← All policies Policy

Data protection (GDPR)

In force from 20 May 2026 · Next review 20 May 2027

1. Purpose and Scope

Kinect Community CIC recognises its legal and moral responsibility to protect the personal data of children, young people, families, staff, volunteers, trustees, and partner organisations. We are committed to handling all personal data lawfully, fairly, transparently, and securely in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Kinect Community CIC is a Community Interest Company (CIC) delivering community-based support, enrichment, engagement, wellbeing, and personal development opportunities for children and young people, including those who are home educated, socially isolated, vulnerable, disengaged from education, or requiring additional support.

This policy applies to all staff, volunteers, trustees, contractors, sessional workers, and anyone processing personal data on behalf of Kinect Community CIC.

2. Key Definitions

Personal Data: Information relating to an identified or identifiable individual. Special Category Data: Sensitive information including health, ethnicity, religion, biometric data, and safeguarding information. Processing: Any activity involving personal data, including collection, storage, sharing, or deletion. Data Controller: The organisation that determines how and why personal data is processed. Data Processor: Any external organisation processing personal data on behalf of Kinect Community CIC. Data Breach: Any accidental or unlawful loss, disclosure, destruction, or unauthorised access to personal data.

3. Roles and Responsibilities

Kinect Community CIC acts as the Data Controller for all personal data held for organisational purposes.

The Directors and Leadership Team are responsible for ensuring compliance with data protection legislation and maintaining appropriate oversight, resources, and governance.

All staff and volunteers are responsible for: • Following this policy at all times. • Keeping personal data secure and confidential. • Sharing information appropriately and lawfully. • Reporting suspected or actual data breaches immediately. • Completing relevant GDPR and safeguarding training.

Kinect Community CIC will appoint a named Data Protection Lead responsible for handling GDPR queries, breaches, and Subject Access Requests.

4. Data Protection Principles

We will ensure personal data is: • Processed lawfully, fairly, and transparently. • Collected for specified, explicit purposes. • Adequate, relevant, and limited to what is necessary. • Accurate and kept up to date. • Retained only for as long as necessary. • Processed securely to maintain confidentiality and integrity. • Managed in a way that demonstrates accountability and compliance.

5. Personal Data We May Collect

Kinect Community CIC may collect and process information relating to:

Children and Young People: • Names, addresses, dates of birth, emergency contacts. • Attendance records and engagement information. • Health, wellbeing, SEND, safeguarding and risk assessment information. • Behaviour and incident records. • Progress and participation records.

Parents/Carers: • Contact information. • Parental responsibility details. • Consent forms and communications.

Staff and Volunteers: • Recruitment and DBS information. • Employment records. • Training and safeguarding records. • Emergency contact details.

We only collect data necessary to support our activities, safeguarding responsibilities, funding requirements, and service delivery.

6. Lawful Basis for Processing

Kinect Community CIC processes personal data under lawful bases including: • Legitimate interests. • Legal obligations. • Consent. • Contract. • Vital interests.

Where special category or safeguarding data is processed, we rely on additional lawful conditions under Article 9 of UK GDPR and the Data Protection Act 2018.

We recognise safeguarding children and young people as a legitimate and essential reason for information processing and sharing.

7. Information Sharing and Safeguarding

Kinect Community CIC may share information with schools, local authorities, safeguarding agencies, healthcare professionals, commissioners, and other relevant agencies where necessary to support children and young people or fulfil safeguarding responsibilities.

Information sharing will always be: • Lawful. • Necessary and proportionate. • Shared on a need-to-know basis. • Recorded appropriately. • Shared securely.

Where appropriate, consent will be sought before sharing information. However, information may be shared without consent where there are safeguarding concerns, risks of harm, or other lawful reasons to do so.

8. Data Security

Kinect Community CIC is committed to protecting personal information through appropriate technical and organisational measures.

These include: • Password-protected systems and devices. • Secure storage of paper records. • Restricted access to sensitive information. • Secure transfer of information. • Staff confidentiality expectations. • Regular staff training and awareness.

Staff must not use personal email accounts or unauthorised devices to store or transfer personal data.

9. Record Retention and Disposal

Personal data will only be retained for as long as necessary for operational, legal, safeguarding, insurance, or funding purposes.

Once information is no longer required, it will be securely disposed of through shredding, confidential waste disposal, or secure digital deletion.

Kinect Community CIC will maintain appropriate retention schedules and disposal records.

10. Data Breaches

Any suspected or actual personal data breach must be reported immediately to the Data Protection Lead.

Kinect Community CIC will: • Investigate all breaches promptly. • Take steps to contain and minimise risks. • Maintain a breach log. • Report serious breaches to the Information Commissioner’s Office (ICO) within 72 hours where legally required. • Inform affected individuals where appropriate.

Following any breach, procedures will be reviewed to reduce the risk of recurrence.

11. Individual Rights

Individuals have the right to: • Be informed about how their information is used. • Access their personal data. • Request correction of inaccurate data. • Request erasure of data in certain circumstances. • Restrict or object to processing. • Request data portability where applicable.

Requests relating to personal data will be handled promptly and in line with UK GDPR timescales.

12. Photographs and Media

Kinect Community CIC may use photographs or videos for celebration, promotional, evidencing, or funding purposes where appropriate consent has been obtained.

Images will be stored securely and used only for agreed purposes. Staff and volunteers must not use personal devices to take photographs of children or young people unless specifically authorised.

13. Training and Monitoring

All staff and volunteers will receive GDPR, confidentiality, safeguarding, and information-sharing guidance appropriate to their role.

This policy will be reviewed annually or sooner where legislation, guidance, or operational needs change.

Monitoring activities may include supervision, audits, incident reviews, and policy evaluations.

14. Complaints

Concerns regarding data protection should initially be raised with Kinect Community CIC.

Individuals also have the right to raise concerns with the Information Commissioner’s Office (ICO) if they believe their information has not been handled appropriately.

This policy should be read alongside: • Safeguarding and Child Protection Policy. • Confidentiality Policy. • Online Safety Policy. • Staff Code of Conduct. • UK GDPR and Data Protection Act 2018 guidance. • Information Commissioner’s Office (ICO) guidance. • Working Together to Safeguard Children. • Keeping Children Safe in Education.

Data Protection Lead: __________________________ Organisation: Kinect Community CIC

Questions about this policy? Email contact@kinectcommunity.org.