Here at Sheffield Credit Union Limited, Trading As South Yorkshire Community Bank (“SYCB”) we take your privacy seriously. This privacy notice explains how we collect, use, share, retain and protect your personal information when you apply for or use our membership, savings, loan and related services.
We process personal information in accordance with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and other legal and regulatory requirements that apply to credit unions.
You can contact us about this notice or your data protection rights by emailing admin@sycb.co.uk, calling 0114 276 0787, or writing to us at 35 Townhead Street, Sheffield, S1 2EB (registered office).
- What type of information is collected from you and how do we collect it?
Personal data is data which can be used to confirm your identity. This may include your name, date of birth, address, telephone number and other basic personal details. Most data that we would hold is collected directly from you via paper forms, online forms, emails, telephone calls or face to face interactions. We will sometimes collect data from third parties who you have authorised to do this for you, or in the event of collecting unpaid debts or establishing your whereabouts in order to contact you or your beneficiary to fulfil our contract with you, from publicly accessible sources. - How do we use your personal information?
- To meet legal and regulatory dutiesFor example, to verify your identity, carry out anti-money laundering, sanctions and fraud checks, keep required records, complete audits, and meet FCA, PRA, HMRC and other legal or regulatory requirements.
- To provide our services.
For example, to manage your membership, savings and loan accounts, process applications and payments, send statements and notices, deal with queries or complaints, manage arrears and recover debts. - To assess applications and manage risk
For example, to assess affordability and credit risk, make lending decisions, prevent fraud and financial crime, and share information with credit reference agencies, fraud prevention agencies, open banking providers and debt recovery agents where appropriate. - For our legitimate interests
For example, to operate and improve our services, keep records accurate, manage risk, protect our systems, premises, staff and members, handle complaints and legal claims, and support members who may need additional help. - With your consent
For example, for certain marketing, optional open banking services, or optional information you choose to provide. You can withdraw consent at any time.Where you tell us about health, vulnerability or support needs, we will use this only where necessary and lawful, for example to provide support, make reasonable adjustments, or meet legal or regulatory expectations.
- How is your information used?
Processing of data is very broadly defined as any operation or a set of operations on the data including: Collecting, recording, organising, structuring, using, consulting, holding, storing, retrieving, amending, copying, erasing, destroying, disclosing by transmitting, disseminating or otherwise making available, sharing with our third parties suppliers (as provided in sections 6 & 7 of this Privacy Notice), securing, transferring, restricting (with the aim of limiting processing of data in future) and profiling. This list of operations is not exhaustive. - Where will we store and send your information?
We store personal information securely in electronic systems and, where needed, in paper records. Access is restricted to employees, directors, volunteers, contractors and service providers who have a legitimate need to access the information.We use appropriate technical and organisational measures to protect personal information, including secure storage, access controls, password protection, staff training, confidentiality obligations, audit trails and secure disposal procedures.Your information is usually stored in the UK or the EEA. Where we or our suppliers transfer personal information outside the UK, we will only do so where an appropriate lawful transfer mechanism is in place and the transfer provides protection for individuals that is not materially lower than that provided under UK data protection law.Where required for international tax compliance, we may report relevant information to HMRC, which may share it with tax authorities in other countries where you or a connected person may be tax resident. - Who might we share your information with?
We will share your information as required only:- With our third party agents/suppliers or subcontractors for operational reasons such as confirming your identity, processing debit card payments, providing secure online services and transmitting documents or data e.g. for signature by email;
- With any persons, including, but not limited to, insurers, who provide a service or benefits to you or for us in connection with your account(s);
- To licensed credit reference agencies for example: Experian and debt recovery agents who may check information against other databases;
- To fraud prevention and other agencies to help prevent crime or where we suspect fraud;
- To any authorities if compelled to do so by law (e.g. HM Revenue & Customs to fill tax compliance obligations and the Department of Work and Pensions (DWP) on request for specific information;
- Members making a legitimate request to view the members’ register (only permitted in supervised environment with access restricted to essential details required for legitimate purpose e.g. member seeking support from other members to call a Special General Meeting).
- For the purpose of compliance and regulatory reporting and to confirm your identity for money laundering purposes, which may include checking the electoral register.
- For the purposes of email marketing which may require our third party company to collect and process personal information about you as an email recipient and to respond to your support services’ enquiries as appropriate. Email marketing shall only apply if you opt in to email marketing when giving us your marketing preferences.
- Credit Reference Agencies, Open Banking and email marketing provider
Should you apply for a loan, we will supply your personal information to credit reference agencies (CRAs) and exchange information about you on an ongoing basis for the purpose of processing your loan applications. You can read our summary of how we share your personal information with CRAs in more detail on our website or by requesting a loan application form. The full document is available via this page on our website, or directly from:TransUnion (formerly CallCredit) at https://www.transunion.co.uk/legal/privacy-centre/pc-credit-referenceEquifax at https://www.equifax.co.uk/privacy-hub/crain
Experian at https://www.experian.co.uk/legal/crain/
If applying for a loan you may also opt to send us your recent bank transaction data via a secure third party open banking provider rather than providing copies of your bank statements. To use this service, you will give your consent to your bank, as well as our third party AccountScore / Consents Online before the transfer is carried out. You will be able to amend your consent and permissions via Consent Online’s portal following the transfer. AccountScore / Consents Online is an FCA registered Account Information Service Provider. This service is optional and hard copies of bank statements will still be accepted with a loan application.
According to your marketing preferences, you will receive emails with marketing and promotional information via our third party supplier Campaign Monitor as indicated in point 6. You can read more about how your information will be shared with this company directly from their website’s terms of use as indicated below. Please refer specifically to Section 3 entitled “Campaign Monitor’s users’ subscribers (email recipients)” in this regard. https://www.campaignmonitor.com/policies
- How long do we keep your information for?
We keep personal information and business records only for as long as necessary for the purpose for which they were collected, unless a longer retention period is required by law, regulation, audit, contract, insurance, safeguarding, dispute resolution or legitimate business need.Our retention periods take account of legal and regulatory requirements, FCA and PRA record-keeping expectations, anti-money laundering and financial crime requirements, HMRC obligations, limitation periods for legal claims, audit and governance requirements, and the rights and freedoms of individuals.Some records may need to be retained after your membership, account or loan has ended. For example, anti-money laundering records, financial records, loan records, transaction records and complaint records may be retained for set periods after the end of the relevant relationship or matter.Where a system does not currently allow full deletion of certain information, we will restrict access, minimise use of the information and keep the position under review until deletion, anonymisation or suppression becomes possible.Records will not be deleted, destroyed or anonymised where they are needed for an active complaint, investigation, legal claim, audit, regulatory request, safeguarding concern or data subject rights request.You can ask us for more information about our retention periods using the contact details above. - What are your 8 rights under the General Data Protection Regulations?
You have rights under data protection legislation. These include the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, rights relating to automated decision-making, and the right to complain.If you make a request about your personal information, we will pass it to a manager and handle it in accordance with our relevant procedure, including our Subject Access Request procedure or Erasure Request procedure where applicable.Subject access requests will usually be responded to within one month. This period may be extended where permitted by law, or paused where clarification is reasonably required. When responding to a subject access request, we may carry out a reasonable and proportionate search, taking into account the nature of the request, the records held and the effort required to locate and review the information.The right to erasure is not absolute. We may need to retain information where this is required or justified for legal, regulatory, contractual, audit, anti-money laundering, financial crime, complaint handling, debt recovery or legal claims purposes.We use tools to help with identity checks, fraud checks, credit checks and affordability assessments. We do not make loan or membership decisions by solely automated means without meaningful human involvement. If this changes, we will tell you and explain any rights that apply.
- Data protection complaints and contact details
If you believe your personal information has not been handled in accordance with data protection legislation, you can complain to us by emailing admin@sycb.co.uk, calling 0114 276 0787, or writing to us at 35 Townhead Street, Sheffield, S1 2EB.We will provide a clear route for data protection complaints, including an electronic means of submitting a complaint where appropriate.We will acknowledge data protection complaints without undue delay and in any event within 30 days of receiving them. We will handle complaints in accordance with our Complaints Policy and Procedure, make appropriate enquiries, keep you informed where appropriate, and tell you the outcome within a reasonable period.If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (“ICO”), the UK regulator for data protection. You can contact the ICO through its website, by telephone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF. - Changes to this Privacy Notice
We may update this privacy notice from time to time, including where legislation, regulatory guidance, systems or operational processes change. If we make important changes to how we use personal information, we will take reasonable steps to let you know and, where required, ask for your consent.
Last updated: June 2026