Bishop of Peterborough’s Office – September 2026
This privacy notice is provided by the Bishop of Peterborough to explain what to expect when we collect and process your personal information in accordance with the [UK GDPR / the EU General Data Protection Regulation (GDPR)].
Data controller(s)
The data controller is:
- The Rt Revd Debbie Sellin, The Bishops’ Office, The Palace, Peterborough PE1 1YA, bishop@peterborough-diocese.org.uk, 01733 562492
For further information on the Bishop of Peterborough please go to:
www.peterborough-diocese.org.uk
Why we collect and use your personal data
- To assess your qualifications and suitability for any office or ministry where you have applied for a ministerial post or office within the diocese.
- To exercise legal and pastoral responsibilities in accordance with the Canons of the Church of England and other relevant legislation, statutory codes, guidance and policies of the Church of England.
- For making appropriate arrangements for your ministerial development (including ministerial development reviews or similar);
- To provide details of clergy with a licence to the Archbishops’ Council for inclusion in, or removal from, the National Register of Clergy.
- To keep a record of the skills and experiences of clergy to enable these to be used to contribute to the mission and ministry of the Church
- To share safeguarding information with an auditor or independent reviewer to facilitate necessary safeguarding audits and safeguarding practice reviews;
- To assess and consider conduct in relation to informal or formal complaints, including the return to ministry assessment
- To transfer your Clergy File when you take up an appointment in a new diocese in the Church of England or the Church in Wales.
- To archive your file for historical research purposes (senior clergy only).
- To undertake relevant duties and obligations in relation to safeguarding;
The categories of personal data we collect and process:
The information we process for this these purposes includes:
- Biographical details
- Information relating to contracts
- Information relating to capability
- Financial information
- Information relating to formal complaints
- Information relating to grievances
- Housing matters
- Information relating to informal complaints
- Ministerial development and training
- Ordination and curacy details
- Pre-ordination details
- Information relating to licensing, including PTO
- Recruitment and appointment
- Safeguarding information
Further details of the records held can be found in the Clergy File Policy.
We also process “special categories”1 of information that may include:
- Race
- Ethnic origin
- Religious belief
- Trade Union membership
- Political opinions
- Health
- Sex life
- Sexual orientation
- Criminal allegations, proceedings or convictions.
The lawful basis for using your information
We collect and use personal data under the following lawful bases:
Personal data
- Consent (Art 6(1)(a)) – sharing of personal data with an external body, except where such sharing is required by legislation or Church of England policies or is in the legitimate interests of the controller; for the sharing of data for the purpose of providing pastoral or therapeutic support; to obtain medical records.
- Contract (Art 6(1)(b)) – processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art 6(1)(c)) – processing is necessary for compliance with a legal obligation to which the controller is subject, as specified in Church or UK legislation.
- Public task (Art 6(1)(e)) – processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the
- controller, as specified in Church legislation and statutory codes.
- Legitimate Interests (Art 6(1)(f)) – to establish, exercise or defend legal claims.
- Legitimate Interests (Art 6(1)(f)) – (Isle of Man and the Channel Islands only) – the inclusion of clergy from the island jurisdictions in the National Clergy Register – national-register-of-clergy-privacy-notice-v1.0-2021.pdf (churchofengland.org).
- Legitimate Interests (Art 6(1)(f)) – for the purpose of safeguarding audits and safeguarding practice reviews.
Legitimate Interests Assessment Summary – safeguarding audits and review
| We have a specific purpose with a defined benefit | The purpose of sharing data with a safeguarding audit or a safeguarding practice review is to enable the auditor to identify areas for consideration to improve safeguarding response to allegations of abuse and safeguarding working practice and thereby creating a safe environment for all. |
| The processing is necessary to achieve the defined benefit. | The reasons for the audit or safeguarding practice review and the necessary processing are to identify strengths and weaknesses and areas for consideration in the safeguarding arrangements, practices, leadership, governance and culture that will lead to improvements. |
| The processing legitimately overrides the interests of the data subject and any risks to their rights or freedoms. | The processing is necessary to achieve the intended purposes, and risks to data subjects are identified and mitigated as far as possible. There are joint interests in learning from the audit or safeguarding practice review and understanding what needs to be done to improve practice. |
For a copy of the full Legitimate Interests Assessment, please use the contact details set out in section 9 below.
Special categories and criminal information
- Explicit consent (Art 9(2)(a) – sharing of personal data with an external body, except where such sharing is required by legislation or Church of England policies or is in the substantial public interest; for the sharing of data for the purpose of providing pastoral or therapeutic support; to obtain medical records
- Legitimate Activity (Art 9(2)(d) – to manage and administer internal functions in relation to membership and/or those with whom we have regular contact. Data is not shared externally outside the institutional bodies that comprise the Church of England or Church in Wales without consent except where specified in this Privacy Notice.
- Substantial Public Interest (Art 9(2)(g) – Data Protection Act 2018 s. 10(3) and Schedule 1:
- Necessary for the exercise of a function conferred on a person by an enactment/rule of law (Schedule 1, Part 2(6))
- Preventing or detecting unlawful acts (Schedule 1, Part 2(10))
- Protection the public against dishonesty etc (Schedule 1, Part 2 (11))
- Safeguarding of children and individuals at risk (Schedule 1, Part 2 (18))
- Insurance (Schedule 1, Part 2 (20))
- Legal claims (Art 9(2)(f) – processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity.
- Archiving (Art 9(2)(j) – archiving senior Clergy Files for public interest, scientific or historical research purposes or statistical purposes.
Consent
It is not always necessary or possible to obtain consent and/or explicit consent for processing and sharing data. Circumstances include but are not limited to:
- where a crime may have been committed;
- where a person is judged to be at risk of significant/serious harm or a person is considered to be a risk of harm to themselves or others;
- The function of the bishop’s office would be prejudiced or prevented if a data subject withheld consent, for example in relation to the provision of medical or safeguarding records.
Who we collect from or share your information with:
We collect your information from:
- You
- Members of the public or parishioners
- Referees
- Church of England bodies
- Church in Wales
- Other Churches
- GPs and other medical professionals
- The Redress Scheme administered by Kennedy’s LLP in accordance with the Abuse Redress Measure 2025
- Educational and training organisations
- Thirtyone:eight – an independent Christian safeguarding charity, who conduct Disclosure and Barring Service (DBS) checks on my behalf
- Church of England Safeguarding Training Portal
- Independent or external auditors or reviewers
- Third-party system providers:
- Pathways
- Eventbrite, through which events and training may be booked
- Legal or other internal/external advisors
Your personal data will be treated as strictly confidential, and will be shared only when necessary, with:
- Institutional bodies that comprise the Church of England for the purposes of administrative functions in connection with your role (including governance bodies and committees)
- The Archbishops’ Council – for the purposes of the National Register
- Crockfords Clerical Directory
- Church in Wales, when you take up an appointment.
- Limited data with other Churches when you take up an appointment.
- Internal and external auditors, and quality assurance reviewers, independent reviewers
- Judicial, statutory, regulatory bodies
- Law enforcement and prosecution agencies pursuing security or criminal investigations
- Legal or other internal/external advisors
- Third Party Providers:
- Optimity the Managed Service Provider for the office IT
- Amperative Limited, who provide an online contact management system for the Diocese of Peterborough.
- Microsoft Online Services, through use of Microsoft 365, Office 365, and SharePoint
- Oracle (which updates the National Register)
- Legal or other internal/external advisors including:
- Anna Spriggs, a partner of Howes Percival LLP, fulfils the Diocesan Registry function and provide legal advice to the Bishop and James Stewart the Deputy Registrar (Hunt & Coombs LLP).
- The Diocesan Chancellor David Pittaway KC and the Deputy Chancellor Sir Martin Griffiths KC
- Legal advisers who provide specialist, non ecclesiastical, legal advice to the Bishop.
- Thirtyone:eight – an independent Christian safeguarding charity, who conduct Disclosure and Barring Service (DBS) checks on my behalf, as well as offering other safeguarding support services
Copies of your file or specific records created under the Clergy File Policy may be held by other relevant individuals in the diocese for the purposes of day-to-day administration or to undertake necessary legal or pastoral duties on behalf of the bishop.
A National Safeguarding Information Sharing Agreement (ISA) has been signed by Church of England bodies and the Church in Wales under the Church of England Information Sharing Framework.
A National Safeguarding Data Sharing Agreement (DSA) has been signed by the Church of England bodies and the Church in Wales and the National Police Chiefs Council.
Clergy Discipline Legislation – Clergy Discipline Measure 2003 (CDM)
The CDM disciplinary system is a judicial process and is governed by specific legislation and a statutory Code of Practice issued by the Clergy Discipline Commission under section 3 of the CDM. Access to CDM papers held in the Clergy File is restricted to relevant individuals in the Bishop’s office and can only be accessed in accordance with the Clergy File Policy.
No CDM (and by extension Ecclesiastical Jurisdiction Measure 1963 (EJM)) papers will be shared with any external individual or body (except law enforcement agencies) unless subject to a legal order from a court or tribunal. Therefore, safeguarding auditors or independent reviewers will not be given access to the CDM/EJM papers.
The CDM (or EJM) process and related data is exempt from Articles 5 and 12-21 of the UK GDPR, pursuant to the Data Protection Act 2018, Schedule 2, Part 2, para 14 and therefore cannot be included in individual rights requests.
Return to Ministry CDM reports are not covered by this exemption.
Confidential References
The Episcopal Reference and Clergy Current Status Letter (CCSL) and any other confidential references are exempt from Articles 13, 14 and 15 of the UK GDPR, pursuant to the Data Protection Act, Schedule 2, Part 4, para 24, and therefore are:
- not disclosable in a subject access request, and
- not covered by the requirements for a Privacy Notice, and
- cannot be sent outside the UK without informing the data subject of any safeguards.
Your personal data will/will not be sent to countries outside the UK/EEA.
I will not transfer your personal information to countries outside the United Kingdom, except:
- where I or my office use the services of a third party (listed above) who host data outside the UK. I and my office will only use third parties who ensure that data hosted outside the UK is held in accordance with UK GDPR.
- In response to a confidential reference from an employer or appointment authority based outside the UK/EEA
- to judicial, statutory, regulatory bodies, law enforcement and prosecution agencies pursuing security or criminal investigations based outside of the UK/EEA where there is a substantial public interest in doing so.
- Where data transfer is required in relation to our international link diocese, or a confidential reference, separate consent will be sought.
How long do we keep your information?
We will keep your information in accordance with the retention section of the Clergy File Policy and Guidance, and the Church of England retention schedule.
Church of England Retention Schedule
Your rights
You have the following rights regarding your personal data, except where a relevant exemption applies:
- The right to be informed about any data we hold about you.
- The right to request a copy of your personal data which we hold about you.
- The right to withdraw your consent at any time (if applicable).
- The right to request that we correct any personal data if it is found to be inaccurate or out of date.
- The right to request your personal data is erased where it is no longer necessary for us to retain such data; documents that are listed in the Guidance as mandatory are unlikely to meet the criteria for erasure.
- The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing.
- The right to object to the processing of your personal data (if applicable).
To exercise these rights, please use the contact information provided below.
Complaints or concerns
If you have any queries or concerns regarding the processing of your personal data, please contact:
To exercise all relevant rights, queries or complaints please contact The Bishops’ Office, The Palace, Peterborough PE1 1YA, bishop@peterborough-diocese.org.uk
This Privacy Notice will be reviewed and amended from time to time to align with changes to Church or UK legislation, codes You have the right to make a complaint at any time to [the Information Commissioner online at: Make a complaint about how an organisation has used your personal information | ICO or by phone on 0303 123 1113 (local rate).
Under current arrangements, the ICO will generally expect you to have approached the data controller first, before making a complaint to them.
This Privacy Notice will be reviewed and amended from time to time to align with changes to Church or UK legislation, codes of practice, policy or guidance.