• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

0330 223 3152

enquiries@simplycollect.co.uk

  • Facebook
  • Twitter
Simply Collect

Simply Collect

Complete Direct Debit Management

  • Who uses us
    • Small Business
    • Dentist
    • Martial Arts Club
    • Gym
    • Nurseries
    • Tradesman
    • Swimming School
    • Yoga
    • Tennis Club
    • Bodybuilding
    • Football Club
    • Golf Club
    • Personal Trainer
    • Plumber
    • Sports Clubs
    • Telecom
    • Web Hosting
    • Landlords
    • Health Club
    • Accountants
    • Equestrian
  • How it works
  • Why use us
  • Learn
    • Direct Debit Info
    • API Documentation
    • FAQs
  • Signup
  • Contact us

Are You Ready for GDPR?

May 2, 2018 By admin

europe-3220208_1920

What is GDPR?

It has become a buzz word recently but it is certainly a big change in terms of how businesses operate and process/store customer information. The new GDPR legislation comes into force on the 25th May 2018 and tightens up the existing DPA rules.

The new GDPR legislation can be a daunting subject to many clubs. From our side, SimplyCOLLECT systems were designed with privacy as a key aspect and are therefore in line with DPA and the BACs scheme and the principles of the GDPR.

Under the legislation, Data Controllers and Data Processors have different responsibilities. SimplyCOLLECT operates as a data processor and as a club you operate as the data controller.

GDPR will apply to all organisations that collect personal data from individuals. You should seek advice to ensure you are compliant but here are some tips on what the legislation requires and looks at.

  • How you process customer data it accurate and updated regularly
  • Is the data collected limited to the uses of the organisation’s activities
  • A customer must “opt-in” to any marketing materials you communicate to them
  • How you store hard or electronic copies of customer data
  • Which personnel have access to personal data

What practical steps can a club take?

The ICO recommends that organisations take the following steps to be compliant. We have also included a link to the ICO 12 step guide)

Awareness:

You should make sure that decision-makers and key personnel in your organisation are aware that the law is changing to the GDPR. They need to appreciate the impact that this is likely to have and identify areas that could cause compliance problems.

Practically this relates to communication from the club to the member and who is responsible for any issues relating to GDPR within your club.

Information your club holds:

GDPR requires you to maintain records of your processing activities. You should document what personal data you hold, where it came from and who you share it with.

For a club, this is any record you have with some personal information that can easily identify the individual. So for clubs who process members using membership forms, you must ensure any information your keep outside of our systems is safe and secure.  We would recommend creating a flow diagram to show the flow of the personal data which will help you understand its journey and be available to members upon request.

Communicating Privacy statements:

When you collect personal data you must give people certain information, such as your identity and how you intend to use their information. This is usually done through a privacy notice. Under the GDPR there are some additional things you will have to tell people. As part of the regulations, you will need to explain your lawful basis for processing the data, your data retention periods and that individuals have a right to complain to the ICO if they think there is a problem with the way you have handled their data.

How you document and provide this to members could be given as a hard copy upon joining or alternatively available on your website. SimplyCOLLECT acting as a data processor will be updating its privacy notice and making this more accessible to your customers via there welcome email and from our website.

The Individual Rights of members:

You should check your procedures to ensure they cover all the rights individuals have, including how you would delete personal data or provide data electronically and in a commonly used format. The GDPR includes the following rights for individuals:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  •  The right to object, and
  •  The right not to be subject to automated decision-making including profiling.

The legislation gives members more control over how they process their data. This can be someone asking for copies of documents signed or electronic information stored on them. This relates to the “Subject Access Request”. This refers to an individual’s right to access information an organisation holds on them. You should update your procedures and plan how you will handle Subject Access Requests to take account of the new rules. Here’s a link to further info on SARs

Lawful basis for processing personal data:

Most clubs would not have considered the lawful basis for processing information but GDPR requires you to document this basis within your privacy statement. Processing of data is lawful when there is consent, contractual, legal obligation in place. SimplyCOLLECT already seek this consent via the membership form under the terms and conditions or if you are using simplyJOIN this is within the T&C’s of the joining process but will also be more explicitly mentioned on the initial sign up page.

Data Protection and Children:

You should start thinking now about whether you need to put systems in place to verify individuals’ ages and to obtain parental or guardian consent for any data processing activity. For the first time, the GDPR will bring in special protection for children’s personal data, particularly in the context of commercial internet services such as social networking. If your organisation offers online services (‘information society services’) to children and relies on consent to collect information about them, then you may need a parent or guardian’s consent in order to process their personal data lawfully.

SimplyCOLLECT already seeks the parental consent to obtain the child details via the membership form additionally via our simplyJOIN product.

Consent: 

You should review how you seek, record and manage consent and whether you need to make any changes. Refresh existing consents now if they don’t meet the GDPR standard. Consent must be freely given, specific, informed and unambiguous. There must be a positive opt-in – consent cannot be inferred from silence, pre-ticked boxes or inactivity. It must also be separate from other terms and conditions, and you will need to have simple ways for people to withdraw consent.

SimplyCOLLECT has already been working hard in the background:

You will see changes to new membership forms and both simplyJOIN/simplyHUB that captures the members “opt-in” consent to communicate marketing materials to members. You will also see changes to user right access to data to enhance the security and the flow of personal data; we do need to make you aware that if you export any data out of the SimplyCOLLECT systems you are responsible from that point forward relating to GDPR.

The simplyHUB will also have a mechanism in place to limit the marketing to non-consenting members. However please be rest assured this only applies to market materials. Members will continue to receive service messages (closures, payment increases) regardless. The new rules only apply to market/promotional messages.

Over the next month, you will see some slight changes in the systems and forms you use on a day to day basis. Being a Direct Debit provider we already adhere to stringent security policies to ensure your member data is safe and secure. You will receive via email an updated section of our client terms and conditions relating to the GDPR regulations once reviewed.

Filed Under: Uncategorized

Primary Sidebar

Recent Posts

  • Direct Debit vs Card payments what’s best for your business
  • How to set aside business taxes
  • Have you looked at the hidden costs of running a business?
  • Childcare and how to get paid on time
  • What is a BACS payment and how would you pay it?
Ready to get started?

No start-up fees. No contract. No risk. Sign up now and let us start taking care of your client management and recurring payment needs today. With the first month of Direct Debit payment absolutely free it could be the best decision you will ever make for your business.

Welcome to the future of client management and payment collections.

Signup Today

Footer

Simply Collect

Simply Collect LTD Company Registration Number 09241302
Belgrade Business Centre, Denington Road, Wellingborough, Northamptonshire, England,
NN8 2QH

VAT no: 230713152

0330 223 3152
enquiries@simplycollect.co.uk

Simply Collect Ltd is registered with the Financial Conduct Authority as a Small Payment Institution, under reference number 919813. Our permitted activity is executing payment transactions.

Sitemap

  • SimplyCOLLECT
  • Who uses us
  • How it works
  • Why use us
  • Signup
  • News

Company

  • FAQs
  • SimplyCOLLECT is on your bank statement
  • Privacy Policy
  • Cookie Policy
  • Website Terms of Service
  • Complaints procedure

Copyright © 2025 Simply Collect. All rights reserved.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT