Photo 51

Policies

Privacy Notice

How Photo 51 CIC collects, uses and protects personal information.

Version
2.2
Last updated
October 2026
Review
July 2027

1. Who we are

Photo 51 CIC is a community interest company (company no. 16605213) delivering film, music, podcasting, digital skills and youth enrichment programmes across London. We are the data controller for the personal information we hold.

Registered address: 5 Brayford Square, London E1 0SG
Contact: info@photo51.org.uk

2. What information we collect

Depending on your relationship with us, we may collect:

  • For young people who sign up to our programmes: name, date of birth, phone number, email if you choose to give it, and three separate choices about photos and film
  • For young people under 18: a parent or carer’s name, phone number and, if given, email address, and their consent
  • Only if a young person chooses to tell us: support needs (medical, mental health or wellbeing, neurodivergence or something else) in their own words, and whether they would like a private chat with the session lead. Only our two safeguarding leads can see this, and it is deleted when they finish
  • A short note that every staff member on their programme needs, for example something that can upset them and what helps, or something they asked us to share. Only our safeguarding leads write it, they keep it to what staff need, and it is deleted when they finish
  • Only where we run a session without a partner who holds them: an emergency contact. We do not collect young people’s addresses or schools
  • Attendance records and session registers
  • Information about needs, interests or circumstances relevant to our programmes, provided voluntarily
  • Photographs or video footage taken during sessions, with consent
  • Feedback, evaluation responses, and anonymised views gathered to inform programme reports and service development
  • Safeguarding records, where a concern arises
  • For staff, volunteers and sessional workers: name, email, phone number, date of birth, home address and postcode, and an emergency contact’s name, relationship and phone number
  • For staff, volunteers and sessional workers: your DBS certificate number, its issue date and whether you are on the DBS Update Service, the dates our safer recruitment checks were completed, and your signed policy agreement, self-declaration and induction result. We never keep a copy or photo of a DBS certificate
  • For paid roles: the date and method of your right to work check, and a copy of your right to work evidence where the law requires us to keep one. If you give us a Home Office share code, it is deleted once the check is done. We do not record your nationality or immigration status
  • Optional: a photo of your face for an ID badge, and your T-shirt size
  • Optional equal opportunities monitoring answers from staff, volunteers and young people. These are stored anonymously, with no name, email or link to you, and are only ever reported as totals once five or more people have answered

3. Why we collect it

  • To deliver our programmes safely and effectively
  • To meet safeguarding and legal obligations
  • To report to funders and commissioners on programme outcomes, anonymised wherever possible
  • To produce insight and evaluation reports for commissioners, using anonymised and aggregated information only
  • To communicate with participants, families and partners
  • To improve our services over time
  • For staff and volunteers: to carry out safer recruitment checks, meet right to work law for paid roles, pay you and post documents to you, contact someone if something happens to you during a session, and make ID badges and team clothing
  • To check, anonymously, that our team reflects the communities we work with

4. Legal basis

  • Legitimate interests: to deliver and improve our community programmes.
  • Consent: for photographs, video, non-essential communications, and the use of anonymised views in reports. For anyone under 18, we also ask a parent or carer to agree to them taking part and to their photo and film choices. Young people aged 13 and over can agree for themselves to their anonymised views being used in reports.
  • Legal obligation: for safeguarding and statutory compliance, including right to work checks for paid roles under the Immigration, Asylum and Nationality Act 2006.
  • Contract: to pay staff and sessional workers and manage the work they do for us.
  • Criminal records information: DBS numbers, check dates and self-declarations are processed only for safer recruitment, under the safeguarding of children and individuals at risk condition in Schedule 1 of the Data Protection Act 2018.
  • Consent: for the optional ID badge photo, which you can ask us to delete at any time. Equal opportunities answers are optional and anonymous.
  • Explicit consent: for any health, mental health or neurodivergence information a young person chooses to share so we can support them safely. They (or their parent or carer) can ask us to delete it at any time.

5. Who we share it with

We do not sell personal data, and we do not share it with third parties for commercial purposes. We may share information with:

  • Partner organisations involved in delivering a specific programme, limited to what that delivery requires
  • Funders and commissioners, where required to evidence outcomes, anonymised wherever possible
  • Statutory agencies (police, children’s social care) where safeguarding obligations require it: safeguarding overrides consent where a child is at risk
  • When we deliver in a partner’s space, the partner may already hold young people’s emergency contacts and medical information under their own privacy notice. We do not copy it
  • Service providers who process data for us under data protection terms: Cloudflare (our website, and the secure database and file storage for staff onboarding records, held in the European Union), Resend (sending emails from our website), Google Workspace (our email and documents), and Cloudflare Workers AI (turning staff voice debriefs into text; see below). Where a provider processes data outside the UK, it does so under UK adequacy regulations or approved contract terms

6. How long we keep it

  • Attendance and session records: minimum three years
  • Young people’s sign up details and consent: three years after the programme, or their time on it, ends. Consent links sent to parents and carers work once and expire after 14 days
  • Young people’s support needs, and any note we share with all staff on their programme: deleted as soon as they finish the programme
  • Calls and messages between staff and a young person outside sessions: a short log (who, when, how, a few words on what about), so our safeguarding leads can see contact is appropriate. Kept for three years. Only the safeguarding leads can read it
  • Check-ins: short, optional ratings young people give themselves from 1 to 5 (for example how confident they feel sharing ideas), so we can see what is changing for them and show funders our work makes a difference. Any question can be skipped, including an optional question in their own words; those words are only quoted in reports if they say yes, and never with their name. Individual answers are seen only by our safeguarding leads; staff running a session do not see them. Reports use totals with no names. Kept with their sign up details and deleted at the same time
  • Case studies: a young person's story, written by our leads and used in reports only with their agreement (and a parent or carer's for under 18s). Anonymous unless they agree to their first name; never a surname. Kept with their sign up details and deleted at the same time, though copies already in published reports cannot be recalled
  • Progress: steps a young person takes with us (for example leading a project) and what they go on to do (for example starting a course or a job), each with a few words of evidence, recorded by our leads so we can show what changed. Reports use totals with no names. Kept with their sign up details and deleted at the same time
  • Young people who drop in to a session before signing up: their name only, on that session’s register, kept for three years. No contact details, and no photos or film of them until they sign up
  • Safeguarding records, including concerns reported by our team: at least seven years, or until the young person is 25 if that is later. Stored separately from programme records, readable only by our Designated Safeguarding Lead and Deputy, and every time a record is opened is logged
  • Photographs and video: until consent is withdrawn or the consented purpose is complete
  • Anonymised evaluation and insight data: retained as programme evidence; it contains no identifiable personal information
  • Staff and volunteer safeguarding records (signed agreements, induction, DBS details and check dates, date of birth): seven years after you stop working with us, then deleted
  • How long you actively spent on the onboarding form and the staff guide (time away from the page is not counted), so we can check the induction is realistic and that it was read: kept with your staff record
  • When you sign in to take registers: a record of when you signed in and which registers and forms you opened, so the safeguarding leads can check who saw young people’s details if a concern is ever raised. Kept for three years. Only the safeguarding leads can see it
  • Right to work check records and copies of evidence: two years after you stop working with us, then deleted automatically
  • Hours, pay and expenses: your pay rate if you are paid, the sessions you were on duty for, time you log outside sessions (labelled by type, never with details of young people), expenses with photos of receipts, who authorised and signed them off, and when they were paid, so we can check invoices, pay you back, cost our work and meet tax law. Seen only by our finance lead, the safeguarding leads, the lead of a session an expense belongs to, and you. Kept seven years, then deleted
  • Voice debriefs: staff can record themselves talking a session through, after young people have left. The recording is sent to Cloudflare Workers AI to be written out and sorted into the debrief headings, then dropped: it is never stored, and Cloudflare does not use it to train AI. Young people’s names from the register are taken out before anything is shown. Nothing is saved until a member of staff chooses to add it to the debrief, which is then kept like any written debrief. We record that a voice debrief was used, but not what was said
  • Phone number, home address, emergency contact, ID badge photo and T-shirt size: deleted when you stop working with us
  • Invite links to our onboarding form: work once and expire after 14 days. If you save part way, your answers so far are kept with your link so you can finish later, then deleted when you sign or the link expires. Your anonymous equal opportunities answers are never saved part way
  • Equal opportunities answers: anonymous, kept as totals only

7. Your rights

  • Access the personal information we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data, subject to our legal obligations
  • Withdraw consent at any time for consent-based processing
  • Complain to the Information Commissioner’s Office (ico.org.uk) if you believe your rights have been breached

To exercise any of these rights, contact info@photo51.org.uk. Young people can exercise these rights themselves where they have the capacity to do so; parents and guardians can act for younger children.

8. Photographs and video

We only photograph or film participants with their explicit consent, recorded when they sign up as three separate choices: our own records and funder reports, our website and social media, and appearing in films we share publicly. For under 18s a parent or carer must also agree, online, on paper, or by phone followed up in writing within 14 days. Consent may be withdrawn at any time. Images are never used beyond what was agreed at the point of consent, and never in a way that could identify a young person as connected to a sensitive programme.

9. How we keep it secure

Personal data is held in secure, access-controlled systems. Safeguarding records are accessible only to the Designated Safeguarding Lead and Deputy. In our staff onboarding system, the finance lead can see only names, contact details, address and right to work records, never safeguarding information. Each person signs in with their own account protected by 2-Step Verification, and every action is logged with who did it and when. Paper records, where unavoidable, are stored locked and transferred to secure digital storage promptly.

10. Changes to this notice

We may update this notice from time to time. The current version is always available on request and at photo51.org.uk.

Photo 51 CIC · 5 Brayford Square, London E1 0SG · info@photo51.org.uk · photo51.org.uk