Data Protection Policy

PEEK is committed to protection and respecting our team members and children, young people and families personal data. PEEK complies fully with the necessary requirements under the Data Protection Act 2018 and the EU General Data Protection Regulation (“GDPR”).  

This policy sets out how PEEK handles the personal data of our participants and families, team members, board trustees, volunteers, stakeholders, funders, and other third parties.

Protecting the confidentiality of personal data is a critical responsibility that we take seriously at all times. If PEEK fails to comply with the relevant data protection law, then we may be subject to substantial sanctions, including potential fines of up to 4% of annual turnover, as well as significant reputational damage. 

This policy applies to all team members, including temporary and sessional team members, volunteers and trustees. All should read, understand and comply with this policy.  This policy sets out what PEEK expects from you to ensure that PEEK complies with the relevant data protection legislation.  Any breach of this policy may result in disciplinary action. 

If you require further information about this policy, please contact us.

Appendix 1

Data Protection Breach

Practical Steps

  • Do contact the Head of Operations with any data protection/privacy concerns, issues or queries.

  • Do not ignore correspondence from individuals which relates to, or which may relate to personal data.

  • Do notify the Head of Operations immediately if a communication is identified as being a request to exercise data protection rights.

  • Do remain vigilant and check whether personal data is being stored securely. ALL Child Protection paperwork should be place in a sealed envelope and passed to the Child Protection Officer (Head of People and Programmes).

  • Do not copy data or store personal data outside of the PEEK systems unless this is strictly necessary.

  • Do ensure any portable hardware you use for work purposed is password protected and the contents are encrypted.

  • Do ensure personal data sent via your PEEK email, or otherwise, is protected.

  • Do ensure any personal data extracted from the systems and stored locally is stored securely and subject to password protection and encryption.

  • Do not discuss confidential matters or details about particular individuals unless this is necessary for the purpose of your role.

  • Do remain vigilant and notify your line manager on discovery of anything suspicious/unusual regarding the way in which their systems are functioning.

  • Do not ignore any incidents/suspected incidents.

  • Do implement the processes set out in the data breach policy.

  • Do not store PEEK Participants personal data in personal folders unless strictly necessary.

  • Do regularly delete personal data from your personal folders, if you are unsure what can be deleted contact the Head of Operations.

  • Do check PEEK forms are FULLY completed by parents/carers before it is input to the systems.

  • Do inform Head of Operations if any of your own personal data is out of date or inaccurate

  • Do ensure all PEEK paperwork is securely stored off site through lockable (Padlock or coded) boxes/rucksacks.