Making a complaint
"*" indicates required fields
The RSE collects personal information relating to a variety of data subjects from Fellows of the RSE and members of the Young Academy of Scotland through to attendees at events, awards applicants, venue clients and staff members throughout the course of its activities. This document delineates the types of personal information that the RSE is likely to collect, the ways in which we collect and process personal information and the rights of data subjects as outlined by the General Data Protection Regulation (GDPR, 2018).
The RSE may collect a number of different personal details which are about a person and which, either on their own or in combination with other information already held about that person, will allow us to identify that person as an individual. Depending on the nature of your relationship with the RSE, these details may include but are not limited to the following:
In accordance with GDPR, the RSE endeavours to collect personal information directly from the data subject and will use all such information solely for the predefined purpose(s) for which that information has been provided.
The RSE may collect information from and/or combine any personal information which has been provided by a data subject with other sources when it is lawful to do so and when so doing is likely to enhance the efficiency and relevance of the services that we provide to others. Such sources may include:
The RSE may also on occasion collect and use sensitive personal information such as dietary or access and assistance requirements which may indicate a health condition. In all such instances, however, we will ask you to provide the necessary details only. For example, we may need to collect sensitive personal information in order to assist with any access requirements that you may have and to comply with our legal obligations under equality legislation. In other cases, we will collect this type of information only with your clear consent. Should you provide us with any sensitive personal information in any other instance, you will be deemed to have consented to our collection and use of that information.
The RSE collects personal information through one or more of the following data collection media:
The personal information collected may be stored in electronic and/or hard copy formats.
The RSE may use personal information for a variety of purposes, depending upon the data subject’s relationship with the RSE and/or the specific service(s) that have been requested. The RSE will use personal information for one or more of the following purposes:
Personal information will, however, be processed if and only if one or more of the following conditions has been satisfied:
Personal information will be made available to members of the RSE’s staff who need to see it in order to perform their functions/roles/responsibilities in respect of the services that have been requested and/or agreed upon. Information may be held in our Customer Relationship Management (CRM) database in order to consolidate details of a data subject’s dealings with the RSE in its entirety and may be shared with service providers such as caterers, sister academies and funding bodies on a need-to-know basis. The RSE will, however, ensure that a confidentiality agreement has been put in place with all such parties prior to the disclosure of any personal data.
The RSE takes all possible steps to protect the security of personal information in accordance with our legal obligations with information being stored either in secure storage or electronically in a secure server and/or databases that are password protected and made accessible to staff on a need-to-know basis only.
Please note, however, that the RSE cannot guarantee the security of the transmission of personal information via the internet. All personal information should therefore be submitted online if and only if the data subject is accepting of the incumbent security risks.
The RSE will keep personal details on record until we have dealt completely with a data subject’s request, enquiry or contract and then for a reasonable period thereafter in accordance with data protection and other legislation as set out in the RSE’s Records Management Policies and Procedures.
Should the RSE decide that the retention of personal information is no longer necessary, all such information will be destroyed/deleted in a secure and confidential manner.
Any personal information provided to the RSE in relation to its Fellows, Young Academy of Scotland members and recipients of awards may, however, be kept indefinitely for the purposes of maintaining a comprehensive archive of the RSE’s activities.
Data subjects are entitled to request:
A subject access request should be submitted in writing to the RSE’s Data Protection Officer:
Email:
dataprotection@therse.org.uk
Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ
The RSE may require an individual to verify his/her identity and/or to provide further details in order to locate the required information but will endeavour to respond to all such enquiries within one calendar month once the necessary information has been provided.
In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE will require that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be denied.
A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:
Whenever possible, they will include also:
If these details are not yet available, the RSE will provide them or an indication of the likely timescale required to provide them to the Information Commissioner’s Office (ICO) by completing and submitting a second notification form within three days of the initial notification.
If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:
For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@therse.org.uk.
The RSE collects personal information relating to a variety of data subjects from Fellows of the RSE and members of the Young Academy of Scotland through to attendees at events, awards applicants, venue clients and staff members throughout the course of its activities. This document delineates the types of personal information that the RSE is likely to collect, the ways in which we collect and process personal information and the rights of data subjects as outlined by the General Data Protection Regulation (GDPR, 2018).
The RSE may collect a number of different personal details which are about a person and which, either on their own or in combination with other information already held about that person, will allow us to identify that person as an individual. Depending on the nature of your relationship with the RSE, these details may include but are not limited to the following:
In accordance with GDPR, the RSE endeavours to collect personal information directly from the data subject and will use all such information solely for the predefined purpose(s) for which that information has been provided.
The RSE may collect information from and/or combine any personal information which has been provided by a data subject with other sources when it is lawful to do so and when so doing is likely to enhance the efficiency and relevance of the services that we provide to others. Such sources may include:
The RSE may also on occasion collect and use sensitive personal information such as dietary or access and assistance requirements which may indicate a health condition. In all such instances, however, we will ask you to provide the necessary details only. For example, we may need to collect sensitive personal information in order to assist with any access requirements that you may have and to comply with our legal obligations under equality legislation. In other cases, we will collect this type of information only with your clear consent. Should you provide us with any sensitive personal information in any other instance, you will be deemed to have consented to our collection and use of that information.
The RSE collects personal information through one or more of the following data collection media:
The personal information collected may be stored in electronic and/or hard copy formats.
The RSE may use personal information for a variety of purposes, depending upon the data subject’s relationship with the RSE and/or the specific service(s) that have been requested. The RSE will use personal information for one or more of the following purposes:
Personal information will, however, be processed if and only if one or more of the following conditions has been satisfied:
Personal information will be made available to members of the RSE’s staff who need to see it in order to perform their functions/roles/responsibilities in respect of the services that have been requested and/or agreed upon. Information may be held in our Customer Relationship Management (CRM) database in order to consolidate details of a data subject’s dealings with the RSE in its entirety and may be shared with service providers such as caterers, sister academies and funding bodies on a need-to-know basis. The RSE will, however, ensure that a confidentiality agreement has been put in place with all such parties prior to the disclosure of any personal data.
The RSE takes all possible steps to protect the security of personal information in accordance with our legal obligations with information being stored either in secure storage or electronically in a secure server and/or databases that are password protected and made accessible to staff on a need-to-know basis only.
Please note, however, that the RSE cannot guarantee the security of the transmission of personal information via the internet. All personal information should therefore be submitted online if and only if the data subject is accepting of the incumbent security risks.
The RSE will keep personal details on record until we have dealt completely with a data subject’s request, enquiry or contract and then for a reasonable period thereafter in accordance with data protection and other legislation as set out in the RSE’s Records Management Policies and Procedures.
Should the RSE decide that the retention of personal information is no longer necessary, all such information will be destroyed/deleted in a secure and confidential manner.
Any personal information provided to the RSE in relation to its Fellows, Young Academy of Scotland members and recipients of awards may, however, be kept indefinitely for the purposes of maintaining a comprehensive archive of the RSE’s activities.
Data subjects are entitled to request:
A subject access request should be submitted in writing to the RSE’s Data Protection Officer:
Email: dataprotection@theRSE.org.uk
Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ
The RSE may require an individual to verify his/her identity and/or to provide further details in order to locate the required information but will endeavour to respond to all such enquiries within one calendar month once the necessary information has been provided.
In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE will require that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be denied.
A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:
Whenever possible, they will include also:
If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:
For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@theRSE.org.uk
The Royal Society of Edinburgh (RSE) is committed to protecting your personal data.
This policy outlines the types of personal data the RSE is likely to collect, and how we ensure this information is held securely and respectfully. The RSE is a registered Scottish Charity (SC000470), and is the parent charity of the RSE Scotland Foundation, a registered Scottish Charity (SC024636).
Personal data means any information about you through which you can be identified. This could include your name and contact details, biographical information, information about your interests and qualifications, or an image of yourself.
Special categories of personal data require a higher level of protection. This data includes information about a person’s race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification purposes, health data, and sexual orientation.
This policy is kept under regular review, and may be modified from time to time. This policy was last updated and approved by the RSE’s Senior Leadership Team on 08/06/2026.
Legal Basis for Processing
By ‘processing’, we mean what happens to your personal data – this could be collecting, recording, keeping, storing, sharing, archiving, deleting, and destroying it.
The lawful bases set out in the GDPR that we use to process your information are:
(a) Consent: we will ask for your consent to process your data. This includes but is not exclusive to marketing preferences, use of cookies, and processing Diversity, Equality, & Inclusion data. Data subjects will always be given visibility of our Privacy Policy and the option to opt-out under this basis;
(b) Contractual obligation: we are required to process your data in order to fulfil the terms of a contract we have with you;
(c) Legal obligation: we are required to keep some data for legal obligations, for example, tax purposes;
(d) Vital interests: we will use personal data if necessary to protect your life, for example, using health information in the event of a medical emergency.
(e) Public task: we are required to support public organisations by supplying them with certain information, for example, the Home Office in its statutory duties;
(f) Legitimate interest: we require your personal information in order to enable us to manage and carry out our core interests as an organisation. Data subjects will always be given visibility of our Privacy Policy and the option to opt-out under this basis.
You have the right to request access to the personal data we process regarding you, and have the right to request rectification of your personal data if there are inaccuracies. Under certain circumstances, you are entitled to request the erasure of your personal data, restrict the processing of your personal data, or object to our processing of your personal data.
Under certain circumstances, you are entitled to receive the personal data concerning you in a structured, commonly used and machine-readable format, and you have the right to transmit your personal data to another data controller.
You have the right to fully or partially withdraw consent previously given regarding the processing of personal data at any time, with effect from the time of the withdrawal. Parents may also fully or partially withdraw consent previously given regarding the processing of their child’s data.
If you have any complaints regarding our processing of your personal data you have the right to lodge a complaint with the RSE, either by either using our online form or by writing directly to the DPO.
You also have the right to lodge a complaint with the Information Commissioner (the UK’s independent authority for data protection and information rights).
To make a subject access request, please submit your request in writing to the RSE’s Data Protection Officer:
Email:
dataprotection@therse.org.uk
Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ
Subject access requests will usually be answered within one month. If we require additional information to confirm your identity or clarify the scope of your request, we will contact you as soon as possible. In certain circumstances (for example where a request is particularly complex, or where we have received a number of requests from the same individual) we may extend the response period by up to two months. If an extension is required, we will inform you within one month of receiving your request and explain the reasons for the delay.
In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE may ask that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be fully or partially denied, or redaction may be applied.
A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:
Whenever possible, they will include also:
If these details are not yet available, the RSE will provide them or an indication of the likely timescale required to provide them to the Information Commissioner’s Office (ICO) by completing and submitting a second notification form within three days of the initial notification.
If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:
For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@therse.org.uk.
For the purposes of engaging supporters with our fundraising efforts, the RSE may collect and review your personal information including:
This information will be used to inform you about upcoming events and activities, provide you with networking opportunities, and notify you about our fundraising activities, including requests to consider giving financial support to the RSE, or to ask you to consider supporting us in other ways. The RSE may also use this information to ask you to fill in surveys to improve our fundraising activities and supporter engagement. You may opt out of fundraising or marketing communications at any time by using the unsubscribe link in our communications or by contacting us.
Information related to donors is held securely in our contact management system, CiviCRM.
The RSE processes personal data for these purposes on the basis of its legitimate interests in promoting and securing support for its charitable objectives, to comply with legal obligations, and, where relevant, on the basis of consent. Where we rely on legitimate interests, we will balance our fundraising activities with individuals’ privacy rights and expectations.
If you make a donation to the RSE, we will use your information to securely process your donation, and to claim Gift Aid. Information shared in a completed Gift Aid declaration will be shared with HMRC to enable us to collect the tax on your donations.
If necessary, we will use publicly available sources to carry out due diligence on donors to comply with applicable legal, regulatory, and ethical obligations, including due diligence requirements.
Following a donation and in agreement with you, we may include your name on a list of donors and legacy pledgers to the RSE and you will be recognised on our Donor List which may be produced both in print and online. You can opt to remain anonymous when making any donation or pledging a legacy gift to us. The RSE may retain records of donations and philanthropic support for archival, historical, and statutory reporting purposes in accordance with our retention policies.
In order to ensure requests for support are targeted and proportionate, including reducing generic communications and unsuitable asks, the RSE will undertake in-house research to analyse the personal information of our community, and assess the likelihood of an individual supporting the RSE. In doing so, we may use profiling techniques, and will use information you have already provided us with, and information that is publicly available about you. This helps us understand our donors and potential donors and ensures, as far as possible, that only relevant communications are sent to you.
In addition to in-house research, we may use a third party to carry out wealth screening. This will involve gathering information from the public domain. Any third-party provider engaged for wealth screening or related services will process personal data under a written data processing agreement containing appropriate confidentiality, security, and data protection obligations. This profiling does not involve solely automated decision-making that produces legal or similarly significant effects. We do not intentionally collect or use special category personal data (such as information about health, ethnicity, religious beliefs, political opinions, or sexual orientation) for fundraising profiling or wealth screening purposes unless you have chosen to provide us with this.
You also have the right to object to the processing of your personal data, including profiling related to fundraising activities, at any time. You may opt-out of wealth screening at any time by contacting our Director of Development, Andrew Grant at agrant@theRSE.org.uk or the Data Protection Officer at dataprotection@theRSE.org.uk.
"*" indicates required fields