GDPR & Data Protection Policy

July 2026

LC Policy #13

This policy sets out how the organisation collects, stores, processes, shares, and protects personal data in accordance with the UK GDPR (General Data Protection Regulations) and Data Protection Act 2018.  Little Crumpets handle sensitive information about children, families, and staff, and are committed to ensuring all data is processed lawfully, fairly, and securely.  Little Crumpets Ltd is registered with the Information Commissioner’s Office (ICO) Registration reference: ZB193548 and is aware of the responsibilities under GDPR.


This policy ensures:

  • Compliance with UK GDPR and the Data Protection Act 2018

  • Safe handling of children’s personal and sensitive data

  • Clear procedures for staff when processing information

  • Secure digital and physical storage of records

  • Transparent communication with parents and carers

  • Protection of data during wraparound routines (drop-off, pick-up, extended hours)


This policy applies to:

  • All staff

  • Volunteers

  • Students

  • Contractors

  • Anyone handling personal data on behalf of the organisation


It covers all data formats:

  • Paper records

  • Digital files

  • Emails

  • Messaging systems

  • Photographs and video

  • Observations and safeguarding notes


Types of Data We Process

We process:

  • Child personal details (name, DOB, address)

  • Parent/carer contact details

  • Medical and allergy information

  • SEND information

  • Attendance records

  • Behaviour and incident reports

  • Safeguarding records (CSR, chronology, referrals)

  • Staff employment and DBS information

  • Payment and booking data


Some of this is special category data, requiring enhanced protection.


Lawful Basis for Processing

We process data under the following lawful bases:

  • Public Task – delivering childcare and safeguarding duties

  • Legal Obligation – complying with safeguarding, Ofsted, and employment law

  • Vital Interests – protecting children in emergencies

  • Contract – managing bookings and payments

  • Consent – for optional activities such as photos or marketing

Safeguarding information is never dependent on consent.


Data Collection

We collect data through:

  • Registration forms

  • Medical forms

  • Safeguarding disclosures

  • Incident reports

  • Staff recruitment documents

  • Digital booking systems


Parents are informed about how their data is used at the point of collection.


Data Storage & Security

A. Physical Records

  • Stored in locked cabinets

  • Access restricted to authorised staff

  • Safeguarding files stored separately


B. Digital Records

  • Password-protected systems

  • Encrypted storage where possible

  • Access limited to staff on a need-to-know basis

  • Regular backups


C. Wraparound-Specific Security

  • Devices used during extended hours must be locked when unattended

  • Registers and medical lists must not be left visible during busy transitions

  • Staff must avoid discussing sensitive information in public areas


Data Sharing

We share data only when necessary and lawful.

Shared With:

  • Schools

  • Local Authority Children’s Services

  • Police

  • Health professionals

  • Ofsted (upon request)

  • Payment processors (for bookings)


Safeguarding Exception

Information may be shared without consent if a child is at risk of harm.


Retention & Disposal

We follow statutory retention periods:

  • Safeguarding records: until the child is 25

  • Incident forms: 3–5 years

  • Staff records: 6 years after employment ends

  • Registers: 3 years

  • Medical forms: current year + 1


Data is disposed of securely:

  • Shredding for paper

  • Permanent deletion for digital files


Subject Access Requests (SARs)

Parents, carers, and staff have the right to:

  • Request access to their data

  • Request corrections

  • Request deletion (where lawful)

  • Request restriction of processing


We respond within one month.


Safeguarding records may be withheld if disclosure could cause harm.


Data Breaches

A data breach includes:

  • Loss of records

  • Unauthorised access

  • Accidental disclosure

  • Cyber incidents


Response Procedure

  • Report immediately to the Manager/DSL

  • Assess risk to individuals

  • Notify affected parties if required

  • Report serious breaches to the ICO within 72 hours


Staff Responsibilities

Staff must:

  • Follow this policy at all times

  • Complete GDPR training

  • Use secure systems

  • Report breaches immediately

  • Avoid using personal devices for childcare data

  • Keep conversations professional and confidential


Photography & Digital Media

We obtain explicit consent for:

  • Photos

  • Videos

  • Social media posts


Safeguarding images (injuries, evidence) are processed under legal obligation.


Data Protection Officer (DPO)

Our DPO (or responsible person) oversees:

  • GDPR compliance

  • Data audits

  • Breach management

  • Staff training

Name: Clare Raffet 

Contact:07958 262295


This policy works alongside Confidentiality Policy, Safeguarding Policy, Allegations Against Staff Policy, Safer Recruitment Policy and Internet Safety Policy.


This policy will be reviewed annually or sooner if legislation changes, Ofsted guidance changes or a data breach occurs.


Previous
Previous

Healthy Eating Policy

Next
Next

Food Safety Policy