Data Protection & Privacy Policy
1. Policy Statement
Limitless Academy is committed to protecting the privacy, dignity, and rights of all individuals whose personal information we collect and process. This includes children, young people, parents and carers, employees, volunteers, trustees, funders, partners, and contractors.
We recognise that children and young people may be particularly vulnerable and require additional protection regarding the use of their personal information. We therefore take all reasonable steps to ensure personal data is processed lawfully, fairly, transparently, and securely.
This policy demonstrates our commitment to complying with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant safeguarding legislation.
2. Purpose
The purpose of this policy is to:
-
Protect the rights and freedoms of individuals.
-
Ensure compliance with UK GDPR and the Data Protection Act 2018.
-
Establish clear responsibilities for managing personal information.
-
Minimise risks associated with data breaches and misuse of information.
-
Promote good information governance throughout the organisation.
3. Scope
This policy applies to:
-
Directors and trustees
-
Employees
-
Volunteers
-
Sessional workers
-
Contractors and consultants
-
Placement students
-
Young people accessing services
-
Parents, carers and guardians
The policy applies to all personal data processed by the organisation, whether held electronically, on paper, photographs, video recordings, or any other format.
4. Definitions
Personal Data
Any information relating to an identified or identifiable living individual.
Examples include:
-
Name
-
Address
-
Telephone number
-
Email address
-
Date of birth
-
Attendance records
-
Images and photographs
Special Category Data
Information requiring additional protection, including:
-
Health information
-
Mental health information
-
Disability information
-
Ethnicity
-
Religious beliefs
-
Sexual orientation
-
Biometric data
Processing
Any activity involving personal data including:
-
Collection
-
Storage
-
Recording
-
Sharing
-
Editing
-
Deletion
5. Data Protection Principles
The organisation will comply with the seven principles of UK GDPR:
5.1 Lawfulness, Fairness and Transparency
We will clearly explain:
-
What information is collected
-
Why it is collected
-
How it will be used
-
Who it may be shared with
Privacy notices will be made available to all individuals.
5.2 Purpose Limitation
Data will only be collected for specified and legitimate purposes.
5.3 Data Minimisation
Only information necessary to deliver services and meet legal obligations will be collected.
5.4 Accuracy
Reasonable steps will be taken to ensure information remains accurate and up to date.
5.5 Storage Limitation
Data will not be kept longer than necessary.
5.6 Integrity and Confidentiality
Appropriate technical and organisational measures will be implemented to protect information.
5.7 Accountability
The organisation will maintain records demonstrating compliance with data protection legislation.
6. Information We Collect
6.1 Young People
The organisation may collect:
-
Full name
-
Preferred name
-
Date of birth
-
Gender
-
Address
-
School or college details
-
Contact information
-
Attendance records
-
Emergency contact information
-
Health information
-
Additional support needs
-
Safeguarding records
-
Photographs and videos
-
Monitoring and evaluation information
6.2 Parents and Carers
We may collect:
-
Names
-
Addresses
-
Contact details
-
Relationship to the young person
-
Consent forms
-
Emergency contact information
6.3 Staff and Volunteers
We may collect:
-
Recruitment information
-
References
-
DBS information
-
Payroll details
-
Bank details
-
Training records
-
Performance records
-
Emergency contacts
7. Lawful Bases for Processing
The organisation relies on the following lawful bases:
Consent
Used for:
-
Photography and media use
-
Marketing communications
-
Optional activities
Contract
Used where services are being provided.
Legal Obligation
Used to comply with:
-
Employment law
-
Safeguarding responsibilities
-
Health and safety requirements
-
Charity and company law obligations
Vital Interests
Where information must be shared to protect life or prevent serious harm.
Legitimate Interests
Where processing is necessary to deliver services and support organisational objectives while protecting individual rights.
8. Children's Data
The organisation recognises that children merit specific protection regarding their personal data.
We will:
-
Use age-appropriate privacy information.
-
Collect only information necessary for service delivery.
-
Seek parental or guardian consent where appropriate.
-
Respect the developing capacity of young people to make decisions regarding their information.
-
Consider the best interests of the child in all processing activities.
9. Safeguarding Information
The organisation may process safeguarding information where concerns arise regarding the welfare of a child or vulnerable person.
Information may be shared without consent where:
-
There is risk of significant harm.
-
A crime may have occurred.
-
Disclosure is required by law.
-
Safeguarding duties override confidentiality.
All safeguarding records will be:
-
Kept separately where possible.
-
Restricted to authorised personnel.
-
Retained in accordance with safeguarding guidance.
10. Photography, Video and Social Media
Photographs and videos may be used for:
-
Promotion of activities
-
Funding reports
-
Social media
-
Website content
-
Printed materials
The organisation will:
-
Obtain appropriate consent.
-
Record consent preferences.
-
Respect requests to withdraw consent.
-
Avoid identifying children by full name unless specifically agreed.
Images will be stored securely and deleted when no longer required.
11. Data Sharing
Information may be shared with:
-
Local authorities
-
Schools and colleges
-
NHS services
-
Social care teams
-
Police
-
Funding organisations
-
Professional advisers
-
Regulatory bodies
Information will only be shared where:
-
Consent has been obtained;
-
There is a lawful basis;
-
It is required by law; or
-
It is necessary for safeguarding purposes.
Whenever possible, anonymised or aggregated information will be used.
12. Data Security
The organisation will implement appropriate security measures including:
Technical Measures
-
Password-protected devices
-
Multi-factor authentication
-
Antivirus software
-
Secure cloud storage
-
Encrypted devices
-
Secure backups
Organisational Measures
-
Confidentiality agreements
-
Staff training
-
Restricted access permissions
-
Clear desk policy
-
Secure disposal procedures
13. Data Retention
The organisation will retain information only as long as necessary.
Example Retention Schedule
Record Type
Retention Period
Participant records
6 years after last engagement
Consent forms
6 years
Accident reports
3 years from date of incident (or longer where children are involved)
Safeguarding records
Until age 25 or longer if required
Staff files
6 years after employment ends
DBS information
No longer than 6 months unless legally required
Data will be securely deleted, shredded, or permanently destroyed.
14. Data Subject Rights
Individuals have the:
Right to be Informed
Know how information is used.
Right of Access
Request copies of personal data.
Right to Rectification
Correct inaccurate information.
Right to Erasure
Request deletion of information where applicable.
Right to Restrict Processing
Limit how information is used.
Right to Data Portability
Receive information in a reusable format.
Right to Object
Object to certain types of processing.
Rights Relating to Automated Decision Making
Challenge automated decisions where applicable.
Requests should be responded to within one month unless an extension is permitted by law.
15. Subject Access Requests (SARs)
Requests may be made verbally or in writing.
The organisation will:
-
Verify identity.
-
Record the request.
-
Gather relevant information.
-
Respond within one calendar month.
-
Provide information free of charge unless requests are excessive or repetitive.
16. Data Breaches
A personal data breach may include:
-
Loss of records
-
Unauthorised access
-
Accidental disclosure
-
Theft of equipment
-
Cyber attack
All breaches must be reported immediately to the Data Protection Lead.
The organisation will:
-
Investigate the incident.
-
Assess risks.
-
Take corrective action.
-
Notify affected individuals where required.
-
Report notifiable breaches to the UK regulator, the Information Commissioner's Office within 72 hours where legally required.
A breach log will be maintained.
17. Staff and Volunteer Responsibilities
All staff and volunteers must:
-
Follow this policy.
-
Maintain confidentiality.
-
Attend training when required.
-
Use secure systems.
-
Report concerns promptly.
-
Avoid sharing information unnecessarily.
Failure to comply may result in disciplinary action.
18. Data Protection Impact Assessments (DPIAs)
A DPIA will be conducted when introducing activities likely to result in a high risk to individuals, including:
-
New databases
-
Monitoring technologies
-
Large-scale collection of sensitive information
-
New digital platforms involving children
19. Monitoring and Compliance
The Board of Directors is responsible for ensuring adequate oversight of data protection compliance.
The Data Protection Lead will:
-
Review procedures annually.
-
Monitor compliance.
-
Maintain breach records.
-
Review privacy notices.
-
Coordinate responses to data requests.
20. Complaints
Individuals who are dissatisfied with how their information has been handled should first contact:
Data Protection Lead
[Name] Sam Hill
[Email] sam@leadlimitless.co.uk
[Telephone] 07468534500
If concerns remain unresolved, individuals may complain to the:
Privacy Policy - the basics
Having said that, a privacy policy is a statement that discloses some or all of the ways a website collects, uses, discloses, processes, and manages the data of its visitors and customers. It usually also includes a statement regarding the website’s commitment to protecting its visitors’ or customers’ privacy, and an explanation about the different mechanisms the website is implementing in order to protect privacy.
Different jurisdictions have different legal obligations of what must be included in a Privacy Policy. You are responsible to make sure you are following the relevant legislation to your activities and location.
What to include in the Privacy Policy
Generally speaking, a Privacy Policy often addresses these types of issues: the types of information the website is collecting and the manner in which it collects the data; an explanation about why is the website collecting these types of information; what are the website’s practices on sharing the information with third parties; ways in which your visitors and customers can exercise their rights according to the relevant privacy legislation; the specific practices regarding minors’ data collection; and much, much more.
To learn more about this, check out our article “Creating a Privacy Policy”.
