Data Protection Policy

1. Purpose

AuDHD UK is committed to protecting the privacy and security of personal data. This policy sets out how we collect, use, store, share, and protect personal information. It ensures we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Scope

This policy applies to all personal data processed by AuDHD UK, including information about beneficiaries, staff, volunteers, peer supporters, and any other individuals we support or work with.

3. Data Protection Principles

We follow these key principles:

  • Lawfulness, Fairness, and Transparency – We process personal data lawfully, fairly, and transparently.

  • Purpose Limitation – We only collect data for specified, explicit, and legitimate purposes.

  • Data Minimisation – We only collect data that is adequate, relevant, and limited to what is necessary.

  • Accuracy – We keep personal data accurate and up to date.

  • Storage Limitation – We retain data only as long as necessary for its purpose or as required by law.

  • Integrity and Confidentiality – We keep data secure and protect against unauthorised access, loss, or damage.

  • Accountability – We take responsibility for how we handle data and can demonstrate compliance with these principles.

4. Collecting and Using Personal Data

We collect personal data directly from individuals or, where appropriate, from third parties (e.g. next of kin, emergency services). Data may include contact details, health or safeguarding information, incident reports, and support records.

We use this data to:

  • Provide support and safeguarding services

  • Manage crises and emergencies

  • Meet our legal and regulatory obligations

  • Communicate with beneficiaries, staff, and volunteers

5. Lawful Bases for Processing

We process personal data only when there is a lawful basis, including:

  • Consent – The individual has given clear consent for processing

  • Vital Interests – Processing is necessary to protect someone’s life

  • Legal Obligation – Processing is necessary to comply with the law

  • Legitimate Interests – Processing is necessary for our legitimate interests, provided these do not override the rights of individuals

In safeguarding or crisis situations, we may share information without consent if there is a risk of significant harm or as required by law (see our Safeguarding Framework for details).

6. Sharing and Disclosing Data

We only share personal data with those who need to know, such as the DSL, Deputy DSL, emergency services, or statutory agencies.

We may share data with external partners (e.g. health professionals, social services) when necessary for safeguarding or legal reasons.

We never sell personal data or use it for marketing without consent.

7. Data Security

  • All personal data is stored securely, whether in paper or electronic form

  • Access to data is restricted to authorised personnel only

  • We use secure systems for storing and transmitting data (e.g. password-protected files, encrypted emails)

  • Any data breaches or losses must be reported immediately to the DSL and, where required, to the Information Commissioner’s Office (ICO)

8. Data Retention

AuDHD UK only retains personal data for as long as it is necessary for operational, safeguarding, financial, or legal reasons.

  • Any data related to safeguarding, legal matters, mental health crisis, financial records, or serious incidents is retained for 7 years, in line with best practice and compliance requirements.

  • All other volunteer data (including CVs and DBS check results) is retained for 3-6 months after onboarding – or completion in the case of repeat DBS checks – with the exception of training records which are held for 7 years.

  • All other data (including emails and basic communications) must be retained for a minimum of 60 days from the date of last contact or use and is then securely deleted, unless a longer period is legally required or justified (e.g. in an ongoing safeguarding or legal case).

When data is no longer needed:

  • Paper records are shredded or securely destroyed

  • Digital files are permanently deleted from systems and backups

  • Third-party deletion logs or confirmations are requested where appropriate

This retention policy supports individuals’ rights under data protection law, including the right to erasure, unless an exception applies.

9. Rights of Individuals

Individuals have the right to:

  • Be informed about how their data is used

  • Access their personal data

  • Rectify inaccurate or incomplete data

  • Request erasure of their data (unless there is a safeguarding or legal reason to retain it)

  • Restrict or object to processing in certain circumstances

  • Request data portability (where applicable)

  • Complain to the ICO if they believe their data rights have been breached

Requests should be made in writing to the DSL or Digital Operations & Systems Coordinator.

10. Roles and Responsibilities

  • DSL / Digital Operations & Systems Coordinator – Responsible for ensuring compliance, responding to data requests, and reporting breaches.

  • All staff and volunteers – Must follow this policy, report any data breaches, and only access or share data as necessary for their role.

11. Training and Awareness

All staff and volunteers receive training on data protection and confidentiality as part of their induction and ongoing safeguarding training.

12. Review

This policy is reviewed annually or after any significant data protection incident, change in law, or organisational change.

For questions or concerns about data protection, contact safeguarding@audhduk.org.

Last updated: 20 July 2026