GDPR Statement

GDPR Compliance Policy (UK GDPR & Data Protection Act 2018)

Version: Dec 2025 (Draft)
Owner: Chair
Approved by: Board of Trustees
Review frequency: Annually or following any significant change/incident
Last updated: 26 January 2026


Contents

1. Purpose

2. Scope

3. Key Definitions

4. Roles and Responsibilities

5. Systems and Information We Hold

6. Lawful Basis for Processing

7. Special Category Data and Criminal Offence Data

8. Transparency and Privacy Information

9. Data Subject Rights

10. Security and Access Controls

11. Retention and Disposal

12. Data Sharing and Third Parties

13. International Transfers

14. Data Breaches

15. Data Protection by Design and DPIAs

Appendix A – Subject Access Request (SAR) Procedure

Appendix B – SAR Response Template (Email)

Appendix C – Logs and Registers (templates)



1. Purpose

This policy sets out how StopSO UK processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It establishes standards for lawful, fair and transparent processing, and supports StopSO UK’s commitment to protecting privacy while delivering its charitable objectives.

2. Scope

This policy applies to all trustees, staff, contractors, volunteers, and any person acting on behalf of StopSO UK (“StopSO people”). It covers all personal data processed by StopSO UK, including information stored in StopSO UK’s CRM, Microsoft OneDrive/Microsoft 365, email systems, and finance/payment systems (PayPal and QuickBooks).

3. Key Definitions
  • Personal data: information relating to an identified or identifiable living individual.
  • Special category data: personal data revealing racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic/biometric data, health data, or data concerning sex life or sexual orientation.

  • Criminal offence data: personal data relating to criminal convictions or offences, allegations, or related security measures.

  • Processing: any operation performed on personal data (e.g., collecting, recording, storing, sharing, deleting).

  • Data controller: the organisation deciding how and why personal data is processed (StopSO UK).

  • SAR: Subject Access Request, a request by an individual to obtain a copy of their personal data and related information.

  • CRM: to be added

4. Roles and Responsibilities

4.1 Board of Trustees

The Board has overall accountability for data protection compliance and ensuring that appropriate policies, oversight and resources are in place.

4.2 Data Protection Lead (DPL)

StopSO UK appoints a Data Protection Lead responsible for coordinating GDPR compliance, maintaining relevant logs (e.g., SAR and breach logs), supporting staff, and acting as the point of contact for data protection matters.

4.3 StopSO People

All StopSO people must follow this policy, keep personal data secure, report suspected breaches promptly, and only access personal data where necessary for their role.

5. Systems and Information We Hold

StopSO UK receives referrals and enquiries from individuals who may have sexually harmed, may be at risk of causing sexual harm, and from survivors of sexual offending and violence, and other clients related to this topic. This information is stored and managed within StopSO UK’s CRM.

5.1 CRM (Referrals and Enquiries)

Data held in the CRM may include: names, contact details, referral narratives, relevant risk information, safeguarding concerns where identified, and administrative notes necessary to manage referral handling and signposting. This may include special category and criminal offence data.

5.2 Microsoft OneDrive / Microsoft 365

StopSO UK stores documents relating to governance, policies, training administration, referral administration, and compliance records within Microsoft OneDrive/Microsoft 365. Access permissions are managed on a role/need-to-know basis.

5.3 Email

StopSO UK email accounts may contain personal data relating to referrals, membership, training, complaints and general correspondence. Emails should be treated as part of StopSO UK’s record system and handled securely.

5.4 Payments and Finance (PayPal / QuickBooks)

StopSO UK may process personal data for donations, Gift Aid where applicable, training payments, invoicing, receipts, and accounting records. Payment processing may be carried out via PayPal and recorded in QuickBooks.

5.5 Clinical Notes

StopSO UK does not hold therapy clinical notes. StopSO members providing therapy do so independently and are responsible for their own clinical record keeping, privacy notices, and professional compliance. StopSO UK may hold limited administrative referral information necessary to facilitate signposting and network processes.

6. Lawful Basis for Processing

StopSO UK identifies and records the lawful basis for processing personal data depending on the purpose. StopSO UK may rely on:

  • Contract – e.g. training bookings, paid services, membership administration where applicable.

  • Legal obligation – e.g. accounting, Gift Aid compliance, statutory record keeping.

  • Legitimate interests – e.g. managing enquiries/referrals appropriately, charity administration, quality assurance, preventing misuse and ensuring safe operations.

  • Consent – e.g. marketing communications/newsletters where consent is required and appropriate.

Where StopSO UK relies on consent, individuals must be able to withdraw consent easily and without detriment (subject to lawful retention requirements).

7. Special Category Data and Criminal Offence Data

Due to the nature of StopSO UK’s work, referrals and enquiries may include special category data (including information about health, trauma, sex life, or sexual orientation) and may also include criminal offence data. StopSO UK applies enhanced safeguards to such information, including restricted access, secure storage and appropriate information-sharing controls.

8. Transparency and Privacy Information

StopSO UK provides clear privacy information through its website Privacy Notice and at the point data is collected where appropriate. StopSO UK aims to be transparent about what data it holds, why it is held, how long it is retained, and who it may be shared with.

9. Data Subject Rights

Individuals have rights under UK GDPR, including:

  • Right to be informed

  • Right of access (SAR)

  • Right to rectification

  • Right to erasure (in certain circumstances)

  • Right to restrict processing (in certain circumstances)

  • Right to object (in certain circumstances)

  • Right to data portability (where applicable)

  • Rights relating to automated decision-making (StopSO UK does not use automated decision-making for significant decisions)

  • Right to complain to the ICO

10. Security and Access Controls

StopSO UK takes appropriate technical and organisational measures to protect personal data. This includes access controls, password protection, and the use of secure cloud systems. Personal data must not be downloaded, shared or copied to personal devices or accounts unless authorised and necessary.

11. Retention and Disposal

StopSO UK will retain personal data only for as long as necessary for the purposes it was collected, including legal and regulatory obligations. Retention periods are set out in StopSO UK’s retention schedule. Personal data must be securely deleted or destroyed when no longer required.

12. Data Sharing and Third Parties

StopSO UK does not sell personal data. StopSO UK may share personal data with trusted service providers (e.g. IT, cloud storage, payment processors) and professional advisers where necessary. StopSO UK may also share information where required by law, where safeguarding requires it, or where it is necessary and proportionate for safety and risk management.

13. International Transfers

StopSO UK is UK-based. Some third-party suppliers may process data outside the UK. Where international transfers occur, StopSO UK will ensure appropriate safeguards are in place, such as contractual protections and risk-based supplier review.

14. Data Breaches

All suspected personal data breaches must be reported immediately to the Data Protection Lead. StopSO UK will contain and assess the breach, record it in the breach log, and notify the ICO within 72 hours where required. Affected individuals will be notified where the breach is likely to result in a high risk to their rights and freedoms.

15. Data Protection by Design and DPIAs

StopSO UK considers privacy and security at the start of new projects, process changes, or new systems. A Data Protection Impact Assessment (DPIA) will be carried out where required, particularly where high-risk processing is likely.



Appendix A – Subject Access Request (SAR) Procedure

This procedure explains how StopSO UK responds to Subject Access Requests under UK GDPR.

A1. How to make a SAR

Requests should be submitted in writing to: admin@stopso.org.uk

StopSO UK will also accept SARs made through other written channels but may redirect to the official mailbox for processing.

A2. Identity verification

StopSO UK may request proof of identity before releasing personal data, particularly where the request relates to sensitive information or where StopSO cannot be confident of the requester’s identity.

A3. Timeframe

StopSO UK will respond within one month of receiving the request (and identity verification, where required). If the request is complex, StopSO UK may extend the deadline by up to two further months and will notify the requester.

A4. Searches and systems

The Data Protection Lead (or delegate) will search relevant systems including:

  • CRM (referral/enquiry records)

  • Microsoft OneDrive/M365 document storage

  • StopSO UK email accounts

  • Finance systems (QuickBooks) and payment records (PayPal) as applicable

A5. Redactions and exemptions

StopSO UK will redact third-party personal data where necessary and may apply lawful exemptions (for example, where disclosure would adversely affect the rights and freedoms of others, or where other exemptions apply).

A6. Format of response

StopSO UK will normally provide the response electronically (e.g. PDF). Where appropriate, StopSO may provide secure links or encrypted attachments.

A7. Record keeping

StopSO UK will log all SARs (date received, deadline, outcome, and any extension rationale) in the SAR Log.


Appendix B – SAR Response Template (Email)

Subject: Your Subject Access Request – StopSO UK

Dear [Name],

Thank you for your request dated [date]. Please find attached the personal data StopSO UK holds relating to you, along with information about how and why we process it.

If you believe any information is inaccurate, you may request rectification. If you have any questions about this response, please contact us at info@stopso.org.uk.

Kind regards,

[Name]

Data Protection Lead, StopSO UK


Appendix C – Logs and Registers (templates)

StopSO UK maintains the following internal records (templates available):

  • SAR Log

  • Data Breach Log

  • Record of Processing Activities (ROPA-lite)

  • Data Sharing Register (where applicable)




This site uses cookies that enable us to make improvements, provide relevant content, and for analytics purposes. For more details, see our Cookie Policy. By clicking Accept, you consent to our use of cookies.