Squirrel Wood collects and uses personal information to manage enquiries, bookings, visits and campsite safety. This policy sets out how that information must be handled, stored and protected.
It should be read alongside our Privacy Policy, which explains how we use personal information and the rights available to individuals.
Responsibility and scope
Doncaster Danum District Scout Council is the data controller responsible for personal information processed through Squirrel Wood.
The District Trustee Board oversees our data protection arrangements. Glynis Robinson coordinates privacy enquiries and the day to day administration of this policy.
This policy applies to volunteers, contractors and anyone handling campsite personal information on our behalf. It covers electronic records, emails, paper documents and information held through our website and booking systems.
Volunteer membership and DBS records are managed through separate Scouts arrangements and are outside the scope of this policy.
Data protection principles
We must handle personal information in accordance with the UK GDPR and the Data Protection Act 2018, as amended.
Personal information must be:
- Used lawfully, fairly and transparently
- Collected for clear and legitimate purposes
- Limited to what is needed
- Accurate and updated where necessary
- Kept only for as long as needed
- Protected against unauthorised access, loss or misuse
We must also be able to demonstrate how we meet these requirements.
Information we handle
Campsite records may include:
- Names and contact details
- Group and organisation details
- Booking requests and correspondence
- Accommodation, activity and equipment arrangements
- Attendance lists
- Emergency contact names and telephone numbers
- Activity permission forms and shooting declarations
- Financial records
- Complaints and incident reports
- Website security and analytics information
We do not collect routine health information for bookings. Incident reports may contain details of injuries or treatment where necessary to record and respond to an incident.
Lawful use of information
A lawful basis must be identified and recorded before personal information is used.
Depending on the purpose, this may include:
Contract: arranging and delivering a booking made by an individual, including steps requested before entering a contract.
Legitimate interests: administering group bookings and enquiries, communicating with visitors, maintaining emergency contacts and supporting safe campsite operations. These interests must be assessed against the rights and interests of the people concerned.
Legal obligation: keeping or disclosing information where a specific legal requirement applies.
Consent: uses for which consent is appropriate or required, including optional website tracking where applicable.
Health information in incident reports requires an additional special category condition. Criminal offence information in shooting declarations requires separate consideration under the applicable rules. The relevant conditions and any required supporting documentation must be recorded before such information is processed.
Submitting an enquiry or accepting a privacy notice does not provide blanket consent for unrelated uses.
Approved systems
Our approved systems include:
- Online Scout Manager: booking administration
- Microsoft 365: email, documents and administration
- Forminator: website enquiry forms
- Google Analytics: website usage analysis, subject to the website’s consent controls
Personal information must not be copied into unapproved applications or personal accounts.
Service providers must be assessed for suitable security, contractual protections and retention arrangements. Their use of overseas hosting or support must also be checked. Any international transfer must have an appropriate legal mechanism and safeguards.
Access and security
Access must be limited to people who need information for their role.
Anyone handling personal information must:
- Use individual accounts and strong passwords
- Enable multi factor authentication where available
- Keep passwords private
- Keep devices updated and protected by a screen lock
- Check recipients and attachments before sending information
- Avoid exposing recipients’ email addresses in group messages
- Keep paper records secure and out of public view
- Avoid unnecessary downloads, printouts and duplicate records
- Report security concerns promptly
Local copies must only be made where authorised and necessary. They must be protected and deleted when no longer needed.
Access must be reviewed when responsibilities change and removed when it is no longer required.
Sharing information
Information may be shared with authorised campsite and District volunteers where necessary for their duties.
Sharing with instructors, service providers, emergency services, insurers, safeguarding bodies or other organisations must have a clear purpose and an appropriate lawful basis. Only the information needed for that purpose should be disclosed.
Requests from authorities must be checked before disclosure. Significant disclosures should be documented.
Accuracy
Booking contacts should be encouraged to tell us about changes to their details.
Errors must be corrected promptly. Information that cannot be verified should be checked or clearly marked, rather than automatically deleted where it remains relevant to a record.
Retention and disposal
Booking records: retained for 36 months after the visit or cancellation.
Financial records: retained for seven years.
Incident records: retained for seven years, subject to any justified longer period required for safeguarding, insurance or legal matters.
Attendance lists, emergency contacts and activity permission forms must be reviewed after the visit. They should be retained only while needed for visit administration, incident handling or a documented safeguarding, insurance or legal purpose.
Other enquiries and correspondence must be reviewed when the matter closes and deleted when no longer needed.
Records subject to an unresolved complaint, claim or investigation must not be destroyed until the relevant need has been assessed.
Paper records must be shredded or disposed of through confidential waste. Electronic records and duplicate copies must be securely deleted. Backup retention and deletion must also be addressed in our system arrangements.
Requests from individuals
People may have rights to access, correct, delete, restrict or obtain a portable copy of their information. They may also have the right to object to processing or withdraw consent.
Requests can be made verbally or in writing and must be passed promptly to Glynis Robinson. A particular form is not required.
We will normally respond within one month, subject to the applicable rules on identity checks, clarification and permitted extensions. Requests are normally handled free of charge.
Identity checks must be proportionate. Information about other people must be protected when responding.
Data breaches
Suspected loss, unauthorised access, accidental disclosure or other misuse of personal information must be reported immediately to Glynis Robinson through the campsite contact details. Volunteers must not wait for certainty before raising a concern.
The responsible team must:
- Take appropriate steps to contain the incident
- Establish what information and people are affected
- Assess the risk to individuals
- Record the breach and decisions made
- Notify the ICO where the reporting threshold is met
- Inform affected people without undue delay where the breach is likely to create a high risk to them
- Review measures needed to prevent recurrence
Notifiable breaches must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of them. Not every breach requires ICO notification, but every breach must be documented.
Cookies and analytics
Functional cookies support website operation. Optional analytics tracking must follow the website’s consent settings.
Visitors must be able to reject tracking and change their preferences. Rejecting optional tracking must not prevent them from making an enquiry.
Cookie information must accurately describe the technologies used, their purposes, providers and duration.
Guidance and review
People handling personal information must receive guidance appropriate to their role.
The District Trustee Board should review this policy annually and when systems, services or legal requirements change. Retention arrangements, access permissions and service providers should be reviewed alongside it.
Contact and complaints
For privacy enquiries, rights requests or concerns, contact:
Glynis Robinson
Email: squirrelwood@doncasterscouts.org.uk
Post: Squirrel Wood Scout Campsite, The Abbes Walk, Burghwallis, Doncaster, DN6 9JQ
Individuals also have the right to complain to the Information Commissioner’s Office.