Data Protection & Privacy Policy
Document control | |
|---|---|
Policy reference | AU-POL-05 |
Version | 1.0 |
Approved by | Board of Directors, Apex Up CIC |
Date adopted | 4 June 2026 |
Last reviewed | 4 June 2026 |
Next review due | 4 June 2027 (or sooner if legislation or guidance changes) |
Policy owner | Director (Data Protection point of contact) |
Applies to | All directors, staff, sessional coaches, volunteers, students and anyone acting on behalf of Apex Up CIC |
Apex Up CIC Data Protection & Privacy Policy
1 Policy statement
Apex Up CIC collects personal information about the children, young people, families, staff and volunteers we work with. We are committed to handling this information lawfully, fairly and securely, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We treat people’s privacy with respect and only use their information for the reasons we have explained to them.
2 Purpose and scope
This policy explains what information we collect, why, how we keep it safe, and the rights people have. It applies to everyone who handles personal information on our behalf.
3 The principles we follow
We make sure personal information is:
- used lawfully, fairly and transparently;
- collected only for clear, specified purposes;
- limited to what we actually need;
- accurate and kept up to date;
- kept no longer than necessary; and
- kept secure, protected against loss, damage or unauthorised access. 4 What we collect and why
We collect information such as names and contact details, dates of birth, emergency contacts, medical and dietary information, and consent forms, so that we can run our sessions safely, keep children safe, contact families, and meet the requirements of funders such as the HAF programme. We collect this on the basis of consent, our legitimate interests in running safe activities, and our legal obligations, including safeguarding.
5 Children’s and special category data
Because we work mainly with children, we take particular care with their information. We obtain consent from a parent or carer where appropriate, keep medical and safeguarding information secure and separate, and share it only with those who need it to keep a child safe or well.
6 Keeping information secure
We store information securely, whether on paper or electronically, using locked storage, password protection and access limited to those who need it. We do not leave registers or personal information unattended, and we make sure devices used for our work are protected. We keep information only as long as we need it, following a retention schedule, and dispose of it securely.
7 Sharing information
We do not sell personal information or share it unnecessarily. We share information with funders, partners or authorities only where there is a clear and lawful reason. Where a child
AU-POL-05 | Version 1.0 Page 2 of 4
Apex Up CIC Data Protection & Privacy Policy
or adult at risk may be at risk of harm, the duty to keep them safe overrides confidentiality, and we will share relevant information promptly with safeguarding agencies.
8 People’s rights
People have the right to ask what information we hold about them, to have inaccurate information corrected, to ask us to delete information where appropriate, and to object to certain uses. Anyone wishing to exercise these rights can contact the Director. We will respond within one month.
9 Data breaches
If personal information is lost, stolen or shared in error, staff and volunteers must tell the Director immediately. We will act quickly to contain the breach, assess the risk, and — where the breach is likely to harm the people involved — report it to the Information Commissioner’s Office (ICO) within 72 hours and inform those affected.
10 Responsibilities and review
The Director acts as our point of contact for data protection. All staff and volunteers are responsible for following this policy. We review it at least annually and after any breach or change in the law.
11 Key contact
Contact | Details |
Data protection point of contact | Muhammed Zahir — mz@apexup.org — 07706 803260 |
Information Commissioner’s Office (ICO) | 0303 123 1113 — ico.org.uk |
AU-POL-05 | Version 1.0 Page 3 of 4
Apex Up CIC Data Protection & Privacy Policy
Approval and adoption
This Data Protection & Privacy Policy has been approved and adopted by the Board of Directors of Apex Up CIC. It will be reviewed at least every twelve months, and sooner if there is a change in legislation, national or local guidance, or following any relevant incident or learning.
Policy reference | AU-POL-05 |
Version | 1.0 |
Date adopted | 4 June 2026 |
Next review due | 4 June 2027 |
Signed on behalf of the Board of Directors of Apex Up CIC:
Muhammed Zahir
Director, Apex Up CIC
Date: 4 June 2026