{"id":4366,"date":"2021-08-11T12:50:46","date_gmt":"2021-08-11T11:50:46","guid":{"rendered":"https:\/\/www.devon.gov.uk\/supportforschools\/?page_id=4366"},"modified":"2024-12-09T17:08:33","modified_gmt":"2024-12-09T17:08:33","slug":"department-for-education-guidance-on-data-sharing-privacy-notices-and-data-security","status":"publish","type":"page","link":"https:\/\/www.devon.gov.uk\/support-schools-settings\/administration-and-finance\/administration\/school-census\/department-for-education-guidance-on-data-sharing-privacy-notices-and-data-security\/","title":{"rendered":"Department for Education Guidance on data sharing, privacy notices and data security"},"content":{"rendered":"\n<p>The UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018) mandate certain safeguards regarding the use of personal data by organisations, including the department, local authorities and schools.<\/p>\n\n\n\n<p>Both give rights to those (known as data subjects) about whom data is processed such as pupils, parents and teachers. These rights include (amongst other information that the department is obliged to provide) the right to know:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the types of data being held<\/li>\n\n\n\n<li>why it is being held<\/li>\n\n\n\n<li>to whom it may be communicated<\/li>\n<\/ul>\n\n\n\n<p>For the purposes of data protection legislation, the terms \u2018process\u2019, \u2018processed\u2019 or \u2018processing\u2019 apply to any activity involving the personal data, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>collecting<\/li>\n\n\n\n<li>storing<\/li>\n\n\n\n<li>sharing<\/li>\n\n\n\n<li>destroying<\/li>\n\n\n\n<li>etcetera \u2013 please note: this list is not exhaustive<\/li>\n<\/ul>\n\n\n\n<p>As data processors and controllers in their own right, it is important that schools process all data (not just that collected for the purposes of the school census) in accordance with the full requirements of the UK GDPR.<\/p>\n\n\n\n<p>Further information on the UK GDPR can be found in the Information Commissioner\u2019s Office (ICO)&nbsp;<a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">UK General Data Protection Regulation (GDPR).<\/a><\/p>\n\n\n\n<p>The sections below provide additional information on two aspects of data protection legislation \u2013 namely privacy notices and data security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Legal duties under the UK General Data Protection Regulation and Data Protection Act 2018: privacy notices<\/h2>\n\n\n\n<p>Being transparent and providing accessible information to individuals about how you will process their personal data is a key element of UK GDPR and DPA 2018. The most common way to provide such information is through a privacy notice. Please see the Information Commissioner\u2019s Office (ICO) website for&nbsp;<a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/individual-rights\/right-to-be-informed\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">further guidance on privacy notices<\/a>.<\/p>\n\n\n\n<p>The DfE provides suggested wording for&nbsp;<a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-and-privacy-privacy-notices\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">privacy notices&nbsp;<\/a>that schools and local authorities may wish to use. However, where the suggested wording is used, the school or local authority <strong>must review and amend&nbsp;<\/strong>the wording to reflect local business needs and circumstances.<\/p>\n\n\n\n<p>This is especially important, as the school will process data that is not solely for use within census data collections. As such, to comply with UK GDPR, the privacy notice should contain details of all uses of data within the school, which may include, for example, information used locally for pupil achievement tracking and (where relevant) the use of CCTV data.<\/p>\n\n\n\n<p>The DfE recommends that the privacy notice is included as part of an induction pack for pupils and staff, is made available on the school website for parents and features on the staff notice board or intranet. Privacy notices do not need to be issued on an annual basis, where:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>new pupils and staff are made aware of the notices<\/li>\n\n\n\n<li>the notices have not been amended<\/li>\n\n\n\n<li>they are readily available in electronic or paper format<\/li>\n<\/ul>\n\n\n\n<p>However, it remains best practice to remind parents of the school\u2019s privacy notices at the start of each term (within any other announcements \/ correspondence to parents), and it is important that any changes made to the way the school processes personal data are highlighted to data subjects.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Legal duties under the UK General Data Protection Regulation and the Data Protection Act 2018: data security<\/h2>\n\n\n\n<p>Schools and local authorities have a (legal) duty under the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 to ensure that any personal data they process is handled and stored securely. Further information on data security is available from the&nbsp;<a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/security\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/security\/<\/a>.<\/p>\n\n\n\n<p>Where personal data is not properly safeguarded, it could compromise the safety of individuals and damage your school\u2019s reputation. Your responsibility as a data controller extends to those who have access to your data beyond your organisation where they are working on your behalf \u2013 for example, where external IT suppliers can remotely access your information.<\/p>\n\n\n\n<p>The \u2018<a href=\"https:\/\/www.gov.uk\/government\/publications\/school-procurement-selecting-a-school-mis\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">School procurement: selecting a school MIS<\/a>\u2019 and \u2018<a href=\"http:\/\/www.nationalarchives.gov.uk\/information-management\/training\/responsible-for-information-csl-course\/#_blank\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">Responsible for information<\/a>\u2019 pages provide further guidance and advice.<\/p>\n\n\n\n<p>It is vital that all staff with access to personal data understand the importance of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>protecting personal data<\/li>\n\n\n\n<li>being familiar with your security policy<\/li>\n\n\n\n<li>putting security procedures into practice<\/li>\n<\/ul>\n\n\n\n<p>As such, schools should provide appropriate initial and refresher training for your staff.<\/p>\n\n\n\n<p>Where schools chose to use cloud software services, additional information on handling data securely within such environments is available within the&nbsp;<a href=\"https:\/\/www.gov.uk\/government\/publications\/cloud-software-services-and-the-data-protection-act#_blank\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">department guidance on data protection for schools considering cloud software services<\/a>.<\/p>\n\n\n\n<p><strong>Information Commissioners Office and Department for Education websites:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th scope=\"col\">GDPR Overview:<\/th><td><a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/<\/a><\/td><\/tr><tr><th scope=\"col\">Privacy notices:<\/th><td>\n<p><a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/individual-rights\/right-to-be-informed\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/individual-rights\/right-to-be-informed\/<\/a><\/p>\n<p><a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-and-privacy-privacy-notices\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/www.gov.uk\/government\/publications\/data-protection-and-privacy-privacy-notices<\/a><\/p>\n<p><a href=\"https:\/\/www.gov.uk\/guidance\/data-protection-how-we-collect-and-share-research-data\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/www.gov.uk\/guidance\/data-protection-how-we-collect-and-share-research-data<\/a><\/p>\n<\/td><\/tr><tr><th scope=\"col\">Data Security (ICO)<\/th><td><a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/security\/\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/security\/<\/a><\/td><\/tr><tr><th scope=\"col\">School procurement:<\/th><td><a href=\"https:\/\/www.gov.uk\/government\/publications\/school-procurement-selecting-a-school-mis\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/www.gov.uk\/government\/publications\/school-procurement-selecting-a-school-mis<\/a><\/td><\/tr><tr><th scope=\"col\">Responsible for Information<\/th><td><a href=\"http:\/\/www.nationalarchives.gov.uk\/information-management\/training\/responsible-for-information-csl-course\/#_blank\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">http:\/\/www.nationalarchives.gov.uk\/information-management\/training\/responsible-for-information-csl-course\/#_blank<\/a><\/td><\/tr><tr><th scope=\"col\">Cloud software services:<\/th><td><a href=\"https:\/\/www.gov.uk\/government\/publications\/cloud-software-services-and-the-data-protection-act#_blank\" rel=\"external noopener noreferrer\" data-wpel-link=\"external\">https:\/\/www.gov.uk\/government\/publications\/cloud-software-services-and-the-data-protection-act#_blank<\/a><\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>The UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018) mandate certain safeguards regarding the use of personal data by [&hellip;]<\/p>\n","protected":false},"author":748,"featured_media":0,"parent":107,"menu_order":19,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":"","_links_to":"","_links_to_target":""},"class_list":["post-4366","page","type-page","status-publish","hentry"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-05-08 07:05:57","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/pages\/4366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/users\/748"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/comments?post=4366"}],"version-history":[{"count":4,"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/pages\/4366\/revisions"}],"predecessor-version":[{"id":28471,"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/pages\/4366\/revisions\/28471"}],"up":[{"embeddable":true,"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/pages\/107"}],"wp:attachment":[{"href":"https:\/\/www.devon.gov.uk\/support-schools-settings\/wp-json\/wp\/v2\/media?parent=4366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}