Child protection Policy
Equality and Diversity Policy
(1) Background
The aim of this policy is to ensure that everyone is treated fairly and with respect and BYSA Foundation activities are equally accessible to all.
This policy is fully supported by the BYSA management committee which is responsible for the implementation and review of this policy.
BYSA will therefore adhere to the following:
- be responsible for setting standards and values to apply throughout every level, as activities should be enjoyed by everyone who wants to participate
- be committed to eliminate discrimination by reason of age, gender, gender reassignment, sexual orientation, race, nationality, ethnic origin, religion or belief, ability or disability and to encourage equal opportunities
- ensure that it treats its volunteers, participants and all othersfairly and with respect and will ensure that all parts of the community have access to and have opportunities to take part in, and enjoy, its programmes of activities, competitions and events
- not tolerate harassment, bullying, abuse or victimisation of an individual, including sexual or racially based harassment or other discriminatory behaviour, whether physical or verbal and work to ensure that such behaviour is met with appropriate action in whatever context it occurs
- be committed to the immediate investigation of any complaints of discrimination on the above grounds, once they are brought to its attention. Complaints will be dealt with in accordance with its complaints policy and, where such a complaint is upheld, the management committee may impose such sanction as it considers appropriate and proportionate to discriminatory behaviour
- be committed to taking positive action where inequalities exist and the development of a programme of on-going training and awareness in order to promote the eradication of discrimination and to promote equality and diversity in all activities.
- be committed to a policy of fair and equitable treatment of all volunteers, participants and others to abide by and adhere to these policies and the requirements of the Equality Act 2010 as well as any amendments to this act and any new legislation.
(2) Terminologies and descriptors
Disability under the Equality act 2010 is defined as:
‘a physical or mental impairment that has a substantial and long-term adverse effect on the ability to carry out normal day-to-day activities. ‘Substantial’ means more than minor or trivial. ‘Impairment’ covers, for example, long-term medical conditions such as asthma and diabetes, and fluctuating or progressive conditions such as rheumatoid arthritis or motor neurone disease. A mental impairment includes mental health conditions (such as bipolar disorder or depression), learning difficulties (such as dyslexia) and learning disabilities (such as autism and Down’s syndrome). Some people, including those with cancer, multiple sclerosis and HIV/AIDS, are automatically protected as disabled people by the Act. People with severe disfigurement will be protected as disabled without needing to show that it has a substantial adverse effect on day-today activities.’
- Direct discrimination occurs when a person is treated less favourably than another person because of a protected characteristic. Direct discrimination also includes discrimination because a person is wrongly thought to have a particular protected characteristic or is treated as if they do
- Indirect discrimination occurs where the effect of certain requirements, provision or practices imposed by an organisation has an adverse impact disproportionately on one group or other. Indirect discrimination generally occurs when a rule or condition, which is applied equally to everyone, can be met by a considerably smaller proportion of people from a particular group; the rule is to their advantage and it cannot be justified on other grounds.
- Discrimination arising from disability occurs when a disabled person is treated unfavourably because of something connected with their disability and this unfavourable treatment cannot be justified. Treatment can be justified if it can be shown that it is intended to meet a legitimate objective in a fair, balanced and reasonable way. If this can be shown then the treatment will be lawful. This form of discrimination can occur only if the service provider knows or can reasonably be expected to know that the disabled person is disabled.
- Positive discrimination is illegal under UK anti-discrimination law and shouldn’t be confused with Positive Action. Positive discrimination generally means being favourable towards an individual or group for whatever reason outlined.”
- Positive action is legal and describes measures targeted at a particular group that are under represented in a particular programme or aspect of a sport. These measures are intended to redress past discrimination or to offset the disadvantages arising from existing attitudes, behaviours and structures.
Lawful positive action measures can include:
– Targeting job training at people of particular racial groups, or either gender, which have been under-represented in certain occupations or grades during the previous 12 months, or encouraging them to apply for such work.
– Providing facilities to meet any specific educational, training or welfare needs identified for a specific racial group.
– Special action being taken is the employment of a female coach to lead a session aimed at women, to specifically encourage uptake and participation by female players
- Harassment can be described as inappropriate actions, behaviour, comments or physical contact, which may cause offence i.e. mental or physical anxiety or hurt to an individual:
– It may be related to gender, gender reassignment, race, disability, sexuality, age, religion, nationality or any personal characteristic of an individual.
– Under the terms of the Criminal Justice Act 1994, harassment was made a criminal offence, punishable by a fine of up to £5,000 and/or a prison sentence of up to six months.
- Victimisation occurs when a service provider treats someone badly because they have made or supported a complaint about discrimination or harassment, or because the service provider thinks that they are doing or may do these things. It will also be victimisation if a service provider treats someone badly because they support someone else who makes a discrimination claim. A person is not protected from victimisation if they have maliciously made or supported an untrue complaint.
- Prejudice is literally pre-judging someone. It is usually led by negative, irrational feelings, resulting from preconceived attitudes and opinions.
- Stereotyping is grouping or labelling people because they are members of a particular ‘visible’ group, and assuming that they have particular traits that are considered to be characteristics of that group.
- Dignity is about respectful, responsible, fair and humane behaviour, something that is reflected in the constitution.
- Disadvantage is where, as a result of discrimination, an individual or group is deprived of some or all resources and opportunities. This may affect people directly or indirectly.
- Social exclusion is when people or areas suffer from one or a combination of linked problems such as unemployment, poor skills, low income, high crime environments or lack of facilities.
Venues and Equipment
Staff members will check:
- Area is safe
- There are no obstacles on the field of play
- Goal posts are within FA safety guidelines
- All equipment is safety checked e.g. footballs have no splits
- All players have shin pads and boots are fully studded
- Changing rooms are checked for safety.
First Aid
- The Club ensures there is a qualified first aider with all teams
- All teams have a suitable first aid kit
- All teams have a mobile phone with them
- All managers have a list of any known children’s illnesses
- The Club Secretary knows if the teams are playing, ‘home’ or ‘away’.
Health and Safety
To support our Health and Safety policy statement we are committed to the following duties:
- Undertake regular, recorded risk assessment of the club grounds and all activities undertaken by the club.This includes the inspection of the field of play prior to any fixture or training session. With a decision on the fitness, safety of the playing and training area taken by the manager.
- Ensure that all players are given the appropriate level of training with appropriate levels of supervision.
- Ensure that normal operating procedures and emergency operating procedures are in place and known by all managers and club officials
- Provide access to adequate first aid facilities, telephone and qualified first aider at all times
- Report any injuries or accidents sustained during any club activity or whilst on the club premises
- Ensure that the implementation of the policy is reviewed regularly and monitored for effectiveness.
- Annual risk assessments of goal posts.
- Annual inspection of all auxiliary equipment i.e. nets, corner flags.
PLAYERS AND MANAGERS DUTY
All players, Managers and Assistant Managers are committed to the following:
- Take reasonable care for your own health and safety, plus that of others who may be affected by what you do or not do
- Co-operate with the Club on health + safety issues
- Correct use of all equipment provided by the Club
- Do not interfere with, or misuse anything provided for your health, safety or welfare.
Code of Conduct for Players
Players Code is to:
- make every effort to develop their own sporting abilities in terms of skills techniques, tactics and stamina.
- give maximum effort and strive for the best possible performance during a game, even if the team is in a position where the desired result has already been achieved.
- set a positive example for others, particularly young players and supporters.
- always have regard to the best interest of the game, including where publicly expressing an opinion on the game and any particular aspect if it, including others involved in the game.
- do not use inappropriate language.
Obligations towards ones own team
A player should:
- make every effort consistent with fair play and the laws of the game to help their own team win.
- resist any influence which might, or might be seen to bring into question their commitment to the team winning.
Law and rules of the game
- A player should know and abide by the laws, rules and spirit of the game and the competition rules
- Accept success and failure, victory and defeat equally.
- resist any temptation to take banned substances or use banned techniques.
Rules set by The Football Association
- Players must be 6 years of age on or before 31st August
- Players in Teams Under 7s and Under 8s cannot play for points
- To play more than seven per side, the player must be 10 years old on or after 31st August.
Club Rules
The Club shall have the status of an Affiliated Members Club of The Football Association by virtue of its affiliation to The Birmingham Football Association and any League or Competition to which the Club is affiliated for the time being shall be deemed to be incorporated into the Club Rules.
No alteration to the Club Rules shall be effective without prior written approval by the Birmingham County FA.
The Club will also abide by The Football Associations Child Protection Policies and Procedures, Codes of Conduct and the Equal Opportunities and
Anti-Discrimination Policy.
It is the responsibility of each team manager to confirm match times, referees, match results and to post off their match sheets.
Any correspondence either verbally or written which are not part of the manager responsibility must first be notified to the Club Secretary who will then deal with them appropriately.
All equipment and Home Kits remain the property of BYSA. Away Kits which have been purchased through sponsorship or fund raising using the Pinley FC name remain the property of BYSA.
The Club will provide a Home Kit for all teams playing for BYSA Club. BYSA Club will also provide appropriate insurance for players and officials. It is the managers responsibility to ensure all kits both Home and Away and equipment are returned to the club if the team decides not to continue anytime.
Teams are only permitted to play in red and black for home games other colours are not allowed for home games. Other colours for away games must first be confirmed with the Management Committee.
Teams must have a complete first aid kit available at matches and training, which will be provided by the Club. Re stocking of this can be done at the managers meeting or by contacting the Club Secretary to make arrangements.
Injured players may be treated with water spray bottles and antiseptic wipes by a first aider. No antiseptic creams or bucket and sponges can be used. Plasters may be issued to a player but not administered.
Each team will be permitted 1 stand down per season. Providing 4 weeks prior notice is given to the Club Secretary. No other cancellation other than adverse weather conditions or the ground being unfit will be permitted
Managers receiving fines for misconduct will be responsible for paying for this within 14 days to the Treasurer. Any player or parent receiving a fine for misconduct will be responsible to pay this to the manager within 14 days.
It is the managers responsibility to collect subscriptions from the players and hand them to the Club Treasurer on a monthly basis at the managers meeting. With the appropriate expenses sheet.
Any sponsors should be forwarded to the Forum Events Co-ordinator and this will then be discussed at a club meeting to make sure they are appropriate no advertising of drugs, alcohol or gambling (e.g. pubs, clubs and betting shops)
Welfare Policy
BYSA take responsibility for Child Protection seriously.
We have clear policy guidelines for anyone working at our Club.
The Club has a Child Welfare Officer who is involved in the safeguard and good practice of football for the children.This person ensures all members of our Club are CRB checked and attend policy courses.
The childs welfare is and must be the paramount consideration.
All children and young people have the right to be protected from abuse regardless of their age, gender, disability, culture, language, racial origin, religious beliefs or sexual identity.
All suspicions and allegations of abuse will be taken seriously and responded to swiftly and appropriately.
The child shall have a Child Protection Officer to be appointed at the first meeting following the AGM.
The Clubs Child Protection Officer shall make every effort to make him/her available for any service training where appropriately.
In all cases this Club will follow the FA Child Protection Procedures and Policies. All Club members must attend the FA Child Protection and Best Practice Course.
Privacy Notice
- BYSA (“we”, “our”, “us”) take your privacy very seriously.
- This Privacy Notice sets out how we use and look after the personal information we collect from you. We are the data controller, responsible for the processing of any personal data you give us. We take reasonable care to keep your information secure and to prevent any unauthorised access to or use of it.
What personal data we hold on you
- Personal data means any information about an individual from which that individual can be identified.
- We collect, use, store and transfer some personal data of our participants [and their parents or guardians], and other members.
- You provide information about yourself when you register with BYSA, and by filling in forms at an event or online, or by corresponding with us by phone, e-mail or otherwise.
- The information you give us may include your name, date of birth, address, e-mail address, phone number, gender, and the contact details of a third party in the case of emergency. We may also ask for relevant health information, which is classed as special category personal data, for the purposes of your health, wellbeing, welfare and safeguarding. Where we hold this data it will be with the explicit consent of the participant or, if applicable, the participant’s parent or guardian.
- Where we need to collect personal data to fulfil BYSA responsibilities and you do not provide that data, we may not be able honour or administer your membership.
Why we need your personal data
- We will only use personal data for any purpose for which it has been specifically provided.
- The reason we need participants’ and members’ personal data is to be able to run the activities of BYSA. Our lawful basis for processing your personal data is that we have a contractual obligation to you as a participant or member to provide the services you are registering for.
- We have set out below, in a table format, a description of all the ways we may use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
| Purpose/ Processing Activity | Lawful Basis for processing under Article 6 of the GDPR. |
| Processing membership forms and payments/ subs | Performance of a contract |
| Organising matches | Performance of a contract |
| Sending out match or information and updates | Performance of a contract |
| Sharing data with coaches, managers or officials to run training sessions or enter events | Performance of a contract |
| Sharing data with leagues we are in membership of, county associations and other competition providers for entry in events | Performance of a contract |
| Sharing data with committee members to provide information about update on activities and to support other developments | BYSA has a legitimate interest to maintain member and participant correspondence for BYSA community purposes. |
| Sharing data with third party service or facility providers | BYSA has a legitimate interest to run the organisation efficiently and as it sees fit. Provision of some third party services is for the benefit of BYSA, participants and its members. |
| Sharing anonymised data with a funding partner as condition of grant funding e.g. Local Authority | BYSA has a legitimate interest to run the organisation efficiently and as it sees fit. Application for funding is a purpose that benefits BYSA, participants and its members. |
| Publishing match and league results | Consent. We will only publish your personal data in a public domain, including images and names, if you have given your consent for us to do so. In the case of children under the age of 13 then only with written consent of parent/guardian. |
| Sending out marketing information such as newsletters and information about promotions and offers from sponsors | Consent. We will only send you direct marketing if you are an existing member, participant or other associated individual and you have not previously objected to this marketing, or, you have actively provided your consent. |
| To ensure we understand possible health risks | Consent. We will only process details on your medical history with your consent. |
Who we share your personal data with
- When you become a member of BYSA, your information, if you are a coach or volunteer will be or if you are another participant may be entered onto the Whole Game System database, which is administered by the FA. We also pass your information to the County FA and to leagues to register participants an teams for matches, tournaments or other events, and for affiliation purposes.
- We may share your personal data with selected third parties, suppliers and sub-contractors such as referees, coaches or match organisers. Third-party service providers will only process your personal data for specified purposes and in accordance with our instructions.
- We may disclose your personal information to third parties to comply with a legal obligation; or to protect the rights, property, or safety of our participants, members or affiliates, or others.
- The BYSA’s data processing may require your personal data to be transferred outside of the UK. Where BYSA does transfer your personal data overseas it is with the sufficient appropriate safeguards in place to ensure the security of that personal data.
Protection of your personal data
- We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
How long we hold your personal data
- We keep personal data on our participants and members while they continue to be a participant or member or are otherwise actively involved with BYSA. We will delete this data 12 months after a participant or member has left or otherwise ended their membership or affiliation, or sooner if specifically requested and we are able to do so. We may need to retain some personal data for longer for legal or regulatory purposes. The personal data that is stored on Whole Game System is subject to their privacy policy so we advise you review that policy together with this notice. If you would like your personal data to be deleted from Whole Game System then please contact them.
Your rights regarding your personal data
- As a data subject you may have the right at any time to request access to, rectification or erasure of your personal data; to restrict or object to certain kinds of processing of your personal data, including direct marketing; to the portability of your personal data and to complain to the UK’s data protection supervisory authority, the Information Commissioner’s Office about the processing of your personal data.
- As a data subject you are not obliged to share your personal data with BYSA. If you choose not to share your personal data with us we may not be able to register or administer your membership.
- We may update this Privacy Notice from time to time, and will inform you to any changes in how we handle your personal data.
- If you have any questions about this Privacy Notice then please contact the BYSA committee on info@bysa.co.uk
Data Protection Policy
1. About this Policy
1.1 This Policy is to help BYSA deal with data protection matters internally. This should be kept with other policies and a copy should be given (or made available) to all staff members, volunteers and others who come into contact with personal data during the course of their involvement with BYSA.
1.2 BYSA (“we”, “our”, “us”) handle personal data about current, former, and on occasion prospective players [and their parents or guardians], volunteers, committee members, others including referees, coaches, managers, contractors, third parties, suppliers, and any other individuals that we communicate with.
1.3 In your official capacity with the BYSA, you may process personal data on our behalf and we will process personal data about you. We recognise the need to treat all personal data in an appropriate and lawful manner, in accordance with the EU General Data Protection Regulation 2016/679 (GDPR).
1.4 Correct and lawful treatment of this data will maintain confidence in BYSA, and protect the rights of players and any other individuals associated with the Academy. This Policy sets out our data protection responsibilities and highlights the obligations of BYSA, which means the obligations of our employees, committee, volunteers, members, and any other contractor or legal or natural individual or organisation acting for or on behalf of BYSA.
1.5 You are obliged to comply with this policy when processing personal data on behalf of BYSA, and this policy will help you to understand how to handle personal data.
1.6 BYSA will be responsible for ensuring compliance with this Policy. Any questions about this Policy or data protection concerns should be referred to the committee.
1.7 We process participant, volunteer, member, referee, coach, manager, contractor, committee, supplier and third party personal data for administrative and management Charity No: 1146398 purposes. Our purpose for holding this personal data is to be able to contact relevant individuals on BYSA business and our legal basis for processing your personal data in this way is the contractual relationship we have with you. We will keep this data for 12 months after the end of your official relationship with BYSA, unless required otherwise by law and / or regulatory requirements. If you do not provide your personal data for this purpose, you will not be able to carry out your role or the obligations of your contract with BYSA.
1.8 All the key definitions under GDPR can be found here.
2. What we need from you
2.1 To assist with our compliance with GDPR we will need you to comply with the terms of this policy. We have set out the key guidance in this section but please do read the full policy carefully.
2.2 Please help us to comply with the data protection principles (set out briefly in section 3 of this policy and in further detail below):
2.2.1 please ensure that you only process data in accordance with our transparent processing as set out in our Privacy notice;
2.2.2 please only process personal data for the purposes for which we have collected it (i.e. if you want to do something different with it then please speak to the Chairman / Secretary first);
2.2.3 please do not ask for further information about players and / or members and / or staff and / or volunteers without first checking with the Chairman / Secretary;
2.2.4 if you are asked to correct an individual’s personal data, please make sure that you can identify that individual and, where you have been able to identify them, make the relevant updates on our records and systems;
2.2.5 please comply with our retention periods listed in our Privacy Notice and make sure that if you still have information which falls outside of those dates, that you delete/destroy it securely;
2.2.6 please treat all personal data as confidential. If it is stored in electronic format then please consider whether the documents themselves should be password protected or whether your personal computer is password protected and whether you can limit the number of people who have access to the information. Please also consider the security levels of any cloud storage provider (and see below). If it is stored in hard copy format then please make sure it is locked away safely and is not kept in a car overnight or disposed of in a public place;
2.2.7 if you are looking at using a new electronic system for the storage of information, please talk to the Chairman / Secretary first so that we can decide whether such a system is appropriately secure and complies with GDPR;
2.2.8 if you are planning on sharing personal data with anybody new or with a party outside the FA structure then please speak to the Chairman / Secretary before doing so who will be able to check that the correct contractual provisions are in place and that we have a lawful basis to share the information;
2.2.9 if you receive a subject access request (or you think somebody is making a subject access request for access to the information we hold on them) then please tell [insert name] as soon as possible because we have strict timelines in which to comply;
2.2.10 if you think there has been a data breach (for example you have lost personal data or a personal device which contains personal data or you have been informed that a coach has done so, or you have sent an email and open copied all contacts in) then please speak to the Chairman / Secretary who will be able to help you to respond.
If you have any questions at any time then please just ask the Chairman / Secretary. We are here to help.
3. Data protection principles
3.1 Anyone processing personal data must comply with the enforceable principles of data protection. Personal data must be:
3.1.1 processed lawfully, fairly and in a transparent manner;
3.1.2 collected for only specified, explicit and legitimate purposes;
3.1.3 adequate, relevant and limited to what is necessary for the purpose(s) for which it is processed;
3.1.4 accurate and, where necessary, kept up to date;
3.1.5 kept in a form which permits identification of individuals for no longer than is necessary for the purpose(s) for which it is processed;
3.1.6 processed in a manner that ensures its security by appropriate technical and organisational measures to protect against unauthorised or unlawful processing and against accidental loss, destruction or damage;
3.2 We are responsible for and must be able to demonstrate compliance with the data protection principles listed above.
4. Fair and lawful processing
4.1 This Policy aims to ensure that our data processing is done fairly and without adversely affecting the rights of the individual.
4.2 Lawful processing means data must be processed on one of the legal bases set out in the GDPR. When special category personal data is being processed, additional conditions must be met.
5. Processing for limited purposes
5.1 BYSA collects and processes personal data. This is data we receive directly from an individual and data we may receive from other sources.
5.2 We will only process personal data for the purposes of BYSA activities as instructed by the committee, the County FA or The FA, or as specifically permitted by the GDPR. We will let individuals know what those purposes are when we first collect the data or as soon as possible thereafter.
6. Consent
6.1 One of the lawful bases on which we may be processing data is the individual’s consent.
6.2 An individual consents to us processing their personal data if they clearly indicate specific and informed agreement, either by a statement or positive action.
6.3 Individuals must be easily able to withdraw their consent at any time and withdrawal must be promptly honoured. Consents should be refreshed every season.
6.4 Explicit consent is usually required for automated decision-making and for cross-border data transfers, and for processing special category personal data. Where children are involved then the consent must be in writing from parent/guardian
6.5 Where consent is our legal basis for processing, we will need to keep records of when and how this consent was captured.
6.6 Our Privacy Notice sets out the lawful bases on which we process data of our players and members.
7. Notifying individuals
7.1 Where we collect personal data directly from individuals, we will inform them about:
7.1.1 the purpose(s) for which we intend to process that personal data;
7.1.2 the legal basis on which we are processing that personal data;
7.1.3 where that legal basis is a legitimate interest, what that legitimate interest is;
7.1.4 where that legal basis is statutory or contractual, any possible consequences of failing to provide that personal data;
7.1.5 the types of third parties, if any, with which we will share that personal data,
including any international data transfers;
7.1.6 their rights as data subjects, and how they can limit our use of their personal
data;
7.1.7 the period for which data will be stored and how that period is determined;
7.1.8 any automated decision-making processing of that data and whether the data
may be used for any further processing, and what that further processing is.
7.2 If we receive personal data about an individual from other sources, we will provide the above information as soon as possible and let them know the source we received their personal data from;
7.3 We will also inform those whose personal data we process that we, BYSA, are the data controller in regard to that data, and which individual(s) in BYSA are responsible for data protection.
8. Adequate, relevant and non-excessive processing
8.1 We will only collect personal data that is required for the specific purpose notified to the individual.
8.2 You may only process personal data if required to do so in your official capacity with BYSA. You cannot process personal data for any reason unrelated to your duties.
8.3 BYSA must ensure that when personal data is no longer needed for specified purposes, it is deleted or anonymised.
9. Accurate data
We will ensure that personal data we hold is accurate and kept up to date. We will check the accuracy of any personal data at the point of collection and at the start of each season. We will take all reasonable steps to destroy or amend inaccurate or out-of-date data.
10. Timely processing
We will not keep personal data longer than is necessary for the purpose(s) for which they were collected. We will take all reasonable steps to destroy or delete data which is no longer required, as per our Privacy Notice.
11. Processing in line with data subjects’ rights
11.1 As data subjects, all individuals have the right to:
11.1.1 be informed of what personal data is being processed;
11.1.2 request access to any data held about them by a data controller;
11.1.3 object to processing of their data for direct-marketing purposes (including profiling);
11.1.4 ask to have inaccurate or incomplete data rectified;
11.1.5 be forgotten (deletion or removal of personal data);
11.1.6 restrict processing;
11.1.7 data portability; and
11.1.8 not be subject to a decision which is based on automated processing.
11.2 BYSA is aware that not all individuals’ rights are absolute, and any requests regarding the above should be immediately reported to the committee, and if applicable escalated to the County FA for guidance.
12. Data security
12.1 We will take appropriate security measures against unlawful or unauthorised processing of personal data, and against the accidental loss of, or damage to, personal data.
12.2 We have proportionate procedures and technology to maintain the security of all personal data.
12.3 Personal data will only be transferred to another party to process on our behalf (a data processor) where we have a GDPR-compliant written contract in place with that data processor.
12.4 We will maintain data security by protecting the confidentiality, integrity and availability of the personal data.
12.5 Our security procedures include:
12.5.1 Methods of disposal. Paper documents should be shredded. Digital storage devices should be physically destroyed.
12.5.2 Equipment. Screens and monitors must not show personal data to passers- by, and should be locked when unattended. Excel spreadsheets will be password protected.
12.5.3 Personal Devices. Anyone accessing or processing BYSA’s personal data on their own device, must have and operate a password only access or similar lock function, and should have appropriate anti-virus protection. These devices must have BYSA’s personal data removed prior to being replaced by a new device or prior to such individual ceasing to work with or support BYSA activities.
13. Disclosure and sharing of personal information
13.1 We share personal data with the County FA, and with applicable leagues using Whole Game System.
13.2 We may share personal data with third parties or suppliers for the services they provide, and instruct them to process our personal data on our behalf as data processors. Where we share data with third parties, we will ensure we have a compliant written contract in place incorporating the minimum data processer terms as set out in the GDPR, which may be in the form of a supplier’s terms of service.
13.3 We may share personal data we hold if we are under a duty to disclose or share an individual’s personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with the individual or other agreements; or to protect our rights, property, or safety of our volunteers, players, other individuals associated with BYSA or others.
14. Transferring personal data to a country outside the EEA
We may transfer any personal data we hold to a country outside the European Economic Area (EEA), provided that one of the appropriate safeguards applies.
15. Reporting a personal data breach
15.1 In the case of a breach of personal data, we may need to notify the applicable regulatory body and the individual.
15.2 If you know or suspect that a personal data breach has occurred, inform a member of the committee immediately, who may need to escalate to the County FA as appropriate. You should preserve all evidence relating to a potential personal data breach.
16. Dealing with subject access requests
16.1 Individuals may make a formal request for information we hold about them. Anyone who receives such a request should forward it to the committee immediately on info@bysa.co.uk and where necessary escalated to the County FA for guidance. Nobody should feel bullied or pressured into disclosing personal information.
16.2 When receiving telephone enquiries, we will only disclose personal data if we have checked the caller’s identity to make sure they are entitled to it.
17. Accountability
17.1 BYSA must implement appropriate technical and organisational measures to look after personal data, and is responsible for, and must be able to demonstrate compliance with the data protection principles.
17.2 BYSA must have adequate resources and controls in place to ensure and to document GDPR compliance, such as:
17.2.1 providing fair processing notice to individuals at all points of data capture;
17.2.2 training committee and volunteers on the GDPR, and this Data Protection Policy; and
17.2.3 reviewing the privacy measures implemented by BYSA.
18. Changes to this policy
We reserve the right to change this policy at any time. Where appropriate, we will notify you by email.
Complaints Procedure
In the event that a person wants to file a complaint because they feel the policies, rules or code of conduct have been broken they should follow the procedures below.
1. The complainant should report the matter in writing/ email to the welfare officer or the secretary, detailing:
– details of what occurred;
– details of when and where the occurrence took place;
– any witness details and copies of any witness statements;
– names of any others who have been treated in a similar way (provided that
those people consent to their names being disclosed);
– details of any former complaints made about the incident, including the date
and to whom such complaint was made; and
– an indication as to the desired outcome.
2. The management committee will sit for any hearings that are requested and will initiate a formal investigation on the matter.
3. The management committee will have the power to:
– Warn as to the future conduct
– Enact suspension
– Removal of any person found to have broken policies or Codes of Conduct
4. If the complaint is with regards to the management committee the individual has
the right to report the incident direct to the Birmingham County Football
Association
Birmingham County FA Headquarters
Ray Hall Lane
Great Barr
Birmingham
B43 6JF
Tel: 0121-357-4278
Email: info@birminghamfa.com
Safeguarding Policy
Children’s and Adult’s Safeguarding Policy for BYSA Foundation.
BYSA Foundation abides by the duty of care to safeguard and promote the welfare of children and young people and is committed to safeguarding practice that reflects statutory responsibilities, government guidance and complies with best practice requirements.
- We recognise the welfare of children is paramount in all the work we do and in all the decisions we take
- All children, regardless of age, disability, gender reassignment, race, religion or belief, sex, or sexual orientation has an equal right to protection from all types of harm or abuse
- Some children are additionally vulnerable because of the impact of previous experiences, their level of dependency, communication needs or other issues
- Working in partnership with children, young people, their parents, carers and other agencies is essential in promoting young people’s welfare
Purpose:
BYSA Foundation will:
- Protect children and young people who receive BYSA services from harm
- This includes the children or adults who use our services
- Provide staff and volunteers, as well as children and young people and their families, with the overarching principles that guide our approach to child protection
This policy applies to anyone working on behalf of BYSA Foundation, including senior managers and the board of trustees, paid staff, volunteers, sessional workers, agency staff and students. Failure to comply with the policy and related procedures will be addressed without delay and may ultimately result in dismissal/exclusion from the organisation.
Definitions:
The Children Act 1989 definition of a child is: anyone who has not yet reached their 18th birthday, even if they are living independently, are a member of the armed forces or is in hospital.
Child and Adult Abuse: Children and adults may be vulnerable to neglect and abuse or exploitation from within their family and from individuals they come across in their daily lives. There are 4 main categories of abuse, which are: sexual, physical, emotional abuse, and neglect. It is important to be aware of more specific types of abuse that fall within these categories, they are:
- Bullying and cyberbullying
- Child sexual exploitation
- Child Criminal exploitation
- Child trafficking
- Domestic abuse
- Female genital mutilation
- Grooming
- Historical abuse
- Online abuse
Safeguarding children: Safeguarding children is defined in Working Together to Safeguard Children 2018 as:
- Protecting children from maltreatment.
- Preventing impairment of children’s health or development.
- Ensuring that children are growing up in circumstances consistent with the provision of safe and effective care.
- Taking action to enable all children to have the best outcomes.
Legal Framework:
This policy has been drawn up on the basis of legislation, policy and guidance that seeks to protect children in England. A summary of the key legislation is available from nspcc.org.uk/learning.
BYSA Foundation should have in place arrangements that reflect the importance of safeguarding and promoting the welfare of children and young people as well as vulnerable adults.
The Prevent duty:
Some organisations in England, Scotland and Wales have a duty, as a specified authority under section 26 of the Counterterrorism and Security Act 2015, to identify vulnerable children and young people and prevent them from being drawn into terrorism. This is known as the Prevent duty. These organisations include:
- Schools
- Registered childcare providers
- Local authorities
- Police
- Prisons and probation services
- NHS trusts and foundations.
- Other organisations may also have Prevent duties if they perform delegated local authority functions.
Children can be exposed to different views and receive information from various sources. Some of these views may be considered radical or extreme.
Radicalisation is the process through which a person comes to support or be involved in extremist ideologies. It can result in a person becoming drawn into terrorism and is in itself a form of harm.
Extremism is vocal or active opposition to fundamental British values, including democracy, the rule of law, individual liberty and mutual respect and tolerance of different faiths and beliefs.
Training and Awareness:
BYSA Foundation will ensure an appropriate level of safeguarding training is available to its Trustees, Employees, Volunteers and any relevant persons linked to the organisation who requires it (e.g. contractors).
For all employees who are working or volunteering with children, this requires them as a minimum to have awareness training that enables them to:
- Understand what safeguarding is and their role in safeguarding children
- Recognise a child potentially in need of safeguarding and take action
- Understand how to report a safeguarding alert
- Understand dignity and respect when working with children
- Have knowledge of the Safeguarding Children Policy
Similarly, employees and volunteers may encounter concerns about the safety and wellbeing of an adult at risk of abuse. For more information on Adult Safeguarding please contact our welfare officer, but the same applies to Adults.
Confidentiality and Information Sharing:
BYSA Foundation expects all employees, volunteers and trustees to maintain confidentiality. Information will only be shared in line with the General Data Protection Regulations (GDPR) and Data Protection.
However, information should be shared with the Local Authority if a child is deemed to be at risk of harm or contact the police if they are in immediate danger, or a crime has been committed.
Recording and Record Keeping:
A written record must be kept about any concern regarding an adult with safeguarding needs. This must include details of the person involved, the nature of the concern and the actions taken, decision made and why they were made.
All records must be signed and dated. All records must be securely and confidentially stored in line with General Data Protection Regulations (GDPR).
Safe Recruitment & Selection:
BYSA Foundation is committed to safe employment and safe recruitment practices, that reduce the risk of harm to children from people unsuitable to work with them or have contact with them.
BYSA Foundation has policies and procedures that that cover the recruitment of all Trustees, employees and volunteers.
Social Media:
All employees and volunteers should be aware of BYSA Foundation social media policy and procedures and the code of conduct for behaviour towards the children we support.
Use of Mobile Phones and other Digital Technology:
All employees, trustees and volunteers should be aware of BYSA Foundation policy and procedures regarding the use of mobile phones and any digital technology and understand that it is unlawful to photograph children and young people without the explicit consent of the person with parental responsibilities.
Whistleblowing:
It is important that people within BYSA Foundation have the confidence to come forward to speak or act if they are unhappy with anything. Whistle blowing occurs when a person raises a concern about dangerous or illegal activity, or any wrong- doing within their organisation. This includes concerns about another employee or volunteer. There is also a requirement by BYSA Foundation to protect whistle-blowers.
Important Contacts:
Welfare officer – Anwar Khattak, 07890695284
Police Emergency – 999, Police Non-emergency – 101
Birmingham County FA – 01213574278
FRAUD AND FUNDS POLICIES
This document sets out the policy and procedures of BYSA Foundation against fraud and Funds/other forms of dishonesty, together with the steps that must be taken where any of these practices is suspected or discovered.
It applies to Trustees Directors, staff and volunteers. Anybody associated with the BYSA Foundation who commits fraud, theft or any other dishonesty, or who becomes aware of it and does not report it, will be subject to appropriate action.
Statement of intent
BYSA Foundation will continually strive to ensure that all its financial and administrative processes are carried out and reported honestly, accurately, transparently and accountably and that all decisions are taken objectively and free of personal interest. We will not condone any behaviour that falls short of these principles.
All members of the organisation have a responsibility for putting these principles into practice and for reporting any breaches they discover.
Definitions
Fraud: A deliberate intent to acquire money or goods dishonestly through the falsification of records or documents. The deliberate changing of financial statements or other records by either: a member of the public, someone who works or is a volunteer for BYSA Foundation. The criminal act is the attempt to deceive and attempted fraud is therefore treated as seriously as accomplished fraud.
Theft: Dishonestly acquiring, using or disposing of physical or intellectual property belonging BYSA Foundation or to individual members, supporters or clients of BYSA Founndation.
Misuse of Equipment: Deliberately misusing materials or equipment belonging to BYSA Foundation.
Abuse of Position: Exploiting a position of trust within the organisation.
Culture
The Charity’s culture is intended to foster honesty and integrity and is underpinned by BYSA Foundation values; these can be seen on our other policies and mission statement.
Trustees Directors, staff and volunteers are expected to lead by example in adhering to policies, procedures and practices. Equally, our members, partners and external organisations (such as suppliers and contractors) are expected to act with integrity and without intent to commit fraud against the Charity in any dealings they may have with the Charity.
As part of the culture, the Charity will provide clear routes by which concerns can be raised by Trustees Directors, staff and volunteers and by those outside of the Charity. A copy of the Charities whistleblowing policy is availability to Trustees, Directors, staff, volunteers, service users, suppliers and other third parties.
Senior management are expected to deal promptly, firmly and fairly with suspicions and allegations of fraud or corrupt practice.
Responsibilities In relation to the prevention of fraud, theft, misuse of equipment and abuse of position, specific responsibilities are as follows:
Trustee Directors:
The Trustee Directors are responsible for establishing and maintaining a sound system of internal control that supports the achievement of the Charity’s policies, aims and objectives. The system of internal control is designed to respond to and manage the whole range of risks that the Charity faces. The system of internal control is based on an on-going process designed to identify the principal risks, to evaluate the nature and extent of those risks and to manage them effectively. Managing fraud risk is seen in the context of the management of this wider range of risks.
The Chief Executive Officer (CEO): Overall responsibility for managing the risk of fraud has been delegated to the CEO. The responsibilities include:
- Undertaking a regular review of the fraud risks associated with each of the key organisational objectives.
- Establishing an effective anti-fraud response plan, in proportion to the level of fraud risk identified.
- The design of an effective control environment to prevent fraud.
- Establishing appropriate mechanisms for:
o reporting fraud risk issues o reporting significant incidents of fraud or attempted fraud to the Board of Trustee Directors;
o Liaising with the Treasurer and (if appropriate) Auditors. o Making sure that all staff are aware of the Charity’s Anti-Fraud Policy and know what their responsibilities are in relation to combating fraud;
o Ensuring that appropriate anti-fraud training is made available to Trustee Directors, staff and volunteers as required; and
o Ensuring that appropriate action is taken to minimise the risk of previous frauds occurring in future.
Senior Management Team: The Senior Management Team is responsible for:
- Ensuring that an adequate system of internal control exists within their areas of responsibility and that controls operate effectively;
- Preventing and detecting fraud as far as possible;
- Assessing the types of risk involved in the operations for which they are responsible;
- Reviewing the control systems for which they are responsible regularly;
- Ensuring that controls are being complied with and their systems continue to operate effectively; and
- Implementing new controls to reduce the risk of similar fraud occurring where frauds have taken place.
Staff and Volunteers: Every member of staff or volunteer is responsible for:
- Acting with propriety in the use of Charity’s resources and the handling and use of funds whether they are involved with cash, receipts, payments or dealing with suppliers;
- Conducting themselves in accordance with the values and behavior principles set out above;
- Being alert to the possibility that unusual events or transactions could be indicators of fraud;
- Alerting their manager when they believe the opportunity for fraud exists e.g. because of poor procedures or lack of effective oversight;
- Reporting details immediately if they suspect that a fraud has been committed or see any suspicious acts or events; and
- Cooperating fully with whoever is conducting internal checks or reviews or fraud investigations.
Detection and Investigation
Whilst having regard to the requirements of the Data Protection legislation, the Charity actively participates in an exchange of information with external agencies on fraud and corruption. It is often the alertness of Directors, staff or volunteers and the general public to the possibility of fraud and corruption that leads to detection of financial irregularity.
The Chair of the Board of Trustee Directors and Treasurer must be notified immediately of all financial or accounting irregularities or suspected irregularities or of any circumstances which may suggest the possibility of irregularities including those affecting cash, stores, property, remuneration or allowances.
Reporting of suspected irregularities is essential as it:
- Facilitates a proper investigation by experienced staff, and ensures the consistent treatment of information regarding fraud and corruption.
- When so notified, the Chair/Treasurer will instigate an investigation by appointing a designated officer, auditor or other adviser.
- The designated officer, auditor or other advisor will:
o deal promptly with the matter
o record evidence received
o ensure the security and confidentiality of evidence.
Work closely with senior managers of the Charity and other agencies, such as the Police and Courts to ensure that all issues are properly investigated and reported upon.
Ensure maximum recoveries are made on behalf of the Charity, and assist the senior managers to implement BYSA Foundation disciplinary procedures where considered appropriate (referral to the Police will not prohibit or restrict action under the Disciplinary Procedure).
In cases of suspected payroll irregularities where a fraud investigation may be possible, discussion will occur between the Chair and the CEO if it is thought a disciplinary investigation is more appropriate.
Malicious accusations may be the subject of disciplinary action.
Awareness/Training
An important contribution to the continuing success of an anti-fraud strategy, and its general credibility, lies in the effectiveness of programmed awareness/training, of Directors staff and volunteers throughout the organisation. This will be achieved through the development of both induction and awareness training for all personnel involved in internal control systems to ensure that their responsibilities and duties in this respect are regularly highlighted and reinforced.
Review
This policy will be reviewed on an annual basis
IT Security Policy
Information that’s collected, analysed, stored, communicated and reported upon may be subject to theft, misuse, loss and corruption. Information may be put at risk by poor education and training, and the breach of security controls. For example incidents can give rise to embarrassment, financial loss, non-compliance with standards and legislation, as well as possible judgements being made against BYSA Foundation.
Objectives
BYSA’s security objectives are that:
- our information risks are identified, managed and treated according to an agreed risk tolerance
- our authorised users can securely access and share information in order to perform their roles
- our physical, procedural and technical controls balance user experience and security
- our contractual and legal obligations relating to information security are met
- our teaching, research and administrative activity considers information security
- individuals accessing our information are aware of their information security responsibilities
- incidents affecting our information assets are resolved and learnt from to improve our controls
Scope
The Information Security Policy and its supporting controls, processes and procedures apply to all information used at BYSA, in all formats. This includes information processed by other organisations in their dealings with BYSA.
Compliance monitoring
Compliance with the controls in this policy will be monitored by the Information Security Team, and reported to the Information Governance Board.
Review
A review of this policy will be undertaken by the Committee/Trustees. This will be annually or as required, and will be approved by the Committee/Trustees.
Policy Statement
It is BYSA’s policy to ensure that information is protected from a loss of:
- confidentiality – information will be accessible only to authorised individuals
- integrity – the accuracy and completeness of information will be maintained
- availability – information will be accessible to authorised users and processes when required
BYSA will implement an Information Security Management System based on certified standards as required. BYSA will be mindful of the approaches adopted by its stakeholders, including research partners.
BYSA will adopt a risk-based approach to the application of the following controls:
- Information security policies
A set of lower-level controls, processes and procedures for information security will be defined, in support of the high-level Information Security Policy and its stated objectives. This suite of supporting documentation will be approved by the Committee/Trustees, published and communicated to BYSA users and relevant external parties.
- Organisation of information security
BYSA will define and implement suitable governance arrangements for the management of information security. This will include identification and allocation of security responsibilities, to initiate and control the implementation and operation of information security within BYSA.
BYSA will appoint:
- an Executive to chair the Information Governance Board and take accountability for information risk
- an Information Governance Board to influence, oversee and promote the effective management of BYSA information
- an Information Security specialist to manage the day-to-day information security function
- Information Asset Owners (IAOs) to assume local accountability for information management
- Information Asset Managers (IAMs) responsible for day-to-day information management
- Human resources security
BYSA’s security policies and expectations for acceptable use will be communicated to all users to ensure that they understand their responsibilities. Information security education and training will be made available to all staff. Poor or inappropriate behaviour will be addressed.
Where practical, security responsibilities will be included in role descriptions, person specifications and personal development plans.
- Asset management
All assets will be documented and accounted for. This includes:
- information
- software
- electronic information processing equipment
- service utilities
- people
Owners will be identified for all assets and they will be responsible for the maintenance and protection of their assets.
All information assets will be classified according to their legal requirements, business value, criticality and sensitivity. Classification will indicate appropriate handling requirements. All information assets will have a defined retention and disposal schedule.
- Access control
Access to all information will be controlled and will be driven by business requirements. Access will be granted or arrangements made for users according to their role and the classification of information, only to a level that will allow them to carry out their duties.
A formal user registration and de-registration procedure will be maintained for access to all information systems and services. This will include mandatory authentication methods based on the sensitivity of the information being accessed, and will include consideration of multiple factors as appropriate.
Specific controls will be implemented for users with elevated privileges, to reduce the risk of negligent or deliberate system misuse. The separation of duties will be implemented, where practical.
- Cryptography
BYSA will provide guidance and tools to ensure proper and effective use of cryptography to protect the confidentiality, authenticity and integrity of information and systems.
- Physical and environmental security
Information processing facilities are housed in secure areas, physically protected from unauthorised access, damage and interference by defined security perimeters. Layered internal and external security controls will be in place to deter or prevent unauthorised access and protect assets. This includes those that are critical or sensitive, against forcible or hidden attacks.
- Operations security
BYSA will ensure the correct and secure operations of information processing systems. This will include:
- documented operating procedures
- the use of formal change and capacity management
- controls against malware
- defined use of logging
- vulnerability management
- Communications security
BYSA will maintain network security controls to ensure the protection of information within its networks. BYSA will also provide the tools and guidance to ensure the secure transfer of information both within its networks and with external entities. This is in line with the classification and handling requirements associated with that information.
- System acquisition, development and maintenance
Information security requirements will be defined during the development of business requirements for new information systems or changes to existing information systems.
Controls to reduce any risks identified will be implemented where appropriate.
Systems development will be subject to change control and separation of test, development and operational environments.
- Supplier relationships
BYSA’s information security requirements will be considered when establishing relationships with suppliers, to ensure that assets accessible to suppliers are protected.
Supplier activity will be monitored and audited according to the value of the assets and the associated risks.
- Information security incident management
Guidance will be available on what constitutes an information security incident and how this should be reported. Actual or suspected breaches of information security must be reported and will be investigated. The appropriate action to correct the breach will be taken, and any learning built into controls.
- Information security aspects of business continuity management
BYSA will have in place arrangements to protect critical business processes from the effects of major failures of information systems or disasters. This is to ensure their timely recovery in line with documented business needs. This will include appropriate backup routines and built-in resilience.
Business continuity plans must be maintained and tested in support of this policy. Business impact analysis will be undertaken, detailing the consequences of:
- disasters
- security failures
- loss of service
- lack of service availability
- Compliance
The design, operation, use and management of information systems must comply with all statutory, regulatory and contractual security requirements.
Currently this includes:
- data protection legislation
- the payment card industry standard (PCI-DSS) · the government’s Prevent strategy
- BYSA’s contractual commitments
BYSA will use a combination of internal and external audits to demonstrate compliance against chosen standards and best practice, including against internal policies and procedures. This will include:
- IT health checks
- gap analyses against documented standards
- internal checks on staff compliance
- returns from Information Asset Owners
Vulnerable Adult Safeguarding Protection Policy
BYSA has a professional duty to provide vulnerable adults with appropriate safety and protection. As the welfare of the vulnerable adult is paramount, we are committed to providing a secure environment so that vulnerable adults may participate in courses/programmes with confidence.
The Head of BYSA, Riaz ul-Haq Khan and Anwar Khattak is responsible for ensuring that this policy is published, implemented and accessible to all personnel, learners and any relevant third parties. The Head of BYSA will also ensure that all personnel have read and understood this policy and that any amendments to the policy are communicated to relevant parties.
Objectives:
In order to provide safety, protection and security to vulnerable adults throughout our operations, we will adhere to our vulnerable adult safeguarding policy and intend to:
▪ protect all vulnerable adults from abuse, whatever their age, culture, disability, gender, language, ethnic origin, religious beliefs or sexuality
▪ raise awareness of vulnerable adult safeguarding issues and promote good practice
▪ conduct risk assessments to minimise potential hazards to vulnerable adults’ welfare
▪ provide support to learners who have been abused and act proactively by preventing any similar incidents through risk assessment
▪ ensure all personnel fully understand their responsibilities and are provided with the appropriate training/regular updates of the legislation.
Allegations Reporting Procedure:
All allegations will be taken seriously and dealt with as soon as practicable by following the procedure below: All allegations should be reported to the designated safeguarding officer.
(The safeguarding officer should acknowledge receipt of the allegation within 5 working days).The designated safeguarding officer will conduct an investigation whilst taken all responsible steps to protect the vulnerable adults.
Outcomes will be communicated to all relevant stakeholders upon conclusion of the investigation. The Designated Safeguarding Officer is responsible for conducting any investigation and communicating the results if the child and/or vulnerable adult abuse is suspected to be committed by a member of centre staff, whether paid or voluntary. Throughout this procedure, records will be maintained and kept securely and confidentially.
The Safeguarding Officer will make any necessary reports to the authorities on the allegation, which places a vulnerable adult in danger.
In the event of an allegation of a vulnerable adult abuse being committed by any sport personnel or tutors/assessors/internal quality assurers, partner list, the Designated Safeguarding Officer is required to report any suspicious/incidents/ violations to the relevant authorities, departments, establishments or police depending on the seriousness of the matter.
