top of page

Data Protection & Privacy Policy

1. Policy Statement

Limitless Academy is committed to protecting the privacy, dignity, and rights of all individuals whose personal information we collect and process. This includes children, young people, parents and carers, employees, volunteers, trustees, funders, partners, and contractors.

We recognise that children and young people may be particularly vulnerable and require additional protection regarding the use of their personal information. We therefore take all reasonable steps to ensure personal data is processed lawfully, fairly, transparently, and securely.

This policy demonstrates our commitment to complying with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant safeguarding legislation.

2. Purpose

The purpose of this policy is to:

  • Protect the rights and freedoms of individuals.

  • Ensure compliance with UK GDPR and the Data Protection Act 2018.

  • Establish clear responsibilities for managing personal information.

  • Minimise risks associated with data breaches and misuse of information.

  • Promote good information governance throughout the organisation.

3. Scope

This policy applies to:

  • Directors and trustees

  • Employees

  • Volunteers

  • Sessional workers

  • Contractors and consultants

  • Placement students

  • Young people accessing services

  • Parents, carers and guardians

The policy applies to all personal data processed by the organisation, whether held electronically, on paper, photographs, video recordings, or any other format.

4. Definitions

Personal Data

Any information relating to an identified or identifiable living individual.

Examples include:

  • Name

  • Address

  • Telephone number

  • Email address

  • Date of birth

  • Attendance records

  • Images and photographs

 

Special Category Data

Information requiring additional protection, including:

  • Health information

  • Mental health information

  • Disability information

  • Ethnicity

  • Religious beliefs

  • Sexual orientation

  • Biometric data

Processing

Any activity involving personal data including:

  • Collection

  • Storage

  • Recording

  • Sharing

  • Editing

  • Deletion

5. Data Protection Principles

The organisation will comply with the seven principles of UK GDPR:

5.1 Lawfulness, Fairness and Transparency

We will clearly explain:

  • What information is collected

  • Why it is collected

  • How it will be used

  • Who it may be shared with

Privacy notices will be made available to all individuals.

5.2 Purpose Limitation

Data will only be collected for specified and legitimate purposes.

5.3 Data Minimisation

Only information necessary to deliver services and meet legal obligations will be collected.

5.4 Accuracy

Reasonable steps will be taken to ensure information remains accurate and up to date.

5.5 Storage Limitation

Data will not be kept longer than necessary.

5.6 Integrity and Confidentiality

Appropriate technical and organisational measures will be implemented to protect information.

5.7 Accountability

The organisation will maintain records demonstrating compliance with data protection legislation.

6. Information We Collect

6.1 Young People

The organisation may collect:

  • Full name

  • Preferred name

  • Date of birth

  • Gender

  • Address

  • School or college details

  • Contact information

  • Attendance records

  • Emergency contact information

  • Health information

  • Additional support needs

  • Safeguarding records

  • Photographs and videos

  • Monitoring and evaluation information

6.2 Parents and Carers

We may collect:

  • Names

  • Addresses

  • Contact details

  • Relationship to the young person

  • Consent forms

  • Emergency contact information

6.3 Staff and Volunteers

We may collect:

  • Recruitment information

  • References

  • DBS information

  • Payroll details

  • Bank details

  • Training records

  • Performance records

  • Emergency contacts

 

 

 

7. Lawful Bases for Processing

The organisation relies on the following lawful bases:

Consent

Used for:

  • Photography and media use

  • Marketing communications

  • Optional activities

Contract

Used where services are being provided.

Legal Obligation

Used to comply with:

  • Employment law

  • Safeguarding responsibilities

  • Health and safety requirements

  • Charity and company law obligations

Vital Interests

Where information must be shared to protect life or prevent serious harm.

Legitimate Interests

Where processing is necessary to deliver services and support organisational objectives while protecting individual rights.

8. Children's Data

The organisation recognises that children merit specific protection regarding their personal data.

We will:

  • Use age-appropriate privacy information.

  • Collect only information necessary for service delivery.

  • Seek parental or guardian consent where appropriate.

  • Respect the developing capacity of young people to make decisions regarding their information.

  • Consider the best interests of the child in all processing activities.

9. Safeguarding Information

The organisation may process safeguarding information where concerns arise regarding the welfare of a child or vulnerable person.

Information may be shared without consent where:

  • There is risk of significant harm.

  • A crime may have occurred.

  • Disclosure is required by law.

  • Safeguarding duties override confidentiality.

All safeguarding records will be:

  • Kept separately where possible.

  • Restricted to authorised personnel.

  • Retained in accordance with safeguarding guidance.

10. Photography, Video and Social Media

Photographs and videos may be used for:

  • Promotion of activities

  • Funding reports

  • Social media

  • Website content

  • Printed materials

The organisation will:

  • Obtain appropriate consent.

  • Record consent preferences.

  • Respect requests to withdraw consent.

  • Avoid identifying children by full name unless specifically agreed.

Images will be stored securely and deleted when no longer required.

11. Data Sharing

Information may be shared with:

  • Local authorities

  • Schools and colleges

  • NHS services

  • Social care teams

  • Police

  • Funding organisations

  • Professional advisers

  • Regulatory bodies

Information will only be shared where:

  • Consent has been obtained;

  • There is a lawful basis;

  • It is required by law; or

  • It is necessary for safeguarding purposes.

Whenever possible, anonymised or aggregated information will be used.

12. Data Security

The organisation will implement appropriate security measures including:

Technical Measures

  • Password-protected devices

  • Multi-factor authentication

  • Antivirus software

  • Secure cloud storage

  • Encrypted devices

  • Secure backups

Organisational Measures

  • Confidentiality agreements

  • Staff training

  • Restricted access permissions

  • Clear desk policy

  • Secure disposal procedures

13. Data Retention

The organisation will retain information only as long as necessary.

Example Retention Schedule

Record Type

Retention Period

Participant records

6 years after last engagement

Consent forms

6 years

Accident reports

3 years from date of incident (or longer where children are involved)

Safeguarding records

Until age 25 or longer if required

Staff files

6 years after employment ends

DBS information

No longer than 6 months unless legally required

Data will be securely deleted, shredded, or permanently destroyed.

 

 

14. Data Subject Rights

Individuals have the:

Right to be Informed

Know how information is used.

Right of Access

Request copies of personal data.

Right to Rectification

Correct inaccurate information.

Right to Erasure

Request deletion of information where applicable.

Right to Restrict Processing

Limit how information is used.

Right to Data Portability

Receive information in a reusable format.

Right to Object

Object to certain types of processing.

Rights Relating to Automated Decision Making

Challenge automated decisions where applicable.

Requests should be responded to within one month unless an extension is permitted by law.

15. Subject Access Requests (SARs)

Requests may be made verbally or in writing.

The organisation will:

  1. Verify identity.

  2. Record the request.

  3. Gather relevant information.

  4. Respond within one calendar month.

  5. Provide information free of charge unless requests are excessive or repetitive.

16. Data Breaches

A personal data breach may include:

  • Loss of records

  • Unauthorised access

  • Accidental disclosure

  • Theft of equipment

  • Cyber attack

All breaches must be reported immediately to the Data Protection Lead.

The organisation will:

  • Investigate the incident.

  • Assess risks.

  • Take corrective action.

  • Notify affected individuals where required.

  • Report notifiable breaches to the UK regulator, the Information Commissioner's Office within 72 hours where legally required.

A breach log will be maintained.

17. Staff and Volunteer Responsibilities

All staff and volunteers must:

  • Follow this policy.

  • Maintain confidentiality.

  • Attend training when required.

  • Use secure systems.

  • Report concerns promptly.

  • Avoid sharing information unnecessarily.

Failure to comply may result in disciplinary action.

18. Data Protection Impact Assessments (DPIAs)

A DPIA will be conducted when introducing activities likely to result in a high risk to individuals, including:

  • New databases

  • Monitoring technologies

  • Large-scale collection of sensitive information

  • New digital platforms involving children

19. Monitoring and Compliance

The Board of Directors is responsible for ensuring adequate oversight of data protection compliance.

The Data Protection Lead will:

  • Review procedures annually.

  • Monitor compliance.

  • Maintain breach records.

  • Review privacy notices.

  • Coordinate responses to data requests.

20. Complaints

Individuals who are dissatisfied with how their information has been handled should first contact:

Data Protection Lead
[Name] Sam Hill
[Email] sam@leadlimitless.co.uk
[Telephone] 07468534500

If concerns remain unresolved, individuals may complain to the:

Information Commissioner's Office (ICO)

Privacy Policy - the basics

Having said that, a privacy policy is a statement that discloses some or all of the ways a website collects, uses, discloses, processes, and manages the data of its visitors and customers. It usually also includes a statement regarding the website’s commitment to protecting its visitors’ or customers’ privacy, and an explanation about the different mechanisms the website is implementing in order to protect privacy. 
 

Different jurisdictions have different legal obligations of what must be included in a Privacy Policy. You are responsible to make sure you are following the relevant legislation to your activities and location. 

What to include in the Privacy Policy

Generally speaking, a Privacy Policy often addresses these types of issues: the types of information the website is collecting and the manner in which it collects the data; an explanation about why is the website collecting these types of information; what are the website’s practices on sharing the information with third parties; ways in which your visitors and customers can exercise their rights according to the relevant privacy legislation; the specific practices regarding minors’ data collection; and much, much more.

To learn more about this, check out our article “Creating a Privacy Policy”.

We Need Your Support Today!

bottom of page