GDPR
THE GENERAL DATA PROTECTION REGULATIONS (2018)
On the 25 May 2018, the new EU General Data Protection Regulations (GDPR) came into force. The GDPR is a law designed to enhance data protection for EU residents and provide a framework for organisations and businesses with how they handle and process personal data.
The GDPR protects the personal data of individuals residing within the EU area, even if they themselves are not EU citizens. The regulations not only restrict organisations within the EU, any company worldwide that handles, stores and/or processes personal data of an EU resident must also comply. Fines for non-compliance are significant and can be up to 4% of worldwide turnover or 20,000,000 EUR whichever is the greater.
Bromley Trust Academy and our parent organisations (London South East Academies Trust and London & South East Education Group) have always taken the security of personal data very seriously, are committed to complying with the GDPR and have spent considerable time analysing our data inventory and business processes and identifying change where needed to remain compliant. All staff at our academies have undergone training for the GDPR and their understanding tested.
Privacy Notices
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Requesting Access to Your Personal Data
Under data protection legislation, people have the right to request access to information about them that we hold. To request your personal information, or be given access to your child’s educational record, please complete our Subject Access Request form.
You also have the right to:
- object to the processing of personal data that is likely to cause, or is causing, damage or distress
- prevent processing for direct marketing
- object to decisions being taken by automated means in certain circumstances, have inaccurate personal data rectified, blocked, erased or destroyed; and
- claim compensation for damages caused by a breach of the Data Protection regulations
If you have a concern about the way we are collecting or using your personal data, you should raise your concern with the Data Controllers and Data Protection Officer in the first instance or directly to the Information Commissioner’s Office at https://ico.org.uk/concerns/
Staff/ Volunteer Information
This notice explains what personal data (information) we hold about staff (and volunteers), how we collect, how we use and may share information about you. We are required to give you this information under data protection law.
The personal information we collect and use
Information collected by us in the course of employing staff in our school we collect the following personal information when you provide it to us:
- Personal information (such as name, address, contact details, employee or teacher number, national insurance number)
- Characteristics (such as gender, age, ethnic group)
- Contract information (such as start dates, hours worked, post, roles and salary information)
- Work absence information (such as number of absences and reasons)
- Qualifications (and, where relevant, subjects taught)
- Relevant medical information
- Information about training you have received during the term of your employment
How we use your personal information
We use your personal information to:
- Enable individuals to be paid
- Support pension payments and calculations
- Fulfil our obligation of maintaining a Single Central Register (SCR) of staff, volunteers and other stakeholders
- Enable sickness monitoring
- Enable leave payments (such as sick pay and maternity leave)
- Develop a comprehensive picture of the workforce and how it is deployed
- Inform the development of recruitment and retention policies
- Inform financial audits of the school
- Fulfil our duty of care towards our staff
- Fulfil our duty of care towards and safeguard our students
- Inform national workforce policy monitoring and development
How long your personal data will be kept
When you leave our employment, we will hold your personal information for up to 6 years in line with London South East College's personnel retention record-keeping guidelines.
Reasons we can collect and use your personal information
- We rely on having a legitimate reason as your employer to collect and use your personal information, and to comply with our statutory obligations, and to carry out tasks in the public interest. If we need to collect special category (sensitive) personal information, we rely upon reasons of substantial public interest (equality of opportunity or treatment).
- We share information about our workforce members under section 5 of the Education (Supply of Information about the School Workforce) (England) Regulations 2007 and amendments.
Who do we share your personal information with
- Department for Education (DfE)
- London South East Colleges and London South East Academies Trust
- Basic details (not extended or special categories of information) is also shared with external companies to be able to provide you with a login to their resources (please see our data map above)
- We will also share personal information with law enforcement or other authorities if required by applicable law.
- The DfE may share information about school employees with third parties who promote the education or well-being of children or the effective deployment of school staff in England by; conducting research or analysis, producing statistics or providing information, advice or guidance
The DfE has robust processes in place to ensure the confidentiality of our data is maintained and there are stringent controls in place regarding access and use of the data. Decisions on whether DfE releases data to third parties are subject to a strict approval process and based on a detailed assessment of:
- who is requesting the data
- the purpose for which it is required
- the level and sensitivity of data requested: and
- the arrangements in place to store and handle the data
To be granted access to school workforce information, organisations must comply with its strict terms and conditions covering the confidentiality and handling of the data, security arrangements and retention and use of the data.
Your Rights
Under the GDPR you have rights which you can exercise free of charge, which allow you to:
- Know what we are doing with your information and why we are doing it
- Ask to see what information we hold about you (Subject Access Requests)
- Ask us to correct any mistakes in the information we hold about you
- Object to direct marketing
- Make a complaint to the Information Commissioner's Office
- Withdraw consent (if applicable)
- Ask us to delete the information we hold about you
- Have your information transferred electronically to yourself or to another organisation
- Object to decisions being made that significantly affect you
- Object to how we are using your information
- Stop us from using your information in certain ways
We will always seek to comply with your request however we may be required to hold or use your information to comply with legal duties. Please note: your request may delay or prevent us delivering a service to you.
For further information about your rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioners Office (ICO) on individuals’ rights under the General Data Protection Regulation.
If you would like to exercise a right, please contact our Data Controllers and/or Data Protection Officer
Keeping your personal information secure
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Requesting access to your personal data
Under data protection legislation, people have the right to request access to information about them that we hold. To r your personal information, or be given access to your child’s educational record, please complete our Subject Access Request form.
You also have the right to:
- prevent processing for direct marketing
-
in certain circumstances, have inaccurate personal data rectified, blocked, erased or destroyed; and
- claim compensation for damages caused by a breach of the Data Protection regulations
Subject Access Request
Rights Of Access To Pupil Information
There are two distinct rights of access to information held by schools about pupils.
Under the General Data Protection Regulations 2018, a pupil has a right to request access to their own personal information. In certain circumstances, requests may be made by a parent on behalf of their child (see below)
The right of parents to have access to curricular and educational records relating to their child as defined within the Education (Pupil Information) (England) Regulations 2005.
These procedures relate to the above-mentioned rights.
Dealing with a Request
For any request of personal information, then you must email: GDPR@lsec.ac.uk
The identity of the requestor will then be established before the disclosure of any personal information, and checks should also be carried out regarding proof of relationship to the child.
Evidence of identity can be established by requesting production of:
- Passport
- Driving licence
- Utility bills with the current address
- Birth / Marriage certificate
- P45/P60
- Credit Card or Mortgage statement - this list is not exhaustive
Any individual has the right of access to information held about them. However with children, this is dependent upon their capacity to understand. As a general rule, a child of 12 or older is expected to be mature enough to understand the request they are making. If the child cannot understand the nature of the request, someone with parental responsibility can ask for the information on the child’s behalf. We may discuss the request with the child and take their views into account when making a decision
The school may make a charge for the provision of information, dependent upon the following:
- Should the information requested contain the educational record then the amount charged will be dependent upon the number of pages provided.
- Should the information requested be personal information that does not include any information contained within educational records, schools cannot charge to provide it. However we can charge a reasonable administrative fee where the request is considered manifestly unfounded or excessive and for additional copies of a request.
- The response time for subject access requests, once officially received, is 1 month (irrespective of school holiday periods, weekends etc.). However, the time to respond does not have to start until we have verified your identity.
- Requests for information from pupils or parents for access to information classed as being part of the education record must be responded to within 15 school days.
- There are some exemptions to the right to subject access that apply in certain circumstances or to certain types of personal information. Therefore all information must be reviewed prior to disclosure.
- Responding to a request may involve providing information relating to another individual (a third party). Third party information is that which identifies another pupil/parent or has been provided by another agency, such as the
- Police, Local Authority, Health Care professional or another school. Before disclosing third party information consent should normally be obtained. There is still a need to adhere to above statutory timescale.
- Any information which may cause serious harm to the physical or mental health or emotional condition of the pupil or another individual involved should not be disclosed, nor should information that would reveal that the child is at risk of abuse, or information relating to court proceedings.
- If there are concerns over the disclosure of information then additional advice should be sought from the DPO and the School’s Safeguarding team.
- Where redaction (information edited/removed) has taken place then a full copy of the information provided should be retained in order to establish, if a complaint is made, what was redacted and why.
- Information disclosed should be clear, thus any codes or technical terms will need to be clarified and explained. If information contained within the disclosure is difficult to read or illegible, then it should be retyped.
- Information can be viewed at the school with a member of staff on hand to help and explain matters if requested, or provided at face to face handover. The views of the applicant should be taken into account when considering the method of delivery. If the applicant has asked for the information to be posted then special next day delivery or recorded delivery postal service must be used.
Complaints
Complaints about the procedures should be made to the Data Protection Officer.
Complaints which are not appropriate to be dealt with through the school’s complaint procedure can be dealt with by the Information Commissioner. Contact details of both will be provided with the disclosure information.
Removable Media
In line with our parent organisation (London South East Colleges), Bromley Trust Academy have, placed restrictions on the use of removable media within the schools. The term removable media covers pen/thumb drives, writable optical media (CD-R/DVD-R) and portable/external hard drives. These restrictions have become part of the staff handbook and policy and all staff, students and visitors are expected to adhere to this restriction.
Staff instead are urged to use the Trust's Bromley cloud storage provided by the London South East Colleges.
Visitors bringing removable media into our premises will need to make contact with the Data Controller of the specific school to supervise the transfer of any materials to and from our networks.
There are few exceptions to this restriction, namely where coursework and assessment materials must be sent to the examination bodies and invigilators. The transfer of this content will be carefully monitored.
Contacts
Bromley Trust Academy with London South East Colleges have appointed a team of staff that are responsible for compliance of the GDPR and to be the first point of contact for matters relating to Data Protection. The following people are responsible for handling Subject Access Requests, change of consent, managing data breaches and replying to enquiries relating to the management of data.
Data Controller
Rob Freeman - Rob.freeman@bromleytrust.lseat.org.uk
Data Protection Officer
Ms. J. Pharo gdpr@lsec.ac.uk
Group Executive Director Corporate Services
London South East Education Group
The Walnuts
Orpington
Kent BR6 0TE
The Information Commissioner's Office
If you are not satisfied with our response, you may have the right to take the matter further to the ICO, their contact details can be found athttps://ico.org.uk/global/contact-us/