Skip to content

DATA PROTECTION
AND SECURITY
Induction training

Logo

Data protection and securityย 

Little Lives UK’s privacy responsibilitiesย 

Little Lives UK has a legal responsibility to protect the privacy of its staff, volunteers, customers, donors and supporters. We must all work together to make sure we uphold our regulatory and best practice obligations with regards to data in a professional, robust and trustworthy manner.ย 

What is personal data?ย 

Personal data means data relating to a living individual who can be identified from that data (or from other information in our possession). Personal data can be factual (such as name, address or date of birth) or it can be an opinion (such as a performance review). Sensitive personal data includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, medical conditions, sexual orientation or criminal record. Sensitive personal data can only be processed under strict conditions, and will usually require the explicit consent of the person concerned. We must take extra care when collecting, using or storing sensitive data.ย 

Data protectionย 

The Data Protection Act 1998 states that anyone processing personal data must comply with theย eight principles of good practice. These provide that personal data must be:ย 

โ–ช Processed fairly and lawfullyย 
โ–ช Processed for limited purposes and in an appropriate wayย 
โ–ช Adequate, relevant and not excessive for the purposeย 
โ–ช Accurate and up to dateย 
โ–ช Not kept longer than necessary for the purposeย 
โ–ช Processed in line with the data subjects’ rightsย 
โ–ช Kept secureย 
โ–ช Not transferred to people or organisations situated in countries without adequate protection.

What the law means for us

Getting this right is important as it helps strengthen the continued trust which our supporters place in the Little Lives UK. Getting it wrong could result in a loss of confidence by the public, the Little Lives UK being fined by the information Commissioner’s Office and our reputation being damaged.

What we need to do

The first thing is to fully understand why data protection is important, how you can help, and what to do if there is a problem.

Secure it

Any paper based information must be held securely in locked cabinets or cupboards. For example, when people share their personal details with us, if the Gift Aid form is not locked away immediately it is then open for anyone to see, which means the data could be copied. This is the same for paperwork completed for volunteers, work experience placements, stock collections and deliveries.

Shred it

If you have been authorised by your Manager or the Legal Team to dispose of a document containing personal data, you must use a cross- cut shredder, don’t just put it in the bin.

Protect it

Keep your passwords private and don’t write them down anywhere. Always log off’ the till and lock the back-office PC when you leave. Our shops have a lot of visitors so we must be vigilant around access to our data and systems.

Don’t share itย 

Do not disclose any data about anyone else without their permission. Be aware that people may try to get you to give out personal information.ย 

Subject Access Requestย 

All individuals have the right to know what information an organisation holds about them and they can request a copy of this. This is called a Subject Access Request and must be made in writing to the organisation. If you receive such a request from a member of the public, a supporter, a volunteer or a member of staff please notify the person in charge in the shop. We are legally obliged to respond within 40 days so it is essential that you pass on any requests as soon as possible.ย 

Data securityย 

The Little Lives UK IT Security Policy sets out what is not permitted whilst using Little Lives UK IT equipment and systems. This covers all paid and unpaid employees, contractors, volunteers and any other people accessing Little Lives UK IT systems.ย 

What we need to doย 

Protect itย 

When using the back-office computer, use passwords with a mixture of numbers and letters (upper / lower case) and symbols.ย 

Keep it cleanย 

Don’t install software or attach equipment, including memory sticks, to the till, back office or the network without authorisation or agreement. To protect us from malware (malicious software) and viruses, don’t open suspicious attachments or click on strange links. Delete spam or emailsย from addresses you don’t trust.ย 

Wirelessย 

If you are in a building with a wireless network, it must only be used for the business purpose for which it was installed.ย 

Internet securityย 

While a small amount of personal use is permitted access to the Internet is provided for business use and as such certain sites or categories are blocked automatically. The internet must not be usedย inappropriately including but not limited to the following:ย 

โ–ช To download software or any inappropriate or illegal materialย 
โ–ช To access the following categories: sexually explicit, gambling, fraud, hacking, illegalย 
โ–ช Drugs, violence, intolerance, terrorism and any other site that may affect the Little Lives UK`s reputationย 
โ–ช To conduct any form of internet bullying, racism, ethnic impropriety, age discrimination or sexual harassmentย 
โ–ช To access other sites such as social networking sites or chat rooms unless part of your business responsibilitiesย 
โ–ช For re-selling donated Little Lives UK stock for personal gain.ย 

Email security

Email content is treated the same way as verbal or written information, and is admissible in a court of law. This also includes the use of other similar communication such as instant messaging, text orย video. While a small amount of personal use is permitted, email must not be used for the following:ย 

โ–ช Transmission of material which infringes copyright, is confidential Little Lives UK material or is deemed to be junk mail of any kindย 
โ–ช Activities that waste staff effort or networked resourcesย 
โ–ช The creation or transmission of any offensive, obscene or indecent material
โ–ช The distribution of material deemed offensive, abusive, threatening, discriminatory or defamatoryย 
โ–ช The transmission of business data to home or personal accounts.ย 

Now that you have completed the Data Protection and Data Security sectionย 

Here are some specific questions for you to go through with your trainer:ย 

Data Protection:ย 

1. Read the ‘Data Protection Policy’ on the notice boardย 

2. What is the key thing to remember about forms containing personal or sensitive personal data?ย 

3. Who do you report a data protection breach to?ย 

Data Security:ย 

1. Read the IT Security Policy’ on the notice boardย 

2. Can you install software or plug a USB stick into office computer?ย 

3. Who do you report any IT security incidents to?