GROUP 04Inclusion and family

Data Protection and Confidentiality

How we handle personal information about children, families and staff.

Ref BW-DP-001Version 1.0 Review by 23/07/2027
01

Purpose

The purpose of this policy is to ensure that Beyond Words CIC manages personal information lawfully, securely and responsibly while protecting the privacy and confidentiality of children, families, employees and anyone associated with the organisation.

Beyond Words recognises that parents and carers entrust us with sensitive personal information. we handling that information with professionalism, integrity and respect, while complying with UK data protection legislation.

This policy explains how information is collected, stored, shared, retained and disposed of safely, and sets out employees' responsibilities for maintaining confidentiality.

03

Scope

This policy applies to all employees, volunteers, students, contractors and any other adults working on behalf of Beyond Words CIC.

It covers:

  • children's records
  • parent and carer information
  • employee records
  • photographs and videos
  • electronic and paper records
  • confidential conversations
  • information sharing
  • record retention and disposal

This policy should be read alongside the organisation's:

04

Our Commitment

Beyond Words is committed to:

  • protecting personal information
  • respecting confidentiality
  • collecting only information that is necessary
  • keeping information accurate and up to date
  • storing information securely
  • sharing information only where lawful and appropriate
  • maintaining transparency with families regarding how information is used
  • complying with all relevant legal requirements

The privacy and dignity of children and families will always be respected.

05

Roles and Responsibilities

  • Founder & Director The Founder & Director is responsible for ensuring that:
  • appropriate data protection procedures are implemented
  • employees understand their responsibilities regarding confidentiality
  • personal information is stored securely
  • information sharing complies with legislation
  • data breaches are managed appropriately
  • appropriate privacy notices are provided where required
  • records are retained and securely disposed of in accordance with organisational procedures
  • data protection training is provided where appropriate
  • this policy is reviewed regularly
  • Employees Employees are responsible for:
  • maintaining confidentiality
  • following this policy and related procedures
  • protecting personal information from unauthorised access
  • reporting any suspected data breach immediately
  • sharing information only where authorised and appropriate
  • handling records respectfully and securely

Employees must never access, share or disclose information unless it is necessary for them to carry out their role. Employees must immediately report any loss of confidential information, devices or records, even if they are unsure whether a data breach has occurred.

06

Personal Information We Hold

Beyond Words collects and processes only the information necessary to provide safe, effective and high-quality services.

This may include:

Information about children

  • Full name
  • Date of birth
  • Home address
  • Parent and carer contact details
  • Emergency contact information
  • Medical information
  • Allergies
  • Medication requirements
  • Individual healthcare plans
  • One Page Profiles
  • Risk assessments
  • Behaviour support information
  • Communication preferences
  • Attendance records
  • Accident and incident records
  • Photographic consent
  • Other information necessary to meet the child's individual needs

Information about parents and carers

This may include:

  • Names
  • Addresses
  • Telephone numbers
  • Email addresses
  • Emergency contacts
  • Collection arrangements
  • Payment information where applicable
  • Consent forms
  • Correspondence relating to the child

Information about employees

This may include:

  • Contact details
  • DBS information
  • Qualifications
  • Training records
  • Employment records
  • Emergency contacts
  • Payroll information
  • Relevant health information where required to support employment

Beyond Words will only collect information that is necessary for legitimate organisational purposes.

07

Confidentiality

  • Confidential Information Employees may have access to confidential information about:
  • children
  • parents and carers
  • colleagues
  • safeguarding concerns
  • medical conditions
  • organisational business

Confidential information must be treated with the highest level of professionalism. The duty of confidentiality continues after an employee, volunteer or contractor has stopped working for Beyond Words.

  • Maintaining Confidentiality Employees will:
  • discuss confidential information only with authorised individuals
  • avoid discussing children or families in public places
  • keep paper records secure
  • ensure electronic information is password protected
  • prevent unauthorised individuals from viewing confidential information
  • follow organisational procedures when sharing information

Employees must never access records unless they require them to carry out their role.

  • Confidential Conversations Conversations involving confidential information should take place in appropriate private settings wherever reasonably practicable

Employees should take care to ensure conversations cannot be overheard by children, visitors or unauthorised individuals.

08

Information Sharing

Beyond Words recognises that information sharing is sometimes necessary to safeguard children and provide appropriate support.

Information will only be shared:

  • where consent has been provided, where appropriate
  • where there is a lawful basis to do so
  • with professionals who have a legitimate need to know
  • where required by law
  • where there are safeguarding concerns

Only the minimum amount of information necessary will be shared.

Information sharing decisions will always take account of the child's welfare and relevant legal requirements. Where there is a safeguarding concern, relevant information may be shared without consent where permitted or required by law in order to protect a child or another person from harm.

09

Photography, Video and Images

  • Photographs and Videos

Photographs and videos may be taken for purposes such as:

  • celebrating children's achievements
  • sharing activities with parents and carers
  • promoting Beyond Words (where consent has been provided)
  • maintaining records where appropriate

All photographs and videos will be taken respectfully and in accordance with parental consent. Photographs and videos must never be taken in toilets, changing areas or during personal and intimate care.

  • Consent Beyond Words will obtain appropriate consent before using photographs or videos of children for promotional or communication purposes

Parents and carers may withdraw their consent at any time, and this will be respected wherever reasonably practicable.

  • Storage of Images Images will be:
  • stored securely
  • accessed only by authorised individuals
  • retained only for as long as necessary
  • deleted securely when no longer required

Employees must never keep photographs of children on personal devices or use them for personal purposes.

10

Storage, Retention and Disposal of

Information

  • Secure Storage Personal information will be stored securely using appropriate physical and electronic security measures

This may include:

  • locked storage for paper records
  • password-protected electronic systems
  • encrypted devices where appropriate
  • restricted access to confidential records

Access will be limited to authorised individuals who require the information to carry out their duties.

  • Retention of Records Records will be retained only for as long as necessary to meet legal, safeguarding and operational requirements

When records are no longer required, they will be disposed of securely. Beyond Words will maintain a Record Retention Schedule to support the secure management and disposal of records.

  • Secure Disposal Confidential information will be disposed of securely by:
  • shredding confidential paper records
  • permanently deleting electronic records
  • securely destroying any storage devices where appropriate

Beyond Words will take reasonable steps to ensure that confidential information cannot be reconstructed or accessed after disposal.

11

Data Breaches

  • Reporting a Data Breach A data breach is any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information

Examples include:

  • sending confidential information to the wrong person
  • losing paper records
  • losing a mobile device containing personal information
  • unauthorised access to electronic records
  • accidental disclosure of confidential information

Employees must report any actual or suspected data breach to the Founder & Director immediately. Employees should not attempt to conceal a data breach and must report it immediately, even if they believe it has already been resolved.

  • Responding to a Data Breach The Founder & Director will:
  • assess the nature and extent of the breach
  • take immediate action to limit any further risk
  • determine whether affected individuals should be informed
  • determine whether the Information Commissioner's Office (ICO) must be notified
  • record the incident and any actions taken
  • review procedures to prevent similar incidents occurring again
12

Individual Rights

Beyond Words recognises that individuals have rights regarding their personal information under UK data protection legislation.

Where applicable, individuals may request to:

  • access their personal information
  • request correction of inaccurate information
  • request deletion of information where legally appropriate
  • restrict or object to certain processing activities
  • withdraw consent where processing is based on consent

Requests will be handled promptly and in accordance with UK GDPR and the Data Protection Act 2018. Requests should normally be made in writing.

13

Monitoring and Review

The Founder & Director is responsible for implementing, monitoring and reviewing this policy through:

  • reviewing data protection procedures
  • monitoring record keeping practices
  • reviewing any data breaches or confidentiality concerns
  • identifying employee training needs
  • implementing improvements where appropriate

This policy will be reviewed annually or sooner if legislation, guidance or organisational practice changes.