Confidentiality and Privacy Policy
1. Purpose
This policy sets out how we collect, use, store and share information about pupils, parents/carers, tutors and staff. It ensures compliance with data protection legislation and promotes safe, lawful and transparent handling of personal information.
2. Principles
Personal information is handled lawfully, fairly and transparently.
Data is collected only for legitimate educational, safeguarding or operational purposes.
Information is kept accurate, secure and only for as long as necessary.
Confidentiality is respected unless there is a safeguarding or legal obligation to share information.
3. Scope
This policy applies to all personal information processed by the organisation, including:
Pupil records
Parent/carer contact details
Tutor and staff information
Safeguarding reports
Attendance and behaviour data
Referral documentation
Any digital or paper-based communication relating to provision
4. Types of Information Collected
We may collect:
Identifying information (name, address, date of birth)
Contact details
Educational history and learning needs
Medical information relevant to safe provision
Safeguarding or risk information
Attendance, progress and assessment data
Communication logs with parents and professionals
Sensitive information (e.g., health, SEND, safeguarding) is processed with enhanced protection and lawful basis.
5. Lawful Basis for Processing
We process data under:
Consent (where applicable)
Contractual necessity (delivery of commissioned provision)
Legal obligation (safeguarding, education law, employment law)
Vital interests (where life or safety is at risk)
Legitimate interests (quality assurance, communication, operational needs)
6. Confidentiality
Tutors and staff must:
Keep all personal information private and secure
Share information only with authorised colleagues or professionals
Avoid discussing personal details in public or inappropriate settings
Use professional communication channels only
Report data breaches immediately to senior management
Confidentiality may be broken only when:
A pupil is at risk of harm
There is a legal requirement to share information
Safeguarding procedures require escalation
7. Information Sharing
Information may be shared with:
Local Authorities
Schools
Social care
Health professionals
Police (where lawful and necessary)
Parents/carers (unless restricted by safeguarding concerns)
Information is shared on a need-to-know basis and recorded appropriately.
8. Data Storage and Security
Digital data is stored on secure, password-protected systems.
Paper records are kept in locked storage.
Access to personal data is restricted to authorised personnel.
Devices used for work must be encrypted and not shared with others.
Staff must not store personal data on personal devices unless approved and secured.
9. Retention of Records
Retention periods follow statutory and operational requirements:
Safeguarding records: retained in line with statutory guidance
Education records: retained for the duration of provision and for an appropriate period afterwards
Employment and HR records: retained according to legal requirements
When retention periods expire, information is securely deleted or destroyed.
10. Rights of Individuals
Individuals have the right to:
Access their personal data
Request correction of inaccurate data
Request deletion where lawful
Object to certain types of processing
Withdraw consent (where processing is based on consent)
Requests must be made in writing and will receive a timely response.
11. Data Breaches
A data breach includes any unauthorised access, loss, disclosure or misuse of personal information.
When a breach occurs:
It is reported immediately to senior management
An internal investigation is carried out
Affected parties and regulators are informed where required
Mitigation actions are taken promptly
12. Staff Responsibilities
All staff must:
Complete data protection and confidentiality training
Follow safe working practices
Use strong passwords and approved systems
Keep documents secure at all times
Report concerns or breaches without delay
13. Review
This policy is reviewed annually or sooner if data protection laws or organisational procedures change.

