Educla Ltd

Data Protection Policy

2025

REVIEW SHEET

Version NumberVersion DescriptionDate of Revision
1OriginalJanuary 2017
Updates have been made annually, but no detailed breakdown is evident. From April 2024 updates will be completed annually in September of each year, or sooner when changes are made to relevant government legislation. Update details will be outlined in the version description section,
2Wording changed from school or school premises to EduclaAddition of sending out annual update formsUpdated policies and information in 11.4June 2024
3Adding awareness of use of AI chatbotsLinks updated and changedJuly 2025

Overview

This policy is in place to ensure all staff are aware of their responsibilities and outlines how Educla complies with the following core principles of the GDPR with regard to current law and guidance.

Educla Ltd is required to keep and process certain information about its staff members and children or young people in accordance with its legal obligations under the GDPR.

Educla may, from time to time, be required to share personal information about its staff, children or young people with other organisations, mainly the LA, other schools and educational bodies, and potentially children’s services.

Organisational methods for keeping data secure are imperative, and Educla believes that it is good practice to keep clear practical policies, backed up by written procedures.

‘Educla Ltd believes that a child or young person should never experience abuse of any kind. We have a responsibility to promote the welfare of all children and young people and to keep them safe. We are committed to practice in a way that protects them.’ 

Contents

1.      Rationale                                                                                                                                                                          1

2.      Associated School Policies                                                                                                                                         1

3.      Compliance                                                                                                                                                                     1

4.      The Data Protection Act, 1998                                                                                                                                 1

5.      Responsibilities Under the DPA and Registration                                                                                             2

6.      Definitions                                                                                                                                                                       2

7.      Data Protection Principles                                                                                                                                         2

7.1         Process personal data fairly and lawfully……………………………………………………………. 2

7.2         Process the data for the specific and lawful purpose for which it collected that data, and not further process the data in a manner incompatible with this purpose………………………………………….. 2

7.3         Ensure that the data is adequate, relevant and not excessive in relation to the purpose for which it is processed…………………………………………………………………………………………………………….. 3

7.4         Keep personal data accurate and, where necessary, up to date………………………………. 3

7.5         Only keep personal data for as long as is necessary……………………………………………… 3

7.6         Process personal data in accordance with the rights of the data subject under the legislation 3

7.7         Put appropriate technical and organisational measures in place against unauthorised or unlawful processing of personal data, and against accidental loss or destruction of data……………………. 3

7.8         Ensure that no personal data is transferred to a country or a territory outside the European Economic Area unless that country or territory ensures adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data……………………………………………………. 4

8.      Consent as a Basis for Processing                                                                                                                           4

8.1         Fair Processing…………………………………………………………………………………………….. 4

9.      Subject Access Rights (SARS)                                                                                                                                    4

9.1         Processing Subject Access Requests………………………………………………………………….. 5

10.   Authorised Disclosures                                                                                                                                               5

10.1      Legal Disclosure……………………………………………………………………………………………. 5

10.2      Illegal Disclosure…………………………………………………………………………………………… 5

11.   Publication of Educlas Information                                                                                                                        6

11.1      Email…………………………………………………………………………………………………………. 6

11.2      CCTV………………………………………………………………………………………………………….. 6

11.3      Images/Photographs……………………………………………………………………………………… 6

12.   Data Integrity                                                                                                                                                                 6

12.1      Data Accuracy……………………………………………………………………………………………… 6

12.2      Data Adequacy and Relevance…………………………………………………………………………. 6

12.3      Length of Time…………………………………………………………………………………………….. 7

13.   Identification of Data                                                                                                                                                   7

14.   Data and Computer Security                                                                                                                                    8

14.1      Physical Security…………………………………………………………………………………………… 8

14.2      Logical Security…………………………………………………………………………………………….. 8

14.3      Procedural Security……………………………………………………………………………………….. 8

15.   Secure transfer of data and access out of school                                                                                              8

16.   Disposal of Data                                                                                                                                                            9

17.   Training & Awareness                                                                                                                                                 9

18.   Enquiries                                                                                                                                                                          9

Appendix A       –      Access to Personal Data Request

Appendix B       –      Privacy Notice – School Workforce

Appendix C       –      Privacy Notice – Pupils in Schools, Alternative Provision and

                                    Pupil Referral Units and Children in Early Years Settings

1.     Rationale

Educla Ltd (hereinafter referred to as ‘the school’) is committed to a policy of protecting the rights and privacy of individuals, including students, staff and others, in accordance with the Data Protection Act, 1998 (DPA).

The School needs to process certain information about its staff, students and other individuals with whom it has a relationship for various purposes such as, but not limited to:

  • the recruitment and payment of staff
  • the administration of programmes of study
  • the recording of a student’s progress
  • agreeing awards
  • collecting fees
  • complying with legal obligations to funding bodies and government

To comply with various legal obligations, including the obligations imposed on it by the Data Protection Act, 1998, the School must ensure that all this information about individuals is collected and used fairly, stored safely and securely, and not disclosed to any third party unlawfully.

2.     Associated School Policies

  • Overarching Safeguarding Statement
  • Child Protection Policy and procedures
  • Online Safety Policy and procedures
  • CCTV Procedures (if not appended to this Policy)
  • Health and Safety Policy
  • Procedures for the use of photography
  • Whole School Behaviour Policy

3.     Compliance

This policy applies to all staff and learners and visitors of Educla.  Any breach of this policy, or of the Act itself will be considered an offence and Educla’s disciplinary procedures will be invoked.

As a matter of best practice, other agencies and individuals working with Educla and who have access to personal information, will be expected to read and comply with this policy.   It is expected that departments or individuals who are responsible for dealing with external bodies will take the responsibility for ensuring that such bodies sign a contract which among other things will include an agreement to abide by this policy.

This policy will be updated as necessary to reflect best practice in data management, security and control and to ensure compliance with any changes or amendments to the DPA and other relevant legislation.

The Information Commissioner’s Office (ICO) https://ico.org.uk/  gives further detailed guidance and how schools and educational establishments undertakes to adopt and comply with ICO guidance.

4.     The Data Protection Act 1998

This piece of legislation came into force on 1 March 2000.  The DPA regulates the processing of personal data, and protects the rights and privacy of all living individuals (including children), for example by giving all individuals who are the subject of personal data a general right of access to the personal data which relates to them.  Individuals can exercise the right to gain access to their information by means of a ‘subject access request’ (sample held at Appendix A).  Personal data is information relating to an individual and may be in hard or soft copy (paper/ manual files; electronic records; photographs; CCTV images), and may include facts or opinions about a person.

The DPA also sets out specific rights for school students in relation to educational records held within the state education system.  These rights are set out in separate education regulations ‘The Education (Student Information) (England) Regulations 2000.’  For more detailed information on these Regulations see the Data Protection Guide on the ICO website.

5.     Responsibilities Under the DPA and Registration

Educla will be the ‘data controller’ under the terms of the legislation – this means it is ultimately responsible for controlling the use and processing of the personal data.

The Centre Manager is responsible for all day-to-day data protection matters, and she will be responsible for ensuring that all members of staff and relevant individuals abide by this policy, and for developing and encouraging good information handling within the centre

Compliance with the legislation is the responsibility of all members of Educla who process personal information.

Individuals who provide personal data to Educla are responsible for ensuring that the information is accurate and up-to-date.

6.     Definitions

Data Controller:                           Any individual or organisation who controls personal data, in this instance the School.

Personal Data:                              Data which relates to a living individual who can be identified.  Addresses and telephone numbers are particularly vulnerable to abuse, but so can names and photographs be, if published in the press, Internet or media.

Sensitive Personal Data:           Personal data relating to an individual’s race or ethnic origin, political opinions, religious beliefs, physical/mental health, trade union membership, sexual life and criminal activities.

Relevant Filing System:            Also known as manual records i.e. a set of records which are organised by reference to the individual/their criteria and are structured in such a way as to make specific information readily accessible e.g. personnel records, microfiches.

Data Subject:                                An individual who is the subject of the personal data, for example, employees, pupils, claimants etc.

Processing:                                    Obtaining, recording or holding data or carrying out any operation on the data including organising, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, blocking, erasing or destroying the data.

Accessible Records:                     Any records which are kept by the Organisation as part of a statutory duty, e.g. pupil records, housing tenancy records, social services records.

Parent:                                             Has the meaning given in the Education act 1996, and includes any person having parental responsibility or care of a child.

7.     Data Protection Principles

The legislation places a responsibility on every data controller to process any personal data in accordance with the eight principles.  In order to comply with its obligations, Educla undertakes to:

1.1         Process personal data fairly and lawfully

Educla will make all reasonable efforts to ensure that individuals who are the focus of the personal data (data subjects) are informed of the identity of the data controller; the purposes of the processing; any disclosures to third parties that are envisaged; given an indication of the period for which the data will be kept, and any other information which may be relevant.

1.2         Process the data for the specific and lawful purpose for which it collected that data, and not further process the data in a manner incompatible with this purpose

Educla will ensure that the reason for which it collected the data originally is the only reason for which it processes those data, unless the individual is informed of any additional processing before it takes place.

1.3         Ensure that the data is adequate, relevant and not excessive in relation to the purpose for which it is processed

Educla will not seek to collect any personal data which is not strictly necessary for the purpose for which it was obtained.  Forms for collecting data will always be drafted with this in mind.   If any irrelevant data are given by individuals, they will be destroyed immediately.

1.4          Keep personal data accurate and, where necessary, up to date

Educla will review and update all data on a regular basis by sending out, annually, a data consent form to all parents or carers of our learners.  It is the responsibility of the individuals giving their personal data to ensure that this is accurate, and each individual should notify Educla if, for example, a change in circumstances mean that the data needs to be updated.  It is the responsibility of Educla to ensure that any notification regarding the change is noted and acted on.

1.5         Only keep personal data for as long as is necessary

Educla undertakes not to retain personal data for longer than is necessary to ensure compliance with the legislation, and any other statutory requirements.  This means Educla will undertake a regular review of the information held and implement a weeding process when, e.g. students or a member of staff leaves the service.

Educla will dispose of any personal data in a way that protects the rights and privacy of the individual concerned.  See also Section 16.

1.6         Process personal data in accordance with the rights of the data subject under the legislation

Individuals have various rights under the legislation including:

  • a right to be told the nature of the information Educla holds and any parties to whom this may be disclosed;
  • a right to prevent processing likely to cause damage or distress;
  • a right to prevent processing for purposes of direct marketing;
  • a right to be informed about the mechanics of any automated decision making process that will significantly affect them;
  • a right not to have significant decisions that will affect them taken solely by automated process;
  • a right to sue for compensation if they suffer damage by any contravention of the legislation;
  • a right to take action to rectify, block, erase, or destroy inaccurate data;
  • a right to request that the Office of the Information Commissioner assess whether any provision of the Act has been contravened;

Educla will only process personal data in accordance with individuals’ rights and appropriate consent

1.7         Put appropriate technical and organisational measures in place against unauthorised or unlawful processing of personal data, and against accidental loss or destruction of data

All members of staff are responsible for ensuring that any personal data which they hold is kept securely and not disclosed to any unauthorised third parties.

Educla will ensure that all personal data is accessible only to those who have a valid reason for using it.

Educla will have in place appropriate security measures e.g.

  • ensuring that hard copy personal data is kept in lockable filing cabinets/ cupboards with controlled access;
  • keeping all personal data in a lockable room with key-controlled access;
  • password protecting personal data held electronically;
  • archiving personal data on disks which are then kept securely (lockable cabinet);
  • placing any PCs or terminals, CCTV camera screens etc. that show personal data so that they are not be visible except to authorised staff.

In addition, Educla will put in place appropriate measures for the deletion of personal data – manual records will be shredded or disposed of as ‘confidential waste’, and appropriate contract terms will be put in place with any third parties undertaking this work.  Hard drives of redundant PCs will be wiped clean before disposal, or if that is not possible, destroyed physically.

This policy also applies to staff and students who process personal data ‘off-site’, e.g. when working at home, and in such circumstances additional care must be taken regarding the security of the data this includes when using AI chatbots,

1.8         Ensure that no personal data is transferred to a country or a territory outside the European Economic Area unless that country or territory ensures adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

Educla will not transfer data to such territories without the explicit consent of the individual.

This also applies to publishing information on the Internet – because transfer of data can include placing data on a website that can be accessed from outside the EEA – so Educla will always seek the consent of individuals before placing any personal data (including photographs) on its website. 

If Educla collects personal data in any form via its website, it will provide a clear and detailed privacy statement prominently on the website, and wherever else personal data is collected.

2.     Consent as a Basis for Processing

Although it is not always necessary to gain consent from individuals before processing their data, it is often the best way to ensure that data is collected and processed in an open and transparent manner.

Consent is especially important when schools and education establishments are processing any sensitive data, as defined by the legislation.

Educla understands consent to mean that the individual has been fully informed of the intended processing and has signified their agreement (e.g. via signing a form), whilst being of a sound mind and without having any undue influence exerted upon them.  Consent obtained on the basis of misleading information will not be a valid basis for processing.  Consent cannot be inferred from the non-response to a communication.

Educla will ensure that any forms used to gather data on an individual will contain a statement (Privacy Notice – formerly known as Fair Processing Notice) explaining the use of that data, how the data may be disclosed, and also indicate whether or not the individual needs to consent to the processing.

Educla will ensure that if the individual does not give her consent for the processing, and there is no other lawful basis on which to process the data, then steps will be taken to ensure that processing of that data does not take place.

2.1         Fair Processing

Under the “Fair Processing” requirements in the Data Protection Act, Educla will inform staff and separately parents/carers of all pupils/students of the data they hold on the staff member or pupils/students, the purposes for which the data is held and the third parties (e.g. LA, DfE, QCA, Connexions etc.) to whom it may be passed.  This fair processing notice, now known as a Privacy Notice will be passed to staff when they join the Educla and parents/carers through communication.  Parents/carers of young people who are new to Educla will be provided with the Privacy Notice through communication and consent form

Example Privacy Notices can be found at Appendix B and C.

3.     Subject Access Rights (SARS)

The Data Protection Acts extend to all data subjects a right of access to their own personal data.  In order to ensure that people receive only information about themselves it is essential that a formal system of requests is in place.  Where a request for subject access is received from a pupil, Educlas policy is that:

  • Requests from pupils will be processed as any subject access request as outlined below and the copy will be given directly to the pupil, unless it is clear that the pupil does not understand the nature of the request.
  • Requests from pupils who do not appear to understand the nature of the request will be referred to their parents or carers.
  • Requests from parents in respect of their own child will be processed as requests made on behalf of the data subject (the child) and the copy will be sent in a sealed envelope to the requesting parent.

3.1         Processing Subject Access Requests

Requests for access must be made in writing.

Pupils, parents or staff may ask for a Data Subject Access form (see Appendix A), available from the School Office.  Completed forms should be submitted to Jude Harrison-SmithProvided that there is sufficient information to process the request, an entry will be made in the Subject Access log book, showing the date of receipt, the data subject’s name, the name and address of requester (if different), the type of data required (e.g. Student Record, Personnel Record), and the planned date of supplying the information (normally not more than 40 days from the request date).  Should more information be required to establish either the identity of the data subject (or agent) or the type of data requested, the date of entry in the log will be date on which sufficient information has been provided.

Note:  In the case of any written request from a parent regarding their own child’s record, access to the record will be provided within 15 school days in accordance with the current Education (Pupil Information) Regulations.

4.     Authorised Disclosures

Educla will, in general, only disclose data about individuals with their consent.  However there are circumstances under which Educla authorised officer may need to disclose data without explicit consent for that occasion.

These circumstances are strictly limited to:

  • Pupil data disclosed to authorised recipients related to education and administration necessary for Educla to perform its statutory duties and obligations.
  • Pupil data disclosed to authorised recipients in respect of their child’s health, safety and welfare.
  • Pupil data disclosed to parents in respect of their child’s progress, achievements, attendance, attitude or general demeanour within or in the vicinity of Educla
  • Staff data disclosed to relevant authorities e.g. in respect of payroll and administrative matters.
  • Unavoidable disclosures, for example to an engineer during maintenance of the computer system.  In such circumstances the engineer would be required to sign a form promising not to disclose the data outside Educla.  Officers and IT personnel writing on behalf of the LA are IT liaison/data processing officers, for example in the LA, are contractually bound not to disclose personal data.
  • Only authorised and trained staff are allowed to make external disclosures of personal data.  Data used within Educla by administrative staff, teachers and welfare officers will only be made available where the person requesting the information is a professional legitimately working within Educla who need to know the information in order to do their work.  The school will not disclose anything on pupils’ records which would be likely to cause serious harm to their physical or mental health or that of anyone else – including anything where suggests that they are, or have been, either the subject of or at risk of child abuse.

4.1         Legal Disclosure

A “legal disclosure” is the release of personal information from the computer to someone who requires the information to do his or her job within or for Educla, provided that the purpose of that information has been registered.

4.2         Illegal Disclosure

An “illegal disclosure” is the release of information to someone who does not need it, or has no right to it, or one which falls outside Educlas registered purposes.

5.     Publication of Educla’s Information

Educla publishes various items which will include some personal data, e.g.

  • internal telephone directory
  • event information
  • staff information
  • lists of students

It may be that in some circumstances an individual wishes their data processed for such reasons to be kept confidential, or restricted to internal school access only.  Therefore it is Educlas policy to offer an opportunity to opt-out of the publication of such when collecting the information.

Staff records appertaining to individual staff will remain of a confidential nature between the Director and Managers, where applicable and the member of staff.

5.1         Email

It is the policy of Educla to ensure that senders and recipients of email are made aware that under the DPA, and Freedom of Information legislation, the contents of email may have to be disclosed in response to a request for information.  One means by which this will be communicated will be by a disclaimer on the school’s email.

Under the Regulation of Investigatory Powers Act 2000, Lawful Business Practice Regulations, any email sent to or from Educla may be accessed by someone other than the recipient for system management and security purposes.

5.2         CCTV

Not Applicable at present

5.3         Images/Photographs

Information regarding our policy for the use of pupils’ images and model Parental Consent forms can be found in:

  • Educla Use of Photographs Policy
  • Educla GDPR Consent Form and Letter
  • Staff Code of Conduct
  • Child Protection Policy

6.     Data Integrity

Educla undertakes to ensure data integrity by the following methods:

6.1         Data Accuracy

Data held will be as accurate and up to date as is reasonably possible.  If a data subject informs Educla of a change of circumstances their computer record will be updated as soon as is practicable.  A printout of their data record will be provided to data subjects every twelve months so they can check its accuracy and make any amendments.

Where a data subject challenges the accuracy of their data, Educla will immediately mark the record as potentially inaccurate, or ‘challenged’.  In the case of any dispute, we shall try to resolve the issue informally, but if this proves impossible, disputes will be referred to independent arbitration.  Until resolved the ‘challenged’ marker will remain and all disclosures of the affected information will contain both versions of the information.

6.2         Data Adequacy and Relevance

Data held about people will be adequate, relevant and not excessive in relation to the purpose for which the data is being held.  In order to ensure compliance with this principle, Educla will check records regularly for missing, irrelevant or seemingly excessive information and may contact data subjects to verify certain items of data. 

6.3         Length of Time

Data held about individuals will not be kept for longer than necessary for the purposes registered.  It is the duty of Jude Harrison-Smithto ensure that obsolete data are properly erased.  See also Section 16.

7.     Identification of Data

Educla will ensure that all school staff, contractors working for it, and delivery partners, comply with restrictions applying to the access to, handling and storage of data classified as Protect, Restricted or higher.Description: restricted

All documents (manual or digital) that contain protected data will be labelled clearly with the Impact Level shown in the header and the Release and Destruction classification in the footer.  Here is an example:

Impact levels are as follows:

41  

IL1–Not Protectively Marked (IL1–NPM)

  • IL2–Protect
  • IL3–Restricted
  • IL4–Confidential

Users must be aware that when data is aggregated the subsequent impact level may be higher than the individual impact levels of the original data.  Guidance on Information Labelling and Impact Levels can be found in the BECTA document “Good Practice for Information Handling I School – Impact Levels and Labelling” Click here to access.

Although BECTA has now closed, this is still deemed to be good practice.

Release and destruction markings will be shown in the footer as follows:

[Release][Parties][Restrictions][Encrypt, Securely delete or shred]
The authority descriptorThe individuals or organisations the information may be released toDescriptor tailored to the specific individualHow the document should be destroyed
Examples:   
Senior Information Risk OwnerSchool use onlyNo internet access No photosSecurely delete or shred
TeacherMother onlyNo information to father ASBOSecurely delete or shred

All paper based IL2-Protected and IL3-Restricted (or higher) material must be held in lockable storage.

Educla recognises that under Section 7 of the Data Protection Act, data subjects have a number of rights in connection with their personal data, the main one being the right of access.  Procedures are in place to deal with Subject Access Requests i.e. a written request to see all or a part of the personal data held by the data controller in connection with the data subject (details can be found in Section 10).  Data subjects have the right to know: if the data controller holds personal data about them; a description of that data; the purpose for which the data is processed; the sources of that data; to whom the data may be disclosed; and a copy of all the personal data that is held about them.  Under certain circumstances the data subject can also exercise rights in connection with the rectification; blocking; erasure and destruction of data.

8.     Data and Computer Security

Educla undertakes to ensure security of personal data by the following general methods (precise details cannot, of course, be revealed):

8.1         Physical Security

Appropriate building security measures are in place, such as alarms, window bars, deadlocks and computer hardware cable locks.  Only authorised persons are allowed in the Office.  Disks, tapes and printouts are locked away securely when not in use.  Visitors to Educla are required to sign in and out, to wear identification badges whilst in Educla and are, where appropriate, accompanied.

8.2         Logical Security

  • Security software is installed on all computers containing personal data.
  • Educla will ensure that ICT systems are set up so that the existence of protected files is hidden from unauthorised users and that users will be assigned a clearance that will determine which files are accessible to them.
  • Personal data may only be accessed on machines that are securely password protected.  Any device that can be used to access data must be locked if left (even for very short periods) and set to auto lock if not used for five minutes.
42  
  • All storage media must be stored in an appropriately secure and safe environment that avoids physical risk, loss or electronic degradation.
  • Personal data can only be stored on Educla autherised equipment (this includes computers and portable storage media).  .
  • When personal data is stored on any portable computer system, USB stick or any other removable media:
  • the device must be password protected (many memory sticks/cards and other mobile devices cannot be password protected);
  • the device must offer approved virus and malware checking software;
  • the data must be securely deleted from the device, in line with Educla policy (below) once it has been transferred or its use is complete.
  • Educla has clear policy and procedures for the automatic backing up, accessing and restoring all data held on Educla systems, including off-site backups. Procedural Security

In order to be given authorised access to the computer, staff will have to undergo checks. All staff are trained in their Data Protection obligations and their knowledge updated as necessary.  Computer printouts as well as source documents are shredded before disposal.

Further information can be found in the Online Safety Policy.

Overall security policy for data is determined by Jude Harrison-Smith (Director) and is monitored and reviewed regularly, especially if a security loophole or breach becomes apparent.  The School’s security policy is kept in a safe place at all times.

Any queries or concerns about security of data in Educla should in the first instance be referred to Jude Harrison-Smith.

Individual members of staff can be personally liable in law under the terms of the Data Protection Acts.  They may also be subject to claims for damages from persons who believe that they have been harmed as a result of inaccuracy, unauthorised use or disclosure of their data.  A deliberate breach of this Data Protection Policy will be treated as disciplinary matter, and serious breaches could lead to dismissal.

9.     Secure transfer of data and access out of Educla

Educla recognises that personal data may be accessed by users out of the centre, or transferred to the LA or other agencies. In these circumstances:

  • Users may not remove or copy sensitive or personal data from Educla or authorised premises without permission and unless the media is encrypted and password protected and is transported securely for storage in a secure location.
  • Users must take particular care that computers or removable devices which contain personal data must not be accessed by other users (e.g. family members) when out of Educla
  • Users must protect all portable and mobile devices, including media, used to store and transmit personal information using approved encryption software.
  • Particular care should be taken if data is taken or transferred to another country, particularly outside Europe, and advice should be taken from the local authority in this event. (NB. to carry encrypted material is illegal in some countries)
43  

10.Disposal of Data

Educla will comply with the requirements for the safe destruction of personal data when it is no longer required.

The disposal of protected data, in either paper or electronic form, must be conducted in a way that makes reconstruction highly unlikely.  Electronic files must be securely overwritten and other media must be shredded, incinerated or otherwise disintegrated for data.

A Destruction Log will be kept of all data that is disposed of.  The log should include the document ID, classification, date of destruction, method and authorisation. 

11.Training & Awareness

All staff will receive data handling awareness/data protection training and will be made aware of their responsibilities, as described in this policy through:

  • Induction training for new staff;
  • Staff meetings/briefings/Staff Development;
  • Day to day support and guidance from the Responsible Person.

12.Enquiries

Information about the school’s Data Protection Policy is available from Jude Harrison-Smith.  General information about the Data Protection Act can be obtained from the Information Commissioners Office https://ico.org.uk/.

A copy of this policy will be available to all employees and covered in new staff Induction Training.  It will be reviewed at least biennially, added to, or modified from time to time and may be supplemented in appropriate cases by further statements and procedures relating to the work of the particular groups of workers.

ACCESS TO PERSONAL DATA REQUEST

(Subject Access Request – SARS)

DATA PROTECTION ACT 1998 (Section 7)

Enquirer’s Surname Enquirer’s Forenames 
  Enquirer’s Address           
Enquirer’s Postcode: 
Enquirer’s Tel No. 
Are you the person who is the subject of the records you are enquiring about (i.e. the “Data Subject”)?YES  /  NO
If NO,
Do you have parental responsibility for a child who is the “Data Subject” of the records you are enquiring about?YES  /  NO
If YES,
  Name of child or children about whose personal data records you are enquiring:        
  Description of Concern / Area of Concern              
  Description of Information or Topic(s) Requested ( In your own words)             
  Additional Information              

Please despatch Reply to:  (if different from enquirer’s details as stated on this form)

Name:

Jude Harrison-Smith

Address:

Educla Ltd

Unit 2 Westmoor

Rockcliffe

Carlisle

Cumbria

CA6 4BH

Postcode:

CA6 4BH

DATA SUBJECT DECLARATION

I request that the School search its records based on the information supplied above under Section 7 (1) of the Data Protection Act 1998 and provide a description of the personal data found from the information described in the details outlined above relating to me (or my child/children) being processed by the School.

I agree that the reply period will commence when I have supplied sufficient information to enable the School to perform the search.

I consent to the reply being disclosed and sent to me at my stated address (or to the Despatch Name and Address above who I have authorised to receive such information).

Signature of “Data Subject” (or Subject’s Parent)   ___________________________________

Name of “Data Subject” (or Subject’s Parent) (PRINTED)   ____________________________

Dated   _________________________________

Privacy Notices:

The school workforce: those employed to teach, or otherwise engaged to work at, a school or a local authority

The Data Protection Act 1998: How we use your information

We process personal data relating to those we employ to work at, or otherwise engage to work at, our school / local authority. This is for employment purposes to assist in the running of the school and/or to enable individuals to be paid. The collection of this information will benefit both national and local users by:

  • improving the management of workforce data across the sector
  • enabling development of a comprehensive picture of the workforce and how it is deployed
  • informing the development of recruitment and retention policies
  • allowing better financial modelling and planning
  • enabling ethnicity and disability monitoring; and
  • supporting the work of the School Teachers’ Review Body

This personal data includes identifiers such as names and National Insurance numbers and characteristics such as ethnic group, employment contracts and remuneration details, qualifications and absence information.

We will not share information about you with third parties without your consent unless the law allows us to. We are required, by law, to pass on some of this personal data to:

  • our local authority
  • the Department for Education (DfE)

If you require more information about how we and/or DfE store and use your personal data please visit:

THIS PAGE IS INTENTIONALLY BLANK FOR PRINTING PURPOSES

Privacy Notices:

Information about pupils in schools, alternative provision, pupil referral units and children in early years settings

Data Protection Act 1998: How we use pupil information

We collect and hold personal information relating to our pupils and may also receive information about them from their previous school, local authority and/or the Department for Education (DfE). We use this personal data to:

  • support our pupils’ learning
  • monitor and report on their progress
  • provide appropriate pastoral care; and
  • assess the quality of our services

This information will include their contact details, national curriculum assessment results, attendance information, any exclusion information, where they go after they leave us and personal characteristics such as their ethnic group, any special educational needs they may have as well as relevant medical information. For pupils enrolling for post 14 qualifications, the Learning Records Service will give us the unique learner number (ULN) and may also give us details about your learning or qualifications.

[For institutions with students aged 13+]

Once our pupils reach the age of 13, the law requires us to pass on certain information to [insert name of local authority or the provider of Youth Support Services in your area] who have responsibilities in relation to the education or training of 13-19 year olds. We may also share certain personal data relating to children aged 16 and over with post-16 education and training providers in order to secure appropriate services for them. A parent/guardian can request that only their child’s name, address and date of birth be passed to [insert name of local authority or the provider of Youth Support Services in your area] by informing [insert name of school administrator]. This right is transferred to the child once he/she reaches the age 16. For more information about services for young people, please go to our local authority website [insert link].

[Careers guidance – schools that pass young people’s information to careers guidance services or the national careers service may wish to set out details here.]

We will not give information about our pupils to anyone without your consent unless the law and our policies allow us to do so. If you want to receive a copy of the information about your son/daughter that we hold, please contact:

  • [insert name/contact details of your school administrator]

[For schools:] We are required, by law, to pass certain information about our pupils to our local authority (LA) and the Department for Education (DfE).

[For academy and free school use only:] We are required, by law, to pass some information about our pupils to the Department for Education (DfE). This information will, in turn, then be made available for use by the LA.

DfE may also share pupil level personal data that we supply to them, with third parties. This will only take place where legislation allows it to do so and it is in compliance with the Data Protection Act 1998.

Decisions on whether DfE releases this personal data to third parties are subject to a robust approval process and are based on a detailed assessment of who is requesting the data, the purpose for which it is required, the level and sensitivity of data requested and the arrangements in place to store and handle the data. To be granted access to pupil level data, requestors must comply with strict terms and conditions covering the confidentiality and handling of data, security arrangements and retention and use of the data.

For more information on how this sharing process works, please visit: https://www.gov.uk/guidance/national-pupil-database-apply-for-a-data-extract

For information on which third party organisations (and for which project) pupil level data has been provided to, please visit: https://www.gov.uk/government/publications/national-pupil-database-requests-received

If you need more information about how our local authority and/or DfE collect and use your information, please visit: