Full privacy notice
Suffolk Libraries takes the safety of your personal information seriously and this notice explains why we collect your personal information, how we use it and keep it safe. It also explains your rights.
Under the Data Protection Act 2018 the Data Controller is Suffolk’s Libraries IPS Limited, Ipswich County Library, Northgate Street, Ipswich IP1 3DE 01473 351249 and the person responsible for data protection is our Compliance Manager, Gareth Lewry. privacy@suffolklibraries.co.uk.
What information does Suffolk Libraries collect and how is it collected?
We collect a range of data which will be different depending on the service, event or activity you wish to access:
When you sign up for a library card, we collect details from your ID documentation including your name, address including post code, date of birth, gender, contact details. This can be updated at any time by either logging into your account online or by speaking to a member of staff. Once you have a library card, we also collect your borrowing history.
When you donate through our website, information collected may include contact and account information such as name, email address, physical address, location data, phone number, social media information, standard web log entries that contain an IP address, cookies (first party, third party, session, persistent, and flash), web beacons, page URL and timestamp.
When signing up for activities and events on our website or in a library we collect a range of data depending on the activity or event being run. This can include e.g., name, address including post code, date of birth, gender and contact details.
Sometimes we will gather data on who is using our libraries and we will engage customers with surveys. The information collected can include – name, age, address including post code, sex, ethnicity and other demographic data.
When using our website we collect cookies (see Cookie Policy).
Some of our libraries have CCTV and staff use body-worn cameras which will collect static or moving images and audio data (see CCTV and Body Worn Camera Policy).
Why does Suffolk Libraries need it and how is it used?
We only collect the minimum amount of information required to provide the service you are using or to comply with our contracts with funders and service providers.
When signing up for a library card we need to know who you are as you are making a contract with us to provide library services. We use it to contact you about your account, such as when a reservation has arrived for you, and to work out any charges owing.
We also use your email address to contact you with information about any event(s) or activities you have signed up for, or if you have agreed to it, we will contact you with news about Suffolk Libraries' events and activities that may be of interest to you or book recommendations. (You can opt out at any time by clicking unsubscribe at the bottom of any email you receive from us).
We need your age as some categories of stock have age limits and some activities available in libraries are aimed at specific age groups.
Age, gender and ethnicity also help us check we are reaching all sections of our communities and identify where we need to develop new services to attract underrepresented groups of users.
When donating through our website we need the financial information outlined above to document the transaction as required under HMRC and Charity Commission rules.
We run a wide range of events and activities across our libraries. Some are Suffolk Libraries run and from time to time we partner with other likeminded trusted organisations to provide events or activities that communities have shown interest in, or we feel communities could benefit from. As part of these events or activities we may collect data for reporting purposes with the partner organisation(s) or to ensure we are reaching as many areas and communities as we can.
How do we protect your data?
Suffolk Libraries takes the security of your data seriously. It has internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused, or disclosed, and is not accessed except by our employees and employees and contractors in the proper performance of their duties.
Any third parties we use to provide a service on our behalf are held to a high standard and we ensure they have adequate security systems and processes in place to ensure your data is held or processed in accordance with their contract with us and in accordance with their obligations under Data Protection Act 2018.
We train all our employees on their role and responsibilities of processing and protecting personal data. We have security provisions in place with our IT system provider to ensure personal data is secure, such as firewalls, anti-virus software and security profile settings.
Legal basis for processing
Consent
In some cases, we will only use your personal information where we have your consent, for example:
Sending you electronic communications about your account, events or activities or updating you about our services
Donating to Suffolk Libraries via our website
When you sign up for events and activities
Contract
We need to use data you provide us to fulfil a contract with you, or example:
When you sign up for a library card to borrow books and resources from the library
Legal Obligation
We need to use some data you provide us where we have a legal obligation, for example:
Dealing with complaints and claims,
HMRC for financial transactions, or
For complying with guidance from the Charity Commission.
Legitimate interest
This means that the reason we are using your information is because there is a legitimate interest for Suffolk Libraries to process it to help us ensure we are utilising public funds effectively and providing the best service to our communities.
Whenever we are to process your Personal Information under the ‘legitimate interest’ lawful basis we make sure that we consider your rights and interests before proceeding.
Your rights
You have various rights in respect of the personal information we hold about you – these are set out in more detail below.
Access to your personal information: You have the right to request access to a copy of the personal information that we hold about you, along with information on what personal information we use, why we use it, who we share it with, how long we keep it for and whether it has been used for any automated decision making. You can make a request for access free of charge. Please make all requests for access in writing and provide us with evidence of your identity.
Right to object: You can object to our processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes. Please contact us as noted above, providing details of your objection.
Consent: If you have given us your consent to use personal information you can withdraw your consent at any time.
Rectification: You can ask us to change or complete any inaccurate or incomplete personal information held about you.
Erasure: You can ask us to delete your personal information where it is no longer necessary for us to use it, you have withdrawn consent, or where we have no lawful basis for keeping it.
Portability: You can ask us to provide you or a third party with some of the personal information that we hold about you in a structured, commonly used, electronic form, so it can be easily transferred.
Restriction: You can ask us to restrict the personal information we use about you where you have asked for it to be erased or where you have objected to our use of it.
No automated decision making: Automated decision-making takes place when an electronic system uses personal information to make decisions without human intervention. You have the right not to be subject to automated decisions that will create legal effects or have a similar significant impact on you, unless you have given us your consent, it is necessary for a contract between you and us or is otherwise permitted by law. You also have certain rights to challenge decisions made about you. We do not currently carry out any automated decision-making.
Please note, some of these rights only apply in certain circumstances and we may not be able to fulfil every request.
If you wish to exercise any of these rights, you can do so by contacting privacy@suffolklibraries.co.uk.
If you have a concern about the way we are collecting or using your personal data, we ask that you raise your concern with us in the first instance by contacting us at privacy@suffolklibraries.co.uk.
Alternatively, you can contact the Information Commissioners office at https://ico.org.uk/concerns/.