NCSUN CIC
Our Data and Privacy Policy
This is the plain-language version of our GDPR and Data Ethics Policy. It explains, in everyday words, what information we hold about people, why we hold it, how we keep it safe, and what rights you have. We have written it this way on purpose. We do not believe a policy about your information should be impossible for you to read.
|
Version |
3.1 |
|
Status |
Approved by the directors, 19 June 2026, pending final legal review |
|
Starts from |
19 June 2026 |
|
Next review |
19 June 2027 |
|
Replaces |
Version 3.0, 19 June 2026. Version 3.1 adds the website enquiries line in section 9 and the contact address in section 8 (26 September 2026). |
|
Who looks after it |
Charli McLean, Managing Director |
|
Day-to-day data security |
Leanne Marie Rose, Safeguarding and Operations Director |
|
Who it applies to |
Everyone who works for or with NCSUN: directors, volunteers, contractors, and the people who take part in our programmes |
|
The law behind it |
The UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025 |
|
Registered with the ICO |
Yes. Our reference is ZC061694. |
|
Legal review |
A data protection lawyer at LawWorks is reviewing our data practices. We will update this policy after that review. We will not sign any paid consultancy contract until the review is finished. |
1. What this policy is for
NCSUN works with people who have lived through hard things: trauma, poverty, losing a home, bereavement, and being let down by systems that were meant to help. Some of what we hold about people is sensitive. This policy explains how we look after it.
Our starting belief is simple. Your information belongs to you, not to us. We are only ever looking after it.
2. What it covers
This policy covers every kind of personal information we hold, on paper or on a computer. That includes our programme records, event records, contact lists, the evidence we keep for grants, our time logs, and anything held in Connect-EnGINE, our community intelligence system. It covers anything that could identify a living person.
It applies to everyone acting for NCSUN: the three directors, every volunteer, and any contractor we bring in. Breaking this policy is treated seriously and can mean someone is asked to leave.
3. The law we follow, in plain terms
We follow three pieces of law: the UK GDPR, the Data Protection Act 2018, and the newer Data (Use and Access) Act 2025. The 2025 Act does not replace the older two. It updates them, and its changes are arriving in stages. Wherever this policy says “GDPR,” we mean the current version as updated by that Act.
The law sets out seven rules for handling personal information (the data protection principles in Article 5 of the UK GDPR). Here is what each one means for us in practice.
|
The rule |
What we actually do |
|
Use it lawfully, fairly, and openly |
We only collect information when we have a clear, lawful reason. We tell people what we are collecting and why, before we collect it. |
|
Only use it for the reason we gave |
We do not quietly reuse someone’s information for something new. If we need it for a new reason, we ask again. |
|
Collect only what we need |
We do not gather information “just in case.” |
|
Keep it accurate |
If someone tells us their details have changed, we update them. |
|
Do not keep it longer than needed |
We have set times for how long we keep different kinds of information, set out later in this policy. |
|
Keep it safe |
We protect information against loss, prying, and misuse, with sensible security for each kind of information we hold. |
|
Be able to show we do all this |
We keep our own records so we can demonstrate that we follow these rules. |
4. Why we are allowed to hold information
The law says we must have a proper reason, called a “lawful basis,” for everything we do with personal information (the six lawful bases are in Article 6 of the UK GDPR). Most of the time, ours is one of two things: the person has agreed (consent), or we have a genuine and fair need to do it (legitimate interests).
When we rely on someone agreeing, that agreement has to be freely given, clear, and specific, and we keep a record of it. When we rely on a genuine need, we think it through and write down why our need is fair and does not override the person. There is one exception the 2025 Act allows: for a small, set list of important purposes such as protecting someone at risk or helping prevent crime (the recognised legitimate interests), we do not have to weigh it up in the same way, because the law has already recognised those reasons. We only use that route for purposes that genuinely fall on that list.
We keep a record of which lawful reason we rely on for each kind of thing we do, and we are completing a fuller record of all our data activities (our record of processing activities under Article 30) as part of the LawWorks review. This is how we can show we are accountable, as the law requires.
Sensitive information. Some of what we hold counts as “special category” information under the law. For us that mainly means things like health, trauma, mental wellbeing, and someone’s experience of disadvantage. The law asks for extra care here: as well as our ordinary lawful reason under Article 6, we need a specific extra condition under Article 9, supported by Schedule 1 to the Data Protection Act 2018. Here is how we handle it.
- Most of the time, when someone takes part in a programme, our basis is their clear and explicit agreement (explicit consent under Article 9(2)(a)).
- When we need to act to protect someone from harm, we may rely instead on the safeguarding of children and individuals at risk condition in Schedule 1, rather than waiting for agreement.
- If we ever needed information to deal with a legal claim, or for a matter of substantial public interest, we would use the specific Article 9 condition the law sets out for that, with its required Schedule 1 support.
We do not lump all sensitive information through one route, and we do not guess at sensitive information about people. We only record it when someone has chosen to share it, or when protecting someone means we have to.
Because we handle this kind of sensitive information, the law also asks us to keep a short document explaining how we look after it and how long we keep it (an appropriate policy document). We maintain that document and keep it up to date.
A note on Connect-EnGINE. Connect-EnGINE holds community insight drawn from conversations, observations, and the work we do across our programmes. Everyone whose information sits in it is given a code, called a GINE ID. We never use a real name in anything that leaves NCSUN. We do not share information from it without the person’s clear agreement, unless we have a lawful reason that comes before consent, such as a duty to keep someone safe. A full Data Protection Impact Assessment on Connect-EnGINE is being completed as part of the LawWorks review.
5. Your rights
If we hold information about you, the law gives you rights over it, and we respect them. To use any of these, contact Charli McLean at connection@ncsun.org. We will reply within one calendar month. If you ask us to find information about you (a subject access request), the law now says our search has to be reasonable and proportionate in scope rather than endless, and that is how we approach it.
|
Your right |
What it means |
|
To see your information |
You can ask what we hold about you and get a copy. |
|
To correct it |
You can ask us to fix anything wrong or incomplete. |
|
To have it deleted |
You can ask us to delete it where there is no longer a good reason to keep it. |
|
To pause our use of it |
You can ask us to stop using it while a disagreement is sorted out. |
|
To take it with you |
Where we hold it because you agreed or because of a contract, you can ask for it in a form you can reuse. |
|
To object |
You can object to us using it on the “genuine need” basis. We will stop unless there is a strong reason that overrides your objection. |
|
To change your mind |
Where we relied on your agreement, you can withdraw it at any time. That does not undo anything we lawfully did before you withdrew. |
6. If you want to complain
If you are unhappy with how we have handled your information, you can tell us, and you have a right to do so. From 19 June 2026 the law sets out clearly how organisations must handle these complaints, and this is how we do it.
You do not need to fill in a form on your own. In most cases we will sit down with you and go through it together, and we will write the complaint up for you. If your complaint happens to be about Charli, you can raise it with another director instead, so you never have to complain to the person concerned.
We will let you know we have received your complaint within 30 days. We will look into it properly and without unnecessary delay, and we will keep you posted on how it is going and what we decide.
If you are still not happy, you can complain to the Information Commissioner, the UK’s data protection regulator. We will give you their current contact details if you ask. Coming to us first never takes away your right to go to the regulator.
7. Keeping information safe
All personal information we hold must be kept securely. Anything on a computer must be behind a password. Only the people who need information for their NCSUN role can get to it. Personal information must never be kept on someone’s own unsecured device, sent through a personal email account, or sent on without encryption or a password.
Paper records must be kept securely and never left lying around in shared or public spaces. When we no longer need a paper record, we destroy it securely.
If information is ever lost or exposed, we act straight away. If the breach could put people’s rights or wellbeing at risk, we tell the Information Commissioner within 72 hours of realising. If it could put someone at high risk, we tell that person directly, without delay. Anyone at NCSUN who spots or suspects a breach must tell Charli McLean immediately.
8. Connect-EnGINE, and the human always in the loop
Connect-EnGINE is our community intelligence system. It holds insight gathered across our programmes. It is a manual, human-run method. It is not artificial intelligence, and we do not describe it as AI anywhere, because that would not be an honest description of how it works.
Everything in it sits under a GINE ID code. The list that links those codes to real people is held securely and seen only by Charli McLean, and where genuinely needed, Leanne Marie Rose. Nobody else sees that list without the Managing Director’s say-so.
Anything we produce from Connect-EnGINE uses the codes only. No real names, and no identifying organisation names, appear in our analysis, our briefings, or our grant applications. That rule has no exceptions.
A human always checks the output. Nothing from Connect-EnGINE goes into any decision, document, or message without a named person reviewing it first. That is not negotiable.
We do not make any decision purely by automation. At the moment there is no automation to make one: the work is done by hand. If we ever bring in automation to help with Connect-EnGINE, we will first carry out a fresh impact assessment, and we will put in place the protections the law requires (under the automated decision-making provisions of the UK GDPR, Articles 22A to 22D, as amended by the Data (Use and Access) Act 2025), including telling people, letting them have their say, and making sure a person can step in. The human in the loop stays, even when some of the work is automated.
9. How long we keep things
We keep information only as long as we genuinely need it. As a guide:
- Programme records: kept while the programme runs and for three years after, so we can report on our impact and meet safeguarding duties.
- Contact and relationship information: reviewed every year.
- Grant evidence: kept for seven years, as funders generally expect.
- Financial records: kept for six years, as company law requires.
- Website enquiries: a copy of anything sent through our website contact form is kept securely in the website’s admin area, which only our administrators can see, for six months, then deleted. This is a backup in case an email goes astray.
- Safeguarding records: kept under the separate rules in our Safeguarding policies.
For Connect-EnGINE, we handle a few kinds of information separately. Raw material that still has someone’s direct details in it is kept only long enough to turn into coded form, then securely deleted. Coded records are kept for as long as we need them to produce and stand behind the community insight. The list linking codes to real people is kept securely while someone’s relationship with NCSUN is live, and reviewed for deletion when that relationship ends. Insight that has been fully anonymised, so it is no longer about identifiable people, we keep as an organisational asset. The full retention schedule, including these Connect-EnGINE categories and exactly when each is deleted, is being completed as part of the LawWorks review and will be added to this policy then.
10. Sending information outside the UK
We hold and use personal information within the United Kingdom, and we do not routinely send it abroad. If sending information outside the UK ever became necessary, we would only do it where there is a proper safeguard in place and where the protection for that information would be, in the words of the updated law, not materially lower than it is under UK rules. We would keep any such arrangement under review, following the Information Commissioner’s guidance.
11. Children and people who may be at risk
We work with children, with care-experienced young people, and with adults who may be at risk. We take extra care with their information. If we ever run an online service that children are likely to use, we follow the extra protections for children that the law sets out, and the principles of the Information Commissioner’s Age Appropriate Design Code, including giving information in a way that suits their age.
When someone is a child or an adult at risk, we think carefully about whether their agreement is the right basis, or whether a safeguarding reason applies, and we involve a parent, guardian, or trusted supporter where that is right and safe. Where keeping someone safe means we have to use or share information without agreement, we rely on the proper safeguarding reason and write down our decision. Keeping people safe always comes first, and this section is read alongside our Safeguarding policies.
12. Sharing with others
We do not sell personal information. We do not hand it to other organisations for their own marketing or business. We only share it where we have a lawful reason: where someone has agreed to that specific sharing, where we have a legal duty such as a safeguarding obligation, or where another organisation is handling information for us under a proper written agreement.
When another organisation processes information on our behalf, we put a written contract in place that meets the law’s requirements for that (Article 28 of the UK GDPR). When we and another organisation decide together how and why information will be used, we write down who is responsible for what (a joint-controller arrangement). When we share anything with funders, partners, or commissioners, it is anonymised, unless the person it relates to has given separate, specific agreement.
Insight from Connect-EnGINE that has been anonymised, to the point where people are no longer reasonably likely to be identified, is no longer personal information, and we may share it for community benefit.
13. Who is responsible
Charli McLean is our Data Protection Manager and holds overall responsibility for this policy and for our compliance with data protection law. Leanne Marie Rose is our Data Security and Compliance Lead and looks after day-to-day data security across our work. Everyone at NCSUN is responsible for understanding this policy, following it, and reporting any worry or suspected breach straight away.
We will review and update this policy after the LawWorks review is complete. We will not sign any paid consultancy contract before then.
14. Sign-off
This policy has been reviewed and approved by the directors of NCSUN CIC. It is a living document and we will update it when the law changes, when our work changes significantly, or after the LawWorks review.
|
Name |
Role |
|
Charlotte McLean |
Managing Director and Lived Experience Architect |
|
Leanne Marie Rose |
Safeguarding and Operations Director |
|
Robert McGregor |
Director of Strategy and Mission Oversight |
|
Approved |
19 June 2026 |
|
Next review |
19 June 2027 |
This policy is not legal advice. We have written it as fully and honestly as we can ahead of our data protection review with LawWorks. A qualified lawyer will review it before we sign any paid consultancy contract. If you have a question about how we handle your information, just ask us.
