Data Management and Protection Policy

Size: px
Start display at page:

Download "Data Management and Protection Policy"

Transcription

1 Data Management and Protection Policy Approved by Governor committee: Finance and Audit Date to be reviewed: June 2018 Responsibility of : Director of Finance and Operations Date ratified by Governing Board: 14th July 2016

2 Aims of this policy To outline Chelsea Academy s approach to the collection and management of personal and sensitive personal data, and compliance with legislation involving the protection of that data; To describe the procedures that seek to ensure the integrity and security of that data. Scope of this policy Personal data is any information that relates to a living individual who can be identified from the information. This includes any expression of opinion about an individual. It also applies to personal data held visually in photographs or video clips (including CCTV) or as sound recordings. Sensitive personal data is defined in the Data Protection Act as that relating to an individual s racial or ethnic origin, po litical opinions, religious beliefs or beliefs of a similar nature, me mbership of a trade union, physical or mental health or condition, sexual life, commission or alleged commission of an offence or proceedings for any offence or alleged offence, or court sentence. Chelsea Academy collects a large amount of personal and sensitive personal data every year including staff and student records, examination marks and references. In addition, it may be required by law to collect and use certain types of information to comply with statutory obligations of Local Authorities (LAs), government agencies and other bodies. The Data Protection Act 1998 is the law that protects personal privacy and upholds individual s rights. It applies to anyone who handles or has access to people s personal data. It applies to information regardless of the way it is used, recorded and stored and whether it is held in paper files or electronically. Registration with the Information Commissioner s Office (ICO) The Academy has a legal responsibility to comply with the Act and is the named data controller under the Act. Data Controllers are people or organisations who hold and use personal information. They decide how and why the information is used and have a responsibility to establish workplace practices and policies that are in line with the Act. The Academy as a data controller is registered with the Information Commissioner s Office for the processing of personal data. This information is included in a public register which is available on the Information Commissioner s website at the following link : Data Protection procedures The Academy Registrar is the Data Protection Officer and is the member of staff responsible for monitoring Chelsea Academy s compliance with the Data Protection Act. This will include staff training, handling subject access requests and an annual self audit as recommended by the Information Commissioner s Office. Chelsea Academy will ensure compliance with the Data Protection Act 1988, and any subsequent legislation and guidance, by adopting the 8 data protection principles: 1

3 1. Data will be processed fairly and lawfully. Anyone providing personal data or sensitive personal data will receive a Privacy Notice setting out how their data will be used and shared. A copy of the Privacy Notice will be published on the Academy website, and can be found at Annex B to this policy. All staff will confirm that they have read, understood and will abide by this policy. To ensure that processing is fair and lawful it will be done in accordance with one of the following grounds in the Act: The individual has given his or her consent The processing is necessary for the performance of a contract with the individual The processing is required under a legal obligation to which Chelsea Academy is subject The processing is necessary to protect the vital interests of the individual The process is necessary to carry out public functions The processing is necessary in order to pursue the legitimate interests of the Academy or third parties provided that that is balanced against the rights, freedoms and legitimate interests of the data subject The processing of sensitive personal data can only be carried out if one of the following additional conditions is also met (in addition to the conditions for processing set out above): The explicit consent, in writing, of the individual is obtained The data is required by law for employment purposes or the administration of justice or legal proceedings The processing is necessary for protection of the vital interests of the data subject or another The individual has already deliberately made the information public The processing is necessary for medical purposes, and undertaken by a health professional or someone who is subject to an equivalent duty of confidentiality The processing is necessary for monitoring equality of opportunity, and is carried out with appropriate safeguards for the rights of the individual. 2. Personal data will be obtained only for one or more specific and lawful purposes, and will only be used for the purposes for which it was obtained. No Chelsea Academy employee will knowingly mislead or deceive any other person about the purpose for which information is being collected. 3. Personal data will be adequate, relevant and not excessive in relation to the purpose(s) for which they are processed. Personal data will only be processed for the purposes of managing the Academy, providing education and guidance for the students and submitting statutory returns. 4. Personal data will be accurate and where necessary kept up to date. They will be reviewed regularly and amended as required. The subject of such data may be asked to confirm that what has been recorded is accurate. 5. Personal data processed for any purpose(s) will not be kept for longer than is necessary for that purpose 2

4 We will retain records only for as long as they may be required under relevant legislation, and ensure that when information is authorised for disposal it is done appropriately and securely. Faculties and departments will carry out an annual review of the data they hold and where it is not necessary it will be disposed of securely. 6. Personal data will be processed in accordance with the rights of data subjects under the 1998 Data Protection Act. We will only share personal information with others when it is necessary and legally appropriate to do so. Parents will have access to key information about their child s progress, attainment, attendance, punctuality and behaviour in real time via a secure internet connection, through the Chelsea Academy Learning Cloud (CALC). They will be entitled to receive a copy of their child s record upon request. Subjects will have the right to know what information we hold about them, how we process it and who we share it with. We will deal with subject access requests in line with the ICO Code of Practice, as set out in Annex A. Young people themselves also have the right of access. The Academy reserves the right to discuss with parents/carers any request, from a student under the age of 16 years of age, before complying with the request. However, the normal position will be, that secondary aged students have sufficient understanding of their rights for any request they make to be honoured. Chelsea Academy will also hold records on Academy staff members to inform recruitment, performance management, continuous professional development and financial management procedures. Staff have the right to access all the data that the Academy holds on them. All staff requests for access should be made through the Director of Finance and Operations following the procedures set out in Annex A. 7. Appropriate technical and organisational measures will be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. The Academy will ensure and maintain an appropriate level of security of access to its premises, equipment, network, programs, data and paper records. Such access will be restricted to the appropriate staff. All staff who have access to personal information will receive training on data protection procedures. The Data Protection Policy will operate alongside the Academy s E Safety and Acceptable Use Policy. 8. Personal data will not be transferred to a country outside the EEA, unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. Training Training is a key requirement to ensure DPA compliance. The Academy is committed to ensuring that training is provided for all new staff as part of their induction process. There will also be regular refresher training for all existing staff. The Data Protection Officer will be responsible for managing the provision of training. Policy review The policy will be reviewed every 2 years as part of the Academy s programme of policy review. Any breach of this Data Protection policy will be treated as a disciplinary matter. 3

5 Annex A: Procedure for responding to subject access requests made under the Data Protection Act 1998 Rights of access to information There are two distinct rights of access to information held by schools about pupils: 1. Under the Data Protection Act 1998 any individual has the right to make a request to access the personal information held about them. 2. The right of those entitled to have access to curricular and educational records as defined within the Education Pupil Information (Wales) Regulations These procedures relate to subject access requests made under the Data Protection Act Actioning a subject access request 1. Requests for information must be made in writing, which includes , and be addressed to the Registrar. If the initial request does not clearly identify the information required, then further enquiries will be made. 2. The identity of the requestor must be established before the disclosure of any information, and checks will be carried out regarding proof of relationship to the pupil. Evidence of identity can be established by requesting production of: passport driving licence utility bills with the current address Birth / Marriage certificate P45/P60 Credit Card or Mortgage statement This list is not exhaustive. 3. Any individual has the right of access to information held about them. However with children, this is dependent upon their capacity to understand (normally age 12 or above) and the nature of the request. The Registrar should discuss the request with the child and take their views into account when making a decision. A child with competency to understand can refuse to consent to the request for their records. Where the child is not deemed to be competent an individual with parental responsibility or guardian shall make the decision on behalf of the child. 4. The school may make a charge of up to 10 for the provision of paper information. If the information requested is only the educational record viewing will be free. 5. The response time for subject access requests, once officially received, is 40 days (not working or school days but calendar days, irrespective of school holiday periods). However the 40 days will not commence until after receipt of fees or clarification of information sought. 6. The Data Protection Act 1998 allows exemptions as to the provision of some information; therefore all information will be reviewed prior to disclosure. 7. Third party information is that which has been provided by others, such as the Police, Local Authority, Health Care professional or another school. Before disclosing third party information 4

6 consent should normally be obtained. There is still a need to adhere to the 40 day statutory timescale. 8. Any information which may cause serious harm to the physical or mental health or emotional condition of the student or another should not be disclosed, nor should information that would reveal that the child is at risk of abuse, or information relating to court proceedings. 9. If there are concerns over the disclosure of information then additional advice should be sought. 10. Where redaction (information blacked out/removed) has taken place, then a full copy of the information provided should be retained in order to establish, if a complaint is made, what was redacted and why. 11. Information disclosed should be clear, thus any codes or technical terms will need to be clarified and explained. If information contained within the disclosure is difficult to read or illegible, then it should be retyped. 12. Information can be provided at the school with a member of staff on hand to help and explain matters if requested, or provided at face to face handover. The views of the applicant should be taken into account when considering the method of delivery. If postal systems have to be used, then registered/recorded mail must be used. Complaints Complaints about the above procedures should be made to the Principal who will decide whether it is appropriate for the complaint to be dealt with in accordance with the school s complaint procedure. Complaints which are not appropriate to be dealt with through the school s complaint procedure can be dealt with by the Information Commissioner. Contact details of both will be provided with the disclosure information. Contacts If you have any queries or concerns regarding these policies / procedures then please contact the Director of Finance and Operations in the first instance Further advice and information can be obtained from the Information Commissioner s Office, or telephone

7 Annex B: Privacy notice Data Protection Act 1998: How we use your information We process personal information relating to our pupils and may receive information about them from their previous school or college, employer, local authority, the Department for Education (DfE) and the Learning Records Service. We hold this personal data to: support our pupils learning monitor and report on their progress provide appropriate pastoral care; and assess the quality of our services Information that we hold will include their contact details, national curriculum assessment results, attendance information, any exclusion information, where they go after they leave us and personal characteristics such as their ethnic group, any special educational needs they may have as well as relevant medical information. Some of this information may also be shared with an Independent Careers Adviser, who operates within the Academy. Chelsea Academy also uses CCTV to monitor its premises and adjacent areas in order to maintain security and to prevent and investigate crime. Images are recorded, kept for up to 30 days and then securely destroyed in accordance with the Data Protection Act. We will not give information to anyone without consent unless the law and our policies allow us to. If you want to see a copy of the information we hold and share about you then please contact the Director of Finance and Operations. If you require more information about how the LA or DfE store and use this data please see their websites or contact them as follows: Data Protection Officer Information Governance Team Information Systems Division (ISD) The Royal Borough of Kensington and Chelsea The Town Hall, Hornton Street, London W8 7NX dataprotection@rbkc.gov.uk Web: Department for Education Telephone: Web: EPIC Youth CEIAG Service : Once a student is aged 13 or over we are required to pass on certain information to the EPIC Youth CEIAG Service, RBKC s information and advice service for all young people aged 13 to 19. We must provide both the student s and parents /carers names and addresses, and any further information relevant to the EPIC Youth CEIAG Service role. However, you (if you are over 16) or your parents can ask that no information beyond name and address be passed to EPIC. Please inform the Academy Registrar if you wish to opt out of this arrangement. For more information about EPIC Youth CEIAG Service, please contact the Local Authority as shown above. This information sheet can also be found on our website. 6

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

DATA PROTECTION POLICY 2016

DATA PROTECTION POLICY 2016 DATA PROTECTION POLICY 2016 ADOPTED FROM BRADFORD METROPOLITAIN COUNCIL MODEL POLICY AUTUMN 2016 To be agreed by Governors on; 17/10/16 Signed by Chair of Governors: Statutory policy: Yes Frequency of

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Date approved by the Board of Directors: 7 July 2017 Date adopted by Essa Academy Local Governing Body:

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1. Introduction This policy is intended to provide information about how the School will use (or process ) personal data about individuals including: Current, past and prospective pupils; Parents, carers

More information

Data Protection Policy

Data Protection Policy Data Protection Policy University of London Data Protection UoL website link: http://www.london.ac.uk/238.html Email: records.managament@london.ac.uk Contents 1 Policy statement... 3 2 Introduction and

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

Data Protection/ Information Security Policy

Data Protection/ Information Security Policy Data Protection/ Information Security Policy Date Policy Reviewed 27 th April 2016 Date Passed to Governors: 27 th April 2016 Approved by Governors: 7 th June 2016 Date of Next Review: June 2018 Data Protection

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

THE HEATH ACADEMY TRUST DATA PROTECTION POLICY

THE HEATH ACADEMY TRUST DATA PROTECTION POLICY THE HEATH ACADEMY TRUST DATA PROTECTION POLICY inspire transform together Summary Policy Reference Number: 024 Category: Authorised By: Committee Responsible: Data Protection Board Of Directors Board Of

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you: Ignata Group Data Protection / Privacy Notice What is the purpose of this document? Ignata is committed to protecting the privacy and security of your personal information. This privacy notice describes

More information

IQ Data Protection Policy

IQ Data Protection Policy IQ Data Protection Policy Statement of purpose IQ Ltd is registered on the Data Protection register as a statutory requirement for organisations that hold personal data. Registration was first completed

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY APPENDIX. DATA PROTECTION POLICY Document Status Author Director of Registry Services (Data) Date of Origin 27 th July 2011 This Version July 2014 Review requirements Date of next review July 2016 Approval

More information

GROUP DATA PROTECTION POLICY

GROUP DATA PROTECTION POLICY GROUP DATA PROTECTION POLICY Conducting business the right way Safeguarding our customer and employee personal data Version 1 [August 2016] CONDUCTING BUSINESS THE RIGHT WAY Our Values, Doing the Right

More information

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS What is the purpose of this document? FS1 Recruitment UK Ltd is committed to protecting the privacy and security of your

More information

Data Protection Policy

Data Protection Policy Data Protection Policy for The Astor Bannerman Group of Companies Issue Date: 3 rd January 2014 Version: 01 Approval History Name Department Role/Position Date approved Signature James Stuart- Smith Director

More information

Data Protection Act 1998 Employee Fair Processing Notice

Data Protection Act 1998 Employee Fair Processing Notice Data Protection Act 1998 Employee Fair Processing Notice Reference: Document Type: Status of Document: Policy Final Version: 1.3 Date Approved: 16 th December 2014 Approved By: Director of HR & OD Publication

More information

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1. Company Name: Document DP3 Topic: Skills Direct Ltd ( the Company ) Data Protection Policy Data protection Date: 21 st May 2018 Version: Version 1 Contents Introduction Definitions Data processing under

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy DATA PROTECTION POLICY WINCHESTER CITY COUNCIL Document Title: Author: Fiona Sutherland Revision History Version Revision Date Summary of Change Distribution 1.0 08/03/16 Internet Intranet WINCHESTER CITY

More information

RESEARCH ETHICS POLICY

RESEARCH ETHICS POLICY RESEARCH ETHICS POLICY ODSc agreed document August 09 Date approved at Board of Trustees October 09 Board of Trustees Number BOT091005e Date Policy/Procedure to be implemented October 09 Date to be reviewed

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

Data Protection Audit Self-assessment toolkit

Data Protection Audit Self-assessment toolkit Data Protection Audit Self-assessment toolkit online preferences security passport details emergency contact details blood group email account number accuracy CCTV images tax records rights payroll number

More information

Disclosure & Barring Service (DBS) Check Policy

Disclosure & Barring Service (DBS) Check Policy Disclosure & Barring Service (DBS) Check Policy Version: Final Author: HR Manager Date Issued: December 16 Date Approved by SMT: January 17 Impact Assessment Completed Yes Date of Next Review: January

More information

DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS

DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS 1 WHAT IS THE PURPOSE OF THIS DOCUMENT? Hopes & Dreams Ltd ( the Nursery

More information

Data Privacy Policy for Employees and Employee Candidates in the European Union

Data Privacy Policy for Employees and Employee Candidates in the European Union Data Privacy Policy for Employees and Employee Candidates in the European Union This Data Privacy Policy is effective as of February 1, 2014 1. Data Privacy Policy Overview 1.1 Under Armour, Inc. (the

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

General Data Protection Regulation

General Data Protection Regulation General Data Protection Regulation Draft Privacy Notice for employees November 2017 www.uk.coop/gdprtoolkit This is a draft document which provides a widely drafted privacy notice to allow data to be processed

More information

Privacy Policy for Employees

Privacy Policy for Employees 1. Introduction This privacy notice explains why we collect your personal information, what we collect, what we do with it and the conditions in which we may disclose it to others. This policy applies

More information

Code of Conduct for Staff

Code of Conduct for Staff Diocese of Bristol Academies Trust Code of Conduct for Staff Date Adopted: 4 th June 2015 Date Reviewed:.v 1 Final Page 1 History of most recent Policy changes (must be completed) Date Page Change Origin

More information

WHISTLEBLOWING POLICY FOR STAFF

WHISTLEBLOWING POLICY FOR STAFF WHISTLEBLOWING POLICY FOR STAFF 2016-2017 Purpose & overview The school is committed to maintaining a culture of openness, accountability and integrity. We seek to ensure that employees feel secure in

More information

Sprowston Community High School. Whistleblowing Policy

Sprowston Community High School. Whistleblowing Policy Sprowston Community High School Whistleblowing Policy From July 2017 to July 2018 Contents (Click on the headings below to jump to the relevant section) Model policy guidance [delete once adopted]... 2.

More information

Data Protection Policy

Data Protection Policy Preston and District Data Protection Policy The University of the Third Age Scope of the policy This policy applies to the work of Preston & District U3A (hereafter the U3A ). The policy sets out the requirements

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title: Data Protection Policy Ref:CP005 Version:2 Approval Body: Corporation via Audit & Risk Committee Date:24th March 2015 Review Date: 24th March 2018 Lead Person: Director, Institutional Effectiveness

More information

Greasbrough Primary School. Recruitment & Selection

Greasbrough Primary School. Recruitment & Selection Greasbrough Primary School Recruitment & Selection December 2016 INTRODUCTION The safe recruitment of staff in schools is the first step to safeguarding and promoting the welfare of children in education.

More information

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems LAST UPDATED June 11, 2018 DATA PROTECTION POLICY International Foundation for Electoral Systems 1. Purpose 1.1. International Foundation for Electoral Systems is committed to complying with privacy and

More information

UK Research and Innovation (UKRI) Data Protection Policy

UK Research and Innovation (UKRI) Data Protection Policy UK Research and Innovation (UKRI) Data Protection Policy Document Information Revision History Version Comment Date By 0.1 Draft Policy created July 2017 DH 0.2 Revision post review by information manager

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

SAFER RECRUITMENT & SELECTION POLICY

SAFER RECRUITMENT & SELECTION POLICY SAFER RECRUITMENT & SELECTION POLICY This policy refers to both Wellington Senior School and Wellington Prep School Headmaster Henry Price Author HR Manager Date Reviewed 09.06.2017 for implementation

More information

Regulates the way data controllers process personal data

Regulates the way data controllers process personal data GUIDANCE NOTE ON THE DATA PROTECTION ACT 1998 This guidance note gives an overview of how the Data Protection Act 1998 (the Act ) applies to clubs (including class associations) and recognised training

More information

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved Gwybodaeth Dan Reolaeth Gwynedd Council DATA PROTECTION POLICY FINAL 2.0 September 2015 Information Management Service 1. Introduction The Council makes considerable use of personal information in all

More information

FIRST NAME: TELEPHONE: POSTCODE: A social enterprise working with young people since 1859

FIRST NAME: TELEPHONE:   POSTCODE: A social enterprise working with young people since 1859 APPLICATION FORM FOR THE POST OF: JOB REFERENCE: As it may be necessary to photocopy this form, if you are completing it by hand please use BLOCK CAPITALS and black or blue ink. A curriculum vitae (CV)

More information

Project Title. Project Number. Privacy Impact Assessment

Project Title. Project Number. Privacy Impact Assessment Project Title Project Number Privacy Impact Assessment This document is classified as Official and is disclosable under the terms of the Freedom of Information Act. No part of the report should be disseminated

More information

The Futures Trust. Safer Recruitment Policy

The Futures Trust. Safer Recruitment Policy The Futures Trust Safer Recruitment Policy The Futures Trust is committed to safeguarding and promoting the welfare of children and young people and requires all staff to share this commitment Date of

More information

Policy for WHISTLEBLOWING. March (version 4) Page 1 of 12 Authors: Peter Ellmer and Mandy Smith

Policy for WHISTLEBLOWING. March (version 4) Page 1 of 12 Authors: Peter Ellmer and Mandy Smith Policy for WHISTLEBLOWING March 2015 23.2.09 (version 4) Page 1 of 12 Authors: Peter Ellmer and Mandy Smith SCHOOL POLICY FOR WHISTLEBLOWING School Aims: 1. All school staff, governors and parents work

More information

Applicants will receive a job description and person specification for the role applied for.

Applicants will receive a job description and person specification for the role applied for. Recruitment, selection and disclosure policy and procedure 1 Introduction The Bedford Charity (The Harpur Trust) is committed to providing the best possible care and education to its pupils and to safeguarding

More information

General Data Protection Regulation. The changes in data protection law and what this means for your church.

General Data Protection Regulation. The changes in data protection law and what this means for your church. General Data Protection Regulation The changes in data protection law and what this means for your church. 1 Contents Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 18 Page 20 Page 23

More information

Nottinghamshire School Disciplinary Procedure

Nottinghamshire School Disciplinary Procedure Nottinghamshire School Disciplinary Procedure Part 2 Managing Allegations of Child Abuse against School Staff April 2017 HR Advice, Support and Training Service 0 Part 2 School Disciplinary Procedure -Managing

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

5. Aims and Objectives To ensure that the safeguarding and welfare of young people who access TLG takes place at each stage of the process.

5. Aims and Objectives To ensure that the safeguarding and welfare of young people who access TLG takes place at each stage of the process. Selection and Recruitment of Staff (Written to comply with DfE statutory guidance Keeping children safe in education, September 2016 and the UK Boarder and Immigration Agency guidance - Prevention of illegal

More information

Data Protection Strategy Version 1.0

Data Protection Strategy Version 1.0 Data Protection Strategy Version 1.0 Contents 1. Introduction... 4 1.1. Purpose... 4 1.2. The OpenLV Project... 4 1.3. Definition of Personal Data... 6 1.4. The Data Controller... 6 1.5. Document Structure...

More information

If you have queries about this privacy notice or wish to exercise any of the rights mentioned in it please contact

If you have queries about this privacy notice or wish to exercise any of the rights mentioned in it please contact Privacy Notice Grace Personnel Ltd takes its Data Protection responsibilities seriously and we are committed to using the data we hold in accordance with the law. The following explains how and why we

More information

DISCIPLINARY POLICY AND PROCEDURE

DISCIPLINARY POLICY AND PROCEDURE DISCIPLINARY POLICY AND PROCEDURE This policy and procedure explains the process which management and Governors will follow in all cases of misconduct to ensure fairness and consistency of approach. General

More information

MS Society Disclosure policy and procedure - Scotland

MS Society Disclosure policy and procedure - Scotland MS Society Disclosure policy and procedure - Scotland Disclosure policy 1 Purpose and scope 1.1 The objectives of this policy and procedure are to ensure: the vulnerable groups who use our services and

More information

Whistleblowing Policy

Whistleblowing Policy Whistleblowing Policy Date of Issue: January 2017 Review date: January 2020 Approved by Management Committee Signature: Published by: School Business Manager Introduction This policy and procedure has

More information

closer look at Definitions The General Data Protection Regulation

closer look at Definitions The General Data Protection Regulation A closer look at Definitions The General Data Protection Regulation September 2017 V1 www.inforights.im Important This document is part of a series, produced purely for guidance, and does not constitute

More information

Whistle Blowing Policy

Whistle Blowing Policy Whistle Blowing Policy Introduction The Code is intended to help employees in or working with or assisting Schools in Lambeth who have major concerns over any wrong-doing within such Schools relating to

More information

LA School Governor Application Form

LA School Governor Application Form Personal details (please print) LA School Governor Application Form Title: First Name: Surname: Address and Postcode: Contact address (if different): E mail address: Daytime telephone: Evening telephone:

More information

Marketing Code of Conduct

Marketing Code of Conduct Marketing Code of Conduct Approved for the purposes of the Electricity Supply Act 1995 (NSW) and the Gas Supply Act 1996 (NSW) by the NSW Minister for Energy 1 January 2011 CONTENTS 1. FOREWORD... 1 1.1

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY 1. Introduction This policy sets out how The Robert Gordon University shall comply with the requirements of the Data Protection Act 1998 and was created with reference to the JISC

More information

Data Protection Policy

Data Protection Policy HOLY TRINITY CE (VA) PRIMARY SCHOOL Data Protection Policy Learning and caring together, building a firm foundation for the future. FOUNDED 1865 Date of Last Review: July 2015 Date to be Revisited: July

More information

WHISTLE BLOWING POLICY

WHISTLE BLOWING POLICY WHISTLE BLOWING POLICY Introduction The Tandridge Learning Trust is committed to the highest possible standards of honesty, openness, probity and accountability. It seeks to conduct its affairs in a responsible

More information

Syntel Human Resources Privacy Statement

Syntel Human Resources Privacy Statement Syntel Human Resources Privacy Statement August 24, 2016 Privacy Statement highlights: Syntel is committed to protecting your privacy. This Privacy Statement ("Statement") addresses prospective, current,

More information

Global Privacy Policy

Global Privacy Policy Global Privacy Policy Table of Contents Introduction... 2 Policy Overview Scope Application of Local Laws Definitions.... 3 Data Protection Principles... 4 Security and Access... 5 Special Circumstances....

More information

HCUC CORPORATION EQUALITY AND DIVERSITY POLICY

HCUC CORPORATION EQUALITY AND DIVERSITY POLICY HCUC CORPORATION EQUALITY AND DIVERSITY POLICY Subject: Equality and Diversity Origination Date: September 2002 Last approved: November 2015 Effective date: September 2017 Person responsible: Approved

More information

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients TECHNICAL RELEASE TECH 05/14BL Data Protection Handling information provided by clients ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over

More information

Code of Conduct: Obligation to Stakeholders

Code of Conduct: Obligation to Stakeholders Policy Owner: Contact Officers: Policy Number: Approved by: College Director/Principal Business Manager QBIPO009 Senior Management Group Date Approved: 22 October 2011 Last Reviewed: July 2016 Related

More information

EQUITAS ACADEMIES TRUST

EQUITAS ACADEMIES TRUST Equitas Academies Trust EQUITAS ACADEMIES TRUST RECRUITMENT AND SELECTION POLICY Review Date: December 2016 To be Reviewed: December 2017 Agreed: F & GP Board 1 Policy Lead: Teresa Burr RECRUITMENT AND

More information

Privacy Strategy, Principles & Policy - Version 1.0 Official Publish Date: 23rd May 2018

Privacy Strategy, Principles & Policy - Version 1.0 Official Publish Date: 23rd May 2018 Privacy Strategy, Principles & Policy - Version 1.0 Official Publish Date: 23rd May 2018 1 Contents 1 About This Document... 1 1.1 Introduction... 1 1.2 Aurora s Privacy Framework... 1 1.3 Scope and Application...

More information

DISCIPLINARY RULES FOR EMPLOYEES

DISCIPLINARY RULES FOR EMPLOYEES DISCIPLINARY RULES FOR EMPLOYEES DISCIPLINARY RULES FOR EMPLOYEES Page Introduction... 1 Gross misconduct... 2 Theft and dishonesty... 2 Failure to undertake the requirements of the job... 3 Breach of

More information

Whistle-blowing. Policy and Procedure

Whistle-blowing. Policy and Procedure Whistle-blowing Policy and Procedure This document will be made available in other languages and formats upon request from employees and students (or their parents/carers) Date of Issue: September 2014

More information

DRAGON SCHOOL SAFER RECRUITMENT POLICY. This policy applies to all sections of the school including the EYFS.

DRAGON SCHOOL SAFER RECRUITMENT POLICY. This policy applies to all sections of the school including the EYFS. ,\R.D U US AD Q SOLEM ~.\'Fov-. DRAGON SCHOOL SAFER RECRUITMENT POLICY For further information please contact: HR Manager Last Reviewed: April 2017 Introduction This policy applies to all sections of the

More information

Our Privacy Principles

Our Privacy Principles SAXON HALL/SOUTHEND MASONIC CENTRE - PRIVACY POLICY Our Privacy Principles We will look after any personal information you share with us. This is central to our values as a company. We want everyone to

More information

This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling Databases.

This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling Databases. The Data Protection Act 1998 & Market Research: Guidance for MRS Members September 2003 This has been produced as a response to the Data Protection Act 1998 and replaces the MRS Guidelines for Handling

More information

SIGBI DATA PROTECTION PROTOCOLS 2018

SIGBI DATA PROTECTION PROTOCOLS 2018 SIGBI DATA PROTECTION PROTOCOLS 2018 For the purpose of this document, references to Soroptimist International Great Britain and Ireland (SIGBI) Limited and Soroptimist International may be written as

More information

UK SCHOOL TRIPS PRIVACY POLICY

UK SCHOOL TRIPS PRIVACY POLICY UK SCHOOL TRIPS PRIVACY POLICY Introduction Welcome to the UK School Trips privacy notice. UK School Trips respects your privacy and is committed to protecting your personal data. This privacy notice will

More information

GDPR Privacy Notice for Staff

GDPR Privacy Notice for Staff GDPR Privacy Notice for Staff Data controller ( the Company ): All companies collectively known as The Lulworth Estate including: Lulworth Castle Farms; Lulworth Heritage Ltd; Lulworth Landscapes Ltd;

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?... Data Protection Guidance for Volunteers Last update 26/11/17 Contents Introduction... 2 1. Why is data protection important?... 2 2. How does it apply to volunteers?... 2 3. What volunteers need to do?...

More information

Thomson House School Freedom of Information Policy

Thomson House School Freedom of Information Policy Thomson House School Freedom of Information Policy Agreed by: Finance and General Purposes Committee Date: January 2017 Review Cycle: Annual Next Review Date: January 2018 1 Freedom of Information Act

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

It is our policy to provide employment equality to all, irrespective of:

It is our policy to provide employment equality to all, irrespective of: Revised: July 2012 The aim of this policy is to communicate the commitment of the Chief Executive, Board of Directors and Senior Management Team to the promotion of equality of opportunity in and by the

More information

The Data Protection Act NOMS Order. The Freedom of Information Act Environmental Information Regulations 2004 ORDER NUMBER 9020

The Data Protection Act NOMS Order. The Freedom of Information Act Environmental Information Regulations 2004 ORDER NUMBER 9020 NOMS Order The Data Protection Act 1998 The Freedom of Information Act 2000 Environmental Information Regulations 2004 ORDER NUMBER 9020 Date of Update: 29/05/09 Issue number: 313 Date of Initial Issue

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

Equality and Diversity Policy

Equality and Diversity Policy Equality and Diversity Policy Warwickshire First Aid Training is a progressive training organisation providing mandatory training to a range of organisations. We provide a range of First Aid, health and

More information

A Parish Guide to the General Data Protection Regulation (GDPR)

A Parish Guide to the General Data Protection Regulation (GDPR) A Parish Guide to the General Data Protection Regulation (GDPR) What s happening and why is it important? The law is changing. Currently, the Data Protection Act 1998 governs how you process personal data

More information

POSITION DESCRIPTION

POSITION DESCRIPTION POSITION DESCRIPTION 1. POSITION DETAILS Position Title: Location: Classification: Status: Reports to: Finance Officer - Fees and Payroll The Lakes College Support Staff Permanent Fulltime Business Manager

More information