Last updated: 22 August, 2026

Purpose This policy sets out how FutureBridge Foundation meets its obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 when handling personal data belonging to beneficiaries, donors, volunteers, staff and trustees.

Our principles We process personal data lawfully, fairly and transparently; only for specified purposes; adequately but not excessively; accurately; for no longer than necessary; and securely.

Responsibilities The Board of Trustees has overall responsibility for data protection compliance. All staff, volunteers and trustees handling personal data are responsible for following this policy and related guidance.

Data security We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or damage, including access controls and secure storage of physical and digital records.

Data breaches Any suspected data breach must be reported immediately to [Data Protection lead to be confirmed]. Where required, breaches will be reported to the Information Commissioner’s Office within the statutory timeframe.

Retention Personal data is retained only for as long as necessary for the purpose it was collected, in line with our data retention schedule. [To be finalised by trustees.]

Training Anyone handling personal data on behalf of the Foundation receives appropriate guidance on their data protection responsibilities.

Related policy This policy should be read alongside our Privacy Policy, which explains how we use personal data collected through our website.

Review This policy is reviewed annually by the Board of Trustees.