Skip to main content
12
MandatoryGDPR & Data

Data Protection & GDPR

Mandatory training on UK GDPR, data protection principles, lawful bases, and secure record handling for DASC staff.

3h~26 min readall-staff, managersAnnualv1.0 · Updated 1 July 2026

Course 12 – Data Protection & GDPR

DASC Standard

Every piece of personal information belongs to a real person.

Parents trust DASC to protect their family's information with the same care that we protect their children.

Good data protection is good safeguarding.


Introduction

Every day, DASC collects, stores and uses information about:

  • children;
  • parents and carers;
  • staff;
  • volunteers;
  • visitors;
  • contractors.

Some of this information is highly sensitive.

Everyone who works at DASC shares responsibility for protecting it.

Data protection is not simply an administrative requirement—it is a legal duty and an essential safeguarding responsibility.


Learning Outcomes

After completing this course you will be able to:

  • explain the purpose of UK GDPR;
  • identify personal and special category data;
  • understand the lawful principles of data protection;
  • handle records securely;
  • recognise and report data breaches;
  • understand individuals' rights;
  • apply GDPR confidently in everyday practice.

What is GDPR?

The UK General Data Protection Regulation (UK GDPR) sets out how organisations must collect, use, store and protect personal information.

Its purpose is to ensure that information is:

  • handled fairly;
  • kept secure;
  • used appropriately;
  • retained only as long as necessary;
  • protected from misuse.

Every member of staff contributes to GDPR compliance.


What is Personal Data?

Personal data is any information that identifies, or could identify, a living person.

Examples include:

  • names;
  • addresses;
  • email addresses;
  • telephone numbers;
  • attendance records;
  • photographs;
  • CCTV images;
  • IP addresses;
  • payroll information.

Personal data exists in both paper and electronic formats.


Special Category Data

Some information requires additional protection.

Examples include:

  • health information;
  • disabilities;
  • ethnicity;
  • religious beliefs;
  • biometric information;
  • safeguarding records.

This information should only be accessed and shared where there is a legitimate reason to do so.


DASC Best Practice

Always ask yourself:

"Do I genuinely need this information to perform my role?"

If the answer is no—

Do not access it.


Ofsted Inspection Insight

Inspectors increasingly expect strong information governance because safeguarding depends upon accurate, secure and confidential records.

Good GDPR practice protects both children and the organisation.


Reflection

Reflect before continuing.

  • What personal information do you use every day?
  • Which information requires the highest level of protection?
  • Why is data protection part of safeguarding?
  • How does protecting information strengthens parents' trust?

Every secure record demonstrates professionalism and respect.


The Seven Principles of UK GDPR

The UK GDPR is built around seven key principles.

These principles guide every decision DASC makes when handling personal information.

Understanding these principles helps staff make safe, lawful and professional decisions every day.


The Seven Principles

PrincipleWhat it Means
Lawfulness, Fairness and TransparencyHandle information legally, fairly and openly
Purpose LimitationUse information only for the reason it was collected
Data MinimisationCollect only the information that is genuinely needed
AccuracyKeep information correct and up to date
Storage LimitationKeep information only for as long as necessary
Integrity and ConfidentialityProtect information from unauthorised access, loss or damage
AccountabilityBe able to demonstrate compliance with GDPR

These principles apply to everyone working at DASC.


DASC Standard

Before collecting any information, ask yourself:

  • Why do we need it?
  • Who needs access?
  • How will we protect it?
  • When should it be deleted?

Good GDPR begins before information is collected.


Lawfulness, Fairness and Transparency

People have the right to know:

  • what information is collected;
  • why it is collected;
  • how it will be used;
  • who it may be shared with;
  • how long it will be kept.

DASC communicates this through privacy notices and clear communication.

Information should never be collected secretly unless there is a lawful safeguarding reason.


Purpose Limitation

Information should only be used for the purpose for which it was collected.

For example:

A parent's telephone number collected for emergency contact purposes should not later be used for unrelated marketing without an appropriate lawful basis.

Purpose matters.


Data Minimisation

Collect only the information that is genuinely necessary.

Avoid collecting information:

  • "just in case";
  • because it "might be useful";
  • without a clear purpose.

The less unnecessary information stored, the lower the risk if something goes wrong.


DASC Best Practice

If you don't need it—

Don't collect it.

If you no longer need it—

Don't keep it.


Accuracy

Incorrect information can create safeguarding risks.

Staff should:

  • update records promptly;
  • correct mistakes;
  • verify important information;
  • encourage parents to report changes.

Examples include:

  • emergency contacts;
  • medical information;
  • authorised collectors;
  • allergies.

Accurate information protects children.


Storage Limitation

Information should not be kept forever.

Records should be:

  • reviewed regularly;
  • retained according to DASC retention schedules;
  • securely destroyed when no longer required.

Deleting information at the correct time is just as important as storing it securely.


Integrity and Confidentiality

Information must be protected against:

  • unauthorised access;
  • accidental loss;
  • theft;
  • alteration;
  • destruction.

Protection includes:

  • passwords;
  • locked cabinets;
  • encryption;
  • secure systems;
  • staff confidentiality.

Safeguarding and information security work together.


Accountability

DASC must be able to demonstrate compliance.

This includes:

  • policies;
  • procedures;
  • staff training;
  • audits;
  • records of processing;
  • breach reporting.

Everyone contributes to accountability through their daily practice.


Ofsted Inspection Insight

Inspectors and regulators expect organisations to demonstrate that data protection is embedded throughout everyday practice rather than existing only within written policies.

Good habits provide the strongest evidence of compliance.


Practice Scenario – Collecting Extra Information

Registration Form


Practice Scenario – Outdated Medical Information

Emergency Contact Review


Manager Coaching Notes

Managers should ensure staff:

  • understand the seven GDPR principles;
  • review records regularly;
  • minimise unnecessary data collection;
  • maintain accurate information;
  • follow retention schedules;
  • understand accountability.

Strong GDPR compliance is built through consistent everyday practice.


Reflection

Reflect on today's learning.

  • Could you explain each of the seven GDPR principles?
  • Why is collecting less information often safer?
  • How does accurate information support safeguarding?
  • What role do you play in GDPR accountability?

The seven principles provide the foundation for every responsible decision about personal information at DASC.


Lawful Bases for Processing Personal Data

DASC cannot collect or use personal information simply because it might be useful.

Every use of personal data must have a lawful basis under UK GDPR.

Understanding these lawful bases helps ensure information is used fairly, legally and transparently.


What is a Lawful Basis?

A lawful basis is the legal reason that allows DASC to collect or use personal information.

Different situations require different lawful bases.

The lawful basis should be identified before information is processed.


DASC Standard

Always know why you are collecting information.

If there is no lawful reason to collect it—

Do not collect it.


The Six Lawful Bases

UK GDPR identifies six lawful bases.

Lawful BasisExample
ConsentParents choose to receive optional newsletters
ContractProcessing staff payroll information
Legal ObligationMaintaining records required by law
Vital InterestsSharing emergency medical information to protect life
Public TaskActivities carried out under official authority (where applicable)
Legitimate InterestsAdministrative activities that do not override individuals' rights

Not every lawful basis applies equally to every organisation or situation.


Consent must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • capable of being withdrawn.

Silence or pre-ticked boxes do not normally amount to valid consent.

Parents should understand exactly what they are agreeing to.


DASC Best Practice

Consent should be a genuine choice.

If someone cannot easily say "no", it may not be valid consent.


Sometimes DASC must process information because the law requires it.

Examples include:

  • safeguarding records;
  • employment records;
  • accident reporting;
  • statutory childcare requirements.

In these situations, consent is usually not the lawful basis.

The legal obligation itself provides the authority.


Vital Interests

Vital interests apply where information is needed to protect someone's life.

Examples include:

  • sharing allergy information with emergency services;
  • providing medical information during an emergency;
  • informing healthcare professionals about serious risks.

Protecting life takes priority.


Legitimate Interests

Legitimate interests may apply where DASC has a genuine organisational need that does not override an individual's rights.

Examples might include:

  • maintaining security systems;
  • preventing fraud;
  • managing day-to-day administration.

Legitimate interests require careful balancing.


Special Category Data

Special category data usually requires:

  • an appropriate lawful basis; and
  • an additional legal condition.

Examples include:

  • medical information;
  • disabilities;
  • safeguarding concerns;
  • ethnicity where lawfully required.

These records require additional protection because they are more sensitive.


Choosing the Correct Basis

The lawful basis should be determined before information is collected.

It should not be changed later simply because another option appears more convenient.

Good planning supports good compliance.


Ofsted Inspection Insight

Inspectors and regulators expect organisations to understand why information is collected and how it supports children's welfare.

Clear purposes demonstrate good governance and accountability.


Practice Scenario – Newsletter Signup

Optional Emails


Practice Scenario – Emergency Medical Information

Allergic Reaction


Manager Coaching Notes

Managers should ensure staff:

  • understand lawful bases;
  • recognise when consent is appropriate;
  • protect special category data;
  • document processing activities;
  • review privacy notices regularly;
  • seek advice if unsure.

Understanding the lawful basis strengthens confidence in everyday GDPR decision-making.


Reflection

Reflect on today's learning.

  • Could you explain the difference between consent and legal obligation?
  • Why should the lawful basis be identified before collecting information?
  • When might vital interests apply?
  • How should special category data be protected?

Good GDPR compliance begins with understanding why information is being collected before deciding how it should be used.


Individual Rights Under UK GDPR

UK GDPR gives individuals important rights over their personal information.

These rights help ensure that organisations remain transparent, accountable and respectful when handling personal data.

At DASC, every member of staff should understand these rights and know how to respond appropriately if a request is received.


Why Individual Rights Matter

Parents, carers, staff and, where appropriate, children have the right to understand:

  • what information is held about them;
  • why it is being used;
  • who it is shared with;
  • how long it will be kept.

These rights strengthen trust and accountability.


DASC Standard

Personal information belongs to the individual.

DASC is responsible for protecting it—not owning it.


The Eight Individual Rights

Under UK GDPR, individuals have the following rights:

RightWhat it Means
Right to be InformedTo know how their information is collected and used
Right of AccessTo request a copy of their personal information
Right to RectificationTo correct inaccurate or incomplete information
Right to ErasureTo request deletion in certain circumstances
Right to Restrict ProcessingTo limit how information is used in certain situations
Right to Data PortabilityTo obtain certain information in a reusable format
Right to ObjectTo object to certain types of processing
Rights Related to Automated Decision-MakingProtection from decisions made solely by automated systems in certain circumstances

Not every right applies in every situation.

Some legal exemptions may apply.


The Right to be Informed

People should understand:

  • what information DASC collects;
  • why it is collected;
  • how it is used;
  • who receives it;
  • how long it is retained;
  • how to exercise their rights.

Privacy notices help meet this requirement.

Information should be written clearly and in language that people can understand.


The Right of Access

Individuals may request access to their own personal information.

This is commonly known as a Subject Access Request (SAR).

Examples include requests for:

  • attendance records;
  • accident reports;
  • correspondence;
  • registration information.

Requests should always be handled in accordance with DASC procedures.


DASC Best Practice

If someone requests personal information—

Do not promise immediate access.

Refer the request to the appropriate manager or Data Protection Lead.

Following the correct process protects everyone.


The Right to Rectification

If information is inaccurate or incomplete, individuals may ask for it to be corrected.

Examples include:

  • incorrect addresses;
  • outdated telephone numbers;
  • inaccurate emergency contacts;
  • incorrect spelling of names.

Accurate information supports effective safeguarding.


The Right to Erasure

Sometimes called the "Right to be Forgotten."

Individuals may request that certain personal information be deleted.

However, this right is not absolute.

DASC may need to retain information where:

  • safeguarding responsibilities apply;
  • legal obligations exist;
  • records are required by law.

Staff should never delete records without following authorised procedures.


Restricting Processing

Individuals may ask DASC to temporarily limit how their information is used while concerns are investigated.

For example:

A parent disputes the accuracy of a record.

The information may need to remain available while the issue is reviewed.


Data Portability

In certain situations, individuals may request that their information be provided in a structured, commonly used electronic format.

This right usually applies only in specific circumstances.

Requests should always follow DASC procedures.


The Right to Object

Individuals may object to certain processing activities.

For example:

  • direct marketing;
  • some uses based on legitimate interests.

Requests should be referred to the appropriate manager for consideration.


Automated Decision-Making

DASC does not normally make significant decisions about children or staff using fully automated systems.

Where automated processes are used, appropriate safeguards should always be in place.

Human oversight remains important.


Ofsted Inspection Insight

Inspectors expect organisations to respect privacy while maintaining appropriate safeguarding records.

Strong GDPR compliance balances individual rights with legal safeguarding responsibilities.


Practice Scenario – Parent Requests Records

Can I Have Everything?


Practice Scenario – Incorrect Emergency Contact

Old Telephone Number


Manager Coaching Notes

Managers should ensure staff:

  • understand individual rights;
  • recognise Subject Access Requests;
  • protect safeguarding records appropriately;
  • update inaccurate information promptly;
  • understand retention requirements;
  • know when to seek specialist advice.

Respecting individual rights strengthens public trust and organisational accountability.


Reflection

Reflect on today's learning.

  • Could you identify a Subject Access Request?
  • Why is the Right to Erasure not always absolute?
  • How does accurate information support safeguarding?
  • What should you do if someone requests a copy of their records?

Protecting privacy means respecting people's rights while continuing to safeguard children effectively.


Storing, Sharing and Retaining Information

Collecting information is only one part of GDPR compliance.

Information must also be:

  • stored securely;
  • shared appropriately;
  • retained for the correct length of time;
  • disposed of safely.

Every stage of the information lifecycle should protect confidentiality and support safeguarding.


Secure Storage

Whether records are digital or paper-based, they must be protected against:

  • unauthorised access;
  • accidental loss;
  • theft;
  • damage;
  • inappropriate disclosure.

Security measures may include:

  • password protection;
  • encryption;
  • locked filing cabinets;
  • restricted access;
  • secure cloud systems.

Children's information should never be left unattended.


DASC Standard

If information is not being used—

Store it securely.

Security should become an everyday habit.


Paper Records

Paper records should:

  • be stored in locked cabinets;
  • only be accessed by authorised staff;
  • never be left on desks overnight;
  • be collected immediately from printers;
  • be shredded securely when no longer required.

Printed documents deserve the same protection as electronic records.


Electronic Records

Electronic information should be:

  • stored only within approved systems;
  • protected by strong passwords;
  • backed up where appropriate;
  • encrypted where required;
  • accessible only to authorised users.

Personal cloud storage or unauthorised applications should never be used for DASC records.


Sharing Information

Before sharing information, ask:

  • Is sharing necessary?
  • Who genuinely needs the information?
  • What is the lawful basis?
  • Am I sharing only the minimum required?

Sharing should always be proportionate.


DASC Best Practice

Share only what is needed.

Nothing more.

Nothing less.


Email Security

Before sending confidential information:

  • check every recipient carefully;
  • confirm attachments;
  • remove unnecessary personal information;
  • use secure systems where appropriate.

Take a moment before pressing Send.

Many data breaches result from simple typing mistakes.


Verbal Confidentiality

Information can also be disclosed through conversation.

Avoid discussing confidential matters:

  • in reception areas;
  • in corridors;
  • on public transport;
  • in cafés;
  • at home with family or friends.

Professional confidentiality applies wherever you are.


Records Retention

Different records must be retained for different periods.

Retention schedules help ensure that information is:

  • available when required;
  • deleted when appropriate;
  • managed consistently.

Keeping records longer than necessary increases unnecessary risk.

Always follow DASC's Records Retention Policy.


Secure Disposal

When information reaches the end of its retention period:

Paper records should be:

  • cross-cut shredded;
  • disposed of using confidential waste services where appropriate.

Electronic records should be:

  • securely deleted;
  • removed from backups in accordance with organisational procedures where applicable.

Deleting files by moving them to the recycle bin may not be sufficient.


Ofsted Inspection Insight

Inspectors expect confidential information to be secure whether they visit the office, observe staff working or review administrative processes.

Strong information governance reflects strong organisational leadership.


Practice Scenario – Printed Register

End of Session


Practice Scenario – Email Attachment

Wrong Recipient


Manager Coaching Notes

Managers should ensure:

  • storage arrangements remain secure;
  • access permissions are reviewed regularly;
  • retention schedules are followed;
  • confidential disposal procedures are understood;
  • staff receive regular GDPR refresher training;
  • information sharing is monitored appropriately.

Effective information management protects both safeguarding and organisational compliance.


Reflection

Reflect on today's learning.

  • Are paper records always stored securely?
  • Do you check recipients before sending confidential emails?
  • Why is retaining information for too long a GDPR risk?
  • How should confidential information be disposed of safely?

Every record should be protected throughout its entire lifecycle—from collection to secure disposal.


Personal Data Breaches

Even in well-managed organisations, mistakes can happen.

A personal data breach does not always result from malicious activity.

Many breaches occur because of simple human error.

The important thing is recognising the breach quickly, reporting it promptly and taking appropriate action.


What is a Personal Data Breach?

A personal data breach is a security incident that leads to the accidental or unlawful:

  • destruction of personal data;
  • loss of personal data;
  • alteration of personal data;
  • unauthorised disclosure of personal data;
  • unauthorised access to personal data.

A breach may involve paper records, electronic systems or verbal disclosure.


DASC Standard

Mistakes must be reported—

not hidden.

Early reporting protects children, families and DASC.


Common Causes of Data Breaches

Examples include:

  • sending emails to the wrong person;
  • losing paperwork;
  • leaving records unattended;
  • discussing confidential information in public;
  • losing laptops or mobile devices;
  • weak passwords;
  • phishing attacks;
  • sharing information without authorisation.

Many breaches can be prevented through good everyday habits.


Examples of Data Breaches

Examples include:

  • a safeguarding report emailed to the wrong parent;
  • a printed register left in reception;
  • an unlocked laptop displaying children's records;
  • confidential paperwork found in general waste;
  • photographs shared without appropriate authorisation.

Not every breach causes harm, but every breach should be assessed.


DASC Best Practice

If you think a breach might have happened—

Report it.

Never wait to see if the problem resolves itself.


Immediate Response

If a breach occurs:

  • remain calm;
  • contain the breach where possible;
  • inform your manager immediately;
  • follow DASC's Data Breach Procedure;
  • record what happened accurately.

Do not attempt to hide mistakes.

Prompt action often reduces the impact significantly.


Reporting Internally

Managers may need to know:

  • what happened;
  • when it happened;
  • who was affected;
  • what information was involved;
  • what immediate action has been taken.

Accurate information supports effective decision-making.


Learning from Breaches

Every breach should lead to learning.

Questions may include:

  • Why did it happen?
  • Could it happen again?
  • Do procedures need improving?
  • Is further staff training required?

The purpose is continuous improvement rather than blame.


The Information Commissioner's Office (ICO)

Some serious personal data breaches must be reported to the Information Commissioner's Office (ICO).

This decision is made by authorised managers or the Data Protection Lead.

Individual staff members should report concerns internally rather than contacting the ICO themselves unless instructed.


Supporting Trust

Parents trust DASC with highly sensitive information.

Responding openly and professionally to mistakes helps maintain that trust.

Honesty strengthens confidence.

Attempts to hide mistakes usually make situations worse.


Ofsted Inspection Insight

Inspectors and regulators understand that mistakes sometimes happen.

They are interested in whether organisations respond quickly, honestly and professionally while improving systems to reduce future risks.

Strong reporting cultures support both safeguarding and compliance.


Practice Scenario – Wrong Attachment

Accidental Email


Practice Scenario – Lost Notebook

Journey Home


Manager Coaching Notes

Managers should ensure:

  • staff recognise personal data breaches;
  • reporting procedures are understood;
  • incidents are investigated fairly;
  • lessons learned are implemented;
  • breach records are maintained;
  • refresher training is provided after significant incidents.

Strong organisations learn from mistakes rather than hiding them.


Reflection

Reflect on today's learning.

  • Could you identify a personal data breach?
  • Why is immediate reporting so important?
  • What information should be included in a breach report?
  • How can learning from mistakes improve GDPR compliance?

Protecting personal information is not about achieving perfection.

It is about responding professionally, learning continuously and maintaining the trust that families place in DASC.


End of Course Assessment

Instructions

Complete the assessment below.

A pass mark of 80% is required before the course can be marked as complete.

No questions provided.


Competency Declaration

Professional Competency & Compliance Declaration

Statutory standard: UK EYFS / KCSIE / Ofsted Framework

Training Record Verification
  • I have thoroughly read and understood all content, statutory frameworks, and operational guidelines presented in this training course.
  • I confirm my commitment to applying these safeguarding and quality standards rigorously in my day-to-day childcare practice.
  • I understand my legal and organisational reporting responsibilities under UK childcare legislation and DASC policy.

Related Policies & Documents


    References

    Course References


      Course Completion

      Congratulations.

      You have completed Course 12 – Data Protection & GDPR.

      Every registration form, safeguarding record, attendance register and medical note represents information that families have entrusted to DASC.

      Protecting that information is not simply about complying with the law—it is about demonstrating professionalism, safeguarding children and maintaining the confidence of parents and carers.

      Remember the four principles of excellent information governance:

      • Collect Only What You Need
      • Protect Information Securely
      • Share Responsibly
      • Report Mistakes Immediately

      Strong GDPR compliance is built through thousands of small, professional decisions made every day.

      By protecting information with care, integrity and respect, you help create a culture where children, families and colleagues can trust DASC to safeguard both their wellbeing and their personal information.

      References

      Legislation

      1. United Kingdom General Data Protection Regulation (UK GDPR) 2018. The Stationery Office. https://www.legislation.gov.uk/eur/2016/679/contents

        View source ↗
      2. Data Protection Act 2018 2018. The National Archives. https://www.legislation.gov.uk/ukpga/2018/12/contents

        View source ↗

      Government Guidance

      1. Department for Education (2025). Statutory Framework for the Early Years Foundation Stage (EYFS). Department for Education. https://www.gov.uk/government/publications/early-years-foundation-stage-framework--2

        View source ↗
      2. Information Commissioner's Office (2024). Guide to Data Protection and the UK GDPR. Information Commissioner's Office. https://ico.org.uk/for-organisations/guide-to-data-protection/

        View source ↗