Skip to content

PRIVACY POLICY

This document details the Age UK Enfield’s Privacy Notice.

Version Control:
Current version:
3.1
Approved by:
QOS
Approval date:
September 2026
Next review date:
September 2027, or earlier if law, guidance or processing changes 
Version history:
 
Version
 
       Date
Main Changes
Changed by
1
5/2018
First Issue
 

2

8/2020

Second Issue

Silvia Schehrer

3

09/2023

Reviewed and updated

Venetta Hunt

3.1

09/2026

Reviewed and updated

SMT

Related documents
Data Protection Policy and Procedure
Data Protection Complaints Handling Process
Data Retention Policy and Schedule
Subject Access Request Procedure
Data Protection Impact Assessment Policy and Procedure
Data Breach Policy and Procedure
Data Quality and Record Keeping Policy
Confidentiality Policy
Information Security and Acceptable Use policies
 
  1. About this notice

Age UK Enfield is committed to protecting personal information and explaining clearly how it is used. This notice applies whenever you engage with us, including when you use our services, become a member, work or volunteer with us, apply for a role, donate, fundraise, attend an event, make an enquiry, visit our website or premises, supply goods or services, or otherwise interact with us.

This notice is provided under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (PECR). It should be read alongside any shorter or service-specific privacy information given when we collect your data.

2. Who we are and how to contact us

Age UK Enfield is the controller of the personal data described in this notice. This means that we decide why and how personal data is used.

Contact
Details
Organisation
Age UK Enfield
Address
The Mabel Churn Centre, 55b The Sunny Road, Enfield, EN3 5EF
General and privacy enquiries
admin@ageukenfield.org.uk
Information Governance Lead
Helen Oliver
ICO registration reference
Z5082844

If another organisation jointly determines the purposes and means of processing with us, we will explain the joint-controller arrangement in the relevant service-specific information.

3. Who this notice covers

This notice covers personal data relating to:

  • clients, service users, members and their representatives or carers
  • supporters, donors, fundraisers, event attendees and website users
  • employees, workers, trustees, volunteers, applicants and former personnel
  • contractors, consultants, suppliers, partners and professional contacts
  • visitors to our premises and people who contact us or are referred to us
4. Personal data we may collect

The information collected depends on your relationship with us and the service or activity involved. It may include:

  • identity and contact details, including name, address, telephone number, email and date of birth
  • service, assessment, referral, casework and support records
  • communication preferences, correspondence, feedback, complaints and enquiries
  • membership, donation, fundraising, Gift Aid, payment and transaction information
  • employment, recruitment, volunteering, training, attendance, payroll and performance records
  • emergency contact, next-of-kin and representative details
  • technical and usage data, such as IP address, device information, cookies and website interactions
  • images, audio or video where appropriate notice and a valid lawful basis are in place
  • premises access, visitor and incident records
  • supplier, contract and professional contact information
Special category and criminal offence data

Where necessary and lawful, we may process more sensitive information, such as health and disability information, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, trade union membership, genetic or biometric data used for identification, and information about criminal convictions or offences. We only do so where an additional condition under data protection law applies and appropriate safeguards are in place.

5. How we collect personal data

We may collect personal data:

  • directly from you, including through forms, telephone calls, email, online services, face-to-face contact and surveys
  • from a relative, carer, representative or person making a referral
  • from local authorities, NHS bodies, health and care professionals, partner charities or other service providers where sharing is lawful
  • from current or former employers, referees, recruitment agencies, disclosure and barring checks, or professional bodies
  • from payment providers, fundraising platforms, event partners and suppliers
  • automatically through our websites, devices and systems, including cookies where permitted
  • from publicly available sources where it is lawful and appropriate to do so

Where we obtain personal data from another source, we will provide privacy information within the period required by law unless an exemption applies.

6. Why we use personal data and our lawful bases

We use personal data only where a lawful basis applies. The table below summarises our main purposes. The precise basis may vary according to the circumstances and will be recorded in our Record of Processing Activities.

Purpose
Examples of data
Lawful basis
Deliver and manage services
Identity, contact, assessment, referral, support and case records
Contract; steps before a contract; legitimate interests; legal obligation; vital interests; or public task where applicable
Safeguarding, health, safety and wellbeing
Health, risk, incident, emergency contact and safeguarding information
Legal obligation; vital interests; legitimate interests. For special category data: health or social care, employment/social protection law, substantial public interest, vital interests, or explicit consent where appropriate
Manage employment, recruitment and volunteering
Application, right-to-work, payroll, attendance, training, health and HR records
Contract; steps before a contract; legal obligation; legitimate interests. Additional special category or criminal-offence conditions apply where relevant
Membership, fundraising, donations and Gift Aid
Contact, preferences, donation and tax declaration details
Contract; legal obligation; legitimate interests; consent where required by PECR
Communicate about our work and events
Contact details, interests and marketing preferences
Consent where required; otherwise legitimate interests where lawful. You can object to direct marketing at any time
Manage complaints, feedback and rights requests
Identity, correspondence, case and verification information
Legal obligation; legitimate interests; establishment, exercise or defence of legal claims where relevant
Manage suppliers, partners and contracts
Professional contact, contract, invoice and payment information
Contract; legal obligation; legitimate interests
Security, fraud prevention and organisational governance
Access logs, device, incident, audit and governance records
Legal obligation; legitimate interests; recognised legitimate interests where the statutory conditions are met
Website operation and analytics
IP address, device, cookie and usage data
Consent for non-essential cookies; legitimate interests for strictly necessary operation and security where lawful
Research, reporting and service improvement
Feedback, service outcomes and appropriately minimised or anonymised information
Legitimate interests; consent where appropriate; research/statistical provisions where applicable

Where we rely on legitimate interests, we consider the purpose, necessity and impact on individuals and apply safeguards. Where we rely on a recognised legitimate interest introduced by the Data (Use and Access) Act 2025, we will ensure the processing falls within the statutory list and meets the relevant conditions.

7. If you do not provide information

Some information is needed to enter into or perform a contract, provide a safe and appropriate service, process a donation or payment, or meet a legal obligation. If you do not provide it, we may be unable to provide the relevant service, employ or engage you, complete a transaction, or meet our legal duties. We will explain this at the point of collection where relevant.

8. Consent and your choices

Where consent is our lawful basis, it must be freely given, specific, informed and unambiguous. Explicit consent is used where required. You may withdraw consent at any time by contacting us. Withdrawal does not affect processing already carried out lawfully before withdrawal. We will not treat consent as valid where there is no genuine choice or where another lawful basis is more appropriate.

9. Direct marketing and cookies

We will comply with PECR and data protection law when sending direct marketing by email, text, telephone or other electronic means. You can opt out at any time by using the unsubscribe method in the communication or contacting us. We will retain enough information on a suppression list to respect your choice.

Our website uses strictly necessary cookies and may use optional cookies such as analytics or marketing cookies. Optional cookies will be used only where the required consent has been obtained. Further details are provided in our Cookie Notice and consent settings.

10. Who we share personal data with

We share only what is necessary and lawful. Depending on the activity, recipients may include:

  • local authorities, NHS bodies, health and care professionals, commissioners and safeguarding agencies
  • Age UK network organisations and delivery partners where relevant to a service or activity
  • IT, cloud hosting, CRM, payroll, HR, payment, printing, mailing and professional service providers acting under contract
  • HM Revenue & Customs, regulators, courts, law enforcement and other public authorities where required or permitted by law
  • insurers, auditors, legal advisers and other professional advisers
  • fundraising platforms, event partners and communications providers
  • prospective purchasers, funders or restructuring advisers if organisational change requires it, subject to appropriate safeguards

Processors acting for us may use personal data only for documented purposes and must apply appropriate security and confidentiality measures. Where organisations use data for their own purposes, they are responsible for their own compliance. We do not sell personal data.

11. International transfers

Some suppliers may store or access personal data outside the United Kingdom. Before making a restricted transfer, we will ensure that a lawful transfer mechanism is in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. We will also carry out any required transfer risk assessment and apply supplementary measures where appropriate. You may contact us for information about the relevant safeguard.

12. Data security

We use appropriate technical and organisational measures proportionate to the risk. These include access controls, staff confidentiality requirements, training, secure storage and disposal, supplier due diligence, backups, incident management, and measures to protect data during transfer. Access is limited to people who need the information for authorised purposes.

We maintain procedures for suspected personal data breaches. Where legally required, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. How long we keep personal data

We keep personal data only for as long as necessary for the purpose for which it was collected, including legal, regulatory, safeguarding, contractual, insurance, accounting and reporting requirements. Specific periods and the criteria used to set them are recorded in our Data Retention Policy and Schedule. At the end of the retention period, information is securely deleted, destroyed or irreversibly anonymised unless continued retention is lawful and necessary.

14. Automated decision-making and profiling

We do not currently make decisions that have legal or similarly significant effects on individuals solely by automated means unless we have clearly explained the activity and a lawful basis applies. If this changes, we will provide meaningful information about the logic involved, the significance and likely consequences, and the safeguards available, including any right to obtain human intervention, express a view and challenge a decision.

15. Your data protection rights

Depending on the circumstances, you may have the right to:

Be informed: receive clear information about how we use your personal data.

Access: obtain confirmation and a copy of personal data we hold about you.

Rectification: have inaccurate information corrected and incomplete information completed.

Erasure: ask us to delete personal data where the law allows.

Restriction: ask us to limit how personal data is used in certain circumstances.

Data portability: receive certain information in a structured, commonly used, machine-readable format and ask us to transmit it where the legal conditions apply.

Object: object to processing based on legitimate interests or public task, and object at any time to direct marketing.

Withdraw consent: withdraw consent at any time where processing relies on consent.

Rights relating to automated decisions: receive safeguards where a significant decision is made solely by automated processing, where applicable.

Rights are not absolute and exemptions may apply. We will explain any decision not to act on a request. To exercise a right, contact us using the details in section 2. We may ask for information needed to verify your identity and locate the relevant records.

We usually respond without undue delay and within one month. The period may be extended where the law allows, for example where a request is complex or numerous; if so, we will tell you within the initial one-month period. We normally do not charge a fee, but may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.

16. Data protection complaints

If you are concerned about how we have used your personal data, please raise the matter with Age UK Enfield first so that we can investigate and respond under our Data Protection Complaints Handling Process.

How to complain to us
Details
Email
admin@ageukenfield.org.uk
Post
Information Governance Lead, Age UK Enfield, The Mabel Churn Centre, 55b The Sunny Road, Enfield, EN3 5EF
Other accessible channels
Telephone, in person, or through any member of staff

You may also complain to the Information Commissioner’s Office if you remain dissatisfied. The ICO can be contacted through its website at www.ico.org.uk or by telephone on 0303 123 1113. Raising a concern with us first does not remove your ability to contact the ICO.

17. Children and people who may need support

Where we process children’s personal data or information about an adult who may need support to understand this notice or exercise their rights, we will use clear, accessible information and make reasonable adjustments. We will carefully consider capacity, authority to act, safeguarding duties and the individual’s rights. Parental or representative involvement will not automatically replace the individual’s rights and will be assessed case by case.

18. Changes to purpose

We will use personal data for the purpose for which it was collected unless a new use is compatible with that purpose or another lawful basis applies. Before using personal data for a new incompatible purpose, we will provide relevant privacy information unless the law permits otherwise. We will document our assessment and update our records and notices as necessary.

19. Keeping this notice up to date

We review this notice at least annually and whenever there is a significant change to law, ICO guidance, our services, systems, suppliers or processing. Material changes will be communicated through appropriate channels before new processing begins where required. The latest approved version will be made available on our website and on request.