Speak to the member of the team now!

 

Confidentiality and Privacy Policy

 

 

1. Purpose

 

This policy sets out how we collect, use, store and share information about pupils, parents/carers, tutors and staff. It ensures compliance with data protection legislation and promotes safe, lawful and transparent handling of personal information.

 

2. Principles

 

 

  • Personal information is handled lawfully, fairly and transparently.

  • Data is collected only for legitimate educational, safeguarding or operational purposes.

  • Information is kept accurate, secure and only for as long as necessary.

  • Confidentiality is respected unless there is a safeguarding or legal obligation to share information.

 

 

3. Scope

 

This policy applies to all personal information processed by the organisation, including:

 

  • Pupil records

  • Parent/carer contact details

  • Tutor and staff information

  • Safeguarding reports

  • Attendance and behaviour data

  • Referral documentation

  • Any digital or paper-based communication relating to provision

 

 

4. Types of Information Collected

 

We may collect:

 

  • Identifying information (name, address, date of birth)

  • Contact details

  • Educational history and learning needs

  • Medical information relevant to safe provision

  • Safeguarding or risk information

  • Attendance, progress and assessment data

  • Communication logs with parents and professionals

 

Sensitive information (e.g., health, SEND, safeguarding) is processed with enhanced protection and lawful basis.

 

5. Lawful Basis for Processing

 

We process data under:

 

  • Consent (where applicable)

  • Contractual necessity (delivery of commissioned provision)

  • Legal obligation (safeguarding, education law, employment law)

  • Vital interests (where life or safety is at risk)

  • Legitimate interests (quality assurance, communication, operational needs)

 

 

6. Confidentiality

 

Tutors and staff must:

 

  • Keep all personal information private and secure

  • Share information only with authorised colleagues or professionals

  • Avoid discussing personal details in public or inappropriate settings

  • Use professional communication channels only

  • Report data breaches immediately to senior management

 

Confidentiality may be broken only when:

 

  • A pupil is at risk of harm

  • There is a legal requirement to share information

  • Safeguarding procedures require escalation

 

 

7. Information Sharing

 

Information may be shared with:

 

  • Local Authorities

  • Schools

  • Social care

  • Health professionals

  • Police (where lawful and necessary)

  • Parents/carers (unless restricted by safeguarding concerns)

 

Information is shared on a need-to-know basis and recorded appropriately.

 

8. Data Storage and Security

 

 

  • Digital data is stored on secure, password-protected systems.

  • Paper records are kept in locked storage.

  • Access to personal data is restricted to authorised personnel.

  • Devices used for work must be encrypted and not shared with others.

  • Staff must not store personal data on personal devices unless approved and secured.

 

 

9. Retention of Records

 

Retention periods follow statutory and operational requirements:

 

  • Safeguarding records: retained in line with statutory guidance

  • Education records: retained for the duration of provision and for an appropriate period afterwards

  • Employment and HR records: retained according to legal requirements

 

When retention periods expire, information is securely deleted or destroyed.

 

10. Rights of Individuals

 

Individuals have the right to:

 

  • Access their personal data

  • Request correction of inaccurate data

  • Request deletion where lawful

  • Object to certain types of processing

  • Withdraw consent (where processing is based on consent)

 

Requests must be made in writing and will receive a timely response.

 

11. Data Breaches

 

A data breach includes any unauthorised access, loss, disclosure or misuse of personal information.

When a breach occurs:

 

  • It is reported immediately to senior management

  • An internal investigation is carried out

  • Affected parties and regulators are informed where required

  • Mitigation actions are taken promptly

 

 

12. Staff Responsibilities

 

All staff must:

 

  • Complete data protection and confidentiality training

  • Follow safe working practices

  • Use strong passwords and approved systems

  • Keep documents secure at all times

  • Report concerns or breaches without delay

 

 

13. Review

 

This policy is reviewed annually or sooner if data protection laws or organisational procedures change.