St Mark s Church of England Academy Data Protection Policy

Size: px
Start display at page:

Download "St Mark s Church of England Academy Data Protection Policy"

Transcription

1 St Mark s Church of England Academy Data Protection Policy 1

2 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:... Error! Bookmark not defined. Revision:... Error! Bookmark not defined. Distribution:... Error! Bookmark not defined. 2

3 Author Claire Wilkins Target Owner CfBT Schools Trust group Issued September 2017 Next review due All employees, consultants and volunteers September 2018 This policy applies to the whole of CfBT Schools Trust (CST), including all schools. Introduction The law around data protection is changing. Current legislation is within the Data Protection Act 1998 (DPA). In May 2018, the General Data Protection Regulation (GDPR) will come into force. This policy will be updated ready for the GDPR in early 2018 and CST will provide information and updates to schools in preparation for these changes. For now, the DPA, and this template policy, continues to apply. The DPA places obligations on organisations that use personal information (Personal Data), including schools, and gives individuals certain rights. The DPA states that those who record and use personal information must be open about how the information is used and must follow the eight principles of good information handling. The Information Commissioner s Office (ICO) is the regulating body and they maintain a public register of data controllers. CST has registered with the ICO as a data controller. This registration covers all CST schools and schools do not need to register separately. Please follow this link to view the registration: CCTV and biometrics are included on our registration. All schools are required to keep CST informed of any changes in how data is processed by the school, so that we can notify the ICO within 28 days of the change (notification@ico.gsi.gov.uk - there is no charge for this). Please note that failure to comply with the above is a criminal offence. Further Information You can find out more about notifying the ICO (and the associated costs) via this page of the ICO website: There is lots of other useful information for schools on data protection on the ICO website: 3

4 Main education page: This page includes the latest ICO guidance notes on the following topics: on biometrics; taking photos in schools; use of CCTV in schools; lesson plans on data protection and many other useful topics. Claire Wilkins, CST Legal and HR Lead is also available to help with any data protection queries. Data Protection tips: Parents and pupils can request to see any personal data held by the school which relates to them this may include s between staff and handwritten notes. Ensure all staff are aware that what they write may be seen. Both the Data Protection Act and the Freedom of Information Act apply to academies do not confuse the two as the requirements and timescales are different. The Data Protection Act applies to academies in a different way to state schools. For example academies have 40 calendar days in which to respond to requests for personal data rather than the 15 days that state schools usually have. The charges are also different. Include a data protection statement or privacy notice in the school prospectus or welcome book as well as on any forms used to collect personal data. It is important to inform parents and pupils what personal information you are collecting and why (including for example telephone numbers, photos of pupils and CCTV images) Schools can take photos of pupils for inclusion in the prospectus or website so long as you have informed parents and pupils of your intentions. Images captured by individuals for personal or recreational use with a mobile phone, digital camera or camcorder are exempt from the DPA (i.e. parents can take photos of pupils in a school play). The rules on data protection are complicated and there are often exceptions to a rule. Seek advice from the Trust s Legal and HR Lead if you are unsure, especially when responding to a data subject access request. 4

5 Biometric Data Since September 2013, there are no circumstances in which a school can lawfully process, or continue to process, a pupil s biometric data (i.e. fingerprints, palm scans) without having notified each parent of a child and received the necessary consent. Schools must obtain the written consent of at least one parent before the biometric data are taken from the child and used. This applies to all pupils in schools under the age of 18. In no circumstances can a child s biometric data be processed without written consent. Schools and colleges must not process the biometric data of a pupil (under 18 years of age) where: a) the child (whether verbally or non-verbally) objects or refuses to participate in the processing of their biometric data b) no parent has consented in writing to the processing; or c) a parent has objected in writing to such processing, even if another parent has given written consent. Schools must provide reasonable alternative means of accessing services for those pupils who will not be using an automated biometric recognition system. All biometric information is legally regarded as personal data as defined by the Data Protection Act 1998; this means that it must be obtained, used and stored in accordance with that Act, as with all other personal data. Data Protection In order to operate efficiently CfBT Schools Trust (CST) has to collect and use information about people. This may include current, past and prospective pupils, parents, members of the public, staff and suppliers. We are committed to ensuring personal data is properly managed and the Data Protection Act 1998 (DPA) is complied with. We will make every effort to meet its obligations under the legislation. This policy, and our processes, will be updated when the new General Data Protection Regulation (GDPR) comes into force in May Scope and Publication This policy applies to all staff, Local Governors, contractors, agents and representatives working for or on behalf of the Trust, including in all schools and the CST central team, and is available via the website and on request. This policy can be made available in large print or other accessible format if required. This policy applies to all personal data processed by the Trust and held electronically or manually. Images captured by individuals for personal or recreational use with a mobile phone, digital 5

6 camera or camcorder are exempt from the DPA (i.e. parents are allowed to take photos of pupils in a school play). Responsibilities CST is the data controller for the purposes of the act and therefore have overall responsibility for compliance with the DPA. CST have delegated responsibility to the Headteacher in each school for ensuring compliance with the DPA and this policy within the day-to-day activities of the school. The Headteacher has appointed a Data Protection Officer (DPO). The DPO is responsible for: notifying CST about any change in the school s use of data to allow CST to keep the ICO up to date with changes in how the school processes data obtaining consent for disclosure of personal data, including routine consent from parents and pupils for using photographs for general school purposes ensuring data protection statements are included on forms that are used to collect personal data acting as a central point of advice for staff on data protection matters coordinating requests for personal data arranging appropriate data protection training for all staff keeping up to date with the latest data protection legislation and guidance ensuring adequate systems are in place for compliance with this policy working with CST to update processes in line with the GDPR. Definitions Personal data: information which relates to an identifiable living individual that is processed as data. Examples would be names of staff and pupils, dates of birth, addresses, national insurance numbers, school marks, medical information, exam results, SEN assessments and staff development reviews. Processing data: collecting, using, disclosing, retaining, or disposing of information. Sensitive personal data: information that relates to race and ethnicity, political opinions, religious beliefs, membership of trade unions, physical or mental health, sexuality and criminal offences. 6

7 The Requirements The DPA stipulates that anyone processing personal data must comply with eight principles of good practice. The principles require that personal data: 1. Shall be processed fairly and lawfully and in particular, shall not be processed unless specific conditions are met. 2. Shall be obtained only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or those purposes. 3. Shall be adequate, relevant and not excessive in relation to the purpose or purposes for which it is processed. 4. Shall be accurate and where necessary, kept up to date. 5. Shall not be kept for longer than is necessary for that purpose or those purposes. 6. Shall be processed in accordance with the rights of data subjects under the Act. 7. Shall be kept secure i.e. protected by an appropriate degree of security. 8. Shall not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of data protection. Notification As required under the DPA, CST will ensure that the ICO is notified that we are processing personal data and in what ways and will ensure the registration is renewed annually. Data Gathering Whenever we collect new information about individuals we will ensure individuals are made aware: that the information is being collected of the purpose that the information is being collected for of any other purposes that it may be used for who the information will or may be shared with; and how to contact the data controller. 7

8 We will only obtain relevant and necessary personal data for lawful purposes and will only process the data in ways which are compatible with the purpose for which it was gathered. Data protection statements will be included in the school prospectus and on forms that are used to collect personal data. Data Storage Personal data will be stored in a secure and safe manner. The following measures are taken to help ensure this: Electronic data will be protected through secure password, encryption software and firewall systems. Computer workstations in administrative areas will be positioned so that they are not visible to casual observers. Manual personal data will be stored securely where it is not accessible to anyone that does not have a legitimate reason to view or process the data. Particular attention will be paid to the need for security of sensitive personal data, for example health and medical records will be kept in a locked cupboard. Personal data will not be left out visible on desks. The physical security of buildings and storage systems will be regularly reviewed. Staff will be trained on this policy and related data protection procedures. Data Checking Systems will be put in place to ensure the personal data that we hold is up to date and accurate. For example, the school will ensure that parents are asked at least once a year to confirm their contact details. Any inaccuracies discovered or reported will be rectified as soon as possible. Disclosing Data Personal data will only be disclosed to organisations or individuals for whom consent has been given to receive the data, or organisations that have a legal right to receive the data without consent being given. When requests to disclose personal data are received by telephone, we will ensure that the caller is entitled to receive the data and that they are who they say they are. In some circumstances, we may call the caller back to check the identity of the caller. 8

9 Personal data will not be included on the website, in newsletters or other media without consent of the individual (or his/her parents where appropriate). Routine consent may be requested from parents to avoid the need for frequent, similar requests for consent being made by the school. Personal data will only be disclosed to the Police if they are able to supply sufficient authority which notifies of a specific, legitimate need to have access to specific personal data. Data Subject Access Requests Any person whose personal data is held by CST is entitled, under the DPA, to ask to access this information. The request must be in writing. The right is to view or be given a copy of the personal data, rather than to the whole document which contains the personal data. There are some exceptions to the rights of access to information in certain records (for example in relation to examination scripts, legal advice). When a request is received by a member of staff, this should be passed to the school s Data Protection Officer without delay. The request must be dealt with promptly; a response must be provided as soon as possible and no later than within 40 calendar days from the date the request was received. We may make a charge of 10 for responding to a request for personal data under the DPA and will need to confirm the requester s identity. Parents can make data subject access requests on their child s behalf if their children are deemed too young to look after their own affairs. If a request is made by a parent for personal data relating to their child and the child is aged 12 years or older, written consent will need to be sought from the child before the data is disclosed to the parent. A record will be kept of all data subject access requests made that require formal consideration. Destroying Data Out-of-date information will be discarded if no longer relevant. Personal data will only be kept as long as reasonably needed, for legal or business purposes. 9

10 Breach of the Policy Non-compliance of this policy and data protection legislation by a member of staff is considered a disciplinary matter which, depending on the circumstances, could lead to dismissal. Monitoring, Evaluation and Review The DPO will monitor the implementation and effectiveness on this policy and report his/her evaluation to the Headteacher on an annual basis. The Headteacher will report back to CST on this policy and its implementation and effectiveness every two years, who will then review the policy, making amendments where necessary. This policy will be reviewed in early 2018 in readiness for the GDPR coming into force in May

11 Indication of Parent s Preference Student Name Date of Birth Address Parent s Declaration of Preference Please insert tick or info. here I agree to photographs or film of my child appearing in any publication or form approved by the Headteacher including the school website. I agree to photographs or film of my child appearing only in the following publications or circumstances (give details). I do not agree to photographs or film of my child appearing in any circumstances. I agree to the following information being associated with my child's photograph or image at the discretion of the Headteacher (please specify e.g. name, age, class, home location, prizes won etc) or say ALL or NONE as appropriate. I consent to the school taking and using information from my child s [insert biometric e.g. fingerprint] by as part of an automated biometric recognition system. This biometric information will be used by the school for the purpose of [describe purpose(s) for which this data will be used, e.g. administration of school library/canteen]. Once your child ceases to use the biometric recognition system, his/her biometric information will be securely deleted by the school. I do not consent to the school taking and using information from my child s [insert biometric e.g. fingerprint] by as part of an automated biometric recognition system. If you wish to withdraw or amend your consent for the above at any time, this must be done in writing and sent to the school. Parents/legal guardians Signed Name (block capitals) Signed Name (block capitals) Signed Student (where applicable) Name (block capitals) 11

DATA PROTECTION POLICY 2016

DATA PROTECTION POLICY 2016 DATA PROTECTION POLICY 2016 ADOPTED FROM BRADFORD METROPOLITAIN COUNCIL MODEL POLICY AUTUMN 2016 To be agreed by Governors on; 17/10/16 Signed by Chair of Governors: Statutory policy: Yes Frequency of

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1. Introduction This policy is intended to provide information about how the School will use (or process ) personal data about individuals including: Current, past and prospective pupils; Parents, carers

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Reviewed by: Reviewed when Resources Committee As required Date written and last reviewed July 2018 Source and date of model policy, if applicable n/a Contents 1. Aims... 2 2. Legislation

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

DATA PROTECTION POLICY 2018

DATA PROTECTION POLICY 2018 DATA PROTECTION POLICY 2018 Amesbury Baptist Church is committed to protecting all information that we handle about people we support and work with, and to respecting people s rights around how their information

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

Data Protection Policy. UK Policy May 2018

Data Protection Policy. UK Policy May 2018 UK Policy May 2018 5 & 7 Diamond Court, Opal Drive, Eastlake Park, Fox Milne, Milton Keynes MK15 0DU, T: 01908 396250, F: 01908 396251 www.cognitaschools.co.uk Registered in England Cognita Limited No

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

Regulates the way data controllers process personal data

Regulates the way data controllers process personal data GUIDANCE NOTE ON THE DATA PROTECTION ACT 1998 This guidance note gives an overview of how the Data Protection Act 1998 (the Act ) applies to clubs (including class associations) and recognised training

More information

Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE

Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE Prepared by: Peter Hawksworth, Headteacher Checked by: Jackie Hesslegrave, Business Manager Adopted by Governors: November 2017 Review

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

Data Management and Protection Policy

Data Management and Protection Policy Data Management and Protection Policy Approved by Governor committee: Finance and Audit Date to be reviewed: June 2018 Responsibility of : Director of Finance and Operations Date ratified by Governing

More information

Data Protection Policy

Data Protection Policy Data Protection Policy (Data Protection Act 1998) (This policy will be updated to incorporate GDPR by May 2018) Page 1 of 9 Data Protection Policy 1 Statement of Policy The Constellation Trust needs to

More information

Baptist Union of Scotland DATA PROTECTION POLICY

Baptist Union of Scotland DATA PROTECTION POLICY Baptist Union of Scotland DATA PROTECTION POLICY Adopted: May 2018 1 1.The Baptist Union of Scotland 48, Speirs Wharf, Glasgow G4 9TH (Charity Registration SC004960) is committed to protecting all information

More information

St Michael s CE Primary School Data Protection Policy

St Michael s CE Primary School Data Protection Policy St Michael s CE Primary School Data Protection Policy We will prepare the children at St. Michael's school for life, by giving them the opportunity to fulfil their potential within a happy caring Christian

More information

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY Adopted: 5 June 2018 1 Earls Hall Baptist Church is committed to protecting all information that we handle about people we support and work with, and to

More information

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3 Norwich Central Baptist Church DATA PROTECTION POLICY Adopted: May.2018 Norwich Central Baptist Church (NCBC) is committed to protecting all information that we handle about people we support and work

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version Date Revision Author Summary of Changes 1.0 21 st May 2018 Ashleigh Morrow EXECUTIVE STATEMENT At CASTLEREAGH NURSERY SCHOOL (the School ), we believe privacy is important.

More information

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY Dingwall Baptist Church DATA PROTECTION POLICY Adopted: By Trustees Dingwall Baptist Church May 2018 1 Dingwall Baptist Church is committed to protecting all information that we handle about people we

More information

VMS Software Ltd- Data Protection Privacy Policy

VMS Software Ltd- Data Protection Privacy Policy VMS Software Ltd- Data Protection Privacy Policy Introduction The purpose of this document is to provide a concise policy statement regarding the Data Protection obligations of VMS Software Ltd. This includes

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

The template uses the terms students / pupils to refer to the children or young people at the institution.

The template uses the terms students / pupils to refer to the children or young people at the institution. This document is for advice and guidance purposes only. It is anticipated that schools / colleges will use this advice alongside their own data protection policy. This document is not intended to provide

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ] SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY Adopted: [17-04-2018] 1 SAFFRON WALDEN COMMUNITY CHURCH is committed to protecting all information that we handle about people we support and work

More information

POLICY ON INFORMATION, SECURITY & DATA PROTECTION

POLICY ON INFORMATION, SECURITY & DATA PROTECTION POLICY ON INFORMATION, SECURITY & DATA PROTECTION As a recruitment company, First Recruitment is a data controller. This means it processes personal data about its work seekers, individual client contacts

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

Data Protection Policy

Data Protection Policy Data Protection Policy for The Astor Bannerman Group of Companies Issue Date: 3 rd January 2014 Version: 01 Approval History Name Department Role/Position Date approved Signature James Stuart- Smith Director

More information

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018 LIFE STYLE CARE PLC Privacy Statement for Employees August 2018 Key points Why we use your personal data: We typically use your personal information for purposes related to your employment relationship

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Control History Title Data Protection Policy Version no. 1.0 Date of publication May 2018 Author(s) Amanda Cramb, HR Manager Next review date May 2021 Page 1 Introduction

More information

RAW MARKETING DATA PROTECTION POLICY

RAW MARKETING DATA PROTECTION POLICY RAW MARKETING DATA PROTECTION POLICY Introduction We take your privacy very seriously and have updated our Privacy Statement in line with the upcoming GDPR regulation. Were absolutely committed to reflecting

More information

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make. What is the purpose of this document? NORTHERN IRELAND SCREEN COMMISSION (Company Number NI031997) whose registered office is at 3 rd Floor Alfred House, 21 Alfred Street, Belfast, BT2 8ED is committed

More information

CHANNING SCHOOL DATA PROTECTION POLICY

CHANNING SCHOOL DATA PROTECTION POLICY CHANNING SCHOOL DATA PROTECTION POLICY The School may amend/change/update this Policy from time to time. 1. Background Data protection is an important legal compliance issue for Channing School. During

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions.

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions. Page 2 of 10 Data Protection Policy Chief Information Officer Chief Information Officer Data Protection Officer The current version (July 2018) is derived from, and supersedes, the version published in

More information

Parent / Carer Privacy Notice

Parent / Carer Privacy Notice Document No. PP Issue No. 1 Issue Date: 2018-05-24 Renewal Date: 2019-05-24 Originator: Kate Frith Responsibility: Director of Resources 1. Policy statement Parent / Carer Privacy Notice We are Fullhurst

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate

More information

Data Protection/ Information Security Policy

Data Protection/ Information Security Policy Data Protection/ Information Security Policy Date Policy Reviewed 27 th April 2016 Date Passed to Governors: 27 th April 2016 Approved by Governors: 7 th June 2016 Date of Next Review: June 2018 Data Protection

More information

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

Data Protection Policy for Staff DJJK. Apr of 10

Data Protection Policy for Staff DJJK. Apr of 10 Data Protection Policy for Staff DJJK Apr 2018 1 of 10 Review and Amendment Record Date Person Conducting the Review Mar 2018 PMS New Policy, GDPR Apr 2018 DJJK Review Changes Made 2 of 10 1 Introduction

More information

Data Protection Policy.

Data Protection Policy. Data Protection Policy. The Leonardo Trust needs to keep certain information on its Employees, Volunteers, Service Users (clients) and Trustees to carry out its day to day operations, to meet its objectives

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Mission Statement WeST holds a deep seated belief in education and lifelong learning. Effective collaboration, mutual support and professional challenge will underpin our quest to

More information

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY LEICESTER HIGH SCHOOL DATA PROTECTION POLICY 1. Background Data protection is an important legal compliance issue for Leicester High School. During the course of the School's activities it collects, stores

More information

Little Gaddesden C. of E. Primary School

Little Gaddesden C. of E. Primary School PRIVACY NOTICE - PARENTS AND CARERS Approved by Resources Committee 21 May 18 Approved by Governing Body 22 May 18 Review by May 20 Little Gaddesden School collects data and information about parents /

More information

EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants

EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants EDWARDS COMMERCIAL CLEANING SERVICES LTD and EDWARDS COMMERCIAL CLEANING (NORTH) LTD Data Protection Policy for Employees, Workers and Consultants 1 Overview Data Protection Policy for Employees, Workers

More information

SHENLEY BROOK END SCHOOL

SHENLEY BROOK END SCHOOL SHENLEY BROOK END SCHOOL DATA PROTECTION POLICY Linked Policies: CCTV Review Information Reviewed by Finance Pay and Personnel Committee 15 May 2012 Reviewed by Policy Committee August 2013 Adopted by

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: 4 1. Statement of Intent 1.1 Radian 1 must collect, store and process information about its customers,

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

Data Protection Policy

Data Protection Policy Policy Current Status Operational Last Review: May 2018 Responsibility for Review: Director of Administration, Contracts and Health Next Review: September 2019 Internal Approval: & Safety SLT Originated:

More information

This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects.

This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects. BELFAST ROYAL ACADEMY Data Protection Policy Introduction Belfast Royal Academy recognises and accepts its responsibilities as set out in the Data Protection Act 1998. The School will take all reasonable

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

HITCHIN GIRLS SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING HITCHIN GIRLS SCHOOL

HITCHIN GIRLS SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING HITCHIN GIRLS SCHOOL HITCHIN GIRLS SCHOOL PRIVACY NOTICE FOR PARENTS / CARERS OF PUPILS ATTENDING HITCHIN GIRLS SCHOOL Hitchin Girls School collects data and information about parents / carers of our pupils so that we can

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Date approved by the Board of Directors: 7 July 2017 Date adopted by Essa Academy Local Governing Body:

More information

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH, NORTHALLERTON (referred to in this policy as NLBC) is committed to

More information

Privacy notice for the school workforce (all staff) The personal data we hold

Privacy notice for the school workforce (all staff) The personal data we hold In line with new General Data Protection Regulations (GDPR), effective from 25 May 2018, please find below details of the privacy notice for all students in school. Privacy notice for the school workforce

More information

Data Protection Policy, including Key Procedures

Data Protection Policy, including Key Procedures Data Protection Policy, including Key Procedures Revision Number :- 0 Date :- 16 April 2018 Status :- Approved Issue Date :- 22 March 2018 HEADING Aims of this Policy SECTION CONTENT Milton s Cottage Trust

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

UoW takes measures to enable data to be restored and accessed in a timely manner in the event of a physical or technical incident.

UoW takes measures to enable data to be restored and accessed in a timely manner in the event of a physical or technical incident. PRIVACY NOTICE UNIVERSITY OF WARWICK We ask that you read this privacy notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal information,

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

Trinity is committed to protecting the privacy and security of personal data.

Trinity is committed to protecting the privacy and security of personal data. This privacy notice applies data processing activities undertaken by Trinity College for security and monitoring relating to staff, students and visitors to Trinity premises including CCTV, other security

More information

PRIVACY NOTICE FOR PARENTS/CARERS OF PUPILS ATTENDING WARREN DELL PRIMARY SCHOOL

PRIVACY NOTICE FOR PARENTS/CARERS OF PUPILS ATTENDING WARREN DELL PRIMARY SCHOOL Warren Dell Primary School PRIVACY NOTICE FOR PARENTS/CARERS OF PUPILS ATTENDING WARREN DELL PRIMARY SCHOOL Warren Dell Primary School collects data and information about parents/carers of our pupils so

More information

Data protection policy including staff and student privacy notices March 2017

Data protection policy including staff and student privacy notices March 2017 Data protection policy including staff and student privacy notices March 2017 Office use Published: March 2017 Next review: May 2018 Statutory/non: Statutory Lead: Alison Elway, Company Secretary/Head

More information

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems LAST UPDATED June 11, 2018 DATA PROTECTION POLICY International Foundation for Electoral Systems 1. Purpose 1.1. International Foundation for Electoral Systems is committed to complying with privacy and

More information

Security of Personal Data Policy and Guidelines

Security of Personal Data Policy and Guidelines Kensington & Chelsea College Security of Personal Data Policy and Guidelines Written by Richard Lane, April 2009 Updated for subject access requests February 2011 1 Introduction KCC holds personal data

More information

PRIVACY NOTICE FOR JOB APPLICANTS

PRIVACY NOTICE FOR JOB APPLICANTS PRIVACY NOTICE FOR JOB APPLICANTS 1. General Information 1.1 Derby County Football Club are committed to protecting the privacy and security of your personal information. 1.2 Under data protection law,

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Contents 1. Purpose and scope... 2 2. Background... 2 3. Principles... 2 4. Aims and commitments... 3 5. Roles and responsibilities... 3 6. Breaches of data privacy legislation...

More information

PRIVACY NOTICE 1. PERSONAL INFORMATION

PRIVACY NOTICE 1. PERSONAL INFORMATION BLACKBURN PRIVACY NOTICE One Voice Blackburn (CIC) Bangor Street Community Centre, Norwhich Street, Blackburn BB1 6NZ 01254 676193 info@onevoicenetwork.org.uk We are committed to respecting your privacy.

More information

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY Member of staff responsible Head teacher Governor responsible Chair of LGB & DPO Date

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title: Data Protection Policy Ref:CP005 Version:2 Approval Body: Corporation via Audit & Risk Committee Date:24th March 2015 Review Date: 24th March 2018 Lead Person: Director, Institutional Effectiveness

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

THE COURTYARD Privacy Notice Policy

THE COURTYARD Privacy Notice Policy THE COURTYARD Privacy Notice Policy The Courtyard aims to offer an outstanding educational and social provision that will equip our students with the skills and experiences needed to discover and live

More information

THE PORTSMOUTH GRAMMAR SCHOOL

THE PORTSMOUTH GRAMMAR SCHOOL THE PORTSMOUTH GRAMMAR SCHOOL STAFF PRIVACY NOTICE In the course of your employment, engagement or other basis of work undertaken for the school, we will collect, use and hold ( process ) personal data

More information

Data Protection Employee Privacy Notice

Data Protection Employee Privacy Notice Data Protection Employee Privacy Notice Data Protection Employee Privacy Notice Page 1 of 7 Contents 1. Introduction... 3 2. What is personal data/special categories of personal data?... 3 3. What information

More information

DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS

DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS 1 WHAT IS THE PURPOSE OF THIS DOCUMENT? Hopes & Dreams Ltd ( the Nursery

More information

Brasenose College Data Protection Policy Statement v1.2

Brasenose College Data Protection Policy Statement v1.2 Brasenose College Data Protection Policy Statement v1.2 1. Introduction All documents referred to in this policy can be found online at the address below: https://www.bnc.ox.ac.uk/privacypolicies 1.1 Background

More information

Privacy Notice: for staff, trustees, governors and all who are engaged to work within The Evolve Trust

Privacy Notice: for staff, trustees, governors and all who are engaged to work within The Evolve Trust Privacy Notice: for staff, trustees, governors and all who are engaged to work within The Evolve Trust Use of Your Personal Data Statement Purpose: Information that we hold in relation to staff, trustees

More information

Privacy Notice: All staff

Privacy Notice: All staff Privacy Notice: All staff Approved: May 2018 Review date: May 2020 Theale C of E Primary School Church Street Theale RG7 5BZ Tel: 0118 9302239 Email: office@theale.w-berks.sch.uk Privacy Notice: All Staff

More information

Job applicant privacy notice (compliant with the General Data Protection Regulations (GDPR)

Job applicant privacy notice (compliant with the General Data Protection Regulations (GDPR) Job applicant privacy notice (compliant with the General Data Protection Regulations (GDPR) The Company is aware of its obligations under the General Data Protection Regulation (GDPR) and is committed

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

Roundwood Primary School. Privacy Notice Parents

Roundwood Primary School. Privacy Notice Parents Roundwood Primary School Privacy Notice - Parents Name of Policy Privacy Notice Parents Date of adoption April 2018 Date of next review April 2020 Governing Body Committee Responsible Resources Member

More information

Norton Community Primary School. Data Protection Policy. September Vision Statement. Nothing is beyond our reach!

Norton Community Primary School. Data Protection Policy. September Vision Statement. Nothing is beyond our reach! Norton Community Primary School Data Protection Policy September 2018 Vision Statement Nothing is beyond our reach! Care and challenge engage and motivate us! Praise reassures and supports us! Successes

More information

Ark Schools Data Protection & Freedom of Information Policy

Ark Schools Data Protection & Freedom of Information Policy Ark Schools Data Protection & Freedom of Information Policy PURPOSE This Ark Schools Data Protection & Freedom of Information (FOI) policy is intended to ensure that personal information is dealt with

More information

Dixons Academies Charitable Trust. Pupils, parents and staff privacy notice

Dixons Academies Charitable Trust. Pupils, parents and staff privacy notice Dixons Academies Charitable Trust Pupils, parents and staff privacy notice Contents: Privacy notice for parents/carers page 3 Privacy notice for pupils.page 7 Privacy notice for staff page 11 1. Privacy

More information

DATA PROTECTION POLICY VERSION 1.0

DATA PROTECTION POLICY VERSION 1.0 VERSION 1.0 1 Department of Education and Skills Last updated 21 May 2018 Table of Contents 1. Introduction... 4 2. Scope & purpose... 4 3. Responsibility for this policy... 5 4. Data protection principles...

More information

DATA BREACH NOTIFICATION POLICY. Last Updated: Review Date:

DATA BREACH NOTIFICATION POLICY. Last Updated: Review Date: DATA BREACH NOTIFICATION POLICY Last Updated: Review Date: 38T 38T Data Breach Notification policy TABLE OF CONTENTS 1. OVERVIEW... 2 2. ABOUT THIS POLICY... 2 3. SCOPE... 2 4. DEFINITIONS... 2 5. WHAT

More information

LPC Law Recruitment Privacy Notice

LPC Law Recruitment Privacy Notice LPC Law is aware of its obligations under the General Data Protection Regulation (GDPR) and is committed to processing your data securely and transparently. This privacy notice sets out, in line with GDPR,

More information

PRIVACY NOTICE FOR OUR MEMBERS

PRIVACY NOTICE FOR OUR MEMBERS Bury St Edmunds PRIVACY NOTICE FOR OUR MEMBERS We are committed to respecting your privacy. This notice is to explain how we may use personal information we collect before, during and after your membership

More information

Data subject access policy

Data subject access policy Data subject access policy Introduction 1. This is our Data subject access requests policy. 2. We are the professional regulator for nurses and midwives in the UK. Our principal functions include setting

More information

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is:

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is: Page 1 of 8 Owned By: Data Protection Officer Review Due: March 2020 DATA PRIVACY POLICY It is the policy of Horiba MIRA Ltd (MIRA) that it shall at all times respect the privacy of individuals by processing

More information