1. Introduction
2. Definitions
3. Scope
4. Data protection principles
5. Responsibility
6. Procedure
7. Surveillance
Appendix 1: Data breach procedure
Appendix 2: Retention and Disposal Schedule
The College holds personal data about our employees, clients, suppliers and other individuals for a variety of business purposes.
This policy sets out how we seek to protect personal data and ensure that staff understand the rules governing their use of personal data to which they have access in the course of their work. In particular, this policy requires staff to ensure that the Compliance Officer (CO) be consulted before any significant new data processing activity is initiated to ensure that relevant compliance steps are addressed.
2.1 Business purposes
The purposes for which personal data may be used by us:
Personnel, administrative, financial, regulatory, payroll and business development purposes.
Business purposes include the following:
2.2 Personal data
Information relating to identifiable individuals, such as job applicants, current and former employees, agency, contract and other staff, clients, suppliers and marketing contacts.
Personal data we gather on students may include:
The following information is held by the College on staff:
2.3 Sensitive personal data
Personal data about an individual’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership (or non-membership), physical or mental health or condition, criminal offences, or related proceedings—any use of sensitive personal data should be strictly controlled in accordance with this policy.
In this document the phrase ‘data processing’ means almost anything to do with information in accordance with the Data Protection Act 2018, Ashbourne ensures that personal information stored by the College is fairly and lawfully processed.
This policy applies to all staff who must be familiar with this policy and comply with its terms. This policy supplements our other policies relating to internet and email use. We may supplement or amend this policy by additional policies and guidelines from time to time. Staff will be notified of changes.
Ashbourne sets this policy in the spirit of the Data Protection Principles; set out by legislation and expressed below:
Ashbourne College ensures that we process personal data fairly and lawfully in accordance with individuals’ rights. This generally means that we should not process personal data unless the individual whose details we are processing has consented to this happening.
The Compliance Officer (CO) is responsible for the processing of data. The CO must ensure that data processing complies with the Data Protection Act, determine the purposes for which the data will be used and oversee the implementation of this policy.
5.1 The Compliance Officer’s responsibilities:
5.2 Responsibilities of the Facilities Manager:
5.3 Responsibilities of the Marketing Manager:
6.1 The processing of all data:
Ashbourne shall always have a legitimate reason for the collecting and storing of data (for example to provide information to the Department of Education’s annual census) and will always ensure that the processing of data has no adverse effect on any individual. It will be transparent in processing data and where appropriate inform individuals through a ‘privacy notice’ that their personal information is being processed.
The processing of all data must be:
6.2 Privacy Notice
Ashbourne’s terms of business contains a Privacy Notice to students, staff, contractors and all other individuals dealing with the College on data protection.
The notice:
The privacy notice can be found on Ashbourne’s website.
6.3 Sensitive personal data
In most cases where we process sensitive personal data we will require the data subject’s explicit consent to do this unless exceptional circumstances apply or we are required to do this by law (e.g. to comply with legal obligations to ensure health and safety at work/ Safeguarding etc). Any such consent will need to clearly identify what the relevant data is, why it is being processed and to whom it will be disclosed.
Sometimes it is necessary to process information about a person’s criminal convictions, race and gender and family details. This may be to ensure that Ashbourne is a safe place for everyone, or to operate other policies, such as the Equality Opportunities Policy and Child Protection and Safeguarding. The College will also ask for information about particular health needs, such as allergies to particular forms of medication, or any conditions such as asthma or diabetes or disabilities. The College will only use the information for the protection of the health and safety of the individual, but will need consent to process this information, for example in the event of a medical emergency. Because this information is considered sensitive, and it is recognised that the processing of it may cause particular concern or distress to individuals, staff and students will be asked to give express consent for the College to do this. Offers of employment or course places may be withdrawn if an individual refuses to consent to this without good reason.
6.4 Conditions for processing personal data
Before data may be processed one of the following conditions must be met:
6.5 Conditions for processing sensitive personal data
Because such information might be used in a discriminatory way, these are more stringent and must include one of the following conditions:
6.6 Exemptions
Generally all personal data collected and processed will be subject to the Data Protection Act. However, some exemptions may apply. For example, Ashbourne on occasions will ask for references (a confidential reference given by the College to a third party regarding education, employment/training, appointment to a public office, a service being provided by the data subject etc) that will remain confidential and are exempt from the requirements of the Act. References we have received and kept on file are not exempt. We must, however, ensure that the rights of the referee are considered. Information about the individual referee should not be disclosed without explicit consent (anonymising the information is acceptable). The College cannot refuse to disclose confidential references without providing reasons. Crime and taxation – personal data may have to be disclosed to government departments or the Police. Data will only be released on the basis of properly drawn up requests. Vital interests – personal data may be released if it is in the vital interests of the individual e.g. a medical emergency. Under 19 students – the College will normally release information about a student’s progress and attendance to parents or guardians of students under 19 years of age on the previous 31st August.
6.7 Accuracy and relevance
Ashbourne will ensure that any personal data we process is accurate, adequate, relevant and not excessive, given the purpose for which it was obtained. We will not process personal data obtained for one purpose for any unconnected purpose unless the individual concerned has agreed to this or would otherwise reasonably expect this.
Individuals may ask that we correct inaccurate personal data relating to them. If you believe that information is inaccurate you should record the fact that the accuracy of the information is disputed and inform the CO.
6.8 Your personal data
Employees and students must take reasonable steps to ensure that personal data we hold about you is accurate and updated as required. For example, if your personal circumstances change, please inform the CO so that they can update your records. Examples of the type of data Ashbourne may process are set out above in the section titled ‘Definitions, Personal Data’.
6.9 Data security
All members of the Ashbourne community must keep personal data secure against loss or misuse. Where other organisations process personal data as a service on our behalf, the CO will establish what, if any, additional specific data security arrangements need to be implemented in contracts with those third party organisations. For example, payment of pensions and salaries are outsourced to third parties.
6.10 Storing data securely
In cases when data is stored on printed paper, it is kept in a secure place where unauthorised personnel cannot access it. Printed data is shredded when it is no longer needed. Data stored on a computer is protected by strong passwords that are changed regularly. All staff and students use a password manager to create and store their passwords.
Data stored on CDs or memory sticks must be locked away securely when they are not being used.
The CO must approve any cloud used to store data.
Servers containing personal data must be kept in a secure location, away from general office space.
Data should be regularly backed up in line with Ashbourne’s backup procedures.
Data should never be saved directly to mobile devices such as laptops, tablets or smartphones.
All servers containing sensitive data must be approved and protected by security software and strong firewall.
We store all sensitive personal information securely either in locked filing cabinets or in computer files which are password protected.
Our computer network system is protected by a robust firewall which is monitored by both our premises manager as well as an external supplier, BTA.
All admin and teaching staff are trained about the proper use of personal data. For example, they only communicate with clients and persons related to clients through authorized channels. They must properly annotate and store all such communication. They must report all breaches of data security to the CO. They are aware that they may be subject to criminal proceedings should they deliberately try to access or disclose without authority
They are aware of the threat posed by ‘phishing’ emails and hackers.
Although rarely used we ensure that fax transmissions of sensitive data are double checked to ensure the correct telephone number. We should ensure that we are confident of the receiver’s identity and that the receiver is standing by their fax machine. We use cover sheets for all fax transmissions and where appropriate seek other modes of transmission.
Before we dispose of any computer equipment we ensure that there is no data stored within the equipment. The College is committed to keeping our security systems and security software systems up-to-date and has suffered no major incidents at the time of writing this policy.
All staff are aware of the importance of checking credentials.
The premises manager is responsible for maintaining security of access, maintaining security of data and physical protection of data on our premises. This includes:
6.11 Breaches of security
Ashbourne takes breaches of security seriously. Examples of potential breaches of security can be caused by a number of factors. Some examples are:
Ashbourne aims to carry out the following procedure to mitigate such circumstances:
See Appendix 1 for full Breach of Security Procedure.
6.12 Data retention
Ashbourne retains personal data for no longer than is necessary for the purpose for which it was collected. What is necessary will depend on the circumstances of each case, taking into account the reasons that the personal data was obtained, but should be determined in a manner consistent with our data retention guidelines (See Appendix 2) .
6.13 Transferring data internationally
There are restrictions on international transfers of personal data which Ashbourne abides by. Staff and Students are made aware that they must not transfer personal data anywhere outside the UK without first consulting the CO.
6.14 Subject access requests
Ashbourne is aware that under the Data Protection Act 2018, individuals are entitled, subject to certain exceptions, to request access to information held about them. Such subject access requests (SARs) should be made to the CO and include contact details and an outline of the specific information required.
Staff who receive a subject access request should refer that request immediately to the CO, who who may ask them to help comply with those requests.
Ashbourne is a paperless organisation and therefore information for SARs will be drawn from data primarily held digitally and/or on paper, excluding safeguarding notes and correspondence, which must be requested separately and will be released at the discretion of the College. The College does not collect information for SARs from GoogleChat. All GoogleChat content is automatically deleted every 24 hours. The College prohibits using this platform to discuss safeguarding issues, and so on this risk assessed basis the content is not stored for any longer than 24 hours.
Staff and Students may contact the CO if they would like to correct or request information that Ashbourne holds about them. There are also restrictions on the information to which individuals are entitled under applicable law.
The College aims to comply with subject access requests as quickly as possible, but will ensure that it is provided within a calendar month of receiving the request, unless there is good reason for delay such as redaction of information that relates to other parties. In such cases, the College will inform the data subject in writing of the cause of the delay.
6.15 Processing data in accordance with the individual’s rights
Information must be processed consistent with the rights of individuals with regard to processing personal data. These rights include:
A request for information which involves others may be declined unless we have the other’s consent.
Marketing
Ashbourne will not send direct marketing material to someone electronically (e.g. via email) unless we have an existing business relationship with them in relation to the services being marketed or an understanding that parties have given consent.
All members of the Ashbourne community will contact the CO for advice on direct marketing before starting any new direct marketing activity.
6.16 Training
All staff will receive training on this policy. New joiners will receive training as part of the induction process. Further training will be provided at least every two years or whenever there is a substantial change in the law or our policy and procedure.
Training is provided through an in-house seminar on a regular basis. It will cover:
Completion of training is compulsory.
It is our policy to develop an understanding of the rights of individuals under the Data Protection Act through internal programmes as well as with training of all teachers and admin staff. Topics would include: What is personal data? How may personal data be used? How should you keep personal data safe? What rights do you have with regard to processing personal data?
6.17 Other types of Data not covered by the act.
This is data that does not identify a living individual and therefore is not covered by the remit of the Data Protection Act; this may fall under other access to information procedures. This would include:
Some of this data would be available publically (for instance the diary for the forthcoming year), and some of this may need to be protected by the College. For example, if the Ashbourne has written a detailed scheme of work that it wishes to sell to other Colleges). Ashbourne may choose to protect some data in this category but there is no legal requirement to do so.
6.18 Privacy Notice – transparency of data protection
Being transparent and providing accessible information to individuals about how we will use their personal data is important for Ashbourne. The following are details on how we collect data and what we will do with it:
6.19 What information is being collected?
6.20 Conditions for processing
Ashbourne will ensure that any use of personal data is justified using at least one of the conditions for processing and this will be specifically documented. All staff who are responsible for processing personal data will be aware of the conditions for processing. The conditions for processing will be available to data subjects in the form of a privacy notice.
6.21 Justification for holding personal personal data
Ashbourne will process personal data in compliance with all eight data protection principles as stated in this policy.
Ashbourne will document the additional justification for the processing of sensitive data, and will ensure any biometric and genetic data is considered sensitive.
6.22 Consent
The data that Ashbourne collects is subject to active consent by the data subject. This consent can be revoked at any time. However, Ashbourne reserves the right to process data where consent may not be obtained in line with competing statutory duties; for example in accordance with Ashbourne’s duty of care in relation to safeguarding; see Child Protection and Safeguarding Policy and Procedure and exemptions clause above.
6.23 Criminal record checks
Any criminal record checks are justified by law as an education provider.
6.24 Data portability
Upon request, a data subject should have the right to receive a copy of their data in a structured format. These requests should be processed within one month, provided there is no undue burden and it does not compromise the privacy of other individuals. A data subject may also request that their data is transferred directly to another system. This must be done for free.
6.25 Right to be forgotten
A data subject may request that any information held on them is deleted or removed, and any third parties who process or use that data must also comply with the request. An erasure request can only be refused if an exemption applies.
6.26 Privacy by design and default
Privacy by design is an approach to projects that promote privacy and data protection compliance from the start. The CO will be responsible for conducting Privacy Impact Assessments and ensuring that all IT projects commence with a privacy plan.
When relevant, and when it does not have a negative impact on the data subject, privacy settings will be set to the most private by default.
6.27 International data transfers
No data may be transferred outside of the EEA without first discussing it with the CO. Specific consent from the data subject must be obtained prior to transferring their data outside the EEA.
6.28 Data audit and register
Regular data audits to manage and mitigate risks will inform the data register. This contains information on what data is held, where it is stored, how it is used, who is responsible and any further regulations or retention timescales that may be relevant.
6.29 Reporting breaches
All members of staff have an obligation to report actual or potential data protection compliance failures. This allows us to:
6.30 Monitoring
All Students and staff must observe this policy. The CO has overall responsibility for this policy. They will monitor it regularly to make sure it is being adhered to.
All staff and students are responsible for the following:
6.31 Consequences of failing to comply
Ashbourne takes compliance with this policy very seriously. Failure to comply puts both you and the organisation at risk.
The importance of this policy means that failure to comply with any requirement may lead to disciplinary action under our procedures which may result in dismissal.
Ashbourne acknowledges its data protection obligations in relation to CCTV. It adopts, where applicable the ICO’s code of practice.
This section also serves as a notice and a guide to data subjects (including pupils, parents, staff, volunteers, visitors to the College and members of the public) regarding their rights in relation to personal data recorded via the CCTV system.
All fixed cameras are in plain sight on premises and Ashbourne does not routinely use CCTV for covert monitoring or monitoring of private property outside the College.
Data captured for the purposes below will not be used for any commercial purpose.
7.1 Objectives of the System :
Locations have been selected that the College reasonably believes require monitoring to address the stated objectives.
Warning signs are placed in prominent positions to inform anyone entering the area, such as pupils, staff, volunteers, visitors and members of the public that they are entering a monitored area, identifying the College as the Data Controller and giving contact details for further information regarding the system.
No images will be captured from areas in which individuals would have a heightened expectation of privacy, including changing and washroom facilities.
7.2 Maintenance
The CCTV system will be operational 24 hours a day, every day of the year.
The System Manager (defined below) will check and confirm that the system is properly recording and that cameras are functioning correctly, on a regular basis.
The system will be checked and (to the extent necessary) serviced, annually.
7.3 Supervision of the System
Staff authorised by Ashbournel to conduct routine supervision of the System may include:
Images will be viewed and/or monitored in a suitable environment where it is unlikely they will be accessed or inadvertently viewed by unauthorised persons.
7.4 Storage of Data
The system is administered and managed by Ashbourne, who will act as the Data Controller. The day-to-day management of images will be the responsibility of the IT Services Manager who will act as the System Manager, or such suitable person as the System Manager.
Images will be stored for two weeks, and automatically over-written unless Ashbourne considers it reasonably necessary for the pursuit of the objectives outlined above, or if lawfully required by an appropriate third party such as the police or local authority.
Where such data is retained, it will be retained in accordance with the Act and our Data Protection Policy. Information including the date, time and length of the recording, as well as the locations covered and groups or individuals recorded, will be recorded in the system log book.
7.5 Access to Images
Access to stored CCTV images will only be given to authorised persons, under the supervision of the System Manager, in pursuance of the above objectives (or if there is some other overriding and lawful reason to grant such access).
The System Manager must satisfy themselves of the identity of any person wishing to view stored images or access the system and the legitimacy of the request. The following are examples when the System Manager may authorise access to CCTV images:
Where images are disclosed aforementioned above a record will be made in the system log including the person viewing the images, the time of access, the reason for viewing the images, the details of images viewed and a crime incident number (if applicable).
Where images are provided to third parties above, wherever practicable steps will be taken to obscure images of non-relevant individuals.
7.6 Other CCTV systems
Ashbourne may be provided by third parties with CCTV images and will manage these in accordance with the College’s own Data Protection Policy and/or Student Behaviour and Exclusions Policy.
For example, many pupils travel on coaches provided by third party contractors and a number of these coaches are equipped with CCTV systems. Ashbourne may use these in establishing facts in cases of unacceptable student behaviour, in which case the parents/guardian will be informed as part of the College’s management of a particular incident. Parents are informed of this as part of the Coach Service Registration document, to which they agree when registering their son or daughter for the coach service.
7.7 Complaints
Any complaints in relation to the College’s CCTV system or its use of CCTV should be referred to the Principal, Mike Kirby.
We have notified the Information Commissioner’s Office that we process and store personal information, as we are required to do by the Data Protection Act.
Compliance Officer: Mike Kirby
A1. Policy Statement
Ashbourne holds large amounts of personal and sensitive data. Every care is taken to protect personal data and to avoid a data protection breach. In the unlikely event of data being lost or shared inappropriately, it is vital that appropriate action is taken to minimise any associated risk as soon as possible. This breach procedure applies to all personal and sensitive data held by Ashbourne.
This procedure applies to all College staff.
A2. Purpose
This breach procedure sets out the course of action to be followed by all staff at Ashbourne if a data protection breach takes place.
A3. Legal Context
The Data Protection Act 1998 makes provision for the regulation of the processing (use) of information relating to individuals, including the obtaining, holding, use or disclosure of such information.
Principle 7 of the Act states that organisations which process personal data must take “appropriate technical and organisational measures against the unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”.
A4. Types of Breach
Ashbourne takes breaches of security seriously. Examples of potential breaches of security can be caused by a number of factors. Some examples are:
Loss or theft of pupil, staff odata and/ or equipment on which data is stored;
A5. Immediate Containment/Recovery
In discovery of a data protection breach, the following steps should be followed:
A6. Investigation
In most cases, the next stage would be for the CO to fully investigate the breach. They should ascertain whose data was involved in the breach, the potential effect on the data subject and what further steps need to be taken to remedy the situation.
The investigation should consider:
The investigation should be completed as a matter of urgency and, wherever possible, within five days of the breach being discovered/reported. A further review of the causes of the breach and recommendations for future improvements can be done once the matter has been resolved.
A7. Notification
Some people/agencies may need to be notified as part of the initial containment. However, the decision will normally be made once an investigation has taken place. The CO should, after seeking expert or legal advice, decide whether anyone should be notified of the breach.
In the case of significant breaches, the Information Commissioner’s Office (ICO) should be notified. Incidents should be considered on a case by case basis. The following points will help you to decide whether and how to notify:
If a large number of people are affected, or there are very serious consequences, you should notify the ICO. The ICO should only be notified if personal data is involved. There is guidance available from the ICO on when and how to notify them.
Consider the dangers of over-notifying. Not every incident warrants notification and over-notification may cause disproportionate enquiries and work. The notification should include a description of how and when the breach occurred and what data was involved. Include details of what you have already done to mitigate the risks posed by the breach. When notifying individuals, give specific and clear advice on what they can do to protect themselves and what you are willing to do to help them.
You should also give them the opportunity to make a formal complaint if they wish following the College’s Complaints Procedure.
A8. Review and Evaluation
Once the initial aftermath of the breach is over, the CO should fully review both the causes of the breach and the effectiveness of the response to it. It should be written and sent to the next available management team meeting for discussion.
If systemic or ongoing problems are identified, then an action plan must be drawn up to put these right.
If the breach warrants a disciplinary investigation, the manager leading the investigation should do so in line with Ashbourne’s Complaints Policy.
This breach procedure may need to be reviewed after a breach or after legislative changes, new case law or new guidance. Consideration should be given to reviewing this breach procedure whenever the data protection policy is reviewed.
A9. Implementation
Ashbourne will ensure that staff are aware of the Data Protection Policy and its requirements including this breach procedure. This should be undertaken as part of induction and supervision. If staffs have any queries in relation to the policy, they should discuss this with their line manager or CO.
1. Management and organisation
2. Legislation and Guidance from DE, ELB, ESA, CCMS etc
3. Students
4. Staff
5. Finance
6. Health & Safety