Data Protection GDPR

Policy & Procedure


Little Fish Norwich Ltd

Accountable Officers:
[Tristan Coull / Toby Ketland– Directors]
Date approved:
[31 August 2026]
Review Date:
[31 August 2027]

Revision History

This table sets out the revision history for the last three versions.
Version No.
Effective date
Author’s Title
Change

Consultation

Who
Date
Tristan Coull (Director)
August 2026

Approval

Approval Path
Date
Toby Ketland
August 2026

Contents

1. Introduction
2. Lawful Basis for Processing Personal Data
3. Personal Data We Collect
4. How We Use Personal Data
5. Data Sharing
6. Data Storage and Security
7. Data Retention
8. Individual Rights
9. Photography and Media
10. Data Breaches
11. Responsibilities
12. Review of Policy

1. Introduction

1.1
Little Fish Norwich Ltd (“LFN”) is committed to protecting the privacy and personal data of all swimmers, parents, volunteers, and employees. As an organisation we recognise our responsibility to handle personal information lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains how we collect, use, store and share personal data, and outlines the rights of individuals whose information we process.

2. Lawful Basis for Processing Personal Data

2.1
(“LFN”) processes personal data only where it is necessary for the effective running of our activities. We follow Swim England’s Wavepower guidance voluntarily as best practice, but we are not a Swim England-affiliated club.

2.2
Little Fish Norwich Ltd is the Data Controller for all personal data it collects. Any third-party systems (e.g., booking platforms, email services, payment processors) act as Data Processors.

3. Personal Data We Collect

3.1
Little Fish Norwich Ltd (“LFN”) collects only the personal data necessary for swimmers, parents, volunteers, and employees to participate safely and effectively in our activities. Because we work primarily with children, we apply additional care and safeguards when handling their information.

The types of personal data we may collect include:

• Identity and contact information – such as names, addresses, email
addresses, phone numbers, and emergency contact details.

• Child-specific information – including dates of birth, parent/guardian
details, and proof of parental responsibility where required.

• Medical and health information – any relevant medical conditions,
allergies, injuries, or additional needs necessary to ensure swimmer
safety and to support coaches in delivering appropriate sessions.

• Participation and performance data – attendance records, progress
notes, assessments, and any optional performance tracking used to
support swimmer development.

• Safeguarding information – records relating to welfare concerns, incident
reports, or communications relevant to the safety and wellbeing of
swimmers. Such information is handled with strict confidentiality and only
by authorised individuals.

• Volunteer and employee information – including training records, DBS
checks, qualifications, and role-related documentation.

• Financial information – limited to payment records or invoices where
required for membership or lesson fees. LFN does not store full card
details.

• Photography and media preferences – consent forms and records
indicating whether images or video may be taken or used for club
purposes.

All personal data is collected for clear, specific purposes and will not be used in
ways incompatible with those purposes. We do not collect more information
than is necessary, and we regularly review the data we hold to ensure it
remains relevant and proportionate.

4. How We Use Personal Data

4.1
Personal data is used to administer membership, manage swimming sessions, communicate with parents, carers and swimmers, ensure safety and safeguarding, and meet Swim England regulatory and insurance requirements. (“LFN”) will only use personal data for the purposes for which it was collected and will not use it for unrelated activities.

5. Data Sharing

5.1
LFN shares personal data only where it is necessary, lawful, and proportionate. Data may be shared with:

• Employees, coaches, and authorised volunteers who require access to fulfil their roles safely and effectively.

• Third-party service providers such as booking systems, email platforms, or payment processors, strictly for operational purposes and under appropriate data-processing agreements.

• Safeguarding or statutory authorities (e.g., police, social services) where required to protect a child or vulnerable person.

• Medical professionals or emergency services in the event of an accident or medical incident.


LFN does not sell personal data and does not share information with third parties for advertising or commercial marketing.

Where we voluntarily follow Swim England’s Wavepower guidance, this does not involve sharing data with Swim England unless explicitly agreed with parents or guardians.

6. Data Storage and Security

6.1
LFN takes data security seriously and implements appropriate measures to protect personal information from loss, misuse, unauthorised access, or disclosure. Digital records are stored on secure, password-protected systems with access restricted to individuals who require the information for their role. Paper records are kept in locked storage and are disposed of securely when no longer needed. Access to personal data is reviewed regularly to ensure it remains appropriate, and all staff and volunteers receive guidance or training to help them understand their responsibilities under UK GDPR. We continually assess our systems and processes to maintain a high standard of security and confidentiality.

7. Data Retention

7.1
LFN retains personal data only for as long as it is needed to fulfil the purposes for which it was collected or to meet legal, safeguarding, or financial obligations. Retention periods are determined by statutory requirements, best-practice safeguarding guidance, and operational needs. Once information is no longer required, it is securely deleted or destroyed to ensure that it cannot be accessed or misused. We maintain an internal retention schedule that is reviewed regularly to ensure compliance.

8. Individual Rights

8.1
Under the UK GDPR, individuals have a number of rights regarding their personal data. Parents or guardians may exercise these rights on behalf of their children. These rights include the ability to request access to the information we hold, to ask for inaccuracies to be corrected, and to request deletion of data where appropriate. Individuals may also request that processing be restricted or object to certain types of processing. Where consent is the basis for processing such as for photography, individuals may withdraw that consent at any time. Requests should be submitted to the LFN Secretary, and we will respond within one month. To protect confidentiality, we may ask for proof of identity before releasing information.

9. Photography and Media

9.1
LFN recognises that photography and video recording require careful consideration, particularly when working with children. We obtain explicit consent from parents or guardians before taking or using images or video of swimmers, and we record these preferences securely. Images are used responsibly and only for the purposes explained at the time consent was given, such as promoting club activities or celebrating achievements. Photography is never permitted in changing areas or other private spaces. Consent can be withdrawn at any time, and we will stop using images immediately and remove them from our platforms where reasonably possible. Although we are not affiliated with Swim England, we voluntarily follow the principles of their Wavepower guidance to ensure safe and respectful use of images.

10. Data Breaches

10.1
A data breach is any incident that results in the loss, unauthorised disclosure, or misuse of personal data. All staff and volunteers must report any suspected breach immediately to the LFN Secretary. We will investigate all incidents promptly, assess the potential impact on individuals, and take steps to contain and mitigate any harm. Where a breach is likely to result in a risk to individuals’ rights or freedoms, we will notify the Information Commissioner’s Office (ICO) within the required 72-hour timeframe. If the risk is high, we will also inform affected individuals without undue delay. All breaches, whether minor or significant, are recorded in an internal incident log.

11. Responsibilities

11.1
Data protection is a shared responsibility across the organisation. LFN is responsible for ensuring compliance with UK GDPR and the Data Protection Act 2018, for maintaining secure systems and processes, and for providing appropriate guidance or training to employees and volunteers. Staff and volunteers must handle personal data responsibly, follow this policy at all times, and report any concerns or breaches immediately. Access to personal data is granted only where necessary for an individual’s role, and everyone involved in the club’s operations is expected to uphold high standards of confidentiality and professionalism.

12. Review of Policy

12.1
This policy will be reviewed annually or sooner if required by changes in legislation or Swim England guidance. The club is committed to maintaining high standards of data protection and ensuring that all members can participate in a safe, respectful and well-managed environment.