General Data Protection Regulations (GDPR)
Exceed Academies Trust is committed to being transparent about how it collects and uses data in order to meet its data protection obligations under the General Data Protection Regulations (GDPR).
We’ve spent a lot of time reviewing our responsibilities under GDPR and like to think we’ve been thoughtful about its intent and meaning. We have undertaken a full information audit (March 2018) across the organisation and will continue to do so in order to maintain a record of all of our processing activities.
The Trust has appointed Ruth Jarvis as its Data Protection Officer (DPO). The role of the DPO is to inform and advise the Trust on its data protection obligations. The DPO can be contacted at email@example.com. Questions about our policies, or requests for further information, should always be directed to the Data Protection Officer in the first instance.
The Trust may however, from time to time, be required to share personal information about its employees, service users, pupils, students or its Exceed trainees with other organisations, mainly the LA, Department for Education, National College, other schools / educational bodies or potentially social services etc. This is classed as lawful basis to process personal data.
The lawful basis for your processing data can also affect which rights are available to individuals. For example:
|Right to Erasure||Right to Portability||Right to Object|
*but right to withdraw consent
What are the lawful bases for processing?
The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever you process personal data:
(a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations).
(d) Vital interests: the processing is necessary to protect someone’s life.
(e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)
The Trust has drafted a number of policies to ensure all staff, trustees and governors are aware of their responsibilities and outlines how the Trust complies with the following core principles of the GDPR.
The general Trust policies relating to data protection are:
- Data Protection Policy
- CCTV Policy
- Subject Access Policy
- Data Breach Policy
- Recruitment Privacy Notice
- Workforce Privacy Notice
- Parent Privacy Notice
- Pupil Privacy Notice
We keep a record of when and how we got consent from the individual.
Should you wish to withdraw consent please complete the following form:
We act on withdrawals of consent as soon as we can.