Privacy Notice

Data Protection Policy

Version 1.0

U3 – Data Protection

DATA PROTECTION OFFICER: Karen Seddon, karen.seddon@kidsplanetdaynurseries.co.uk

ICO REGISTRATION NUMBER: Z2484469 (Tier 3 Data Controller)

Aim: to outline the Kids Planet approach to responsible and compliant processing of personal data.

Scope: Kids Planet customers, employees, registered children and all other persons about whom Kids Planet hold and process personal information.

Access: Kids Planet website, Dayforce, Sharepoint

Personal Data and Data Subjects

Personal data is any information about an individual from which that person can be identified. There are “special categories” of more sensitive personal data which require a higher level of protection, such as information about a person’s health or sexual orientation.

Details of the data processed by Kids Planet in relation to our families, includes:

  • Personal data – data that personally identifies you, such as name and contact details
  • Special Category data – data that may reveal a characteristic of identity, such as race or sexual orientation or your health. Examples include passports and health declarations.
  • Child data.

As young children are unaware of their rights as data subjects, additional protections are built into our processing activities, to ensure that child data is processed and shared in the child’s best interests.

  • Criminal Offence Data, such as references to DBS certificates and self-disclosure forms.

A data subject is the person to whom personal information relates. Where the data subject is a child, a parent with parental responsibility can exercise

Legislation

  • We comply with requirements set out in the Statutory Framework for the Early Years Foundation Stage (EYFS) and accompanying regulations, as well as legislation related to safeguarding children.
  • We also comply with the requirements of the UK GDPR, the Data Protection Act 2018 (DPA) and the Data (Use and Access) Act 2025 (DUAA), in upholding the rights of data subjects and ensuring all personal data is processed fairly and responsibly.

Kids Planet is a Data Controller.

We are committed to protecting the privacy and security of personal data.

Data Protection Principles

There are seven key principles outlined in the legislation and to which we adhere:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation: we process personal data only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.
  3. Data minimisation: we process data that is relevant to the purposes we have told you about and limit processing only to those purposes.
  4. Accuracy: we do all we reasonably can to ensure the personal data we hold, is accurate and up to date.
  5. Storage limitation: We retain personal data only as long as necessary for the purposes we have told You about.
  6. Integrity and confidentiality: we do all we reasonably can to ensure personal data is held securely.
  7. Accountability: we accept responsibility as a data controller to demonstrate compliance with data protection legislation.

Data Subject Rights

UK GDPR affords data subject with individual rights. Not all of these rights are absolute and this means that in most cases, a balanced approach to entitlement and interests is promoted by the regulations.

  1. Right to be informed about the processing of personal data. Kids Planet actively inform colleagues and parents about the data we process. Our policies and privacy notices are transparent and accessible.
  2. Right to access personal data held by Kids Planet. Please refer to our Subject Access Request policy for further details.
  3. Right to rectify data that is incorrect or incomplete. Kids Planet will consider whether the data is inaccurate and other factors, such as whether an inaccurate account (such as a false allegation) was rectified but the inaccurate account was lawfully retained. If Kids Planet believes the information to be correct, the data will be supplemented by an account from the data subject.
  4. Right to erasure – sometimes known as ‘the right to be forgotten’. Kids Planet will consider any deletion requests and whether it is necessary for us to retain information due to an overriding obligation or legitimate interest.
  5. Right to restrict processing. Requests for data restriction are an alternative to erasure and may be temporary, such as while the lawfulness or accuracy of data processing is being verified or in order to support a legal claim.
  6. Right to data portability where data subjects provide us with data that is processed electronically, either on the lawful basis of consent or performance of contract, they can request machine readable copies (such as on a spreadsheet) and it may be that this right applies.
  7. Right to object to the processing of your data in certain circumstances. All objections are given due consideration and data subjects have an absolute right in all circumstances to object to direct marketing. If a data subject objects to receiving promotional offers for example, Kids Planet will no longer contact them directly with this information.

Lawful bases

There are 6 lawful bases for processing personal data, set out in UK GDPR. The recently enacted DUAA adds a 7 th lawful basis. Kids Planet must have a lawful basis for every processing activity. For each activity, one of the 7 lawful bases is chosen and documented.

  1. Consent from the data subject. Where the data subject is a registered child, the parent can consent on the child’s behalf.
  2. Performance of contract, such as a parent contract or an employment contract. If the processing is necessary in order for obligations under the contract to be fulfilled or for a contracted service to be provided.
  3. Legal obligation, such as under health and safety or safeguarding legislation.
  4. Vital interests which means processing of data is necessary to protect the life of the data subject or another person. An example could be sharing of medical information with paramedics in an emergency.
  5. Public task such as an official function or task in the public interest. An example could be sharing of personal data with a Public Health agency in order to contain an outbreak.
  6. Legitimate Interests if the processing activity is necessary for the legitimate interests of Kids Planet or a third party. Where legitimate interests is chosen as a lawful basis, we must complete a Legitimate Interests Risk Assessment that facilitates careful balancing of data subject rights against legitimate interests, as well as the necessity of the activity to those interests.
  7. Recognised legitimate interests if the processing is necessary for achieving the legitimate interests of Kids Planet or a third party and the legitimate interest is pre-defined as lawful, such as crime prevention, emergency situations and safeguarding children.

The lawful bases chosen for broad categories of data processing activities are included in our privacy notices, as well as internal documents such as our Register of Processing Activities.

Roles and responsibilities

Information Commissioners Office (ICO)

The ICO is the UK independent regulator for data protection, privacy and information rights. Kids Planet is registered with the ICO as a data controller and the Kids Planet DPO is named on our registration.

Kids Planet Board

The Board has overall responsibility for information governance across the Kids Planet group. The Board is kept abreast of non-compliance and emerging issues, by the Data Protection Officer.

Data Protection Officer (DPO)

The DPO is and must be, independent from childcare operations and is afforded autonomy for ensuring compliance with UK GDPR and all associated legislation.

DPO tasks are set out in UK GDPR:

  • Inform and advise including risk-based advice
  • Monitor compliance including policies and procedures, training and audit
  • Oversee Data Protection Impact Assessments
  • Directly co-operate with the ICO
  • Be the first point of contact with the ICO

Chief Technical Officer, IT Department and Data Team

Employees in these roles oversee cyber security and associated risks, including the security and protection of personal information.

These teams offer expert guidance in information technology and electronic systems, ensuring robust controls are enforced and tested.

These teams are also responsible for training and awareness in these areas.

Childcare Operations leaders and the People Team

These teams directly oversee, monitor, audit and embed compliance in our settings.

All employees

Employees are responsible for their own compliance with Kids Planet policies and procedures, attendance at mandatory training and raising of any breach or compliance issue with line managers and / or the DPO.

Resources

Kids Planet provide colleagues with the tools they need to be responsible data processors, including:

  • Secure operating systems with compliant providers.
  • Remote working safeguards.
  • Confidential waste facilities.
  • Secure archiving facilities.
  • Confidential system for visitor sign-in.

Data protection forms part of basic Kids Planet training, delivered to all colleagues, by way of induction training.

Managers and Central Support colleagues undertake further training on RISE in how to remain compliant with UK GDPR.

Relevant policies

  • U2 – Compliments and Complaints
  • U3 – Data Protection
  • U3b – Employee Privacy
  • U3c – Parent and Child Privacy
  • U3d – CCTV
  • U3e – Data breach
  • U3f – Subject Access Request
  • U3g – Retention and Archiving