Data Protection Policy

Author:             Briarwood School

HISTORY OF POLICY CHANGES/REVIEW

Date Page Details of change
January 2000 Created
March 2017 Reviewed

Data Protection Policy

Briarwood School collects and uses personal information about staff, pupils, parents and other individuals who come into contact with the school. This information is gathered in order to enable the school to provide education and other associated functions. In addition, there may be a legal requirement to collect and use information to ensure that the school complies with its statutory obligations.

Schools have a duty to be registered, as Data Controllers, with the Information Commissioner’s Office (ICO) detailing the information held and its use. These details are then available on the ICO’s website. Schools also have a duty to issue a Fair Processing Notice to all pupils/parents, this summarises the information held on pupils, why it is held and the other parties to whom it may be passed on.

Purpose

This policy is intended to ensure that personal information is dealt with correctly and securely and in accordance with the Data Protection Act 1998, and other related legislation. It will apply to information regardless of the way it is collected, used, recorded, stored and destroyed, and irrespective of whether it is held in paper files or electronically.

All staff involved with the collection, processing and disclosure of personal data will be aware of their duties and responsibilities by adhering to these guidelines.

What is Personal Information?

Personal information or data is defined as data which relates to a living individual who can be identified from that data, or other information held.

Data Protection Principles

The Data Protection Act 1998 establishes eight enforceable principles that must be adhered to at all times:

  1. Personal data shall be processed fairly and lawfully;
  2. Personal data shall be obtained only for one or more specified and lawful purpose(s);
  3. Personal data shall be adequate, relevant and not excessive;
  4. Personal data shall be accurate and where necessary, kept up to date;
  5. Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose or those purposes;
  6. Personal data shall be processed in accordance with the rights of data subjects under the Data Protection Act 1998;
  7. Personal data shall be kept secure i.e. protected by an appropriate degree of security;
  8. Personal data shall not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of data protection.

General Statement 

The school is committed to maintaining the above principles at all times. Therefore the school will:

  • Inform individuals why the information is being collected when it is collected
  • Inform individuals when their information is shared, and why and with whom it was shared
  • Check the quality and the accuracy of the information it holds
  • Ensure that information is not retained for longer than is necessary
  • Ensure that when obsolete information is destroyed that it is done so appropriately and securely
  • Ensure that clear and robust safeguards are in place to protect personal information from loss, theft and unauthorised disclosure, irrespective of the format in which it is recorded
  • Share information with others only when it is legally appropriate to do so
  • Set out procedures to ensure compliance with the duty to respond to requests for access to personal information, known as Subject Access Requests
  • Ensure our staff are aware of and understand our policies and procedures 

Registration 

The school is registered as a Data Controller on the Data Protection Register held by the Information Commissioner.

Privacy Notice 

Under the “Fair Processing” requirements in the Data Protection Act, the school will inform parents / carers of pupils of the data they hold on the pupils, the purposes for which the data is held and the third parties (eg LA, DfE) to whom it may be passed.

A hard copy of the Privacy Notice for Pupils is provided to all new parents / carers as part of the new starter pack. See Appendix 2

To inform staff of the data they hold, the purposes for which the data is held and the third parties to whom it may be passed, a hard copy of the Privacy Notice for Staff will posted on the staff noticeboard and will be provided to new starters as part of their induction pack. See Appendix 3

Complaints 

Complaints will be dealt with in accordance with the school’s complaints policy. Complaints relating to information handling may be referred to the Information Commissioner (the statutory regulator). 

Review 

Review Date: Academic Year 2019 – 2020

Contacts 

If you have any enquires in relation to this policy, please contact Mr David Hussey, Headteacher who will also act as the contact point for any subject access requests.

Further advice and information is available from the Information Commissioner’s Office, www.ico.gov.uk or telephone 01625 5457453

Appendix 1 

Briarwood School – Subject Access Requests 

Procedures for responding to subject access requests made under the Data Protection Act 1998 

Rights of access to information: 

There are two distinct rights of access to information held by schools about pupils.

  1. Under the Data Protection Act 1998 any individual has the right to make a request to access the personal information held about them.
  2. The right of those entitled to have access to curricular and educational records as defined within the Education Pupil Information (Wales) Regulations 2004.

These procedures relate to subject access requests made under the Data Protection Act 1998. 

Actioning a Subject Access Request 

  1. Requests for information must be made in writing; which includes email, and be addressed to Mr David Hussey, Headteacher. If the initial request does not clearly identify the information required, then further enquiries will be made.
  2. The identity of the requestor must be established before the disclosure of any information, and checks should also be carried out regarding proof of relationship to the child. Evidence of identity can be established by requesting production of:
  • passport
  • driving licence
  • identity card
  • utility bills with the current address
  • Birth / Marriage certificate
  • P45/P60
  • Credit Card or Mortgage statement

This list is not exhaustive.

  1. Any individual has the right of access to information held about them. However with children, this is dependent upon their capacity to understand (normally age 12 or above) and the nature of the request. The Headteacher should discuss the request with the child and take their views into account when making a decision. A child with competency to understand can refuse to consent to the request for their records. Where the child is not deemed to be competent an individual with parental responsibility or guardian shall make the decision on behalf of the child.
  2. The school may make a charge for the provision of information, dependent upon the following:
  • Should the information requested contain the educational record then the amount charged will be dependant upon the number of pages provided.
  • Should the information requested be personal information that does not include any information contained within educational records schools can charge up to £10 to provide it.
  • If the information requested is only the educational record viewing will be free, but a charge not exceeding the cost of copying the information can be made by the Headteacher.
  1. The response time for subject access requests, once officially received, is 40 days (not working or school days but calendar days, irrespective of school holiday periods). However the 40 days will not commence until after receipt of fees or clarification of information sought
  2. The Data Protection Act 1998 allows exemptions as to the provision of some information; therefore all information will be reviewed prior to disclosure.
  3. Third party information is that which has been provided by another, such as the Police, Local Authority, Health Care professional or another school. Before disclosing third party information consent should normally be obtained. There is still a need to adhere to the 40 day statutory timescale.
  4. Any information which may cause serious harm to the physical or mental health or emotional condition of the pupil or another should not be disclosed, nor should information that would reveal that the child is at risk of abuse, or information relating to court proceedings.
  5. If there are concerns over the disclosure of information then additional advice should be sought.
  6. Where redaction (information blacked out/removed) has taken place then a full copy of the information provided should be retained in order to establish, if a complaint is made, what was redacted and why.
  7. Information disclosed should be clear, thus any codes or technical terms will need to be clarified and explained. If information contained within the disclosure is difficult to read or illegible, then it should be retyped.
  8. Information can be provided at the school with a member of staff on hand to help and explain matters if requested, or provided at face to face handover.

The views of the applicant should be taken into account when considering the method of delivery. If postal systems have to be used then registered/recorded mail must be used. 

Appendix 2

 

PRIVACY NOTICE – Children & Young People

Privacy Notice – Data Protection Act 1998

Briarwood School is a data controller for the purposes of the Data Protection Act. We collect information from pupils and may receive information about pupils from previous schools. We hold this personal data and use it to:

  • Support pupils teaching and learning;
  • Monitor and report on pupils progress;
  • Provide appropriate pastoral care, and
  • Assess how well the school is doing.

This information includes contact details, assessment results, attendance information and personal characteristics such as ethnic group, special educational needs and relevant medical information.

We will not give information about you to anyone outside the school without your consent unless the law and our rules allow us to do so.

We are required by law to pass some information about you to the Local Authority and the Department for Education (DfE)

If you want to see a copy of the information about you that we hold and/or share, please contact the School Office.

If you require more information about how the Local Authority (LA) and/or DfE store and use pupils’ information, then please go to the following website:

http://www.bristol.gov.uk/page/council-and-democracy/data-protection-act

http://media.education.gov.uk/assets/files/doc/w/what%20the%20department%20does%20with%20data%20on%20pupils%20and%20children.doc

or contact the LA or DfE as follows:

Data Protection Officer, Bristol City Council, Romney House, Romney Avenue, Bristol BS7 9TB Website:  www.bristol.gov.uk

Public Communications Unit, Department for Education, Sanctuary Buildings, Great Smith Street, London SW1P 3BT Website: www.education.gov.uk

Appendix 3 

 

PRIVACY NOTICE – School Workforce

 Privacy Notice – Data Protection Act 1998

Briarwood School is a data controller for the purposes of the Data Protection Act.

Personal data is held by the school / Local Authority about those employed or otherwise engaged to work at the school. This is to assist in the smooth running of the school and/or enable individuals to be paid. The collection of this information will benefit both national and local users by:

  • Improving the management of school workforce data across the sector;
  • Enabling a comprehensive picture of the workforce and how it is deployed to be built up;
  • Informing the development of recruitment and retention policies;
  • Allowing better financial modeling and planning;
  • Enabling ethnicity and disability monitoring; and
  • Supporting the work of the School Teacher Review Body and the School Support Staff Negotiating Body.

This personal data includes some or all of the following – identifiers such as name and National Insurance Number and characteristics such as ethnic group; employment contract and remuneration details, qualifications and absence information.

We will not give information about you to anyone outside the school or Local Authority (LA) without your consent unless the law and our rules allow us to do so.

We are required by law to pass on some of this data to:

  • the LA
  • the Department for Education (DfE)

If you require more information about how the LA and/or DfE store and use this data please go to the following websites:

  • http://www.bristol.gov.uk/page/council-and-democracy/data-protection-act

and

or contact the LA or DfE as follows

Data Protection Officer, Bristol City Council, Romney House, Romney Avenue, Bristol BS7 9TB Website:  www.bristol.gov.uk

Public Communications Unit, Department for Education, Sanctuary Buildings, Great Smith Street, London SW1P 3BT Website: www.education.gov.uk