Some of the language used in privacy notices can be specialised. The Information Commissioner's website provides a useful introduction to key terms and concepts.
We will process your personal data when using the Parliament gym. Your full name will be recorded in order for us to keep track on those who have permission to use the gym, having completed an induction and agreed to the disclaimer form. This allows the Scottish Parliamentary Corporate Body (SPCB) Facilities Management Office and Security Office to manage the safe use of the facility. For gym users without Scottish Parliament email accounts, a personal email address will be requested in order to share service updates.
We may also require to process your personal data through QR Codes for the purposes of complying with the Scottish Parliament’s obligations under Test and Protect.
Further information about the use of QR codes in our privacy notice
Read the FAQ about QR codes in the Parliament
Normal category data such as first names, surnames and in limited cases personal email addresses.
Information is provided by the gym user with their consent via a disclaimer form hosted by Microsoft Forms on the SPCB’s sharepoint site. Personal email addresses will be requested separately when required via email from the SPCB’s Contract Manager for the gym service. Providing a personal email address is optional and the gym user can decline to provide this information if they wish and still use the gym.
Data protection law states that we must have a legal basis for handling your personal data.
The legal basis for the processing as described above is that it is necessary for the purposes of the legitimate interests of the SPCB to provide safe use of the facilities to building users (Article 6(1)(f) UK General Data Protection Regulation (UK GDPR)).
For the processing of personal data through QR Codes the legal basis is that it is necessary for performance of a legal obligation (Article 6(1)(c) UK GDPR).
Information will be kept until the gym user leaves the organisation. Records will be checked every 6 months and any users who have left the organisation will be removed. Data will be held on Microsoft Forms, with limited access to only those required to manage it.
Data protection legislation sets out the rights which individuals have in relation to personal data held about them by data controllers. Applicable rights are listed below. You can exercise your data subject rights in particular circumstances depending on the purpose for which the data controller is processing the data and the legal basis upon which the processing takes place.
The following rights may apply:
You have the right to request a copy of the personal information about you that we hold.
Further information on how to make a 'data subject access request'.
You have the right to ask us to correct the personal data we hold about you. We want to make sure that your personal information is accurate, complete and up to date and you may ask us to correct any personal information about you that you believe does not meet these standards.
You have the right at any time to require us to stop using your personal information for direct marketing purposes. In addition, where we use your personal information to perform tasks carried out in the public interest then, if you ask us to, we will stop using that personal information unless there are overriding legitimate grounds to continue.
You have the right to ask us to delete personal information about you where:
In some cases, you may ask us to restrict how we use your personal information. This right might apply, for example, where we are checking the accuracy of personal information about you or assessing the validity of any objection you have made to our use of your information. The right might also apply where this is no longer a basis for using your personal information, but you don't want us to delete the data. Where this right is validly exercised, we may only use the relevant personal information with your consent, for legal claims or where there are other public interest grounds to do so.
Please contact us using the details below if you wish to use any of these rights.
We keep this privacy statement under regular review and will put any updates on this website. You can get paper copies of the privacy statement using the contact information below.
This privacy statement was last updated on 16 November 2021.
We seek to resolve directly all complaints about how we handle personal information but you also have the right to lodge a complaint with the Information Commissioner's Office.
Or by phone at: 0303 123 1113
If you have any further questions about the way in which we process personal data, or
about how to exercise your rights, please contact the Head of Information Governance
at:
The Scottish Parliament
Edinburgh
EH99 1SP
Telephone: 0131 348 6913
(Calls are welcome through the Text Relay service or in British Sign Language through contactSCOTLAND-BSL.)
Email: dataprotection@parliament.scot
Please contact us if you require information in another language or format