Privacy notice
How Day One collects, uses and protects personal information
Effective: 19 August 2026 | Version 2
This notice applies to young people and programme participants, parents and guardians, volunteers and mentors, donors and supporters, school and employer contacts, job applicants, website visitors and anyone else who contacts or works with Day One.
It explains what personal information we collect, why we use it, who we share it with, how long we keep it and the rights available to you. We use "personal information" and "personal data" to mean the same thing.
1. Who we are
Day One Opportunities for School Leavers is a Charitable Incorporated Organisation (CIO) registered with the Charity Commission for England and Wales under charity number 1213814. We use the operating name "Day One".
Day One is the data controller for the personal information described in this notice. This means we decide why and how that information is used.
Contact our Privacy Lead if you have a question, wish to exercise a data protection right or want to make a complaint:
- Email: office@mydayone.org.uk
- Post: Day One Opportunities for School Leavers, 483 Green Lanes, London N13 4BC
- Telephone: 020 3951 2511
2. The laws that apply
We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and those laws as amended by the Data (Use and Access) Act 2025 (DUAA).
We apply the data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability.
3. The information we collect
The information we collect depends on how you interact with us. It may include:
- identity and contact details, such as your name, date of birth, address, email address, telephone number and emergency contact details;
- programme and eligibility information, including your school or college, year group, educational history, qualifications, interests, goals, attendance, engagement, feedback and outcomes;
- employment and opportunity information, such as your CV, applications, work experience, interview feedback, references and information needed to make introductions to employers or training providers;
- information about parents, guardians, teachers, school staff, mentors, volunteers, donors, supporters, suppliers, partner organisations and employer contacts;
- communications and preferences, including enquiries, correspondence, consent choices and marketing preferences;
- photographs, audio, video and recordings of programme sessions or events, where appropriate;
- donation and Gift Aid information, transaction details and limited payment information. Full card details are normally collected directly by our payment provider and are not stored by us;
- website and technical information, such as IP address, device, browser, cookie identifiers, pages viewed and how you use our website;
- volunteer, trustee, worker and applicant information, including work history, references, right-to-work information, availability and training records; and
- any other information you choose to give us, or that we need to deliver a service, protect a person or comply with the law.
Special category and criminal offence information
Some information needs extra protection. We may collect information about racial or ethnic origin, health or disability, religious or philosophical beliefs, sexual orientation, sex life, or trade union membership. We may also collect information relating to safeguarding concerns or criminal convictions and offences, including Disclosure and Barring Service (DBS) information where a role requires it.
We collect only what is necessary and apply additional safeguards. Section 6 explains the extra legal conditions we use.
4. How we obtain information
We normally collect information directly from you when you complete a form, apply for or take part in a programme, communicate with us, volunteer, donate, attend an event, use our website or consent to a recording.
We may also receive information from:
- a parent or guardian, school, college, teacher or careers adviser;
- an employer, work-experience host, training provider, delivery partner, mentor or referee;
- a fundraising platform, event organiser or payment provider;
- a regulator, public authority, law-enforcement body or safeguarding organisation;
- publicly available professional sources, such as an organisation's website or LinkedIn, when identifying adult partner, supporter or volunteer contacts; and
- our website, analytics, communications and IT systems.
If we obtain your information from someone else, we will provide privacy information within a reasonable period and normally no later than one month, at our first communication with you, or before the first disclosure, unless the law provides an exception.
5. Why we use information and our lawful bases
We must have a lawful basis under Article 6 of the UK GDPR for each use of personal information. The main activities and bases we rely on are below. More than one basis may apply, depending on the circumstances.
| What we do | Information used | Lawful basis |
|---|---|---|
| Responding to enquiries and assessing applications | Identity, contact, programme, education and communications data | Steps before entering an agreement; legitimate interests in responding, selecting participants and administering our charitable work |
| Delivering programmes, mentoring, events and ongoing support | Identity, contact, programme, attendance, education, goals, feedback and outcomes | Performance of an agreement; legitimate interests in delivering and improving our charitable programmes |
| Working with schools, employers, training providers and delivery partners | Contact, programme, opportunity, CV/application and outcome information | Performance of an agreement; legitimate interests in creating appropriate opportunities and partnerships; consent where we ask you to choose whether information is shared |
| Protecting welfare and safeguarding children or adults at risk | Identity, contact, safeguarding, health and incident information | Legal obligation; vital interests; standard legitimate interests; or, where its statutory conditions are met, recognised legitimate interests under the safeguarding condition |
| Providing accessibility support and reasonable adjustments | Contact, programme, health, disability and support-needs information | Performance of an agreement; legal obligation; legitimate interests in accessible delivery |
| Evaluating impact, equality and participation | Programme, feedback, outcome, socio-economic and diversity information | Legitimate interests in measuring impact and improving equality of opportunity; consent where appropriate |
| Managing volunteers, mentors, trustees, workers and recruitment | Identity, contact, work history, references, training, right-to-work, equality and DBS information | Steps before or performance of an agreement; legal obligation; legitimate interests in safe and effective recruitment and management |
| Processing donations, Gift Aid and financial records | Identity, contact, transaction, taxpayer declaration and limited payment information | Performance of an agreement; legal obligation; legitimate interests in fundraising and financial administration |
| Sending news, fundraising and supporter communications | Contact details, relationship with us, interests and preferences | Consent; or, where the legal conditions are met, the charitable-purpose soft opt-in under PECR together with legitimate interests |
| Taking and using photographs, videos or recordings | Image, voice, contributions and session information | Legitimate interests for limited internal administration, safeguarding or quality purposes; consent for promotional or wider sharing where appropriate |
| Operating and securing our website and systems | Technical, usage, account, security and communications data | Legitimate interests in secure and effective systems; legal obligation; recognised legitimate interests only where a defined condition such as crime prevention or public security is met; consent or a PECR exception for storage and access technologies |
| Managing legal, regulatory, insurance and governance matters | Any relevant information | Legal obligation; legitimate interests in governance, advice and legal claims; recognised legitimate interests only where a defined statutory condition is met |
Our legitimate interests
When we rely on legitimate interests, we assess whether the use is necessary and balance our interests against your rights and reasonable expectations. Where the information relates to a child, the child's best interests are a primary consideration. You may object to processing based on legitimate interests; see section 15.
Recognised legitimate interests is a separate lawful basis with a limited statutory list of conditions. The relevant DUAA provisions came into force on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82). We rely on this basis only where a listed condition applies, the processing is necessary, and any additional rules for special category or criminal offence information are also met.
When information is required
Sometimes we need information to enter into or perform an agreement, meet a legal or safeguarding duty, or provide a requested service. If you do not provide it, we may be unable to accept an application, provide a programme or adjustment, process a donation, arrange an opportunity or meet our safeguarding responsibilities. We will explain when information is required.
6. Special category and criminal offence information
In addition to an Article 6 lawful basis, we must have a further condition before using special category data. Depending on the purpose, we may rely on:
- your explicit consent;
- employment, social security and social protection law;
- vital interests where a person cannot give consent;
- legal claims;
- substantial public interest conditions under the Data Protection Act 2018, including safeguarding children or individuals at risk and equality of opportunity or treatment; or
- research and statistical purposes with the required safeguards.
For criminal offence information, we rely on a condition authorised by UK law, such as safeguarding or employment-related vetting, and comply with Article 10 of the UK GDPR and Schedule 1 to the Data Protection Act 2018. We maintain an Appropriate Policy Document where the law requires one.
Providing diversity information is normally optional. We will explain the purpose, minimise access, use aggregated or anonymised results where possible, and not use the information to make unfair decisions about you.
7. Children and young people
Many people we support are young people and some are under 18. Children have the same data protection rights as adults. We explain our use of information in clear, age-appropriate language and take account of age, development, vulnerability and the best interests of the child.
Where appropriate, we involve a parent or guardian, but a competent young person may exercise their own data protection rights. We do not use children's information for fundraising marketing. We do not share a child's information with an employer, programme partner or other third party unless there is a clear, lawful and proportionate reason and appropriate safeguards are in place.
If we offer an online service likely to be used by children, we apply data protection by design and the Children's Code where relevant, including high-privacy defaults and proportionate risk assessment.
8. Who we share information with
Access within Day One is limited to trustees, employees, contractors and authorised volunteers who need the information for their role and are subject to appropriate confidentiality and data protection requirements.
We may share necessary information with:
- schools, colleges, parents or guardians, employers, work-experience hosts, training providers, mentors and programme-delivery partners;
- funders and evaluation partners, usually using aggregated or anonymised information;
- payment, donation and Gift Aid providers;
- website hosting, email, cloud storage, CRM, video-conferencing, analytics, survey and other IT providers;
- professional advisers, auditors, insurers and banks;
- the Charity Commission, HM Revenue & Customs, the Information Commissioner's Office and other regulators or public authorities;
- police, local authorities and safeguarding organisations where necessary to protect a person, prevent or detect crime, or comply with law; and
- a successor organisation or adviser involved in a merger, restructuring or transfer, subject to confidentiality and data protection safeguards.
Service providers acting as our processors may use information only on our documented instructions and must protect it. Schools, employers and other partners may be independent controllers for their own use of information; their privacy notices will then also apply.
We do not sell personal information.
9. International transfers
Some suppliers may store or access personal information outside the UK. Before making a restricted transfer, we use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or an applicable exception. Where required, we assess the destination and safeguards, including through a transfer risk assessment.
You may contact us for more information about the safeguards used for a particular transfer.
10. Marketing and fundraising communications
We may send information about our programmes, events, impact, volunteering, partnerships, fundraising and ways to support us.
For email, text and similar electronic messages to individuals, we use consent or, where every legal condition is met, the charitable-purpose soft opt-in. The soft opt-in provisions came into force on 5 February 2026 under SI 2026/82. We use them only where Day One obtained the contact details directly from the person on or after that date when the person supported, or expressed an interest in, our charitable work; the message is sent solely to further our charitable purposes; and we offered a simple opportunity to opt out both when we collected the details and in each message.
We may use legitimate interests for post or for some business-to-business communications, subject to your rights and applicable marketing rules. We screen telephone marketing where required.
You may opt out at any time by using the unsubscribe link, replying to the message, changing your preference where available, or emailing office@mydayone.org.uk. We may keep a minimal suppression record so that we respect your choice.
11. Cookies and similar technologies
Our website may use cookies, pixels, local storage and similar technologies. Strictly necessary technologies support core functions and security. Other technologies may support preferences, audience measurement, analytics or embedded content.
We ask for consent before using non-essential technologies unless a specific PECR exception applies. Where we rely on an exception for a low-risk purpose such as statistical analysis or website improvement, we provide clear information and a simple way to object. You can accept, reject or change your choices through our cookie banner or preference tool. Withdrawing consent does not affect earlier lawful use.
Our cookie information and preference tool should identify each technology, provider, purpose and duration. Browser settings may also block or delete cookies, although parts of the website may then work differently.
12. Photographs, recordings and group communications
We may photograph or record programme sessions, events, interviews, calls or online meetings for administration, safeguarding, evaluation, training, quality assurance or agreed publicity. We will tell participants when recording takes place, explain how the material will be used and provide an alternative where reasonably possible.
We normally seek clear consent before using an identifiable person's image, voice or story in public communications, especially where the person is under 18. Consent may be withdrawn for future use, although we may not be able to remove material already lawfully published or distributed.
If you choose to join a WhatsApp or similar group, your profile name, profile image, telephone number and messages may be visible to other members. Group members may retain information after you leave. Do not share sensitive information or another person's information unless authorised. We will provide group rules and use an alternative channel where reasonably possible.
13. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected. The table below summarises our default periods. A period runs from the stated trigger and applies unless a longer or shorter period is required by law, a regulator, an insurer, a safeguarding authority, an official inquiry, a funding condition or a legal hold. We record the reason for any extension.
| Information category | Default retention period or trigger |
|---|---|
| General enquiries and programme applications not taken forward | 2 years after the enquiry is closed or the application decision. Unsuccessful job, worker and volunteer applications are kept for 6 months after the recruitment decision, or up to 12 months where the applicant agrees to future contact. |
| Programme and participant records (excluding safeguarding files) | 6 years after the programme or support relationship ends. Records needed for a claim involving a child may be kept until the person's 25th birthday or until the claim is finally resolved, if later. |
| Child safeguarding and welfare files | In England and Wales, until the person's 25th birthday. We keep them longer where required for an unresolved case, legal proceedings, an official inquiry, a statutory scheme, or a direction from a safeguarding authority, regulator or insurer. |
| Concerns or allegations about an adult working or volunteering with children | Until the person reaches normal pension age or for 10 years after the allegation or investigation is concluded, whichever is longer. Records of a finding that an allegation was malicious are deleted when the matter closes unless law or a legal hold requires otherwise. |
| DBS certificates and certificate information | We do not normally retain a copy of a certificate. If a dispute makes temporary retention necessary, the copy is kept for no more than 6 months after the decision, then securely destroyed. We may retain a minimal record of the check and recruitment decision with the relevant personnel record. |
| Personnel records for employees, trustees, mentors and volunteers | For the role or relationship and 6 years after it ends, except safeguarding records and any items subject to a different legal period. |
| Donations, Gift Aid and accounting records | Accounting records are kept for at least 6 years. A Gift Aid declaration is kept for 6 years after the most recent donation for which Gift Aid was claimed under it. |
| Contracts, grants, complaints, data-rights requests and legal or insurance matters | 6 years after the contract, grant or matter ends, or longer while a claim, audit, investigation or legal hold remains open. |
| Marketing preferences and suppression records | Contact details are kept while the person remains subscribed and are reviewed after 2 years without meaningful engagement. A minimal suppression record is kept for as long as needed to honour an opt-out or objection. |
| Website, security and cookie information | Security and access logs are normally kept for up to 12 months. Cookie and similar-technology periods are stated in our cookie information and preference tool. |
| Photographs, videos and recordings | Reviewed at least every 3 years and deleted when no longer needed for the stated purpose. We stop new promotional use after consent is withdrawn, subject to material already lawfully published and any safeguarding, evidential or legal need. |
We review records when a period expires and securely delete or anonymise information that is no longer needed. A limited record may be kept to record an objection, withdrawal of consent or request not to be contacted.
14. How we protect information
We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction. Measures may include access controls, multi-factor authentication, encryption where appropriate, backups, staff and volunteer training, confidentiality requirements, supplier checks and incident-response procedures.
No internet or storage system is completely secure. If a personal data breach creates a risk to people's rights and freedoms, we will notify the ICO within the required time where applicable. If the risk is high, we will also inform affected people without undue delay.
Our website may link to other organisations' websites. Those organisations are responsible for their own privacy practices, and you should read their privacy notices.
15. Your data protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- be informed about how your personal information is used;
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests or for statistical purposes in certain circumstances;
- object at any time to direct marketing, including related profiling;
- receive certain information in a structured, commonly used and machine-readable format and ask us to transfer it where the right to data portability applies;
- withdraw consent at any time, without affecting processing carried out before withdrawal; and
- complain to us or the Information Commissioner's Office.
These rights are not absolute and exemptions may apply. We normally respond within one month after receiving the request and any information reasonably needed to confirm identity. We may extend the time by up to two further months for a complex request or a number of requests. For a subject access request, the response period may be paused while we await clarification that is reasonably required.
Automated decision-making and profiling
We may use limited manual profiling to understand interests, evaluate programme reach or tailor communications. We do not currently make decisions about people that have legal or similarly significant effects using solely automated processing.
If this changes, we will provide meaningful information about the decision and safeguards. Where the law requires, these include the ability to make representations, obtain human intervention and contest the decision. Additional restrictions apply to special category data.
16. Complaints
Please contact our Privacy Lead at office@mydayone.org.uk if you are unhappy with how we use personal information. You may complain by email, post or another reasonable method. We will acknowledge a data protection complaint within 30 days, make appropriate enquiries, keep you informed and provide the outcome without undue delay.
You may also complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. Visit ico.org.uk/make-a-complaint or call 0303 123 1113. You can complain to the ICO without first contacting us, although the ICO may ask whether you have raised the matter with us.
17. Changes to this notice
We review this notice regularly and update it when our activities, suppliers or the law change. The current version will be published on our website. If a change significantly affects how we use your information, we will take reasonable steps to bring it to your attention.
Day One Opportunities for School Leavers | Registered charity 1213814