GDPR & DATA PROTECTION POLICY (2025)
Effective date: 30 July 2025
Data Protection Officer: Michael Milano
Email: michael@clubausome.co.uk
Phone: 079495713189
1. Policy statement
Club AUsome protects the privacy and security of personal data. We comply with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. All staff, volunteers, and contractors must handle personal data lawfully, fairly, and transparently.
2. Legislation compliance
We operate under:
-
United Kingdom General Data Protection Regulation (UK GDPR)
-
Data Protection Act 2018
-
Privacy and Electronic Communications Regulations
-
Children’s Code (Age-Appropriate Design Code)
-
Freedom of Information Act 2000, where it applies
-
Human Rights Act 1998, Article 8 (right to privacy)
3. Scope
This policy applies to all staff, volunteers, trustees, contractors, and service users. It covers all personal data and special category data we collect, use, share, store, or delete, both offline and online.
4. Principles of data processing
We follow these principles and apply them in practice:
-
Lawfulness, fairness, transparency
We choose a lawful basis before we collect data. We explain what we will do with the data in clear language at the point of collection. -
Purpose limitation
We collect data for a specific reason and do not use it for another reason without a new lawful basis. -
Data minimisation
We collect the least amount of data needed to deliver the service. -
Accuracy
We keep data accurate and up to date. We correct mistakes when asked or when we find them. -
Storage limitation
We set retention periods. We delete or anonymise data when we no longer need it. -
Integrity and confidentiality (security)
We protect data using access controls, encryption, and secure storage. Only people who need data for their role can see it. -
Accountability
We keep records to show how we comply. We train our team and audit our practices.
5. Individual rights
People have the right to:
-
Access their data
-
Ask us to delete data
-
Correct inaccurate data
-
Restrict or object to processing
-
Receive their data in a portable format
-
Withdraw consent, where consent is our basis
-
Complain to the Information Commissioner’s Office
How to act on these rights
Email the Data Protection Officer at michael@clubausome.co.uk. We verify identity and respond within one calendar month. We record all requests and our actions.
6. Data collection and processing
What we collect
Names, contact details, emergency contacts, relevant health or disability information needed for safe access, photos and videos with prior consent, and payment or booking information.
Our lawful bases
-
Consent, for photos and optional communications.
-
Contract, for bookings and service delivery.
-
Legal obligation, for safeguarding reports and Disclosure and Barring Service checks.
-
Vital interests, for emergencies.
-
Legitimate interests, for routine operations where rights are not overridden.
Special category data
We process health information only when needed for safety, inclusion, or adjustments. We apply extra safeguards and strict access controls.
Children and young people
We collect consent from a parent or carer where law requires it. We design all online services to follow the Children’s Code.
7. Data storage and retention
Security controls
-
Role-based access.
-
Multi-factor authentication for admin accounts.
-
Encryption at rest and in transit for digital systems.
-
Locked cabinets for paper files.
-
Device controls for any device that stores data.
Retention periods (how we do it in practice)
-
General volunteer and staff records: engagement period plus 6 years.
-
Unsuccessful recruitment records: 6 months from decision.
-
Safeguarding records about a child: until the child reaches 25, or longer if a case is ongoing or legally required.
-
Safeguarding records about an adult: 7 years from case closure, or longer if legally required.
-
Booking and finance records: 7 years for tax.
-
Photos and videos with consent: for the stated purpose or campaign, then deleted unless renewed consent is given.
-
Messaging logs and contact lists in groups: reviewed every 12 months and pruned.
We document deletion or anonymisation.
8. Communications policy
Telephone
Only trained team members use official numbers for service updates or emergencies. We do not leave sensitive details in voicemail.
Radios
Radios are for operations and emergencies. We avoid personal data. If we must use a name for safety, we keep it brief and factual.
Messaging apps (WhatsApp, Facebook Messenger, Telegram, Signal)
Group membership reveals your name and phone number to other members. If you do not agree, request an alternative method. Admins remove people who leave a role. We do not share personal data in groups unless needed and proportionate. We review group rules every 6 months.
Social media
We post photos or identifiable content only with clear, recorded consent. Staff and volunteers must not share internal information or images of service users on personal accounts. Admins manage permissions and remove content that breaches this policy.
9. Data sharing
We share data only when needed and lawful. Examples:
-
Safeguarding concerns with the local authority, police, or the Disclosure and Barring Service.
-
Payment data with our payment processor.
-
Recruitment data with referees.
We use data sharing agreements or terms that protect confidentiality. We do not sell personal data.
10. Data breaches
Report any suspected breach to the Data Protection Officer immediately. We contain the breach, assess risk, and keep a log. If the risk is high, we notify the Information Commissioner’s Office within 72 hours and inform affected people without undue delay. We fix root causes and update training.
11. Training and awareness
All staff and volunteers complete annual data protection training. We run refreshers after any incident or legal change. We brief all new starters before they access systems.
12. Disclosure and Barring Service (DBS) compliance and Code of Practice
What this covers
Checks for roles that involve children, young people, or vulnerable adults.
How we comply
-
We carry out a role risk assessment to choose the correct level of check (basic, standard, or enhanced with barred list as appropriate).
-
We follow the Disclosure and Barring Service Code of Practice. We ask only for information that is relevant to the role.
-
We treat all applicants fairly. A past conviction does not automatically bar a person. We consider relevance, seriousness, time elapsed, and pattern.
-
We verify identity with original documents in a private setting.
-
We never require applicants to share their full certificate by email or open message.
-
We do not keep copies of certificates. We record the certificate number, issue date, and decision outcome.
-
We store our recruitment decision record securely.
-
We review checks at set intervals based on risk, usually every three years or sooner if the role changes.
Retention and confidentiality
-
Certificate copies are not kept.
-
Certificate numbers and outcomes are kept for up to 6 months for audit, then deleted, unless lawfully required for longer.
-
Access is limited to those who make safer-recruitment decisions.
Example
A new volunteer for youth sessions needs an enhanced check with barred list. Identity is verified in person. When the certificate arrives, the recruiter records the number and decision. No copy is stored.
13. Safeguarding reporting and confidentiality
How to report
Any concern about harm or risk is reported at once to the Designated Safeguarding Lead or their deputy. If a person is in immediate danger, call emergency services first, then notify the Designated Safeguarding Lead.
What we record
We record facts, dates, times, who was present, and what was said using the person’s own words where possible. We avoid opinions. We store the record in a secure safeguarding case file.
Confidentiality rules
-
We share safeguarding information on a strict need-to-know basis.
-
We do not promise secrecy. We explain that we may need to share with the local authority, police, or other agencies to keep people safe.
-
We protect the reporter’s identity where possible.
-
We keep a clear access list for each case file.
Example
A volunteer reports a disclosure from a young person. The Designated Safeguarding Lead records the disclosure, informs children’s services the same day, and restricts access to the case file to the Designated Safeguarding Lead, Data Protection Officer, and chair of trustees if oversight is needed.
14. Internal investigations and confidentiality
When used
Complaints, conduct issues, data incidents, or allegations about staff or volunteers.
Process
-
We appoint an investigator who is impartial and senior enough.
-
We collect statements and evidence in a secure case file.
-
We inform the person who is the subject of the concern at the right stage and explain the process.
-
We keep people informed within the limits of confidentiality and law.
-
We keep a clear audit trail of decisions and reasons.
Confidentiality rules
-
Information is shared only with those who need it to carry out the investigation or to meet legal duties.
-
We protect the identity of witnesses where possible.
-
We remind all participants not to discuss the case outside formal channels.
-
Retaliation against reporters or witnesses is a disciplinary matter.
Example
A complaint is raised about a volunteer’s behaviour in a session. The lead investigator interviews witnesses, reviews radio logs, and checks messaging records. Access to the case is limited to the investigator, the Data Protection Officer, and the relevant trustee subcommittee.
15. Recruitment and references confidentiality
What we collect
Application forms, identity checks, right-to-work status where relevant, interview notes, references, and safer-recruitment checks.
How we protect it
-
Applications are stored in our recruitment system with role-based access.
-
Interview notes and scoring sheets are kept in a secure folder.
-
References are requested using a standard form that explains confidentiality and lawful use.
-
Referees submit references directly to us. We do not pass references to the applicant.
-
We verify references by contacting the referee at a known official channel.
Retention
-
Successful candidates: recruitment file moves to the personnel file and is kept for the engagement period plus 6 years.
-
Unsuccessful candidates: 6 months from decision, then deleted.
-
Equality and diversity monitoring forms are stored separately and reported only in aggregate.
Example
A referee emails a confidential reference to our official address. The recruiting manager files it in the secure folder. The applicant is told the outcome but does not receive a copy of the reference.
16. Data Protection Impact Assessments (DPIAs)
We run a Data Protection Impact Assessment before high-risk processing. Examples: new safeguarding software, a new camera system, or any large-scale profiling. We record risks, mitigations, and decisions.
17. International transfers
If a supplier stores data outside the United Kingdom, we check safeguards, such as adequacy regulations or standard contractual clauses. We keep this in our supplier file.
18. Processors and suppliers
We choose suppliers who meet our security standards. We sign data processing terms that set duties, security, sub-processor controls, and deletion on exit. We review key suppliers yearly.
19. Access control and audit
We grant access based on role. We remove access when roles change or people leave. We review access rights every quarter. We keep audit logs for key systems.
20. Supporting documents (read with this policy)
-
Safeguarding Policy
-
Safeguarding Reporting Procedure
-
Internal Investigations Procedure
-
Disclosure and Barring Service (DBS) Policy and Code of Practice Compliance
-
Safer Recruitment Policy and Procedure
-
Social Media and Communications Policy
-
Data Breach Response Plan
-
Data Retention Schedule
-
Subject Access Request Procedure
21. Contact
Data Protection Officer: Michael Milano
Email: michael@clubausome.co.uk
Phone: 079495713189