Confidentiality and Data Protection Policy
1. Introduction
Calmer Soul is committed to maintaining the highest standards of confidentiality and data protection. We recognise our responsibility to safeguard the privacy of all staff, volunteers, facilitators, and participants engaging in our online wellbeing support Huddles. This policy sets out how we handle confidential information and ensure compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Scope
This policy applies to all:
-
Staff members (permanent, temporary, or contract-based)
-
Volunteers
-
Huddle facilitators and support personnel
-
Participants in online support Huddles, workshops, and events
-
Third-party collaborators
3. Principles of Confidentiality
-
Personal and sensitive information shared within Calmer Soul must be treated with the utmost confidentiality.
-
Information disclosed in Huddles is private and should not be shared outside the group unless required by law or safeguarding concerns.
-
Confidentiality applies to all forms of communication, including verbal discussions, written records, emails, and digital communications.
-
Staff and volunteers must ensure that any confidential information is securely stored and accessed only by authorised personnel.
4. Data Protection Compliance
Calmer Soul processes personal data in accordance with UK GDPR and the Data Protection Act 2018. We commit to:
-
Lawfully, fairly, and transparently collecting and processing personal data.
-
Only collecting data necessary for the intended purpose.
-
Keeping personal data accurate and up to date.
-
Ensuring data is stored securely and retained only for as long as necessary.
-
Protecting data against unauthorised access, loss, or disclosure.
5. Information Sharing and Disclosure
Confidential information may only be disclosed in the following circumstances:
-
Where explicit consent has been obtained from the individual.
-
Where required by law, including safeguarding concerns and legal obligations.
-
Where there is a risk of serious harm to the individual or others.
-
When working with third parties under formal agreements that ensure data protection compliance.
6. Safeguarding and Confidentiality
-
In cases where a safeguarding concern arises, confidentiality may need to be breached to protect an individual from harm.
-
Any safeguarding concerns must be reported in line with our Safeguarding Policy and handled appropriately.
-
Only the minimum necessary information will be shared with relevant authorities to protect individuals.
7. Secure Handling of Personal Data
-
Access to personal data is restricted to authorised personnel only.
-
Digital data is stored securely with appropriate encryption and password protection.
-
Physical records, where applicable, are kept in locked storage and disposed of securely when no longer needed.
-
Emails and digital communications containing personal data are handled with care to prevent unauthorised access.
8. Breach of Confidentiality
-
Any suspected or actual breach of confidentiality must be reported immediately.
-
Breaches will be investigated, and appropriate actions will be taken to prevent recurrence.
-
Serious breaches may result in disciplinary action, including termination of contracts or removal from volunteering roles.
9. Rights of Individuals
Under UK GDPR, individuals have the right to:
-
Access their personal data held by Calmer Soul.
-
Request corrections to inaccurate data.
-
Request deletion of their data where appropriate.
-
Restrict or object to data processing in certain circumstances.
-
Lodge a complaint with the Information Commissioner’s Office (ICO) if they believe their data rights have been violated.
10. Policy Review
-
This policy is reviewed annually or as necessary to ensure compliance with UK GDPR and best practices.
-
Staff and volunteer feedback is considered in policy updates.
11. Contact Information
For confidentiality or data protection concerns, please contact:
Email: [email protected]
This policy is effective as of 1 January 2025 and applies to all confidentiality and data protection matters within Calmer Soul.