Clavering Primary School

DATA PROTECTION POLICY AND PROCEDURES

Data Protection Policy

General rules in complying with Data Protection law

Policy points are numbered. The numbering corresponds to explanations of ‘why?’ and ‘how?’ for each point further down the page.

What must I do?

 

  1. MUST: All employees must comply with the requirements of Data Protection Law and Article 8 of the Human Rights Act when processing the personal data of living individuals
  2. MUST: Where personal data is used we must make sure that the data subjects have access to a complete and current Privacy Notice.
  3. MUST: We must formally assess the risk to privacy rights introduced by any new (or change to an existing) system or process which involves the use of personal data
  4. MUST: We must process only the minimum amount of personal data necessary to deliver services.
  5. MUST: All employees who record opinions or intentions about service users must do so carefully and professionally
  6. MUST: We must take reasonable steps to ensure the personal data we hold is accurate, up to date and not misleading.
  7. MUST: We must rely on consent as a condition for processing personal data only if there is no relevant legal power or other condition
  8. MUST: Consent must be obtained if personal data is to be used for promoting or marketing goods and services.
  9. MUST: Consent will expire at the end of each ‘Key Stage’ period unless it is reconfirmed.
  10. MUST: We must ensure that the personal data we process is reviewed and destroyed when it is no longer necessary.
  11. MUST: If we receive a request from a member of the public or colleagues asking to access their personal data, we must handle it as a Subject Access Request under the Data Protection Act 2018 or a request for the Education Record under the Education (Pupil Information) (England) Regulations 2005
  12. MUST: If we receive a request from anyone asking to access the personal data of someone other than themselves, we must fully consider Data Protection law before disclosing it
  13. MUST: When someone contacts us requesting we change the way we are processing their personal data, we must consider their rights under Data Protection law.
  14. MUST NOT: You must not access personal data which you have no right to view
  15. MUST: You must follow system user guidance or other formal processes which are in place to ensure that only those with a business need to access personal data are able to do so
  16. MUST: You must share personal data with external bodies who request it only if there is a current agreement in place to do so or it is approved by the Data Protection Officer or SIRO.
  17. MUST: Where the content of telephone calls, emails, internet activity and video images of employees and the public is recorded, monitored and disclosed this must be done in compliance with the law and the regulator’s Code of Practice.
  18. MUST: All employees must be trained to an appropriate level, based on their roles and responsibilities, to be able to handle personal data securely.
  19. MUST: When using ‘data matching’ techniques, this must only be done for specific purposes in line with formal codes of practice, informing service users of the details, their legal rights and getting their consent where appropriate.
  20. MUST: We must maintain an up to date entry in the Public Register of Data Controllers
  21. MUST: Where personal data needs to be anonymised or pseudonymised, for example for research purposes, we must follow the relevant procedure
  22. MUST NOT: You must not share any personal data held by us with an individual or organisation based in any country outside of the United Kingdom without seeking advice from the SIRO or Data Protection Officer
  23. MUST: We must identify Special Categories of personal data and make sure it is handled with appropriate security and only accessible to authorised persons
  24. MUST: When sending Special Category data to an external person or organisation, it should be marked as “OFFICIAL-SENSITIVE” and where possible, sent by a secure method
Why must I do it?

 

  1. To comply with legislation
  2. To comply with Data Protection legislation which requires us to make the data subject aware of how we will handle their personal data
  3. To ensure that the rights of the Data Subject are protected in any proposed new activity or change to an existing one
  4. The law states that we must only process the minimum amount of information needed to carry out our business purpose. It is not acceptable to hold information on the basis that it might possibly be useful in the future without a view of how it will be used.   Changes in circumstances or failure to keep the information up to date may mean that information that was originally adequate becomes inadequate.
  5. To maintain professional standards and to assist in defending the validity of such comments if the data subject exercises their rights to ask us to amend or delete their personal data if they feel it to be inaccurate.
  6. To comply with a principle of Data Protection law
  7. To comply with Data Protection law. Where processing does not rely on a legal condition other than consent
  8. When using personal data for marketing and promoting services it is unlikely that any lawful condition other than consent would apply.
  9. Consent can only be valid for a reasonable period of time.
  10. To comply with a principle of Data Protection law.
  11. To comply with the right to access personal data
  12. To comply with a principle of Data Protection law.
  13. To comply with the rights of the Data Subject under Data Protection law
  14. Personal data must be protected by effective security controls to ensure that only those with approved business need to access the data can do so
  15. Personal data must be protected by effective security controls to ensure that only those with approved business need to access the data can do so
  16. To comply with the legal requirements to keep personal secure but also to ensure that where there are legal grounds to share information in a managed way that this is done correctly.
  17. The law permits organisations to hold such data in order to measure the quality of services being provided, to record consent etc. In certain circumstances recordings may be accessed e.g. to investigate alleged criminal activity or breaches of Organisation policy etc.
  18. To comply with a principle in Data Protection law and the Data Protection Officer governance requirements
  19. To comply with the Data Subject’s rights
  20. This is a regulatory requirement and allows the public to see what personal information we hold to support transparency
  21. Where personal data is used for research purposes, the processing of the data can be legitimised by provisions within Data Protection law
  22. To comply with the right of the Data Subject to have equivalent legal safeguards in place over their data in another country as they would here. Personal data transferred overseas (including hosted solutions) must be securely handled under the same or substantially similar provisions that exist under the Data Protection Act.
  23. To comply with Article 9 of GDPR
  24. To comply with Article 9 of GDPR and comply with a principle of Data Protection law requiring personal data is processed with appropriate security measure.
How must I do it?

 

  1. By following the points in this policy
  2. By approving and reviewing a compliant privacy notice in line with the Privacy Notice Procedure and making it available to the data subjects
  3. By completing and approving a Privacy Impact Assessment, or Data Protection Impact Assessment where the processing is ‘high risk’ to the rights of the data subjects.
  4. By ensuring that the means we use to gather personal data (such as forms etc.) only ask for the information that is required in order to deliver the service.
  5. By considering that anything committed to record about an individual may be accessible by that individual in the future or challenged over its accuracy.
  6. For example, there should be at least an annual check of the currency of data held about service users and whenever contact is re-established with a service user, you should check that the information you hold about them is still correct.
  7. By following the points in the Consent Procedure
  8. By following the points in the Consent Procedure
  9. By following the points in the Consent Procedure. Parents/ Guardians of pupils in the last year of a key stage should expect a communication to ask them to refresh their consents. If they do not respond ahead of a deadline date then consent should be assumed to be no longer valid.
  10. By following the points in the Records Management Policy. We must review personal data regularly and delete information which is no longer required; although we must take account of statutory and recommended minimum retention periods. Subject to certain conditions, the law allows us to keep indefinitely personal data processed only for historical, statistical or research purposes. The Retention Schedule will give guidance in these areas.
  11. By following the points in the Statutory Requests for Information Policy. We must be aware that data subjects can ask others to make a request on their behalf. There must be evidence of consent provided by the Data Subject to support this.
  12. By following the points in the Statutory Requests for Information Policy. Such requests would typically be managed under the Freedom of Information Act (if from a member of the public) or under Data Protection or Justice law if for a criminal investigation, however the decision whether or not to disclose someone’s personal data to a third party must satisfy the requirements of Data Protection law
  13. By reviewing the impact of any requested change on any statutory duty being fulfilled by the Organisation.
  14. By being aware through training and guidance from your manager on what information is appropriate for you to access to do your job. Systems and other data storage must be designed to protect access to personal data. You must inform your manager if you have access to data which you suspect you are not entitled to view.
  15. By ensuring appropriate security controls are in place and rules to support those controls are followed. The following should be in place:
  • technical methods, such as encryption, password protection of systems, restricting access to network folders;
  • physical measures, such as locking cabinets, keeping equipment like laptops out of sight, ensuring buildings are physically secure; and
  • organisational measures, such as:
    • Providing appropriate induction and training so that staff know what is expected of them
    • Taking reasonable steps to ensure the reliability of staff that access personal data, for example, by the use of Disclosure and Barring Service (DBS) checks.
    • Making sure that passwords are kept secure, forced to be changed after an agreed period and are never shared
  1. Consult your manager, any procedure guidance or any library of sharing agreements managed by the Organisation. Consult the Data Protection Officer or SIRO in one-off cases of sharing.
  2. By ensuring that employees and members of the public are fully aware of what personal data is being recorded about them and why, and it what circumstances that data may be used. Operation of overt surveillance equipment such as CCTV must always be done in line with relevant codes of practice captured in the Surveillance Management Procedure. Any covert surveillance must be done in line with the provisions in the Investigatory Powers Act (2016)
  3. By completing compulsory training courses relevant to your role. Records will be kept of induction training and annual refresher training. Training content for each role will be determined by feedback on current training methods and the outcome of investigating security incidents. This will be reviewed frequently.
  4. By ensuring an Impact Assessment has been approved for the activity
  5. The entry should be reviewed annually and an update is to be made when any change to the purposes of processing personal data occur
  6. Follow the guidance in the Data Minimisation Procedure
  7. Consult the Data Protection Officer over any proposed sharing outside of the UK. If you are a manager who is proposing a change to or implementing a new system which may involve the hosting of personal data in a nation outside the UK, this must be first assessed by a Privacy Impact Assessment, which must be approved by your SIRO and Data Protection Officer
  8. Special Categories of Personal Data are information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data for the purpose of uniquely identifying an individual, data concerning health or data concerning an individual’s sex life or sexual orientation. Where this data is held it should be stored securely and in a way that access is restricted only to those internal staff that have a valid need to access it. It should only be shared externally after verifying that the recipient is entitled to access this data and through secure means.
  9. Hard-copy packages must be marked as such by writing on the exterior of the package. Emails should contain the wording in the ‘subject’ field before the email title. Refer to the Records of Processing Activity document and the register of Data Flows for clear instruction on how you are expected to handle sending the data securely according to the particular activity you are undertaking.
What if I need to do something against the policy?

 

If you believe you have a valid business reason for an exception to these policy points, having read and understood the reasons why they are in place, please raise a formal request by contacting the school office.

Document Control

 

Version:                     4

Date approved:         July 2019

Approved by:             FGB

Next review:              July 2020

References

 

  • Data Protection Act 2018 (including the General Data Protection Regulation 2016
  • Article 8, The Human Rights Act 1998
  • Education (Pupil Information) (England) Regulations 2005
  • Investigatory Powers Act 2016
Breach Statement

 

Breaches of Information Policies will be investigated and may result in disciplinary action. Serious breaches of Policy may be considered gross misconduct and result in dismissal without notice, or legal action being taken against you.

 

PRIVACY NOTICES

Clavering Primary School respects you and your child’s privacy and are committed complying with privacy legislation.

The information below is what is referred to as a ‘Privacy Notice’ which explains how we use and protect your personal information.

We have a Data Protection Officer whose role it is to ensure that any personal information processed by the school is processed fairly and lawfully. If you have any concerns or questions regarding how we look after your personal information, please contact the Data Protection Officer, Lauri Almond, at or by calling 0333 032 2970.

  1. What is Personal Information?

Personal information is often records that can identify and relate to a living person. This can also include information that when put together with other information can then identify a person. for example online identifiers or location data.

  1. What are Special Categories of Information?

This is personal information that needs more protection due to its sensitivity. This information is likely to include:

  • sexuality and sexual health
  • religious or philosophical beliefs
  • ethnicity
  • physical or mental health
  • trade union membership
  • political opinion
  • genetic/biometric information
  1. How we limit the use of personal information

We use personal information to deliver education effectively; but wherever possible, the information that we process will be anonymised, pseudonymised or de-personalised. This means the information can no longer identify a person.

When using personal information for research purposes, the information will be anonymised/ pseudonymised to avoid the identification of a person, unless you have agreed that your personal information can be used for the research project.

We do not sell personal information to any other school for the purposes of selling products.

  1. Why we use personal information

We use personal information to help us run the school effectively, deliver a quality education, and safeguard pupils and staff. Please see our service specific notices which explains how we use personal information for each of our activities.

  1. Your privacy rights

The law provides you with a number of rights to control the processing of your personal information:

Accessing the information we hold about you

You have the right to ask for all the information we have about you. When we receive a request from you in writing, we must normally give you access to everything we have recorded about you. However, we will not let you see any parts of your record which contain:

  • Confidential information about other people; or
  • Information a professional thinks will cause serious harm to your or someone else’s physical or mental wellbeing; or
  • If we think that the prevention or detection of crime may be adversely affected by disclosing information to you.

This applies to paper and electronic records. If you ask us, we will also let others see your record (except if one of the points above applies).  If you cannot ask for your records in writing, we will make sure there are other ways you can apply. If you have any queries regarding access to your information please contact or 01799 550300

Changing information you believe to be inaccurate

You should let us know if you disagree with something written on your file. We may not always be able to change or remove the information; however, we will correct factual inaccuracies and may include your comments in the records.  Please use the contact details above to report inaccurate information.

Asking for your information to be deleted (right to be forgotten)

In some circumstances you can request the erasure of the personal information used by us, for example:

  • Where the personal information is no longer needed for the purpose for which it was collected
  • Where you have withdrawn your consent to the use of your information and there is no other legal basis for the processing
  • Where there is no legal basis for the use of your information
  • Where erasure is a legal obligation

Where personal information has been shared with others, we shall make every reasonable effort to ensure those using your personal information comply with your request for erasure.

Please note that the right to erasure does not extend to using your personal information where:

  • Is required by law
  • It is used for exercising the right of freedom of expression
  • It is in the public interest in the area of public health
  • It is for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes where it would seriously affect the achievement of the objectives of the processing
  • It is necessary for the establishment, defense or exercise of legal claims.

Restricting what your information is used for

You have the right to ask us to restrict what we use your personal information for where one of the following applies:

  • You have identified inaccurate information, and have notified us of this
  • Where using your information is unlawful, and you wish us to restrict rather than erase the information
  • Where you have objected to us using the information, and the legal reason for us using your information has not yet been provided to you

When information is restricted it cannot be used other than to securely store the information, and with your consent, to handle legal claims, protect others, or where it is for important public interests of the UK. Where restriction of use has been granted, we will inform you before the use of your personal information is resumed.

You have the right to request that we stop using your personal information in some circumstances, for example where we are relying on your consent. However we are required by law to use personal information to deliver education services so for those purposes we could not grant your request.

Computer based decisions about you and if you are ‘profiled’

You have the right to object about decisions being made about you by automated means (by a computer and not a human being), unless it is required for any contract you have entered into, required by law, or you have consented to it. You also have the right to object if you are being ‘profiled’. Profiling is where decisions are made about you based on certain things in your personal information.

If you have concerns regarding automated decision making, or profiling, please contact the school who will advise you about how your information is being used.

  1. Who will we share your personal information with?

As explained in our service specific notices we use a range of companies and partners to either store personal information or to manage it for us. Where we have these arrangements there is always a contract, memorandum of understanding or information sharing protocol in place to ensure that the school complies with information protection law. We complete privacy impact assessments before we share personal information to ensure their compliance with the law.

Sometimes we have a legal duty to provide information about people to other schools, e.g. Child Protection concerns or statutory returns to the Department for Education, for example the school census.

We may also share your personal information when we feel there is a good reason that is more important than protecting your confidentiality. This does not happen often, but we may share your information:

  • To find and stop crime or fraud; or
  • if there are serious risks to the public, our staff or to other professionals; or
  • to protect a child.

The law does not allow us to share your information without your permission, unless there is proof that someone is at risk or it is required by law. This risk must be serious before we can go against your right to confidentiality.  When we are worried about physical safety or we feel that we need to take action to protect someone from being harmed in other ways, we will discuss this with you and, if possible, get your permission to tell others about your situation.  We may still share your information if we believe the risk to others is serious enough to do so.

There may also be rare occasions when the risk to others is so great that we need to share information straight away. If this is the case, we will make sure that we record what information we share and our reasons for doing so. We will let you know what we have done and why as soon as or if we think it is safe to do so.

We are required by law to share certain information with the Department for Education; for more details on how they use personal information please click here

We are also required to share some information with Essex County Council; for more details on how they use personal information please click here

If you live or attend school in Southend Borough Council area you will find their privacy notice here

If you live or attend school in the Thurrock Council area you will find their privacy notice here

  1. How do we protect your information?

We will do what we can to make sure we hold personal records (on paper and electronically) in a secure way, and we will only make them available to those who have a right to see them.  Our security measures include:

  • Encryption allows information to be hidden so that it cannot be read without special knowledge (such as a password). This is done with a secret code or cypher. The hidden information is said to be encrypted.
  • Controlling access to systems, networks and buildings allows us to stop people who are not allowed to view your personal information from getting access to it.
  • Training for our staff allows us to make them aware of how to handle information and how and when to report when something goes wrong.
  • Ways for us to access your information should something go wrong and our systems not work, including how we manage your information in event of an emergency or disaster.
  • Regular testing of our technology and processes including keeping up to date on the latest security updates (commonly called patches).

If your information leaves the country

Sometimes, for example where we receive a request to transfer school records to a new school, it is necessary to send that information outside of the UK. In such circumstances additional protection will be applied to that information during its transfer, and where the receiving country does not have an adequacy decision, advice will be sought from the Information Commissioners Office prior to the information being sent.

  1. How long do we keep your personal information?

Our retention schedule lists how long your information may be kept for different purposes. A copy of our retention schedule can be requested from our school office.

  1. Where can I get advice?

You can contact our Data Protection Officer at or by calling 0333 032 2970.

For independent advice about information protection, privacy and information sharing issues, you can contact the Information Commissioner’s Office (ICO) at:

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire SK9 5AF

Tel: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate number

Alternatively, visit ico.org.uk or email .

10. Cookies & how you use this website

To make this website easier to use, we sometimes place small text files on your device (for example your iPad or laptop). These are known as ‘cookies’. Most big websites do this too.

They improve things by:

  • remembering the things you’ve chosen, so you don’t have to keep re-entering them whenever you visit a new page
  • remembering information you’ve given (for example, your address) so you don’t need to keep entering it
  • measuring how you use the website so we can make sure it meets your needs.

By using our website, you agree that we can place these types of cookies on your device.

We do not use cookies on this website that collect information about what other websites you visit (often referred to as privacy intrusive cookies).

Our cookies aren’t used to identify you personally. They’re just here to make the site work better for you. Indeed, you can manage and/or delete these files as you wish.

To learn more about cookies and how to manage them, visit AboutCookies.org or watch a video about cookies.

Other people’s cookies

We sometimes use videos from YouTube and feeds from other websites such as Facebook and Twitter. These websites place cookies on your device when watching or viewing these pages.

Below are links to their cookie policies:

  • Google and YouTube
  • Facebook
  • Twitter

Turning off cookies

You can stop cookies being downloaded on to your computer or other device by selecting the appropriate settings on your browser. If you do this, however, you may not be able to use the full functionality of this website.

There is more information about how to delete or stop using cookies on AboutCookies.org. If you wish, you can also opt out of being tracked by Google Analytics.

Further guidance on the use of personal information can be found at ico.org.uk

Further Privacy Notices

Privacy notice – processing under consent (excluding use of photo and video)

Privacy notice – processing of photo and video

Privacy Notice – statutory processing of pupil and parent data

Privacy Notice – Volunteers

Privacy Notice – Governors Services

Privacy Notice – Employment Records for school staff

Privacy notice – processing of online payments

Data Protection Policy Statement

20181012 – Data Protection Policy Statement

STATUTORY REQUESTS

Statutory Requests

ADVICE TO PARENTS/GUARDIANS

11B. GDPR Rights – Advice to Parents-Guardians