Privacy Notice

WOODBURN PRIMARY SCHOOL – Privacy Notice for pupils & parents/families/legal guardians regarding use of personal information

May 2018

Woodburn Primary School is the data controller of the personal information we hold about our pupils and their parents/families/carers/legal guardians. This means that we are responsible for deciding how we hold and use the personal information which we collect. We are required under the General Data Protection Regulation (GDPR) to notify you of the information contained in this privacy notice.

We collect and use pupil information under the Education Act (Northern Ireland) 2014 and other legislation.
The majority of pupil information you provide to us is information which you are legally obliged to provide but some pupil information is provided to us on a voluntary basis. When collecting information from you we will inform you whether you are required to provide certain pupil information to us or if you have a choice in this.

This notice applies to prospective, current and former pupils and their families/carers/legal guardians and those applying for a place at the school and their families/carers/legal guardians. We may update this notice at any time but if we do so, we will inform you as soon as reasonably practicable.

It is important that you read and retain this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information and what your rights are under the GDPR.
If you have any questions about this privacy notice or how we handle personal information, please contact the Principal who will deal with your query.

Our Data Protection Officer (DPO) is the Education Authority and it monitors the school’s data protection procedures to ensure they meet the standards and requirements of the GDPR.
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. The ICO’s details are as follows: The ICO – Northern Ireland 3rd Floor 14 Cromac Place, Belfast BT7 2JB Tel: 028 9027 8757 / 0303 123 1114 Email: ni@ico.org.uk

How we collect and hold personal information
We collect some personal information about our pupils and their families/carers/legal guardians during a pupil’s application process to the school.
We will sometimes collect additional information from third parties such as the Education Authority (EA), Department of Education (DE), or previous school(s) attended by a pupil.
We mainly collect personal information about our pupils and their families/carers/legal guardians throughout the course of the pupil’s time at the school, for instance when completing educational visit consent forms, from statutory curriculum assessments and during our pastoral care.

What personal information we collect, store and use about our pupils
Personal information is information that identifies you and relates to you. We will collect, store and use the following categories of personal information about our pupils:
• Personal information (such as name, age, date of birth, photographs and unique pupil number)
• Contact information (such as address, emergency contact information and telephone number)
• Attendance information (such as sessions attended, number of absences and absence reasons)
• Assessment information (such as statutory assessment process, standardised tests provided by commercial companies)
• Exclusion and behavioural information
• Non-sensitive characteristic data (such as free school meal eligibility)
• Special categories of data (such as ethnicity, language, country of birth, nationality, information regarding
health (medical information), special educational needs, allergies and disability, free school meal
eligibility).

Why we collect and use this information
We use pupil data:
• To support pupil learning
• To monitor and report on pupil progress
• To provide appropriate pastoral care
• To assess the quality of our services
• To comply with the law regarding data sharing

Personal information we collect, store and use about our pupils’ parents/families/carers/legal guardians
We will collect, store and use the following categories of personal information about our pupils’ parents/ families/carers/legal guardians:
• Personal information (such as name, age, date of birth)
• Contact information (such as address(es) and telephone number(s))

Why we collect, store and use this information
We will only use personal information when the law allows us to. Most commonly, we will use personal information relating to our pupils and their parents/families/carers/legal guardians where we need to comply with our legal obligations and where it is needed in the public interest for us to exercise our authority as a public educational body.
In some cases we may use personal information where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. For example, the school has a legitimate interest in providing pupils with an education, safeguarding and promoting pupil welfare, facilitating the efficient operation of the school.
We may also use your personal information, less frequently to protect a pupil’s or their family’s interests (or someone else’s interests). For example, when investigating a complaint made by another pupil.
We keep personal information electronically on the School’s information management systems, the School’s IT network, and/or manually in indexed filing systems.

Consent
Whilst the majority of pupil information you provide is mandatory, some of is provided on a voluntary basis.
Where we need consent, the school will provide the person with parental responsibility for a pupil with a specific and clear notice which explains the reasons why the data is being collected and how the data will be used. If we ask for your consent to use personal information, you can take back this consent at any time by contacting the school in writing.

How long is data stored for?
We will only keep personal information for as long as necessary to fulfil the purposes we collected it (for example, to educate and look after pupils) and including for the purposes of satisfying any legal, accounting, or reporting requirements.

We do not store personal data forever; we only hold pupil and family data for as long as we are legally able to do so. However, sometimes we will keep personal information for historical reasons (e.g. year group or sports team photographs) but you will always have a right to ask for it to be destroyed.
We use the DE Document Retention and Disposal Policy which informs how long we keep personal information.

In determining the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

Data Security
We have put in place appropriate security measures to prevent personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a need to know. They will only process personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator (currently the ICO) of a suspected breach where we are legally required to do so.

Who we may share pupil information with
• the new school/s that the pupil’s attend after leaving us
• the Department of Education (NI) (DENI)
• the Education Authority for Northern Ireland (EA)
• The Board of Governors
• Department of Health and Health & Social Care Trusts (NHS) – School Health Team
• Council for the Curriculum, Examinations and Assessment (CCEA)
• Social Services
• Education Training Inspectorate (ETI)
• PSNI
• C2K School Management Information System
• Commercial standardised test providers.

Why we share pupil information
We do not share information about our pupils with anyone without consent unless the law and our policies allow us to do so. We only permit access to personal data for specified purpose and in accordance with our instructions. We are required to share pupils’ data with DE and/or the EA on a statutory basis. This data sharing underpins school funding and educational attainment policy and monitoring.

Schools Census
DE has a legal right to ask for particular information under the Education and Libraries (NI) Order 2003 and is referred to as the “School Census”. This information includes information on pupil characteristics such as date of birth, gender, ethnicity, religion, free school meal entitlement and special educational needs status. A number of statistical releases are made available through the DE website covering data on enrolments, participation rates, pupil teacher ratios, school leavers, attendance and school performance.

Transferring data outside the EU
We will not transfer the personal information we collect about you to any country outside the EU without telling you in advance that we intend to do so and what steps we have taken to ensure adequate protection for your personal information in those circumstances.

Your rights of access, correction, erasure and restriction
Under GDPR, parents and pupils have the right to request access to information about them that we hold. To make a request for your personal information, or be given access to your child’s educational record, contact the Principal. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

Under certain circumstances, by law a parent/carer/legal guardian or a child over the age of 13 has the right to:
• Request access to personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and your child and to check that we are lawfully processing it. You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
• Request correction of the personal information that we hold about you and your child. This enables you to have any incomplete or inaccurate information we hold corrected.
• Request erasure of personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
• Object to processing of personal information where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing you and your child’s personal information for direct marketing purposes.
• Request the transfer of your personal information to another party, for instance a new school.

If you have a concern about the way we are collecting or using personal data, we request you raise your concern with us in the first instance.
Please note that this document may be subject to amendment by the Education Authority in due course.