Policies
The purpose and scope of this policy statement
The Association for Fostering, Kinship and Adoption (AFKA) Scotland provides services involving or directly relating to children and vulnerable adults.
The services and activities include:
- Chairing or participating in adoption and fostering panels.
- Providing consultations on complex cases involving children and their families or carers.
- Chairing disruption meetings and case reviews.
- Providing a wide range of training and practice development opportunities for practitioners
and carers who are working directly with children. - Participating in family finding events such as Adoption Exchange Days and Adoption Activity Days, where children and prospective adoptive parents are present.
- Undertaking research that may directly involve vulnerable children and their families.
The purpose of this policy statement is:
- To protect children and young people who receive AFKA Scotland ’s services. This includes the children of adults who use our services; and
- To provide those that use our services, including staff and volunteers with the overarching principles that guide our approach to child protection.
This policy statement applies to anyone working on behalf of AFKA Scotland including the Executive Director, the Board of Trustees, paid staff, volunteers, sessional workers, associate staff and students.
Legal framework
This policy has been drawn up on the basis of legislation, policy and guidance that seeks to protect children in Scotland and with reference to the Scottish Government’s National Guidance for child protection in Scotland.
We believe that children and young people should never experience abuse of any kind
- We have a responsibility to promote the welfare of all children and young people, to keep them safe and to practise in a way that protects them.
We recognise that the welfare of the child is paramount
- All children, regardless of age, disability, gender reassignment, ethnicity, religion or belief, sex, or sexual orientation have a right to equal protection from all types of harm or abuse.
- Some children are additionally vulnerable because of the impact of previous experiences, their level of dependency, communication needs or other issues.
- Working in partnership with children, young people, their parents, carers and other agencies is essential in promoting young people’s welfare.
We will seek to keep children and young people safe by:
- Valuing, listening to and respecting them;
- Identifying the Executive Director as the nominated child protection/safeguarding lead along with a nominated member of the board of trustees;
- Developing child protection and safeguarding policies and procedures which reflect best practice (see AFKA Scotland’s Child Protection Policy);
- Using our child protection policy and procedures to share concerns and relevant information with agencies who need to know, and involving children, young people, parents, families and carers appropriately;
- Sharing information about child protection and safeguarding best practice with children, their families, staff and volunteers as part of the training and other services delivered by the organisation;
- Recruiting staff and volunteers safely, ensuring all necessary checks are made;
- Providing effective management for staff and volunteers through supervision, support, training and quality assurance measures;
- Developing a staff handbook that incorporates information about conduct for staff and volunteers;
- Using our procedures to manage any allegations against staff and volunteers appropriately;
- Ensuring that we have effective complaints procedures in place;
- Ensuring that we provide a safe physical environment for any activities or events that we organise by applying health and safety measures in accordance with the law and regulatory guidance; and
- Recording and storing information professionally and securely.
Related policies and procedures
This policy statement should be read alongside our other organisational policies and procedures, in particular the AFKA Scotland’s Child Protection policy which incorporates the procedures for responding to concerns about a child or young person’s well being.
Contact details
Angie Gillies
Nominated Child Protection Lead
Angie.Gillies@AFKAScotland.org
0131 322 8490
1. Our stance on personal data
AFKA Scotland takes your right to privacy seriously. We are committed to protecting your privacy and security and it is important to us that you understand how and why we collect and use information about you. This Privacy Notice explains how and why we use your personal data, to ensure you remain informed and in control of your information.
2. Who are we?
AFKA Scotland is an independent membership organisation for professionals, foster carers and adopters, and anyone else working with or looking after children in or from care, or adults who have been affected by adoption. Our registered name and address is: AFKA Scotland, Pure Offices, Suite 84, 4-5 Lochside Way, Edinburgh Park, Edinburgh, EH12 9DT (Charity No. SC046417).
3. What information do we collect?
We collect only the personal data that we need to provide you with services, fulfil orders and keep in touch. The categories of personal information that we collect, process, store and share include:
- Personal details (name, email address, phone number, postal address);
- Professional details (workplace, job title, subject interests); and
- Details of purchases (training events, workshops and conferences).
4. How do we process your personal data?
AFKA Scotland complies with its obligations under current GDPR and Data Protection legislation by using data only for the purposes for which it was collected; by keeping personal data up-to-date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data. We use your personal data for the following purposes:
- To administer membership records.
- To deliver membership benefits to you (such as providing advice and information, sending newsletters and mailings, running forums).
- To effectively manage and provide commissioned training, workshops and conferences.
- To recruit and manage our employees and volunteers.
- To run our training and events.
- To maintain our own accounts and records.
- To record enquiries submitted to the AFKA Scotland advice line.
- To operate the AFKA Scotland website and deliver the services that you have requested.
- To process your financial payments.
- To keep you informed about news, events, activities and services that are relevant to you.
- To send you information about products and services that relate to your previous interests or where you have requested such information.
5. What is our lawful basis for processing your personal data?
We will only process your personal data where we have a lawful basis (a legal reason allowing us to process personal data) to do so. The categories of lawful basis which apply to our processing of personal data are:
5.1 Consent
Where we have a record that shows you have given us express consent to use your personal data. This applies to the following purposes:
- Direct marketing (if requested to be added to our mailing list); and
- Training, workshop and conference information.
5.2 Legitimate interests
Where we are able to demonstrate a legitimate interest in using your personal data which has been balanced against your own interests, rights and freedoms as the data subject. This applies to the following purposes:
- Direct marketing (if based on e.g. previous purchases);
- Sending email newsletters and upcoming events to members;
- Marketing workshops, training and conferences; and
- Administration of consortium and forum meetings and special interest group meetings.
5.3 Compliance with legal obligations
Where we are required to process your personal data to comply with a common law or statutory obligation. This applies to the following purposes:
- Keeping financial records.
5.4 Contractual necessity
Where it is necessary for us to process your information in order to fulfil our contractual obligations to you, or where you have asked us to do something prior to entering into a contract. This applies to the following purposes:
- Membership administration – signing up new members, renewing and cancelling membership;
- Collecting membership fees;
- Delivering membership benefits – sending mailings and books, organising and facilitating of member meetings and providing information around workshops and conferences relevant to the member;
- Administrating groups – providing information to members regarding upcoming events, workshops, conferences, meetings and training relevant to the member;
- Running training/events/workshops/consultancy services – booking delegates onto conferences and speakers;
- Providing our advice line service; and
- Consultancy work – serving on adoption or fostering panels, chairing disruption meetings or any other specific contracted work carried out for you by AFKA Scotland.
6. Sharing your personal data
Within AFKA Scotland
Your personal data will only be accessible to AFKA Scotland staff who need to process it for the purposes of providing services, fulfilling orders and keeping in touch, and for the purposes of processing payments.
With Third Parties
We sometimes share your personal data with trusted third parties (other organisations or companies that we work with or which provide services to us). For example in compiling a delegate list for meetings, workshops and conferences when circulating information among our members by e-mail.
We apply the following policies to those organisations to keep your data safe and protect your privacy:
- We provide only the information they need to perform their specific services;
- They may only use your data for the exact purposes we specify in our contract with them;
- We work closely with them to ensure that your privacy is respected and protected at all times; and
- If we stop using their services, any of your data held by them will either be deleted or rendered anonymous.
7. How long will we keep your personal data?
Whenever we collect or process your personal data, we will only keep it for as long as necessary for the purpose for which it was collected.
At the end of that retention period, your data will either be deleted completely or anonymised, for example by aggregation with other data so that it can be used in a non-identifiable way for statistical analysis and business planning. Some examples of customer data retention periods:
- Your membership – while the membership is current and for 3 years after the membership expires.
- Financial data: records of sales e.g. invoices and receipts – for 6 years plus the current financial year.
- Making an enquiry to the Advice Line – for 6 years.
- Attendance at our training, workshop, conferences or other events – while membership is current and for 3 years after the membership expires.
- You working for us as a member of staff, associate or volunteer – payroll records for 6 years, health and safety records for 3 years, basic employment details indefinitely.
8. Further processing
If we wish to use your personal data for a new purpose, not covered by this Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Whenever necessary, we will seek your prior consent to the new processing.
9. How will we secure your personal information?
We know how much data security matters to you. With this in mind, we will treat your data with the utmost care and take all appropriate steps to protect it. We employ a variety of physical and technical measures to keep your data safe and to prevent unauthorised access to or use or disclosure of your personal information.
Electronic data and databases are stored on secure computer systems and we control who has access to information (using both physical and electronic means). Our staff all receive data protection training and we have a set of detailed data protection procedures that personnel are required to follow when handling personal data.
We secure access to all transactional areas of our websites using ‘https’ technology.
Access to your personal data is password-protected, and sensitive data (such as payment card information) is secured by SSL encryption.
10. Your rights and your personal data
We want to ensure that you remain in control of your personal data. Part of this is making sure you understand your legal rights.
An overview of your different rights
You have the right to request:
- Access to the personal data we hold about you, free of charge in most cases.
- The correction of your personal data when incorrect, out of date or incomplete.
- The deletion of your personal data, for example, when you withdraw consent, or object and we have no legitimate overriding interest, or once the purpose for which we hold the data has come to an end.
- That we stop using your personal data for direct marketing (either through specific channels, or all channels).
- That we stop any consent-based processing of your personal data after you withdraw that consent.
- Review by Brenda Reilly, AFKA Scotland Business Support and Finance Manager, of any decision.
You have the right to request a copy of any information about you that AFKA Scotland holds at any time, and also to have that information corrected if it is inaccurate. To ask for your information, please email or write to Brenda Reilly, Data Protection Co-ordinator, AFKA Scotland, Pure Offices, Suite 84, 4-5 Lochside Way, Edinburgh Park, Edinburgh, EH12 9DT.
To ask for your information to be amended, please update your online account (where applicable), or speak to Brenda Reilly. If we choose not to action your request we will explain to you the reasons for our refusal.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
Where we rely on our legitimate interest
In cases where we are processing your personal data on the basis of our legitimate interest, you can ask us to stop for reasons connected to your individual situation. We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data.
Direct marketing
You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request.
Checking your identity
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice. If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
11. Complaints
AFKA Scotland tries to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously and encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office. You can contact them by calling 0303 123 1113 (local rate) or email scotland@ico.org.uk.
12. Contacting us
If you have any questions or concerns about this Privacy Notice and our privacy practices, please in the first instance contact the Data Protection Co-ordinator at AFKA Scotland by email at brenda.reilly@afkascotland.org.
For further information on how your information is used, how we maintain the security of your information, and your rights to access information we hold on you, please contact us:
By email at info@afkascotland.org.
Or write to us at:
Data Protection Co-ordinator
AFKA Scotland
Pure Offices
Suite 84
4-5 Lochside Way
Edinburgh Park
Edinburgh
EH12 9DT
13. Changes to this Privacy Notice
If we modify this Privacy Notice, we will post the revised version here, with an updated revision date. Please check back periodically, and especially before you provide any personally identifiable information.
Last revision: July, 2026
AFKA Scotland is committed to providing a good quality service, and we welcome feedback on all aspects of our work from everyone who uses our services.
We are always glad to hear from people who want to compliment a particular member of staff or provide us with positive feedback on our service delivery. If you send us a compliment we will ensure it is shared appropriately with staff.
We welcome specific comments on the service you have received, particularly any improvement ideas you may have.
If you have a complaint, we would encourage you to speak directly with the person with whom you have been dealing. We hope that most problems can be sorted out at this stage. If not, you should contact the Executive Director who will try to resolve the matter with you.
If the Executive Director is unable to resolve the matter to your satisfaction, or if the complaint is about the Executive Director, you will be asked to write to the Board of Trustees to make a formal complaint.
The Complaints Procedure
The Complaints Procedure is to help individuals and organisations to make suggestions and complaints where they feel that an informal complaint has not resolved the matter to their satisfaction.
How to Make a Complaint
You can make a complaint verbally to a staff member. Your complaint will be put in writing with your agreement, or if you prefer, a representative or colleague may do this for you. The staff member, representative or colleague will then pass the complaint to the Executive Director of AFKA Scotland.
or
You can make a complaint in writing directly to the Executive Director who will:
- Let you know they have received it within 7 working days;
- Send you a copy of AFKA Scotland’s Complaints Procedure; and
- Look into your complaint.
You can involve a representative or colleague both in supporting you to make your complaint and in any meetings where the complaint is being looked into.
The Executive Director will contact you within two working weeks to arrange a time to discuss your complaint either by phone or in person. Following the discussions, you will get a written reply to Your complaint within a further two working weeks.
If you are not satisfied with the written reply, you can ask to meet with the member of staff concerned and the Executive Director to discuss the matter in detail and try to resolve it.
We will write to you with the result of the complaints meeting, usually within two working weeks of the meeting.
If you are not satisfied with the result of the complaint you may appeal to the Chairperson of AFKA Scotland’s Board of Trustees, as long as you do this within 28 days of getting the written note of the result. The Chairperson will contact you to discuss your complaint and seek a resolution. You will get a written reply to your complaint to the Chairperson within two working weeks of the discussion.
If you are still not satisfied, you can contact the Chairperson of the Board of Trustees who will convene a small panel of people who have not been directly involved in the complaint to consider the issues raised. You will be entitled to submit further information for consideration by the panel. You will be told the outcome of the panel’s consideration as quickly as possible. The decision of the panel will be final.
Contact details
If you wish to share a compliment, make a suggestion or lodge a complaint please write to:
AFKA Scotland
Pure Offices
Suite 84
4-5 Lochside Way
Edinburgh Park
Edinburgh
EH12 9DT
Alternatively you can email us at info@afkascotland.org or call 0131 322 8490.
Overview of the General Data Protection Regulation
The Charity will ensure that all personal data that it holds will be:
- processed lawfully, fairly and in a transparent manner;
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
- adequate, relevant and limited to what is necessary;
- accurate and kept up-to-date;
- kept in a form which permits identification of data subjects for no longer than is necessary;
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
1. Introduction to the GDPR
Under the EU General Data Protection Regulations (GDPR), the Association for Fostering, Kinship and Adoption Scotland (herein after referred to as “the Charity”) is required to comply with the GDPR and undertakes to do so. Throughout this policy document, numbers prefixed by “Art:“ in brackets (eg: {Art:5}) refer to the relevant Article(s) in the GDPR.
For ease of access, extracts of relevant GDPR Articles are contained in the Appendix to this Policy.
2. Definitions {Art:4}
The definitions of terms used in this policy are the same as the definitions of those terms detailed in Article-4 of the GDPR.
Data Subject
A data subject is an identifiable individual person about whom the Charity holds personal data.
Contact Information
For the purposes of this Policy, “Contact Information” means any or all of the person’s:
full name (including any preferences about how they like to be called);
- full postal address;
- telephone and/or mobile number(s);
- e-mail address(es);
- social media IDs/Usernames (eg: Facebook, Skype, Hangouts, WhatsApp)
3. Principles of the GDPR {Art:5}
The Charity will ensure that all personal data that it holds will be:
- processed lawfully, fairly and in a transparent manner in relation to individuals.
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals; and
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
4. Lawful Processing
The Charity will obtain, hold and process all personal data in accordance with the GDPR for the following lawful purposes. In all cases the information collected, held and processed will include Contact Information (as defined in 2 above).
4.1 By Consent
- People who are interested in, and wish to be kept informed of, the activities of the Charity.
- Subject to the person’s consent, this may include information selected and forwarded by the Charity on activities relevant to those of the Charity by other organisations.
Note: this will not involve providing the person’s personal data to another organisation.
The information collected may additionally contain details of any particular areas of interest about which the person wishes to be kept informed.
The information provided will be held and processed solely for the purpose of providing the information requested by the person.
4.2 By Contract
People who sell goods and/or services to, and/or purchase goods and/or services from the Charity.
The information collected will additionally contain details of:
- The goods/services being sold to or purchased from the Charity.
- Bank and other details necessary and relevant to the making or receiving of payments for the goods/services being sold to or purchased from the Charity.
The information provided will be held and processed solely for the purpose of managing the contract between the Charity and the person for the supply or purchase of goods/services.
4.3 By Legal Obligation
Employees (Human Resources)
Where there is a legal obligation on the Charity to collect, process and share information with a third party – eg: the legal obligations to collect, process and share with HM Revenue & Customs payroll information on employees of the Charity, the information provided will be held, processed and shared with others solely for the purpose meeting the Charity’s legal obligations.
Taxation (HM Revenue & Customs)
For the purpose of managing an employee’s PAYE and other taxation affairs the information collected will additionally contain details, as required by HM Revenue & Customs, of:
- The person’s National Insurance Number.
- The person’s taxation codes.
- The person’s salary/wages, benefits, taxation deductions & payments.
- Such other information as may be required by HM Revenue & Customs.
Pensions
For the purpose of managing an employee’s statutory pension rights the information collected will additionally contain details, as required by the Charity’s pension scheme of:
- The person’s National Insurance Number.
- The person’s salary/wages, benefits, taxation deductions & payments.
- Such other information as may be required by the pension scheme.
4.4 By Vital Interest
The Charity undertakes no activities which require the collection, holding and/or processing of personal information for reasons of vital interest.
4.5 By Public Task
The Charity undertakes no public tasks which require the collection, holding and/or processing of personal information.
4.6 Legitimate Interest
Volunteers, Including Trustees
In order to be able to operate efficiently, effectively and economically, it is in the legitimate interests of the Charity to hold such personal information on its volunteers and trustees as will enable the Charity to communicate on matters relating to the operation of the charity, eg:
- the holding of meetings.
- providing information about the Charity’s activities – particularly those activities which, by their nature, are likely to be of particular interest to individual volunteers/trustees.
- seeking help, support and advice from volunteers/trustees, particularly where they have specific knowledge and experience.
- ensuring that any particular needs of the volunteer/trustee are appropriately and sensitively accommodated when organising meetings and other activities of the Charity.
5. Individual Rights
Note: The following clauses are taken primarily from the guidance provided by the Office of the Information Commissioner,
5.1 The right to be informed {Arts 12-14}
When collecting personal information, the Charity will provide to the data subject free of charge, a Privacy Policy written in clear and plain language which is concise, transparent, intelligible and easily accessible containing the following information:
- Identity and contact details of the controller
- Note: where the organisation has a controller’s representative and/or a data protection officer, their contact details should also be included
- Purpose of the processing and the lawful basis for the processing
- The legitimate interests of the controller or third party, where applicable
- Categories of personal data
- Not applicable if the data are obtained directly from the data subject
- Any recipient or categories of recipients of the personal data
- Details of transfers to third country and safeguards
- Retention period or criteria used to determine the retention period
- The existence of each of data subject’s rights
- The right to withdraw consent at any time, where relevant
- The right to lodge a complaint with a supervisory authority
- The source the personal data originates from and whether it came from publicly accessible sources
Not applicable if the data are obtained directly from the data subject
- Whether the provision of personal data is part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data
Not applicable if the data are NOT obtained directly from the data subject
- The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences
In the case of data obtained directly from the data subject, the information will be provided at the time the data are obtained.
In the case that the data are not obtained directly from the data subject, the information will be provided within a reasonable period of the Charity having obtained the data (within one month), or,
if the data are used to communicate with the data subject, at the latest, when the first communication takes place; or
if disclosure to another recipient is envisaged, at the latest, before the data are disclosed.
5.2 The right of access {Art:15}
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him/her are being processed, and, where that is the case, access to his/her personal data and the information detailed in the Charity’s relevant Privacy Policy:
5.3 The right to rectification {Art:16}
The data subject shall have the right to require the controller without undue delay to rectify any inaccurate or incomplete personal data concerning him/her.
5.4 The right to erase {The right to be forgotten} {Art:17}
Except where the data are held for purposes of legal obligation or public task (4.3 or 4.5) the data subject shall have the right to require the controller without undue delay to erase any personal data concerning him/her.
Note: This provision is also known as “The right to be forgotten”.
5.5 The right to restrict processing {Art:18}
Where there is a dispute between the data subject and the Controller about the accuracy, validity or legality of data held by the Charity the data subject shall have the right to require the controlled to cease processing the data for a reasonable period of time to allow the dispute to be resolved.
5.6 The right to data portability {Art:20}
Where data are held for purposes of consent or contract (4.1 or 4.2) the data subject shall have the right to require the controller to provide him/her with a copy in a structured, commonly used and machine-readable format of the data which he/she has provided to the controller, and have the right to transmit those data to another controller without hindrance.
5.7 The right to object {Art:21}
- The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him/her which is based Public Task or Legitimate Interest (5 or 4.6), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
- Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him/her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
- At the latest at the time of the first communication with the data subject, the right referred to in paragraphs a) and d) shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.
5.8 Rights in relation to automated decision making and profiling {Art:22}
Except where it is: a) based on the data subject’s explicit consent, or b) necessary for entering into, or performance of, a contract between the data subject and a data controller; the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him/her or similarly significantly affects him/her.
6. Operational Policies & Procedures – The Context
The Association for Fostering, Kinship and Adoption Scotland (the Charity) is a small Charity holding just a small amount of non-sensitive data on a small number of people.
The Trustees understand and accept their responsibility under the EU General Data Protection Regulation (GDPR) to ensure that the organisation holds all personal data securely and uses it only for legitimate purposes with the knowledge and approval of the data subjects.
By the following operational policies and procedures, the Trustees undertake to uphold the principles and requirements of the GDPR in a manner which is proportionate to the nature of the personal data being held by the Charity. The policies are based on the Trustees’ assessment, in good faith, of the potential impacts on both the Charity and its data subjects of the personal data held by the Charity being stolen, abused, corrupted or lost.
7. Personnel
7.1 Data Protection Officer
In the considered opinion of the Trustees the scope and nature of the personal data held by the Charity is not enough to warrant the appointment of a Data Protection Officer. Accordingly, no Data Protection Officer is appointed.
7.2 Data Controller
Angela Gillies, Executive Director and Brenda Reilly, Business Support and Finance Manager both AFKA Scotland are the Data Controllers for the Charity.
7.3 Data Processor
Each employee of AFKA Scotland is a Data Processor for the Charity. The Charity will not knowingly outsource its data processing to any third party (eg: Google G-Suite, Microsoft OneDrive) except as provided for in the section “Third Party Access to Data”.
7.4 Access to Data
Except where necessary to pursue the legitimate purposes of the Charity, only the Data Controllers and Data Processors shall have access to the personal data held by the Charity.
7.5 Training
The Data Controllers and Data Processors will periodically undergo appropriate training, be updated on any changes in legislation commensurate with the scale and nature of the personal data that the Charity holds and processes under the GDPR.
8. Collecting & Processing Personal Data
The Charity collects a variety of personal data commensurate with the variety of purposes for which the data are required in the pursuit of its charitable objects.
All personal data will be collected, held and processed in accordance with the relevant Data Privacy Notice provided to data subjects as part of the process of collecting the data.
A Data Privacy Notice will be provided, or otherwise made accessible, to all persons on whom the Charity collects, holds and processes data covered by the GDPR. The Data Privacy Notice provided to data subjects will detail the nature of the data being collected, the purpose(s) for which the data are being collected and the subjects rights in relation to the Charity’s use of the data and other relevant information in compliance with the prevailing GDPR requirements.
9. Information Technology
9.1 Data Protection by Design/Default
Inasmuch as:
- none of the Charity’s volunteers/Trustees are data protection professionals.
- it would be a disproportionate use of charitable funds to employ a data protection professional, given the scale and nature of the personal data held by the Charity; the Trustees will seek appropriate professional advice commensurate with its data protection requirement whenever:
- they are planning to make significant changes to the ways in which they process personal data.
- there is any national publicity about new risks (eg: cyber-attacks)
which might adversely compromise the Charity’s legitimate processing of personal data covered by the GDPR. Personal data will never be transmitted electronically (eg: by e-mail) unless securely encrypted.
9.2 Updated Data Storage and Processing Statement
The scale and nature of the personal data held by the Charity does not require the purchase of dedicated computers for the processing of personal data.
The Charity does not use external or removable storage devices for the retention or backup of personal data. Instead, all personal data is securely stored and processed within the Charity’s Microsoft 365 environment, specifically through Microsoft SharePoint and Microsoft Teams. These platforms provide controlled access, encryption, and audit capabilities that support GDPR compliance.
All data held within Microsoft 365 is backed up through Datto Backupify, ensuring that the Charity’s information is protected against accidental deletion, corruption, or loss. Backupify provides secure, automated cloud‑to‑cloud backup and recovery for SharePoint, Teams, and associated Microsoft 365 services.
Whilst Data Processors may access and work with personal data on their computers or laptops, no GDPR‑regulated personal data is stored locally on these devices. Any temporary working files created during processing are deleted once the task is complete.
The Charity’s day‑to‑day IT requirements, including the management and security of Microsoft 365 services, are supported by Kick ICT who provide ongoing technical support and ensure that systems remain secure and operational.
The Charity maintains appropriate access controls and permissions within Microsoft 365 to ensure that personal data is only accessible to authorised Data Processors and is protected from unauthorised access, misuse, or accidental disclosure.
9.3 Data Processing Location
Data Processors shall only process the Charity’s personal data in a secure location, and not in any public place, eg: locations whether the data could be overlooked by others, Computers/laptops in use for data processing will not be left unattended at any time.
9.4 Data Backups
To protect against loss of data by accidental corruption of the data or malfunction of a removable data storage device (including by physical damage), all the Charity’s personal data shall be backed up periodically and whenever any significant changes (additions, amendments, deletions) are made to the data.
As far as is reasonably practical, all files containing personal data covered by the GDPR will be encrypted.
9.5 Obsolete or Dysfunctional Equipment (Disposal of Removable Storage Media)
Equipment used to hold personal data, whether permanently or as interim working copies, which come to the end of their useful working life, or become dysfunctional, shall be disposed of in a manner which ensures that any residual personal data held on the equipment cannot be recovered by unauthorised persons.
Inasmuch as:
- this will be a relatively infrequent occurrence.
- techniques for data recovery and destruction are constantly evolving.
- none of the Trustees has relevant up-to-date expert knowledge of data cleansing.
equipment which becomes obsolete or dysfunctional shall not be disposed of immediately. Instead, it will be stored securely while up-to-date expert advice on the most appropriate methods for its data cleansing and disposal can be sought and implemented.
10. Data Subjects
10.1 The Rights of Data Subjects
In compliance with the GDPR the Charity will give data subjects the following rights.
These rights will be made clear in the relevant Data Privacy Notice provided to data subjects:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right of erasure {LO} Also referred to as “The right to be forgotten”
- the right to restrict processing;
- the right to data portability; {LO} {LI}
- the right to object; {SC} {Co} {LO}
- the right not to be subjected to automated decision making, including profiling.
The above rights are not available to data subjects when the legal basis on which the Charity is holding and processing their data are:
{SC} Subject Consent
{Co} Contractual obligation
{LO} Legal Obligation
{LI} Legitimate Interest
10.2 Rights of Access, Rectification and Erasure
Data subjects will be clearly informed of their right to access their personal data and to request that any errors or omissions be corrected expeditiously.
Such access shall be given, and the correction of errors or omissions shall be made free of charge provided that such requests are reasonable and not trivial or vexatious.
There is no prescribed format for making such requests provided that:
- the request is made in writing, signed and dated by the data subject (or their legal representative);
- the data claimed to be in error or missing is clearly and unambiguously identified.
- the corrected or added data is clear and declared by the subject to be complete and accurate.
It will be explained to subjects who make a request to access their data and/or to have errors or omissions corrected, or that their data be erased, that, while their requests will be actioned as soon as is practical there may be delays where the appropriate volunteers or staff to deal with the request do not work on every normal weekday.
Where a data subject requests that their data be rectified or erased, the Data Controller and Data Processor will ensure that the rectifications or erasure will be applied to all copies of the subject’s personal data including those copies which are in the hands of a Third Party for authorised data processing.
10.3 Right of Portability
The Charity will only provide copies of personal data to the subject (or the subject’s legal representative) on written request.
The Charity reserves the right either:
- to decline requests for portable copies of the subject’s personal data when such requests are unreasonable (ie: excessively frequent) or vexatious;
or
- to make a reasonable charge for providing the copy.
10.4 Data Retention Policy
Personal data shall not be retained for longer than:
- In the case of data held by subject consent:
the period for which the subject consented to the Charity holding their data;
- in the case of data held by legitimate interest of the charity:
the period for which that legitimate interest applies. For example: in the case of data subjects who held a role, such as a volunteer, with the Charity the retention period is that for which the Charity reasonably has a legitimate interest in being able to identify that individual’s role in the event of any retrospective query about it;
- in the case of data held by legal obligation:
the period for which the Charity is legally obliged to retain those data.
The Charity shall regularly – not less than every 6 months – review the personal data which it holds and remove any data where retention is no longer justified. Such removal shall be made as soon as is reasonably practical, and in any case no longer than 20 working days (of the relevant Data Processor) after retention of the data was identified as no longer justified.
11. Privacy Impact Assessment
11.1 Trustees’ Data
The volume of personal data is very low – less than 12 individuals
The sensitivity of the data is low-moderate: the most sensitive data being date of birth, previous names and previous/current addresses. The risk of data breach is small as the data is rarely used, with the majority of the data being held for a combination of legal obligation and legitimate interest.
Overall impact: LOW
11.2 Volunteers’/Members’ Data
There are currently under 10 volunteers who provide periodic support to the Charity and so the volume of personal data is low. The sensitivity of the data is low: the most sensitive data being an e-mail address. The risk of data breach is small – primarily the accidental disclosure of names and e-mail addresses.
Overall impact: LOW
11.3 Supporters’ & Enquirers’ Data
The volume of personal data is low-moderate. The sensitivity of the data is low: the most sensitive data being an e-mail address. The risk of data breach is small – primarily the accidental disclosure of names and e-mail addresses.
Overall impact: LOW
12. Third Party Access to Data
Under no circumstance will the Charity share with, sell or otherwise make available to Third Parties any personal data except where it is necessary and unavoidable to do so in pursuit of its charitable objects as authorised by the Data Controller.
Whenever possible, data subjects will be informed in advance of the necessity to share their personal data with a Third Party in pursuit of the Charity’s objects.
Before sharing personal data with a Third Party the Charity will take all reasonable steps to verify that the Third Party is, itself, compliant with the provisions of the GDPR and confirmed in a written contract. The contract will specify that:
- The Charity is the owner of the data;
- The Third Party will hold and process all data shared with it exclusively as specified by the instructions of the Data Controller;
- The Third Party will not use the data for its own purposes;
- The Third Party will adopt prevailing industry standard best practice to ensure that the data are held securely and protected from theft, corruption or loss;
- The Third Party will be responsible for the consequences of any theft, breach, corruption or loss of the Charity’s data (including any fines or other penalties imposed by the Information Commissioner’s Office) unless such theft, breach, corruption or loss was a direct and unavoidable consequence of the Third Party complying with the data processing instructions of the Data Controller
- The Third Party will not share the data, or the results of any analysis or other processing of the data with any other party without the explicit written permission of the Data Controller;
- The Third Party will securely delete all data that it holds on behalf of the Charity once the purpose of processing the data has been accomplished.
- The Charity does not, and will not, transfer personal data out of the EU.
13. Data Breach
In the event of any data breach coming to the attention of the Data Controller, they will immediately inform the Trustees and notify the Information Commission’s Office.
In the event that full details of the nature and consequences of the data breach are not immediately accessible (eg: because Data Processors do not work on every normal weekday) the Data Controller will bring that to the attention of the Information Commissioner’s Office and undertake to forward the relevant information as soon as it becomes available.
14. Privacy Policy & Privacy Notices
The Charity will have a Privacy Policy and appropriate Privacy Notices which it will make available to everyone on whom it holds and processes personal data, in accordance with 5.1.
In the case of data obtained directly from the data subject, the Privacy Notice will be provided at the time the data are obtained.
In the case that the data are not obtained directly from the data subject, the Privacy Notice will be provided within a reasonable period of the Charity having obtained the data (within one month), or,
if the data are used to communicate with the data subject, at the latest, when the first communication takes place; or
if disclosure to another recipient is envisaged, at the latest, before the data are disclosed.
Appendix
Extracts of Relevant Articles from the GDPR
- Article 4: Definitions
For the purposes of this Regulation:
- ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- ‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future;
- ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
- ‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
- ‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;
- ‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
- ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- ‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
- ‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
- ‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
- ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
- ‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;
- ‘main establishment’ means the registered offices of Adoption and fostering Alliance Scotland.:
- ‘information society service’ means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council (¹);
- ‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.
¹ Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services (OJ L 241, 17.9.2015, p. 1).
- Article 6: Lawfulness of processing
- Processing shall be lawful only if and to the extent that at least one of the following applies:
- the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the controller is subject;
- processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
- Processing shall be lawful only if and to the extent that at least one of the following applies:
Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.
- Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points (c) and (e) of paragraph 1 by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations as provided for in Chapter IX.
- The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:
- Union law; or
- Member State law to which the controller is subject.
The purpose of the processing shall be determined in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The Union or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued.
- Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject’s consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia:
- any link between the purposes for which the personal data have been collected and the purposes of the intended further processing;
- the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller;
- the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10;
- the possible consequences of the intended further processing for data subjects;
- the existence of appropriate safeguards, which may include encryption or pseudonymisation.
- Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject
- The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means.
- The controller shall facilitate the exercise of data subject rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject.
- The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.
- If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
- Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either:
- charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
- refuse to act on the request.
- The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.
- Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject.
- The information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner a meaningful overview of the intended processing. Where the icons are presented electronically, they shall be machine-readable.
- The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of determining the information to be presented by the icons and the procedures for providing standardised icons.
- Article 13: Information to be provided where personal data are collected from the data subject
- Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:
- the identity and the contact details of the controller and, where applicable, of the controller’s representative;
- the contact details of the data protection officer, where applicable;
- the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;
- where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;
- the recipients or categories of recipients of the personal data, if any;
- where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.
- In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing:
- the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
- the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;
- where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- the right to lodge a complaint with a supervisory authority;
- whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data;
- the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
- Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.
- Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.
- Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:
- Article 24: Responsibility of the Controller
- Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
- Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
- Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.
- Article 25: Data protection by design and by default
- Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
- The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.
- An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.
Original September, 2019 (Updated January 2026)