top of page

Data Protection and Confidentiality Policy

Organisation: P+S Care and Support Services Limited
Lead Responsible / Data Protection Officer (DPO): Cheryl Sharp, Founder & Director

1. Policy Statement

P+S Care and Support Services is committed to protecting the privacy and confidentiality of all children, young people (CYP), families, and staff. We comply fully with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018, ensuring that personal data is processed lawfully, fairly, and securely at all times.

We recognise that the nature of our work involves handling sensitive information and that maintaining confidentiality is essential to safeguarding children, young people, and families, as well as upholding trust in our services.

2. Data Protection Officer (DPO)

  • Cheryl Sharp, Founder & Director, is the appointed Data Protection Officer.

  • Responsibilities:

    • Ensuring organisational compliance with GDPR and Data Protection Act 2018.

Policy Created January 2025

Policy Reviewed January 2026

  • Acting as the point of contact with the Information Commissioner’s Office (ICO).

  • Overseeing staff training in data protection and confidentiality.

  • Monitoring data handling, storage, and retention processes.

  • Investigating and reporting data breaches in line with ICO requirements.

  • Training: The DPO undertakes regular GDPR and data protection training to maintain up-to-date knowledge of legislation and best practice.

ICO Registration Number: ZB939412

3. Principles of GDPR

P+S Care and Support Services adheres to the seven key principles of GDPR:

  1. Lawfulness, Fairness, and Transparency – Data is collected and processed lawfully and individuals are informed about how their data is used.

  2. Purpose Limitation – Data is collected for specified, explicit, and legitimate purposes only.

  3. Data Minimisation – Only data necessary for service delivery is collected and retained.

  4. Accuracy – Personal data is accurate and kept up to date.

  5. Storage Limitation – Data is retained only for as long as necessary, in line with retention schedules.

  6. Integrity and Confidentiality – Data is processed securely to prevent unauthorised access, loss, or damage.

  7. Accountability – We take responsibility for how we process and protect personal data.

4. Definition of Personal Data

Personal data is any information that identifies or could identify a living individual. This includes but is not limited to:

  • Names, addresses, and contact details.

  • Date of birth.

  • Family and social care records.

  • Health and education records.

  • Safeguarding and case notes.

5. Staff Responsibilities

All staff and volunteers must:

  • Complete GDPR and confidentiality training during induction and through annual refreshers.

  • Handle personal data confidentially and only share information on a strict need-to-know basis.

  • Use secure systems for recording, storing, and sharing information (e.g., encrypted emails, password-protected files).

  • Report any suspected data breaches immediately to the DPO.

  • Follow retention and disposal procedures, ensuring records are securely destroyed when no longer required.

6. Data Processing, Storage, and Management

  • Electronic Data: Stored securely on encrypted systems with role-based access.

  • Paper Records: Stored in locked cabinets in secure offices, with restricted access.

  • Sharing Data: Information is only shared with authorised agencies (e.g., Local Authorities, safeguarding partners) in line with safeguarding duties, lawful bases for processing, or with consent where required.

  • Retention: Data retention schedules align with statutory guidance, ensuring personal data is not held longer than necessary.

7. Data Breach Procedures

  • All suspected breaches must be reported to the DPO immediately.

  • The DPO will investigate, record, and assess the breach.

  • If the breach poses a risk to individuals’ rights or freedoms, the DPO will notify the ICO within 72 hours and affected individuals as required.

  • Lessons learned from breaches will be used to strengthen systems and prevent recurrence.

8. Confidentiality

  • Confidential information is never shared outside of lawful, safeguarding, or contractual requirements.

  • Staff are reminded that breaches of confidentiality are treated as disciplinary matters and may result in dismissal.

  • Confidentiality extends beyond employment—former staff remain bound by this duty.

9. Monitoring and Review

This policy will be reviewed annually by Cheryl Sharp (DPO) to ensure compliance with legislation and to incorporate any regulatory changes.

bottom of page