Confidentiality Policy

Introduction

At Rainbow Rogues, we are committed to maintaining the confidentiality and privacy of all individuals accessing our services, including service users, staff, volunteers, and stakeholders. We recognise that confidentiality is essential for building trust, ensuring privacy, and upholding the dignity of individuals. This policy outlines our commitment to protecting confidential information and the procedures we follow to maintain confidentiality.

Scope

This policy applies to all staff, volunteers, and individuals associated with Rainbow Rogues who may have access to confidential information as part of their roles or responsibilities.

Definition of Confidential Information

Confidential information includes, but is not limited to, personal data, sensitive information, and any details related to the identities, circumstances, or experiences of service users, staff, volunteers, and stakeholders. This may include:
• Personal details (e.g., name, address, contact information)
• Medical or health-related information
• Financial information
• Family or household information
• Case notes, assessments, and records
• Any information shared in confidence by individuals accessing our services
• Counselling-related data, including session notes, intake forms, clinical observations, and personal disclosures made during counselling

Confidentiality Responsibilities

Access to Information: Access to confidential information is restricted to authorised individuals who require it to perform their duties. Staff, volunteers, and stakeholders must adhere to the principle of least privilege and only access information necessary for their role.
Clinical Confidentiality: Counsellors, including trainees, are expected to uphold clinical confidentiality in accordance with professional ethical standards, such as those outlined by COSCA or BACP. Breaches will be treated with the same seriousness as those involving other staff.
Non-Disclosure: Confidential information must not be disclosed, shared, or discussed with unauthorised individuals or third parties without the explicit consent of the individual concerned or as required by law.
Data Protection: Rainbow Rogues complies with relevant data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, to ensure the lawful and secure processing of personal data.
Storage and Disposal: Confidential information must be stored securely and protected from unauthorised access, loss, or theft. When no longer required, confidential records and documents must be securely disposed of in accordance with data protection guidelines.

Confidentiality Procedures

All staff, volunteers, and stakeholders will receive training on confidentiality policies and procedures upon joining Rainbow Rogues and will receive regular updates thereafter. Confidentiality agreements may be required for individuals accessing sensitive information as part of their role. Breaches of confidentiality will be taken seriously and may result in disciplinary action, including termination of employment or volunteer status.

Confidentiality Safeguards

Rainbow Rogues implements appropriate technical, physical, and organisational safeguards to protect confidential information from unauthorised access, disclosure, or alteration. Encryption, password protection, and access controls are used to secure electronic data, while physical documents are stored in locked cabinets or rooms. Any breach of confidentiality, particularly involving personal data, will be handled according to Rainbow Rogues’ Data Breach Protocol. Serious breaches may be reported to the Information Commissioner’s Office (ICO).

Confidentiality Commitment

Rainbow Rogues is committed to upholding the highest standards of confidentiality and privacy in all aspects of our work. We recognise that confidentiality is fundamental to building trusting relationships with individuals accessing our services and maintaining their confidence in our organisation.

Sharing Information with Outside Agencies

Rainbow Rogues will share information with outside agencies only when the parent has given written consent. Information may be given verbally or in written form. If verbal information has been shared, notes will be taken of the conversation and will be kept on the Child’s Care Plan. Copies of any reports we issue can be sent to parents for their records upon request. Information shared by children or young people will be treated with the same level of confidentiality and respect. In cases where safeguarding concerns arise, Rainbow Rogues will act in accordance with its Child Protection Policy.

Private Facebook Group

All Parents will be invited to join the private Facebook group. This group is used to share information and ask for advice. Parents should expect to participate in this group, understanding that some discussions will be confidential. All Parents, therefore, must use their common sense and keep any information they see in this group confidential, not discussing the matters outside the group. Any breaches of confidentiality in this group will be addressed in accordance with this policy and may result in removal from the group or further action.

Additional Safeguards and Best Practices

• Staff have access to confidentiality training (GDPR) via their ALDO platform and are fully responsible for keeping their training current.
• Confidentiality Training Records: Rainbow Rogues maintains a record of all confidentiality training completed by staff and volunteers. This is reviewed biannually to ensure that everyone is up to date with current expectations and responsibilities.
• Remote Work and Digital Communication: Staff and volunteers are expected to maintain confidentiality when working remotely or communicating digitally. All digital communication, including emails and video calls, should be conducted using secure platforms authorised by Rainbow Rogues.
• Third-Party Platforms and IT Providers: Any third-party software or IT providers used to store or transmit confidential information must meet UK GDPR standards and have appropriate data processing agreements in place. This includes platforms used for storing care plans, counselling notes, and communication.

Monitoring and Review

The procedures outlined in this policy will be reviewed regularly or included in internal audits to ensure they are being followed effectively and remain current with the latest guidance.

Contact Information

If you have any questions or concerns about confidentiality, please get in touch with the Manager at Rainbow Rogues by email: manager@rainbowrogues.org.uk