Society Specific Documents

 

Society Event Proposal Form - Use this template if you want to organise a larger event that is not your usual activity. Return this form to your society coordinator or club contact for approval.

Society Inventory Template - Use this template to keep track of your societies/clubs inventory

Template for Society AGM ENG

Template for Society AGM Cymraeg

Society Tier Tracker

Society Tier Tracker-Cymraeg

Societies Risk Assessment Matrix

Operating Procedures Template

Societies Development Plan Template - Please complete and return to [email protected]

Guild of Societies Constitution Template - ENG

Societies Funding Policy

Widening Access and GDPR

 

Widening Access

As groups that are run by students, for students, Clubs and Societies should strive to be accessible to as many students as possible. These groups can stop students feeling isolated and, in extreme cases, can keep students on their course. Often, students facing barriers to participating in Club and Society activities are most vulnerable to feeling isolated and most likely to drop out of their course. Therefore, Committees should work to break down barriers to participation in their activities.

A Widening Access Policy should act as a working document to help Committee Members identify the barriers faced by different students and create action points to break down these barriers. Some initiatives may be aimed at breaking down barriers for specific groups of students, such as Erasmus students, student parents and students who do not drink alcohol. Other initiatives may focus on helping individual members with specific needs. Each initiative that you create should be specific to the activities of your group. It is unreasonable to expect this Policy to remove every barrier from every event; instead, it should help all members get value from their membership, in one way or another.

We recommend that you identify 2-3 different points in your Widening Access Policy, looking at different aspects about what your Club or Society does and how you can improve. 

This Widening Access Policy Template can be used to create your own Policy for your Club or Society. If you're not sure where to begin, here are three examples, or you can email [email protected] with any questions.

General Data Protection Regulation (GDPR)

The General Data Protection Regulation or GDPR came into effect in the 2017-2018 academic year. This impacts on how personal data is collected and used by organisations, including the University, the Students’ Union and our student groups. There will be an increase in penalties for organisations (data controllers) and, more notably, for individuals (data processors). The SU has made changes to the way it operates over the summer to comply with the GDPR and all student groups must also be ready to do so from Freshers 2017.

Due to the GDPR, we highly recommend that you do not collect personal information under any circumstance, instead using the information you are given access to through the sale of memberships and tickets. Directing people to a Facebook Group is an easy alternative to collecting email addresses and other data. However, if you do collect personal data, please read and follow the below information.

 

What is Persoal Data?

Personal data includes any information that relates to an “identified or identifiable” person. Within student groups, examples of personal data include the names, email addresses, student numbers and phone numbers of members and non-members that you may collect or are given access to via cardiffstudents.com, plus any data collected that is specific to the activities of your student group.

 

What do you need to do differenly?

If you collect personal data from individuals, you must get their explicit permission for everything you will do with the data you collect. This can be done by simply asking an extra question when producing surveys. For example, if you are collecting information for an additional mailing list, you may ask…

“I give consent for this information to be used to contact me regarding events and trips, membership, offers and news from the xxxxx Society.”

You would also need a tick box or drop-down option for individuals to explicitly agree to this. You cannot get implicit permission (i.e. “By submitting this survey I give permission for my data to be used…).

We recommend using Google Forms or similar to collect personal information. This can explicitly ask for permission and hides data from people submitting data. It will also timestamp when the survey is submitted, creating an audit trail in case complaints are made.

Once you have collected the information, it must only be used for the purposes it was collected. You must also promptly respond to requests for data to be removed from your records or for individuals to unsubscribe from mailing lists. You should include unsubscribe instructions in all email communications.

 

Third Parties

The Students’ Union, your group or individuals using data may be fined by the Information Commissioner for the misuse of data. This includes making data available – intentionally or accidentally – to third parties, including sponsors, other organisations and anyone who is not a committee member. Therefore, you should not give sponsors any personal data from your records or sell any personal data to another organisation.  This may be considered a disciplinary offense.

When contacting people via email, always use the BCC option. This means that recipients will not be able to see other recipients email address and therefore prevents them from capturing and misusing this data. We highly recommend using the Mailing function under your admin tools on cardiffstudents.com to contact individuals, as this automatically BCCs all recipients for you.

 

Data Security

Storing data securely is another important part of proper data use. Make sure that data is stored on devices with suitable passwords and do not store data on a shared device. When transferring data on USB sticks or other devices, make sure they are kept securely and are not left behind in a shared computer or in a public place.

 

How could this affect you?

As a committee member, you are a data processor and therefore have a responsibility to handle personal data in an appropriate way in line with GDPR. Failure to follow this guidance may result in disciplinary action from the Students’ Union and/or the University as well as potential fines from the Information Commissioner’s Office.