1. Purpose and scope
This policy explains how Concrete Cows Motorcycle Club protects personal and confidential information. It applies to officers, committee members, administrators, limited administrators, editors, volunteers and contractors handling Club information on the website, email, devices, paper, cloud services or backups. The committee owns this policy; Rupert Campbell-Black is the security and data lead.
2. Core rules
Everyone handling Club information must use it only for authorised purposes; collect only what is needed; keep it accurate; limit access; follow retention periods; use approved secure systems; and immediately report loss, phishing, misuse, unauthorised access or accidental disclosure. Passwords, databases, membership lists and unprotected exports must never be shared through personal messaging accounts or public links.
3. Information classification
| Classification | Examples | Handling |
|---|---|---|
| Public | Published events, approved photographs and public wording | May be shared publicly after approval |
| Internal | Routine committee papers and operational information | Authorised officers and volunteers only |
| Confidential personal data | Membership lists, names, emails, applications, accounts and unpublished photographs | Named roles only; encrypted transfer and storage |
| Restricted | Password hashes, credentials, setup keys, security logs and incidents | Minimum number of full administrators; record and review access |
4. Access control
- Every person must use an individual account and unique username; shared administrator accounts are prohibited.
- Full-administrator access is limited to the minimum number of trusted people.
- Limited administrators may manage events, applications and photographs, but not website wording, users or database maintenance.
- Accounts are disabled promptly when no longer needed, and access is reviewed at least every six months.
5. Passwords and authentication
- Passwords must be at least 12 characters, unique and preferably randomly generated or made from unrelated words.
- Temporary passwords are sent separately from usernames and changed promptly.
- Use a reputable password manager for privileged access.
- Enable multi-factor authentication on hosting, email, domain, backup and database services wherever available.
- Reset suspected disclosed credentials immediately and review the incident.
6. Devices, email and remote access
Devices used for Club data must be supported, updated, screen-locked and encrypted. Do not download Club information to public or shared computers. Protect membership exports in transit and delete local copies when finished. Check recipients and use BCC for group email unless address visibility is agreed. Verify unexpected login links, attachments or bank-detail changes through another channel.
7. Website and hosting security
Enforce HTTPS; patch PHP, hosting and dependencies; keep credentials out of public repositories and release files; use a least-privilege database account; retain role checks, CSRF protection, password hashing, throttling, security headers and audit logs; and keep original photographs outside the public web root. Review audit and failed-login activity monthly. Test material releases and retain a rollback copy.
8. Backups and recovery
Back up the database, configuration and protected photographs on a documented, committee-approved schedule. Encrypt and restrict backups, keep a logically separate copy, document retention, test restoration at least twice yearly, and make and verify a fresh backup before each database migration.
9. Retention and secure disposal
Review expired applications, inactive accounts, exports and incident records at least quarterly. Securely delete electronic files and cross-cut shred paper personal data. Review historical photographs proportionately and handle reasonable objections promptly.
10. Suppliers and data sharing
Before using a supplier, record what it receives and where it processes information; assess security and privacy terms; put contracts in place where required; verify safeguards for overseas transfers; and remove access and retrieve or delete information when service ends. External sharing must be authorised, necessary and lawful.
11. Personal data incidents
- Contact Rupert Campbell-Black immediately at info@concretecowsmc.com.
- Contain the incident without destroying evidence—for example revoke a link, disable an account, change credentials or isolate a device.
- Record what happened, when it began, who and what were affected, and the action taken.
- Preserve relevant logs, messages and files securely.
Where a breach is likely to risk people's rights and freedoms, the Club must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. High-risk breaches must also be communicated to affected people without undue delay. Every breach and the reporting decision must be recorded.
12. Requests and complaints
Forward data-access, correction, deletion, restriction, objection and privacy complaints immediately to Rupert Campbell-Black. Do not delete or alter relevant information after a request. Record its date, verify identity proportionately and track the response deadline.
13. Training, review and enforcement
People with personal-data access must read this policy before access is granted and refresh training annually. Breaches may result in removal of access or a Club role. The committee will review this policy annually, after a significant incident, and whenever systems or processing materially change.
Approval status: Pending committee approval
Policy owner: Concrete Cows Motorcycle Club Committee
Next review: Within 12 months of approval