JournoTECH

Loading

DATA PROTECTION, GDPR AND RECORDS MANAGEMENT POLICY

About our data protection, GDPR & Records management policy

JournoTECH works across technology, artificial intelligence, digital security, journalism, education, research, digital creativity and emerging technologies.

Our work involves handling information about staff, volunteers, trainers, participants, partners, clients, researchers, community members and other people who interact with us.

We take the protection of personal information seriously. This policy explains how JournoTECH approaches data protection, privacy, information security and record keeping across our work.

This policy applies to our day-to-day operations, programmes, training, research, events, community activities, communications and digital services.

Our separate Cookie Policy covers the use of cookies and similar technologies on our website.

Our commitment

JournoTECH will handle personal information responsibly, fairly and transparently.

We will:

  • only collect information that we have a legitimate reason to use;
  • explain, where appropriate, why we are collecting information and how it will be used;
  • keep personal information accurate where reasonably possible;
  • protect information against unauthorised access, loss, misuse or disclosure;
  • only keep information for as long as it is needed;
  • respect people’s data protection rights;
  • take additional care when handling information about children, young people and adults who may require additional support;
  • investigate and respond appropriately to suspected data breaches;
  • regularly review our data protection and information-handling practices.

What personal information we may collect

Depending on our relationship with an individual and the activity involved, JournoTECH may collect information such as:

  • names and contact details;
  • email addresses and telephone numbers;
  • organisation and professional information;
  • participant registration information;
  • parent/carer and emergency contact information;
  • attendance information;
  • dietary and allergy information where necessary for an activity;
  • accessibility and reasonable-adjustment information;
  • staff, freelancer and volunteer information;
  • DBS and safeguarding-related information where appropriate;
  • photographs, video and other media;
  • correspondence and communications;
  • research and interview information;
  • grant and programme records;
  • financial and payment information;
  • information required to manage our services and programmes.

We will avoid collecting information simply because it might be useful in the future.

Why we use personal information

JournoTECH may use personal information to:

  • deliver training, programmes, events and services;
  • communicate with participants, parents/carers, staff, partners and clients;
  • manage registrations and attendance;
  • provide appropriate support and reasonable adjustments;
  • protect the health, safety and safeguarding of participants;
  • manage staff, volunteers, trainers and specialists;
  • conduct research and evaluation;
  • administer grants and funding requirements;
  • manage finances and administration;
  • maintain appropriate organisational records;
  • improve our programmes and services;
  • comply with legal and regulatory requirements;
  • respond to enquiries and requests.

Where consent is the appropriate legal basis for processing, we will seek consent in a clear and appropriate way.

Children and young people’s information

JournoTECH may work with children and young people through training, education, community programmes and other activities.

We will take particular care when collecting and using information about children and young people.

Where appropriate, we will:

  • collect only information that is necessary;
  • explain how information will be used in an age-appropriate way;
  • obtain appropriate parent/carer consent where required;
  • keep children’s information secure;
  • limit access to people who need the information for their role;
  • avoid publicly identifying children unnecessarily;
  • take appropriate care when using photographs, videos or other media.

Data protection arrangements will work alongside our Safeguarding Children, Young People and Adults Policy.

Sensitive and confidential information

Some information requires additional care because of its nature.

This may include information relating to:

  • health or medical needs;
  • allergies and dietary requirements;
  • disability or accessibility needs;
  • safeguarding concerns;
  • DBS checks;
  • financial information;
  • other information that may be particularly private or sensitive.

JournoTECH will only collect or use such information where there is an appropriate reason to do so and will restrict access wherever possible.

Information security

JournoTECH uses digital systems to manage information. These may include email, cloud storage, databases, project management systems and other technology platforms.

We will take reasonable steps to protect information through measures such as:

  • strong passwords;
  • appropriate access controls;
  • multi-factor authentication where available and appropriate;
  • limiting access according to people’s roles;
  • secure cloud services;
  • keeping devices and software appropriately updated;
  • secure sharing of documents;
  • avoiding unnecessary storage of personal information on personal devices;
  • securely disposing of information when it is no longer required.

Staff, volunteers, contractors and others working with JournoTECH must not share passwords or provide unauthorised people with access to personal information.

Access to information

Personal information should only be accessed by people who need it for legitimate JournoTECH activities.

Access may be restricted according to role and responsibility.

For example, information about safeguarding, participants, staff or finances should not automatically be accessible to everyone working with JournoTECH.

Where external trainers, specialists, contractors or partners need access to personal information, JournoTECH will consider what information they genuinely need and what appropriate arrangements are required.

Sharing information

JournoTECH will not routinely share personal information simply because another organisation requests it.

Information may be shared where there is an appropriate legal or operational basis, for example:

  • where an individual has given appropriate consent;
  • where sharing is necessary to deliver a service or programme;
  • where required by law;
  • where necessary to protect someone from serious harm;
  • where required for safeguarding;
  • where required by a funder or regulator and there is an appropriate lawful basis.

We will aim to share only the information that is necessary for the particular purpose.

Safeguarding and information sharing

Data protection does not prevent JournoTECH from taking action to protect someone from harm.

Where there is a safeguarding concern, relevant information may need to be shared with appropriate safeguarding professionals, emergency services, authorities or other relevant organisations.

Information will be handled carefully and only shared where there is an appropriate reason to do so.

Our safeguarding procedures are set out in our Safeguarding Children, Young People and Adults Policy.

Photographs, video and media

JournoTECH may use photographs, video, audio recordings or other media as part of our programmes, journalism, training, research, communications and promotional activities.

Where consent or another appropriate legal basis is required, we will obtain it before using the relevant material.

We will take additional care when photographing or recording children and young people.

We will not assume that permission to participate in a JournoTECH programme automatically means permission to use someone’s photograph, video or other identifiable media for publicity.

Research and interviews

JournoTECH may conduct research, interviews, investigations, evaluations and community engagement activities.

Where personal information is collected for these purposes, we will explain the purpose of the activity and handle the information appropriately.

Where research involves sensitive information or potentially vulnerable participants, additional safeguards may be introduced depending on the nature of the project.

Record keeping

JournoTECH maintains records that are necessary to operate responsibly and meet legal, financial, safeguarding, contractual, funding and organisational requirements.

Records may include:

  • participant records;
  • attendance records;
  • registration forms;
  • consent records;
  • safeguarding records;
  • accident and incident records;
  • staff and volunteer records;
  • DBS and recruitment records;
  • financial and accounting records;
  • grant and funding records;
  • contracts and agreements;
  • research records;
  • photographs and media;
  • correspondence and organisational records.

We will aim to keep records accurate, appropriately organised and secure.

Retention and deletion

JournoTECH will not keep personal information indefinitely without a reason.

Different types of records may need to be kept for different periods depending on:

  • legal requirements;
  • safeguarding considerations;
  • funding requirements;
  • accounting requirements;
  • contractual obligations;
  • insurance requirements;
  • research requirements;
  • legitimate organisational needs.

When information is no longer required, JournoTECH will take reasonable steps to securely delete, destroy or anonymise it.

Some safeguarding, financial, legal or other records may need to be retained for longer than ordinary programme records.

Data protection rights

Individuals may have rights over the personal information JournoTECH holds about them under applicable data protection law.

Depending on the circumstances, these may include rights to:

  • ask what personal information we hold;
  • request access to their information;
  • ask for inaccurate information to be corrected;
  • request deletion where applicable;
  • object to certain processing;
  • request restriction of processing in certain circumstances;
  • withdraw consent where consent is the legal basis for processing;
  • raise a concern with the Information Commissioner’s Office where appropriate.

Requests should be sent to:

Elfredah Kevin-Alerechi
Email: info@journotech.org

We will handle requests in accordance with applicable data protection requirements.

Data breaches

A data breach may include personal information being:

  • accidentally sent to the wrong person;
  • lost or stolen;
  • accessed without authorisation;
  • accidentally deleted;
  • exposed through a security incident;
  • disclosed without an appropriate reason.

Anyone working with JournoTECH who becomes aware of a suspected data breach should report it promptly to the policy contact.

JournoTECH will assess the incident, take steps to contain and reduce any harm, document the incident and consider whether notification to affected individuals or the Information Commissioner’s Office is required.

Third-party services and suppliers

JournoTECH may use external platforms and service providers to operate our programmes and organisation.

Before using a service to process personal information, we will consider its suitability, security, privacy arrangements and the information being processed.

Where appropriate, contractual or other data protection arrangements will be put in place.

Staff, volunteers and contractors

Anyone working with JournoTECH who handles personal information is expected to:

  • respect confidentiality;
  • only access information they need for their role;
  • keep information secure;
  • not share personal information without an appropriate reason;
  • report suspected data breaches;
  • follow JournoTECH’s data protection procedures;
  • complete relevant training where required.

These responsibilities continue after someone stops working with JournoTECH where confidentiality obligations continue to apply.

Data protection and safeguarding

Data protection and safeguarding must work together.

JournoTECH will not use data protection as a reason to ignore a genuine safeguarding concern.

At the same time, safeguarding information will be handled carefully and shared only with appropriate people who need to know.

Policy documents

This policy should be read alongside other JournoTECH policies and procedures, including:

  • Safeguarding Children, Young People and Adults Policy;
  • Equality, Diversity and Inclusion Policy;
  • Health and Safety Policy;
  • Cookie Policy;
  • relevant consent, programme, research and information-security procedures.

Review

JournoTECH will review this policy periodically and when there are significant changes to our activities, technology, data processing practices or applicable data protection requirements.

Policy updated date: September 16, 2026
Policy contact: Elfredah Kevin-Alerechi
Email: info@journotech.org