GDPR and Data protection Policy
1. Purpose of this Policy
Balfour Swimming School is committed to protecting the privacy and security of all personal data we collect.
This policy explains:
what personal data we collect
why we collect it
how we store and protect it
your rights under UK GDPR
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Â
 2. Data Controller
Balfour Swimming School is the Data Controller for all personal data processed in connection with our activities.
Contact:
Data Protection LeadÂ
Balfour Swimming School
Email: balfourswimmingschool@gmail.com
Â
3. What Personal Data We Collect
We collect only the information necessary to run safe, effective swimming lessons.
Â
3.1 For children/swimmers
Name, date of birth, gender
Parent/guardian contact details
Medical information (e.g., asthma, allergies)
Swimming ability and lesson history
Emergency contact details
Â
3.2 For parents/guardians
Name and contact details
Payment information (processed securely by third‑party providers)
Â
3.3 For staff/volunteers
Name and contact details
DBS information
Qualifications and training records
Emergency contact details
Â
3.4 Website or digital data
Contact form submissions
Cookies (if applicable)
IP address (for security)
Â
 4. Why We Collect Personal Data (Lawful Basis)
We process data under the following lawful bases:
Contract — to provide swimming lessons
Legal obligation — safeguarding, health & safety, DBS checks
Vital interests — medical emergencies
Legitimate interests — running and improving the swim school
Consent — photography, marketing communications
We only collect what is necessary.
 5. How We Use Personal Data
We use personal data to:
manage lesson bookings
communicate with parents
ensure swimmer safety
respond to medical needs
maintain safeguarding standards
manage staff and volunteers
process payments
comply with legal requirements
We never sell personal data.
Â
 6. How We Store and Protect Data
We take data security seriously. Measures include:
password‑protected systems
encrypted storage where possible
restricted access for staff only
secure payment processors
regular policy reviews
Paper records (if used) are stored in locked cabinets and destroyed securely.
Â
 7. Sharing Personal Data
We only share data when necessary, such as with:
pool operators (for emergency or safety reasons)
insurers (for incident reporting)
emergency services
DBS checking services
payment processors
We do not share data with third parties for marketing.
Â
 8. Photography & Video
We will only take or use photographs/videos of swimmers if:
explicit written consent is given by a parent/guardian
images are used safely and appropriately
no child is identified by full name without consent
Parents must follow our Photography & Social Media Policy.
Â
 9. Data Retention
We keep personal data only as long as necessary:
Swimmer records: up to 3 years after leaving
Incident reports: 3–7 years depending on severity
Safeguarding records: indefinitely, as required
Staff records: 6 years after employment/volunteering ends
Data is securely deleted or shredded when no longer needed.
Â
 10. Your Rights Under UK GDPR
You have the right to:
Access your data
Correct inaccurate data
Request deletion (where legally allowed)
Restrict processing
Object to certain uses
Withdraw consent at any time
Data portability (where applicable)
Requests will be handled within 30 days.
Â
11. Data Breaches
If a data breach occurs:
We will assess the risk immediately
Inform affected individuals if there is a high risk
Report serious breaches to the ICO within 72 hours
We maintain an internal breach log.
Â
 12. Changes to This Policy
This policy will be reviewed annually or sooner if:
legislation changes
our operations change
new risks are identified