Families First Solutions (FFS) is committed to the principles of Information Governance and Compliance that align with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The principles of information governance are concerned with the management of information in an organisation. Information governance balances the use and security of information. It helps with legal compliance and operational transparency. An organisation can establish a framework for those working on behalf of the company to handle information through their information governance policies and procedures.
Information governance incorporates: records management, information security and protection, risk management, privacy, data storage and archiving and knowledge management.
For FFS, this means that we make every effort to rigorously adhere to the requirements of the UK GDPR and UK Data Protection Law.
Legal Framework
The UK General Data Protection Regulation (UK GDPR) is the UK’s data protection framework. It works alongside the Data Protection Act 2018 to regulate the processing of personal data.
Core Data Protection Principles
The GDPR is based on the core principles of data protection. In adhering to these principles FFS is committed to:
- Collecting no more data than is necessary from an individual for the purpose for which it will be used
- Obtaining personal data fairly by giving notice of the collection and its specific purpose
- Retaining the data for no longer than is necessary
- Keeping data safe and secure
- Providing individuals with a copy of their personal data upon request
Our lawful basis for processing personal data may include consent, contractual obligation, compliance with legal obligations, or legitimate interest, depending on the nature of the interaction.
Practical Application for Clients
- We will only ask for the relevant data required to run a course.
- Data will be processed in accordance with the law, kept safe, and destroyed when no longer needed. (See Appendix A for our retention schedule.)
- You can request data deletion at any time. We will inform you if this might have a negative effect (e.g. missing follow-up materials).
- If we hold your details, we may contact you up to four times per year about future training. You may opt out at any time. Any marketing campaign follows the good practice guidance issued by the Information Commissioners Office.
- This includes data collected through our online learning platform during course registration. When you sign up, we collect your name, email, and course information to deliver training and track progress. This data is processed under our legitimate interest in service delivery and improvement. We only send marketing communications to these users if they have opted in during sign-up, and all communications include the option to unsubscribe at any time.
- Our online training includes a clear explanation of how data is used and stored. Users must accept these terms during sign-up.
- When you attend a webinar, training session, or meeting organised by Families First Solutions, we may share your name and attendance with your local authority for reporting, funding, or administrative purposes. This is typically done to help them track participation or follow up on actions related to local policy or provision. We will only share data that is necessary, and only with relevant parties. You’ll be informed in the meeting invite and can contact us if you have concerns.
- Emails containing factual information needed to access a session are, in law, ‘service messages’ and are exempt from this policy and GDPR legislation. We also retain the right to contact you if you owe FFS money.
- Very occasionally, we may have to share your information for your welfare—for example, if you become unwell during a session or disclose a safeguarding concern. We will inform you when possible.
Use of Data for Feedback and Analytics
- We collect and store participant feedback following training sessions and meetings to help us evaluate and improve our services. Where feedback includes personal identifiers (such as a name or email address), this is treated as personal data and stored securely. This data may be retained for up to 5 years unless otherwise agreed, and may be anonymised for reporting purposes.
- We also collect and analyse data such as course uptake, session attendance, and engagement to monitor reach and impact, evaluate delivery, and report to our partners (e.g. local authorities). Where possible, this information is anonymised or aggregated.
- Our lawful basis for processing this data is legitimate interest. This means that we use the data in ways that are necessary for us to improve our services and fulfil our obligations to partners and funders, and which do not override your individual rights and freedoms. If at any point you have concerns about this processing, you can contact us for more information or to object.
Privacy Statement
The principles of this policy are embedded in the following Privacy Statement:
Families First Solutions is committed to protecting your personal data and privacy. We recognise that ensuring the accuracy and security of your personal data is essential to retaining your confidence and trust. The information you provide to us will only be used for the purposes that you provide it and will never be used for third party marketing. Full details of how we manage any information we hold about you can be found in our Information Management and Privacy Policy.
When we collect your personal data we will normally tell you:
- what your information will be used for
- who it may be shared with
- where you have a choice about your data we will ask for your consent to use it
Your Rights Under the GDPR
Under the provisions of the GDPR, you have the right to:
- Request details about the information we hold on you
- Request that we rectify any mistakes
- ‘To be forgotten’ – to have your data completely deleted from our systems
- Prevent your personal data being processed
- Object to certain types of processing, including direct marketing
Data Storage
- Information is stored electronically on password protected computers. Any backup systems ensure that data is stored securely and are also password protected.
- All computer systems are virus checked on an on-going basis.
- Some information pertaining to individual projects is stored on secure platforms including SharePoint and Dropbox. This data is subject to the same rigorous controls as all other data held by FFS. Access to these platforms is limited to authorised personnel and is protected by strong passwords and two-factor authentication where possible. These services may store data outside the UK, and where applicable, appropriate safeguards such as Standard Contractual Clauses are used to ensure compliance with data protection laws.
- Occasionally we have to hold data in hard copy, e.g. if you have handed over your details at a face-to-face session, this is held until it is transferred to electronic storage which will be done as soon as possible. Care is taken at all times to keep this as securely as possible. Hard copy records are destroyed by shredding, once they have been transferred to electronic storage in line with the permissions given by you.
- If you visit our website we only collect your information with your specific consent, our company policy is to not take any action with IP addresses.
- Some of our training includes links to or embeds from third-party platforms such as YouTube. These services may collect usage data or set cookies in accordance with their own privacy policies
- The secure service Mailchimp is used to manage our termly mailings. All protocols linked to this software are followed, and in line with best practice, individuals may unsubscribe at any time.
Data Breaches
- Families First Solutions is registered with the Information Commissioners Office.
- If a data breach occurs, we will report this to the Information Commissioners Office within 72 hours, where feasible. We will inform clients as soon as possible about what has happened and what steps we have taken to rectify the situation.
Subject Access Requests
- We respond to subject access requests by following the most up to date guidance published by the Information Commissioners Office. Should any requests for data be considered vexatious, we will notify the Information Commissioners Office.
- We aim to respond to all valid requests within one calendar month, in line with ICO guidance.
Review and Contact
- This policy will be reviewed every 12 months or earlier if a change in legislation, working practices or feedback from clients or partners necessitates.
- If you have any questions or concerns about how we handle your personal data, please contact our Data Protection Lead at info@familiesfirst.org.uk
- This policy was adopted in May 2025
Appendix A – Record Retention Schedule
Data Collected |
How Long This is Kept For |
Rationale |
Information to deliver projects |
5 years |
To refer back to the information if follow-up is needed |
Information to raise invoices and invoice details |
7 years |
In line with HMRC’s requirement to hold all accounting paperwork for 7 years. |
Marketing data (with consent) |
Indefinitely |
Every mailing gives the individual or company the option to opt out |
Zoom and Microsoft Teams chat logs |
3 Months |
Covers follow-up queries post-session |
Ad hoc data collection |
Case by case |
Kept as long as needed or with permission |
| Feedback from participants | 5 years |
Used to evaluate and improve services; may be anonymised for reports |
| Learning platform registration data
|
5 years |
Needed to manage access, training history, and progress |
| Attendance records | 5 years |
Used for reporting to local authorities and internal evaluation |
This Policy was last reviewed 21/05/2025
