Data Protection Policy

1. Introduction

Somerset Equus is committed to protecting the privacy and security of personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and current guidance issued by Somerset County Council. This policy outlines our responsibilities, procedures, and expectations regarding the handling of personal information.

2. Scope

This policy applies to all employees, volunteers, contractors, and any other individuals who process personal data on behalf of Somerset Equus. It covers all personal data processed, regardless of format or storage medium.

3. Key Principles
  • Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and in a transparent manner.
  • Purpose Limitation: Data will only be collected for specified, explicit, and legitimate purposes.
  • Data Minimisation: Only data necessary for operational purposes will be collected and processed.
  • Accuracy: We ensure that personal data is accurate and kept up to date.
  • Storage Limitation: Personal data and records will be retained in line with current legislation and best practice guidance. The retention period will vary depending on whether the data relates to young people or adults: records for young people will be kept for the legally required period, which is typically longer due to safeguarding and statutory requirements, while records for adults will be retained only as long as necessary in accordance with relevant legal and regulatory obligations. Somerset Equus will ensure all data is securely disposed of once the appropriate retention period has elapsed.
  • Integrity and Confidentiality: Data will be processed securely to prevent unauthorised access, loss, or damage.
4. Legal Basis for Processing

Somerset Equus processes personal data based on one or more lawful bases under UK GDPR, including consent, contractual necessity, legal obligation, and legitimate interest. Where required, explicit consent will be obtained from data subjects.

5. Data Subject Rights

Individuals have the right to access their data, request rectification or erasure, restrict processing, object to processing, and request data portability. Somerset Equus will respond to such requests in accordance with statutory requirements.

6. Security Measures

Appropriate organisational and technical measures are in place to safeguard personal data. These include secure storage solutions, access controls, regular staff training, and compliance checks. Any data breaches will be reported and managed in line with Somerset County Council guidance and the Information Commissioner’s Office requirements.

7. Data Sharing and Transfers

Personal data will only be shared with authorised parties and in accordance with legal requirements. Transfers outside the UK will be subject to adequate protection mechanisms, such as Standard Contractual Clauses or other approved safeguards.

8. Training and Awareness

All staff and volunteers receive regular training on data protection requirements and best practices, including updates from Somerset County Council and relevant national legislation.

9. Review and Updates

This policy will be reviewed annually, or as required following legislative changes or updated guidance from Somerset County Council. Any amendments will be communicated promptly to all relevant parties.

10. Contact and Complaints

For queries or concerns regarding data protection at Somerset Equus, please contact the Data Protection Officer. Complaints may also be directed to the Information Commissioner’s Office if unresolved. This policy is effective from the 31 st of December 2025 and remains under regular review to ensure ongoing compliance with data protection legislation and local council guidance.