top of page
Screenshot 2026-07-18 at 8.31.27 PM.png

CONFIDENTIALITY AND DATA PROTECTION POLICY 

The data protection officer is Shelley Perry. 

 

This policy has been written in conjunction with the 8 principles of data protection set out by the information commissioner. The 8 principles state that personal information must be: 

  • Fairly and lawfully processed 

  • Processed for specified purposes 

  • Adequate, relevant and not excessive 

  • Accurate and, where necessary, kept up to date 

  • Not kept for longer than is necessary 

  • Processed in line with the rights of the individual 

  • Kept secure 

  • Not transferred to countries outside the European Economic area unless the information is adequately protected 

  • As required by law we will notify the information commission office on a yearly basis stating that we are complying with the requirements of the Data Protection Act 1998. As a sign of good practice, a yearly audit will be carried out on our data protection procedures. 

 

CLIENT INFORMATION 

  • Clients will be informed of information held about them and what it will be used for.  

  • Clients may request a copy of the information held about them by Flourish in writing. We will reply within 40 days. A fee of £10 will be charged to respond to requests for information. 

 

PERSONAL INFORMATION STORAGE 

  • All personal information (both clients and employees) will be held securely and will be kept accurate and up to date. 

  • All personal information (both clients and employees) will be destroyed by shredding when Flourish no longer have a need for it.  

  • Hard copies of personal information will be stored in a locked cabinet. 

  • Personal information stored on a hard drive will only be accessible to Flourish staff via a password. Staff will lock or turn off computers when not present. 

  • Identity checks will be carried out before giving out personal information to anybody making incoming or outgoing calls to the service. Clients will be asked to create a password for this process. 

 

 

STAFF 

  • All Flourish staff will be required to demonstrate understanding of their duties and responsibilities to the Data Protection Act.  

  • Only trained staff members of Flourish will have access to personal information.  

 

Maintaining confidentiality is an essential part of all services offered by Flourish. It contributes to creating a safe environment, and to relationships based on trust. This enables clients to speak most freely and engage meaningfully. It enables workers to function more effectively, and ethically. 

 

All staff involved with Flourish aim to respect the dignity and worth of every individual; and to maintain their rights to a private and confidential service. This means that access to and sharing of information is restricted and on a ‘need to know’ basis. Information is not passed on outside of Flourish without a client’s expressed permission unless there is a requirement by law, or someone is believed to be at serious risk. Where Flourish determines that a breach of confidentiality has to be made, wherever possible the client will be fully informed as to why, what, how and to whom. Information shared in this way will be kept to the minimum necessary to deal with the issue directly leading to the breach of confidential.

bottom of page