General principles
General principles
XXXX recognises that XXXX employees, volunteers, trustees, secondees and
students use information about individuals and organisations during the
course of their work or activities. In most cases information will not be stated
as confidential and it will be necessary to use common sense and discretion
in deciding whether information is expected to be confidential. This policy
aims to give guidance but if in doubt, seek advice from XXXX.
Colleagues are able to share information with their line manager where
necessary to discuss issues and seek advice.
Colleagues should avoid exchanging personal information about individuals
with whom they have a professional relationship.
It is not appropriate to discuss a person’s sexuality without their prior
Colleagues should avoid talking about organisations or individuals in social
Colleagues will not disclose to anyone, other than their line manager, any
information considered sensitive, personal, financial or private without the
knowledge or consent of the individual, or an officer, in the case of an
If it is necessary to discuss difficult situations with each other to gain a wider
perspective on how to approach a problem the organisation’s consent must
be sought before personal information enters into the discussion, unless it is
beyond doubt that the organisation would not object to this. Alternatively, a
discussion may take place with names or identifying information remaining
Where there is a legal duty on XXXX to disclose information, the person to
whom the confidentiality is owed will be informed that disclosure has or will
be made.
Why information is held
Why information is held
Most information held by XXXX relates to organisations or individuals which
support or fund them etc.
Information is kept to enable XXXX colleagues to XXXX.
XXXX has a role in putting people in touch with voluntary and community
organisations and keeps contact details which are passed on to any
enquirer, except where the group or organisation expressly requests that the
details remain confidential.
Information about volunteers is given to known groups or statutory agencies
which request volunteers, but is not disclosed to anyone else.
Information about students is given to the training organisation and the
college, but to no one else.
Information about ethnicity and disability of users is kept for the purposes of
monitoring our equal opportunities policy and also for reporting back to
Access to information
Access to information
Information is confidential to XXXX as an organisation and may be passed to
colleagues, line managers or trustees to ensure the best quality service for
3.2. Where information is sensitive, i.e. it involves disputes or legal issues, it will
be confidential to the employee dealing with the case and their line
manager. Such information should be clearly labelled ‘Confidential’ and
should state the names of the colleagues entitled to access the information
and the name of the individual or group who may request access to the
Colleagues will not withhold information from their line manager unless it is
purely personal.
Users may have sight of XXXX records held in their name or that of their
organisation. The request must be in writing to the Director giving 14 days’
notice and be signed by the individual, or in the case of an organisation’s
records, by the Chair or Executive Officer. Sensitive information as outlined
in paragraph 3.2 will only be made available to the person or organisation
named on the file.

Employees may have sight of their personnel records by giving 14 days’
notice in writing to the Director.
When photocopying or working on confidential documents, colleagues must
ensure they are not accidentally seen by others. This also applies to
information on computer screens.
Storing information
Storing information
General non-confidential information about organisations is kept in unlocked
filing cabinets with open access to all XXXX colleagues.
Information about volunteers, students and other individuals will be kept in
filing cabinets by the colleague directly responsible. These colleagues must
ensure line managers know how to gain access.
Employees’ personnel information will be kept in lockable filing cabinets by
line managers and will be accessible to the Director.
Files or filing cabinet drawers bearing confidential information should be
labelled ‘confidential’.
In an emergency situation, the Director may authorise access to files by
other people.
Duty to disc
Duty to disclose information
There is a legal duty to disclose some information including:
Child abuse will be reported to the Social Services Department
Drug trafficking, money laundering, acts of terrorism or treason will
be disclosed to the police.
In addition if colleagues believe that an illegal act has taken place, or that a
user is at risk of harming themselves or others, they must report this to the
Director who will report it to the appropriate authorities.
Users should be informed of this disclosure.
6.1 When dealing with Disclosures and Disclosure information XXXX complies
fully with the CRBS Code of practice
6.2 Disclosure information is always kept separately from an applicant’s
personnel file in secure storage with access limited to those who are entitled
to see it as part of their duties. It is a criminal offence
criminal offence to pass this
criminal offence to pass this
information to anyone who is not entitled to receive it.
6.3 Documents will be kept for a year and then destroyed by secure means.
Photocopies will not be kept. However, XXXX may keep a record of the date

of issue of a Disclosure, the name of the subject, the type of Disclosure
requested, the position for which the Disclosure was requested, the unique
reference number of the Disclosure and the details of the recruitment
decision taken.
Data Protection Act
Data Protection Act
7.1. Information about individuals, whether on computer or on paper, falls within
the scope of the Data Protection Act and must comply with the data
protection principles. These are that personal data must be:
Obtained and processed fairly and lawfully.
Held only for specified purposes.
• Adequate, relevant and not excessive.
Accurate and up to date.
Not kept longer than necessary.
Processed in accordance with the Act.
Kept secure and protected.
Not transferred out of Europe.
Breach of confidentiality
Breach of confidentiality
8.1. Employees who are dissatisfied with the conduct or actions of other
colleagues or XXXX should raise this with their line manager using the
grievance procedure, if necessary, and not discuss their dissatisfaction
outside XXXX.
8.2. Colleagues accessing unauthorised files or breaching confidentially may face
disciplinary action. Ex-employees breaching confidentiality may face legal
9.1. Where the Finance Officer has concerns about the use of XXXX funds, he or she
may refer directly to the Chair or Treasurer outside the usual grievance procedure.