top of page

Data Protection, GDPR, Record retention and Privacy Notice Policy

Image by Omar Al-Ghossen

Policy Statement

 

I am committed to protecting the privacy, confidentiality and personal information of the children and families who use my childminding service.  I am registered with the ICO (the Information Commissioner's Office) - registration number PZ3302605.

I recognise that children and their families have a right to expect that personal information will be collected, stored and used responsibly and securely.  I expect parents to keep private and confidential any sensitive information they may accidently learn about my family, setting, or the other children and families attending Daisy Dolls, unless it is a child protection issue.

This policy explains how I comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the record-keeping and information requirements applicable to early years providers.

 

I will only collect information that is necessary for the safe, effective management of my childminding service and the care, learning and development of children at Daisy Dolls.  BCP Local Authority, Department for Education, Ofsted and The Statutory Framework EYFS all require me to collect relevant information on children and their families.

Data Protection Principles

 

I will ensure that personal information is:

  • Processed lawfully, fairly and transparently.

  • Collected for specific and legitimate purposes.

  • Adequate, relevant and limited to what is necessary.

  • Accurate and kept up to date where necessary.

  • Kept only for as long as necessary.

  • Stored securely and protected from unauthorised access, loss or misuse.

  • Treated confidentially.

I will take particular care when handling information relating to children, recognising that children require additional protection.

Information I Collect

I will collect:

  • Child’s name, date of birth and address.

  • Child's NHS number.

  • Parent/carer names, contact details dates of birth and National Insurance numbers.

  • Who has parental responsibility for the child

  • Emergency contact information including names, addresses and contact numbers.

  • Child's doctor's name and contact number.

  • Health visitor/health clinic and dentist details.

  • Information about the child’s health, allergies, medical needs and dietary requirements.

  • Information about immunisations.

  • Information about additional needs or disabilities.

  • Ethnic group

  • Religion

  • Home language

  • Information necessary to safeguard the child.

  • Attendance and collection records.

  • Permissions and consent records.

  • Accident, incident and existing injury records.

  • Medication records.

  • Child development, learning and observation records.

  • Information required for funding or statutory purposes.

  • Relevant information provided by other professionals, with appropriate authority.

I will not routinely collect information that is unnecessary for the care, safety or administration of the child.

How Personal Information Is Used

Personal information will be used to:

  • Provide safe and appropriate care.

  • Meet the child’s individual needs.

  • Support learning and development.

  • Contact parents/carers in an emergency.

  • Administer medication or respond to health needs.

  • Meet safeguarding responsibilities.

  • Meet legal and regulatory requirements.

  • Communicate with parents/carers.

  • Maintain required records.

  • Process funding where applicable.

  • Work with other professionals where this is necessary and lawful.

  • Respond to Ofsted or other authorised regulatory requests.

I keep documentation including name, address, national insurance number, date of birth and tracking data on the Local Authority funding forms using the legal basis of  'contractual necessity'.  This data is held in paper format and online and I am required to retain these forms by the Local Authority for audit, after which time paper copies will be shredded.  It is used for claiming Early Education Funding, the termly Headcount and annual Early Years Census (England).

Personal information will not be used for unrelated purposes without a lawful basis for doing so.

 

I record all accidents.  This will either be using Tapestry or on a paper copy.

I will notify PACEY of any accidents which may result in an insurance claim, e.g. an accident resulting in a doctor or hospital visit.  PACEY will log and acknowledge receipt of the correspondence and forward the information to the company providing my public liability insurance policy to enable a claim number to be allocated.  I am using the Professional Association for Childcare and Early Years (PACEY) public liability insurance from Royal & Sun Alliance plc.  Policy Number RTT161353.  The total life of the policy is 21 years and 4 months to enable the child to make a claim against the policy at a later date.

I will inform Ofsted, BCP Safeguarding Children Partnership, and the Health and Safety 
Executive of any significant injuries, accidents or deaths as soon as possible.

I will share information if it is in a child's best interests to do so.  For example, in a medical emergency I will share medical information wit a healthcare professional.

What I do with your data and with whom it is shared

I am required to ensure the information I collect about you and your child/ren is treated confidentially and only shared when there is a need for it to be shared, ideally with your permission in advance of sharing, for example –

  • I share information with other settings or agencies involved in your child’s care as required by the EYFS.

  • I am required to share a copy of the child’s 2-year progress check with their health visitor as required by the EYFS.

  • I am required to share information with my Local Authority for the purposes of the 9 months +, 2, 3-4-year-old funding offer and any extra funding I might claim for the child (see the Local Authority Privacy Notice for more details).

  • I share information about income and expenses including when requested, your invoices and payments with HMRC and Tax Credits.

 

Lawful Basis for Processing

I will process personal information using an appropriate lawful basis under UK GDPR.

 

This may include:

  • Legal obligation – where the law requires me to keep or provide information.

  • Contract – where information is necessary to provide the childminding service agreed with parents/carers.

  • Legitimate interests – where appropriate and where the interests and rights of the child and family are protected.

  • Vital interests – where information is necessary to protect someone’s life or safety.

  • Consent – where consent is the appropriate lawful basis.

Where special category information, such as health information, is processed, I will ensure that an appropriate additional condition for processing is met.

 

Confidentiality

 

Information about children and families will be treated as confidential.

I will not discuss a child’s personal circumstances with other families, friends or members of the public.

Information may only be shared with appropriate people or organisations when:

  • There is a legal requirement.

  • It is necessary to protect a child or another person from harm.

  • It is necessary for the child’s care.

  • Appropriate consent has been obtained, where consent is required.

  • A professional or regulatory body has a lawful right to request the information.

Confidential information will not be discussed in public places where it could be overheard.

 

Safeguarding Information

Safeguarding takes priority over confidentiality.

 

If I have a concern that a child may be at risk of harm, I have a duty of care to follow the BCP Safeguarding Children Partnership procedures and make a referral without parental consent.

 

This may include contacting the relevant safeguarding authority, children’s services, police or other appropriate agencies.

 

I will follow my Safeguarding and Welfare Policy and applicable local safeguarding procedures.

 

Photographs and Videos

Photographs or videos of children will only be taken and used in accordance with the permissions agreed with parents/carers.

 

I will:

  • Store photographs securely.

  • Avoid identifying children unnecessarily.

  • Not use photographs for publicity or social media without appropriate permission.

  • Not share photographs with other families.

  • Remove photographs when they are no longer required.

Parents/carers may withdraw consent for uses that rely on consent.

Electronic and Paper Records

I hold 2 different types of records about a child and their parents.

Developmental records including:

  • Information from parents.

  • Details about the child’s learning and development at home.

  • A copy of the child’s statutory 2-year progress check.

  • Observations of the child’s learning.

  • Assessments, individual planning and regular progress summaries.

Personal records including:

  • Personal details required by the statutory frameworks and/or the Local Authority for funding forms – see above.

  • Contractual details including attendance registers and fees information.

  • Emergency details including your contact details and records of the child’s health and care needs (see above).

  • Safeguarding and child protection records.

  • Any records required to support the child such as shared information from other agencies and professionals.

Most of the information I collect about parents and their child is statutory.  When information is optional, I will let parents know that they have a choice whether to share it with me or not.

 

Paper records will be kept securely and, where appropriate, in a locked or restricted-access location.

Electronic records kept on the computer, in iCloud, Google Drive or Dropbox, and also accessible on the phone and iPad will be protected using appropriate security measures, which include: password protection, two step verification, device security, screen locks, secure backups, up-to-date software and security measures.

The computer is for sole use of my childminding business (Daisy Dolls).  No other member of my family or anyone else has access to the protected password or the computer.  My phone is password protected and has face recognition and fingerprint recognition enabled.  I will take reasonable steps to prevent unauthorised access to personal information.

Backup files if used will be encrypted and stored on a memory stick which I will lock away when not being used.  Firewall and virus protection software are in place.

Tapestry, the online learning journal, is compliant with GDPR.

Emails, Messaging and Communication

When communicating electronically with parents/carers, I will take reasonable steps to protect personal information.

I will avoid including unnecessary sensitive information in ordinary messages.

Where appropriate, parents/carers will be asked to confirm important information or decisions in writing so that an accurate record can be maintained.

Data Breaches

A personal data breach may include information being:

 

  • Lost or stolen.

  • Accidentally disclosed to the wrong person.

  • Accessed without permission.

  • Accidentally deleted or destroyed.

  • Sent to the wrong email address or recipient.

If a breach occurs, I will assess what has happened and take immediate steps to contain and minimise the risk.

Where required by UK GDPR, I will report the breach to the Information Commissioner’s Office (ICO) within 72 hours and inform affected individuals where necessary.

I will record significant data breaches and any action taken.

Children’s and Parents’ Rights

Individuals have rights under UK GDPR, subject to applicable exemptions.

These may include the right to:

  • Be informed about how personal information is used.

  • Request access to personal information.

  • Request correction of inaccurate information.

  • Request restriction of processing in certain circumstances.

  • Object to certain processing.

  • Request deletion in circumstances where there is no legal requirement to retain the information.

Some rights are limited where I have a legal obligation to retain information or where safeguarding responsibilities apply.

Requests relating to personal information will be dealt with within the applicable legal timescales.

Subject Access Requests

Parents/carers may request access to personal information held about themselves or, where appropriate, their child.

Requests should normally be made in writing.

I will verify the identity of the person making the request and consider whether any information must be withheld, for example information relating to another individual or information where disclosure could compromise safeguarding.

Records Retention

 

I will not keep personal information indefinitely.

Records will be retained only for as long as necessary to meet:

  • Legal requirements.

  • Regulatory requirements.

  • Safeguarding responsibilities.

  • Financial and tax requirements.

  • Insurance requirements.

  • Legitimate business needs.

Examples of records that may be retained include:

  • Medication  records - to comply with the EYFS and the Limitation Act 1980, I keep Accident, Injury, First Aid Records and Medication Administration Records using the legal basis of 'Legal Obligation' until the child is 21 years and 4 months old for insurance requirements.

  • Parent contracts and agreements - attached to the Accident, Injury, First Aid records and Medication Administration Records I retain parent contracts, the child record form and Attendance register using the legal basis of 'Vital Interests' to provide additional evidence of compliance with the EYFS.

  • Child registration/admission information - retained  during the child's attendance and for the required period afterwards.

  • Attendance records - retained in accordance with EYFS and legal requirements up to a child is 21 years and 4 months old.

  • Accident and Incident records - In accordance with EYFS, legal and safeguarding requirements (see below).

  • Safeguarding records - retained in accordance with safeguarding requirement and relevant guidance.  ICO advise is that this data should be kept for a minimum between Ofsted inspections or within the Ofsted inspection cycle which is 3 years.

  • Learning and Development records - retained during the child's attendance and for an appropriate period afterwards.

  • Financial, invoices and tax records - retained in accordance with HMRC requirements of 6 years.

  • Consent and permission forms - retained for as long as relevant and required.

  • Complaints records - retained in accordance with EYFS, Ofsted and legal requirements.

  • Data protection records - retained for as long as necessary to demonstrate compliance.

I have been advised by the Information Commissioners Office that it is reasonable to keep a record of parent mobile phone numbers on my mobile phone and parent email addresses on my computer for up to 1 financial year after your child leaves my setting, so I can contact the parent if necessary to clarify, for example, accounts information or details relating to their Tax Credits/Early Education Funding claim (if relevant).  The data will be deleted after this period.

If I close my setting or on my retirement, I will keep documentation for as long as legally required by the purpose for which it was collected.  There is no absolute duty to encrypt data stored online but I will keep it as securely as possible during the retention period (see Article 32 of GDPR for more information).

You have the right to ask for information held about you and your child to be withdrawn.  This is called the ‘right to erasure’ in GDPR.  However, if I need to keep information because it is legally required then exceptions to the ‘right to erasure’ apply.  I will make a decision about each erasure request individually – please speak to me for more information.

 

Where a specific legal or regulatory retention period applies, that requirement will take priority.

At the end of the retention period, records will be securely destroyed or permanently deleted.

Disposal of Information

Confidential paper records will be securely shredded.

Electronic records will be securely dust deleted when they are no longer required.

I will take reasonable steps to ensure that information cannot be reconstructed or accessed after disposal.

Privacy Notice

Who I Am

I am the data controller for the personal information processed by my childminding setting.

 

Childminder: Denise Barrett

Setting: Daisy Dolls

Contact: 07866 246351

Why I Collect Information

I collect information about children and families so that I can:

  • Provide safe and suitable childcare.

  • Meet children’s individual needs.

  • Support children’s learning and development.

  • Meet safeguarding responsibilities.

  • Communicate with parents/carers.

  • Comply with legal and regulatory requirements.

  • Maintain appropriate records.

  • Meet financial, insurance and business obligations.

Who Information May Be Shared With

Where necessary and lawful, information may be shared with:

  • Parents/carers.

  • Ofsted.

  • Local authority services.

  • Safeguarding and children’s services.

  • Health professionals.

  • Emergency services.

  • Other professionals involved in supporting the child.

  • HMRC or other authorities where legally required.

  • Insurance providers or legal advisers where necessary.

I will only share information that is necessary and appropriate.

Your Privacy

Daisy Dolls has taken the 'Dorset Pledge':

 

I pledge to uphold the principles and processes that support the fair and lawful processing and sharing of personal information as outlined in the Dorset Pledge. I understand that by committing to these principles and processes, I am helping pledge partners meet their statutory obligations while adhering to UK data protection legislation. My goal is to ensure that the residents of Dorset have total confidence in the accuracy, consistency, and security of their data. I will do my part to protect personal information and maintain the trust of the community by following best practices and implementing appropriate measures to safeguard data.'

Parents/carers can ask me questions about the information I hold and how it is used.

If you have a concern about how I have handled personal information, please speak to me in the first instance.

 

If you remain dissatisfied, you have the right to raise a concern with the Information Commissioner’s Office (ICO).

Data Protection Responsibilities

As a childminder, I am responsible for ensuring that personal information is handled appropriately.

 

I will:

  • Keep information secure.

  • Keep records accurate.

  • Follow appropriate retention periods.

  • Respect confidentiality.

  • Report and manage data breaches.

  • Review this policy regularly.

  • Keep up to date with relevant data protection requirements.

© 2026

 Daisy Doll Childminder

not for reuse
Web Design by Jack Barrett
bottom of page