GDPR & Data Protection Policy
July 2026
LC Policy #13
This policy sets out how the organisation collects, stores, processes, shares, and protects personal data in accordance with the UK GDPR (General Data Protection Regulations) and Data Protection Act 2018. Little Crumpets handle sensitive information about children, families, and staff, and are committed to ensuring all data is processed lawfully, fairly, and securely. Little Crumpets Ltd is registered with the Information Commissioner’s Office (ICO) Registration reference: ZB193548 and is aware of the responsibilities under GDPR.
This policy ensures:
Compliance with UK GDPR and the Data Protection Act 2018
Safe handling of children’s personal and sensitive data
Clear procedures for staff when processing information
Secure digital and physical storage of records
Transparent communication with parents and carers
Protection of data during wraparound routines (drop-off, pick-up, extended hours)
This policy applies to:
All staff
Volunteers
Students
Contractors
Anyone handling personal data on behalf of the organisation
It covers all data formats:
Paper records
Digital files
Emails
Messaging systems
Photographs and video
Observations and safeguarding notes
Types of Data We Process
We process:
Child personal details (name, DOB, address)
Parent/carer contact details
Medical and allergy information
SEND information
Attendance records
Behaviour and incident reports
Safeguarding records (CSR, chronology, referrals)
Staff employment and DBS information
Payment and booking data
Some of this is special category data, requiring enhanced protection.
Lawful Basis for Processing
We process data under the following lawful bases:
Public Task – delivering childcare and safeguarding duties
Legal Obligation – complying with safeguarding, Ofsted, and employment law
Vital Interests – protecting children in emergencies
Contract – managing bookings and payments
Consent – for optional activities such as photos or marketing
Safeguarding information is never dependent on consent.
Data Collection
We collect data through:
Registration forms
Medical forms
Safeguarding disclosures
Incident reports
Staff recruitment documents
Digital booking systems
Parents are informed about how their data is used at the point of collection.
Data Storage & Security
A. Physical Records
Stored in locked cabinets
Access restricted to authorised staff
Safeguarding files stored separately
B. Digital Records
Password-protected systems
Encrypted storage where possible
Access limited to staff on a need-to-know basis
Regular backups
C. Wraparound-Specific Security
Devices used during extended hours must be locked when unattended
Registers and medical lists must not be left visible during busy transitions
Staff must avoid discussing sensitive information in public areas
Data Sharing
We share data only when necessary and lawful.
Shared With:
Schools
Local Authority Children’s Services
Police
Health professionals
Ofsted (upon request)
Payment processors (for bookings)
Safeguarding Exception
Information may be shared without consent if a child is at risk of harm.
Retention & Disposal
We follow statutory retention periods:
Safeguarding records: until the child is 25
Incident forms: 3–5 years
Staff records: 6 years after employment ends
Registers: 3 years
Medical forms: current year + 1
Data is disposed of securely:
Shredding for paper
Permanent deletion for digital files
Subject Access Requests (SARs)
Parents, carers, and staff have the right to:
Request access to their data
Request corrections
Request deletion (where lawful)
Request restriction of processing
We respond within one month.
Safeguarding records may be withheld if disclosure could cause harm.
Data Breaches
A data breach includes:
Loss of records
Unauthorised access
Accidental disclosure
Cyber incidents
Response Procedure
Report immediately to the Manager/DSL
Assess risk to individuals
Notify affected parties if required
Report serious breaches to the ICO within 72 hours
Staff Responsibilities
Staff must:
Follow this policy at all times
Complete GDPR training
Use secure systems
Report breaches immediately
Avoid using personal devices for childcare data
Keep conversations professional and confidential
Photography & Digital Media
We obtain explicit consent for:
Photos
Videos
Social media posts
Safeguarding images (injuries, evidence) are processed under legal obligation.
Data Protection Officer (DPO)
Our DPO (or responsible person) oversees:
GDPR compliance
Data audits
Breach management
Staff training
Name: Clare Raffet
Contact:07958 262295
This policy works alongside Confidentiality Policy, Safeguarding Policy, Allegations Against Staff Policy, Safer Recruitment Policy and Internet Safety Policy.
This policy will be reviewed annually or sooner if legislation changes, Ofsted guidance changes or a data breach occurs.