Policy and practiceContracts and data

1.2.3 Data Protection

Version v3 ·

Overview

When organising educational visits, personal information is often collected and shared to help keep participants safe. This may include medical information, emergency contacts, or other relevant details.

Protecting this information is essential. Schools must handle personal data responsibly and in line with legal requirements to safeguard participants and maintain trust with families.

All personal data must be handled in accordance with the Data Protection Act 2018 and UK GDPR. This applies to how information is collected, stored, used and shared.

Personal data must be handled:

  • Lawfully, fairly and transparently
  • Only for clear and specific purposes
  • Securely and only for as long as necessary

Always follow your setting’s data protection policies when planning and running visits.

Collecting and Sharing Information

As a Visit Leader you need accurate and up-to-date information to support participant welfare during a visit. This may include:

  • Emergency contact details
  • Medical conditions and medication
  • Dietary requirements
  • Other relevant information, such as swimming ability or accessibility needs

Use secure methods to collect and share this information, such as approved digital systems or official forms. Parents should be encouraged to provide accurate information so that appropriate support can be arranged.

Sensitive Information

Some information is particularly sensitive, including:

  • Medical conditions or allergies
  • Dietary needs
  • Safeguarding information
  • Emergency contact details

Access to this information should be limited to staff who need it to ensure participants’ safety and wellbeing.

Parents must be informed about how personal data will be used and shared. This is usually explained through the school’s privacy policy.

In some cases, specific consent may be required, for example when sharing personal data with residential centres or activity providers. Electronic consent is acceptable if it is securely recorded.

Photographs and Media

Photographs or videos in which individuals can be identified are considered personal data.

Settings must obtain appropriate parental consent before taking or using such images, unless they are required for safety or security purposes.

Working with External Providers

If participant information is shared with external providers, you should ensure they follow appropriate data protection standards. Check how they will store, use, and eventually delete or return personal information.

Data Security and Retention

Personal information must be stored securely and access limited to authorised staff. After the visit, information should be deleted or retained in line with your setting’s data retention policy.

In an emergency, relevant information may be shared without consent if necessary to protect life or safety.

Key Points

  • Only collect information that is necessary for the visit
  • Keep personal data accurate and up to date
  • Limit access to sensitive information
  • Store and share data securely
  • Follow your establishment’s policies and legal requirements

Links to further reading:

  • OEAP National Guidance available at https://oeapng.info
  • 4.4j Participant Information and Data Protection