This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects.

Similar documents
SHENLEY BROOK END SCHOOL

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Data Protection Policy

RAW MARKETING DATA PROTECTION POLICY

VMS Software Ltd- Data Protection Privacy Policy

DATA PROTECTION POLICY WINCHESTER CITY COUNCIL. Data Protection Policy

Data Protection Policy

The SENAD Group. Section 5 Data Protection Protocol

DATA PROTECTION POLICY 2016

POLICY ON INFORMATION, SECURITY & DATA PROTECTION

Data Protection Policy

General Optical Council. Data Protection Policy

Data Protection Policy

Privacy Notice for Clients of RISDON HOSEGOOD Solicitors

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

Data Protection Policy

DATA PROTECTION POLICY VERSION 1.0

DATA PROTECTION POLICY

Data protection (GDPR) policy

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Management and Protection Policy

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Tourettes Action Data Protection Policy

LEICESTER HIGH SCHOOL DATA PROTECTION POLICY

Security of Personal Data Policy and Guidelines

Data Protection Policy

Data Protection Policy & Procedures

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

General Data Protection Regulation. What should community energy organisations be doing to prepare?

DATA PROTECTION POLICY

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

Data Protection Policy

Data Protection Policy, including Key Procedures

Data Protection. Policy

Data Protection Policy.

CHANNING SCHOOL DATA PROTECTION POLICY

Data subject access policy

General Personal Data Protection Policy

Data Protection Policy for the Grimsby Institute of Further & Higher Education

Data Protection Policy

Brasenose College Data Protection Policy Statement v1.2

St Mark s Church of England Academy Data Protection Policy

BROOKS PERSONAL TRAINING

The Society of St Stephen s House Site Security and Monitoring Privacy Notice

Brasenose College is committed to protecting the privacy and security of personal data.

DATA PROTECTION POLICY

DATA PROTECTION POLICY

Global Privacy Policy

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

UK Research and Innovation (UKRI) Data Protection Policy

Data Protection Policy and Handbook. Scottish Information Commissioner

DATA PROTECTION POLICY

DATA PROTECTION POLICY 2018

Hendre Infants School DATA PROTECTION POLICY. Nurture, Believe, Achieve Headteacher: A. J. Brett-Harris

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions.

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

Nissa Consultancy Ltd Data Protection Policy

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

Parent / Carer Privacy Notice

DATA PROTECTION POLICY

GROUP DATA PROTECTION POLICY

This privacy notice applies to attendees, organisers and others involved in Merton College s conferences and events

Trinity is committed to protecting the privacy and security of personal data.

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

ScottishPower Data Protection Policy

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective:

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

DATA PROTECTION POLICY AND PROCEDURE

Data Protection Policy

Royal Irish Academy: Data Protection Policy, Procedures and Guidelines in relation to CCTV

Baptist Union of Scotland DATA PROTECTION POLICY

Data Protection Policy

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is:

Queen s Croft High School DATA PROTECTION POLICY AND PRIVACY NOTICE

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

POLICY. Data Breach Notification Policy. Version Version 1.0. Equality Impact Assessment Status. Date approved 23 rd May 2018

APPLICATION FORM SCAFFOLDING LTD POSITION APPLIED FOR PERSONAL DETAILS NEXT OF KIN DRIVING LICENCE DETAILS YES YES. T Offence code. Date.

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Data Protection Policy

PRIVACY NOTICE for Welsh St Donat s Community Council, May 2018

DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

DATA PROTECTION POLICY

Data Protection Strategy Version 1.0

DATA PROTECTION POLICY

Orbit Recruitment Privacy Policy

Data Protection Policy

Data Protection/ Information Security Policy

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

The template uses the terms students / pupils to refer to the children or young people at the institution.

St Michael s CE Primary School Data Protection Policy

Data Protection Policy. UK Policy May 2018

PRIVACY NOTICE FOR JOB APPLICANTS

Sample Data Management Policy Structure

GENERAL DATA PROTECTION REGULATION.

THE HEATH ACADEMY TRUST DATA PROTECTION POLICY

Transcription:

BELFAST ROYAL ACADEMY Data Protection Policy Introduction Belfast Royal Academy recognises and accepts its responsibilities as set out in the Data Protection Act 1998. The School will take all reasonable steps to meet these responsibilities and to promote good practice in the handling and use of personal information. This policy statement applies to all School governors and employees and individuals about whom the School holds and uses personal information, as well as other partners and companies with which the School undertakes business. Scope The School needs to collect and use certain types of information about people to pursue its legitimate interests and activities, to protect the vital interests of the data subjects (employees, pupils, suppliers and others with whom the School does business) and to comply with legislative requirements relative to processing of data for employment purposes. These types of information include details of current, past and prospective employees, pupils, suppliers, clients and others with whom the School communicates. In addition, the School may be required by law to collect and use certain types of information to comply with the requirements of government departments. This personal information must be dealt with properly, with appropriate safeguards in place to ensure the rights and freedoms of data subjects. The School wishes to ensure that it treats personal information lawfully and correctly and to this end, the Board of Governors endorses the obligations of the Act and seeks to adhere to the Principles of Data Protection contained therein. The following section outlines the main provisions and principles contained within the Act, with which the Board of Governors and staff members are required to comply.

1. Main Provisions of the 1998 Legislation a. The School as a Data Controller must register with the Information Commissioner, who maintains a public register of the type of information processed by organisations, where it is obtained from and the purposes for which it is used. b. There is a requirement to observe the eight Data Protection Principles as outlined below. c. A data subject can have right of access to personal information held, how it is processed and to whom it is disclosed. Any request for access to this information must be complied with within 40 days from the date of request and the maximum fee chargeable for the provision of this information is 10. 2. Main Terminology within the Act Data Controller Any individual or organisation which controls personal data; in this instance the school. Personal Data Information held on a relevant filing system, accessible record or computerised record (as well as digital, audio or video equipment) which identifies living individuals. Sensitive personal Data Personal data relating to an individual s race or ethnic origin, political opinions, religious beliefs, physical/mental health, trade union membership, criminal activities. Relevant filing system A set of records which is organised by reference to the individual and is structured to make information readily accessible e.g. personnel records. Data subject An individual who is the subject of the personal data for example an employee, pupil etc. Processing This includes recording or holding data, organising, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, blocking, erasing or destroying of data.

3. Data Protection Principles There are eight main principles within the Act. Specifically, the Principles require that personal data: 1. shall be processed fairly and lawfully and shall not be processed unless specific conditions are met; 2. shall be obtained only for one or more specified and lawful purposes and shall not be processed in any manner incompatible with that purpose or those purposes; 3. shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed; 4. shall be accurate and where necessary, kept up to date; 5. shall not be kept for longer than is necessary for that purpose or those purposes; 6. shall be processed in accordance with the rights of the data subject under the Act; and that: 7. appropriate technical or organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss, destruction or damage to personal data; 8. personal data shall not be transferred to a country or territory outside the European Economic Area unless that country ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of their personal data. 4. Application to the School The School will seek through appropriate management and application of criteria and controls to: observe conditions relative to the fair collection and use of information;

meet its legal obligations to specify the purposes for which information is used; collect and process appropriate information and only to the extent that it is needed to fulfil operational needs or to comply with legal requirements; ensure the quality of the information used, including its accuracy and relevance for the purpose specified; ensure that the rights of people about whom information is held can be exercised under the Act (including the right to be informed that processing is being undertaken, the right of access to personal information, the right to prevent processing in certain circumstances, the right to correct, block or erase information which is regarded as erroneous); adopt measures to safeguard personal information; ensure that personal information is not transferred abroad without suitable safeguards. In addition, the School will take steps to seek to ensure that: there is someone within the organisation with responsibility for data protection (currently the Bursar/Finance Supervisor in conjunction with the Vice Principal with responsibility for the Class System and processing of pupil records); everyone managing and handling information within the School understands that they are contractually responsible for following good data protection practice; everyone managing and handling personal information is appropriately trained to do so; everyone managing and handling personal information is appropriately supervised; anyone making enquiries about handling personal information knows what to do;

queries about handling personal information are promptly dealt with; a review is made of the way personal information is managed; methods of handling personal information are assessed and evaluated; information is disseminated on good practice in respect of handling, using and storing personal information. A copy of this policy will be issued to all employees. It will be reviewed as required in accordance with legislative changes or guidance issued by the Department of Education. As a result it may be modified from time to time and supplemented in appropriate cases by further statements and procedures. Authorised by --------------------------------------- Date --------------------------------------- Authorised by --------------------------------------- (Warden of the Board of Governors) Date --------------------------------------- Reviewed Dec 13