PolicyAndPlay Policy Template Updated 2024
[Your Setting Name]
Policy: GDPR & Data Protection Version: 2.0 Review date: [Date]
PolicyAndPlay template: Replace all [bracketed placeholders]. This policy is aligned to the UK GDPR (as retained under the Data Protection Act 2018) and is suitable for childminders and small nurseries acting as data controllers.

GDPR & Data Protection Policy

1. Introduction

[Setting Name] is committed to protecting the privacy and security of personal data we hold about children, their families, and staff. This policy explains what data we collect, why we collect it, how we keep it safe, and what rights individuals have.

As a childcare provider, we act as a Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our Data Protection Lead is: [Your Name]
Contact: [email address]

We are registered with the Information Commissioner's Office (ICO): [ICO Registration Number — or "Registration pending"]

Do I need to register with the ICO? Most childminders who process personal data for purposes other than their own personal use must register with the ICO. Registration costs £40/year for small organisations. Check ico.org.uk to confirm your obligation and register online.

2. What Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Children

2.2 Parents and Carers

2.3 Staff and Volunteers

3. Why We Process Personal Data — Lawful Basis

Data typePurposeLawful basis (UK GDPR)
Child's name, DOB, addressRegistration and identity verificationContract (Art 6(1)(b))
Medical / health informationKeeping the child safe; duty of careVital interests (Art 6(1)(d)) + explicit consent for special category data (Art 9(2)(a))
Observation records / learning journeysEYFS requirement to track developmentLegal obligation (Art 6(1)(c))
Photographs of childrenLearning journeys, parent communicationLegitimate interests (Art 6(1)(f)) + parental consent
Financial/payment recordsInvoicing, tax complianceContract + legal obligation
Funding claims (15/30 hours)Claiming free childcare fundingLegal obligation
Staff DBS recordsSafer recruitment / Ofsted requirementLegal obligation
Accident and incident recordsHealth & safety; Ofsted requirementLegal obligation

4. How We Keep Data Secure

4.1 Physical data

4.2 Digital data

4.3 Sharing data

We will only share personal data with third parties where:

We do not sell, rent, or share personal data for marketing purposes.

5. Retention Periods

Record typeRetention period
Children's records (registration, obs, learning journeys)Until the child turns 25 (or 21 if no injury/accident involved)
Accident / injury recordsUntil the child turns 21, or 3 years minimum
Safeguarding recordsIndefinitely (in line with LSCP guidance)
Financial/payment records7 years (HMRC requirement)
Staff records7 years after employment ends
DBS check records6 months after check date (number only retained thereafter)
CCTV footage (if used)31 days maximum unless required for investigation

6. Your Rights Under UK GDPR

Parents, carers, and staff have the following rights regarding their personal data:

To exercise any of these rights, contact: [Your email address]

7. Data Breaches

A data breach is any accidental or unlawful loss, destruction, disclosure, or access to personal data. If a breach occurs:

  1. The data protection lead is informed immediately
  2. The breach is contained where possible (e.g. changing passwords, recovering lost documents)
  3. The breach is assessed for risk to individuals
  4. If the breach poses a risk to individuals, the ICO is notified within 72 hours
  5. Affected individuals are notified if there is a high risk to their rights and freedoms
  6. All breaches are recorded in our Data Breach Log, regardless of severity

8. Photography and Social Media

9. Policy Review

This policy is reviewed annually or when data protection law changes. Next review: [Date]

If you have a concern about how we handle your data that we cannot resolve, you have the right to complain to the ICO: ico.org.uk | 0303 123 1113

Signature of Data Protection Lead
Date signed