Data Protection Policy
1. Statement of commitment
Pets on the Green Ltd is committed to protecting the personal data of everyone whose information we hold โ including children, parents and carers, school and local authority contacts, employees, volunteers, suppliers, and members of the public.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, guided by the principles set out by the Information Commissioner's Office (ICO).
โ Back to top2. Scope
This policy applies to all personal data processed by Pets on the Green Ltd (POTG), in any format or medium, and to everyone who processes personal data on our behalf, including:
- the Director
- employees
- volunteers
- students
- contractors
3. Definitions
- Personal data โ information relating to an identified or identifiable living individual.
- Special category data โ data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, and data concerning a person's sex life or sexual orientation.
- Data subject โ the individual to whom the personal data relates.
- Processing โ any operation performed on personal data, such as collecting, recording, storing, using, sharing, or deleting it.
- Data controller โ the organisation that determines the purposes and means of processing. For this policy, the data controller is Pets on the Green Ltd.
- Data processor โ an organisation that processes personal data on behalf of the controller.
4. Data protection principles
We apply the seven principles of the UK GDPR:
- Lawfulness, fairness and transparency โ we process data legally, fairly, and in a way people understand.
- Purpose limitation โ we collect data only for specified, explicit purposes and do not use it in incompatible ways.
- Data minimisation โ we collect only what we actually need.
- Accuracy โ we keep data accurate and up to date, and correct errors promptly.
- Storage limitation โ we keep data only for as long as we need it.
- Integrity and confidentiality โ we keep data secure against loss, damage, or unauthorised access.
- Accountability โ we take responsibility for how we handle data and can demonstrate our compliance.
5. Lawful bases for processing
Every time we process personal data we identify a lawful basis under Article 6 of the UK GDPR:
| Lawful basis | POTG example |
|---|---|
| Contract | Delivering a booked session or service to a school, family, or organisation. |
| Legitimate interests | Administering our services, keeping business records, and limited marketing to existing contacts. |
| Legal obligation | Meeting employment, tax, and health-and-safety record-keeping duties. |
| Consent | Sending marketing to new contacts, or using photographs where consent is given. |
| Vital interests | Acting in a medical emergency to protect someone's life. |
| Public task | Where we carry out work in the public interest on behalf of a school or local authority. |
Special category data
Where we process special category data, we identify an additional condition under Article 9 โ most commonly explicit consent, substantial public interest, or vital interests. Where required, we maintain an Appropriate Policy Document under Schedule 1 of the Data Protection Act 2018.
โ Back to top6. What we collect
| Category | Examples | Source | Lawful basis |
|---|---|---|---|
| Children attending sessions | Name, age/year group, relevant needs, medical/allergy notes, photos (with consent) | Parents/carers, schools | Contract; consent; vital interests (special category) |
| Parents/carers | Name, contact details, emergency contact, correspondence | The individual | Contract; legitimate interests |
| School/LA contacts | Name, role, work contact details, booking records | The individual, their organisation | Contract; public task; legitimate interests |
| Employees & volunteers | Contact details, recruitment records, DBS status, payroll, training records | The individual | Contract; legal obligation |
| Suppliers | Contact details, contracts, payment details | The individual, their organisation | Contract; legitimate interests |
| Marketing contacts | Name, email address, contact preferences | The individual | Consent; legitimate interests |
7. How we keep data secure
Technical measures
- password-protected and encrypted devices;
- two-factor authentication (2FA) on key accounts;
- reputable cloud providers with UK/EU data residency or appropriate transfer safeguards;
- regular, tested backups;
- confidential handling of email โ using BCC for bulk messages and never sending sensitive data over unencrypted channels.
Organisational measures
- access on a need-to-know basis;
- data protection covered at induction plus an annual briefing;
- secure storage of paper records;
- encrypted and inventoried removable media;
- no storage of personal data on personal devices;
- secure wiping of devices before disposal.
8. Sharing data
We do not sell personal data. We share personal data only where we have a lawful basis to do so, for example with:
- parents and carers;
- schools and local authorities;
- external professionals (with consent, or under our safeguarding duties);
- data processors, under Article 28 data processing agreements;
- statutory authorities;
- others in an emergency.
9. Individual rights
We respond to requests to exercise data protection rights within one calendar month, unless an extension applies. Individuals have the right:
- to be informed;
- of access (see our Subject Access Request procedure);
- to rectification;
- to erasure;
- to restrict processing;
- to data portability;
- to object;
- rights in relation to automated decision-making and profiling.
10. Personal data breaches
Anyone who suspects a personal data breach must report it to the Director immediately. Our Data Breach Response Procedure governs how we respond, including the 72-hour window for notifying the ICO where the breach is reportable.
โ Back to top11. Records of processing (ROPA)
We maintain a Record of Processing Activities in line with Article 30 of the UK GDPR, and we review it annually.
โ Back to top12. Data protection by design and default
We consider data protection from the start of any new system or service. We carry out a Data Protection Impact Assessment (DPIA) for higher-risk processing โ for example, processing children's special category data โ before it goes live.
โ Back to top13. Roles and responsibilities
- Data Controller: Pets on the Green Ltd.
- Data protection lead: Ciera O'Rourke (the Director acts as data protection lead).
- Is a Data Protection Officer (DPO) required? No โ POTG does not meet the Article 37 criteria for a mandatory DPO.
- Day-to-day contact: Ciera O'Rourke, ciera.rose@icloud.com.
14. Training and awareness
- an induction briefing for all;
- an annual refresher for anyone handling personal data;
- the Director keeps up to date with ICO guidance at the annual review.
15. Concerns and complaints
Please contact the Director first with any concern about how we handle personal data. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.
โ Back to top16. Review
We review this policy at least annually, and immediately upon any material change to the law, ICO guidance, our processing activities, or our team.
โ Back to top