This policy sets out data protection standards which should be followed across Supporting Education Group (the Group). References to Company is to each individual Company within the Group.
This policy applies to all staff within the Group who should become familiar with and comply with its terms. Staff includes employees, temporary and agency works, other contractors, interns and volunteers.
Material scope – the GDPR applies to the processing of personal data wholly or partly by automated means (i.e. by computer) and to the processing other than by automated means of personal data (i.e. paper records) that form part of a filing system or are intended to form part of a filing system.
Territorial scope – the GDPR will apply to all controllers that are established in the EU (European Union) who process the personal data of data subjects, in the context of that establishment. It will also apply to controllers outside of the EU that process personal data in order to offer goods and services, or monitor the behavior of data subjects who are resident in the EU.
Staff are expected to familiarise themselves with the provisions set out and fully understand their individual responsibilities under the GDPR. Any breach of the GDPR will be dealt with under the Group’s disciplinary policy and may also be a criminal offence, in which case the matter will be reported as soon as possible to the appropriate authorities.
Definitions
Personal data – any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special category data – personal data revealing the data subject’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical and mental health, sex life, sexual orientation, biometric or genetic data.
Criminal offence data - personal information relating to criminal convictions and offences, allegations, proceedings, and related security measures.
Data controller – the organisation storing and controlling such information is referred to as the Data Controller. This could be Supporting Education Group or any of the Companies within the Group. Each are data controllers in their own right.
Data subject – any living individual who is the subject of personal data held by an organisation.
Processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Automated decision making and profiling – two forms of automated processing. Automated decision making is when a decision is made which is based solely on automated processing (without human intervention) which produces legal effects or significantly affects an individual. Automated decision making is prohibited except in exceptional circumstances. Profiling is also based on automated processing where it is used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person.
Third party – a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
- To protect the data subject’s vital interests;
- To meet legal compliance obligations (other than a contractual obligation);
- To perform a task in the public interest or in order to carry out official functions as authorised by law;
- For the purposes of the organisation’s legitimate interests where authorised in accordance with data protection legislation. This is provided that it would not prejudice the rights and freedoms or legitimate interests of the data subject.
For special category data, we can only process this data provided one of the above lawful conditions are met and one of the lawful bases for special category data is met. These conditions can be found here.
For criminal offence data, we can only process this data provided one of the above lawful conditions are met and there is a legal or official authority to process this data. These conditions can be found here.
See 2.1.4 below for more detail about consent.
Transparently – i.e. to be clear, open and honest with data subjects about who we are, and how and why we use their personal data. The GDPR includes rules on giving privacy information to data subjects, placing an emphasis on making privacy notices understandable and accessible.
The Group will issue privacy notices from time to time, informing data subjects about the personal information that we collect and hold, how they can expect their personal information to be used and for what purposes.
The Group take appropriate measures to provide information in privacy notices in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
Consent – Where the Group relies on consent as a lawful basis for processing (as set out above), it will adhere to the requirements set out in the GDPR. Consent must be freely given, specific, informed and be an unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them. Explicit consent requires a very clear and specific statement to be relied upon (i.e. more than just mere action is required).
A data subject will have consented to processing of their personal data if they indicate agreement clearly either by a statement or positive action to the processing. Consent requires affirmative action so silence, pre-ticked boxes or inactivity will not amount to valid consent.
Data subjects must be easily able to withdraw consent to processing at any time and withdrawal must be promptly honoured. The Group will keep records of consents obtained in order to demonstrate compliance with consent requirements under the GDPR.
Where the Group provides online services to children, parental or custodial authorisation must be obtained. This requirement applies to children under the age of 16.
Personal data will not be processed in any matter that is incompatible with the legitimate purposes. The Group will not use personal data for new, different or incompatible purposes from that disclosed when it was first obtained unless they have informed the data subject of the new purpose (and they have consented where necessary).
These controls have been selected on the basis of identified risks to personal data, and the potential for damage or distress to individuals whose data is being processed.
The Group’s compliance with this principle is contained in its information security policies.
Data Protection Officer: Judicium Consulting Limited
Address: 98 Theobalds Road, London, WC1X 8WB Email: dataservices@judicium.com
Web: www.judiciumeducation.co.uk
Telephone: 0345 548 7000 option 1
Lead Contact: Craig Stilwell
- If you are unsure of the lawful basis being relied on by the Group to process personal data;
- If you need to draft privacy notices or fair processing notices;
- If you are unsure about the retention periods for the personal data being processed;
- If you are unsure about what security measures need to be put in place to protect personal data;
- If there has been a personal data breach and would refer you to the procedure set out in the Group’s data breach procedure;
- If you are unsure on what basis to transfer personal data outside the EEA;
- If you need any assistance dealing with any rights invoked by a data subject (and would refer you to the data requests procedure);
- Whenever you are engaging in a significant new (or a change in) processing activity which is likely to require a data protection impact assessment or if you plan to use personal data for purposes other than what it was collected for;
- If you plan to undertake any activities involving automated processing or automated decision making;
- If you need help complying with applicable law when carrying out direct marketing activities;
- If you need help with any contracts or other areas in relation to sharing personal data with third parties.
- if computerised, password protected in line with corporate requirements in the Access Control Policy; and/or
- stored on computer media which are encrypted.
A list of countries that currently satisfy the adequacy requirements of the Commission are published in the Official Journal of the European Union. http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm
Binding corporate rules – The Group may adopt approved binding corporate rules for the transfer of data outside the EU. This requires submission to the relevant supervisory authority for approval. This is for internal transfers between branches of multinational organisations.
Standard contract clauses – the Group may adopt approved standard contractual clauses for the transfer of data outside of the EEA. Standard clauses are those adopted by the Commission and are available on the ICO website. In the absence of an adequacy decision, standard contractual clauses are the most likely option for international data transfers. The DPO can help implement these clauses when required.