1/9/2025

  • Activ8 Data Protection Policy

    1. Purpose

    This policy sets out how Activ8 collects, uses, stores, and protects personal data. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

    2. Scope

    This policy applies to all Activ8 staff, volunteers, and contractors who have access to personal data relating to children, parents/carers, schools, staff, and partners.

    3. What is Personal Data?

    Personal data is any information that can identify a living individual. This includes names, contact details, addresses, photos, financial information, health/medical details, and safeguarding records.

    4. Data Protection Principles

    Activ8 follows the 7 principles of data protection. Personal data must be:
    1. Lawful, fair, and transparent – processed with a clear purpose.
    2. Used for specific purposes – collected only for legitimate activities.
    3. Limited – only what is necessary is collected.
    4. Accurate – kept up to date.
    5. Stored no longer than necessary – securely deleted or archived when no longer needed.
    6. Secure – protected against loss, damage, or unauthorised access.
    7. Accountable – we are responsible for demonstrating compliance.

    5. What Data We Collect

    Activ8 may collect and process:
    - Children’s data – names, DOB, medical details, attendance, safeguarding records.
    - Parent/carer data – names, contact details, payment details.
    - Staff data – employment records, qualifications, DBS, payroll information.
    - Partner/school data – contracts, contacts, and communications.

    6. Lawful Basis for Processing

    We process personal data on the following grounds:
    - Contractual obligation (e.g. delivering wraparound or PE services).
    - Legal obligation (e.g. safeguarding, HMRC, OFSTED requirements).
    - Legitimate interest (e.g. business operations, quality assurance).
    - Consent (e.g. use of photos for marketing, where parents opt-in).

    7. How We Protect Data

    - Data is stored securely on password-protected systems and encrypted drives.
    - Paper records are kept in locked storage.
    - Access is limited to authorised staff only.
    - Staff must not use personal devices for sensitive data unless approved.

    8. Sharing Data

    We only share data where necessary and lawful, for example:
    - With schools, OFSTED, or local authorities (safeguarding, compliance, complaints).
    - With HMRC or payroll providers (staff data).
    - With catering/third parties where essential to service delivery.

    We never sell personal data.

    9. Data Retention

    - Safeguarding records – kept until the child is 25.
    - Accident/incident records – 3 years minimum.
    - Staff records – 6 years after leaving employment.
    - Financial records – 6 years.

    Retention schedules are reviewed annually.

    10. Rights of Individuals

    Parents, children (where appropriate), and staff have the right to:
    - Access their data (“subject access request”).
    - Request correction or deletion of data.
    - Restrict or object to processing.
    - Withdraw consent (where consent is the basis).

    Requests should be made in writing to the Data Protection Lead.

    11. Breaches

    All data breaches (loss, unauthorised access, accidental disclosure) must be reported immediately to the Data Protection Lead. Serious breaches may be reported to the ICO within 72 hours.

    12. Responsibilities

    - Data Protection Lead (DPL): Owen Wedgwood, Managing Director
    - All staff must complete training and follow this policy.
    - Managers must ensure secure handling of records at their sites.

    13. Review

    This policy will be reviewed annually or sooner if legislation changes.

PARTNERING WITH

Exceed Learning PartnershipEmpowering Minds MATCIMSPADoncaster CouncilAspire Active Partnerships