Privacy Policy

Introduction

MOSA is committed to protecting the privacy and security of personal information. 

This policy explains what data we collect, how we use it, how it is stored, and the rights members have under data protection law.

Please read this policy carefully.

Definitions

  • Data subject: The individual whose personal data is held.
  • Personal data: Any information relating to an identifiable living individual.

Information We Collect

Membership Application:

  • Title, forename, surname
  • Address (home/work)
  • Email address & telephone number(s)
  • Date of birth (optional)
  • Job title, qualifications
  • Professional body and registration number
  • School name and address
  • Group members (if applicable)

Event Booking:

  • Title, name, address, contact details
  • Date of birth (optional)
  • Job title, school name
  • Dietary requirements (optional)
  • Car registration (for educational events)

How Data Is Stored & Protected

Member data is stored securely in the password-protected administration area of www.mosa.org.uk.

Each member has a personal login.

  • Access is restricted to authorised officers:
    • Executive Officer
    • Executive Secretary
    • Treasurer
    • Educational Officers and Support Team
    • Website developer (Avenue42, limited access)

MOSA also uses Mailchimp for email communications, in compliance with their privacy policy (https://mailchimp.com/legal/privacy/).

Data Retention

  • Membership data is deleted when a member terminates their membership.
  • Event booking data for non-members is retained only to provide follow-up information (e.g. handouts, certificates, event invitations).
  • Mailing list data is removed when a member withdraws consent or ends membership.

How Data Is Used

  • To verify eligibility for membership (professional registration)
  • To administer membership and events
  • To communicate with members (via website, email, or Mailchimp)
  • To provide attendance records and certificates
  • To comply with legal obligations (e.g. HMRC reporting for paid officers)

Data Sharing

MOSA does not share personal information except:

  • When jointly organising events with partner organisations (e.g. BSA, SAPHNA or RCGP).
  • When legally required, such as for tax reporting to HMRC.

MOSA does not transfer data outside the UK.

Members’ Rights

Members have the following rights under data protection law:

  • Access to their personal data (via a Subject Access Request)
  • Correction of inaccurate data
  • Erasure of personal data (‘right to be forgotten’)
  • Restriction or objection to processing
  • Withdrawal of consent at any time
  • Data portability
  • Lodging a complaint with the ICO (https://ico.org.uk or 0303 123 1113)

Subject Access Requests (SARs)

  • Requests must be made in writing to the Executive Secretary (exec.sec@mosa.org.uk).
  • Proof of identity is required.
  • Requests will be processed within 30 working days.
  • Information relating to third parties will be redacted.
  • All SARs will be logged.

Data Breach Policy

A personal data breach is any unauthorised access, loss, alteration, or disclosure of personal data.

If a breach is likely to affect members’ rights and freedoms, MOSA will:

  1. Notify the ICO within 72 hours.
  2. Inform affected members without undue delay, unless data is secure (e.g. encrypted).
  3. Record all breaches to help strengthen security.

Updating Information

Members should notify the Executive Secretary (exec.sec@mosa.org.uk) of any changes to their personal information.

Changes to This Policy

MOSA may update this policy to reflect changes in law or practice. The latest version will always be available at www.mosa.org.uk.

Contact

  • Executive Officer: exec.officer@mosa.org.uk
  • Executive Secretary: exec.sec@mosa.org.uk
  • ICO Helpline: 0303 123 1113