Blog

Sensitive Data and Vulnerable People

Sensitive Data and Vulnerable People

What We Can Learn from Recent ICO Audits

We’ve spotted a theme in three recent ICO audits, all of which focus on organisations that support some of the most vulnerable people in society.

From secure children’s homes to women’s refuges and youth justice settings, these services often handle large volumes of deeply personal, sensitive information. However, as these audits show, supporting vulnerable people doesn’t automatically mean strong data protection practices are in place.

We’re going to take a closer look at the key themes:

  1. Governance & accountability
  2. Records management
  3. Cybersecurity
  4. Responding to subject access requests

The purpose of this piece isn’t to point fingers, it’s to help other organisations, especially small charities, social enterprises, or purpose-driven businesses, understand what good data practice looks like, because if you’re handling personal data, these lessons apply to you too.

These audits looked at three very different setups: Clayfields House (a secure children’s home), Oakhill Secure Training Centre, and Juno Women’s Aid.

You can find all three audit summaries on the ICO’s website here, just search for the relevant organisation: https://ico.org.uk/action-weve-taken/audits-and-overview-reports/


So how is the sector doing?

1. Governance & Accountability

Let’s start with the foundations: who’s responsible for what, and how well is that documented.

Juno Women’s Aid received a limited rating, with the ICO identifying 6 urgent and 7 high-priority recommendations.

Clayfields House was stronger here, getting a reasonable rating, showing that improvements are possible even in complex environments.

Oakhill Secure Training Centre also received a limited rating, with gaps in understanding who is responsible for what, missing data mapping, and unclear controller/processor roles.

Common areas to strengthen:

  • Data mapping – know what processing activities you have and the data you use.
  • Records of Processing Activities documentation – ensure this is kept up to date.
  • Lawful basis – ensure you use the most appropriate lawful basis for your processing activities.
  • Privacy notices – ensure you tell people what you do with their data and what their rights are.
  • DPIAs – ensure your DPIA process is up to date, and carry out DPIAs for high risk processing, such as biometric recognition systems.
  • Appropriate Policy Document – ensure this covers all your requirements
  • Roles and Responsibilities – ensure everyone knows what their responsibilities are
  • Training – ensure everyone receives training, especially those in specialised roles.

Without strong governance foundations, it’s hard to manage risk, respond to breaches, or meet legal requirements and for organisations working with trauma survivors or children, that risk is magnified.

If you work in a small charity or grassroots organisation, ask yourself:

  • Do we know what data we collect and why?
  • Have we documented it properly?
  • Is someone clearly responsible for overseeing data protection?

These might sound like big tasks, but we recommend taking it to a board meeting and you’ll soon work your way through it. Even small steps, like reviewing your privacy notice or assigning a lead, goes a long way.

These might sound like big tasks, but we recommend taking it to a board meeting and you’ll soon work your way through it. Even small steps, like reviewing your privacy notice or assigning a lead, goes a long way.

2. Records Management

Records management often gets overlooked, but it’s a core part of effective data protection. If you don’t know what data you hold, where it is, or how long it’s kept, you can’t comply with basic legal requirements like responding to subject access requests or securely deleting data.

In the recent audits, this area showed the range of approaches in place.

At Juno Women’s Aid, records management was flagged as needing attention. Their retention schedule needs a full review to ensure it captures all the different types of information they hold along with the correct retention periods. They also need to ensure that their offsite archiving storage provider is complying with contractual obligations to destroy records securely.

Clayfields House needs to continue to progress the roll out of the SharePoint Electronic Document Record Management System (EDRMS) to enable them to improve the efficiency of managing electronic information and records, including the timely deletion when information is no longer required.  They also need to define retention rules for emails, ensuring those that form part of a corporate record are moved to a secure location before automatic email deletion occurs. On the positive, their manual records are stored securely and access to them is controlled; access to systems and data is well controlled with formal processes in place to assign and revoke access rights; and key systems, applications and data are backed up

Oakhill Secure Training Centre needs to update their Record Retention Policy to include clearly defined retention periods for biometric data.  On the positive, they do have a formal process in place for assigning and revoking access rights.

For any organisation, especially those handling sensitive data, there are some straightforward actions that make a real difference.

  • Review your retention schedule regularly and make sure it’s actually being used.
  • Know what systems hold personal data and who can access them.
  • Ensure destruction processes are auditable, even when handled by third parties.
  • Close down old user accounts promptly when staff leave or change roles.

Records management isn’t just about creating a policy; you also need to be following it and have good systems support in place.

3. Information & Cybersecurity

Good cybersecurity doesn’t just protect systems; it protects people. In the recent audits, we’re looking at, there was a real mix of practice. It’s clear that some organisations are getting the basics right, while others still have work to do.

Clayfields House had some good measures in place, including clearly identifying and documenting all their hardware and software assets and keeping this up to date; undertaking background checks on personnel where required for their roles and responsibilities; monitoring networks for unusual behaviour; and information about existing or emerging threats is collected and analysed to support proactive risk management.

Oakhill Secure Training Centre’s report shows they need to improve their physical access rights to ensure staff and visitors only have access to information they need; and ensure their destruction of hardware assets is formally documented.  They were able to demonstrate some good measures too, such as clear desk and screen policies, undertaking appropriate background checks, and routinely conducting network vulnerability scans and implementing appropriate remedial actions to address any identified risks.

Both of these organisations had clearly documented personal data breach procedures in place and staff had a good awareness of the breach reporting process.

Juno Women’s Aid audit did not include information and cyber security.

No matter what kind of organisation you have or the size, it’s worth checking these areas:

  • Do you know where your cyber risks are and do you have a register that tracks them?
  • Are you using strong access controls, including MFA where possible?
  • Do you have oversight of your IT providers or contractors and are responsibilities clear?
  • Are your staff confident about what to do if there’s a breach or incident?

4. Subject Access Requests

When someone asks to see the personal data you hold about them, known as a Subject Access Request (SAR), it can feel daunting, especially if you hold sensitive data, but handling them well is a key part of transparency and trust.

Only one of the three organisations had SARs included as an audit scope area, this was Juno Women’s Aid.

The audit showed they had limited formal processes and procedures in place to deal with SARs. There is considerable scope for improvement, including:

  • implementing measures to ensure that all requests are passed to the DP lead in good time, which will enable them to complete requests within the statutory timescale.
  • Updating procedural documentation with the searches that should be undertaken on all available systems to ensure that all information relating to the individual has been recovered.
  • Marking disclosure bundles to show which copy they retain and which has been disclosed to the individual.
  • Logging all complaints, including ones that are reported to the ICO, and ensure these are monitored and reported to the Board of Trustees for oversight.

If your organisation supports people in challenging circumstances, SARs are likely to come up and they can carry extra sensitivity.

Some helpful questions to ask:

  • Do all your staff know what a SAR looks like, even if it’s not in writing?
  • Do you have a clear log to record requests and track deadlines?
  • Are you confident in how you check identity and redact sensitive details before disclosing?
  • Are your policies up to date and do they reflect the reality of your service?

A clear, consistent process for SARs shows the people you work with that you respect their rights and are taking care with their information.


What have we learned?

Over the past few posts, we’ve looked at recent ICO audits of three organisations working with some of the most vulnerable people in society Juno Women’s Aid, Clayfields House and Oakhill Secure Training Centre.

Each audit highlighted strengths and areas for improvement across governance, records management, cybersecurity, and handling data access requests. Taken together, they also showed something more important: that organisations doing vital frontline work often need more support when it comes to managing personal and sensitive data.

These services are often built out of lived experience, with a strong commitment to care and safety, but that doesn’t always translate into formal policies or technical infrastructure, especially when time, money and expertise may be limited.

If you’re in a small organisation, charity or support service and some of the findings felt familiar, you’re not alone. The good news is that small steps make a big difference – putting in a simple SAR log, reviewing who has access to sensitive data, or making sure staff feel confident in their responsibilities can go a long way.

If you’ve found this helpful and want a hand understanding how it might apply to your organisation, we’re happy to chat it through and point you in the right direction. You can reach us at info@dunwelldataprotection.co.uk