Purpose
The purpose of this policy is to ensure that Beyond Words CIC manages personal information lawfully, securely and responsibly while protecting the privacy and confidentiality of children, families, employees and anyone associated with the organisation.
Beyond Words recognises that parents and carers entrust us with sensitive personal information. we handling that information with professionalism, integrity and respect, while complying with UK data protection legislation.
This policy explains how information is collected, stored, shared, retained and disposed of safely, and sets out employees' responsibilities for maintaining confidentiality.
Legal and Professional Framework
This policy has been developed in accordance with relevant legislation and recognised guidance, including but not limited to:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Children Act 1989
- Children Act 2004
- Working Together to Safeguard Children (2025)
- Equality Act 2010
- Privacy and Electronic Communications Regulations (PECR) 2003
Beyond Words will review this policy regularly to ensure it reflects current legislation and best practice.
Scope
This policy applies to all employees, volunteers, students, contractors and any other adults working on behalf of Beyond Words CIC.
It covers:
- children's records
- parent and carer information
- employee records
- photographs and videos
- electronic and paper records
- confidential conversations
- information sharing
- record retention and disposal
This policy should be read alongside the organisation's:
Our Commitment
Beyond Words is committed to:
- protecting personal information
- respecting confidentiality
- collecting only information that is necessary
- keeping information accurate and up to date
- storing information securely
- sharing information only where lawful and appropriate
- maintaining transparency with families regarding how information is used
- complying with all relevant legal requirements
The privacy and dignity of children and families will always be respected.
Roles and Responsibilities
- Founder & Director The Founder & Director is responsible for ensuring that:
- appropriate data protection procedures are implemented
- employees understand their responsibilities regarding confidentiality
- personal information is stored securely
- information sharing complies with legislation
- data breaches are managed appropriately
- appropriate privacy notices are provided where required
- records are retained and securely disposed of in accordance with organisational procedures
- data protection training is provided where appropriate
- this policy is reviewed regularly
- Employees Employees are responsible for:
- maintaining confidentiality
- following this policy and related procedures
- protecting personal information from unauthorised access
- reporting any suspected data breach immediately
- sharing information only where authorised and appropriate
- handling records respectfully and securely
Employees must never access, share or disclose information unless it is necessary for them to carry out their role. Employees must immediately report any loss of confidential information, devices or records, even if they are unsure whether a data breach has occurred.
Personal Information We Hold
Beyond Words collects and processes only the information necessary to provide safe, effective and high-quality services.
This may include:
Information about children
- Full name
- Date of birth
- Home address
- Parent and carer contact details
- Emergency contact information
- Medical information
- Allergies
- Medication requirements
- Individual healthcare plans
- One Page Profiles
- Risk assessments
- Behaviour support information
- Communication preferences
- Attendance records
- Accident and incident records
- Photographic consent
- Other information necessary to meet the child's individual needs
Information about parents and carers
This may include:
- Names
- Addresses
- Telephone numbers
- Email addresses
- Emergency contacts
- Collection arrangements
- Payment information where applicable
- Consent forms
- Correspondence relating to the child
Information about employees
This may include:
- Contact details
- DBS information
- Qualifications
- Training records
- Employment records
- Emergency contacts
- Payroll information
- Relevant health information where required to support employment
Beyond Words will only collect information that is necessary for legitimate organisational purposes.
Confidentiality
- Confidential Information Employees may have access to confidential information about:
- children
- parents and carers
- colleagues
- safeguarding concerns
- medical conditions
- organisational business
Confidential information must be treated with the highest level of professionalism. The duty of confidentiality continues after an employee, volunteer or contractor has stopped working for Beyond Words.
- Maintaining Confidentiality Employees will:
- discuss confidential information only with authorised individuals
- avoid discussing children or families in public places
- keep paper records secure
- ensure electronic information is password protected
- prevent unauthorised individuals from viewing confidential information
- follow organisational procedures when sharing information
Employees must never access records unless they require them to carry out their role.
- Confidential Conversations Conversations involving confidential information should take place in appropriate private settings wherever reasonably practicable
Employees should take care to ensure conversations cannot be overheard by children, visitors or unauthorised individuals.
Information Sharing
Beyond Words recognises that information sharing is sometimes necessary to safeguard children and provide appropriate support.
Information will only be shared:
- where consent has been provided, where appropriate
- where there is a lawful basis to do so
- with professionals who have a legitimate need to know
- where required by law
- where there are safeguarding concerns
Only the minimum amount of information necessary will be shared.
Information sharing decisions will always take account of the child's welfare and relevant legal requirements. Where there is a safeguarding concern, relevant information may be shared without consent where permitted or required by law in order to protect a child or another person from harm.
Photography, Video and Images
- Photographs and Videos
Photographs and videos may be taken for purposes such as:
- celebrating children's achievements
- sharing activities with parents and carers
- promoting Beyond Words (where consent has been provided)
- maintaining records where appropriate
All photographs and videos will be taken respectfully and in accordance with parental consent. Photographs and videos must never be taken in toilets, changing areas or during personal and intimate care.
- Consent Beyond Words will obtain appropriate consent before using photographs or videos of children for promotional or communication purposes
Parents and carers may withdraw their consent at any time, and this will be respected wherever reasonably practicable.
- Storage of Images Images will be:
- stored securely
- accessed only by authorised individuals
- retained only for as long as necessary
- deleted securely when no longer required
Employees must never keep photographs of children on personal devices or use them for personal purposes.
Storage, Retention and Disposal of
Information
- Secure Storage Personal information will be stored securely using appropriate physical and electronic security measures
This may include:
- locked storage for paper records
- password-protected electronic systems
- encrypted devices where appropriate
- restricted access to confidential records
Access will be limited to authorised individuals who require the information to carry out their duties.
- Retention of Records Records will be retained only for as long as necessary to meet legal, safeguarding and operational requirements
When records are no longer required, they will be disposed of securely. Beyond Words will maintain a Record Retention Schedule to support the secure management and disposal of records.
- Secure Disposal Confidential information will be disposed of securely by:
- shredding confidential paper records
- permanently deleting electronic records
- securely destroying any storage devices where appropriate
Beyond Words will take reasonable steps to ensure that confidential information cannot be reconstructed or accessed after disposal.
Data Breaches
- Reporting a Data Breach A data breach is any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information
Examples include:
- sending confidential information to the wrong person
- losing paper records
- losing a mobile device containing personal information
- unauthorised access to electronic records
- accidental disclosure of confidential information
Employees must report any actual or suspected data breach to the Founder & Director immediately. Employees should not attempt to conceal a data breach and must report it immediately, even if they believe it has already been resolved.
- Responding to a Data Breach The Founder & Director will:
- assess the nature and extent of the breach
- take immediate action to limit any further risk
- determine whether affected individuals should be informed
- determine whether the Information Commissioner's Office (ICO) must be notified
- record the incident and any actions taken
- review procedures to prevent similar incidents occurring again
Individual Rights
Beyond Words recognises that individuals have rights regarding their personal information under UK data protection legislation.
Where applicable, individuals may request to:
- access their personal information
- request correction of inaccurate information
- request deletion of information where legally appropriate
- restrict or object to certain processing activities
- withdraw consent where processing is based on consent
Requests will be handled promptly and in accordance with UK GDPR and the Data Protection Act 2018. Requests should normally be made in writing.
Monitoring and Review
The Founder & Director is responsible for implementing, monitoring and reviewing this policy through:
- reviewing data protection procedures
- monitoring record keeping practices
- reviewing any data breaches or confidentiality concerns
- identifying employee training needs
- implementing improvements where appropriate
This policy will be reviewed annually or sooner if legislation, guidance or organisational practice changes.
