Last updated 10th January 2026

1. Our Principles

This policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Aims

PSP recognises that the mishandling of an individual’s personal data may cause them distress or put them at risk of identity fraud. As a result, we are committed to:

  • Complying fully with data privacy legislation;
  • Where practicable, adhering to good practice, as issued by the ICO or other appropriate bodies; and
  • Handling an individual’s personal data in a careful and considerate manner that recognises the importance of such information to their privacy and welfare.

We seek to achieve these aims by:

  • Ensuring that all trustees, employees and contractors who process data for our purposes are made aware of their individual responsibilities under data privacy legislation and how these apply to their areas of work;
  • Providing training, guidance and advice as necessary to enable all trustees and employees to discharge their responsibilities for data protection effectively;
  • Incorporating data privacy requirements into the PSP’s administrative procedures where these involve the processing of personal data;
  • Providing procedures for the processing of subject access and other rights based requests made by individuals; and
  • Investigating promptly any suspected breach of data privacy legislation; reporting it, where necessary; and seeking to learn any lessons from the incident in order to reduce the risk of reoccurrence. 

3. The Data We Collect

We follow the principle of data minimisation and only collect personal data that is necessary to meet PSP’s objects or to meet legal obligations. This may include:

•     Names

•     Postal addresses

•     Email addresses

•     Telephone numbers

•     Donation amounts and dates

•     Records required by law, such as accounting and financial records

We do not knowingly collect personal data relating to children.

4. How We Use Personal Data

We use personal data only for clear and legitimate purposes:

•     To process and acknowledge donations

•     To administer and record Gift Aid claims

•     To communicate with donors and prospective donors where appropriate and permitted

•     To maintain accurate financial and administrative records

•     To meet legal, regulatory, and reporting obligations

We do not use personal data for automated decision-making or profiling.

5. Lawful Basis for Processing

Our lawful bases for processing personal data under UK GDPR are:

•     Consent – where individuals have actively agreed to receive communications from us

•     Legal obligation – where we are required to retain records by law (for example, financial records)

•     Legitimate interests – for basic charity administration and donor relationship management, where these interests are not overridden by individuals’ rights

6. How We Store & Protect Data

We take appropriate technical and organisational measures to keep personal data secure, including:

•     Secure storage of electronic records using password protection

•     Secure storage of paper records

•     Restricting access to personal data to authorised trustees or volunteers only

•     Ensuring trustees and volunteers understand their data protection responsibilities

7. Data Retention

We will only keep personal data for as long as it is necessary.  This means. Inter alia:

•     Donor and prospective donor contact details are kept while there is an active relationship or until consent is withdrawn

•     Financial are retained for the periods required by law

•     Personal data that is no longer required is securely deleted, anonymised, or destroyed

8. Sharing Personal Data

8.1 General

We do not sell or rent personal data.  We only share data where required by law or by a regulator or for operational purposes such as external fund-raising, accounting and audit purposes.  Any third-party organisations we use are required to keep personal data secure, comply with UK legal requirements and use the data only for the purposes we have specified.

8.2 Individual Rights

Individuals have the following rights under data protection law:

•     The right to access their personal data

•     The right to have inaccurate data corrected

•     The right to request deletion of data, where applicable

•     The right to restrict or object to certain processing

•     The right to withdraw consent for communications at any time

Requests can be made to the registered office, by email to the Company Secretary or via the contact details on our website and we will respond within the timescales set out in law.

9. Data Breaches

In the event of a personal data breach, we will assess the risk and take appropriate action. Where required by law we will report the breach to the ICO and, if necessary, inform affected individuals.

10. Complaints

If you have concerns about how we handle personal data, please contact us in the first instance. You also have the right to complain to the Information Commissioner’s Office (ICO).

11. Publication and Review of This Policy

This policy will be published on PSP’s website and made publicly available.   The policy will be communicated to all PSP Trustees, the Company Secretary and each employee of the Company on their joining.  This policy is subject to review and PSP reserves the right to amend the policy without prior notice.