in coordination with the Data Controller.
    • Regular Security Testing: Regularly test, assess, and evaluate the effectiveness of Technical and Organisational Measures to ensure processing security.
    • Protective Measures: Implement firewalls, anti-virus software, and intrusion detection/prevention systems to safeguard the Union’s Data and IT infrastructure.
    • Continuous Monitoring: Utilize a continuous monitoring strategy for information systems to detect attacks, potential attacks, and unauthorized use.
    • Network Monitoring: Ensure all network connections are monitored for suspicious activity.
    • Result Analysis: Analyze continuous monitoring results to identify and address security issues.
    • Vulnerability Assessments and Testing: Regularly assess systems for vulnerabilities, particularly systems where Union Data is stored/Processed, to prevent exploitation. Regularly test systems for vulnerabilities to prevent exploitation with periodic vulnerability scans and penetration tests on systems handling Personal Data, addressing any identified issues promptly.
    • Software Testing: Test software and firmware updates for effectiveness and potential side effects before installation.
    • Compliance Monitoring: Monitor security controls for compliance and take actions if components are deemed non-compliant.
    • Timely Patching: Apply security patches and updates in a timely manner. Implement patches categorized as “critical” within 72 hours of release.
    • Patch Management Process: Use Development, Test, QA, and Production environments during the patch management process.
    12. Vulnerability Awareness
    • Anti-Virus Protection: Ensure that systems have anti-virus software running with current, updated virus definition files.
    • Threat Intelligence: Subscribe to external security alerts, lists, and bulletins related to the information systems used.
    • External Security Alerts: Subscribe to external security alerts and advisories related to information systems.
    • Internal Security Alerts: Generate and disseminate internal security alerts, advisories, and directives as deemed necessary.
    13. Backup and Recovery
    • Regular Backups: Perform regular backups of critical systems, especially those containing Union Data.
    • Backup Security: Protect the confidentiality, integrity, and availability of backup information at storage locations.
    • Recovery Procedures: Regularly test recovery procedures to validate the ability to restore systems in the event of data loss, corruption, or breach.
    • Contingency Planning: Ensure recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.
    • Alternate Storage Site: Utilize an alternate storage site to permit the storage and recovery of backup information, providing equivalent security safeguards as the primary site.
  • Alternate Communication Means: Ensure alternate forms of telecommunication are available should primary means be unavailable.
  • 14. Incident Management and Breach Notification
  • Incident Response Plan: Implement an incident response plan to manage Security Incidents or Personal Data breaches involving Union Data.
  • Incident Response Training: Provide staff with incident response training to respond appropriately and immediately to information spillages.
  • Immediate Reporting: Ensure that any Security Incident or Personal Data Breach related to Union Data or Union/Data Processor system functionality are reported to the Union’s Data Protection Officer, where feasible, within 24 hours of becoming aware of it, pursuant to DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Assistance: Provide all necessary assistance for breach reporting to the Information Commissioner’s Office (ICO) or notification to members as required by law.
  • Incident Tracking: Track and document all Security Incidents as part of continuous improvement.
15. Sub-processor Management
  • Approval for Subprocessors: Obtain the Union’s approval before engaging any sub-processors to Process Union Data or administer the Union’s IT infrastructure pursuant to DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Equivalent Obligations: Ensure that any sub-processors are bound by equivalent security measures and Data Protection obligations as per DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Regular Audits: Regularly audit sub-processors to ensure compliance and keep the Union informed of any relevant audit results or findings.
16. International Data Transfers
  • Specific Conditions for International Transfers: The general policy and specific conditions to be met for authorising International Data Transfers are detailed in the “IWW Privacy and Data Protection Policy” section titled “Transfers Overseas” and the subsection titled “Further details about our policy for transfers of personal data to countries outside the UK and EEA”.
  • DPIA for International Transfers: Additionally, a it is necessary to conduct a Data Protection Impact Assessment (DPIA) prior to approving International Transfers. The procedures for conducting such DPIAs are detailed in the “IWW Privacy and Data Protection Policy” section titled “Using, and sharing data with third-party communications/data-processing platforms and services”. International Transfers should not be performed if the DPIA’s conclusions are negative.
  • Approval for International Transfers: Obtain the Data Protection Officer’s approval before engaging in international transfers of Union Data.
  • Transfer Compliance: Ensure that any transfer of Personal Data outside the UK or EEA complies with Chapter V of the UK GDPR, using approved transfer mechanisms such as Standard Contractual Clauses or Binding Corporate Rules.
  • Data Transfer Agreements: Enter into data transfer agreements as required to lawfully transfer Personal Data internationally.


⚠ Minimal Organisational TOMs we Require our Third Party Data Processor Organisations to Implement

⚠ This section specifies the minimal Technical and Organisational Measures that third party Organisational Data Processors authorised by the IWW WISE-RA are required to implement whenever accessing and processing IWW WISE-RA data and IWW Data Subjects’ Personal Data:

The Data Processor agrees to implement and maintain the following Technical and Organisational Measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR and the specific requirements of the Union’s IT infrastructure. These measures are designed to protect the confidentiality, integrity, and availability of personal data processed on behalf of the IWW.

1. Information Security Policies
  • Policy Maintenance: Maintain and implement a documented information security policy that includes guidelines to safeguard the confidentiality, integrity, and availability of Union Data.
  • Documented Procedures: Ensure that these policies include specific and formally documented provisions and procedures for access control management, systems configuration and maintenance, data encryption, maintenance of information systems’ physical security, systems and network security and functionality monitoring, vulnerability and patch management, security incident management, and backup and recovery protocols.
  • Enhanced Confidentiality Measures: Implement specific measures to protect all confidential information, ensuring it is not disclosed without prior written consent from the Data Controller.
  • Regular Reviews: Review and update policies regularly, especially in response to changes in Union requirements or the Data Processor’s role.
2. GDPR Compliance / Regular Audits and Compliance Reviews
  • Designated Security Leader: Designate an Information Security Leader / Data Protection Manager / Data Protection Officer responsible for overseeing and implementing these security measures. Provide the name and contact information of this individual to the Union.
  • Compliance with Standards: Comply with specific security standards as required by the Data Controller, such as ISO 27001 or other relevant certifications. Provide evidence of compliance, including certificates or audit reports.
  • Internal Audits: Conduct regular internal audits of security practices and controls, particularly regarding the processing of Union Data.
  • Audit Reporting: Provide the Union with the results of security audits or compliance reviews.
  • Third-Party Audits: Allow for and contribute to audits and inspections conducted by the Data Controller or an auditor mandated by the Data Controller.
  • Documentation Provision: Provide documentation and evidence upon request to the Data Controller to demonstrate compliance with the Technical and Organisational Measures.
  • Records of Processing Activities & Register of Systems: Maintain an accurate and regularly updated Register of Systems, including records of all categories of Processing activities carried out on behalf of the Data Controller, Processing purposes, third-party recipients of the Personal Data, data storage locations, Personal Data transfers, data retention period, any related Data Processor Agreements governing the processing, and a description of the security measures in place. The Register of Systems should be made available upon request.
  • Assistance with DPIAs: Assist the Data Controller in conducting Data Protection Impact Assessments when required under Article 35 of the UK GDPR, providing necessary information to the Data Controller about processing activities and potential risks.
  • Data Subject Rights Assistance: Assist the Data Controller in responding to Data Subject requests under the UK GDPR, ensuring timely provision of information required to fulfill such requests. Refrain from responding directly to Data Subjects unless authorized by the Data Controller.
  • DPO Cooperation: Cooperate with the Data Controller’s Data Protection Officer, providing access to necessary information to perform their duties effectively.
  • Regulatory Cooperation: Cooperate fully with the Information Commissioner’s Office (ICO) or other relevant Regulatory Authorities in the performance of their tasks. Provide the Data Controller with prior notice unless otherwise mandated by legislation or the Regulatory Authority. Keep the Data Controller informed at all times of ongoing communications with Regulatory Authorities.
3. Personnel and Data Access Policies
  • Security Awareness Training: Provide basic security awareness training as well as Security Incident response training for all personnel during onboarding and periodically thereafter.
  • Termination Procedures: Implement appropriate termination procedures for personnel with access to information systems, ensuring access rights are promptly revoked upon termination or role change.
  • Third-Party Access Control: Implement appropriate access control procedures for external parties granted access to information systems.
  • Confidentiality Agreements: Require all personnel, including employees and subcontractors, to sign confidentiality agreements to protect union data and ensure compliance with UK GDPR.
  • Outsourcing Restrictions: Do not outsource information security functions or data processing functions to third parties without prior approval from the Union.
  • Liability Insurance: Maintain appropriate liability insurance, including cyber liability insurance, in addition to general liability insurance.
  • Geographical Compliance: Ensure that all personnel and physical office locations comply with UK Data Protection Legislation.
4. Access Control
  • User Access Management: Ensure that access to Union Data is granted strictly based on role and necessity, particularly for sensitive Personal Data and Special Category Data.
  • Authentication/Verification Protocols: Use robust authentication methods, including multi-factor authentication (MFA), combined with Access Control Lists for systems that contain or control access to Union Personnel and Members’ Personal Data and platform permissions, preventing unauthorized actions.
  • Access Reviews: Regularly audit user access levels to ensure that only authorised Union personnel, members, and Data Processor staff have appropriate access to sensitive areas.
  • Activity Logging and Monitoring: Log all administrative activities related to user permissions, data access, and system changes. Monitor these logs for unusual or unauthorised access.
5. Data Minimisation and Retention
  • Data Limitation: Ensure that Union Data Processed within the Union’s systems or the Data Processor’s systems is limited to what is necessary for the specific tasks defined in the contract.
  • Retention Policies: Implement appropriate data retention and deletion policies to ensure Personal Data is only retained for as long as necessary.
  • Secure Disposal: Securely delete or anonymize Personal Data when no longer required.
  • Data Return or Deletion: Upon termination of services, return all Union Data & Personal Data to the Data Controller or securely delete it as instructed, providing confirmation of deletion.
6. Pseudonymisation and Anonymisation
  • Data Protection Techniques: Where applicable, implement pseudonymisation and anonymisation techniques for Personal Data within Union or Data Processor systems or during any data extraction, especially if used in analytics or reporting.
7. Data Encryption
  • Data at Rest: Encrypt all Union Data including data stored on servers and backups, using strong encryption standards (e.g., AES-256).
  • Data in Transit: Ensure all data transmitted between systems is protected using secure communication protocols such as TLS 1.2 or higher.
  • Cryptographic Protocols: Issue public key certificates and/or obtain them from approved service providers.
8. Physical Security
  • Access Restrictions: For physical infrastructure managed by the Data Processor (e.g., data centres), ensure access is restricted to authorised personnel only. Use mechanisms like key cards, biometric access controls, and physical surveillance.
  • Secure Off-Site Backups: Maintain off-site backups in physically secure locations to protect against physical threats like theft, fire, or damage.
9. System Configuration
  • System Inventory: Maintain an accurate and current documented inventory of system components. Review and update this inventory regularly.
  • Configuration Management: Document and approve deviations from established configuration settings. Restrict or prohibit the use of non-essential functions, ports, protocols, and services.
10. System Maintenance
  • Maintenance Monitoring: Monitor all maintenance activities.
  • Tool Control: Control and monitor all information system maintenance tools.
  • Activity Records: Maintain records for all maintenance and diagnostic activities.
  • Authorized Personnel: Maintain a list of authorised maintenance personnel. Ensure they have the required access authorisations.
11. Systems and Network Security Monitoring and Vulnerability and Patch Management
  • Risk Mitigation: Implement measures to mitigate any identified risks as determined by Data Processing Impact Assessments (DPIAs), in coordination with the Data Controller.
  • Regular Security Testing: Regularly test, assess, and evaluate the effectiveness of Technical and Organisational Measures to ensure processing security.
  • Protective Measures: Implement firewalls, anti-virus software, and intrusion detection/prevention systems to safeguard the Union’s Data and both the Union’s and the Data Processor’s IT infrastructure.
  • Continuous Monitoring: Utilize a continuous monitoring strategy for information systems to detect attacks, potential attacks, and unauthorized use.
  • Network Monitoring: Ensure all network connections are monitored for suspicious activity.
  • Result Analysis: Analyse continuous monitoring results to identify and address security issues.
  • Vulnerability Assessments and Testing: Regularly assess systems for vulnerabilities, particularly systems where Union Data is stored/Processed, to prevent exploitation. Regularly test systems for vulnerabilities to prevent exploitation with periodic vulnerability scans and penetration tests on systems handling Personal Data, addressing any identified issues promptly.
  • Software Testing: Test software and firmware updates for effectiveness and potential side effects before installation.
  • Compliance Monitoring: Monitor security controls for compliance and take actions if components are deemed non-compliant.
  • Timely Patching: Apply security patches and updates in a timely manner. Implement patches categorized as “critical” within 72 hours of release.
  • Patch Management Process: Use Development, Test, QA, and Production environments during the patch management process.
12. Vulnerability Awareness
  • Anti-Virus Protection: Ensure that systems have anti-virus software running with current, updated virus definition files.
  • Threat Intelligence: Subscribe to external security alerts, lists, and bulletins related to the information systems used.
  • External Security Alerts: Subscribe to external security alerts and advisories related to information systems.
  • Internal Security Alerts: Generate and disseminate internal security alerts, advisories, and directives as deemed necessary.
13. Backup and Recovery
  • Regular Backups: Perform regular backups of critical systems, especially those containing Union Data.
  • Backup Security: Protect the confidentiality, integrity, and availability of backup information at storage locations.
  • Recovery Procedures: Regularly test recovery procedures to validate the ability to restore systems in the event of data loss, corruption, or breach.
  • Contingency Planning: Ensure recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.
  • Alternate Storage Site: Utilize an alternate storage site to permit the storage and recovery of backup information, providing equivalent security safeguards as the primary site.
  • Alternate Communication Means: Ensure alternate forms of telecommunication are available should primary means be unavailable.
14. Incident Management and Breach Notification
  • Incident Response Plan: Implement an incident response plan to manage Security Incidents or Personal Data Breaches involving Union Data.
  • Incident Response Training: Provide staff with incident response training to respond appropriately and immediately to information spillages.
  • Immediate Reporting: Ensure that any Security Incident or Personal Data Breach related to Union Data or Union/Data Processor system functionality are reported to the Union’s Data Protection Officer, where feasible, within 24 hours of becoming aware of it, pursuant to DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Assistance: Provide all necessary assistance for breach reporting to the Information Commissioner’s Office (ICO) or notification to members as required by law.
  • Incident Tracking: Track and document all Security Incidents as part of continuous improvement.
15. Sub-processor Management
  • Approval for Subprocessors: Obtain the Union’s approval before engaging any sub-processors to Process Union Data or administer the Union’s IT infrastructure pursuant to DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Equivalent Obligations: Ensure that any sub-processors are bound by equivalent security measures and Data Protection obligations as per DPA or Data Protection Undertaking and Union Data Policy requirements.
  • Regular Audits: Regularly audit sub-processors to ensure compliance and keep the Union informed of any relevant audit results or findings.
16. International Data Transfers
  • Approval for International Transfers: Obtain the Union’s approval before engaging in any international transfers of Union Data.
  • DPIA for International Transfers: Conduct a Data Protection Impact Assessment (DPIA) prior to proposed International Transfers. Share the DPIA results with the IWW Data Protection Officer for approval/rejection. International Transfers must not be performed if the DPIA’s conclusions are negative.
  • Transfer Compliance: Ensure that any transfer of Personal Data outside the UK or EEA complies with Chapter V of the UK GDPR, using approved transfer mechanisms such as Standard Contractual Clauses or Binding Corporate Rules.
  • Data Transfer Agreements: Enter into data transfer agreements as required to lawfully transfer Personal Data internationally.

By adhering to these Technical and Organisational Measures, the Data Processor commits to protecting the IT infrastructure and Personal Data under the care of the IWW, ensuring compliance with UK GDPR and supporting the Union’s mission to safeguard its members’ rights and information.


Access to membership records, contact lists, casework records, organising records, or other personal data controlled by the IWW must be limited to persons who have a legitimate need for access arising from their office, role, task, mandate, employment, contract, or authorised union function.

Access should normally be:

  • requested through the relevant authorised process;
  • approved or countersigned by the appropriate officer, body, Data Protection Officer, Communications Administrator, IT Committee, or other authorised person;
  • recorded in the relevant access-control system or access log;
  • conditional on the person having signed the required Data Protection Undertaking, Data Processor Agreement, confidentiality undertaking, or equivalent agreement;
  • limited to the minimum access necessary for the role or task; and
  • time-limited by office, role, mandate, task, contract, or continuing need.

All internal IWW members or personnel who are Authorised Data Handlers and all External Data Processors who are authorised or mandated to process Personal Data on behalf of the IWW, including IWW role holders, volunteers, employees, staff, individual contactors, or third party contractor organisations, must sign a Data Protection Undertaking or Data Processor Agreement (DPA) with the IWW, in which they commit to comply with our Privacy and Data Protection Policy, Technical and Organisational Measures, and with applicable data protection laws.

The contents of IWW Data Protection Undertakings and DPAs are stipulated in the section of the “IWW Privacy and Data Protection Policy” titled “Further Details on our Data Processor Agreement and Data Protection Undertaking Policy”.

The DPO, IT Committee and Communications Administrator must implement appropriate access control and access termination procedures for personnel or external parties with access to Union information systems, ensuring access rights are promptly revoked upon termination or role change.

Commencement and termination of data access for IWW role holders, Authorised Data Handlers or Data Processors is robustly managed through the Union’s Access Control List systems, which are automatically and electronically linked to a registry of role holders on the IWW Membership Database which is actively maintained up to date by the IWW Communications Administrator. Only persons who are bound by a DPA Data Protection Undertaking are granted access to Personal Data under the IWW’s care.

The DPO, IT Committee and Communications Administrator must ensure that access to Union Data is granted strictly based on role and necessity, particularly for sensitive Personal Data and Special Category Data.

Any change in role, office, task, mandate, employment, contract, good-standing status, or continuing need for access must be reported promptly to the Data Protection Officer, Communications Administrator, IT Committee, or other person responsible for access control. Access must be removed or amended promptly when it is no longer required.

We use robust authentication methods, including (where possible/applicable/appropriate) multi-factor authentication (MFA), combined with Access Control Lists for systems that contain or control access to Union Personnel and Members’ Personal Data and platform permissions, preventing unauthorized actions.

The Data Protection Officer, Communications Administrator and IT Committee regularly audit user access levels to ensure that only authorised Union personnel, members, and authorised Authorised Data Handlers or Data Processor staff have appropriate access to sensitive areas.

The Data Protection Officer, Communications Administrator and IT Committee maintain logs of all administrative activities related to user permissions, data access, and system changes. They monitor these logs for unusual or unauthorised access.

The IWW WISE-RA Data Protection Officer (DPO) has the right to suspend access to Union IT systems or other information processing media immediately on suspicion of a breach of the terms of the Union’s Privacy and Data Protection Policy, a breach of DPA Data Protection Undertaking terms, or on suspicion of a data protection breach or any other lapse, negligence, breach or malfeasance with regard to the processing of Union data. The Communications Administrator and members of the IT Committee may do the same and shall notify the DPO immediately. All such incidents shall be reported to the next Delegates Executive Committee meeting.

Personal data exported from IWW systems, including downloaded files, spreadsheets, printed contact lists, casework notes, membership reports, email lists, or other extracted data, remains subject to this Policy. Exported data must not be shared with unauthorised persons, must be stored securely, must be password-protected or encrypted where appropriate, and must not be retained for longer than necessary.

Printed contact lists or printed records containing personal data must be kept securely, must not be left unattended or accessible to unauthorised persons, and must be securely destroyed as soon as they have served the purpose for which they were produced.

Authorised Data Handlers and Data Processors must avoid exporting data from the system in which it is normally held unless export is necessary for the authorised purpose. Where export is necessary, the exported data must be minimised, protected, tracked where appropriate, and deleted or returned when no longer needed.


⚠ Data Breaches

Personal data Breach / Security Incident definition: any incident whatsoever and howsoever caused which results (or could potentially result) in: (i) unauthorised or unlawful processing of personal data, including any unauthorised reproduction, alteration, disclosure, sale, or any other misuse or exploitation of personal data; (ii) accidental loss, destruction, or corruption of, or damage to personal data; (iii) the confidentiality, integrity, or availability of personal data otherwise becoming compromised; or (iv) the Union or a Union Authorised Data Handlers or Data Processor or service user breaching the Union’s Privacy and Data Protection Policy or related policies, or data protection legislation.

Personal data breaches, data security incidents, and any failure to comply with data protection laws or IWW policies relevant to data protection can result in disciplinary and legal action against the IWW and/or the person who has perpetrated the breach, from the Information Commissioner’s Office or from individuals affected. The IWW is exposed to potential heavy fines for failure to comply with data protection law.

Any such data breach, security incident or infringement of this Policy, related policies, or data protection laws shall be considered as a serious matter under the IWW WISE-RA’s Complaints and Disciplinary procedures.

Disciplinary or legal processes addressing data breaches, data security incidents, or infringements of this Policy, related policies, or data protection laws, as concerns data processed by, or on behalf of the IWW WISE-RA, shall be governed by the law of England and Wales.

IWW WISE-RA Authorised Data Handlers or Data Processors must notify the IWW WISE-RA Data Protection Officer of any accidental or unauthorised access of the personal data, or any breach of IWW WISE-RA policies relevant to data protection and processing that they may become aware of.

⚠ Reporting a personal data breach or data security incident.

Any suspected personal data breach, security incident, or breach of the present Policy or any related policies must be reported to the Union’s Data Protection Officer (DPO) without delay.

The applicable legislation requires Data Controllers to notify any personal data breach to the Information Commissioner’s Office (ICO) and, in certain instances, the Data Subject. This will be done by the Union’s DPO.

Where the Union acts as the Data Processor for third party Data Controller of the Personal data that is subject to the personal data breach or security incident, the Union’s DPO will immediately notify the Data Controller’s Data Protection Officer and implement their instructions.

The DPO will keep accurate records, on the Union’s Membership Database, of all information and evidence relevant to the data breach or security incident. Access to these records will be restricted at the discretion of the DPO following data minimisation and need-to-know principles as outlined in this Policy and the applicable legislation.

The DPO will conduct an investigation of any data breach or security incident and produce a Data Breach Report or Data Security Incident Report outlining the timeline, causes, effects/consequences, potential liabilities, damages and costs to all affected parties, and outlining proposed actions to address and mitigate the breach/incident, any proposed disciplinary measures on those responsible for the breach/incident, as well as proposed policy and procedure updates to prevent the recurrence of similar breaches/incidents.

This report will be submitted to the IWW WISE-RA Secretary, Delegates Executive Council (DEC), and any complaint officer and complaints panel appointed to address the breach, as well as the ICO if legally or contractually required to do so.  

The DEC will review the report’s proposals and the DPO will implement (or direct relevant Authorised Data Handlers or Data Processors to implement) any of the actions, proposals, and amended proposals that the DEC decides to enact as a result of this process.

In case of a data breach or security incident, the Union’s DPO will notify, and act as the main point of contact, with the affected Data Subjects, members and service users, Data Controllers, and/or the ICO where we are legally or contractually required to do so.

If you know or suspect that a personal data breach has occurred, do not attempt to investigate the matter yourself. Immediately contact the DPO, and follow the DPO’s instructions. You should preserve all evidence relating to the potential personal data breach or data security incident, as it will need to be attached to the data Data Breach Report or Data Security Incident Report.


⚠ Enforcement

Any data breach, security incident or infringement of this Policy, related policies, or data protection laws shall be considered as a serious matter under the IWW WISE-RA’s Complaints and Disciplinary procedures.

Disciplinary or legal processes addressing data breaches, data security incidents, or infringements of this Policy, related policies, or data protection laws, as concerns data processed by, or on behalf of the IWW WISE-RA, shall be governed by the law of England and Wales.

Infringing data protection laws or policy is a disciplinary offence and will be dealt with by the WISE-RA complaints and disciplinary procedures as appropriate.

The IWW WISE-RA Data Protection Officer (DPO) has the right to suspend database and any other access to Union IT systems or other information processing media immediately on suspicion of a breach. The Communications Administrator and members of the IT Committee may do the same and shall notify the DPO immediately. All such incidents shall be reported to the next Delegates Executive Committee meeting.


Sharing of information

We may disclose information about you to IWW officers, staff, organisers, and workplace representatives, insofar as reasonably necessary for the purposes as set out in this privacy policy.

The IWW distinguishes between:

  • Authorised persons acting under the IWW’s authority, such as officers, reps, caseworkers, staff and approved volunteers;
  • External processors, who process personal data on the IWW’s behalf under Article 28 UK GDPR;
  • Sub-processors, appointed by an external processor with the IWW’s authorisation where Article 28 requires this; and
  • Third-party controllers / controller-to-controller disclosures, where the recipient determines its own purposes and means of processing.

All Authorised Data Handlers must be subject to written confidentiality, security and data-handling obligations (Data Protection Undertakings), training, and role-based access controls. External processors and sub-processors must be engaged only where they provide sufficient guarantees and must be bound by a written Article 28-compliant Data Processor Agreement (DPA) contract.

Where the IWW relies on the not-for-profit conditions in Article 9(2)(d) or Schedule 1 paragraph 31, disclosure outside the union body will not take place unless the data subject has consented to the disclosure or another lawful route clearly applies.

⚠ Before any controller-to-controller disclosure of Special Category Data or Criminal Offence Data, the IWW will record: the purpose of the disclosure; the Article 6 basis; the Article 9 or Article 10 / Schedule 1 condition; the minimum data necessary; the recipient category; and any consent, authority or safeguard relied upon. 

⚠ In the context of an official IWW WISE-RA complaints process, investigation or mediation process, when an officially appointed or elected mediation officer, complaints officer, investigating officer or the members of an appointed investigation or complaints panel require access to personal data to complete their mandated duties, they will, as all other Authorised Data Handlers or Data Processors, be required to sign a Data Protection Undertaking or Data Processor Agreement (DPA), and the Data Protection Officer should record their authorisation for the data access with their approval of the undertaking or DPA. When personal information is sought in this way, the mediation officer, complaints officer, investigating officer or the members of an appointed investigation or complaints panel may, at their discretion, opt to not inform the Data Subject about their access to the Data Subject’s personal data, if they deem this to be in the legitimate interest of the Union and conducting the process fairly and successfully. However, when information has been sought in this way, the Data Processors must inform the member at the end of the process (and in advance of relevant formal meetings), even if no further procedure or action is taken.

We may need to disclose limited information about you to Webarchitects, the web service cooperative that hosts our website, email list and email servers, in order to administer our websites and provide our online services for members.

If you make monthly recurring membership dues payments through our payment provider, you will be sharing your payment details with our third-party payment processor, GoCardless.

We may need to disclose information about you to third party contractors or services we use for any of the data processing purposes listed above; for example, to maintain or upgrade our IT systems and membership database. Where this is necessary, we ensure appropriate data protection measures are in place.

If you purchase items on our online shop, you may need to provide your payment details to PayPal or we may need to share your payment details with another card payment processor. We will also need to share your name and shipment address with the Royal Mail or other courier or postal services we might use to send you the goods you purchase.

The IWW will not disclose any of your personally identifiable information to any other third party unless it is justified by:

  • the lawful basis of pursuing our legitimate interests as a trade union;
  • or it is necessary to fulfil our contractual obligations;
  • or we have your explicit consent to do so;
  • or it is necessary to protect someone’s life;
  • or we are required to do so by law.

⚠ Generally, we are not allowed to share personal data with third-parties unless certain safeguards and contractual arrangements have been put in place.

⚠ Our Authorised Data Handlers or Data Processors may only share the personal data we hold with another IWW Authorised Data Handlers or Data Processor if the recipient has signed an IWW WISE-RA Data Protection Undertaking or Data Processor Agreement and has a job-related need to know the information.

⚠ In addition to the justifications for sharing personal data listed above, we may only share the personal data we hold with third parties, such as our service providers if:

  • they have a need to know the information for the purposes of providing contracted services;
  • sharing the personal data complies with the Privacy Notice and Privacy and Data Protection Policy provided to the Data Subject and, if required by the present Policy, the Data Subject’s consent has been obtained;
  • the third-party’s data processing systems comply with the required data security standards, policies and procedures and use of the third-party’s data processing services is authorised by the IWW WISE-RA Data Protection Officer and formally mandated by the IWW’s governing bodies, and/or the third-party service provider puts adequate security measures in place by entering into a Data Processor Agreement (DPA) with the Union;
  • sharing the personal data complies with any relevant or applicable DPA between the Union and the third-party Data Controller / the Data Processor / the Data Subject (as relevant to the specific circumstances) that is the source or initial provider of the data;
  • the data sharing constitutes a data transfer that complies with any applicable cross border transfer restrictions.

Disclosures not directly related to the original reason why data is held

Personal data must not be disclosed for purposes unrelated to the reason for which it was collected unless the disclosure is lawful, necessary, proportionate, and authorised in accordance with this Policy.

⚠ Where a proposed disclosure is likely to be at the request of, or in the interests of, the data subject, the normal approach is to obtain and record the data subject’s informed consent or other recorded authorisation, unless another lawful basis is more appropriate and the disclosure is fair and transparent.

⚠ Where a proposed disclosure arises in the context of an internal union investigation, complaint, disciplinary matter, safeguarding concern, official investigation, legal obligation, regulatory request, or other exceptional circumstance, the person handling the matter must consult the Data Protection Officer unless urgent circumstances make prior consultation impracticable. The Data Protection Officer, or an authorised delegate where appropriate, must record the basis for the disclosure, the information disclosed, the recipient, the purpose, and any decision not to inform the data subject at that stage.

⚠ Where information has been obtained or disclosed without notifying the data subject because notification would prejudice an investigation, safeguarding action, legal rights, legal obligations, confidentiality, or another lawful purpose, the data subject should be informed as soon as it is lawful, fair and practicable to do so, unless an applicable exemption or continuing risk justifies withholding notification.

Further Details on Our Data Processor Agreement and Data Protection Undertaking Policy

The IWW distinguishes between:

  1. External Data Processors, meaning external organisations or individuals who process personal data on behalf of the IWW as a separate party; and
  2. Authorised Data Handlers, meaning officers, staff, accredited Reps, caseworkers, committee members, organisers, phonebankers, volunteers, contractors embedded within the IWW’s operations, and any other persons formally authorised by the IWW to process personal data under the IWW’s authority and instructions.

This distinction reflects the structure of UK GDPR Articles 28 and 29 and ICO guidance on controllers and processors.

External Data Processors must not process any IWW-controlled personal data unless they are appointed under a written Article 28 Data Processing Agreement or another written legal act compliant with UK GDPR. The IWW will use only processors providing sufficient guarantees that they will implement appropriate technical and organisational measures so that the processing meets the requirements of the UK GDPR and protects the rights of data subjects.

Authorised Data Handlers must not access or process IWW-controlled personal data unless they have first signed an Individual Data Protection Undertaking, completed any required induction or training, been granted role-appropriate access, and been instructed on the purpose, scope and limits of the processing they are authorised to carry out. Persons acting under the IWW’s authority may process personal data only on the IWW’s instructions and only within the scope of their role, mandate, task or appointment.

An Article 28 Data Processing Agreement is required whenever a separate outside party processes personal data on the IWW’s behalf. This includes, for example, database developers, migration contractors, software support providers, hosting providers, cloud storage providers, mailing houses, external administrators, outsourced case-management or communications providers, and external individual consultants where they are acting as processors rather than as controllers in their own right.

An Individual Data Protection Undertaking is required whenever a natural person is granted access to IWW personal data under the IWW’s own authority, including internal office holders, role holders, staff, accredited Reps, committee members, caseworkers, organisers, internal volunteers, and formally appointed non-member volunteers operating within the IWW’s structure. In such cases, the Undertaking serves as the IWW’s internal confidentiality, instruction, security and accountability instrument; it is distinct from an organisation-to-organisation Article 28 Data Processing Agreement.

Every Article 28 Data Processing Agreement used by the IWW must, at minimum, identify:

  • the subject-matter and duration of the processing;
  • the nature and purpose of the processing;
  • the type of personal data;
  • the categories of data subjects; and
  • the obligations and rights of the IWW as controller.

It must also require the processor to:

  • process the data only on documented IWW instructions;
  • ensure confidentiality;
  • apply Article 32 security measures;
  • obtain prior written authorisation before appointing any sub-processor;
  • assist the IWW with data subject rights requests;
  • assist the IWW with compliance under Articles 32 to 36 UK GDPR;
  • delete or return the data at the end of the relationship; and
  • make information available to demonstrate compliance and permit audits or inspections.

In addition, every IWW Article 28 Data Processing Agreement must address:

  • personal data breach reporting to the IWW without undue delay;
  • restrictions on international transfers and remote access outside the UK/EEA without the IWW’s prior written approval and the required legal safeguards;
  • cascade-down obligations for sub-processors;
  • cooperation with the ICO and other lawful supervisory or regulatory requests;
  • record-keeping;
  • retention and secure deletion; and
  • contractual allocation of liability, remedies, suspension and termination rights.

Some of these matters arise expressly under UK GDPR Articles 30, 31, 32, 33 and 82 rather than Article 28 alone, but the IWW requires them to be addressed in all processor agreements.

Every Individual Data Protection Undertaking used by the IWW must, at minimum, require the signatory to:

  • keep personal data confidential;
  • process personal data only for authorised IWW purposes;
  • access only the minimum data necessary;
  • follow all IWW instructions, policies and technical controls;
  • keep devices, passwords, accounts and communications channels secure;
  • report suspected or actual breaches, phishing incidents, malware incidents, device loss, or unauthorised access immediately;
  • forward data subject requests to the IWW Data Protection Officer without answering them unless authorised;
  • avoid copying, exporting or sharing personal data except where strictly necessary and authorised;
  • return or securely destroy data and credentials when their role ends or on request; and
  • understand that breach of the Undertaking may lead to suspension of access, removal from role, contractual sanctions, internal discipline, or further legal action where appropriate.

Where processing involves Special Category Data under Article 9 UK GDPR, no person may process that data for the IWW unless the IWW has identified and documented both an Article 6 lawful basis and an Article 9 condition, together with any applicable Schedule 1 Data Protection Act 2018 condition and Appropriate Policy Document requirements. Access to Special Category Data must be limited to those with a clear need to know; higher-risk processing must be considered for a Data Protection Impact Assessment; and enhanced technical and organisational safeguards must be applied.

Where processing involves Criminal Offence Data under Article 10 UK GDPR, no person may process that data for the IWW unless the IWW has identified and documented an Article 6 lawful basis, the relevant Article 10 route, the applicable Schedule 1 Data Protection Act 2018 condition, and any Appropriate Policy Document requirement. For the IWW this may, depending on context, include conditions such as employment, social security and social protection; safeguarding of children and individuals at risk; consent; not-for-profit bodies; or legal claims. Criminal Offence Data must be handled with especially strict access control, confidentiality, retention discipline, and logging.

The IWW must keep records sufficient to demonstrate compliance with this policy. These records should include, where applicable:

  • signed Article 28 Data Processing Agreements;
  • signed Individual Data Protection Undertakings;
  • Article 30 records of processing;
  • access approvals;
  • access revocations;
  • role-based access logs;
  • training logs;
  • Legitimate Interests Assessments where legitimate interests is relied upon;
  • Data Protection Impact Assessments for high-risk processing;
  • Appropriate Policy Documents where required;
  • breach logs; and
  • audit records showing processor or handler compliance.

The IWW may authorise a volunteer or non-member to act on its behalf where this is necessary for union functions and the person is operating under IWW authority rather than independently. Before such authorisation is granted, the IWW must record the person’s role, scope of authority, supervising officer or committee, systems they may use, data they may access, lawful purpose, training completed, and whether they are covered by an Undertaking or, if they are a separate external service provider, an Article 28 Data Processing Agreement. A volunteer or non-member must not be used as an informal private workaround to avoid IWW controls or external restrictions.

IWOC and Find a Prisoner procedure

Prison-location or prisoner-contact requests using IWW-held information may be made only by Authorised Data Handlers specifically approved for that purpose by IWOC and, where required by internal procedure, by the Data Protection Officer. The handler must use only the minimum data necessary, must record the request and outcome, and should use an IWW-controlled email account or other approved IWW communication channel wherever practicable.

Where possible, the incarcerated member’s authorisation to seek prison-location or contact information should be obtained and recorded in advance. If prior authorisation is unavailable because contact has been lost, requests should be narrowly framed and treated as safeguarding/contact-restoration activity, with Data Protection Officer review or retrospective review recorded in the case log.

No officer, member, partner, friend or supporter may submit such requests privately using IWW-held data unless they have been formally authorised by the IWW and have signed the relevant Undertaking.

⚠ Using, and sharing data with third-party communications/data-processing platforms and services

No discussion or decision-making about internal union business, and no discussion or processing of personal data under the care of the IWW WISE-RA should be done on third-party communications or data-processing platforms or services, unless it is first authorised by the Union’s Data Protection Officer and then: a) formally and democratically mandated by the Union or a constitutive body of the Union to which that data strictly pertains; or b) the third-party data processor is hired as a service provider by the IWW, and their processing of IWW data, including personal data under the IWW’s care, is bound by a Data Processor Agreement between the IWW and that third-party service provider.

WISE-RA bans posting, discussing or revealing the following information on any non-mandated or unauthorised third-party data processing services or platforms:

  • any information that would constitute a breach of union rules covering mutual consent, safer spaces, confidentiality, trust, data protection and communications channels usage rules;
  • any Union discussions, decision-making, information or affairs that are currently held on, or for which the principle of ensuring optimal data-protection / data-security / operational-security would dictate that they should best/only be held on IWW WISE-RA controlled communications or data-processing channels;
  • information about disputes or complaints that are or should be subject to the union’s internal complaints/mediation process, or that is embargoed as a result of the union’s complaints/mediation process;
  • any member’s or IWW WISE-RA Data Subject’s personal data, including their name, links to their social media accounts, photos, or any other personally identifying information, unless such information is posted or revealed with that member’s explicit consent.

Membership data and any personal data under the care of the IWW WISE-RA must not be used for the purposes of administering third-party communications or data-processing services/platforms, unless it is first authorised by the Union’s Data Protection Officer (DPO) and then: a) formally and democratically mandated by the union or a constitutive body of the union to which that data strictly pertains; or b) the third-party data processor is hired as a service provider by the IWW, and their processing of IWW data, including personal data under the IWW’s care, is bound by a Data Processor Agreement between the IWW and that third-party service provider.

⚠ Mandating the use of membership data or IWW Data Subjects’ personal data for the purposes of processing it on, or administering third party platforms is discouraged, except where it is necessary to engage a third party data processor as a service provider subject to a Data Processor Agreement with the Union. Likewise, Mandating the use of third-party platforms to discuss or decide internal union business is discouraged. IWW-controlled, internal communications platforms and tools should be given priority preference for all IWW communications and data processing.

⚠ When a third-party communications service/platform or a third-party Data Processor is proposed/envisaged for use and data sharing, including where international transfers of data would be involved, the DPO will conduct a Data Protection impact Assessment (DPIA), to assess whether:

  • the proposed processing can be considered necessary and proportional in relation to its purpose;
  • an existing communications or data processing platform/tool fully controlled by the IWW WISE-RA, or the IWW’s own personnel and volunteers can adequately fulfill the same functions/services;
  • a communications or data processing platform/tool fully controlled by the IWW WISE-RA can be built in a reasonable amount of time to fulfil the same functions;
  • the proposed third-party service has data-protection / data-security systems and provisions that are compatible with the Union’s Privacy and Data Protection Policy, any other related policies, and the applicable legislation as it applies to the Union’s processing of personal data;
  • Using the proposed third-party platform does not entail any unacceptable operational security risks, risks to personal data under our care, data protection or other liabilities, or lessen our ability to defend the Union and it’s members’ legal rights;
  • using the proposed third-party service does not undermine the Union’s archival, transparency and accountability requirements, the Union’s democracy, and members’ democratic rights to access and participate in discussions and decision making;
  • the IWW body that proposes to use the third-party service demonstrates that it will observe good data-security, data-protection and operational security practices when using the service, in accordance with the union’s relevant policies;
  • the IWW body that proposes to use the third-party service demonstrates that it will ensure the platform is properly and transparently moderated in accordance with the WISE-RA Data Protection, Safer Spaces, and communications policies;
  • the IWW body that proposes to use the third-party service demonstrates that it can ensure that all required risk mitigation measures are in place and will be complied with.

The DPIA can remain informal and unwritten if the assessment leads the DPO to conclude that the proposal to use a third-party platform should be rejected. the DPIA only needs to be recorded in writing if the proposed platform is approved.

A written DPIA will also contain a description of the processing, its purposes, and the lawful basis for the processing.

If the DPO concludes that the proposed third-party service does not meet the required criteria and standards, it will be either rejected or only authorised for use only until an IWW WISE-RA controlled service/platform can be used instead, or the DPO may propose and authorise an alternative third-party platform.

⚠ Where possible, non-commercial, open-source platforms should be given preference for both IWW controlled services and third-party services.

Excluding cases outlined in the next paragraph, if third-party services are mandated for the above purposes, IWW members and non-member users should not be opted-in by default: in order to participate, each individual user must explicitly opt-in based on informed consent, in such a manner that remaining opted-out is the default. Consent for opt-ins to third-party services must be collected and recorded via the IWW WISE-RA Membership Database.

Consent is not required, and data sharing and processing may proceed on the lawful basis of the IWW’s legitimate interests as a trade union if the third-party data processing service is hired as a service provider by the IWW and its data processing activities are bound by a Data Processor Agreement between the service provider and the IWW.

⚠ When any constitutive body of IWW WISE-RA mandates a third-party communications or data-processing service for which personal data processing requires Data Subjects’ consent, they should contact the union’s Communications Administrator, who will provide technical support to ensure that the proper opt-in consent collection form is used. The Communications Administrator will also make sure the WISE-RA Data Protection Officer and IT Committee are informed.


Transfers overseas

We do not routinely transfer your data outside of the UK or the European Economic Area. Where this is necessary, we ensure appropriate data protection measures are in place.

The IWW Interwob Forum is an online discussion platform whose use is shared with the membership of other IWW Regional Administrations (RA) and Regional Organising Committees (ROC) that are outside the United-Kingdom and European Economic Area (EEA). These non UK and non EEA based IWW RAs and ROCs are administratively separate from IWW WISE-RA but part of the same worldwide confederation of IWW unions.

Members of these non UK and non EEA IWW Administrations who access and use the Interwob Forum may be able to read the contents of some posts made by IWW WISE-RA Interwob Forum users, and see their Interwob usernames and profiles.

Interwob users have the option of using personally non-identifying usernames, and default usernames and user profile settings do not expose personally identifying data beyond the user’s first name and membership number.

The Interwob Forum is accessible only to members in Good Standing of IWW RAs and ROCs.

All Interwob Forum moderators and Administrators who can access personally identifying user data, including those residing outside the EEA, must sign an IWW WISE-RA Data Protection Undertaking or Data Processor Agreement before they obtain moderator or administrator access, in order to ensure their compliance and accountability to UK and EU GDPR data protection laws and IWW WISE-RA data protection policies. 


The applicable legislation restricts data transfers to countries outside the European Economic Area (EEA) in order to ensure that the level of data protection afforded to individuals by the applicable legislation is not undermined. You transfer personal data from one country to another when you transmit, send, view or access that data in or to a different country.

it is necessary to conduct a Data Protection Impact Assessment (DPIA) prior to approving International Transfers. The procedures for conducting such DPIAs are detailed in the “IWW WISE-RA Privacy and Data Protection Policy” section titled “Using, and sharing data with third-party communications/data-processing platforms and services”. International Transfers should not be performed if the DPIA’s conclusions are negative.

No international transfers of Union Data can be performed without the prior formal approval of the IWW WISE-RA Data Protection Officer.

The IWW WISE-RA will not normally transfer Personal data outside UK or EEA, except if one of the following conditions applies:

  • it is necessary to process the details of members residing outside the EEA;
  • in connection with members travelling abroad or otherwise engaged in international solidarity work;
  • As necessary to fairly conduct elections involving IWW WISE-RA organisations outside the EEA, and only where there is a Data Processing Agreement between relevant organisations which meets the requirements of the present Policy, the applicable data protection legislation, and our legal obligations;
  • the UK ICO or another relevant regulatory authority has issued a decision confirming that the country to which we transfer the personal data ensures an adequate level of protection for the data subjects’ rights and freedoms;
  • appropriate safeguards are in place such as binding corporate rules (BCR), standard contractual clauses approved by the the UK ICO or another relevant regulatory authority, an approved code of conduct or a certification mechanism, a copy of which can be obtained from the Union’s DPO if applicable;
  • the Data Subject has provided explicit consent to the proposed transfer after being informed of any potential risks;
  • where the Union acts as the Data Processor for a third party Data Controller of the personal data concerned, and where the contract for services or Data Processor Agreement between the Union and the Data Controller explicitly authorises the transfer; or
  • the transfer is necessary for one of the other reasons set out in the applicable legislation, including the performance of a contract between us and the Data Subject; the performance of a contract with a third party Data Controller of the personal data concerned; reasons of public interest; to establish, exercise or defend legal claims or to protect the vital interests of the Data Subject where the Data Subject is physically or legally incapable of giving consent; and, in some limited cases, for our legitimate interests.


Automated processing, profiling and decision making

We may implement various limited forms of automated processing. This may involve automations for the following purposes:

  • Automations and automated analytics to organise, structure, manage and analyse various forms of personally identifiable and non-personal data, to save time on manual data processing, improve our administrative work, or to enable and improve the functionalities and security of the information technology tools we use or the online services we build and maintain.
  • We may employ automation to erase/anonymise/delete personal data that we no longer need to retain, after the data retention period expires.

None of the automated processing currently employed by the IWW involves profiling in a manner that could result in legal effects or consequences that significantly affect any individual.

The IWW does not currently perform any automated decision-making, nor any form of human decision making based on automated processing or profiling that may result in legal effects or consequences that significantly affect any individual.


The Union shall avoid any form of automated decision-making that has a legal or similar significant effect on our Data Subjects, unless absolutely necessary for our legitimate interests, or our legal or contractual obligations, and it complies with the applicable legislation.

Automated Decision-Making, definition: when a decision is made which is based solely on Automated Processing (including profiling) which produces legal effects or significantly affects an individual. The applicable legislation prohibits Automated Decision-Making (unless certain conditions are met) but not Automated Processing.

Automated Processing definition: any form of Automated Processing of Personal data consisting of the use of Personal data to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning that individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Profiling is an example of Automated Processing.

Generally, automated decision-making is prohibited when a decision has a legal or similar significant effect on an individual unless:

  • a Data Subject has explicitly consented;
  • the processing is authorised by law; or
  • the processing is necessary for the performance of or entering into a contract.

If certain types of special category data are being processed, then grounds (b) or (c) will not be allowed but such special category data can be processed where it is necessary (unless less intrusive means can be used) for substantial public interest like fraud prevention.

Much personal data processed by the Union may reveal trade union membership; political, religious or philosophical beliefs; sexual orientation; health information; or race/ethnicity and should therefore be treated as Special Category Data where it identifies or reveals those matters.

Criminal Offence Data remains separately governed by Article 10 UK GDPR and the Data Protection Act 2018. The IWW will apply the higher applicable safeguards where data falls into either category..

If a decision is to be based solely on automated processing (including profiling), then Data Subjects must be informed, when we first communicate with them, of their right to object. This right must be explicitly brought to their attention and presented clearly and separately from other information.

We must inform the Data Subject of the logic involved in the decision making or profiling, the significance and envisaged consequences and give the Data Subject the right to request human intervention, express their point of view or challenge the decision.

A Data Protection Impact Assessment must be carried out before any automated processing (including profiling) or automated decision-making activities are undertaken.



Emails to members and promotional communications (‘direct marketing’)

We use the postal, email and telephone contact data we have about our members to provide them with information and updates about the IWW’s activities, internal democratic processes, internal discussions, campaigns, and services. We do this on the lawful basis of pursuing the IWW’s legitimate interests as a trade union.

General information emails that we send to our members from our membership database bulk mailer are tracked. This helps us to ensure that you only receive emails from us that are of interest to you.

You can opt-out/unsubscribe from receiving emails and communications from us at any time. Opt-out/unsubscription methods will be accessibly signposted in our regular communications. Members can unsubscribe from general information emails sent via our database mailer at anytime by clicking the email opt-out link at the bottom of our emails.

If you choose to opt out from general information emails, we will retain the right to send you a minimal number of important communications for the purposes of pursuing the legitimate interests or meeting the statutory requirements of the IWW as a trade union (namely information that we are legally required to send to our members: about union ballots and our Annual Returns Statement).

We may also occasionally engage in promotional communications with non-members who have explicitly opted-in or subscribed to receive updates and information from us, or who have contacted us in the past to enquire about our activities and services. When we do this, we will always explicitly offer the right to object to further promotional communications.

We will never share your contact details with any third-party service providers or data processors for promotional, marketing or advertising purposes.


We can contact and send regular communications to IWW members on the lawful basis of the IWW’s legitimate interests as a trade union, and thus do not need to base such contact or regular communications on consent.

Concerning non-members, a Data Subject’s prior consent is required for electronic direct marketing (for example, by email, text or calls, particularly automated calls). The limited exception for existing non-member contacts, known as “soft opt in”, allows organisations to send marketing texts or emails if they have obtained contact details in the course of a prior business interaction or exchange with that person (i.e., in our case, any interaction that is relevant to our mission or services as a union), they are marketing similar services, and they gave the person an opportunity to opt out of marketing when first collecting the details and in every subsequent message

For all our Data Subjects, members and non-members, the right to object to direct marketing must be explicitly offered in an intelligible manner so that it is clearly distinguishable from other information. A Data Subject’s objection to direct marketing must be promptly honoured. If a non-member opts out at any time, their details should be suppressed as soon as possible. Suppression involves retaining just enough information to ensure that marketing preferences are respected in the future. For members, suppression is not necessary, but their opt-out preferences must be promptly implemented.



Criminal Offence Data, Representation, Safeguarding, Incarcerated Workers Organising Committee, Incarcerated members, prison-location requests and prisoner advocacy

The IWW may process personal data and Criminal Offence Data where this is necessary for its legitimate trade union, employment, safeguarding, representational, campaigning, advice, welfare, complaint-handling, legal-rights or administrative functions.

⚠ This includes, but is not limited to, processing in connection with:

(a) membership administration, organising, campaigning, representation, advocacy or welfare support for incarcerated members, former members, prospective members, or persons supported by the Incarcerated Workers Organising Committee (IWOC);

(b) prison-location requests, maintaining correspondence, restoring lost contact, prison-related complaints, prison conditions, prison labour organising, prison or probation records, court or judicial matters, and campaigning or advocacy relating to the rights and interests of incarcerated workers and other persons affected by imprisonment or criminal conviction;

(c) trade union representation, advice, accompaniment, casework, grievance, disciplinary, investigatory or dispute-resolution work on behalf of ordinary union members in the workplace, including where criminal conviction, allegation, investigation, court, prison, probation or police-related information is relevant to the member’s employment dispute, grievance, disciplinary process, defence, complaint, legal rights or welfare;

(d) the employment, engagement, supervision, welfare, safeguarding, grievance, disciplinary, health-and-safety, whistleblowing or legal-rights matters of IWW employees, staff, officers, reps, organisers, volunteers, candidates, contractors or other persons acting under the IWW’s authority, where Criminal Offence Data is relevant and its processing is necessary and proportionate;

(e) internal safeguarding, complaints, disputes, disciplinary or investigatory matters within the Union where Criminal Offence Data is relevant to protecting children, adults at risk, vulnerable persons, members, staff, officers, volunteers, service-users or others; and

(f) advice, campaigning, advocacy, complaints, welfare support or legal-rights work concerning persons with criminal convictions, allegations, investigations, court proceedings, prison or probation histories, including persons who are no longer incarcerated, where the processing is necessary for the Union’s legitimate activities and an applicable legal condition is identified.

⚠ Criminal Offence Data may include, without limitation, information relating to criminal convictions, alleged offences, charges, arrests, police investigations, court proceedings, sentencing, prison or probation status, prisoner number, prison location, prison disciplinary material, licence or bail conditions, related security measures, correspondence with police, prisons, probation or courts, and information obtained from the data subject, their family or representatives, employers, workplace correspondence, legal representatives, courts, tribunals, public authorities, correspondence, FOI responses or other lawful sources.

⚠ Before processing Criminal Offence Data, the IWW will identify and record:

(i) an Article 6 UK GDPR lawful basis; and
(ii) the applicable Schedule 1 Data Protection Act 2018 condition required by Article 10 UK GDPR.

⚠ Depending on the context, the IWW may rely in particular on one or more of the following Schedule 1 conditions: paragraph 1 (employment, social security and social protection), paragraph 18 (safeguarding of children and individuals at risk), paragraph 29 (consent), paragraph 31 (not-for-profit bodies), paragraph 33 (legal claims), or another applicable Schedule 1 condition where more appropriate. Where the processing also involves Special Category Data, the IWW will also identify and record the applicable Article 9 UK GDPR condition.

The IWW will process Criminal Offence Data only where necessary and proportionate for the identified purpose, and only to the minimum extent reasonably required. Access will be restricted to persons authorised by the IWW for the relevant function and subject to confidentiality, security, record-keeping and instruction requirements. Criminal Offence Data will not be processed merely because it may be useful or interesting, and will not be retained for longer than is necessary for the purpose for which it was collected or used.

The IWW does not maintain any comprehensive register of criminal convictions. Criminal Offence Data is processed on a case-by-case or function-specific basis for membership administration, casework, safeguarding, representation, advocacy, legal rights, complaints, welfare support and related purposes.

Prison-location requests and Find a Prisoner enquiries

⚠ Prison-location requests, including requests to the Ministry of Justice, HMPPS, prison authorities or the Find a Prisoner service, Authorised Data Handlers specifically approved for that purpose by IWOC and, where required by internal procedure, by the Data Protection Officer. The handler must use only the minimum data necessary, must record the request and outcome, and should use an IWW-controlled email account or other approved IWW communication channel wherever practicable.

⚠ Wherever reasonably possible, IWOC will obtain and record the incarcerated person’s authorisation for the IWW and its authorised officers, reps, organisers or volunteers to seek, receive, update and process prison-location and contact information on their behalf. Where prior authorisation is unavailable because contact has been lost, or because urgent welfare, safeguarding or representation concerns arise, the IWW may make a strictly limited enquiry necessary to restore contact, protect the person’s interests, support representation, or request that the relevant authority seek the person’s permission or forward contact information or correspondence as appropriate. Such enquiries must be approved or retrospectively reviewed by the DPO or an authorised delegate and recorded in the relevant casework log.

⚠ No person may use IWW-held personal data for prison-location or related enquiries unless they are acting under the IWW’s authority, have signed the required confidentiality and data protection undertaking or contract, have been instructed on the lawful basis, applicable Schedule 1 condition, minimum-data requirement and record-keeping procedure, and comply with this policy and any related prison-contact procedures adopted by the Union.

Where IWOC experiences repeated non-response, refusal, or suspected blacklisting in relation to prison-location or prisoner-contact requests, the handler must record the dates, route used, information supplied, follow-up steps and outcome, and escalate the matter to the IWOC Secretary and the Data Protection Officer. The IWW may then decide whether to pursue a complaint, seek clarification of the applicable process, adjust the authorised route, or take other lawful steps. Informal or misleading workarounds must not be used in place of this escalation process.


User Accounts

If you create or are given a user account on any IWW controlled online platform or service (such as an IWW email account, a Membership Database user account, or a Members' Area, Interwob forum or Wobchat user account), you are responsible for maintaining the security of your account and you are fully responsible for all activities that occur under the account. You must immediately notify IWW of any unauthorized uses of your account or any other breaches of security. IWW will not be liable for any acts or omissions by you, including any damages of any kind incurred as a result of such acts or omissions.

When using IWW websites and communications tools, all account holders are expected to abide by the privacy and data protection rules and policies outlined on this page as well as IWW rules and policies concerning Safer Spaces, usage of our communications channels, and data security / operational security.

Each user account provided by the IWW on its websites is intended for the exclusive and individual use of the authorized account holder. The account holder is the sole authorized user for their respective account, username, and password. The account holder must ensure the confidentiality of their account credentials and is prohibited from sharing their password with any other individual or permitting any other individual to use their account.

⚠ IWW email account passwords may sometimes need to be shared with a co-officer or co-role-holder for shared use; in such cases passwords must pnly be shared with the other authorised users using secure, encrypted communications (see step-by-step instructions for this.).

Excluding the exception outlined in the preceding paragraph, The sharing of user account credentials, including but not limited to the username and password, with any other person is strictly prohibited. Access and use of accounts by any person other than the intended account holder is strictly prohibited, whether the account credentials are willingly provided to another person or are acquired by another person through unauthorized means such as hacking or theft.

Any instance of unauthorized access to a user account, regardless of whether such access is the result of intentional sharing of account credentials by the account holder or through unauthorized acquisition by a third party, will be considered a security breach and a violation of this Policy.

In the event of unauthorized access to a user account, the IWW will initiate an investigation and take appropriate actions. This may include, but is not limited to, disciplinary measures in accordance with the IWW’s complaints process. Legal action may also be considered where applicable. The response to such incidents will be conducted in alignment with the severity of the breach and the specifics of the situation.

Account holders are required to immediately notify IWW upon becoming aware of any unauthorized use of their account or any other breach of security related to their account. Prompt reporting is crucial to ensure timely and effective response to such incidents.


User-posted contents and media

Authorised Data Handlers' content posting responsibilities; rights as contact points.

⚠ Personal data should not be circulated on email lists or group communications channels unless this is necessary for an authorised union purpose. Authorised Data Handlers should remember that email lists, Interwob forum, Wobchat and other group communications are not always secure or confidential, and that messages may be retained in archives, downloaded, forwarded, copied, or become accessible to more people than originally expected.

⚠ When sending bulk emails or messages, Authorised Data Handlers must use authorised systems and must avoid exposing recipients’ email addresses or contact details to one another unless there is a legitimate and transparent reason for doing so. Where appropriate, blind-copy, mailing-list tools, membership database bulk-mailing tools, or other privacy-preserving methods should be used.

⚠ Where individuals volunteer to act as public contact points for branches, campaigns, events, committees, or other union activity, their relevant official IWW contact details may be published or shared for that purpose, provided they understand the intended disclosure and have agreed or been appropriately authorised to act in that public-facing role. Public role-holder contact details should be limited to what is necessary for the relevant union function.

User rights and responsibilities

IWW members can post contents to the public facing website (which must be approved by site editors before it is published). Members can also post contents to internal members-only discussion areas, such as Wobchat, the InterWob Forum, or any IWW email lists they may be subscribed to. Members can upload files to the IWW Owncloud file repository. IWW roleholders may be granted IWW hosted email accounts from which they can send and receive emails.

When using IWW websites and communications tools, members are expected to abide by the privacy and data protection rules and policies outlined on this page as well as IWW rules and policies concerning Safer Spaces, usage of our communications channels, and data security / operational security.

Please do not post content revealing someone else's personal data without their prior consent.

The IWW retains the right to revoke your access to any IWW members-access-only websites and email accounts and their contents, including personal IWW email accounts and website user accounts.

Copyright advisory

User contributions submitted to IWW controlled websites are protected under an “All Rights Reserved” copyright of the IWW WISE-RA. This is to protect our users' posted content from unauthorised misuse and publication. All rights regarding the distribution, reproduction, adaptation, and public performance of user contributions on IWW WISE-RA websites are retained by the IWW WISE-RA. Use of any content in any form without the explicit permission of IWW WISE-RA is strictly prohibited.

⚠ Without limiting any of those representations or warranties, the IWW WISE-RA reserves the right (though not the obligation) to, in its sole discretion, (i) refuse or remove any content that, in the IWW WISE-RA’s reasonable opinion, violates any of the IWW WISE-RA’s policy or is in any way harmful or objectionable, or (ii) terminate or deny access to and use of the Website to any individual or entity for any reason, in the IWW WISE-RA’s sole discretion. the IWW WISE-RA will have no obligation to provide a refund of any amounts previously paid.

User content precaution advisories and disclaimers

All IWW members will be able to see and download any content that you post or upload to Wobchat, the InterWob Forum, the IWW Owncloud file repository or any other members-only IWW websites. IWW email list subscribers will be able to see and download any content that you post to those lists. Any content you post to the public website (once site editors publish it) will be publicly visible and can be downloaded by any visitor to the website.

Please only post content you are comfortable sharing with these audiences.

If you upload images to the websites you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

The IWW has not reviewed, and cannot review, all of the material, including computer software, posted to its websites by users, and cannot therefore be responsible for that material’s content, use or effects. By operating its websites, the IWW does not represent or imply that it endorses the material there posted, or that it believes such material to be accurate, useful or non-harmful. As a user of our websites you are responsible for taking precautions as necessary to protect yourself and your computer systems from viruses, worms, Trojan horses, and other harmful or destructive content.

IWW websites may contain content that is offensive, indecent, or otherwise objectionable, as well as content containing technical inaccuracies, typographical mistakes, and other errors. IWW websites may also contain material that violates the privacy or publicity rights, or infringes the intellectual property and other proprietary rights, of third parties, or the downloading, copying or use of which is subject to additional terms and conditions, stated or unstated. IWW disclaims any responsibility for any harm resulting from the use by visitors of its websites, or from any downloading by those visitors of content there posted.

We have not reviewed, and cannot review, all of the material, including computer software, made available through the websites and webpages to which the IWW's websites link, and that link to the IWW's websites. The IWW does not have any control over those non-IWW websites and webpages, and is not responsible for their contents or their use. By linking to a non-IWW websites and webpages, the IWW does not represent or imply that it endorses such website or webpage. You are responsible for taking precautions as necessary to protect yourself and your computer systems from viruses, worms, Trojan horses, and other harmful or destructive content. The IWW disclaims any responsibility for any harm resulting from your use of non-IWW websites and webpages.

Downloading, editing or deleting your content/posts from IWW websites

Members can directly download, amend, or delete any content they have posted on Wobchat, the InterWob Forum, IWW's Owncloud, or that is stored in their IWW email accounts by visiting the 'My Membership' page of the IWW Members' Area website (access to this area is restricted to members only and requires a password).

Public website contributors can amend their posts themselves and can contact website editors or the IWW IT Committee or IWW Data Protection Officer to publish the amended content.

Members can ask their local branch officers or contact the IWW Communications Administrator to subscribe or unsubscribe their email address(es) to/from their local branch's email lists. IWW roleholders can contact the IWW Communications Administrator for support with subscription or unsubscription on IWW email lists.

Please note that once you have sent an email, the recipient(s) of that email, including the subscribers of any IWW email list(s) you post to, will be able to read that email and download its contents, and this cannot be undone nor deleted from the IWW email list's message archive.

By default, contents that you have emailed, posted or uploaded yourself via Wobchat, the InterWob Forum, the IWW Owncloud file repository, IWW email accounts and email lists, or any other IWW communications platform, will remain indefinitely stored and visible on those platforms, even if you are no longer a member, unless you delete them yourself or explicitly request their erasure.

If you wish to erase content that you posted on any IWW member-only website such as the Interwob Forum or Wobchat, while you have access as a member, you must do so yourself using the available editing and deletion tools.

⚠ You are only entitled to delete posts that you have published in your capacity as an individual member. If you are or have been a formally elected or appointed IWW role-holder, you are not entitled to delete any posts that you have made in that capacity.

If you are no longer a member and/or no longer have access to IWW member-only websites, you may request erasure of personal content by contacting the Data Protection Officer or Communications Administrator. If authorised by the Data Protection Officer, erasure will be implemented by anonymising the content rather than deleting it, as this counts as erasure under current data protection legislation. You may appeal to the Data Protection Officer to request full deletion of content, subject to adequate justification and authorisation by the Data Protection Officer.

Erasure, anonymisation or deletion of posts may be refused if the contents are relevant to, or if you are subject to any formal internal process reasonably requiring the data to be retained, such as a formal complaint or investigation, or if the Data Protection Officer decides the data needs to be retained for any reason compatible with the present Privacy Policy or as provided by the relevant legislation or regulatory authorities. In such cases, if you are still an active member, your ability to directly edit and delete your posts may be temporarily or permanently blocked.

Likewise, on third-party communications (or data processing) platforms where you have given your consent to the IWW to share your personal data in order to connect/subscribe you and communicate with you (e.g., Whatsapp or Signal chat groups, Slack Channels, Loomio, etc.), contents that you post may remain indefinitely stored there unless you take action to delete them yourself or request their erasure by that third party Data Controller. You can ask us us to remove the subscription/connection/contact-data, that you had initially given us to add/subscribe you to a third-party platform, and we will comply with your request (except in rare cases where we maintain a lawful basis to delay or refrain from doing so), but we cannot, on your behalf, erase the content you posted yourself from those platforms, and it is your responsibility to do so.

If you require assistance with any of the above, including requests for your data to be erased from Wobchat, the InterWob Forum, the IWW Owncloud file repository, or IWW Email accounts, please click here to submit a request via the contact form in the IWW Members Area website (select the 'Personal data requests' category). (Access to this area is restricted to members only and requires a password).


Social media

The IWW and its various bodies use social media websites such as Twitter, Youtube and Facebook to promote their activities. We do not collect any personal data from social media profiles. We do not use your member data to target our social media posts or any social media advertising. We do not provide or sell members' data to third parties for the purposes of social media marketing or any other form of marketing or analytics.

Occasionally, posts on our websites may contain social media buttons or links to social media sites. When you click on these buttons or links, these sites will be registering that action and may use your information.

You should check the respective policies of each of these social media sites to see how exactly they use your information and to find out how to opt out, or delete, such information.


Amendments to this policy

We reserve the right to change this Privacy and Data Protection Policy at any time without notice to you. We will post revised versions of this Policy on the website at https://www.iww.org.uk/privacy

IWW WISE-RA Authorised Data Handlers or Data Processors should regularly check this page as a reference of data protection policies and practices, and to keep themselves informed of any policy changes.