Privacy notice
How we use your information
This privacy notice tells you who we are and what to expect when the Natural History Museum collects your personal information. It is intended for visitors, customers, supporters and anyone who has a relationship with the Museum, whether or not they use the Museum's website and other digital channels.
The notice provides information on:
- who we are
- how we use your information
- cookies and tracking
- Wi-Fi service
- conditions under which we use your information
- visitor and customer analytics and prospect research
- who we share information with
- transfers of data abroad
- how long we keep your information
- your rights
- access to personal information and correction
- consent and your right to opt out
- complaints, enquiries and feedback
- how to contact us
- changes to this privacy notice
- useful links
This privacy notice does not cover links to external websites. We encourage you to read the privacy statements on the other websites you visit.
Who we are
The Natural History Museum exists to inspire a love of the natural world and unlock answers to the big issues facing humanity and the planet. More than five million people visit the sites in South Kensington and Tring every year, and the website receives over 500,000 unique visitors a month. It is a world-leading science research centre, and through its unique collections and unrivalled expertise it is tackling issues such as food security, eradicating diseases and managing resource scarcity.
The Natural History Museum Trading Company (NHMTC) carries out the commercial activities of the Museum (e.g. events, retail and the Wildlife Photographer of the Year exhibition). As a wholly owned subsidiary, NHMTC is subject to the Museum's policies and procedures.
In this privacy notice and in the data protection statements which you will see wherever we collect your personal information, 'the Natural History Museum', 'the Museum' and 'we' refer to the Natural History Museum and the Natural History Museum Trading Company. As a wholly owned subsidiary, personal data may be shared from the Natural History Museum to the Natural History Museum Trading Company and vice versa.
The Museum is the data controller of your personal information.
How we use your information
When you give us your personal data we will explain specifically how we will use it in a fair processing statement with a link to this privacy notice. The main purposes for which we collect and process the details of customers, visitors, Members, service users, enquirers, donors and potential donors are to provide the service, goods or information that you have requested:
- for administration purposes (e.g. to administer donations, and to keep a record of our relationship with you)
- to further our charitable aims, including fundraising activities
- to gather feedback
- to enable the best possible supporter journey and experience
We may use your data to contact you by email (if you have given us your consent or are a business contact), post or phone with news and information about the Museum that we feel may be of interest to you as well as about our other special events, activities, products and services. We will not use your personal information in this way if you have opted out, unsubscribed or otherwise indicated that you do not wish to be contacted for such marketing purposes.
Cookies and tracking
When you visit www.nhm.ac.uk, nhmshop.co.uk, data.nhm.ac.uk, wpy-entry.com or any of the Museum's websites, we collect standard internet log information and details of visitor behaviour patterns. We do this to find out, for example, the number of visitors to the various parts of the site, to compile statistical reports on website activity and to personalise our visitors' website experience. We also use cookies and similar technologies to help us understand how you use our sites, and so that we can personalise your experience on the website and via other channels (for example if you are opted in to receive marketing emails). We also use similar technologies when sending marketing emails to understand which emails are being read and how customers interact with them.
Cookies are small blocks of data created by a web server to collect information while you are browsing a website. You can set your browser to not accept cookies and you can remove cookies from your browser. However, in a few cases some of our website features may not function as a result. You can read more about how we use cookies and how to disable them on our cookies page.
If you opt in to ‘Advertising’ cookies via our cookie preference centre, we use advertising cookies from third parties to allow us to assess the effectiveness of our adverts, and to optimise our digital advertising. These cookies can affect what you see on third party sites. Advertising cookies remember that you have visited a website and use that information to provide you with advertising which is tailored to your interests. This is often called online behavioural advertising (OBA) and is done by grouping together shared interests based upon web browsing history.
A guide to behavioural advertising and online privacy has been produced by the internet advertising industry.
For details on the third-party cookies we use, and how to disable them, see our Cookie Policy.
Wi-Fi service and other sensing systems
We operate a Wi-Fi system, counting systems and other sensing systems to detect movement within the Museum’s premises.
Free Wi-Fi access is available throughout the Museum via the network named 'NHM-Free-wifi' or 'NHM-Tring-Free-WiFi'. If you access the Museum's free Wi-Fi network, you will be asked to agree to the Museum's Wi-Fi terms and conditions of use, which explain how your data will be used.
If you do not use the free Wi-Fi network but have Wi-Fi enabled on your smartphone, tablet or another internet-enabled device, your device can still be detected by the Museum's Wi-Fi service.
We record anonymous data about the location and type of devices in the Museum that have Wi-Fi enabled and other sensing data, for security and so that we can monitor the flow of visitors around the Museum and improve our services.
We will not link the anonymous device data with any other personal data that identifies you individually without your express permission. If in the future we want to process your data in this way to offer you new services, we will ask you via a consent form before doing so.
Conditions under which we use your information
We follow the principles of fair and legal processing described in the General Data Protection Regulation. We will only process personal data under one of the available lawful conditions - for example, if:
a) You have consented to the use of your personal data for the specific purpose in question. Examples of when we use this legal basis include:
- to use your personal email account to send you marketing information – this includes information about our news, fundraising, events, products, and services
- to continue to contact you if you are a Museum donor, or potential donor, so that we can build and maintain our relationship and correspondence with you, once first contact has been made under legitimate interests
- to conduct research and collect feedback from you regarding your visits to the Museum and to our website
- to contact you by email if you have taken part in one of our citizen science projects and we require some more information about what you have found or seen
- to provide you with access to our recruitment portal if you are a prospective applicant for a job vacancy or volunteer role
- to contact you by post or phone if you are a Development Group contact who is signed up to the Telephone Preference Service or Mail Preference Service and you are not an existing donor
b) we need to process your personal data in order to deliver a contracted service, for example if you:
- buy a ticket for an event
- become a Member - the services we provide to Members are outlined in the membership terms and conditions and include: contacting you to renew your membership; sending out regular letters via email; analysing member activity to improve our services to you; providing customer service to answer questions or respond to feedback; contacting you about becoming a patron or making a donation to the Museum; and showing you relevant adverts on your social media based on your other activity and interactions as a Member
- become a Patron - the way we use personal data of our Patrons is outlined in the Patrons application form and include: administrating your Patron membership; sending you a regular email newsletter and event invites; and sending you the Evolve magazine
- register for an account to enter the Wildlife Photographer of the Year competition
- create an account to use the Find Your Climate Action tool
- take part in a competition the Museum is running
- make an enquiry regarding booking a Museum venue for an event
- decide to book a Museum venue for an event
- enter into a brand licensing agreement with us
- make a donation directly to the Museum, or through a third-party giving platform such as Just Giving with whom we have a contract
- have a contract with us regarding requesting a research loan from the Museum’s collections
- are donating an item to the Museum’s collections
- complete the application process for a job or volunteer role at the Museum
- are named as a signatory on a commercial contract that we have entered into, or we are seeking to enter into
c) we are entitled or required by law to process personal data in a certain way, for example:
- for fraud or crime prevention purposes
- if you submit a data subject rights request we will process your information in order to assess and, where appropriate, action your request as according to the GDPR and Data Protection Act 2018
- if you make a donation, we have a legal obligation to continue to store certain information about you and the donation for financial records keeping purposes as required under the Companies Act 2006
- if you choose to add Gift Aid to a donation that you make, then we have a legal obligation to retain your gift aid declaration in order to comply with HMRC legislation
- if you apply for a job at the Museum and provide us with any information about reasonable adjustments you require under the Equality Act 2010
d) we need to protect the vital interests of any person
- to ensure that we meet the needs of attendees to certain events at the Museum, for example ensuring that dietary allergies are accounted for
e) we are required to process personal data in performance of a task carried out in the public interest or in the exercise of our official authority. Under Section 3 of the British Museum Act 1963, the Museum’s public task can be defined as a responsibility for keeping its collections and making them available for inspection by the public. Therefore, we will process your data under this legal basis if:
- you are a collector, borrower or lender and have entered your details into our collection management system or data portal in association with one or more specimens or objects.
- you are requesting or providing a loan, we will use the personal information you provide to contact you about the loan and help manage that loan
- you are donating an object or specimen to the Museum, personal data will be used on the Material Transfer Agreement for the donation
- your personal information forms part of an object or specimen's history
- you wish to access Library, Archive and Public Records items in the Reading Rooms
- you are captured in CCTV footage in and around the Museum premises in order to ensure safety and security of the collections and the public
f) the processing of personal data is within our legitimate interests, where we carry out activities that would not be considered to fall into the definition at (e) above, but are enabling the Museum to meet its objectives.
Types of personal data processing which are based upon the Museum’s legitimate interests include:
- sending you marketing, publicity and fundraising mailshots that do not require your consent (such as postal or phone contact, or business to business communications)
- if you are a Development Group contact who may be able to make a donation to the Museum, we may carry out prospect research on you before we first contact you to make sure we are aware of your interests and your giving capacity
- if you are making a significant donation to the Museum, we may carry out due diligence research to ensure that the source of the donation aligns with our Mission and Values
- carrying out visitor and customer analytics so we can better understand people’s interactions with the Museum and make improvements to make them better
- If you choose to opt into email marketing, then a pseudonymised version of your email address may be shared with Facebook based on the legitimate interest lawful basis in order that Facebook can serve relevant adverts to you as well as to similar ‘lookalike’ audiences
- exercising or defending against occasional legal claims that the Museum encounters, for example in the area of health and safety
- corresponding with you if you have contacted the Museum with an enquiry or some feedback, this may involve passing on your email address to the relevant colleague who is able to best assist you
- processing booking requests for education visits
- so that we can send you relevant emails based on your interests and behaviour. We will do this by analysing information such as which pages you view on our website, commercial transactions (e.g. ticket and retail purchases) and activities (e.g. email actions, point of sign up to marketing) and postcode data in order to personalise the communications and content you receive, and better target our marketing. Please note that whilst this profiling activity is considered to be in our legitimate interests, information about your activity on our websites will only be collected and used for this purpose if you first consent to the setting of non-essential cookie categories via our cookie preference centre.
- conducting feedback surveys in relation to specific events or exhibitions
- processing visitor requests for disabled parking spaces at the Museum
- processing information about individuals involved in security or health and safety incidents during a visit to the Museum, or whilst at an event on our premises
- collecting names of participants involved in our citizen science activities, in order to ensure we have the necessary information to form a biological record
The legitimate interest legal basis also covers the processing of personal data during some of the Museum’s business to business activities, for example:
- to review names and CVs of lead specialist individuals working at an organisation, in order to assess the expertise on offer from a supplier during the procurement process
- to contact press and media contacts
- to contact government contacts
- to facilitate management of our teacher advisory network
- to contact personal assistants of donors (or prospective donors) regarding matters such as whether the donor (or prospective donor) would like to attend a Museum event
- to contact prospective donors in their business capacity - for example to consider corporate partnership opportunities, or emailing contacts at philanthropic trusts or foundations
- to manage security requirements for business contacts visiting the Museum to meet with staff members
- to encourage collaboration between our science staff with other researchers, scientists and curators beyond the Museum for purposes including research, collections use, laboratory use, and publications.
Special category personal data and criminal convictions information
Special category data is defined at Article 9 GDPR as personal data revealing:
- racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data
- biometric data for the purpose of uniquely identifying a natural person
- data concerning health, or
- data concerning a natural person’s sex life or sexual orientation.
Processing special category data will sometimes be necessary to ensure that the Museum can effectively provide a service to you, or so you can best enjoy what the Museum has to offer. For example, we may need information regarding accessibility requirements or dietary requirements so that you are able to access and enjoy our facilities and events. We may also need to process special category information, such as medical information, when recording and managing health and safety incidents.
Criminal conviction data
Article 10 GDPR covers processing in relation to criminal convictions and offences or related security measures. In addition, section 11(2) of the DPA 2018 specifically confirms that this includes personal data relating to the alleged commission of offences or proceedings for an offence committed or alleged to have been committed, including sentencing. This is collectively referred to as ‘criminal offence data’
When the Museum carries out due diligence research in order to accept support and donations, we may access special category information or information relating to criminal offences or convictions.
Profiling
‘Profiling’ is the word that data protection regulations use to describe activities which involve the behavioural characteristics of individuals being analysed to find out about their preferences, predict their behaviour, make decisions about them or classify them into different groups or sectors.
At the Museum, we carry out profiling activities because knowing more about our customers and supporters means that we can make sure we are communicating with you in the best possible way, with the most relevant information for your interests, and therefore giving you the best possible experience.
The specific profiling activities we may carry out include:
- Predicting what products our shop customers might be interested in based on their online browsing history.
- Combining online and offline data to build up a picture of an individual’s interests.
- Segmenting our customers and supporters into different groups based on their likely interests, which are indicated by the nature of their interactions with the Museum.
Different ‘lawful bases' are used for different parts of the profiling process. This is detailed as follows:
- If you opt into ‘performance’ cookies via our cookie preference centre, then consent is used to collect information about your activity on our websites.
- If you opt into ‘advertising’ cookies via our cookie preference centre, then consent is used to collect information about your activity on our websites and to provide you with tailored Museum advertising when browsing other websites.
- Information about website behaviours (collected via cookie consent) is combined with other information we know about you, for example ticket purchases, membership status and which part of the country you live in. This is used to decide which ‘segment’ best suits you, so that you can be provided with an experience of the Museum which is tailored to your likely interests and behaviours. This is based on the legitimate interest lawful basis as we consider that it is not only in the interests of our customers and supporters to have the best possible experience, but also allows us to increase engagement with the Museum’s mission to create advocates for the planet.
- If you are opted in to receive email marketing from the Museum, then the consent lawful basis is used to send you relevant email content based on the segment you have been assigned to.
- If you are a member, then the performance of a contract lawful basis is used to send you relevant email content based on the segment you have been assigned to, based on member communications being a membership benefit set out in the member T&Cs.
- From time to time, the Museum may carry out postal or telephone marketing campaigns which use information gained from profiling and segmentation to ensure that you are contacted with the most relevant content. This is based on the legitimate interest lawful basis as we consider that it is not only in the interests of our customers and supporters to have the best possible experience, but also allows us to increase engagement with the Museum’s mission to create advocates for the planet.
We do not consider the profiling activities we carry out to be intrusive for the following reasons:
- Our profiling and segmentation activities serve only to improve the relevance and quality of the interactions that our customers and supporters would otherwise be having with us anyway, rather than contacting you via additional channels which could be considered intrusive.
- We ensure that you maintain control by ensuring that cookies tracking website behaviour and providing tailored web content are only set with user consent, and that marketing emails are only sent where consent has been provided.
- The profiling that we carry out does not lead to automated decisions which could have legal or similarly significant effects on you.
- We will never use special category data as part of our profiling activity.
Visitor and customer analytics and prospect research
It is within the Museum's legitimate interests to hold and analyse your data to continue to improve our understanding of our target audiences and supporters. This is so we can provide world-class, transformative, visitor-focused experiences, customer service and educational engagement, and effective and appropriate supporter engagement.
Visitor analytics data is collected on an anonymous basis wherever possible, or pseudonymised so that individuals cannot be readily identified. This includes monitoring visitor numbers and tracking movement of people and collections of individuals around the Museum. (For more information see sections on cookies and Wi-Fi.)
We carry out customer analytics to improve our understanding of our target audiences. We do this by analysing your commercial transactions (e.g. ticket and retail purchases) and activities (e.g. email interaction with the Museum, such as which emails you open and how often, use of Museum Wi-Fi including via cookies and similar technologies). This helps us target our marketing more efficiently, understand what topics you are interested in, and personalise and improve your experience if you have consented to receive marketing from us, by providing the most relevant and timely content.
You can object to our carrying out this kind of activity for marketing purposes by emailing [email protected], and we will review our basis for doing so in your case. Please note that objecting to this activity will mean that you are automatically unsubscribed from marketing.
Supporter research
As a recognised charity we seek to maximise our income from fundraising in order to achieve our aims and objectives. This support is vital in helping us continue our pioneering scientific research, education and conservation. In order to make our fundraising activities as effective as possible we therefore undertake supporter research in order to appropriately engage with high value donors.
Supporter research involves building up a holistic summary of an individual, their interests, suitability and likelihood they will donate and is fundamental to the ability to generate income through fundraising. Therefore, we may collect personal information to research potential supporters that have been identified through publicly available sources, personal referrals, recommendations from existing supporters, through their existing involvement with the Museum and occasionally from fully contracted independent researchers who work with us when we do not have the in-house capacity required.
In addition to information that our supporters provide to us, we may use data collected from publicly available quantitative and qualitative information to assess an individual’s inclination to provide financial and non-financial support and their areas of philanthropic interest, to enable the formulation of an approach which the individual finds attractive.
This may include:
- Financial information (including whether particular donations or funding appeals may be of interest)
- philanthropy and other giving (including donations to other organisations)
- other support (for example, details of volunteering roles)
- career highlights and other life achievements
- a photograph of you
- and information about areas of interest and extra-curricular activities.
We use targeted internet searches and may search the following websites where relevant in order to obtain and maintain the accuracy of the data listed above:
- Archives from media outlets and archived press releases
- company websites
- Higher education institution websites
- business-related resources including Companies House, One Source, BoardEx and Fame
- Charity Commission and other internet sources for non-profits
- LinkedIn, to check business details
- public records databases