Privacy and Data Protection (GDPR) Policy

SPM Development Services Limited Privacy and Data Protection (GDPR) Policy September 2026

Reviewed and Updated: September 2026
Next Review: September 2027, or sooner if data protection legislation or statutory guidance changes.
Approved by: Simon Piper-Masha

Introduction

SPM Development Services Ltd is committed to protecting personal information and using it lawfully, fairly and transparently. This policy explains how SPM collects, uses, shares, stores and protects personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

Who We Are

SPM Development Services Ltd is the data controller for the personal data it collects and processes.
The Head of Centre is responsible for overseeing data protection compliance and responding to data protection enquiries.
Address: 90 East India Way, Croydon, Surrey, CR0 6RZ

What Information We Collect

SPM may collect and process:
SPM will collect only the information necessary for a clear purpose. Health, disability and safeguarding information will be treated as special category data and given additional protection. Information about criminal convictions or offences will only be processed where there is a lawful basis and appropriate safeguards are in place.

How We Use Personal Information

SPM may use personal information to:
SPM will not use personal information for purposes that are incompatible with the reason it was collected.

Lawful Bases for Processing

SPM will identify and record an appropriate lawful basis before processing personal data. Depending on the circumstances, this may include:
Where special category data is processed, SPM will also identify an additional condition under data protection law. This may include health or social care, safeguarding, substantial public interest or legal claims. Consent will not be relied upon where another lawful basis is more appropriate.

Safeguarding and Information Sharing

SPM will share information when this is necessary and proportionate to safeguard a child or young person. Consent is not always required where there is a lawful basis for sharing information to prevent harm or protect someone’s vital interests.
Information-sharing decisions will be made in line with Keeping Children Safe in Education (2026), Working Together to Safeguard Children (2026) and current government information-sharing guidance. The Designated Safeguarding Lead will oversee safeguarding information-sharing decisions and ensure that the reasons for sharing, or deciding not to share, are recorded.

Security Measures

SPM uses technical and organisational measures to protect data against loss, damage or unauthorised access. These include secure storage, password protection, restricted access, encryption where appropriate, and regular staff training in data protection.

Staff Responsibilities

Personal Data Breaches

All suspected personal data breaches must be reported immediately to the Head of Centre. SPM will take prompt action to contain the breach, assess the risk, recover or protect information where possible and record the incident and action taken.
Where a breach is likely to result in a risk to people’s rights and freedoms, SPM will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it.
Where the risk is high, we will also inform affected individuals without undue delay. All breaches will be recorded, including those that do not require notification.

Retention of Information

SPM will keep personal information only for as long as it is needed for the purpose for which it was collected and to meet safeguarding, legal, contractual, commissioning and awarding organisation requirements.
Retention periods will be recorded in SPM’s retention schedule and reviewed regularly. Different types of records may be retained for different periods. Safeguarding records may need to be kept for longer where this is necessary to protect a child or young person or respond to a future concern.
When information is no longer required, it will be securely deleted, destroyed or anonymised. Information subject to an ongoing safeguarding matter, complaint, investigation, legal claim or information request will not be destroyed until the matter has concluded.

Your Data Protection Rights

Depending on the circumstances, individuals may have the right to:

These rights are not absolute and may be limited by legal, safeguarding or regulatory
requirements. Requests should be made to the Head of Centre and will normally be
answered within one month. This period may be extended by up to two further months
where a request is complex or numerous. SPM will explain any extension or lawful reason
for refusing or limiting a request. There will normally be no charge.

Data Protection Complaints

Anyone who is concerned about how SPM has handled their personal information may make a complaint to the Head of Centre using the contact details in this policy.
SPM will acknowledge the complaint within 30 days, make appropriate enquiries without undue delay, keep the complainant informed and provide a written outcome.
If the complainant remains dissatisfied, they may raise the matter with the Information Commissioner’s Office at www.ico.org.uk.

Policy Review

This policy will be reviewed annually, or sooner if legislation or statutory guidance changes.