Group Privacy and Data Protection Policy
1. Introduction
The Scout Association (TSA) takes the protection of privacy and personal data very seriously. Hence it has introduced:
A Privacy and Data Protection Policy, with key responsibilities listed as rules, in its Policy, Organisation and Rules (POR), in the May 2026 edition (POR May 2026, 2a.3.1);
A Data Protection Policy, external to but referenced from POR May 2026.
These are referred to jointly in this Policy as the ‘TSA Data Protection Policy’.
The TSA Data Protection Policy sets out the Scout Association’s approach to protecting personal data in compliance with:
The EU General Data Protection Regulation “GDPR”, Regulation (EU) 2016/679 of 27 April 2016;
The UK Data Protection Act 2018; and also explains people’s legal rights in relation to how their personal data is processed.
It is important to note that local Scout Groups:
Are independent charities and are Data Controllers in their own right;
Are directly responsible for any personal data they process; and
Are directly responsible, therefore, for ensuring that they comply with their responsibilities under both the law and the rules of the Scout Association.
3rd Winchester may update this policy from time to time in minor respects. It will make sure that any substantial or significant changes will be notified to members and associate members directly.
2. Purpose of this Data Protection Policy and what it covers
This policy:
Relates to 3rd Winchester (The Worthies) Scout Group (‘3rd Winchester’ and ‘the Group’ in this policy);
Sets out the Group’s approach to protecting personal data; and
Explains people’s rights in relation to how the Group may process personal data;
Only addresses the changes in policy from the TSA Data Protection Policy that relate those policies to local circumstances;
Follows the section numbering of TSA Data Protection Policy from Section 5 onwards.
In the event of any conflict then the TSA Data Protection Policy or its successors take precedence over this policy.
3. Agreement of data controllers and data processors to abide by this policy
Many people within the Group act as data controllers and data processors. This includes Leaders (Team Members), Team Leaders, Lead Volunteers, Supporters, Administrators, Committee members and Trustee Board members. They are therefore both data controllers and data processors. These people are empowered to decide the purposes and methods of processing personal data and carry it out subject to complying with the TSA Data Protection Policy and this Policy.
All adult members and associate members of TSA have accepted the Applicant Declaration on The Scout Association Digital Membership System confirming that they agree to abide by the policies and rules of The Scout Association. With respect to data protection these are:
The TSA Data Protection Policy as identified above; and
This policy (3rd Winchester).
Hence all adult members and associate members have agreed to abide by these policies for the processing of personal data in association with the Group.
Initially, this presumes that all data processors and data controllers operating on behalf of 3rd Winchester are adult members or associate members of TSA. In practice, the key data processors and data controllers are adult members or associate members of TSA and it is required under Section 7 of the TSA Data Protection Policy that:
Before sharing personal data with other people or organisations, [the data processors and data controllers] must ensure that [the recipient people or organisations] are GDPR compliant;
[Appropriate] rights of access [are] allocated to users depending on their need to access personal or confidential information;
[No person] should have access to personal or confidential information unless [they] need it to carry out [their] role.
For clarity, there are occasions where it is appropriate to share personal data with other people including young (non-adult) members of TSA and non-members involved in activities (e.g. parents); in such cases the adult member or associate member sharing the personal data must ensure that the person receiving it is fully aware of and will adhere to the requirements for only keeping it private, only using it for the purpose intended and destroying it, or returning it, at the end of the period for which it was provided.
4. Non-registration with the Information Commissioner’s Office
3rd Winchester is not registered with the Information Commissioner’s Office. This is not required as the Group:
Only processes information necessary to establish or maintain membership or support;
Only processes information necessary to provide or administer activities for people who are members of the organisation or have regular contact with it;
Only holds information about individuals whose data it needs to process for this exempt purpose; and
The personal data processed is restricted to personal information that is necessary for this exempt purpose.
This non-registration shall be reviewed if any changes are made to the type of information being processed. It is noted that this specifically includes the installation of CCTV monitoring and recording at any of its premises, events or otherwise.
It should be noted that CCTV is in operation at Pinsent Campsite and is monitored on a District Level and is noted in the District’s policy. Winchester District is therefore registered with the ICO.
5. What type of personal data do we collect and why?
5.1 Adults
For adults there are no changes or additions to Section 5 of The Data Protection Policy, referenced from POR, May 2026.
5.2 Explorers & Young Leaders
Explorers and Young Leaders are youth members, aged between 14 to 18 years of age. Explorers is split into multiple Units with all Units, and therefore Data Protection compliance, forming part of the District. The District also hold personal data of individuals on the Explorer waiting list. Young Leaders must be registered with the District. Explorers, Young Leaders and those on the Explorer waiting list, their data stored is as per Section 5.3, below. Their personal data of Young Leaders is both held by the district (under their Policy) and by 3rd Winchester.
5.3 Youth members and adult volunteers
In addition to the information on adults addressed by Section 5 of the TSA Data Protection Policy, 3rd Winchester also record information about young people and additional information on adult members. The information we may hold about young people and adult members includes the following:
Name and contact details, including emergency contact details
Age/date of birth
Details of any health conditions/allergies/dietary requirements
Ethnicity
Gender
Nationality
Religion
Disciplinary information
Details of dependents
Records relating to the time for which they were members
Length and periods of membership (and absence from membership)
Record of attendance at events including nights away, hikes, time on the water and similar activities
Details of training received and awards/badges gained
Details of experience, qualifications, occupations and skills
For young people employed in the same manner as adults, the list of information held about adults also applies (see Section 5.1 above)
Name and contact details of parents/guardians
Information of parents/guardians/associated adults’ experience, qualifications, occupations and skills where provided by the parents/guardians/associated adults that may assist in delivering a quality programme (note that where parents/guardians/ associated adults are registered directly with TSA then their data is addressed under the provisions for adults
Photographic preferences
5.4 Data storage
Within the Group:
Adults’ information is stored on The Scout Association Digital Membership System, the Scout Association’s adult database;
Young persons’, Network and Adult Leaders information is stored on Online Scout Manager (OSM), a commercially available database management system specifically designed to store information about young people and adult members in TSA;
Adult members and associate members may take copies of this information and process it in support of the Group’s business on a temporary basis and subject to the provisions for data protection;
If a need arises to store any personal data that cannot be readily or clearly stored in The Scout Association Digital Membership System or OSM then the 3rd Winchester Trustee Board shall be informed of the type of data, the reason for storage and the means of storage. Examples include the allocation of a line manager in accord with POR but not made available by The Scout Association Digital Membership System or the recording of a condition on role approval.
Pinsent Scout Campsite (District) stores data related to booking of the campsite and onsite activities, as well as activity instructors, on Online Scout Manager (OSM), a commercially available database management system specifically designed to store information related to the Campsite.
5.5 Data passed to other organisations
The Group passes data to other organisations in order to deliver its legitimate purposes.
These are:
The Duke of Edinburgh’s Award organisation - in passing the essential information to this organisation the Group assumes that the Duke of Edinburgh’s Award organisation is a responsible organisation that takes on the responsibility for the data passed.
Other third-party organisations that need the data in order to provide activities in accordance with acceptable safety standards - in this case the data processor passing the information to the third party must ensure that the third party is committed to processing the data in line with the legal requirements (This can be seen as an extension to Rule 9.9 Use of External Centres and Instructors)
Third-party organisation where the Group has a Legal requirement to provide personal data to an external organisation. This may include, The Scout Association Safeguarding Team, the Police, Social Services, and The Health Security Agency (this is not an exhaustive list).
6. Conditions for collecting personal data
No changes or additions to Section 6 of The Data Protection Policy, referenced from POR May 2026.
7. Keeping personal data secure
The Data Protection Policy, referenced from POR, May 2026, it is noted that many volunteers process relevant data in locations that, while entry-controlled, are not restricted to adult members or associate members. Such locations include family houses and computers with family access. In such situations, the data processor is required to ensure the principles are satisfied. This is likely to require:
Password protection of access to databases including The Scout Association Digital Membership System and OSM at the point of entry to the database website itself rather than the machine used to access it;
Closing the access to such databases and files when leaving the access point unattended;
Password protection of files containing relevant information;
Each data processor providing 3rd Winchester with an email address that can only read by the data processor themselves.
Where files are shared over email, they must be password protected, the password conveyed over either a separate email or by separate communication systems (i.e. text message).
8. Responsibilities
Within 3rd Winchester, the Group Trustee Board is responsible for ensuring that adequate data protection systems are in place in respect of the processing of personal data on behalf of the Group. To this effect, the Trustee Board is responsible for:
Making sure that this data protection policy is up to date;
Obtaining advice, as required, for people acting as its data processors and data controllers on data protection issues;
Dealing with complaints about the Group’s use of personal and sensitive personal data;
Reporting to the ICO if the Group does not keep to any regulations or legislation
9. Data Retention
No changes or additions to Section 9 of the TSA Data Protection Policy.
10. Rights to accessing and updating personal data
No changes or additions to Section 10 of the TSA Data Protection Policy.
In the event a person wishes to access, amend, update or removed their personal data, which 3rd Winchester holds, they should first do this via an online portal, for example OSM Parents Portal and/or TSA Membership system. If this is not possible, they should then contact their Leader or Line Manager for assistance. If they are still not satisfied that the appropriate access, amendment, update or removal has been made, the individual should contact the Data Protection Compliance Officer, as per Section 12 of this Policy, below.
11. Subject access requests
No changes or additions to Section 11 of the TSA Data Protection Policy.
To request a Subject Access Request from the Group, contact should be made with the Group Data Protection Compliance Officer, as per Section 12, below.
12. Further information and contacts
Subject access requests for data held by the 3rd Winchester should be made to the
Groups Data Protection Compliance Officer at Chair@3rdwinscouts.org.uk
If you have any queries about anything set out in this policy or about your own rights, please contact the District Data Protection Compliance Officer at the above email address.