Privacy Policy
Effective date: 6th August 2026
About this notice
This notice tells you what personal information National Disability Card Ltd ("NDC", "we", "us") holds
about you when you apply for a National Disability Card or National Carers Card, hold one, or use our
website, what we do with it, who we share it with, how long we keep it, and what your rights are.
It is issued under Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the
Data Protection Act 2018.
If you have a question about your data or want to exercise any of your rights, contact us using the
details in Section 14.
1. Who we are
NDC is the data controller for your personal information. Our details:
• Name: National Disability Card Ltd
• Trading names: National Disability Card, National Carers Card, and DisabilityID (DisabilityID is our registered trade mark)
• Company number: 12275048
• Registered office: 15a Deben Mill Business Centre, Old Maltings Approach, Melton, Woodbridge, England, IP12 1BL
• ICO registration: ZA733593
• Day-to-day data protection contact: Dianne Taylor
• Data Protection Lead: Edward Herbert (edward@disabilityid.co.uk)
NDC is a UK social enterprise founded in 2019. We operate the National Disability and Carers Card Scheme.
2. Who this notice covers
This notice applies to:
• People who apply for a National Disability Card or National Carers Card.
• Current cardholders.
• Former cardholders.
• Parents or guardians applying on behalf of a child.
• Visitors to our website (www.disabilityid.co.uk).
• People who contact us by email, post, phone, or social media.
It does not cover NDC employees, contractors, or job applicants — see our separate Employee Privacy Notice for those.
3. What personal information we collect
The information we hold depends on what you do. It typically includes:
When you apply for a card
• Your full name and date of birth.
• Your address, email address, and phone number.
• A photograph for your card (you upload this).
• A self-declaration about your disability or carer status.
• Evidence supporting your eligibility (for example, the back of your Blue Badge, a GP letter, or other documentation you provide).
• For carer applications: information about the care you provide (the types of support and your average weekly hours of care). We do not collect or keep identifiable information about the person you care for.
• If you choose the optional emergency contact QR code: your emergency contact’s name, their relationship to you, and their phone number. Only the phone number is encoded in the QR code printed on your card. We keep the name and relationship in our records solely so that we know whose number it is, for example if a data protection query arises; they never appear on the card.
• Payment details (handled by Stripe, see Section 7).
When you hold a card
• The cards we have issued to you, their unique card numbers, and their expiry dates.
• Records of any contact with our support team.
• Any renewals, changes to your details, or replacement requests.
Children's applications
Where you are applying on behalf of a child:
• The child's name, date of birth, address, photo, and eligibility evidence.
• Your name, contact details, and confirmation that you have parental responsibility for the child.
See Section 5 for how we handle children's data.
When you contact us
• The content of your messages, emails, or calls.
• Records of complaints and how they were resolved.
When you visit our website
• Your IP address, browser type, device type, pages visited, and how you arrived on the site.
• Cookies, see our separate Cookie Notice for details.
When you use the NDC mobile app
• Your device type, operating system, app version, and basic error and crash logs, to help us keep the app working.
• Your account details (name, email, card number) so we can show you your card and cardholder features.
• Location data, only where you grant the app location permission through your device settings. The app uses your device’s precise (GPS) location solely to search for and display places, discounts, and services near you at the time of your request (for example, nearby accessible facilities or cardholder offers). Your location is processed only transiently for that immediate search: it is not stored on our servers or on your device after the search is complete, and we never build a history of where you have been. To run the search, your coordinates are passed to the mapping service on your device (Google Maps on Android, Apple Maps on iOS), whose processing is covered by Google’s or Apple’s own privacy policy.
We do not share your location with advertisers, analytics providers, or any other external companies. You can withdraw location permission at any time in your device settings; the app will still work, but it will not be able to show you nearby results.
4. How we use your information and our lawful basis
UK GDPR requires us to have a lawful basis for everything we do with your personal information. The
bases we rely on are:
Special category data
Your disability evidence and certain related information are special category data under UK GDPR Article 9. We process this data on the following conditions:
• Article 9(2)(g) and Schedule 1, Part 2, Paragraph 16 of the Data Protection Act 2018: substantial public interest, support for individuals with a particular disability or medical condition. Operating a scheme that allows disabled people to identify themselves to access reasonable adjustments and concessions is recognised public-interest activity.
• Article 9(2)(a): your explicit consent, which we ask for on the application form when you upload your evidence. The substantial public interest condition above remains our primary basis, so the processing of your evidence does not stand or fall on consent alone.
We do not use your special category data for marketing or any purpose other than running the scheme.
5. Children's data
We accept applications for children of any age. Where the applicant is under 18:
• An adult (18 or over), acting with the agreement of a person with parental responsibility, must complete the application on the child’s behalf.
• We confirm the applying adult's relationship to the child and their parental responsibility.
• We hold the child's information for the same purposes and the same periods as we would for an adult cardholder.
• The applying adult exercises the child's rights under UK GDPR until the child is old enough to do so themselves (typically from age 13 for online services in the UK, or earlier where the child has sufficient understanding).
• We do not aim our marketing at children. Marketing emails are sent to the email address given on the application, which for a child’s application is the applying adult’s address. If you are 13 or older and want to take over the running of your own card, contact us and we will work with your parent or guardian to make that happen.
6. Who we share your information with
We share your information only where we need to and only with the people who need to see it.
Inside NDC
NDC staff with a legitimate need (for example, the verification team and customer support) can see
your information. We control access so that staff see only what they need for their role.
Service providers we work with
• Stripe, our payment processor. Stripe handles your card details on our behalf. NDC never sees or stores your full card number or security code.
• Mailchimp, our email service provider, where you have opted in to marketing or where we are sending service messages.
• Zendesk and Google Workspace (Gmail), our customer-service tools, where you contact us with an enquiry, complaint, or subject access request.
• Google Maps (on Android) or Apple Maps (on iOS): when you use the app’s nearby-search features, your coordinates are passed transiently to the mapping service on your device to find results near you. We do not give the mapping service your name or card details, and we share nothing else with it.
• Royal Mail, for the postal delivery of your card to your address.
• Our website hosting and supporting providers, who help us run the website and the application system. These providers are bound by data processing agreements.
• Xero, our accounting system, for payment records.
• Our accountants, auditors and legal advisers, where needed for tax, compliance, or legal reasons.
Public bodies, regulators, and law-enforcement
We may share information where the law requires it, for example:
• HMRC, where we are required to share information for tax purposes.
• The Information Commissioner’s Office (ICO), where required.
• Law enforcement, where we are required to assist with the prevention or detection of crime.
Retailers, venues, and partners
When you show your card at a venue or to a retailer, you are sharing the information visible on the card with that person (your name, photo, card type, and card number). NDC does not share additional information with retailers or venues without your explicit consent.
If you chose the optional emergency contact QR code, anyone who scans the code on your card can obtain the phone number you provided. Only the number is encoded, never your contact’s name. Because the code is printed on the card itself (so that it works in an emergency without any data connection), it cannot be changed or removed once the card has been produced; if the number needs updating or removing, a replacement card must be ordered, and a fee may be charged for this service. If you are an emergency contact and want a number taken out of use, contact us using the details in Section 14: we will remove your details from our records where you ask, and email the cardholder to ask them to order a replacement card.
Where a retailer or venue contacts us to confirm that a card is current and valid (for example, to support a VAT zero-rated sale to a disabled customer), we will confirm only the validity of the card. We do not share your underlying evidence or any further detail.
What we don't do
We do not sell your personal information. We do not share it for third-party marketing.
7. International transfers
NDC is based in the UK and most of our processing happens in the UK. Some of our service providers (for example Stripe and Mailchimp) are based in the United States or store data in the United States. Where we transfer your information outside the UK, we rely on appropriate safeguards under UK GDPR, including:
• The UK Extension to the EU-US Data Privacy Framework (for transfers to US providers certified under the Framework).
• The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses.
• UK adequacy regulations where they apply. You can request a copy of the relevant safeguard from us.
8. How long we keep your information
We keep your information only as long as we need to. The detail is in our Records Retention Schedule, but the headline periods for cardholder data are:
• Active cardholder profile (name, date of birth, contact details, condition self-declaration, photo): while you have a current card, plus a 12-month grace period after a card has expired without renewal.
• Medical / disability evidence files: 3 months after your card is printed. This gives us time to deal with any errors in printing or issues with your card once you receive it, and to issue reprints where needed. After 3 months, your medical evidence is deleted.
• Signed cardholder declaration and verification log: 6 years, to support HMRC's VAT records-retention rules where retailers rely on our verification to offer VAT zero-rated goods to disabled customers.
• Renewal history: 6 years from your final card expiry without renewal, for fraud-prevention and HMRC alignment.
• Declined applications: 12 months, to allow re-application without starting from scratch and to deal with any appeal.
• Payment metadata (date, amount, Stripe reference, never your full card number): 6 years, for HMRC.
• Cardholder support correspondence (non-complaint): 3 years from last interaction.
• Complaints and disputes: 6 years from resolution.
• Marketing-only contact (where you've opted in but the rest of your profile has been deleted): kept while your consent stands and you remain engaged with our emails; reviewed at 2 years of no engagement.
• Suppression list (so we don't accidentally email people who have unsubscribed): 5 years.
• Deceased cardholder records: anonymised within 6 months of confirmed notification.
• Location data from the mobile app: processed only transiently to run your nearby search;
never stored on our servers or your device once the search is complete.
At the end of these periods we securely delete the data, or anonymise it so that you can no longer be identified.
9. Your rights
You have the following rights in relation to your personal information under UK GDPR. We will respond to any request within one month of receiving it. For complex or multiple requests we may extend this by up to two further months, and we will tell you within the first month if so; the period may also pause while we verify your identity or clarify your request.
• Right of access — ask for a copy of the personal information we hold about you (a "subject access request").
• Right to rectification — correct any information that is wrong or incomplete.
• Right to erasure — ask us to delete your information, in certain circumstances.
• Right to restrict processing — ask us to limit how we use your information, in certain circumstances.
• Right to object to processing based on legitimate interests, in certain circumstances.
• Right to data portability — receive a copy of certain information in a structured, machine-readable format.
• Right to withdraw consent, where we rely on your consent (for example, for marketing emails). Withdrawing consent does not affect anything we did before you withdrew it.
• Right to object to direct marketing — you can opt out of marketing at any time, by clicking unsubscribe on any marketing email or by contacting us.
• Right to complain to the Information Commissioner’s Office (ico.org.uk), the UK’s data protection regulator, at any time.
• Right to ask us to take another look at any decision we make about you. Any decision to decline an application is reviewed by a person on our team and is not made by automated processing alone; if you would like someone else to take a fresh look at any decision, just ask.
To exercise any of these rights, email us or write to us using the contact details in Section 14. We do not charge for handling these requests except in the very rare case where the request is "manifestly unfounded or excessive" — in which case we will explain the position to you before doing anything.
10. Marketing
Service messages
We send service messages without needing your marketing consent. These include renewal
reminders, account-related updates, replies to your enquiries, and important changes to our service.
Marketing emails
We send marketing emails (NDC news, partner offers, scheme updates) only:
• On the PECR 2003 soft opt-in basis: when you apply for or buy something from us, the application form gives you a clear chance to say no to marketing at the time, and every email we send includes an unsubscribe link.
• Or where you have separately opted in to hear from us.
Every marketing email contains an unsubscribe link. You can also stop marketing at any time by emailing us. We act on unsubscribes promptly.
We do not share your details with third parties for their marketing.
11. Cookies
Our website uses cookies. Cookies are small text files stored on your device that help our website work, remember your preferences, and help us understand how visitors use the site.
We use the following categories of cookie:
• Strictly necessary cookies — needed for the website to work. These do not need yourconsent.
• Analytical / performance cookies — help us understand how the site is used so we can improve it.
• Functionality cookies — remember your preferences.
• Targeting / advertising cookies — help us show you relevant adverts on other websites. Non-essential cookies are only set if you give consent (via the cookie banner). You can change your preferences at any time from the cookie banner or your browser settings.
For full detail, see our separate Cookie Notice.
12. Keeping your information secure
We take security seriously. We use technical and organisational measures including:
• Access to systems controlled by individual accounts, strong passwords, and multi-factor authentication where available.
• Encryption of data in transit and at rest.
• Restricted access — only people who need to see your information do.
• A documented incident response process for any actual or suspected breach.
• Regular review of our security practices.
If you spot something that looks wrong, or you suspect your account has been compromised, please tell us immediately at info@disabilityid.co.uk.
13. Changes to this notice
We review this notice at least once a year and whenever there is a material change in how we process your information. The current version is published on our website. We will tell you about significant changes by email.
Version: August 2026.
14. Contact and complaints
Contact
• General queries: info@disabilityid.co.uk
• Day-to-day data protection contact: Dianne Taylor, at the Woodbridge office.
• Data Protection Lead: Edward Herbert, edward@disabilityid.co.uk.
• Post: 15a Deben Mill Business Centre, Old Maltings Approach, Melton, Woodbridge, England, IP12 1BL.
Complaints
If you are not happy with how we handle your information, please tell us first so we can try to put things right. You have a legal right to complain to us about how we handle your personal information, by any of the contact routes above or any other reasonable means; we will acknowledge your complaint within 30 days and respond without undue delay.
Governing law: this notice is governed by the laws of England and Wales.