RISE SPACE Data Protection Policy

Devised: 07/09/21
Agreed: 08/09/21
Review: 01/09/26

Amendments

Version 1 — Pg 2 / Pg 8 / Throughout — Addition of types of personal data in a college. Inclusion of Special Category Data. Change of branding. — Approved: KM

Version 2 — Pg 3 — Addition of 3 categories to the legal bases for processing data. — Approved: KM

Version 2 — Pg 5 — Addition of the role and responsibility of Trustees and all staff in data protection. — Approved: KM

1. Scope of the Policy

Personal information is any information that relates to a living individual who can be identified from the information. This includes any expression of opinion about an individual and intentions towards an individual. It also applies to personal data held visually in photographs or video clips (including CCTV) or as sound recordings.

RISE SPACE collects a large amount of personal data every year including:

  • staff records
  • names and addresses of those requesting prospectuses
  • examination marks
  • references
  • fee collection
  • research data used by the provision

In addition, it may be required by law to collect and use certain types of information to comply with statutory obligations of Local Authorities (LAs), government agencies and other bodies.

This policy applies to:

  • students
  • staff
  • visitors
  • parents/carers
  • governing body
  • volunteers

RISE SPACE is committed to the protection of all personal and sensitive data for which it holds responsibility as the Data Controller, handling such data in line with the data protection principles and the Data Protection Act (DPA).

Changes to data protection legislation, including General Data Protection Regulations (GDPR), will be monitored and implemented to remain compliant.

Legal Bases for Processing Data

The legal bases for processing data are:

  • Consent
  • Contract
  • Legal obligation
  • Vital interests
  • Public interest
  • Legitimate interests

The requirements of this policy are mandatory for all staff employed by the provision and any third party contracted to provide services within the provision.

2. The Eight Principles

Under GDPR, there are eight data protection principles, or rules for good information handling, all of which will be implemented by RISE SPACE.

2.1

Data will be processed fairly and lawfully with transparency.

2.2

Personal data shall be obtained only for one or more specific and lawful purposes.

Examples of personal data in a college include:

  • identity details
  • contact details
  • attendance information
  • assessment and exam results
  • recruitment information
  • staff contracts
  • references

2.3

Personal data shall be adequate, relevant and not excessive.

2.4

Personal data shall be accurate and kept up to date.

2.5

Personal data shall not be kept for longer than necessary.

2.6

Personal data shall be processed in accordance with the rights of data subjects and protected against unauthorised access, loss or destruction.

2.7

Appropriate technical and organisational measures shall be taken against unlawful processing and accidental loss or damage.

2.8

Personal data shall not be transferred outside the EEA unless adequate protection exists.

3. Roles and Responsibilities

3.1 The Provision Will:

  • manage and process personal data properly
  • protect individual privacy rights
  • provide individuals access to their personal data upon request

3.2 Data Controller

Keighly Murphy is the Data Controller and holds responsibility for personal information.

All staff:

  • will treat information confidentially
  • undertake GDPR training
  • follow internal monitoring procedures

Any external Data Processors must confirm GDPR compliance and ICO registration.

ICO guidance can be found here:
https://ico.org.uk

4. Personal and Sensitive Data

All data within the provision’s control shall be identified as personal, sensitive or both to ensure compliance with legal requirements.

Consent

The provision will ask for consent where there is no lawful basis for processing information.

Lawful bases include:

  1. Contract
  2. Legal Obligation
  3. Vital Interests
  4. Public Task
  5. Legitimate Interests

Data Breaches

All data breaches must be immediately reported to the Data Controller.

The Data Controller will:

  • assess whether the breach must be reported to the ICO
  • review how the breach occurred
  • implement preventative changes

Individual Rights

Individuals have the right to:

  • be informed about data being held
  • access their data
  • request erasure
  • restrict processing
  • data portability
  • object to processing
  • avoid automated decision-making

Sharing Information with Third Parties

RISE SPACE may share data where legally required or in the best interests of students or staff.

Examples include:

  • other educational provisions
  • examination bodies
  • Department for Education
  • Ofsted
  • social workers
  • health authorities
  • police and courts

Any shared data will be password protected where appropriate.

Special Category Data

Special category data includes:

  • racial or ethnic origin
  • political opinions
  • religious beliefs
  • trade union membership
  • genetic information
  • biometric information
  • health information
  • sexual orientation

Subject Access Requests

Individuals have the legal right to request access to their data.

Requests:

  • must be made in writing
  • will be responded to within one month
  • are free of charge

Right to be Forgotten

Individuals may request that personal data is erased where no longer required.

Photographs and Video

Images of staff and students may be used for educational activities.

External publication requires prior consent.

Location of Information and Data

RISE SPACE aims to reduce paperwork and securely store information electronically where possible.

Hard copy records are stored securely.

Sensitive information must not be left unattended or transported insecurely.

Data Security

RISE SPACE undertakes risk assessments relating to personal data and implements appropriate security measures.

Data Disposal

All redundant data will be securely destroyed in compliance with ICO guidance.

IT assets will be professionally cleaned prior to disposal.

Abbreviations

  • GDPR – General Data Protection Regulations
  • ICO – Information Commissioner’s Office
  • DPO – Data Protection Officer

CONTACT US