Data Protection Policy

REVIEW SHEET

Version NumberVersion DescriptionDate of Revision
1OriginalJanuary 2017
Updates have been made annually, but no detailed breakdown is evident. From April 2024 updates will be completed annually in September of each year, or sooner when changes are made to relevant government legislation. Update details will be outlined in the version description section,
2Wording changed from school or school premises to EduclaAddition of sending out annual update formsUpdated policies and information in 11.4June 2024
3Adding awareness of use of AI chatbotsLinks updated and changedJuly 2025
4Changes and updates Updated to UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025; updated principles, lawful bases, SARs, children’s rights, complaints, breaches, international transfers, AI, DPIAs, security and data sharing; removed obsolete DPA 1998/BECTA provisions. See separate Summary of August 2026 Amendments.August 2026

Overview

This policy explains how Educla Ltd protects personal information and complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA), together with current Information Commissioner’s Office (ICO) guidance.

Educla Ltd is required to keep and process certain information about its staff members and children or young people in accordance with its legal obligations under the GDPR.

Educla may, from time to time, be required to share personal information about its staff, children or young people with other organisations, mainly the LA, other schools and educational bodies, and potentially children’s services.

Organisational methods for keeping data secure are imperative, and Educla believes that it is good practice to keep clear practical policies, backed up by written procedures.

‘Educla Ltd believes that a child or young person should never experience abuse of any kind. We have a responsibility to promote the welfare of all children and young people and to keep them safe. We are committed to practice in a way that protects them.’ 

Contents

1.      Rationale                                                                                                                                                                          1

2.      Associated School Policies                                                                                                                                         1

3.      Compliance                                                                                                                                                                     1

4.      The Data Protection Act, 1998                                                                                                                                 1

5.      Responsibilities Under the DPA and Registration                                                                                             2

6.      Definitions                                                                                                                                                                       2

7.      Data Protection Principles                                                                                                                                         2

7.1         Process personal data fairly and lawfully……………………………………………………………. 2

7.2         Process the data for the specific and lawful purpose for which it collected that data, and not further process the data in a manner incompatible with this purpose………………………………………….. 2

7.3         Ensure that the data is adequate, relevant and not excessive in relation to the purpose for which it is processed…………………………………………………………………………………………………………….. 3

7.4         Keep personal data accurate and, where necessary, up to date………………………………. 3

7.5         Only keep personal data for as long as is necessary……………………………………………… 3

7.6         Process personal data in accordance with the rights of the data subject under the legislation 3

7.7         Put appropriate technical and organisational measures in place against unauthorised or unlawful processing of personal data, and against accidental loss or destruction of data……………………. 3

7.8         Ensure that no personal data is transferred to a country or a territory outside the European Economic Area unless that country or territory ensures adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data……………………………………………………. 4

8.      Consent as a Basis for Processing                                                                                                                           4

8.1         Fair Processing…………………………………………………………………………………………….. 4

9.      Subject Access Rights (SARS)                                                                                                                                    4

9.1         Processing Subject Access Requests………………………………………………………………….. 5

10.   Authorised Disclosures                                                                                                                                               5

10.1      Legal Disclosure……………………………………………………………………………………………. 5

10.2      Illegal Disclosure…………………………………………………………………………………………… 5

11.   Publication of Educlas Information                                                                                                                        6

11.1      Email…………………………………………………………………………………………………………. 6

11.2      CCTV………………………………………………………………………………………………………….. 6

11.3      Images/Photographs……………………………………………………………………………………… 6

12.   Data Integrity                                                                                                                                                                 6

12.1      Data Accuracy……………………………………………………………………………………………… 6

12.2      Data Adequacy and Relevance…………………………………………………………………………. 6

12.3      Length of Time…………………………………………………………………………………………….. 7

13.   Identification of Data                                                                                                                                                   7

14.   Data and Computer Security                                                                                                                                    8

14.1      Physical Security…………………………………………………………………………………………… 8

14.2      Logical Security…………………………………………………………………………………………….. 8

14.3      Procedural Security……………………………………………………………………………………….. 8

15.   Secure transfer of data and access out of school                                                                                              8

16.   Disposal of Data                                                                                                                                                            9

17.   Training & Awareness                                                                                                                                                 9

18.   Enquiries                                                                                                                                                                          9

Appendix A       –      Access to Personal Data Request

Appendix B       –      Privacy Notice – School Workforce

Appendix C       –      Privacy Notice – Pupils in Schools, Alternative Provision and

                                    Pupil Referral Units and Children in Early Years Settings

1.     Rationale

Educla Ltd is committed to protecting the rights and privacy of learners, staff, parents/carers and others and to handling personal information lawfully, fairly, transparently and securely under the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

The School needs to process certain information about its staff, students and other individuals with whom it has a relationship for various purposes such as, but not limited to:

  • the recruitment and payment of staff
  • the administration of programmes of study
  • the recording of a student’s progress
  • agreeing awards
  • collecting fees
  • complying with legal obligations to funding bodies and government

Educla will ensure personal information is collected for clear purposes, processed on an appropriate lawful basis, kept accurate and secure, retained only as long as necessary and shared only where there is a lawful and proportionate reason.

2.     Associated School Policies

  • Overarching Safeguarding Statement
  • Child Protection Policy and procedures
  • Online Safety Policy and procedures
  • CCTV Procedures (if not appended to this Policy)
  • Health and Safety Policy
  • Procedures for the use of photography
  • Whole School Behaviour Policy

3.     Compliance

This policy applies to all staff and learners and visitors of Educla.  Any breach of this policy, or of the Act itself will be considered an offence and Educla’s disciplinary procedures will be invoked.

As a matter of best practice, other agencies and individuals working with Educla and who have access to personal information, will be expected to read and comply with this policy.   It is expected that departments or individuals who are responsible for dealing with external bodies will take the responsibility for ensuring that such bodies sign a contract which among other things will include an agreement to abide by this policy.

This policy will be updated as necessary to reflect best practice in data management, security and control and to ensure compliance with any changes or amendments to the DPA and other relevant legislation.

The Information Commissioner’s Office (ICO) https://ico.org.uk/  gives further detailed guidance and how schools and educational establishments undertakes to adopt and comply with ICO guidance.

4.     Current UK data protection law

The principal framework is the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. The DUAA amends rather than replaces the UK GDPR and DPA 2018, and all of its data-protection provisions are in force by August 2026. Educla will follow current ICO guidance.

The DPA also sets out specific rights for school students in relation to educational records held within the state education system.  These rights are set out in separate education regulations ‘The Education (Student Information) (England) Regulations 2000.’  For more detailed information on these Regulations see the Data Protection Guide on the ICO website.

5.     Responsibilities Under the DPA and Registration

Educla Ltd will normally act as a controller where it determines the purposes and means of processing. In some commissioning, examination or partnership arrangements it may act as a processor or joint controller; responsibilities will be established and documented.

The Director/Centre Manager has overall responsibility for day-to-day data protection governance, supported by designated information-governance staff. Educla will keep under review whether it is legally required to appoint a Data Protection Officer (DPO).

Compliance with the legislation is the responsibility of all members of Educla who process personal information.

Individuals who provide personal data to Educla are responsible for ensuring that the information is accurate and up-to-date.

6.     Definitions

Data Controller:                           Any individual or organisation who controls personal data, in this instance the School.

Personal Data:                              Data which relates to a living individual who can be identified.  Addresses and telephone numbers are particularly vulnerable to abuse, but so can names and photographs be, if published in the press, Internet or media.

Special Category Data: Personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health information, or information concerning sex life or sexual orientation. Criminal-offence information is separately protected.

Relevant Filing System:            Also known as manual records i.e. a set of records which are organised by reference to the individual/their criteria and are structured in such a way as to make specific information readily accessible e.g. personnel records, microfiches.

Data Subject:                                An individual who is the subject of the personal data, for example, employees, pupils, claimants etc.

Processing:                                    Obtaining, recording or holding data or carrying out any operation on the data including organising, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, blocking, erasing or destroying the data.

Accessible Records:                     Any records which are kept by the Organisation as part of a statutory duty, e.g. pupil records, housing tenancy records, social services records.

Parent:                                             Has the meaning given in the Education act 1996, and includes any person having parental responsibility or care of a child.

7.     Data Protection Principles

Educla will comply with the seven UK GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability.

1.1         Process personal data fairly and lawfully

Educla will make all reasonable efforts to ensure that individuals who are the focus of the personal data (data subjects) are informed of the identity of the data controller; the purposes of the processing; any disclosures to third parties that are envisaged; given an indication of the period for which the data will be kept, and any other information which may be relevant.

1.2         Process the data for the specific and lawful purpose for which it collected that data, and not further process the data in a manner incompatible with this purpose

Educla will ensure that the reason for which it collected the data originally is the only reason for which it processes those data, unless the individual is informed of any additional processing before it takes place.

1.3         Ensure that the data is adequate, relevant and not excessive in relation to the purpose for which it is processed

Educla will not seek to collect any personal data which is not strictly necessary for the purpose for which it was obtained.  Forms for collecting data will always be drafted with this in mind.   If any irrelevant data are given by individuals, they will be destroyed immediately.

1.4          Keep personal data accurate and, where necessary, up to date

Educla will review and update all data on a regular basis by sending out, annually, a data consent form to all parents or carers of our learners.  It is the responsibility of the individuals giving their personal data to ensure that this is accurate, and each individual should notify Educla if, for example, a change in circumstances mean that the data needs to be updated.  It is the responsibility of Educla to ensure that any notification regarding the change is noted and acted on.

1.5         Only keep personal data for as long as is necessary

Educla undertakes not to retain personal data for longer than is necessary to ensure compliance with the legislation, and any other statutory requirements.  This means Educla will undertake a regular review of the information held and implement a weeding process when, e.g. students or a member of staff leaves the service.

Educla will dispose of any personal data in a way that protects the rights and privacy of the individual concerned.  See also Section 16.

1.6         Process personal data in accordance with the rights of the data subject under the legislation

Individuals have various rights under the legislation including:

  • a right to be told the nature of the information Educla holds and any parties to whom this may be disclosed;
  • a right to prevent processing likely to cause damage or distress;
  • a right to prevent processing for purposes of direct marketing;
  • a right to be informed about the mechanics of any automated decision making process that will significantly affect them;
  • a right not to have significant decisions that will affect them taken solely by automated process;
  • a right to sue for compensation if they suffer damage by any contravention of the legislation;
  • a right to take action to rectify, block, erase, or destroy inaccurate data;
  • a right to request that the Office of the Information Commissioner assess whether any provision of the Act has been contravened;

Educla will only process personal data in accordance with individuals’ rights and appropriate consent

1.7         Put appropriate technical and organisational measures in place against unauthorised or unlawful processing of personal data, and against accidental loss or destruction of data

All members of staff are responsible for ensuring that any personal data which they hold is kept securely and not disclosed to any unauthorised third parties.

Educla will ensure that all personal data is accessible only to those who have a valid reason for using it.

Educla will have in place appropriate security measures e.g.

  • ensuring that hard copy personal data is kept in lockable filing cabinets/ cupboards with controlled access;
  • keeping all personal data in a lockable room with key-controlled access;
  • password protecting personal data held electronically;
  • archiving personal data on disks which are then kept securely (lockable cabinet);
  • placing any PCs or terminals, CCTV camera screens etc. that show personal data so that they are not be visible except to authorised staff.

In addition, Educla will put in place appropriate measures for the deletion of personal data – manual records will be shredded or disposed of as ‘confidential waste’, and appropriate contract terms will be put in place with any third parties undertaking this work.  Hard drives of redundant PCs will be wiped clean before disposal, or if that is not possible, destroyed physically.

This policy also applies to staff and students who process personal data ‘off-site’, e.g. when working at home, and in such circumstances additional care must be taken regarding the security of the data this includes when using AI chatbots,

1.8         Ensure that no personal data is transferred to a country or a territory outside the European Economic Area unless that country or territory ensures adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

Educla will not transfer personal information outside the UK unless the transfer complies with the UK GDPR international-transfer rules, including UK adequacy regulations or appropriate safeguards where required. International use of cloud, AI and other online services must be assessed before personal information is uploaded.

This also applies to publishing information on the Internet – because transfer of data can include placing data on a website that can be accessed from outside the EEA – so Educla will always seek the consent of individuals before placing any personal data (including photographs) on its website. 

If Educla collects personal data in any form via its website, it will provide a clear and detailed privacy statement prominently on the website, and wherever else personal data is collected.

2.     Consent as a Basis for Processing

Consent is only one lawful basis for processing and will not be used where another lawful basis is more appropriate. Educla will identify and document a lawful basis for each processing purpose and, for special category data, an applicable Article 9 condition and any required Data Protection Act 2018 condition.

Where Educla relies on consent it must be freely given, specific, informed, unambiguous, evidenced and capable of withdrawal. Consent is not the default basis for safeguarding, statutory, employment or other processing where it would be inappropriate.

Educla understands consent to mean that the individual has been fully informed of the intended processing and has signified their agreement (e.g. via signing a form), whilst being of a sound mind and without having any undue influence exerted upon them.  Consent obtained on the basis of misleading information will not be a valid basis for processing.  Consent cannot be inferred from the non-response to a communication.

Educla will ensure that any forms used to gather data on an individual will contain a statement (Privacy Notice – formerly known as Fair Processing Notice) explaining the use of that data, how the data may be disclosed, and also indicate whether or not the individual needs to consent to the processing.

Educla will ensure that if the individual does not give her consent for the processing, and there is no other lawful basis on which to process the data, then steps will be taken to ensure that processing of that data does not take place.

2.1         Fair Processing

Under the “Fair Processing” requirements in the Data Protection Act, Educla will inform staff and separately parents/carers of all pupils/students of the data they hold on the staff member or pupils/students, the purposes for which the data is held and the third parties (e.g. LA, DfE, QCA, Connexions etc.) to whom it may be passed.  This fair processing notice, now known as a Privacy Notice will be passed to staff when they join the Educla and parents/carers through communication.  Parents/carers of young people who are new to Educla will be provided with the Privacy Notice through communication and consent form

Example Privacy Notices can be found at Appendix B and C.

3.     Subject Access Rights (SARS)

The Data Protection Acts extend to all data subjects a right of access to their own personal data.  In order to ensure that people receive only information about themselves it is essential that a formal system of requests is in place.  Where a request for subject access is received from a pupil, Educlas policy is that:

  • Requests from pupils will be processed as any subject access request as outlined below and the copy will be given directly to the pupil, unless it is clear that the pupil does not understand the nature of the request.
  • Requests from pupils who do not appear to understand the nature of the request will be referred to their parents or carers.
  • Requests from parents in respect of their own child will be processed as requests made on behalf of the data subject (the child) and the copy will be sent in a sealed envelope to the requesting parent.

3.1         Processing Subject Access Requests

A subject access request (SAR) may be made verbally or in writing, including electronically, and does not need to use a particular form or wording. Staff must recognise and promptly forward requests for access to personal information.

Educla may offer a SAR form to help identify the information sought, but its use is not compulsory. Identity and authority will be verified where reasonably necessary. Educla will respond without undue delay and normally within one month, subject to lawful extensions for complex or multiple requests.

Children have their own data protection rights. A parent does not automatically have a UK GDPR right to all of a child’s personal information. Educla will consider the child’s competence, best interests, parental responsibility, confidentiality, safeguarding and applicable education-record legislation. The separate statutory parental right to an educational record in England applies to maintained schools and should not be assumed to apply to Educla solely because it provides alternative provision.

4.     Authorised Disclosures

Educla may share personal information where there is a lawful basis and sharing is necessary and proportionate. Consent is not always required. This may include safeguarding, education provision, commissioning, awarding-organisation requirements, employment administration, legal obligations or other lawful purposes.

These circumstances are strictly limited to:

  • Pupil data disclosed to authorised recipients related to education and administration necessary for Educla to perform its statutory duties and obligations.
  • Pupil data disclosed to authorised recipients in respect of their child’s health, safety and welfare.
  • Pupil data disclosed to parents in respect of their child’s progress, achievements, attendance, attitude or general demeanour within or in the vicinity of Educla
  • Staff data disclosed to relevant authorities e.g. in respect of payroll and administrative matters.
  • Unavoidable disclosures, for example to an engineer during maintenance of the computer system.  In such circumstances the engineer would be required to sign a form promising not to disclose the data outside Educla.  Officers and IT personnel writing on behalf of the LA are IT liaison/data processing officers, for example in the LA, are contractually bound not to disclose personal data.
  • Only authorised staff may make external disclosures. Staff must consider identity, purpose, lawful basis, necessity, proportionality, data minimisation, security and safeguarding. Data protection law does not prevent necessary and proportionate information sharing to safeguard children.

4.1         Legal Disclosure

A “legal disclosure” is the release of personal information from the computer to someone who requires the information to do his or her job within or for Educla, provided that the purpose of that information has been registered.

4.2         Illegal Disclosure

An “illegal disclosure” is the release of information to someone who does not need it, or has no right to it, or one which falls outside Educlas registered purposes.

5.     Publication of Educla’s Information

Educla publishes various items which will include some personal data, e.g.

  • internal telephone directory
  • event information
  • staff information
  • lists of students

It may be that in some circumstances an individual wishes their data processed for such reasons to be kept confidential, or restricted to internal school access only.  Therefore it is Educlas policy to offer an opportunity to opt-out of the publication of such when collecting the information.

Staff records appertaining to individual staff will remain of a confidential nature between the Director and Managers, where applicable and the member of staff.

5.1         Email

It is the policy of Educla to ensure that senders and recipients of email are made aware that under the DPA, and Freedom of Information legislation, the contents of email may have to be disclosed in response to a request for information.  One means by which this will be communicated will be by a disclaimer on the school’s email.

Under the Regulation of Investigatory Powers Act 2000, Lawful Business Practice Regulations, any email sent to or from Educla may be accessed by someone other than the recipient for system management and security purposes.

5.2         CCTV

Not Applicable at present

5.3         Images/Photographs

Information regarding our policy for the use of pupils’ images and model Parental Consent forms can be found in:

  • Educla Use of Photographs Policy
  • Educla GDPR Consent Form and Letter
  • Staff Code of Conduct
  • Child Protection Policy

6.     Data Integrity

Educla undertakes to ensure data integrity by the following methods:

6.1         Data Accuracy

Data held will be as accurate and up to date as is reasonably possible.  If a data subject informs Educla of a change of circumstances their computer record will be updated as soon as is practicable.  A printout of their data record will be provided to data subjects every twelve months so they can check its accuracy and make any amendments.

Where a data subject challenges the accuracy of their data, Educla will immediately mark the record as potentially inaccurate, or ‘challenged’.  In the case of any dispute, we shall try to resolve the issue informally, but if this proves impossible, disputes will be referred to independent arbitration.  Until resolved the ‘challenged’ marker will remain and all disclosures of the affected information will contain both versions of the information.

6.2         Data Adequacy and Relevance

Data held about people will be adequate, relevant and not excessive in relation to the purpose for which the data is being held.  In order to ensure compliance with this principle, Educla will check records regularly for missing, irrelevant or seemingly excessive information and may contact data subjects to verify certain items of data. 

6.3         Length of Time

Data held about individuals will not be kept for longer than necessary for the purposes registered.  It is the duty of Jude Harrison-Smithto ensure that obsolete data are properly erased.  See also Section 16.

7.     Identification of Data

Educla will use proportionate information-classification and handling controls based on sensitivity, confidentiality and risk. Staff, contractors and delivery partners must follow access restrictions, secure storage and authorised-sharing requirements.

  • IL2–Protect
  • IL3–Restricted
  • IL4–Confidential
[Release][Parties][Restrictions][Encrypt, Securely delete or shred]
The authority descriptorThe individuals or organisations the information may be released toDescriptor tailored to the specific individualHow the document should be destroyed
Examples:   
Senior Information Risk OwnerSchool use onlyNo internet access No photosSecurely delete or shred
TeacherMother onlyNo information to father ASBOSecurely delete or shred

All paper based IL2-Protected and IL3-Restricted (or higher) material must be held in lockable storage.

Educla recognises that under Section 7 of the Data Protection Act, data subjects have a number of rights in connection with their personal data, the main one being the right of access.  Procedures are in place to deal with Subject Access Requests i.e. a written request to see all or a part of the personal data held by the data controller in connection with the data subject (details can be found in Section 10).  Data subjects have the right to know: if the data controller holds personal data about them; a description of that data; the purpose for which the data is processed; the sources of that data; to whom the data may be disclosed; and a copy of all the personal data that is held about them.  Under certain circumstances the data subject can also exercise rights in connection with the rectification; blocking; erasure and destruction of data.

8.     Data and Computer Security

Educla undertakes to ensure security of personal data by the following general methods (precise details cannot, of course, be revealed):

8.1         Physical Security

Appropriate building security measures are in place, such as alarms, window bars, deadlocks and computer hardware cable locks.  Only authorised persons are allowed in the Office.  Disks, tapes and printouts are locked away securely when not in use.  Visitors to Educla are required to sign in and out, to wear identification badges whilst in Educla and are, where appropriate, accompanied.

8.2         Logical Security

  • Security software is installed on all computers containing personal data.
  • Educla will ensure that ICT systems are set up so that the existence of protected files is hidden from unauthorised users and that users will be assigned a clearance that will determine which files are accessible to them.
  • Personal data may only be accessed on machines that are securely password protected.  Any device that can be used to access data must be locked if left (even for very short periods) and set to auto lock if not used for five minutes.
42  
  • All storage media must be stored in an appropriately secure and safe environment that avoids physical risk, loss or electronic degradation.
  • Personal information must only be stored or accessed using Educla-authorised systems, services and equipment unless an alternative has been specifically approved following an appropriate security and data-protection assessment.
  • When personal data is stored on any portable computer system, USB stick or any other removable media:
  • the device must be password protected (many memory sticks/cards and other mobile devices cannot be password protected);
  • the device must offer approved virus and malware checking software;
  • the data must be securely deleted from the device, in line with Educla policy (below) once it has been transferred or its use is complete.
  • Educla has clear policy and procedures for the automatic backing up, accessing and restoring all data held on Educla systems, including off-site backups. Procedural Security

In order to be given authorised access to the computer, staff will have to undergo checks. All staff are trained in their Data Protection obligations and their knowledge updated as necessary.  Computer printouts as well as source documents are shredded before disposal.

Further information can be found in the Online Safety Policy.

Overall security policy for data is determined by Jude Harrison-Smith (Director) and is monitored and reviewed regularly, especially if a security loophole or breach becomes apparent.  The School’s security policy is kept in a safe place at all times.

Any queries or concerns about security of data in Educla should in the first instance be referred to Jude Harrison-Smith.

All staff are accountable for complying with this policy and must immediately report suspected loss, unauthorised access, disclosure or other personal-data incidents. Deliberate or serious breaches may be addressed under Educla’s disciplinary procedures and may have legal or regulatory consequences.

9.     Secure transfer of data and access out of Educla

Educla recognises that personal data may be accessed by users out of the centre, or transferred to the LA or other agencies. In these circumstances:

  • Users may not remove or copy sensitive or personal data from Educla or authorised premises without permission and unless the media is encrypted and password protected and is transported securely for storage in a secure location.
  • Users must take particular care that computers or removable devices which contain personal data must not be accessed by other users (e.g. family members) when out of Educla
  • Users must protect all portable and mobile devices, including media, used to store and transmit personal information using approved encryption software.
  • Particular care should be taken if data is taken or transferred to another country, particularly outside Europe, and advice should be taken from the local authority in this event. (NB. to carry encrypted material is illegal in some countries)
43  

10.Disposal of Data

Educla will comply with the requirements for the safe destruction of personal data when it is no longer required.

The disposal of protected data, in either paper or electronic form, must be conducted in a way that makes reconstruction highly unlikely.  Electronic files must be securely overwritten and other media must be shredded, incinerated or otherwise disintegrated for data.

A Destruction Log will be kept of all data that is disposed of.  The log should include the document ID, classification, date of destruction, method and authorisation. 

10.3 Personal data breaches

Any actual or suspected personal data breach must be reported immediately to the Director/Centre Manager or designated data-protection lead. Educla will contain and assess the incident, document the facts, effects and remedial action, and decide whether ICO notification is required. Where a breach is likely to risk people’s rights and freedoms, the ICO must normally be notified without undue delay and, where feasible, within 72 hours of awareness. Where the risk is high, affected individuals will also be informed without undue delay unless an exception applies.

10.4 Data protection complaints

Educla will provide an accessible route, including an electronic method, for complaints about its handling of personal information. Under the Data (Use and Access) Act 2025 requirements in force from 19 June 2026, data protection complaints will be acknowledged within 30 days and investigated and responded to without undue delay. Individuals will also be informed of their right to complain to the ICO.

10.5 Artificial intelligence, automated processing and new technology

Staff must not enter identifiable learner, family, staff, safeguarding, health or other confidential information into public or unapproved generative-AI tools. Any approved AI or automated processing involving personal information must have an identified lawful basis, appropriate transparency, security and data-minimisation controls, and a Data Protection Impact Assessment (DPIA) where processing is likely to result in high risk. Educla will apply current UK GDPR/DUAA safeguards to solely automated decisions with legal or similarly significant effects.

10.6 Data protection by design and DPIAs

Educla will apply data protection by design and by default when introducing new systems, technologies, data-sharing arrangements or significant changes to processing. A DPIA must be completed before high-risk processing begins and reviewed when the nature, scope, context or risk changes.

11.Training & Awareness

All staff will receive appropriate data protection, information-security and confidentiality training at induction and refresher training thereafter. Training will include recognising SARs, secure sharing, personal-data breaches, safeguarding information, phishing/cyber risks and safe use of AI and online services.

  • Induction training for new staff;
  • Staff meetings/briefings/Staff Development;
  • Day to day support and guidance from the Responsible Person.

12.Enquiries

Information about the school’s Data Protection Policy is available from Jude Harrison-Smith.  General information about the Data Protection Act can be obtained from the Information Commissioners Office https://ico.org.uk/.

A copy of this policy will be available to staff and relevant stakeholders. It will be reviewed at least annually and sooner where legislation, ICO guidance, technology, organisational practice or identified risk requires change.

ACCESS TO PERSONAL DATA REQUEST

(Subject Access Request – SARS)

UK GDPR – RIGHT OF ACCESS (SUBJECT ACCESS REQUEST)

Enquirer’s Surname Enquirer’s Forenames 
  Enquirer’s Address           
Enquirer’s Postcode: 
Enquirer’s Tel No. 
Are you the person who is the subject of the records you are enquiring about (i.e. the “Data Subject”)?YES  /  NO
If NO,
Do you have parental responsibility for a child who is the “Data Subject” of the records you are enquiring about?YES  /  NO
If YES,
  Name of child or children about whose personal data records you are enquiring:        
  Description of Concern / Area of Concern              
  Description of Information or Topic(s) Requested ( In your own words)             
  Additional Information              

Please despatch Reply to:  (if different from enquirer’s details as stated on this form)

Name:

Jude Harrison-Smith

Address:

Educla Ltd

Unit 2 Westmoor

Rockcliffe

Carlisle

Cumbria

CA6 4BH

Postcode:

CA6 4BH

DATA SUBJECT DECLARATION

I request access to personal information held by Educla Ltd about me, or about the child where I am authorised to act on their behalf, under Article 15 UK GDPR. Educla may verify identity/authority and may seek reasonable clarification to identify the information requested.

I understand that Educla will respond without undue delay and normally within one month, subject to UK data protection legislation.

I consent to the reply being disclosed and sent to me at my stated address (or to the Despatch Name and Address above who I have authorised to receive such information).

Signature of “Data Subject” (or Subject’s Parent)   ___________________________________

Name of “Data Subject” (or Subject’s Parent) (PRINTED)   ____________________________

Dated   _________________________________

Privacy Notices:

The school workforce: those employed to teach, or otherwise engaged to work at, a school or a local authority

Workforce Privacy Notice – August 2026

Educla processes workforce information for recruitment, employment, payroll, safeguarding, training, performance, legal compliance and safe operation. A current controlled Workforce Privacy Notice should set out categories of information, purposes, lawful bases, recipients, retention, transfers, individual rights and complaint routes.

  • improving the management of workforce data across the sector
  • enabling development of a comprehensive picture of the workforce and how it is deployed
  • informing the development of recruitment and retention policies
  • allowing better financial modelling and planning
  • enabling ethnicity and disability monitoring; and
  • supporting the work of the School Teachers’ Review Body

This personal data includes identifiers such as names and National Insurance numbers and characteristics such as ethnic group, employment contracts and remuneration details, qualifications and absence information.

We will not share information about you with third parties without your consent unless the law allows us to. We are required, by law, to pass on some of this personal data to:

  • our local authority
  • the Department for Education (DfE)

If you require more information about how we and/or DfE store and use your personal data please visit:

THIS PAGE IS INTENTIONALLY BLANK FOR PRINTING PURPOSES

Privacy Notices:

Information about pupils in schools, alternative provision, pupil referral units and children in early years settings

Learner Privacy Notice – August 2026

Educla processes learner information to provide education and support, monitor progress and attendance, provide pastoral and safeguarding support, administer qualifications, meet commissioning/legal requirements and evaluate service quality. A current controlled Learner Privacy Notice should explain categories, purposes, lawful bases, recipients, retention, transfers, learner rights and complaint routes.

  • support our pupils’ learning
  • monitor and report on their progress
  • provide appropriate pastoral care; and
  • assess the quality of our services

This information will include their contact details, national curriculum assessment results, attendance information, any exclusion information, where they go after they leave us and personal characteristics such as their ethnic group, any special educational needs they may have as well as relevant medical information. For pupils enrolling for post 14 qualifications, the Learning Records Service will give us the unique learner number (ULN) and may also give us details about your learning or qualifications.

[For institutions with students aged 13+]

Once our pupils reach the age of 13, the law requires us to pass on certain information to [insert name of local authority or the provider of Youth Support Services in your area] who have responsibilities in relation to the education or training of 13-19 year olds. We may also share certain personal data relating to children aged 16 and over with post-16 education and training providers in order to secure appropriate services for them. A parent/guardian can request that only their child’s name, address and date of birth be passed to [insert name of local authority or the provider of Youth Support Services in your area] by informing [insert name of school administrator]. This right is transferred to the child once he/she reaches the age 16. For more information about services for young people, please go to our local authority website [insert link].

[Careers guidance – schools that pass young people’s information to careers guidance services or the national careers service may wish to set out details here.]

We will not give information about our pupils to anyone without your consent unless the law and our policies allow us to do so. If you want to receive a copy of the information about your son/daughter that we hold, please contact:

  • [insert name/contact details of your school administrator]

[For schools:] We are required, by law, to pass certain information about our pupils to our local authority (LA) and the Department for Education (DfE).

[For academy and free school use only:] We are required, by law, to pass some information about our pupils to the Department for Education (DfE). This information will, in turn, then be made available for use by the LA.

DfE may also share pupil level personal data that we supply to them, with third parties. This will only take place where legislation allows it to do so and it is in compliance with the Data Protection Act 1998.

Decisions on whether DfE releases this personal data to third parties are subject to a robust approval process and are based on a detailed assessment of who is requesting the data, the purpose for which it is required, the level and sensitivity of data requested and the arrangements in place to store and handle the data. To be granted access to pupil level data, requestors must comply with strict terms and conditions covering the confidentiality and handling of data, security arrangements and retention and use of the data.

For more information on how this sharing process works, please visit: https://www.gov.uk/guidance/national-pupil-database-apply-for-a-data-extract

For information on which third party organisations (and for which project) pupil level data has been provided to, please visit: https://www.gov.uk/government/publications/national-pupil-database-requests-received

If you need more information about how our local authority and/or DfE collect and use your information, please visit:

Key references reviewed:

• UK General Data Protection Regulation (UK GDPR).

• Data Protection Act 2018.

• Data (Use and Access) Act 2025 (DUAA).

• Current Information Commissioner’s Office guidance on DUAA changes, subject access, children’s information, data sharing, AI, DPIAs and personal data breaches.