Betty Stafford’s Care Ltd Appropriate Policy Document (Sensitive Data)

Last updated: 12th June 2026

Introduction

Betty Staffords Care Ltd processes special category data, as defined in Article 9 of the General Data Protection Regulation (GDPR). This data must be processed in accordance with the requirements of the Data Protection Legislation.

For the purpose of this policy, Data Protection Legislation includes all applicable data protection and privacy legislation in force from time to time in the UK including, but not limited to, the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) (DPA 2018); and the Privacy and Electronic Communications Regulations 2003 as amended; or any successor legislation, and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of personal data (including, without limitation, the privacy of electronic communications).

Some of the conditions for processing special category, as set out in DPA 2018 Schedule 1, require us to have an Appropriate Policy Document (APD) in place. The APD must set out and explain our procedures for securing compliance with the principles in Article 5 of the GDPR and our policies regarding the retention and erasure of such personal data.

The information in this policy supplements Betty Staffords Care Ltd’s Data Protection Policy and also our privacy notices, the main one of which is on our website: www.bettystaffords.co.uk

Purpose

This document explains our processing in relation to special category and satisfies the requirement to have an APD in place, as set out in Schedule 1, Part 4 of the DPA 2018.

Scope and status

This policy applies to all processing of special category, undertaken by or on behalf of Betty Staffords Care Ltd, which is based on a condition in Schedule 1 of the DPA, which requires an APD.

Special category data is defined at Article 9 of the GDPR as personal data revealing:

  • Racial or ethnic origin;

  • Political opinions;

  • Religious or philosophical beliefs;

  • Trade union membership;

  • Genetic data;

  • Biometric data for the purpose of uniquely identifying a natural person;

  • Mental or physical disability;

  • Data concerning health; or

  • Data concerning a natural person’s sex life or sexual orientation.

Conditions for processing

We process special categories of personal data as set out in our website privacy notice.

Compliance with the principles

Accountability principle

We have put in place appropriate technical and organisational measures to meet the requirements of accountability. These include:

  • taking a ‘data protection by design and default’ approach to our activities;

  • maintaining documentation of our processing activities;

  • adopting and implementing data protection policies and ensuring we have written contracts in place with our data processors;

  • implementing appropriate security measures in relation to the personal data we process; and

  • carrying out data protection impact assessments for our high-risk processing and where otherwise deemed helpful.

We regularly review our accountability measures and update or amend them where required.

Principle (a): lawfulness, fairness and transparency

We have put in place appropriate measures to ensure we meet this principle. These include:

  • ensuring that we always meet relevant lawful basis/bases for processing, including at least one of the conditions in Schedule 1 of the DPA 2018, where required (please refer to the list below);

  • providing clear and transparent information about why we process personal data including our lawful basis for processing in our privacy notices; and setting out our main processing activities in our website privacy notice.

Data concerning health

  • Lawful Processing Basis

    • Compliance with a legal obligation (Article 6 (1)(c)) or necessary for the performance of a contract with the Data Subject (Article 6(1)(b)).

  • Processing Condition

    • Necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the Data Subject in connection with employment, social security or social protection. (Paragraph 1(1)(a), Schedule 1, DPA 2018.)

Racial or ethnic origin data

  • Lawful Processing Basis

    • Compliance with a legal obligation (Article 6(1)(c)).

  • Processing Condition

    • Necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the Data Subject in connection with employment, social security or social protection. (Paragraph 1(1)(a), Schedule 1, DPA 2018.)

Criminal Convictions Data

  • Lawful Processing Basis

    • Compliance with a legal obligation (Article 6(1)(c)).

      OR

    • In the organisation's legitimate interests (Article 6(1)(f)) which are not outweighed by the fundamental rights and freedoms of the Data Subject.

  • Processing Condition

    • Necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the Controller or the Data Subject in connection with employment, social security or social protection. (Paragraph 1(1)(a), Schedule 1, DPA 2018.)

    • Meets one of the substantial public interest conditions set out in Part 2 of Schedule 1 to the DPA 2018 (such as preventing or detecting unlawful acts). (Paragraph 10(1), Schedule 1, DPA 2018.)

Equal opportunity data

  • Lawful Processing Basis

    • In the organisation's legitimate interests (Article 6(1)(f)) which are not outweighed by the fundamental rights and freedoms of the Data Subject.

  • Processing Condition

    • Necessary for the purposes of identifying or keeping under review the existence or absence of equality of opportunity or treatment between groups of people specified in relation to that category with a view to enabling such equality to be promoted or maintained. (Paragraph 8(1)(b), Schedule 1, DPA 2018.)

Principle (b): purpose limitation

Our purposes for processing are set out in our website privacy notice. We will not process personal data for purposes incompatible with the original purpose it was collected for.

Principle (c): data minimisation

We collect personal data necessary for the relevant purposes and ensure it is not excessive. The information we process is necessary for and proportionate to our purposes. Where personal data is provided to us or obtained by us, but is not relevant to our stated purposes, we will erase it.

Principle (d): accuracy

Where we become aware that personal data is inaccurate or out of date, having regard to the purpose for which it is being processed, we will take every reasonable step to ensure that data is erased or rectified without delay. If we decide not to either erase or rectify it, for example because the lawful basis we rely on to process the data means these rights don’t apply, we will document our decision.

Principle (e): storage limitation

All special category data processed by us is retained for the periods set out in our retention schedules. Where bespoke retention schedules have been created for Betty Staffords Care Ltd, the retention periods for this data are based on our business needs, best practice and/or legal obligations. Our retention schedules are reviewed regularly and updated when necessary.

Principle (f): integrity and confidentiality (security)

Electronic information is processed within our secure network. Hard copy information is processed in line with appropriate security procedures. Both our electronic systems and physical storage have appropriate access controls applied. The systems we use to process personal data allow us to erase or update personal data at any point in time, where required.

Retention policies

Our retention policies are available via our website in our website privacy policy.

APD review

This policy will be reviewed in line with the review procedures for Betty Staffords Care Ltd’s Data Protection Policy. It may be revised more frequently if necessary.

This Appropriate Policy Document has been approved and authorised by:

Name: Elizabeth Jane Lewis

Position: Director

Date: June 2026

Due for Review by: June 2027