UK GDPR (General Data Protection Regulation)

25th May 2018 saw the implementation of the General Data Protection Regulation and the implementation of the Data Protection Act 2018. They both exist to protect individuals’ data and cover a series of safeguards, clarifying how is it being stored, shared and used. In schools we handle data every day, and are required to store data for legitimate purposes and legal obligations to safeguard our staff and pupils.

The documents below help us manage the data effectively and securely. If you require any further information regarding our GDPR policies and procedures or would like paper copies of any of the information below, please contact our admin team on 01332 342647 or via email on admin@central.derby.sch.uk.

Data Protection and My Rights

At Central Community Nursery and Ashgate Nursery Schools, personal data is stored and used for a variety of reasons. You may be a parent, carer, pupil, staff member, governor, visitor or anyone else who the school store data about. There are a number of categories of people, and many different types of data that are used in schools on a daily basis. 

Whilst Privacy Notices set out details about why data may be collected, stored and used, there are some overriding principles that apply to every person (the Data Subject) when a school stores data. As Data Subjects, sometimes our consent is necessary for a school to process data about us. That might relate to photographs in school, reports in local press or similar. Consent is dealt with in the separate parts of the policy and can be accessed on the website or through the school office. There are other occasions when data about us or our children may be used by the school to fulfil a legal obligation, a contract or some other lawful usage. 

We all have rights to our data which are listed below:

1.The right to rectification. Where data held about us is inaccurate, we have a right to apply for it to be amended and put right. This has to be done within one month, or within three months in complex cases. To do this we have to contact the data compliance manager within school, or the data protection officer. We have a right to complain if this is not done.

2. The right of access. This is a subject access request and is dealt with in more detail as part of the data protection policy. In essence, we have a right to see information about us that is classed as “personal data”. There is a separate process for us to make this request within school, and the school may ask us to clarify or be more specific about what kind of data we are asking for if there is a lot of it. Again, there is a one month timeframe for this that can be extended for three months in complex cases.

3. We have a right to erasure. This means that in certain circumstances we can ask for data about us to be permanently deleted. However, this can be limited if the data needs to be kept for some official or lawful purpose. The right to erasure sometimes occurs if we withdraw consent to a process.

4. We sometimes have the right to restrict processing. If we believe that data is inaccurate, and we have asked for it to be erased, we can ask the data processor and controller to stop any processing until the investigation into erasure or amendment has taken place.

5. The right to data portability. This has little bearing in the school setting. Transfer of data for pupils is regulated by guidance from the Department for Education. Data about staff is part of HMRC contractual obligations. Data portability would usually apply to things like utility companies or bank accounts.

6. The right to object to personal data being used for marketing. Again, in the school setting this is likely to be very limited as marketing tends to be limited to school fetes, fairs and plays. Schools and academy trusts should not be sharing data with commercial third-party entities to enable direct marketing of individuals. If this was the case, then an individual could object and ensure that the data was no longer used for that purpose.

7. The right to ask that decisions are made about us on the basis of our data, rather than by an automated process. Again, any application of this in schools would be extremely limited. This tends to be regarding situations such as reference agency checks for loans and mortgages for example.

These rights are important and sit alongside the school’s legal obligations to manage our data properly.

Please also see the Privacy Notices and Data Protection Policy.

If you feel that any of the Rights set out here are not being managed properly, or if that information held of our files is inaccurate or should not be there or should be changed or amended, please do let us know by using the Data Subject Rights Query Form.

We will respond within 28 days of receiving the form, and we will give our reasons in writing for any decision we make.

You may choose to accept the decision, in which case no further action is required. If you disagree, you can request a review by us and by our Data Protection Officer. You may also submit a complaint through our complaints policy if you believe we have not acted appropriately. Alternatively, you can refer the matter to the Information Commissioner’s Office (ICO), whose contact details are available at https://ico.org.uk/ or by telephone on 0303 123 1113.

Consent

We will seek consent from staff, volunteers, young people, parents and carers to collect and process their data. We will be clear about our reasons for requesting the data and how we will use it. There are contractual, statutory and regulatory occasions when consent is not required. however, in most cases data will only be processed if explicit consent has been obtained.

Consent is defined by the GDPR as “any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him other”.

We may seek consent from young people also, and this will be dependent on the child and the reason for processing.

Consent and Renewal

Please view our Privacy Notices below for more details.

It is important to read the notices as they explain how data is used in detail. Obtaining clear consent and ensuring that the consent remains in place is important for school. We also want to ensure the accuracy of that information. On arrival at school you will be asked to complete a form giving next of kin details, emergency contact and other essential information. We will also ask you to give consent to use the information for other in school purposes, as set out on the data collection/consent form. We review the contact and consent form on an annual basis. It is important to inform school if details or your decision about consent changes.

Pupil Consent Procedure

Where processing relates to a child under 16 years old, school will obtain the consent from a person who has parental responsibility for the child. Pupils may be asked to give consent or to be consulted about how their data is obtained, shared and used in certain situations.

Withdrawal of Consent

Consent can be withdrawn, subject to contractual, statutory or regulatory constraints. Where more than one person has the ability to provide or withdraw consent the school will consider each situation on the merits and within the principles of GDPR and also child welfare, protection and safeguarding principles. Please complete our Withdrawal Consent Form.

Subject Access Requests

As an organisation we collect and process data about individuals. We explain what information we collect, and why in our Privacy Notices.

Any individual, or person with parental responsibility, or young person with sufficient capacity to make a request is entitled to ask what information is held. Copies of the information shall also be made available on request. Please use our Subject Access Request Form to initiate this process. To ensure that requests are dealt with in an effective and timely manner we may seek to clarify the terms of a request. To collate and manage requests we have designated our School Business Manager to co-ordinate all requests. Please ensure that requests are made on the form to Suzie Simpson, School Business Manager.

Evidence of their identity, on the basis of the information set out and the signature on the identity must be cross-checked to that on the application form. Discretion about employees and persons known to the school may be applicable but if ID evidence is not required an explanation must be provided by school staff and signed and dated accordingly

Exemptions to a SAR exist and may include:

•       Education, Health, Social Work records
•       Examination marks and scripts
•       Safeguarding records
•       Special educational needs
•       Parental records and reports
•       Legal advice and proceedings
•       Adoption and Court records and/or reports
•       Regulatory activity and official requests e.g. DfE statistical information
•       National security, Crime and taxation
•       Journalism, literature and art
•       Research history, and statistics
•       Confidential references

All data subjects have the right to know:

•       What information is held?
•       Who holds it?
•       Why is it held?
•       What is the retention periods?
•       That each data subject has rights. Consent can be withdrawn at any time (to some  things).
•       A right to request rectification, erasure or to limit or stop processing
•       A right to complain

Much of this will be contained within the Privacy Notices below.

The information will be provided in an electronic format, usually within one calendar month of the request. However in some circumstances, for example the school is closed for holidays, this may be extended by up to another calendar month. Following delivery of the information the requester has the right to ask for a review or use the complaint process if they feel that information has not been provided

Data Protection Impact Assessments (DPIA)

When considering the purchase of any new service or product that involves processing personal data, a DPIA will be conducted. The specific responsibility for completing the DPIA will be assigned to a named member of staff, depending on the nature of the product. Each DPIA is likely to require input from a range of individuals.

The role of the Data Protection Officer (DPO) must be clearly set out for each DPIA, depending on whether their involvement is direct or supervisory. Appropriate controls must be implemented to mitigate any risks identified on a case by case basis before a decision to proceed can be made.

At the start of each project, the relevant member of the team must determine whether a DPIA is required. This assessment should take into account the nature of the proposed purchase, the aims of the project, and the type of personal data involved.

If the risk assessment suggests that the processing may result in high risk, the DPO must consult with the Information Commissioner before implementation. Although it is difficult to imagine a situation in a school where this would apply, staff must be aware that it remains a possibility.

A good DPIA is part of good procurement practice. The Department for Education provides advice about procurement in schools, available at: https://www.gov.uk/guidance/buying-for-schools

For more information click here

Class Dojo DPIA