BSN Privacy Notice
This privacy notice explains what types of personal data we may hold about you, how we collect it, how we use it and who we may share information with. We are required to give you this information under data protection law.
This Privacy Notice is intended to inform you, about how we collect, use, store, and share your personal information in the course of supporting fostering agencies and their subsidiaries. We are committed to protecting your privacy and complying with data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are BSN Social Care hereafter referred to as “we”, “us”, or “our”. We provide support to a family of fostering agencies operating across the United Kingdom.
BSN Social care is registered as a controller with the Information Commissioner’s Office (ICO) our registered number is ZA888103.
We may collect, use, store, and transfer different kinds of personal and special category data about you and your personnel, including but not limited to:
We use various methods to collect data from and about you, including:
We will only use your personal data when the law allows us to.
Most commonly, we will use your personal data in the following circumstances:
We process your personal data under the following legal bases:
We will use your personal data for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.
Who We Share Your Personal Data With
We may share your personal data with the following categories of recipients:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
BSN and our subsidiary agencies may use approved artificial intelligence (AI) technologies to enhance efficiency, improve service delivery, and support administrative processes. Any AI tool used within BSN Social Care must be reviewed and approved before use within our organisation.
Where AI tools process personal data, BSN and its subsidiary agencies will only use them where we have identified an appropriate lawful basis under UK data protection law and where their use is necessary, proportionate, and transparent. We will not use AI tools to make decisions about individuals without appropriate human oversight.
One of the tools we use is Magic Notes, an AI-powered application designed to assist with notetaking, summarisation, and organisation of key information. This tool helps authorised staff capture important details during meetings and interactions, supporting accurate records and communication across teams.
We are committed to using AI responsibly and transparently. All personal data processed through Magic Notes is handled in accordance with our Data Protection Policy and applicable data protection legislation. Information is used only for legitimate business purposes, access is restricted to authorised users, and records are retained only for the period set out in our retention schedule before being securely deleted. If you have any questions about our use of AI or Magic Notes, please contact our Data Protection Officer for further information.
You can also read the Magic Notes Privacy Notice here: Magic Notes.
We are also currently trialling Microsoft Copilot and Claude AI with a limited number of authorised users. These tools are being assessed for suitability, and personal data must not be processed through them unless they have been formally approved for that purpose.
If you have any concerns about the use of AI within BSN Social Care, please contact our Data Protection Officer
We comply with UKGDPR, Data Protection Act 2018 and DUAA 2025 regarding international transfers outside of the UK.
There are circumstances where we may need to send personal information to, or make personal information accessible by, organisations located outside the UK.
The UK GDPR contains specific rules where personal information is transferred to a separate organisation located outside the UK and that transfer is not otherwise covered by the UK GDPR.
The transfer rules apply where we initiate the transfer of personal information to an organisation outside the UK and the organisation receiving the information is a separate legal entity.
In these circumstances, the transfer is known as a restricted transfer.
Where a restricted transfer is necessary, we will only make the transfer where it is permitted under UK data protection law. This may include where the destination country is covered by UK adequacy regulations, where appropriate safeguards are in place such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or where a specific exception applies.
We will assess any proposed international transfer before it takes place and will only transfer the minimum personal information necessary for the relevant purpose.
If you have any concerns about this you can speak to our Data Protection Officer.
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
Procedures are in place to deal with any suspected data breach, and we will notify you and any applicable regulator of a breach where we are legally required to do so.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal and special category data that we hold, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your personal data, and whether we can achieve those purposes through other means. We will always follow our internal retention policy and schedule with regards to how long we should keep our data.
Below is a list of the rights that all individuals have under data protection legislation, they do not apply in all circumstances, please see below for further information or you can contact our Data Protection Officer.
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including:
If you wish to exercise any of the rights set out above, please contact the DPO using the form provided below.
If you have any questions about this Privacy Notice or our privacy practices, please contact our Data Protection officer using the online form below
Due to changes in Data protection legislation, the Data Use and Access Act 2025 (DUAA) was introduced. Following these changes you now have the right to make a complaint about how we have handled your personal data. You can do this at any time and we have 30 days to respond to you. Please contact our Data Protection Officer using the details below.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time. Any changes we make will be posted on this page. We encourage you to review this notice periodically to stay informed about how we are protecting your information.
Get in touch with the Data Protection Officer
If you would like further information on our data handling practices, to make a complaint or to exercise your individual rights.
Please contact our Data Protection Officer. DataProtectionBSN@bsnsocialcare.co.uk .
This Privacy Notice was updated on the 22/06/2026