๐Ÿพ PawSteps ยท Pets on the Green Ltd

Data Protection Policy

UK GDPR & Data Protection Act 2018 ยท Version 1.0 ยท Approved April 2026 ยท Next review April 2027 ยท Data protection lead: Ciera O'Rourke

1. Statement of commitment

Pets on the Green Ltd is committed to protecting the personal data of everyone whose information we hold โ€” including children, parents and carers, school and local authority contacts, employees, volunteers, suppliers, and members of the public.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, guided by the principles set out by the Information Commissioner's Office (ICO).

โ†‘ Back to top

2. Scope

This policy applies to all personal data processed by Pets on the Green Ltd (POTG), in any format or medium, and to everyone who processes personal data on our behalf, including:

  • the Director
  • employees
  • volunteers
  • students
  • contractors
โ†‘ Back to top

3. Definitions

  • Personal data โ€” information relating to an identified or identifiable living individual.
  • Special category data โ€” data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, and data concerning a person's sex life or sexual orientation.
  • Data subject โ€” the individual to whom the personal data relates.
  • Processing โ€” any operation performed on personal data, such as collecting, recording, storing, using, sharing, or deleting it.
  • Data controller โ€” the organisation that determines the purposes and means of processing. For this policy, the data controller is Pets on the Green Ltd.
  • Data processor โ€” an organisation that processes personal data on behalf of the controller.
โ†‘ Back to top

4. Data protection principles

We apply the seven principles of the UK GDPR:

  1. Lawfulness, fairness and transparency โ€” we process data legally, fairly, and in a way people understand.
  2. Purpose limitation โ€” we collect data only for specified, explicit purposes and do not use it in incompatible ways.
  3. Data minimisation โ€” we collect only what we actually need.
  4. Accuracy โ€” we keep data accurate and up to date, and correct errors promptly.
  5. Storage limitation โ€” we keep data only for as long as we need it.
  6. Integrity and confidentiality โ€” we keep data secure against loss, damage, or unauthorised access.
  7. Accountability โ€” we take responsibility for how we handle data and can demonstrate our compliance.
โ†‘ Back to top

5. Lawful bases for processing

Every time we process personal data we identify a lawful basis under Article 6 of the UK GDPR:

Article 6 lawful bases and POTG examples
Lawful basisPOTG example
ContractDelivering a booked session or service to a school, family, or organisation.
Legitimate interestsAdministering our services, keeping business records, and limited marketing to existing contacts.
Legal obligationMeeting employment, tax, and health-and-safety record-keeping duties.
ConsentSending marketing to new contacts, or using photographs where consent is given.
Vital interestsActing in a medical emergency to protect someone's life.
Public taskWhere we carry out work in the public interest on behalf of a school or local authority.

Special category data

Where we process special category data, we identify an additional condition under Article 9 โ€” most commonly explicit consent, substantial public interest, or vital interests. Where required, we maintain an Appropriate Policy Document under Schedule 1 of the Data Protection Act 2018.

โ†‘ Back to top

6. What we collect

Categories of personal data we process
CategoryExamplesSourceLawful basis
Children attending sessions Name, age/year group, relevant needs, medical/allergy notes, photos (with consent) Parents/carers, schools Contract; consent; vital interests (special category)
Parents/carers Name, contact details, emergency contact, correspondence The individual Contract; legitimate interests
School/LA contacts Name, role, work contact details, booking records The individual, their organisation Contract; public task; legitimate interests
Employees & volunteers Contact details, recruitment records, DBS status, payroll, training records The individual Contract; legal obligation
Suppliers Contact details, contracts, payment details The individual, their organisation Contract; legitimate interests
Marketing contacts Name, email address, contact preferences The individual Consent; legitimate interests
โ†‘ Back to top

7. How we keep data secure

Technical measures

  • password-protected and encrypted devices;
  • two-factor authentication (2FA) on key accounts;
  • reputable cloud providers with UK/EU data residency or appropriate transfer safeguards;
  • regular, tested backups;
  • confidential handling of email โ€” using BCC for bulk messages and never sending sensitive data over unencrypted channels.

Organisational measures

  • access on a need-to-know basis;
  • data protection covered at induction plus an annual briefing;
  • secure storage of paper records;
  • encrypted and inventoried removable media;
  • no storage of personal data on personal devices;
  • secure wiping of devices before disposal.
โ†‘ Back to top

8. Sharing data

We do not sell personal data. We share personal data only where we have a lawful basis to do so, for example with:

  • parents and carers;
  • schools and local authorities;
  • external professionals (with consent, or under our safeguarding duties);
  • data processors, under Article 28 data processing agreements;
  • statutory authorities;
  • others in an emergency.
International transfers. Where personal data is transferred outside the UK, we rely on an adequacy decision, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (SCCs), supported by a transfer risk assessment.
โ†‘ Back to top

9. Individual rights

We respond to requests to exercise data protection rights within one calendar month, unless an extension applies. Individuals have the right:

  • to be informed;
  • of access (see our Subject Access Request procedure);
  • to rectification;
  • to erasure;
  • to restrict processing;
  • to data portability;
  • to object;
  • rights in relation to automated decision-making and profiling.
Children's data. Requests are normally made by a parent or person with parental responsibility, taking account of the child's wishes and capacity. In the UK, the default age at which a child is presumed competent to exercise their own data protection rights is 13.
โ†‘ Back to top

10. Personal data breaches

Anyone who suspects a personal data breach must report it to the Director immediately. Our Data Breach Response Procedure governs how we respond, including the 72-hour window for notifying the ICO where the breach is reportable.

โ†‘ Back to top

11. Records of processing (ROPA)

We maintain a Record of Processing Activities in line with Article 30 of the UK GDPR, and we review it annually.

โ†‘ Back to top

12. Data protection by design and default

We consider data protection from the start of any new system or service. We carry out a Data Protection Impact Assessment (DPIA) for higher-risk processing โ€” for example, processing children's special category data โ€” before it goes live.

โ†‘ Back to top

13. Roles and responsibilities

  • Data Controller: Pets on the Green Ltd.
  • Data protection lead: Ciera O'Rourke (the Director acts as data protection lead).
  • Is a Data Protection Officer (DPO) required? No โ€” POTG does not meet the Article 37 criteria for a mandatory DPO.
  • Day-to-day contact: Ciera O'Rourke, ciera.rose@icloud.com.
โ†‘ Back to top

14. Training and awareness

  • an induction briefing for all;
  • an annual refresher for anyone handling personal data;
  • the Director keeps up to date with ICO guidance at the annual review.
โ†‘ Back to top

15. Concerns and complaints

Please contact the Director first with any concern about how we handle personal data. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.

โ†‘ Back to top

16. Review

We review this policy at least annually, and immediately upon any material change to the law, ICO guidance, our processing activities, or our team.

โ†‘ Back to top