1.0.1: Introduction
OSCA - Online Safeguarding & Cyber Agency collects and handles personal data for safeguarding, cyber-safety, investigation, reporting, administrative, and security purposes. This policy explains what information OSCA may hold, why it is held, how it is protected, who may access it, and how individuals can request access, correction, restriction, or removal.
1.0.2: Organisation Status
OSCA is an independent safeguarding and cyber-safety organisation. OSCA is not a police force, government agency, court, statutory authority, or emergency service, and does not claim official law-enforcement powers. Where a matter involves immediate danger, suspected criminal activity, child safeguarding, or serious harm, OSCA may advise contact with the appropriate authority or make a lawful referral where necessary.
1.0.3: Data Controller
For the purposes of UK data protection law, OSCA is responsible for deciding why and how personal data is collected, stored, reviewed, shared, restricted, or deleted. Privacy and data protection requests should be sent to [insert privacy email] with enough information to identify the relevant record or concern.
1.0.4: Information OSCA May Collect
OSCA may collect names, usernames, aliases, contact details, account identifiers, reports, concerns, case notes, evidence, screenshots, messages, links, dates, times, staff actions, audit logs, record flags, risk notes, and other information needed to assess safeguarding, cyber-safety, misconduct, or investigation-related matters.
1.0.6: Sensitive and Special Category Data
Some records may include sensitive information, such as safeguarding concerns, age, vulnerability, health information, or other special category data. OSCA will only collect and use this information where it is necessary, relevant, proportionate, and connected to a valid safeguarding, safety, investigation, legal, or administrative purpose.
1.0.7: Criminal Offence and Allegation Data
Some OSCA records may include allegations, suspected offences, harmful behaviour, misconduct, safeguarding risks, or evidence linked to possible criminal activity. OSCA does not decide criminal guilt, and such records are kept only for assessment, safeguarding, review, accountability, or referral purposes where there is a lawful reason to do so.
1.0.8: Why OSCA Uses Personal Data
OSCA may use personal data to receive and assess reports, manage investigations, review safeguarding or cyber-safety risks, contact relevant people, preserve evidence, maintain audit logs, manage staff access, prevent misuse of systems, support internal decisions, handle complaints, and make lawful referrals where serious risk or harm is identified.
1.0.9: Lawful Basis
OSCA may rely on lawful bases such as legitimate interests, consent, legal obligation, or vital interests, depending on the situation. Where special category or criminal offence data is involved, OSCA will consider whether additional legal conditions, safeguards, restrictions, or policy documentation are required before processing or retaining the information.
1.1.0: Access Controls
Access to OSCA systems and records is restricted to authorised users with a valid need to access the information. OSCA may use passwords, roles, permissions, session controls, supervisor access, and audit logs to reduce unauthorised access, because apparently “don’t snoop through records” still needs engineering support.
1.1.1: Audit Logging
OSCA may record user activity including logins, record views, record creation, edits, deletions, exports, flag changes, permission updates, and administrative actions. These logs are used to protect the integrity of OSCA systems, investigate misuse, maintain accountability, and support internal reviews.
1.1.2: Sharing Information
OSCA will only share personal data where it is lawful, necessary, and proportionate. Information may be shared with authorised OSCA staff, safeguarding contacts, platform safety teams, technical providers, legal advisers, or appropriate authorities where serious harm, safeguarding risk, legal need, or system security requires it.
1.1.3: Data Retention
OSCA will not keep personal data for longer than necessary. Retention periods may depend on the seriousness of the matter, safeguarding relevance, investigation status, legal risk, audit requirements, and whether the information is still needed for accountability, protection, dispute handling, or system security.
1.1.4: Deletion, Restriction, Redaction, and Removal Timescales
Individuals may request deletion, restriction, correction, or review of their personal data by contacting OSCA. OSCA will respond to valid removal requests within the legally required timescale, normally within one calendar month, unless the request is complex or the law allows an extension. OSCA may refuse, delay, or limit removal where the person is involved in an active investigation, an open safeguarding risk or concern, an unresolved complaint, an audit or security review, or where the data must be retained for lawful safeguarding, evidential, legal, accountability, or legitimate investigation purposes. Where OSCA cannot lawfully or safely remove a full record, the record may instead be restricted, anonymised, or redacted, with identifying details replaced by labels such as “REDACTED” or “CLASSIFIED” where appropriate.
1.1.5: Accuracy of Records
OSCA will take reasonable steps to keep records accurate, fair, and up to date. Where information is disputed, OSCA may correct it, add a dispute note, restrict access during review, remove unsupported material, or retain the information with added context where there is a lawful reason to do so.
1.1.6: Data Subject Rights
Individuals may have rights to access, correction, deletion, restriction, objection, and information about how their data is used. These rights are not absolute, and OSCA may need to verify identity or refuse part of a request where disclosure would affect safeguarding, confidentiality, system security, legal obligations, or the rights of others.
1.1.8: Children and Safeguarding
Where records involve children, young people, vulnerable people, exploitation, abuse, threats, or serious harm, OSCA will handle the information with additional care. Where appropriate, OSCA may advise referral to parents, guardians, schools, safeguarding bodies, police, emergency services, or other suitable organisations.
1.1.9: Security
OSCA uses reasonable technical and organisational measures to protect personal data, including access controls, account permissions, secure hosting, audit logs, limited administrative access, and internal rules on confidentiality. No online system is perfectly secure, because the internet is a flaming skip with login forms, but OSCA will take reasonable steps to reduce risk.
1.2.0: Data Breaches
If OSCA becomes aware of a suspected personal data breach, it will assess what happened, what data was affected, who may be at risk, whether containment is possible, whether affected individuals should be informed, and whether the ICO or another authority must be notified.
1.2.1: Third-Party Services
OSCA may use third-party services for hosting, email, databases, backups, logging, communications, or website operation. Where these providers process personal data, OSCA will aim to use services with appropriate security and data protection safeguards.
1.2.2: Cookies and Website Logs
OSCA may use necessary cookies, login sessions, security logs, IP records, browser information, and error logs to operate and protect the website. Non-essential cookies or analytics should only be used where users are clearly informed and consent is obtained where required.
1.2.3: Complaints
Anyone concerned about how OSCA handles personal data should contact [insert privacy email] so the matter can be reviewed. Individuals also have the right to complain to the Information Commissioner’s Office if they believe their data protection rights have been breached.
1.2.4: Changes to This Policy
OSCA may update this Privacy Policy when its systems, legal obligations, data handling, or investigation processes change. The latest version will be published on the OSCA website with an updated date.