Course 12 – Data Protection & GDPR
DASC Standard
Every piece of personal information belongs to a real person.
Parents trust DASC to protect their family's information with the same care that we protect their children.
Good data protection is good safeguarding.
Introduction
Every day, DASC collects, stores and uses information about:
- children;
- parents and carers;
- staff;
- volunteers;
- visitors;
- contractors.
Some of this information is highly sensitive.
Everyone who works at DASC shares responsibility for protecting it.
Data protection is not simply an administrative requirement—it is a legal duty and an essential safeguarding responsibility.
Learning Outcomes
After completing this course you will be able to:
- explain the purpose of UK GDPR;
- identify personal and special category data;
- understand the lawful principles of data protection;
- handle records securely;
- recognise and report data breaches;
- understand individuals' rights;
- apply GDPR confidently in everyday practice.
What is GDPR?
The UK General Data Protection Regulation (UK GDPR) sets out how organisations must collect, use, store and protect personal information.
Its purpose is to ensure that information is:
- handled fairly;
- kept secure;
- used appropriately;
- retained only as long as necessary;
- protected from misuse.
Every member of staff contributes to GDPR compliance.
What is Personal Data?
Personal data is any information that identifies, or could identify, a living person.
Examples include:
- names;
- addresses;
- email addresses;
- telephone numbers;
- attendance records;
- photographs;
- CCTV images;
- IP addresses;
- payroll information.
Personal data exists in both paper and electronic formats.
Special Category Data
Some information requires additional protection.
Examples include:
- health information;
- disabilities;
- ethnicity;
- religious beliefs;
- biometric information;
- safeguarding records.
This information should only be accessed and shared where there is a legitimate reason to do so.
DASC Best Practice
Always ask yourself:
"Do I genuinely need this information to perform my role?"
If the answer is no—
Do not access it.
Ofsted Inspection Insight
Inspectors increasingly expect strong information governance because safeguarding depends upon accurate, secure and confidential records.
Good GDPR practice protects both children and the organisation.
Reflection
Reflect before continuing.
- What personal information do you use every day?
- Which information requires the highest level of protection?
- Why is data protection part of safeguarding?
- How does protecting information strengthens parents' trust?
Every secure record demonstrates professionalism and respect.
The Seven Principles of UK GDPR
The UK GDPR is built around seven key principles.
These principles guide every decision DASC makes when handling personal information.
Understanding these principles helps staff make safe, lawful and professional decisions every day.
The Seven Principles
| Principle | What it Means |
|---|---|
| Lawfulness, Fairness and Transparency | Handle information legally, fairly and openly |
| Purpose Limitation | Use information only for the reason it was collected |
| Data Minimisation | Collect only the information that is genuinely needed |
| Accuracy | Keep information correct and up to date |
| Storage Limitation | Keep information only for as long as necessary |
| Integrity and Confidentiality | Protect information from unauthorised access, loss or damage |
| Accountability | Be able to demonstrate compliance with GDPR |
These principles apply to everyone working at DASC.
DASC Standard
Before collecting any information, ask yourself:
- Why do we need it?
- Who needs access?
- How will we protect it?
- When should it be deleted?
Good GDPR begins before information is collected.
Lawfulness, Fairness and Transparency
People have the right to know:
- what information is collected;
- why it is collected;
- how it will be used;
- who it may be shared with;
- how long it will be kept.
DASC communicates this through privacy notices and clear communication.
Information should never be collected secretly unless there is a lawful safeguarding reason.
Purpose Limitation
Information should only be used for the purpose for which it was collected.
For example:
A parent's telephone number collected for emergency contact purposes should not later be used for unrelated marketing without an appropriate lawful basis.
Purpose matters.
Data Minimisation
Collect only the information that is genuinely necessary.
Avoid collecting information:
- "just in case";
- because it "might be useful";
- without a clear purpose.
The less unnecessary information stored, the lower the risk if something goes wrong.
DASC Best Practice
If you don't need it—
Don't collect it.
If you no longer need it—
Don't keep it.
Accuracy
Incorrect information can create safeguarding risks.
Staff should:
- update records promptly;
- correct mistakes;
- verify important information;
- encourage parents to report changes.
Examples include:
- emergency contacts;
- medical information;
- authorised collectors;
- allergies.
Accurate information protects children.
Storage Limitation
Information should not be kept forever.
Records should be:
- reviewed regularly;
- retained according to DASC retention schedules;
- securely destroyed when no longer required.
Deleting information at the correct time is just as important as storing it securely.
Integrity and Confidentiality
Information must be protected against:
- unauthorised access;
- accidental loss;
- theft;
- alteration;
- destruction.
Protection includes:
- passwords;
- locked cabinets;
- encryption;
- secure systems;
- staff confidentiality.
Safeguarding and information security work together.
Accountability
DASC must be able to demonstrate compliance.
This includes:
- policies;
- procedures;
- staff training;
- audits;
- records of processing;
- breach reporting.
Everyone contributes to accountability through their daily practice.
Ofsted Inspection Insight
Inspectors and regulators expect organisations to demonstrate that data protection is embedded throughout everyday practice rather than existing only within written policies.
Good habits provide the strongest evidence of compliance.
Practice Scenario – Collecting Extra Information
Registration Form
Practice Scenario – Outdated Medical Information
Emergency Contact Review
Manager Coaching Notes
Managers should ensure staff:
- understand the seven GDPR principles;
- review records regularly;
- minimise unnecessary data collection;
- maintain accurate information;
- follow retention schedules;
- understand accountability.
Strong GDPR compliance is built through consistent everyday practice.
Reflection
Reflect on today's learning.
- Could you explain each of the seven GDPR principles?
- Why is collecting less information often safer?
- How does accurate information support safeguarding?
- What role do you play in GDPR accountability?
The seven principles provide the foundation for every responsible decision about personal information at DASC.
Lawful Bases for Processing Personal Data
DASC cannot collect or use personal information simply because it might be useful.
Every use of personal data must have a lawful basis under UK GDPR.
Understanding these lawful bases helps ensure information is used fairly, legally and transparently.
What is a Lawful Basis?
A lawful basis is the legal reason that allows DASC to collect or use personal information.
Different situations require different lawful bases.
The lawful basis should be identified before information is processed.
DASC Standard
Always know why you are collecting information.
If there is no lawful reason to collect it—
Do not collect it.
The Six Lawful Bases
UK GDPR identifies six lawful bases.
| Lawful Basis | Example |
|---|---|
| Consent | Parents choose to receive optional newsletters |
| Contract | Processing staff payroll information |
| Legal Obligation | Maintaining records required by law |
| Vital Interests | Sharing emergency medical information to protect life |
| Public Task | Activities carried out under official authority (where applicable) |
| Legitimate Interests | Administrative activities that do not override individuals' rights |
Not every lawful basis applies equally to every organisation or situation.
Consent
Consent must be:
- freely given;
- specific;
- informed;
- unambiguous;
- capable of being withdrawn.
Silence or pre-ticked boxes do not normally amount to valid consent.
Parents should understand exactly what they are agreeing to.
DASC Best Practice
Consent should be a genuine choice.
If someone cannot easily say "no", it may not be valid consent.
Legal Obligation
Sometimes DASC must process information because the law requires it.
Examples include:
- safeguarding records;
- employment records;
- accident reporting;
- statutory childcare requirements.
In these situations, consent is usually not the lawful basis.
The legal obligation itself provides the authority.
Vital Interests
Vital interests apply where information is needed to protect someone's life.
Examples include:
- sharing allergy information with emergency services;
- providing medical information during an emergency;
- informing healthcare professionals about serious risks.
Protecting life takes priority.
Legitimate Interests
Legitimate interests may apply where DASC has a genuine organisational need that does not override an individual's rights.
Examples might include:
- maintaining security systems;
- preventing fraud;
- managing day-to-day administration.
Legitimate interests require careful balancing.
Special Category Data
Special category data usually requires:
- an appropriate lawful basis; and
- an additional legal condition.
Examples include:
- medical information;
- disabilities;
- safeguarding concerns;
- ethnicity where lawfully required.
These records require additional protection because they are more sensitive.
Choosing the Correct Basis
The lawful basis should be determined before information is collected.
It should not be changed later simply because another option appears more convenient.
Good planning supports good compliance.
Ofsted Inspection Insight
Inspectors and regulators expect organisations to understand why information is collected and how it supports children's welfare.
Clear purposes demonstrate good governance and accountability.
Practice Scenario – Newsletter Signup
Optional Emails
Practice Scenario – Emergency Medical Information
Allergic Reaction
Manager Coaching Notes
Managers should ensure staff:
- understand lawful bases;
- recognise when consent is appropriate;
- protect special category data;
- document processing activities;
- review privacy notices regularly;
- seek advice if unsure.
Understanding the lawful basis strengthens confidence in everyday GDPR decision-making.
Reflection
Reflect on today's learning.
- Could you explain the difference between consent and legal obligation?
- Why should the lawful basis be identified before collecting information?
- When might vital interests apply?
- How should special category data be protected?
Good GDPR compliance begins with understanding why information is being collected before deciding how it should be used.
Individual Rights Under UK GDPR
UK GDPR gives individuals important rights over their personal information.
These rights help ensure that organisations remain transparent, accountable and respectful when handling personal data.
At DASC, every member of staff should understand these rights and know how to respond appropriately if a request is received.
Why Individual Rights Matter
Parents, carers, staff and, where appropriate, children have the right to understand:
- what information is held about them;
- why it is being used;
- who it is shared with;
- how long it will be kept.
These rights strengthen trust and accountability.
DASC Standard
Personal information belongs to the individual.
DASC is responsible for protecting it—not owning it.
The Eight Individual Rights
Under UK GDPR, individuals have the following rights:
| Right | What it Means |
|---|---|
| Right to be Informed | To know how their information is collected and used |
| Right of Access | To request a copy of their personal information |
| Right to Rectification | To correct inaccurate or incomplete information |
| Right to Erasure | To request deletion in certain circumstances |
| Right to Restrict Processing | To limit how information is used in certain situations |
| Right to Data Portability | To obtain certain information in a reusable format |
| Right to Object | To object to certain types of processing |
| Rights Related to Automated Decision-Making | Protection from decisions made solely by automated systems in certain circumstances |
Not every right applies in every situation.
Some legal exemptions may apply.
The Right to be Informed
People should understand:
- what information DASC collects;
- why it is collected;
- how it is used;
- who receives it;
- how long it is retained;
- how to exercise their rights.
Privacy notices help meet this requirement.
Information should be written clearly and in language that people can understand.
The Right of Access
Individuals may request access to their own personal information.
This is commonly known as a Subject Access Request (SAR).
Examples include requests for:
- attendance records;
- accident reports;
- correspondence;
- registration information.
Requests should always be handled in accordance with DASC procedures.
DASC Best Practice
If someone requests personal information—
Do not promise immediate access.
Refer the request to the appropriate manager or Data Protection Lead.
Following the correct process protects everyone.
The Right to Rectification
If information is inaccurate or incomplete, individuals may ask for it to be corrected.
Examples include:
- incorrect addresses;
- outdated telephone numbers;
- inaccurate emergency contacts;
- incorrect spelling of names.
Accurate information supports effective safeguarding.
The Right to Erasure
Sometimes called the "Right to be Forgotten."
Individuals may request that certain personal information be deleted.
However, this right is not absolute.
DASC may need to retain information where:
- safeguarding responsibilities apply;
- legal obligations exist;
- records are required by law.
Staff should never delete records without following authorised procedures.
Restricting Processing
Individuals may ask DASC to temporarily limit how their information is used while concerns are investigated.
For example:
A parent disputes the accuracy of a record.
The information may need to remain available while the issue is reviewed.
Data Portability
In certain situations, individuals may request that their information be provided in a structured, commonly used electronic format.
This right usually applies only in specific circumstances.
Requests should always follow DASC procedures.
The Right to Object
Individuals may object to certain processing activities.
For example:
- direct marketing;
- some uses based on legitimate interests.
Requests should be referred to the appropriate manager for consideration.
Automated Decision-Making
DASC does not normally make significant decisions about children or staff using fully automated systems.
Where automated processes are used, appropriate safeguards should always be in place.
Human oversight remains important.
Ofsted Inspection Insight
Inspectors expect organisations to respect privacy while maintaining appropriate safeguarding records.
Strong GDPR compliance balances individual rights with legal safeguarding responsibilities.
Practice Scenario – Parent Requests Records
Can I Have Everything?
Practice Scenario – Incorrect Emergency Contact
Old Telephone Number
Manager Coaching Notes
Managers should ensure staff:
- understand individual rights;
- recognise Subject Access Requests;
- protect safeguarding records appropriately;
- update inaccurate information promptly;
- understand retention requirements;
- know when to seek specialist advice.
Respecting individual rights strengthens public trust and organisational accountability.
Reflection
Reflect on today's learning.
- Could you identify a Subject Access Request?
- Why is the Right to Erasure not always absolute?
- How does accurate information support safeguarding?
- What should you do if someone requests a copy of their records?
Protecting privacy means respecting people's rights while continuing to safeguard children effectively.
Storing, Sharing and Retaining Information
Collecting information is only one part of GDPR compliance.
Information must also be:
- stored securely;
- shared appropriately;
- retained for the correct length of time;
- disposed of safely.
Every stage of the information lifecycle should protect confidentiality and support safeguarding.
Secure Storage
Whether records are digital or paper-based, they must be protected against:
- unauthorised access;
- accidental loss;
- theft;
- damage;
- inappropriate disclosure.
Security measures may include:
- password protection;
- encryption;
- locked filing cabinets;
- restricted access;
- secure cloud systems.
Children's information should never be left unattended.
DASC Standard
If information is not being used—
Store it securely.
Security should become an everyday habit.
Paper Records
Paper records should:
- be stored in locked cabinets;
- only be accessed by authorised staff;
- never be left on desks overnight;
- be collected immediately from printers;
- be shredded securely when no longer required.
Printed documents deserve the same protection as electronic records.
Electronic Records
Electronic information should be:
- stored only within approved systems;
- protected by strong passwords;
- backed up where appropriate;
- encrypted where required;
- accessible only to authorised users.
Personal cloud storage or unauthorised applications should never be used for DASC records.
Sharing Information
Before sharing information, ask:
- Is sharing necessary?
- Who genuinely needs the information?
- What is the lawful basis?
- Am I sharing only the minimum required?
Sharing should always be proportionate.
DASC Best Practice
Share only what is needed.
Nothing more.
Nothing less.
Email Security
Before sending confidential information:
- check every recipient carefully;
- confirm attachments;
- remove unnecessary personal information;
- use secure systems where appropriate.
Take a moment before pressing Send.
Many data breaches result from simple typing mistakes.
Verbal Confidentiality
Information can also be disclosed through conversation.
Avoid discussing confidential matters:
- in reception areas;
- in corridors;
- on public transport;
- in cafés;
- at home with family or friends.
Professional confidentiality applies wherever you are.
Records Retention
Different records must be retained for different periods.
Retention schedules help ensure that information is:
- available when required;
- deleted when appropriate;
- managed consistently.
Keeping records longer than necessary increases unnecessary risk.
Always follow DASC's Records Retention Policy.
Secure Disposal
When information reaches the end of its retention period:
Paper records should be:
- cross-cut shredded;
- disposed of using confidential waste services where appropriate.
Electronic records should be:
- securely deleted;
- removed from backups in accordance with organisational procedures where applicable.
Deleting files by moving them to the recycle bin may not be sufficient.
Ofsted Inspection Insight
Inspectors expect confidential information to be secure whether they visit the office, observe staff working or review administrative processes.
Strong information governance reflects strong organisational leadership.
Practice Scenario – Printed Register
End of Session
Practice Scenario – Email Attachment
Wrong Recipient
Manager Coaching Notes
Managers should ensure:
- storage arrangements remain secure;
- access permissions are reviewed regularly;
- retention schedules are followed;
- confidential disposal procedures are understood;
- staff receive regular GDPR refresher training;
- information sharing is monitored appropriately.
Effective information management protects both safeguarding and organisational compliance.
Reflection
Reflect on today's learning.
- Are paper records always stored securely?
- Do you check recipients before sending confidential emails?
- Why is retaining information for too long a GDPR risk?
- How should confidential information be disposed of safely?
Every record should be protected throughout its entire lifecycle—from collection to secure disposal.
Personal Data Breaches
Even in well-managed organisations, mistakes can happen.
A personal data breach does not always result from malicious activity.
Many breaches occur because of simple human error.
The important thing is recognising the breach quickly, reporting it promptly and taking appropriate action.
What is a Personal Data Breach?
A personal data breach is a security incident that leads to the accidental or unlawful:
- destruction of personal data;
- loss of personal data;
- alteration of personal data;
- unauthorised disclosure of personal data;
- unauthorised access to personal data.
A breach may involve paper records, electronic systems or verbal disclosure.
DASC Standard
Mistakes must be reported—
not hidden.
Early reporting protects children, families and DASC.
Common Causes of Data Breaches
Examples include:
- sending emails to the wrong person;
- losing paperwork;
- leaving records unattended;
- discussing confidential information in public;
- losing laptops or mobile devices;
- weak passwords;
- phishing attacks;
- sharing information without authorisation.
Many breaches can be prevented through good everyday habits.
Examples of Data Breaches
Examples include:
- a safeguarding report emailed to the wrong parent;
- a printed register left in reception;
- an unlocked laptop displaying children's records;
- confidential paperwork found in general waste;
- photographs shared without appropriate authorisation.
Not every breach causes harm, but every breach should be assessed.
DASC Best Practice
If you think a breach might have happened—
Report it.
Never wait to see if the problem resolves itself.
Immediate Response
If a breach occurs:
- remain calm;
- contain the breach where possible;
- inform your manager immediately;
- follow DASC's Data Breach Procedure;
- record what happened accurately.
Do not attempt to hide mistakes.
Prompt action often reduces the impact significantly.
Reporting Internally
Managers may need to know:
- what happened;
- when it happened;
- who was affected;
- what information was involved;
- what immediate action has been taken.
Accurate information supports effective decision-making.
Learning from Breaches
Every breach should lead to learning.
Questions may include:
- Why did it happen?
- Could it happen again?
- Do procedures need improving?
- Is further staff training required?
The purpose is continuous improvement rather than blame.
The Information Commissioner's Office (ICO)
Some serious personal data breaches must be reported to the Information Commissioner's Office (ICO).
This decision is made by authorised managers or the Data Protection Lead.
Individual staff members should report concerns internally rather than contacting the ICO themselves unless instructed.
Supporting Trust
Parents trust DASC with highly sensitive information.
Responding openly and professionally to mistakes helps maintain that trust.
Honesty strengthens confidence.
Attempts to hide mistakes usually make situations worse.
Ofsted Inspection Insight
Inspectors and regulators understand that mistakes sometimes happen.
They are interested in whether organisations respond quickly, honestly and professionally while improving systems to reduce future risks.
Strong reporting cultures support both safeguarding and compliance.
Practice Scenario – Wrong Attachment
Accidental Email
Practice Scenario – Lost Notebook
Journey Home
Manager Coaching Notes
Managers should ensure:
- staff recognise personal data breaches;
- reporting procedures are understood;
- incidents are investigated fairly;
- lessons learned are implemented;
- breach records are maintained;
- refresher training is provided after significant incidents.
Strong organisations learn from mistakes rather than hiding them.
Reflection
Reflect on today's learning.
- Could you identify a personal data breach?
- Why is immediate reporting so important?
- What information should be included in a breach report?
- How can learning from mistakes improve GDPR compliance?
Protecting personal information is not about achieving perfection.
It is about responding professionally, learning continuously and maintaining the trust that families place in DASC.
End of Course Assessment
Instructions
Complete the assessment below.
A pass mark of 80% is required before the course can be marked as complete.
No questions provided.
Competency Declaration
Professional Competency & Compliance Declaration
Statutory standard: UK EYFS / KCSIE / Ofsted Framework
Related DASC Policies
Related Policies & Documents
References
Course References
Course Completion
Congratulations.
You have completed Course 12 – Data Protection & GDPR.
Every registration form, safeguarding record, attendance register and medical note represents information that families have entrusted to DASC.
Protecting that information is not simply about complying with the law—it is about demonstrating professionalism, safeguarding children and maintaining the confidence of parents and carers.
Remember the four principles of excellent information governance:
- Collect Only What You Need
- Protect Information Securely
- Share Responsibly
- Report Mistakes Immediately
Strong GDPR compliance is built through thousands of small, professional decisions made every day.
By protecting information with care, integrity and respect, you help create a culture where children, families and colleagues can trust DASC to safeguard both their wellbeing and their personal information.
References
Legislation
United Kingdom General Data Protection Regulation (UK GDPR) 2018. The Stationery Office. https://www.legislation.gov.uk/eur/2016/679/contents
View source ↗Data Protection Act 2018 2018. The National Archives. https://www.legislation.gov.uk/ukpga/2018/12/contents
View source ↗
Government Guidance
Department for Education (2025). Statutory Framework for the Early Years Foundation Stage (EYFS). Department for Education. https://www.gov.uk/government/publications/early-years-foundation-stage-framework--2
View source ↗Information Commissioner's Office (2024). Guide to Data Protection and the UK GDPR. Information Commissioner's Office. https://ico.org.uk/for-organisations/guide-to-data-protection/
View source ↗