
Data Protection and Privacy Notice
Introduction
The General Data Protection Regulation became applicable in the United Kingdom on 25 May 2018.
Following the end of the United Kingdom’s transition period after leaving the European Union, the UK General Data Protection Regulation took effect on 1 January 2021.
The principal legislation governing the processing of personal information in the United Kingdom now includes:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications (EC Directive) Regulations 2003, where applicable; and
- amendments made by the Data (Use and Access) Act 2025.
The National Association for Retired British Transport Police Officers—referred to in this notice as “NARBTPO”, “the Association”, “we” or “us”—takes the protection of members’ personal information seriously.
This notice explains the general principles we follow, the information we hold, why we use it and the rights available to individuals.
Data Protection Principles
When processing personal information, we aim to ensure that it is:
Lawful, fair and transparent
Personal information must be processed lawfully, fairly, and transparently.
Collected for specified purposes
Personal information must be collected for specified, explicit and legitimate purposes. It must not subsequently be used in a way that is incompatible with those purposes unless the law permits that further use.
Adequate and limited
We should only collect and use personal information that is adequate, relevant and limited to what is necessary for the purpose for which it is processed.
Accurate
We must take reasonable steps to ensure that personal information is accurate and, where necessary, kept up to date.
Inaccurate personal information should be corrected or erased without unnecessary delay, taking account of the purpose for which it is held.
Retained only as long as necessary
Personal information must not be kept in an identifiable form for longer than is necessary for the purpose for which it was collected, unless a longer period is permitted or required by law.
Secure
Appropriate technical and organisational measures must protect personal information.
These measures should protect information against unauthorised or unlawful use and against accidental loss, destruction, alteration or damage.
Accountable
NARBTPO is responsible for complying with these principles and must be able to demonstrate that appropriate data protection arrangements are in place.
Data Controller
NARBTPO is identified in this notice as the organisation responsible for deciding why and how members’ personal information is used.
Where NARBTPO is an unincorporated association, the office-holder or office-holders who are legally responsible for acting as controller should be determined in accordance with the Association’s constitution or other governing document.
The Secretary or Membership Secretary may act as the principal contact for data protection matters, but this does not necessarily make that individual the sole data controller.
Information We Hold
We may hold information that members have provided when applying for or maintaining membership of NARBTPO, including:
- name;
- postal address;
- email address;
- telephone number;
- membership details;
- communication preferences;
- Members’ Directory preferences;
- correspondence with the Association and
- payment or financial records relating to membership.
We should only collect information that is reasonably required for the administration and operation of the Association.
How We Obtain Your Information
Most of the personal information we hold is provided directly by members when they:
- apply to join NARBTPO;
- renew or maintain their membership;
- provide updated contact information;
- correspond with the Association;
- make a payment;
- complete a Members’ Directory form; or
- choose to receive Association publications or communications.
Why We Use Your Information
We may use members’ personal information to:
- administer membership;
- maintain accurate membership records;
- collect and record membership payments;
- communicate with members about Association business;
- send Retired Lines and other membership publications;
- provide information about meetings, events and activities;
- administer the Members’ Directory;
- respond to enquiries, requests and complaints;
- maintain appropriate financial and administrative records;
- protect the security of the Association’s records; and
- meet legal, regulatory or governance obligations.
Lawful Basis for Processing
Data protection law requires the Association to identify an appropriate lawful basis for each use of personal information.
Depending on the particular activity, the Association may process personal information because:
- it is necessary to administer the Association and provide membership services;
- it is in the legitimate interests of the Association and its members, provided those interests are not overridden by the individual’s rights;
- it is necessary to comply with a legal obligation; or
- the individual has given consent for a particular optional use.
Where we rely on consent, members may withdraw that consent at any time. Withdrawal of consent does not affect processing that took place lawfully before consent was withdrawn.
The Association should maintain an internal record of the lawful basis relied upon for each processing activity.
Members’ Directory
We will only publish personal contact details in the Members’ Directory where the member has clearly indicated the information they wish to include.
Members may choose:
- not to appear in the Directory;
- to have only their name included;
- to include selected contact details; or
- to include all the information requested on the Directory form.
Members may change or withdraw their Directory preference at any time.
Where no clear preference has been recorded, contact information should not be published until the member’s wishes have been confirmed.
Information supplied for the Directory may be edited for consistency, accuracy or space, but we will not intentionally publish information that a member has asked us to withhold.
Retired Lines and Other Communications
We use members’ contact information to provide membership-related publications and notices, including Retired Lines.
Members who no longer wish to receive Retired Lines or other optional communications may notify the Membership Secretary.
Opting out of an optional publication does not necessarily prevent the Association from sending essential communications relating to membership, payments, governance, legal obligations or the security of members’ information.
Members have an absolute right to object to the use of their personal information for direct marketing.
Where the Privacy and Electronic Communications Regulations require consent for an electronic communication, we will seek the appropriate consent before sending it.
Sharing and Access to Information
Access to members’ personal information is restricted to those committee members and other authorised persons who require it for legitimate Association purposes.
We may also use carefully selected service providers, such as providers of:
- printing and mailing services;
- email or communications systems;
- website hosting;
- information technology support;
- payment or banking services; or
- secure record storage and destruction.
Where another organisation processes information on our behalf, it should use it only in accordance with our instructions and applicable contractual and security requirements.
We do not sell members’ personal information.
Information will not be disclosed to another organisation unless:
- it is necessary for a legitimate Association purpose;
- the member has agreed to the disclosure;
- the disclosure is required or permitted by law; or
- it is necessary to protect the rights, property or safety of the Association, its members or another person.
Information Security
The security of members’ personal information is important to us.
We use appropriate technical and organisational measures designed to protect personal information against:
- unauthorised access;
- inappropriate disclosure;
- unlawful use;
- accidental loss;
- alteration;
- destruction; and
- damage.
No system can guarantee absolute security. We therefore review our arrangements and take reasonable steps to identify and reduce data protection risks.
Retaining Personal Information
We retain personal information only for as long as it is reasonably required for the purpose for which it was collected or for an applicable legal, financial, governance or evidential requirement.
Different types of information may need to be retained for different periods.
Financial and accounting records will be retained for the period required by applicable legislation and regulations governing NARBTPO. They will then be securely destroyed or anonymised when they are no longer required.
The Association should maintain a written retention schedule setting out how long each category of record is normally kept.
Keeping Your Details Up to Date
Members are asked to notify us promptly if their personal information changes.
This includes changes to:
- name;
- postal address;
- email address;
- telephone number;
- communication preferences; and
- Members’ Directory preferences.
Although members are encouraged to provide updated details, NARBTPO remains responsible for taking reasonable steps to ensure that the personal information it uses is accurate.
Your Data Protection Rights
Depending on the circumstances and the lawful basis used for processing, individuals may have the following rights.
Right to be informed
You have the right to receive clear information about how your personal information is collected and used.
Right of access
You may ask whether we process your personal information and request a copy of that information together with relevant supplementary information.
We will normally respond without undue delay and within one month.
The response period may be extended where a request is complex or where a person has made a number of requests. We may also ask for reasonable clarification or evidence of identity where this is necessary.
Right to rectification
You may ask us to correct inaccurate information or complete information that is incomplete.
Right to erasure
You may ask us to erase personal information in certain circumstances.
The right to erasure is not absolute. We may need to retain information where it is still required for a lawful purpose, including compliance with legal obligations, financial record-keeping or the establishment, exercise or defence of legal claims.
Right to restrict processing
You may ask us to restrict the use of your personal information in certain circumstances.
Where processing is restricted, we may continue to store the information but will generally not use it for other purposes unless the law permits us to do so.
Right to data portability
In certain circumstances, you may request personal information that you provided to us in a structured, commonly used and machine-readable format.
This right generally applies where processing is automated and is based on consent or is necessary for the performance of a contract.
Right to object
You may object to processing based on legitimate interests or a task carried out in the public interest.
The right is not absolute in every situation, but we must consider the circumstances and explain our decision.
You have an absolute right to object to the use of your personal information for direct marketing.
Rights relating to automated decisions
Where a decision producing legal or similarly significant effects is made solely by automated processing, data protection law provides safeguards that may include:
- being informed about the decision;
- making representations;
- challenging the decision; and
- requesting human intervention.
NARBTPO does not currently intend to make significant membership decisions solely through automated processing.
Making a Rights Request
A request relating to your personal information may be made verbally or in writing.
To help us identify and respond to your request, please provide:
- your name;
- sufficient information to confirm your identity;
- a description of the information or processing concerned; and
- your preferred contact details.
Requests should be sent to the Membership Secretary:
Email: membership@narbtpo.com
We will only request identification where it is reasonably necessary to confirm the identity of the person making the request.
Data Protection Complaints
You may make a complaint if you are concerned about how NARBTPO has collected, used, disclosed, retained or protected your personal information.
Complaints should be sent to:
Email: secretary@narbtpo.com
We will:
- provide a clear way for you to submit a complaint;
- acknowledge your complaint within 30 days;
- take appropriate steps to investigate it without undue delay;
- keep you appropriately informed; and
- notify you of the outcome without undue delay.
A data protection complaint is separate from a request to exercise one of your individual rights. Different response periods may therefore apply.
Complaints to the Information Commissioner
You also have the right to complain to the Information Commissioner’s Office, which is the United Kingdom’s independent data protection regulator.
The Information Commissioner’s Office may be contacted by telephone on:
0303 123 1113
We encourage members to contact NARBTPO first so we can investigate and address the concern.
Personal Data Breaches
A personal data breach may include the accidental or unlawful loss, alteration, destruction, disclosure of or access to personal information.
We will investigate suspected breaches and take appropriate steps to contain them and reduce any risk to affected individuals.
Where a breach meets the legal reporting threshold, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours after becoming aware of it.
Where a breach is likely to create a high risk to an individual’s rights and freedoms, we will also notify the affected individual without undue delay unless an applicable exception applies.
Contact Us
Questions, requests, corrections, objections and complaints concerning personal information should be directed to the NARBTPO Secretary:
Email: secretary@narbtpo.com
The Association should also provide a postal address here if members are to be allowed to submit requests or complaints by post.
Changes to This Notice
We may amend this notice to reflect changes in the law, regulatory guidance or the way in which NARBTPO processes personal information.
Last reviewed: [18/07/2026]
Next scheduled review: [18/07/2027]