Policies & procedures

Data Protection Policy

This Data Protection Policy explains how Street Lights Collective CIC collects, uses, stores, shares, protects and deletes personal information. It applies to all directors, staff, sessional workers, volunteers, practitioners, advisors,…

All policies
Organisation
Street Lights Collective CIC
Policy title
Data Protection Policy
Version
1.0
Date approved
To be inserted
Review date
Annually, or sooner if law, guidance, risk or organisational activity changes
Approved by
Board of Directors
Responsible lead
Board of Directors, supported by the Finance and Compliance Lead
Designated Safeguarding Lead
Phillip Chackochen
Finance and Compliance Lead
Marisa Ferguson

Purpose of this policy

This Data Protection Policy explains how Street Lights Collective CIC collects, uses, stores, shares, protects and deletes personal information. It applies to all directors, staff, sessional workers, volunteers, practitioners, advisors, partners and anyone acting on behalf of the Organisation.

Street Lights Collective CIC works with children, young people, families, schools, communities, professionals and partner organisations. This means the Organisation may handle sensitive information about identity, family circumstances, safeguarding concerns, trauma, education, attendance, behaviour, health, referrals, programme participation, photographs, videos, testimonials, staff records and partnership activity.

The purpose of this policy is to ensure that personal information is handled lawfully, fairly, safely, transparently and respectfully. It also supports the Organisation to comply with the UK General Data Protection Regulation, the Data Protection Act 2018 and relevant guidance from the Information Commissioner’s Office.

Street Lights approach to data protection

Street Lights Collective CIC is rooted in Presence. Power. Purpose. This also shapes how the Organisation handles personal information.

PrincipleMeaning for data protection
PresenceWe are trusted with real stories, lived experience and sensitive information. We handle that trust with care.
PowerWe do not misuse information, exploit stories or remove people’s control over their personal data.
PurposeWe only collect and use information for clear, necessary and legitimate reasons connected to the Organisation’s work.

Data protection is not only a compliance issue. For Street Lights, it is part of safeguarding, dignity, trust, accountability and trauma informed practice.

Scope of this policy

This policy applies to all personal information handled by Street Lights Collective CIC, whether held digitally, on paper, in photographs, in videos, in emails, in messages, in case notes, in attendance records, in referral forms, in monitoring reports or in any other format.

This policy applies to information relating to:

  • children and young people
  • parents and carers
  • families and community members
  • programme participants
  • youth ambassadors
  • staff, sessional workers and volunteers
  • six trauma informed practitioners within the delivery team
  • directors and advisors
  • schools, local authorities and partner organisations
  • referrers, commissioners, funders and professionals
  • people who contact the Organisation online, by email, by telephone or in person

Legal framework

Street Lights Collective CIC will process personal information in line with applicable UK data protection law and relevant guidance. This includes:

  • UK General Data Protection Regulation
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations where relevant
  • Information Commissioner’s Office guidance
  • safeguarding duties and statutory guidance where relevant
  • contractual and funding requirements where these are lawful and appropriate
  • Where safeguarding duties require information to be shared to protect a child, young person or adult at risk, Street Lights Collective CIC will prioritise safety and act in line with safeguarding procedures and data protection law.

Data protection principles

Street Lights Collective CIC will follow the data protection principles. Personal information must be:

PrincipleHow Street Lights will apply it
Lawfulness, fairness and transparencyWe will use information only where we have a lawful reason, and we will be clear about how information is used.
Purpose limitationWe will collect information for clear purposes and will not use it for unrelated reasons without a lawful basis.
Data minimisationWe will only collect information that is adequate, relevant and necessary.
AccuracyWe will take reasonable steps to keep information accurate and up to date.
Storage limitationWe will not keep information for longer than necessary.
Integrity and confidentialityWe will protect information from unauthorised access, loss, damage or misuse.
AccountabilityWe will be able to show how we comply with data protection responsibilities.

Types of information we may collect

Street Lights Collective CIC may collect and process the following types of personal information where relevant to its work.

Children, young people and programme participants

  • name, age, date of birth and contact details where appropriate
  • parent or carer details and emergency contacts
  • school, college, referral agency or local authority details
  • attendance and participation records
  • programme assessments, feedback and outcomes
  • mentoring notes, session summaries and action plans
  • education, employment or training progression information
  • information about additional needs, accessibility needs or reasonable adjustments
  • safeguarding concerns, risk indicators and referrals where relevant
  • photographs, videos, audio recordings or testimonials where valid consent has been obtained, unless another lawful basis applies

Parents, carers and families

  • names and contact details
  • relationship to child or young person
  • family support needs where relevant
  • attendance at workshops, programmes and events
  • feedback, testimonials and impact information
  • safeguarding or welfare information where relevant

Staff, volunteers, practitioners, advisors and directors

  • identity and contact details
  • recruitment and selection information
  • DBS information where applicable
  • references and suitability checks
  • training and supervision records
  • contracts, payment records and invoices where relevant
  • emergency contact details
  • conduct, complaints or safeguarding records where relevant

Partners, referrers, commissioners and funders

  • names, roles and professional contact details
  • organisation details
  • referral and communication records
  • contract, service and funding information
  • meeting notes, reports and evaluation information

Special category information and sensitive information

Street Lights Collective CIC may sometimes process special category information or sensitive information because of the nature of its work. This may include information about health, trauma, disability, ethnicity, religion or belief, family circumstances, safeguarding concerns, criminal exploitation, youth violence risk, or other sensitive matters.

This information will only be processed where necessary, lawful, proportionate and properly protected. Access to sensitive information will be restricted to those who need it for safeguarding, programme delivery, reporting, legal, contractual or organisational purposes.

Information about criminal allegations, offences, exploitation, gang involvement, police involvement, youth justice or court related issues will be handled with particular care. The Organisation will only collect and share this information where there is a clear lawful basis and a legitimate need to do so.

Lawful basis for processing

Street Lights Collective CIC will identify an appropriate lawful basis before processing personal information. Depending on the activity, the lawful basis may include:

Lawful basisExample within Street Lights
ConsentUsing photographs, videos, testimonials or optional mailing list sign ups.
ContractManaging contracts with staff, contractors, schools, commissioners or partners.
Legal obligationKeeping records required by law, safeguarding duties, finance records or employment requirements.
Vital interestsSharing information in an emergency to protect life or prevent serious harm.
Public taskWhere work is commissioned by or carried out with a public authority and the processing is necessary for that task.
Legitimate interestsManaging programmes, responding to enquiries, safeguarding administration, evaluation and organisational development, where rights and freedoms are properly considered.

For special category data, the Organisation will also identify an additional condition where required. This may include explicit consent, substantial public interest, safeguarding, social care, employment law obligations or vital interests, depending on the circumstances.

Children and young people’s information

Street Lights Collective CIC recognises that children and young people deserve particular care when their information is collected and used.

The Organisation will:

  • explain how information will be used in language that is clear and age appropriate
  • obtain parent or carer consent where required
  • respect the voice and understanding of the young person where appropriate
  • only collect information that is necessary for the purpose
  • protect information from unnecessary sharing
  • avoid exposing young people through photographs, videos or public stories without proper consent and risk consideration
  • consider contextual safeguarding risks before publishing or sharing any information that could identify a young person, location, peer group or risk context

Consent

Consent must be freely given, specific, informed and clear. The Organisation will not rely on consent where there is an imbalance of power or where the person has no real choice.

Consent may be used for:

  • photographs and videos
  • testimonials and case studies
  • mailing lists and newsletters
  • optional surveys or feedback
  • sharing stories for publicity or funding purposes
  • Consent can be withdrawn. Where consent is withdrawn, Street Lights Collective CIC will stop using the information where it is reasonable and lawful to do so. Withdrawal of consent may not always require deletion of records where the Organisation has another lawful reason to keep them, such as safeguarding, legal, financial or contractual obligations.

Photography, filming, testimonials and storytelling

Street Lights Collective CIC may use photographs, videos, testimonials and stories to demonstrate impact and promote community benefit. This must be done ethically and safely.

The Organisation will:

  • obtain written consent before using identifiable images, videos or testimonials, unless another lawful basis clearly applies
  • seek parent or carer consent for children where required
  • consider the views and safety of the young person
  • avoid using images or stories that could increase risk, shame, stigma or retaliation
  • avoid identifying young people connected to safeguarding concerns, gang conflict, exploitation, youth justice or family trauma unless there is a clear and safe reason
  • allow people to ask for images or stories to be removed where reasonable
  • avoid sensationalising trauma, violence or pain for publicity, funding or social media

Contextual safeguarding and data protection

Street Lights Collective CIC understands that harm can happen beyond the home and can be connected to peer groups, schools, estates, transport routes, social media, local areas, gangs, exploitation and postcode conflict. This is why contextual safeguarding is central to how the Organisation handles information.

Information may need to be collected or shared where there are concerns about:

  • serious youth violence
  • knife carrying
  • gang involvement
  • criminal exploitation
  • county lines
  • online grooming or threats
  • postcode conflict
  • retaliation risk
  • unsafe peer groups
  • missing episodes
  • sexual exploitation
  • domestic abuse
  • neglect or abuse
  • risk of significant harm
  • Where information is shared for safeguarding reasons, the Organisation will share only what is necessary, with the appropriate person or agency, and will record the reason for sharing. The Designated Safeguarding Lead, Phillip Chackochen, will oversee safeguarding related information sharing wherever possible.

Data sharing

Street Lights Collective CIC may share personal information where it is lawful, necessary and proportionate. This may include sharing with:

  • children’s social care
  • adult social care
  • police
  • schools, colleges or education providers
  • local authorities
  • youth justice services
  • health or mental health services
  • funders or commissioners where reporting requirements apply
  • partner organisations involved in delivery
  • emergency services
  • professional advisors where required
  • The Organisation will not sell personal information. It will not share personal information for unrelated marketing purposes.

Where routine data sharing takes place with a partner organisation, a written agreement should be used where appropriate. This may include the purpose of sharing, what information is shared, who can access it, how it is protected, retention arrangements and safeguarding escalation routes.

Referrals and safeguarding records

Referral forms, safeguarding records, mentoring notes, risk assessments and case related information must be handled securely.

The Organisation will:

  • record safeguarding concerns clearly and factually
  • separate facts from professional opinion where possible
  • store safeguarding records securely with restricted access
  • share safeguarding information only where necessary and lawful
  • keep a record of decisions, referrals and information sharing
  • ensure the DSL has access to information needed to protect children, young people and adults at risk

Data security

Street Lights Collective CIC will take appropriate steps to protect personal information from unauthorised access, loss, destruction, alteration, disclosure or misuse.

Security measures may include:

  • password protected devices and accounts
  • secure cloud storage with controlled access
  • multi factor authentication where possible
  • restricted access to sensitive records
  • secure disposal of paper records
  • locked storage for paper files
  • regular review of who has access to data
  • care when sending information by email
  • avoiding personal devices for sensitive records unless authorised and secure
  • secure transfer methods for sensitive information
  • clear instructions for staff, practitioners and volunteers

Use of personal devices, email and messaging

Staff, practitioners, directors and volunteers must handle information carefully when using phones, laptops, tablets, email or messaging applications.

The Organisation expects that:

  • sensitive information is not stored unnecessarily on personal devices
  • devices used for Organisation work are password protected
  • confidential information is not shared in informal group chats unless this has been authorised for a clear purpose
  • photographs or videos of children and young people are not stored on personal devices longer than necessary
  • personal social media accounts are not used to communicate privately with children or young people
  • email addresses are checked carefully before sensitive information is sent
  • blind copy is used for group emails where recipients should not see each other’s details
  • any suspected loss or unauthorised disclosure is reported immediately

Retention and deletion

Street Lights Collective CIC will not keep personal information for longer than necessary. Retention periods may depend on legal, safeguarding, contractual, financial, insurance and operational requirements.

The following retention schedule provides guidance and should be reviewed by the Board.

Record typeSuggested retention period
General enquiriesUp to 12 months after last contact, unless further action is required.
Programme attendance recordsUp to 6 years after programme completion, unless safeguarding reasons require longer retention.
Participant feedback and evaluationUp to 6 years, anonymised where possible.
Safeguarding records concerning childrenUntil the young person reaches age 25, or longer where required by the seriousness of the concern or advice from statutory services.
Adult safeguarding recordsUp to 6 years after last action, or longer where risk, legal or safeguarding reasons require it.
Staff and volunteer recruitment records for unsuccessful applicantsUp to 6 months after recruitment decision, unless a dispute or safeguarding concern requires longer retention.
Staff, sessional worker and volunteer recordsUp to 6 years after the working relationship ends, unless safeguarding or legal reasons require longer retention.
DBS certificate informationCertificate numbers and check details only, kept in line with DBS requirements. Copies should not normally be kept longer than necessary.
Financial recordsAt least 6 years, in line with accounting and tax requirements.
Photograph and video consent formsFor as long as the image or video is used, then reviewed and deleted when no longer needed.
Complaints recordsUp to 6 years after closure, or longer if safeguarding, legal or regulatory issues require it.

Where possible, personal information should be anonymised or pseudonymised when used for evaluation, reporting or learning.

Individual rights

People have rights over their personal information. These may include the right to:

  • be informed about how their information is used
  • access their personal information
  • ask for inaccurate information to be corrected
  • ask for information to be deleted in certain circumstances
  • ask for processing to be restricted in certain circumstances
  • object to certain processing
  • data portability in certain circumstances
  • challenge automated decisions where relevant
  • Requests relating to personal information should be sent to the Board of Directors or the appointed Data Protection Lead once confirmed. Requests should be handled within the legal timeframe, normally one month. Where a request is complex, the Organisation may extend the response period in line with data protection law.

The Organisation may need to verify identity before responding to a request. It may also need to withhold some information where disclosure would affect safeguarding, another person’s rights, legal privilege, investigations or other lawful exemptions.

Subject access requests

A subject access request is a request by an individual for a copy of their personal information. Requests do not have to use formal wording. Any staff member, volunteer, practitioner, advisor or director who receives a request must pass it to the Board of Directors as soon as possible.

When handling a subject access request, the Organisation will:

  • confirm the identity of the person making the request where necessary
  • clarify the scope of the request where needed
  • search relevant records
  • consider whether any exemptions apply
  • protect the rights and information of other people
  • respond within the required timeframe
  • keep a record of the request and response

Data breaches

A personal data breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information.

Examples may include:

  • sending sensitive information to the wrong person
  • losing a phone, laptop or paper file containing personal information
  • unauthorised access to records
  • posting an image of a child without consent where this creates risk
  • sharing safeguarding information in the wrong group chat
  • cyber attack, hacking or malware
  • loss of attendance sheets or consent forms
  • Any suspected or actual breach must be reported immediately to the Board of Directors and, where safeguarding information is involved, to the Designated Safeguarding Lead, Phillip Chackochen.

The Organisation will assess the breach, contain the risk, record what happened, decide whether the Information Commissioner’s Office must be notified, and decide whether affected individuals must be informed. Where a report to the ICO is required, this should be done within 72 hours of becoming aware of the breach, where feasible.

Direct marketing, newsletters and communications

Street Lights Collective CIC may send newsletters, updates, invitations or information about programmes where it has a lawful basis to do so.

People should be able to opt out of non essential communications. The Organisation will not send direct marketing to children or young people without careful consideration, appropriate consent where required, and safeguarding consideration.

Data protection by design

Street Lights Collective CIC will consider data protection at the start of new programmes, partnerships, systems and projects. This means asking:

  • what information will be collected
  • why the information is needed
  • what lawful basis applies
  • who will have access
  • how the information will be stored
  • whether children or vulnerable people are involved
  • whether sensitive information is involved
  • whether information will be shared
  • how long information will be kept
  • what risks exist and how they will be reduced
  • Where a programme or activity is likely to create higher risk to people’s rights, freedoms, safety or privacy, the Organisation should complete a Data Protection Impact Assessment before the activity begins.

Data Protection Impact Assessments

A Data Protection Impact Assessment, known as a DPIA, helps the Organisation identify and reduce privacy risks before starting higher risk processing.

A DPIA should be considered where Street Lights Collective CIC plans to:

  • process large amounts of sensitive information
  • use new digital systems to manage participant data
  • share data regularly with multiple partners
  • use photographs, video or online platforms involving young people
  • process information relating to safeguarding, exploitation, violence or criminal risk
  • track outcomes over time across programmes
  • carry out work involving vulnerable children, families or adults at risk

Training and awareness

All directors, staff, sessional workers, practitioners and volunteers must understand their data protection responsibilities.

Training and induction should cover:

  • confidentiality
  • secure record keeping
  • safe use of email and messaging
  • safeguarding information sharing
  • photography and consent
  • data breach reporting
  • subject access requests
  • retention and deletion
  • ethical storytelling
  • contextual safeguarding and privacy risks

Roles and responsibilities

RoleResponsibility
Board of DirectorsOverall accountability for data protection compliance, governance, risk and policy approval.
Andrew FullerDirector with strategic responsibility for ensuring that data protection supports the mission, safeguarding and public accountability of the Organisation.
Mark Anthony MalcolmDirector with responsibility for supporting programme delivery, safe practice and operational accountability.
Phillip ChackochenDesignated Safeguarding Lead. Responsible for safeguarding related information, referrals and escalation.
Marisa FergusonFinance and Compliance Lead. Supports secure financial records, compliance records and funding documentation.
Staff, practitioners and volunteersResponsible for following this policy, keeping information secure and reporting concerns promptly.
Partners and advisorsResponsible for handling any information shared with them lawfully, securely and in line with agreed arrangements.

Data processors and third party systems

Street Lights Collective CIC may use third party systems or providers such as cloud storage, email, website platforms, finance software, event platforms, survey tools or document storage services.

Where a third party processes personal data on behalf of the Organisation, the Organisation should ensure that appropriate safeguards and contractual arrangements are in place. The Organisation should consider security, access controls, location of data, retention, deletion and breach reporting arrangements.

International transfers

Street Lights Collective CIC will not intentionally transfer personal information outside the United Kingdom unless appropriate safeguards are in place and the transfer is lawful. Some digital platforms may store or process data outside the United Kingdom. Where this applies, the Organisation will take reasonable steps to ensure appropriate protections are in place.

Complaints

Anyone who is concerned about how Street Lights Collective CIC has handled their personal information may raise a complaint with the Organisation.

Complaints should be handled fairly, promptly and confidentially. The Organisation will investigate concerns and take corrective action where required.

Individuals also have the right to complain to the Information Commissioner’s Office if they are unhappy with how their personal information has been handled.

Policy review

This policy shall be reviewed annually by the Board of Directors, or sooner if there are changes in law, guidance, organisational activity, data systems, safeguarding risk or delivery arrangements.

The review should consider:

  • changes in UK data protection law or ICO guidance
  • changes in Street Lights programmes or partnerships
  • learning from breaches or near misses
  • safeguarding learning
  • feedback from staff, volunteers, young people, families or partners
  • new technology or systems used by the Organisation

Approval and signatures

This Data Protection Policy was approved by the Board of Directors of Street Lights Collective CIC.

NameRoleSignatureDate
Andrew FullerDirector
Mark Anthony MalcolmDirector
Phillip ChackochenDesignated Safeguarding Lead
Marisa FergusonFinance and Compliance Lead

Related policies and documents

This policy should be read alongside:

  • Safeguarding and Child Protection Policy
  • Equality, Diversity and Inclusion Policy
  • Constitution
  • Governing Document
  • Leadership and Advisory Register
  • Complaints Policy once adopted
  • Health and Safety Policy once adopted
  • Risk Assessment documents
  • Consent forms and referral forms

Practical data protection checklist

Before collecting, using or sharing personal information, staff and representatives should ask:

  • Do we need this information?
  • Have we explained why we are collecting it?
  • Do we have a lawful basis?
  • Is the information accurate?
  • Who needs access?
  • How will it be stored safely?
  • How long will it be kept?
  • Could sharing it place someone at risk?
  • Does the DSL need to be involved?
  • Have we recorded the decision properly?

Street Lights Collective CIC

Presence. Power. Purpose.

Our full policy suite is available on request as part of your due diligence.

Request documentation