Version: Dec 2025 (Draft)
Owner: Chair
Approved by: Board of Trustees
Review frequency: Annually or following any significant change/incident
Last updated: 26 January 2026
5. Systems and Information We Hold
6. Lawful Basis for Processing
7. Special Category Data and Criminal Offence Data
8. Transparency and Privacy Information
10. Security and Access Controls
12. Data Sharing and Third Parties
15. Data Protection by Design and DPIAs
Appendix A – Subject Access Request (SAR) Procedure
Appendix B – SAR Response Template (Email)
Appendix C – Logs and Registers (templates)
This policy sets out how StopSO UK processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It establishes standards for lawful, fair and transparent processing, and supports StopSO UK’s commitment to protecting privacy while delivering its charitable objectives.
This policy applies to all trustees, staff, contractors, volunteers, and any person acting on behalf of StopSO UK (“StopSO people”). It covers all personal data processed by StopSO UK, including information stored in StopSO UK’s CRM, Microsoft OneDrive/Microsoft 365, email systems, and finance/payment systems (PayPal and QuickBooks).
Special category data: personal data revealing racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic/biometric data, health data, or data concerning sex life or sexual orientation.
Criminal offence data: personal data relating to criminal convictions or offences, allegations, or related security measures.
Processing: any operation performed on personal data (e.g., collecting, recording, storing, sharing, deleting).
Data controller: the organisation deciding how and why personal data is processed (StopSO UK).
SAR: Subject Access Request, a request by an individual to obtain a copy of their personal data and related information.
CRM: to be added
4.1 Board of Trustees
The Board has overall accountability for data protection compliance and ensuring that appropriate policies, oversight and resources are in place.
4.2 Data Protection Lead (DPL)
StopSO UK appoints a Data Protection Lead responsible for coordinating GDPR compliance, maintaining relevant logs (e.g., SAR and breach logs), supporting staff, and acting as the point of contact for data protection matters.
4.3 StopSO People
All StopSO people must follow this policy, keep personal data secure, report suspected breaches promptly, and only access personal data where necessary for their role.
StopSO UK receives referrals and enquiries from individuals who may have sexually harmed, may be at risk of causing sexual harm, and from survivors of sexual offending and violence, and other clients related to this topic. This information is stored and managed within StopSO UK’s CRM.
5.1 CRM (Referrals and Enquiries)
Data held in the CRM may include: names, contact details, referral narratives, relevant risk information, safeguarding concerns where identified, and administrative notes necessary to manage referral handling and signposting. This may include special category and criminal offence data.
5.2 Microsoft OneDrive / Microsoft 365
StopSO UK stores documents relating to governance, policies, training administration, referral administration, and compliance records within Microsoft OneDrive/Microsoft 365. Access permissions are managed on a role/need-to-know basis.
5.3 Email
StopSO UK email accounts may contain personal data relating to referrals, membership, training, complaints and general correspondence. Emails should be treated as part of StopSO UK’s record system and handled securely.
5.4 Payments and Finance (PayPal / QuickBooks)
StopSO UK may process personal data for donations, Gift Aid where applicable, training payments, invoicing, receipts, and accounting records. Payment processing may be carried out via PayPal and recorded in QuickBooks.
5.5 Clinical Notes
StopSO UK does not hold therapy clinical notes. StopSO members providing therapy do so independently and are responsible for their own clinical record keeping, privacy notices, and professional compliance. StopSO UK may hold limited administrative referral information necessary to facilitate signposting and network processes.
StopSO UK identifies and records the lawful basis for processing personal data depending on the purpose. StopSO UK may rely on:
Contract – e.g. training bookings, paid services, membership administration where applicable.
Legal obligation – e.g. accounting, Gift Aid compliance, statutory record keeping.
Legitimate interests – e.g. managing enquiries/referrals appropriately, charity administration, quality assurance, preventing misuse and ensuring safe operations.
Consent – e.g. marketing communications/newsletters where consent is required and appropriate.
Where StopSO UK relies on consent, individuals must be able to withdraw consent easily and without detriment (subject to lawful retention requirements).
Due to the nature of StopSO UK’s work, referrals and enquiries may include special category data (including information about health, trauma, sex life, or sexual orientation) and may also include criminal offence data. StopSO UK applies enhanced safeguards to such information, including restricted access, secure storage and appropriate information-sharing controls.
StopSO UK provides clear privacy information through its website Privacy Notice and at the point data is collected where appropriate. StopSO UK aims to be transparent about what data it holds, why it is held, how long it is retained, and who it may be shared with.
Individuals have rights under UK GDPR, including:
Right to be informed
Right of access (SAR)
Right to rectification
Right to erasure (in certain circumstances)
Right to restrict processing (in certain circumstances)
Right to object (in certain circumstances)
Right to data portability (where applicable)
Rights relating to automated decision-making (StopSO UK does not use automated decision-making for significant decisions)
Right to complain to the ICO
StopSO UK takes appropriate technical and organisational measures to protect personal data. This includes access controls, password protection, and the use of secure cloud systems. Personal data must not be downloaded, shared or copied to personal devices or accounts unless authorised and necessary.
StopSO UK will retain personal data only for as long as necessary for the purposes it was collected, including legal and regulatory obligations. Retention periods are set out in StopSO UK’s retention schedule. Personal data must be securely deleted or destroyed when no longer required.
StopSO UK does not sell personal data. StopSO UK may share personal data with trusted service providers (e.g. IT, cloud storage, payment processors) and professional advisers where necessary. StopSO UK may also share information where required by law, where safeguarding requires it, or where it is necessary and proportionate for safety and risk management.
StopSO UK is UK-based. Some third-party suppliers may process data outside the UK. Where international transfers occur, StopSO UK will ensure appropriate safeguards are in place, such as contractual protections and risk-based supplier review.
All suspected personal data breaches must be reported immediately to the Data Protection Lead. StopSO UK will contain and assess the breach, record it in the breach log, and notify the ICO within 72 hours where required. Affected individuals will be notified where the breach is likely to result in a high risk to their rights and freedoms.
StopSO UK considers privacy and security at the start of new projects, process changes, or new systems. A Data Protection Impact Assessment (DPIA) will be carried out where required, particularly where high-risk processing is likely.
This procedure explains how StopSO UK responds to Subject Access Requests under UK GDPR.
A1. How to make a SAR
Requests should be submitted in writing to: admin@stopso.org.uk
StopSO UK will also accept SARs made through other written channels but may redirect to the official mailbox for processing.
A2. Identity verification
StopSO UK may request proof of identity before releasing personal data, particularly where the request relates to sensitive information or where StopSO cannot be confident of the requester’s identity.
A3. Timeframe
StopSO UK will respond within one month of receiving the request (and identity verification, where required). If the request is complex, StopSO UK may extend the deadline by up to two further months and will notify the requester.
A4. Searches and systems
The Data Protection Lead (or delegate) will search relevant systems including:
CRM (referral/enquiry records)
Microsoft OneDrive/M365 document storage
StopSO UK email accounts
Finance systems (QuickBooks) and payment records (PayPal) as applicable
A5. Redactions and exemptions
StopSO UK will redact third-party personal data where necessary and may apply lawful exemptions (for example, where disclosure would adversely affect the rights and freedoms of others, or where other exemptions apply).
A6. Format of response
StopSO UK will normally provide the response electronically (e.g. PDF). Where appropriate, StopSO may provide secure links or encrypted attachments.
A7. Record keeping
StopSO UK will log all SARs (date received, deadline, outcome, and any extension rationale) in the SAR Log.
Subject: Your Subject Access Request – StopSO UK
Dear [Name],
Thank you for your request dated [date]. Please find attached the personal data StopSO UK holds relating to you, along with information about how and why we process it.
If you believe any information is inaccurate, you may request rectification. If you have any questions about this response, please contact us at info@stopso.org.uk.
Kind regards,
[Name]
Data Protection Lead, StopSO UK
StopSO UK maintains the following internal records (templates available):
SAR Log
Data Breach Log
Record of Processing Activities (ROPA-lite)
Data Sharing Register (where applicable)
This site uses cookies that enable us to make improvements, provide relevant content, and for analytics purposes. For more details, see our Cookie Policy. By clicking Accept, you consent to our use of cookies.