Speak to the member of the team now!

 

Data Protection Policy

 

 

1. Purpose

 

This policy sets out how personal data is collected, processed, stored, shared and protected. It ensures compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and all relevant statutory requirements.

 

2. Principles

 

We adhere to the following data protection principles:

 

  • Data is processed lawfully, fairly and transparently.

  • Data is collected for specified, explicit and legitimate purposes.

  • Data is adequate, relevant and limited to what is necessary.

  • Data is accurate and kept up to date.

  • Data is retained only for as long as necessary.

  • Data is kept secure and protected from unauthorised access, loss or disclosure.

 

 

3. Scope

 

This policy applies to all personal data processed by the organisation, including data relating to:

 

  • Pupils and young people

  • Parents and carers

  • Staff, tutors and applicants

  • Professionals and commissioning bodies

  • Any other individuals whose data we process

 

 

4. Lawful Basis for Processing

 

We process personal data under one or more of the following lawful bases:

 

  • Consent

  • Contractual necessity

  • Legal obligation

  • Vital interests

  • Public task (where applicable)

  • Legitimate interests

 

Special category data (e.g., health, SEND, safeguarding) is processed only under an appropriate condition such as substantial public interest or explicit consent.

 

5. Types of Data Collected

 

We may collect:

 

  • Contact information

  • Educational records

  • Attendance and engagement data

  • Medical and SEND information

  • Safeguarding information

  • Behavioural records

  • Referral documents

  • Staff HR and training information

  • Communication logs and reports

 

 

6. Data Collection and Use

 

Personal data is used for:

 

  • Delivering educational provision

  • Safeguarding pupils

  • Managing referrals and placements

  • Communication with parents and professionals

  • Monitoring progress and outcomes

  • Employment, payroll and HR functions

  • Legal and regulatory compliance

 

Data is not used for automated decision-making without human oversight.

 

7. Data Sharing

 

Data may be shared with:

 

  • Local Authorities

  • Schools

  • Social care

  • Health agencies

  • Police (when lawful)

  • Parents/carers (unless restricted)

  • Staff directly involved in provision

 

Information is shared on a strict need-to-know basis and is always justified, proportionate and documented.

 

8. Data Storage and Security

 

 

  • Digital data is stored on secure, password-protected systems.

  • Paper records are kept in locked, controlled-access storage.

  • Only authorised staff may access personal data.

  • Portable devices must be encrypted.

  • Personal data must not be stored on personal devices unless explicitly approved and secured.

  • Emails containing personal data must be sent securely.

 

 

9. Retention and Disposal

 

Data is retained only for as long as required for educational, safeguarding, operational or legal purposes.

Once retention periods expire, data is securely destroyed or permanently deleted.

 

10. Rights of Individuals

 

Individuals have the right to:

 

  • Access their data

  • Request correction of inaccurate data

  • Request deletion where lawful

  • Restrict or object to processing in certain circumstances

  • Withdraw consent where processing is based on consent

  • Request data portability (where applicable)

 

Requests must be submitted in writing and will be responded to within statutory deadlines.

 

11. Data Breaches

 

A data breach includes any unauthorised access, loss, disclosure or misuse of personal information.

When a breach occurs:

 

  • It must be reported immediately to senior management.

  • An investigation will be conducted.

  • Affected individuals and the ICO will be notified where legally required.

  • Measures will be taken to prevent recurrence.

 

 

12. Staff Responsibilities

 

All staff and tutors must:

 

  • Complete data protection training

  • Follow organisational security procedures

  • Handle all personal data confidentially

  • Report breaches or concerns without delay

  • Ensure work devices and documents are secure at all times

 

 

13. Data Protection Lead

 

A designated senior staff member acts as the Data Protection Lead, responsible for oversight, compliance and responding to data requests or concerns.

 

14. Review

 

This policy is reviewed annually or sooner if legislation or organisational practices change.