Privacy and Data Protection Policy (GDPR)
This Privacy Policy explains how Islington Mind collects, uses, stores and disposes of personal information, meaning any information that identifies or could identify an individual. It sets out how we comply with the UK GDPR and the Data Protection Act 2018, and provides a framework for ensuring that personal data is handled lawfully, fairly, securely and transparently.
At Islington Mind, we are committed to protecting the personal information of service users, employees and volunteers, and to ensuring that all personal data is processed in a fair, open and transparent manner.
The key data protection principles we follow are that personal data must be:
- lawful, fair and transparent;
- collected for specific purposes;
- adequate, relevant and limited to what is necessary;
- accurate and kept up to date;
- retained only as long as necessary; and
- processed securely.
Islington Mind is registered with the Information Commissioner’s Office (ICO) as a data controller (Registration number: ZB673659). As the data controller, Islington Mind is responsible for, and controls, the processing of personal information.
This policy applies to trustees, staff, contractors and volunteers, and covers the personal data of service users, employees, volunteers, donors, funders, suppliers and partners.
Download a pdf copy of the full policy.
Revised April 2026