The Essentials in Summary
IMPORTANT NOTICE
This page sets out my personal concerns, questions, and opinions as a whistleblower. The inclusion of any individual's name is not an allegation that they have personally broken the law or acted improperly. It reflects the roles I believe regulators may wish to scrutinise as part of their review.
Between August and November 2025, I believe that multiple compliance and governance concerns arose in connection with The Scout Association, one of the UK's largest youth charities. I have reported these concerns to the Charity Commission and the Information Commissioner's Office (ICO) for review. These concerns may involve trustees, senior leaders, and multiple departments. This site sets out my personal account and analysis as a whistleblower, based on contemporaneous emails, screenshots, and documents in the ZIP archive. Where I refer to potential 'breaches' of law or guidance, these are my concerns and interpretations unless and until a regulator or court reaches a formal conclusion.
What Happened?
- I believe there are grounds for concern about the lawful basis relied upon for publishing my disability diagnosis in a national blog post and on social media. I have asked the ICO to review whether valid, explicit consent existed and what special category conditions were relied upon.
- In my view, the interview process was poorly designed for neurodivergent candidates and did not proactively address reasonable adjustments, despite my disability being recorded in their systems.
- In my view, when I raised internal concerns, my disclosure appeared to be handled as a standard complaint on two occasions rather than being treated as a systemic governance matter.
- I repeatedly requested internal resolution. In my view, I did not receive the level of engagement I expected from the Association and its trustees, and this represents a serious governance concern.
- In my view, the ID requirements for a Subject Access Request appeared disproportionate and I have asked the ICO to review.
- To my knowledge, I did not receive any direct written response from the DPO for nearly six months after my initial concern was raised.
- I am concerned that if Data Protection processes were managed by Legal Services (for example, Legal Services managing data subject access requests), this may affect perceived independence, but this is for regulators to assess.
- In my view, there appear to be differences between some public statements made on behalf of the Association and the documents I hold. I make no suggestion that any named individual has been dishonest. I have provided the relevant materials to regulators for them to assess whether any inconsistency exists.
- Trustees were informed by email, and I have raised concerns about potential conflicts of interest in how some roles were involved.
- I believe the blog and social posts were removed after I notified the Association that I would escalate to regulators. I have asked regulators to consider whether appropriate records and decision trails exist for the timing of that removal.
- I am concerned that the whistleblower and complaints processes, as applied in my case, may not provide sufficient independence at senior level, but this is for regulators to decide.
- Based on the platform's stated reach, I believe the post may have been accessible to a very large audience. I am concerned that removal was not prompt after my warning, and I have provided the timeline for regulator review.
- I am concerned that trustees may not have notified their insurers of a written claim, but I cannot confirm this and it is for the insurers to address.
Legal & Regulatory Breaches
UK GDPR
I believe the events I describe may engage UK GDPR requirements, including:
- Principles and lawful basis/special category conditions: Concerns about consent and/or other conditions relied upon for processing and publishing my diagnosis as special category data, and concerns about inconsistent explanations given.
- Transparency and subject access: Concerns about subject access handling and whether the ID requirements imposed were proportionate.
- Security and incident consideration: Concerns about public accessibility of special category data and whether any assessment or notification duties were considered.
- Accountability documentation: To my knowledge, I have not been provided with records of decision-making, any DPIA, or detailed input from the DPO, and I have asked the regulator to assess whether appropriate accountability records exist.
Charity Commission Guidance
Alleged issues under CC3, CC20, CC26, CC27 and CC29:
- I believe the trustee oversight and handling of my disclosure raise governance concerns.
- To my knowledge, no serious incident report was filed, but I cannot confirm this.
- In my view, reputational risk, potential conflicts of interest, and data management concerns were not addressed to a standard I would expect.
- I am concerned that the whistleblowing handling and risk oversight in my case may have been ineffective.
Equality Act 2010 (or poor process)
- Sections 20–21: In my view, reasonable adjustments did not appear to be proactively offered during the selection process despite my disability being on record. I consider this poor practice, but I acknowledge I cannot see the full picture of what was discussed internally.
- Section 27: In my view, aspects of the timeline and my experience of the subject access request may raise concerns that a court or tribunal could consider relevant, although only a court or tribunal could decide whether any unlawful victimisation occurred.
Who is Involved?
Listing an external organisation, department, or role below means that I emailed or copied that area in my correspondence. Listing an individual's name and role below is not an allegation that that person has broken the law, acted improperly, or bears personal responsibility for any of the concerns I describe. I include names to provide transparency about the roles involved in my correspondence, and because I believe regulators may wish to examine the conduct of those roles. The list below includes both trustees/executive leadership and operational staff I corresponded with during this matter. Operational staff are named to provide transparency about the roles involved in my correspondence and to support the factual record. I do not allege that any operational staff member bore personal responsibility for the governance concerns described. Their inclusion reflects the scope of my correspondence, not an allegation of wrongdoing by them individually
External Organisations
- Black Penny Consulting Ltd (06607756) (Active Data Protection Officer for The Scout Association)
- Kennedy's Law LLP (OC353214) (Instructed Solicitor for The Scout Association)
- AXA Insurance UK Plc (00078950) (Insurer for The Scout Association)
- Liberty Mutual Insurance Europe SE (OE022276) (Insurer for The Scout Association)
Departments
- Governance
- Legal Services
- Whistleblowing
- Safeguarding
- Communications & Media Relations
- Brand & Content
- Data Protection
- Executive Leadership
Individuals (names & roles)
- Aidan Jones - Board of Trustees/Executive Leadership Team
- Chris Reed - Executive Leadership Team
- Carl Hankinson - Board of Trustees/UK Leadership Team
- Ayesha Karim - Board of Trustees/UK Youth Team/UK Leadership Team
- Craig Dewar-Willox - Board of Trustees
- Busola Sodeinde - Board of Trustees
- Christopher James - Brand and Content Team
- Helen Church - Resolution Team
- Nadeem Azhar - Legal Team
- Natalie Layton - Governance Team
- Alanah Reid - Brand and Content Team/Employee Forum Team
- Volkan Ceylan - UK Youth Team
- Andrew Maslen - Information Governance Team
Why It Matters
- I am concerned that data protection obligations may not have been fully met, which I believe could engage high-risk data protection considerations, but this is for the ICO to determine.
- Trustees are legally bound to run the charity in line with UK law; in this case, I believe there are grounds for concern about whether appropriate governance and oversight occurred.
- In my view, the responses I received appeared to prioritise other factors over addressing my concerns, but whether this reflects a failure of legal duty is for regulators to assess.
- In my view, the number of issues I experienced over a short period is, in my experience, highly unusual.
- If a national charity is ultimately found by regulators to have failed in charity governance and/or data protection obligations, that can harm its relationship with key partners.
- Significant regulatory action could occur depending on regulator findings.
- National programmes, international events, and partner trust are at stake.
- If functions lack independence in handling (for example, Legal Services and Data Protection processes being closely aligned), this may highlight systemic issues, but that is for regulators and the court to decide.
- In serious cases, regulators have powers to intervene in a charity’s governance, including measures affecting trustees. If allegations are upheld, there could be consequences for national leadership.
- In my view, these issues may reflect a reluctance at The Scout Association toward fully resolving serious concerns, but I acknowledge I may not have the full picture.