1. Purpose

The purpose of this policy is to ensure that [College Name] complies with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, protecting the personal data of all individuals associated with the college, including students, staff, and other stakeholders.

2. Scope

This policy applies to all personal data processed by LCPS, including data relating to students, staff, contractors, volunteers, visitors, and any other individuals whose data the college processes.

3. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Special Category Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a person’s sex life or sexual orientation.
  • Processing: Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
  • Data Subject: An individual whose personal data is processed by the college.
  • Data Controller: The entity that determines the purposes and means of processing personal data.
  • Data Processor: The entity that processes personal data on behalf of the data controller.

4. Principles

In accordance with GDPR, LCPS will adhere to the following data protection principles:

  1. Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and in a transparent manner.
  2. Purpose Limitation: Personal data will be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
  3. Data Minimization: Personal data will be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
  4. Accuracy: Personal data will be accurate and, where necessary, kept up to date.
  5. Storage Limitation: Personal data will be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed.
  6. Integrity and Confidentiality: Personal data will be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

5. Data Subject Rights

Data subjects have the following rights regarding their personal data:

  • Right to be Informed: The right to be informed about the collection and use of their personal data.
  • Right of Access: The right to access their personal data and supplementary information.
  • Right to Rectification: The right to have inaccurate personal data rectified, or completed if it is incomplete.
  • Right to Erasure: The right to have personal data erased in certain circumstances.
  • Right to Restrict Processing: The right to request the restriction or suppression of their personal data in certain circumstances.
  • Right to Data Portability: The right to obtain and reuse their personal data for their own purposes across different services.
  • Right to Object: The right to object to the processing of their personal data in certain circumstances.
  • Rights related to Automated Decision Making and Profiling: The right not to be subject to a decision based solely on automated processing, including profiling, that has legal or similarly significant effects on them.

6. Data Security

LCPS will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate.
  • Regular testing, assessment, and evaluation of the effectiveness of security measures.
  • Ensuring confidentiality, integrity, availability, and resilience of processing systems and services.
  • Regularly reviewing and updating security practices and policies.

7. Data Breaches

In the event of a data breach, LCPS will:

  • Take immediate steps to contain and recover the breach.
  • Assess the risk to individuals and determine whether the breach needs to be reported to the Information Commissioner’s Office (ICO) and the affected individuals.
  • Notify the ICO within 72 hours of becoming aware of the breach if it is likely to result in a risk to the rights and freedoms of individuals.
  • Document all data breaches, regardless of whether they need to be reported.

8. Data Protection Officer

LCPS will appoint a Data Protection Officer (DPO) responsible for overseeing data protection strategy and implementation, ensuring compliance with GDPR and other relevant data protection laws. The DPO’s responsibilities include:

  • Informing and advising the college and its staff about their obligations under GDPR.
  • Monitoring compliance with GDPR and other data protection laws.
  • Providing advice regarding Data Protection Impact Assessments (DPIAs).
  • Cooperating with the ICO.
  • Acting as a contact point for data subjects and the ICO.

9. Training and Awareness

LCPS will provide regular data protection training and awareness programs for all staff and students to ensure they understand their responsibilities under GDPR and this policy.

10. Review and Monitoring

This policy will be reviewed annually by the Data Protection Committee to ensure it remains effective and compliant with applicable laws and regulations. Any amendments will be communicated to all relevant stakeholders.

← Back to Policies & Procedures

Skip to content