Skip to content

September 2026

This privacy notice is provided by the Bishop of Peterborough to explain what to expect when we collect and process your personal information in accordance with the [UK GDPR / the EU General Data Protection Regulation (GDPR)].

Data Controller

The data controller is:

For further information on the Bishop of Peterborough please go to:

www.peterborough-diocese.org.uk

Why We Collect and Use Your Personal Data

We collect and process personal data for the following purposes:

  • To assess your qualifications and suitability for any office, licence or lay ministry role within the Diocese of Peterborough.
  • To exercise legal and pastoral responsibilities in accordance with the Canons of the Church of England and other relevant legislation, statutory codes, guidance and policies of the Church of England.
  • To make appropriate arrangements for your ministerial development, including training, ministerial reviews and continuing development.
  • To maintain records relating to licensing, authorisation and ministry.
  • To keep a record of the skills and experience of Readers and Licensed Lay Ministers in order to support the mission and ministry of the Diocese.
  • To undertake relevant duties and obligations in relation to safeguarding.
  • To facilitate safeguarding audits and safeguarding practice reviews, including the sharing of information with auditors and independent reviewers where necessary.
  • To assess and consider matters relating to informal complaints, formal complaints, grievances, capability or conduct concerns.
  • To administer and maintain records to ensure that relevant information is accurate, complete and appropriately retained.

Categories of Personal Data We Collect and Process

The information we process may include:

  • Biographical details.
  • Licensing and ministry information.
  • Recruitment and appointment records.
  • Ministerial development and training records.
  • Safeguarding information.
  • Safeguarding training records.
  • DBS information.
  • Information relating to informal complaints.
  • Information relating to formal complaints.
  • Information relating to grievances.
  • Information relating to capability matters.
  • Health information where relevant to ministry, support arrangements or safeguarding obligations.

Further details of the records held can be found in the relevant Lay Ministry policies and procedures.

We may also process special category information including:

  • Race.
  • Ethnic origin.
  • Religious belief.
  • Trade union membership.
  • Political opinions.
  • Health information.
  • Sexual orientation.
  • Criminal allegations, proceedings or convictions.

The Lawful Basis for Using Your Information

Personal Data

We collect and use personal data under the following lawful bases:

  • Consent (Article 6(1)(a)) – sharing of personal data with external bodies where required and for pastoral or therapeutic support.
  • Contract (Article 6(1)(b)) – processing necessary for the performance of a contract or prior to entering a contract.
  • Legal Obligation (Article 6(1)(c)) – processing required by Church or UK legislation.
  • Public Task (Article 6(1)(e)) – processing necessary for the exercise of the Bishop’s statutory and ecclesiastical responsibilities.
  • Legitimate Interests (Article 6(1)(f)) – establishing, exercising or defending legal claims.
  • Legitimate Interests (Article 6(1)(f)) – safeguarding audits and safeguarding practice reviews.

Legitimate Interests Assessment Summary – safeguarding audits and review 

We have a specific purpose with a defined benefit The purpose of sharing data with a safeguarding audit or a safeguarding practice review is to enable the auditor to identify areas for consideration to improve safeguarding response to allegations of abuse and safeguarding working practice and thereby creating a safe environment for all. 
Processing is necessary to achieve the defined benefit. The reasons for the audit or safeguarding practice review and the necessary processing are to identify strengths and weaknesses and areas for consideration in the safeguarding arrangements, practices, leadership, governance and culture that will lead to improvements. 
The processing legitimately overrides the interests of the data subject and any risks to their rights or freedoms. The processing is necessary to achieve the intended purposes, and risks to data subjects are identified and mitigated as far as possible. There are joint interests in learning from the audit or safeguarding practice review and understanding what needs to be done to improve practice 

For a copy of the full Legitimate Interests Assessment, please use the contact details set out below. 

Special Category and Criminal Information

  1. Explicit consent (Art 9(2)(a) – sharing of personal data with an external body, except where such sharing is required by legislation or Church of England policies or is in the substantial public interest; for the sharing of data for the purpose of providing pastoral or therapeutic support; to obtain medical records 
  2. Legitimate Activity (Art 9(2)(d) – to manage and administer internal functions in relation to membership and/or those with whom we have regular contact. Data is not shared externally outside the institutional bodies that comprise the Church of England or Church in Wales without consent except where specified in this Privacy Notice. 
  3. Substantial Public Interest (Art 9(2)(g) – Data Protection Act 2018 s. 10(3) and Schedule 1: 
  4. Necessary for the exercise of a function conferred on a person by an enactment/rule of law (Schedule 1, Part 2(6)) 
  5. Preventing or detecting unlawful acts (Schedule 1, Part 2(10)) 
  6. Protecting the public against dishonesty etc (Schedule 1, Part 2 (11)) 

4.           Safeguarding of children and individuals at risk (Schedule 1, Part 2 (18)) 

5.           Insurance (Schedule 1, Part 2 (20)) 

  1. Legal claims (Art 9(2)(f) – processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity. 

It is not always necessary or possible to obtain consent before processing information. This may include circumstances where:

  • A crime may have been committed.
  • A person may be at risk of serious harm.
  • A person may present a risk of harm to themselves or others.
  • Obtaining consent would prejudice the functions of the Bishop’s Office, including safeguarding processes.

Who We Collect Information From

We may obtain information from:

  • You.
  • Members of the public or parishioners.
  • Referees.
  • Church of England bodies.
  • The Church in Wales.
  • Other churches.
  • Educational and training providers.
  • Thirtyone:eight.
  • The Church of England Safeguarding Training Portal.
  • Independent auditors and reviewers.
  • The Redress Scheme administered by Kennedy’s LLP in accordance with the Abuse Redress Measure 2025 
  • Legal advisers and other professional advisers.

Who We Share Information With

Your personal data will be treated as confidential and shared only where necessary with:

  • Institutional bodies that comprise the Church of England.
  • Governance bodies and diocesan committees.
  • Archdeacons.
  • The Warden of Lay Ministry and authorised diocesan officers.
  • The Church in Wales where relevant.
  • Internal and external auditors and reviewers.
  • Judicial, statutory and regulatory bodies.
  • Law enforcement and prosecution agencies.
  • Professional advisers.
  • Third-party providers may include:
    • Optimity.
    • Amperative Limited.
    • Microsoft Online Services (Microsoft 365, Office 365 and SharePoint).
    • Eventbrite.
    • Pathways.
    • Thirtyone:eight.
    • Oracle (where applicable to Church systems).

A National Safeguarding Information Sharing Agreement (ISA) has been signed by Church of England bodies and the Church in Wales under the Church of England Information Sharing Framework. A National Safeguarding Data Sharing Agreement (DSA) has been signed by Church of England bodies, the Church in Wales and the National Police Chiefs’ Council.

Confidential References

Confidential references are exempt from Articles 13, 14 and 15 of the UK GDPR pursuant to Schedule 2, Part 4, Paragraph 24 of the Data Protection Act 2018 and therefore:

  • Are not disclosable in a subject access request.
  • Are not covered by the requirements for a privacy notice.
  • May not be sent outside the UK without informing the data subject of safeguards.

Transfers Outside the UK

We do not normally transfer personal information outside the United Kingdom.

However, information may be transferred:

  • Through approved third-party providers that host data outside the UK.
  • In relation to confidential references.
  • To judicial, statutory, regulatory or law enforcement agencies where there is a substantial public interest.
  • Where separate consent has been obtained for an international transfer.

How Long We Keep Your Information

We will keep your information in accordance with the retention section of the Clergy File Policy and Guidance, and the Church of England retention schedule.

Church of England Retention Schedule

Your Rights

  • Subject to applicable exemptions, you have the right to:
  • Be informed about the personal data we hold about you.
  • Request access to your personal data.
  • Withdraw consent where consent is relied upon.
  • Request correction of inaccurate information.
  • Request erasure of personal data in certain circumstances.
  • Request restriction of processing.
  • Object to processing in certain circumstances.

Complaints or Concerns

If you have any questions or concerns regarding the processing of your personal data, please contact: The Bishops’ Office, The Palace, Peterborough PE1 1YA, bishop@peterborough-diocese.org.uk

You have the right to make a complaint at any time to [the Information Commissioner online at: Make a complaint about how an organisation has used your personal information | ICO or by phone on 0303 123 1113 (local rate). 

Under current arrangements, the ICO will generally expect you to have approached the data controller first, before making a complaint to them.

This Privacy Notice will be reviewed and amended from time to time to align with changes to Church or UK legislation, codes of practice, policy or guidance.me to align with changes to Church or UK legislation, codes of practice, policy or guidance.