Data Protection Policy
1. Purpose
AuDHD UK is committed to protecting the privacy and security of personal data. This policy sets out how we collect, use, store, share, and protect personal information. It ensures we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Scope
This policy applies to all personal data processed by AuDHD UK, including information about beneficiaries, staff, volunteers, peer supporters, and any other individuals we support or work with.
3. Data Protection Principles
We follow these key principles:
Lawfulness, Fairness, and Transparency – We process personal data lawfully, fairly, and transparently.
Purpose Limitation – We only collect data for specified, explicit, and legitimate purposes.
Data Minimisation – We only collect data that is adequate, relevant, and limited to what is necessary.
Accuracy – We keep personal data accurate and up to date.
Storage Limitation – We retain data only as long as necessary for its purpose or as required by law.
Integrity and Confidentiality – We keep data secure and protect against unauthorised access, loss, or damage.
Accountability – We take responsibility for how we handle data and can demonstrate compliance with these principles.
4. Collecting and Using Personal Data
We collect personal data directly from individuals or, where appropriate, from third parties (e.g. next of kin, emergency services). Data may include contact details, health or safeguarding information, incident reports, and support records.
We use this data to:
Provide support and safeguarding services
Manage crises and emergencies
Meet our legal and regulatory obligations
Communicate with beneficiaries, staff, and volunteers
5. Lawful Bases for Processing
We process personal data only when there is a lawful basis, including:
Consent – The individual has given clear consent for processing
Vital Interests – Processing is necessary to protect someone’s life
Legal Obligation – Processing is necessary to comply with the law
Legitimate Interests – Processing is necessary for our legitimate interests, provided these do not override the rights of individuals
In safeguarding or crisis situations, we may share information without consent if there is a risk of significant harm or as required by law (see our Safeguarding Framework for details).
6. Sharing and Disclosing Data
We only share personal data with those who need to know, such as the DSL, Deputy DSL, emergency services, or statutory agencies.
We may share data with external partners (e.g. health professionals, social services) when necessary for safeguarding or legal reasons.
We never sell personal data or use it for marketing without consent.
7. Data Security
All personal data is stored securely, whether in paper or electronic form
Access to data is restricted to authorised personnel only
We use secure systems for storing and transmitting data (e.g. password-protected files, encrypted emails)
Any data breaches or losses must be reported immediately to the DSL and, where required, to the Information Commissioner’s Office (ICO)
8. Data Retention
AuDHD UK only retains personal data for as long as it is necessary for operational, safeguarding, financial, or legal reasons.
Any data related to safeguarding, legal matters, mental health crisis, financial records, or serious incidents is retained for 7 years, in line with best practice and compliance requirements.
All other volunteer data (including CVs and DBS check results) is retained for 3-6 months after onboarding – or completion in the case of repeat DBS checks – with the exception of training records which are held for 7 years.
All other data (including emails and basic communications) must be retained for a minimum of 60 days from the date of last contact or use and is then securely deleted, unless a longer period is legally required or justified (e.g. in an ongoing safeguarding or legal case).
When data is no longer needed:
Paper records are shredded or securely destroyed
Digital files are permanently deleted from systems and backups
Third-party deletion logs or confirmations are requested where appropriate
This retention policy supports individuals’ rights under data protection law, including the right to erasure, unless an exception applies.
9. Rights of Individuals
Individuals have the right to:
Be informed about how their data is used
Access their personal data
Rectify inaccurate or incomplete data
Request erasure of their data (unless there is a safeguarding or legal reason to retain it)
Restrict or object to processing in certain circumstances
Request data portability (where applicable)
Complain to the ICO if they believe their data rights have been breached
Requests should be made in writing to the DSL or Digital Operations & Systems Coordinator.
10. Roles and Responsibilities
DSL / Digital Operations & Systems Coordinator – Responsible for ensuring compliance, responding to data requests, and reporting breaches.
All staff and volunteers – Must follow this policy, report any data breaches, and only access or share data as necessary for their role.
11. Training and Awareness
All staff and volunteers receive training on data protection and confidentiality as part of their induction and ongoing safeguarding training.
12. Review
This policy is reviewed annually or after any significant data protection incident, change in law, or organisational change.
For questions or concerns about data protection, contact safeguarding@audhduk.org.
Last updated: 20 July 2026