Data Protection Policy
How we handle the personal data we hold about children, families, volunteers, staff, trustees and donors, your rights over it, and how to raise a data protection complaint.
- Version
- 1.0 · September 2026
- Policy year
- 2026–27
- Next review
- September 2027
- Approved by
- Board of Trustees
Section 1Purpose and scope
Being The Cure holds personal data about children, parents and carers, volunteers, staff, trustees, donors and beneficiaries. Much of it is sensitive: medical and allergy information, safeguarding records, and information about family circumstances. This policy sets out how that data is handled and who is accountable for it.
BTC is the data controller. This policy applies to everyone who handles personal data for BTC, whoever they are and wherever they are working.
Section 2Legal framework
- The UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
- Article 24(2) of the UK GDPR, which requires a controller to implement appropriate data protection policies where that is proportionate. Given that BTC holds children’s health and safeguarding data, it is proportionate, and this policy is that measure.
- Article 30 of the UK GDPR, which requires a written record of processing activities. The exemption in Article 30(5) for organisations with fewer than 250 employees does not apply to BTC, because its processing includes special category data. BTC therefore maintains a record of processing activities.
- Articles 13 and 14, which require privacy notices. BTC maintains separate notices for children and their parents or carers, for volunteers, and for staff and trustees.
- Article 33, which requires a personal data breach to be notified to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours where it is likely to result in a risk to people’s rights and freedoms. Article 33(5) requires every breach to be documented, whether or not it is notifiable.
- Section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025 and in force from 19 June 2026. This is new and is dealt with at section 5 below.
- Section 137 of the Data Protection Act 2018 and the Data Protection (Charges and Information) Regulations 2018, under which a controller must pay the data protection fee to the Information Commissioner unless exempt. BTC is registered under the ICO with registration ZC261119.
Section 3Data protection principles
BTC processes personal data lawfully, fairly and transparently; for specified, explicit and legitimate purposes; limited to what is necessary; accurately and kept up to date; kept no longer than necessary; and securely. The trustees are accountable for demonstrating that this happens.
Lawful bases. BTC relies on: consent for photography, marketing and optional activities; contract for employment and paid services; legal obligation for safeguarding referrals, employment records and statutory information notices; and legitimate interests for administering its activities and for fundraising to existing supporters. For special category data, BTC relies principally on the safeguarding condition in Schedule 8 to the Data Protection Act 2018, and on explicit consent for medical and dietary information collected at registration.
Section 4Safeguarding and information sharing
Data protection is not a reason to withhold information needed to keep a child safe. The UK GDPR and the Data Protection Act 2018 permit sharing, including of special category data, where it is necessary for safeguarding purposes. Anyone in doubt shares the concern with the Designated Safeguarding Lead and lets the DSL decide what is shared onward. Consent is not required before making a safeguarding referral, and seeking it may increase risk to the child.
Where the London Borough of Newham serves a notice under section 436E of the Education Act 1996, inserted by section 38 of the Children’s Wellbeing and Schools Act 2026, requiring information about a child receiving out-of-school education, BTC will comply. The CEO records each notice received and the information supplied, and reports it to the next committee meeting.
Section 5Individual rights, and the new complaints duty
People have the right to be informed, to access their data, and to rectification, erasure, restriction, portability and objection, subject to the exemptions in the Act. A subject access request is answered within one month, extendable by two further months where the request is complex. Searches must be reasonable and proportionate. Requests are logged and answered by the CEO, Vijith Vijay, vijith@beingthecure.org.
Complaints about how BTC handles personal data: Since 19 June 2026, section 164A of the Data Protection Act 2018 has required BTC to facilitate the making of such complaints, including by providing a complaint form that can be completed electronically and by other means; to acknowledge receipt within 30 days of the complaint being received; and, without undue delay, to take appropriate steps to respond, to make enquiries to the extent appropriate, to inform the complainant of progress, and to inform them of the outcome.
This is a hard statutory deadline and it is separate from the general Complaints Policy. Data protection complaints are made to the CEO, Vijith Vijay, at vijith@beingthecure.org, and are logged with the date received, the date acknowledged and the date of the outcome. A complainant who remains dissatisfied may complain to the Information Commissioner’s Office.
Section 6Security, retention and breaches
- Personal data is held on BTC systems only. It is not stored on personal devices, personal cloud accounts or personal email, and is not removed from BTC systems without the CEO’s written authority.
- Safeguarding and accident records are held on the Saturday School app at saturdayschool.beingthecure.org, which is a BTC system for this purpose. Concerns are not recorded in personal notebooks, personal email or messaging apps.
- Access is limited to those who need it for their role. Safeguarding records are held separately from general records, with access restricted to the DSL, the deputy DSL and the CEO.
- Paper records containing personal data are held in a locked cabinet and are not left unattended.
- Retention follows the schedule in the Privacy Notices and Records Retention Policy. Safeguarding records about a child are retained until the child’s twenty-fifth birthday unless a longer period is required.
- Every personal data breach, including a suspected one, is reported to the CEO immediately and recorded in the breach log, whether or not it is notifiable. The CEO assesses whether it must be reported to the Information Commissioner within 72 hours and whether the people affected must be told. A significant breach is also a reportable serious incident to the Charity Commission.
Section 7Accountability
BTC is not required to appoint a statutory Data Protection Officer. Article 37(1) of the UK GDPR requires one only for public authorities, for controllers whose core activities involve regular and systematic monitoring on a large scale, and for those whose core activities involve large-scale processing of special category or criminal offence data. BTC is none of these. The Data (Use and Access) Act 2025 did not replace the DPO with a senior responsible individual; that proposal was in an earlier Bill that fell.
The trustees nevertheless appoint a named data protection lead at trustee level, and the CEO is responsible day to day. This is a governance appointment and not a statutory DPO appointment, so the independence obligations in Articles 38 and 39 do not apply to it. The DPO is the Kayser Izard, Chair of Trustees.
Version history
- Version 1.0September 2026· Board of Trustees
New policy. First issue.
Questions about this policy?
Contact us at info@beingthecure.org. If a child is in immediate danger, call 999.
Being The Cure is a registered charity in England and Wales (No. 1188077). This page is the published version of the Data Protection Policy 2026–27.