Data Protection and GDPR Policy

Overview

Policy Statement

Beyond Barriers CIC is committed to protecting the privacy, confidentiality and security of all personal information relating to young people, parents/carers, staff, volunteers, contractors and partner agencies. The organisation recognises its responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and is committed to ensuring that all personal data is processed lawfully, fairly, transparently and securely.

Beyond Barriers CIC works with vulnerable young people aged 16–24 and therefore recognises the importance of maintaining the highest standards of confidentiality, safeguarding and information security.

The organisation is registered with the Information Commissioner’s Office (ICO) as a Data Controller.

  1. Purpose

The purpose of this policy is to ensure that:

  • Personal data is collected and processed lawfully and fairly.
  • Confidential information is protected from unauthorised access, loss or misuse.
  • Staff understand their responsibilities regarding data protection.
  • Individuals understand their rights regarding their personal data.
  • Appropriate systems are in place to ensure compliance with UK GDPR and Data Protection legislation.
  1. Scope

This policy applies to:

  • All staff
  • Volunteers
  • Directors
  • Contractors
  • External professionals working on behalf of Beyond Barriers CIC

It applies to all personal data processed by the organisation in both electronic and paper formats.

  1. Definitions

Personal Data

Any information relating to an identifiable person.

Special Category Data

Sensitive information including:

  • Health information
  • EHCP information
  • Safeguarding records
  • Race or ethnicity
  • Religious beliefs
  • Sexual orientation
  • Criminal or safeguarding information
  1. Data Protection Principles

Beyond Barriers CIC will ensure all personal data is:

  1. Processed lawfully, fairly and transparently.
  2. Collected for specified, legitimate purposes.
  3. Adequate, relevant and limited to what is necessary.
  4. Accurate and kept up to date.
  5. Retained only as long as necessary.
  6. Stored securely and confidentially.
  7. Processed in a way that demonstrates accountability and compliance.
  1. Lawful Basis for Processing

Beyond Barriers CIC processes data under the following lawful bases:

  • Consent
  • Legal obligation
  • Vital interests
  • Public task
  • Legitimate interests
  • Safeguarding responsibilities

Sensitive data may also be processed where necessary for:

  • Education provision
  • Safeguarding
  • Health and social care support
  • Protecting vulnerable individuals
  1. Data Collection

The organisation may collect and process information relating to:

  • Young people accessing provision
  • Parents and carers
  • Staff and volunteers
  • Commissioners and partner agencies

This may include:

  • Contact details
  • Attendance records
  • EHCPs
  • Medical information
  • Safeguarding information
  • Behaviour and risk assessments
  • Educational reports
  • Employment and qualification records

Information is collected only where necessary to provide safe and effective support.

  1. Consent

Where consent is required:

  • Consent will be freely given, informed and specific.
  • Consent can be withdrawn at any time.
  • Records of consent will be maintained securely.
  • Additional consideration will be given regarding capacity and vulnerability.
  1. Data Storage & Security

Beyond Barriers CIC takes appropriate technical and organisational measures to protect personal data.

Measures include:

  • Password-protected devices and systems
  • Secure storage of paper records
  • Restricted access to confidential information
  • Locked filing cabinets
  • Secure email systems
  • Staff confidentiality expectations
  • Regular review of access permissions
  • Secure disposal and shredding of confidential documents

All staff are responsible for maintaining confidentiality and ensuring information is accessed only on a need-to-know basis.

  1. Data Sharing

Information may be shared with:

  • Local Authorities
  • Schools and colleges
  • Social care services
  • Health professionals
  • Safeguarding agencies
  • Commissioners
  • Awarding bodies

Information will only be shared:

  • Where lawful and necessary
  • In the best interests of the young person
  • For safeguarding purposes
  • With appropriate consent where required

Safeguarding concerns may be shared without consent where there is risk of harm.

  1. Data Retention

Records will be retained only for as long as necessary in accordance with legal, safeguarding and operational requirements.

Secure disposal methods will include:

  • Confidential shredding
  • Permanent deletion of electronic records
  • Secure destruction of storage devices where necessary
  1. Data Subject Rights

Individuals have the right to:

  • Access their personal data
  • Request correction of inaccurate information
  • Request erasure where appropriate
  • Restrict processing
  • Object to processing
  • Request transfer of data
  • Withdraw consent where applicable

Requests should be made in writing to the Directors of Beyond Barriers CIC.

  1. Data Breaches

Any actual or suspected data breach must be reported immediately to the Directors.

The organisation will:

  • Investigate breaches promptly
  • Take action to minimise risk
  • Notify the ICO where required
  • Inform affected individuals where appropriate
  • Review procedures following incidents
  1. Staff Responsibilities

All staff, volunteers and contractors must:

  • Maintain confidentiality
  • Follow data protection procedures
  • Access information only when necessary
  • Store information securely
  • Report breaches immediately
  • Complete relevant training and induction

Failure to comply with this policy may result in disciplinary action.

  1. Safeguarding & Confidentiality

Safeguarding concerns will always take priority over confidentiality where there is risk of harm to a child or vulnerable adult.

Information sharing will follow:

  • Keeping Children Safe in Education
  • Working Together to Safeguard Children
  • Care Act 2014 guidance
  • UK GDPR and Data Protection Act 2018
  1. Monitoring & Review

This policy will be reviewed annually or sooner where:

  • Legislation changes
  • Guidance changes
  • Operational needs require updates
  • Significant incidents occur

Policy Information

Policy Owner: Beyond Barriers Pathways CIC Directors
Approved By: Rebecca Cox & Sarah Harris
Review Frequency: Annually
Date Approved: 09/06/2026
Review Date:  09/06/2027