Purpose of the Policy
The purpose of this policy is to protect young people, parents, carers, families, volunteers and staff by ensuring that everyone involved in The Gaitherin understands their responsibilities when handling confidential information. It sets out how information should be collected, used, stored, shared and protected. This policy applies to all staff, volunteers, students, contractors, and anyone working on behalf of the Gaitherin.
What Counts as Confidential Information
Confidential information includes, but is not limited to:
- Personal details (Names, addresses, phone numbers)
- Medical information, allergies, and medication needs
- Emergency contact information
- Behavioural, wellbeing or supported needs
- Safeguarding or child protection requirements
- Any other information shared by a young person, parent or carer in confidence.
The Gaitherin aims to collect only the minimum information necessary to ensure safety and effective participation.
Key Confidentiality Principles
All staff, volunteers and students must:
- Only access information needed to carry out their role and support participants.
- Keep all personal information safe and secure.
- Share information only with appropriate staff and only when necessary
- Discuss participants, parents, or carers only in appropriate settings where conversations cannot be overheard.
- Never discuss a young person, parents, or carers outside of the Gaitherin.
- Share information with outside agencies only with the families permission, unless there is a child protection concern.
- Follow all procedures for the secure handling and return of information.
Safeguarding and Child Protection
The only exception to confidential information being shared without parental consent is where there is a child protection concern
In such cases:
- Staff must follow the Gaitherin’s safeguarding procedures
- Information must be passed to the designated safeguarding lead or relevant authorities
- Information shared must be limited to what is necessary to protect the child
Data Protection and GDPR
The Gaitherin complies with UK GDPR and relevant data protection legislation. This means:
- Personal information is collected for clear and specific purposes, mainly related to the wellbeing of the young person, and safety and event administration.
- Information is stored securely and only accessed by authorised staff.
- Information is kept only as long as necessary and then securely deleted or returned to the Administration staff.
- Families have the right to request access to their information and can ask for corrections where needed.
Storage, Access and Disclosure
- Personal information, (including health, medication, and allergy details) is kept accessible only to staff who need it for safety reasons.
- Access is normally agreed during planning stages and during the registration process.
- At the end of the Gaitherin, all records are returned to Administration staff for secure storage or disposal.
- Anyone concerned about how information has been handled should report this to the Gaitherin Administrator or Co-ordinator immediately.
Social Media, Photos and Videos
- Pictures and videos will only be taken and shared with written parental permission , normally as part of the registration process.
- No names or identifying details will be included in any social media posts or marketing.
- Parents and carers may withdraw consent at any time.
Training and Awareness
- All staff and volunteers will receive guidance on confidentiality and data protection before working with young people.
- Gaitherin co-ordinator and Administrator are responsible for promoting good confidentiality practice and processes.
Breaches of Confidentiality
Any suspected or actual breach of confidentiality must be reported immediately to the Gaitherin Co-ordinator or Administrator. Breaches may result in further actions, including additional training, review of procedures, or disciplinary measures where appropriate.