| Policy Details | |||
|---|---|---|---|
| Policy Owner | Deputy Chief Executive | ||
| CE Sponsor | Principal & Chief Executive | ||
| Date created this year | 26 February 2025 | ||
| Version: | Approved by: | Date approved: | To be reviewed: |
| 1 | College Executive | 28 February 2025 | March 2026 |
| 1 | Audit & Risk Committee | 06 March 2025 | March 2026 |
| Version Control | |||
| Version Number | Changes from previous 12 months policy | ||
| 1 | Updates to job titles throughout the policy | ||
| Change of responsibility for student information to Deputy Principal | |||
| Addition of Data Protection Principles on page 3 | |||
| Yes/No | Comments | ||
| 1 | Does the policy/guidance affect one group less or more favourably than another on the basis of: | ||
|---|---|---|---|
| Race or ethnicity | No | ||
| Disability | No | ||
| Gender | No | ||
| Religion or belief | No | ||
| Sexual orientation | No | ||
| Age | No | ||
| Marriage and Civil Partnership | No | ||
| Maternity and Pregnancy | No | ||
| Gender Reassignment | No | ||
| 2 | Is there any evidence that some groups are affected differently? | No | |
| 3 | If you have identified potential discrimination, are any exceptions valid, legal and/or justifiable? | N/A | |
| 4 | Is the impact of the policy/guidance likely to be negative? | No | |
| 5 | If so, can the impact be avoided? | N/A | |
| 6 | What alternatives are there to achieving the policy/guidance without the impact? | N/A | |
| 7 | Can we reduce the impact by taking different action? | N/A |
Colchester Institute needs to retain information about its staff, students and other stakeholders to allow it to carry out its day-to-day business activities and deliver its strategic objectives, as well as meet legal obligations including data requirements of funding agencies and statutory bodies.
The lawful and correct treatment of personal information is of paramount importance to the organisation and to maintain confidence with all our stakeholders, whoever they are in the wide range of activities we undertake. Through dissemination of this policy we will ensure that the College treats all personal information, including special category data (sensitive personal information) lawfully and correctly.
With the emergence of the General Data Protection Regulation (GDPR), the Government aligned UK law with new EU requirements through the adoption of the Data Protection Act 2018 (‘the Act’) in May 2018. To comply with the provisions of the Act, the College takes steps to ensure that personal information is collected only where necessary, is stored securely, and is used in accordance with the data protection principles:
Lawfulness, fairness and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality (security)
Accountability
It follows that all data is:
The purpose of this policy is to ensure that everyone handing personal information is:
Scope (information covered by the Act)
‘Personal data’ covered by the Act is essentially any recorded information (paper and electronic) which identifies a living individual.
Personal Data
To identify an individual, Colchester Institute considers ‘Personal data’ to be:
Special Category Data (previously referred to as Sensitive Personal Data)
As this type of data could create more significant risks to a person’s fundamental rights and freedoms, it requires more protection. Generally speaking, in order to process such data there must be a lawful basis in addition to satisfying a condition under article 9 (2) of the GDPR** (See below). The College will generally use explicit consent to process the following special category data:
Any information relating to an individual’s racial or ethnic origin, political opinions, religious beliefs, trade union activities, physical or mental health, physical disabilities, medical, geometric or biometric data, sexual life, sexual orientation
Whilst details of criminal convictions, care needs, physical disabilities are no longer included under the strict definition (GDPR), for the purposes of Colchester Institute these and any other data of equivalent personal standing, shall be included as ‘Special Category Data’ and require special protection.
Individual Rights
The College understands its requirements with regard to the Act and supporting individuals rights when it comes to personal data held or processed by the College.
Responsibilities
In order to respond to the requirements of the Act, Colchester Institute will:
Processes
All personal data will be obtained, as far as possible, from the individual and they will be informed at the time of providing the information, as to how their personal data will be used, in support of the provision of college education and training services and any other related activities.
• Personal data will only be collected for justified reasons and specified purposes. These will normally be communicated, in advance, to the person concerned.
• Personal data processed should be accurate, valid and restricted to that which is necessary to satisfy requirements.
• Special Category Data (Sensitive personal data) may normally only be processed if the person has given their explicit consent. (See page 3)
Important
The security of employee and student data should be comprehensively protected against unauthorised access, improper use, accidental loss, destruction and/or damage, by being kept in locked storage, password protected, or by using other suitable precautions.
Electronic Special Category Data must be password protected and/or encrypted.
External hard drives, memory sticks, unencrypted laptops and personal cloud storage must not be used to store sensitive data. Staff must take all precautions necessary to maintain confidentiality of all such information whilst in their possession, whether in soft copy or hard copy. The IT Security policy must be followed at all times and staff must exercise extreme care when transmitting special category data by email (internally or externally – password protection must always be used).
Personal information should not be disclosed either orally or in writing or accidentally or otherwise to any unauthorised third party. Staff should note that unauthorised disclosure will usually be a disciplinary matter and may be considered gross misconduct in some cases.
Information on authorised access and disclosure for students is included on the College enrolment form. All staff must ensure they confirm any disclosure is authorised and ensure they follow appropriate processes. (Appendix B “Procedure for Police Enquiries/Attendance on Site)
Colchester Institute will ensure:
Obligation of Staff
Obligation of students
Technical Security
The College has in place appropriate security measures as required by the Act. Information systems are installed with adequate security controls and all employees who use these systems will be properly authorised to use them for college business.
The IT Security Policy will be published on the College sharepoint. The College relies on computer servers to store data, and will maintain up-to-date antivirus software and appropriate firewalls. Regular back-ups and robust processes for disabling accounts as people leave are in place. Accounts are controlled via groups to ensure only those that need to know certain information have access to that information. A Mobile Device Acceptable Use Policy covers mobile security access control. The wireless access points used at the College all require authentication to be used and cannot be accessed by unauthorised persons. The College ensures all emails are scanned with appropriate software and staff training records are maintained by People and Culture. The College will test the strength of its IT Security Controls from time to time using external expertise and will secure Cyber Essentials Certification annually as a minimum.
Designated Data Controllers
The College has designated Data Controllers with responsibilities for employee and student records as detailed below. Data Controllers determine the purposes for which and the manner in which personal data is processed. They also ensure the sharing of information is undertaken in accordance with this policy.
Director of People and Culture – employee records
Head of Admissions, Registrations and Exams – student records
Director of Estates – CCTV
Breach Reporting
The College is required to notify the ICO in the event of a data security breach. Any staff member who is concerned about data loss must immediately contact the College’s nominated Data Protection Officer (DPO). This is Alison Bennett, Head of Governance. Contact details are reproduced below:
Email: dpo@colchester.ac.uk
Tel: 01206 712606
The Data Protection Officer will investigate any concern from the details provided. The person reporting the breach must provide as much information as possible in order for the investigation to take place. The DPO will involve Data Controllers and members of the College Executive as required. The outcome of the investigation will determine whether there will be a requirement to report the breach to the ICO under relevant guidelines
Entitlement to Access to Personal Data
Employees and students are entitled to make a formal request to access any personal data which is being used or “processed” by a computerised system and personal information kept about them as part of a “relevant filing system”. Requests must be made in writing as stated below. The College aims to comply with requests for access to personal information as quickly as possible and will ensure that it is provided within 40 days of the request.
Employees
Employees wishing to access such personal data must complete the Subject Access Request Form (see appendix A) and submit to the Director of People and Culture (Data Controller – employees).
Students
Students wishing to access such personal data should complete the Subject Access Request form (see Appendix A) which is also available from the Registry Department at the Colchester campus or Information Centre at Braintree. In some cases we may need to ask for proof of identification before the request can be processed
Rights of people (detailed on page 5 under responsibilities)
To ask the organisation to take any of these steps, the individual should send the request to dpo@colchester.ac.uk
Sharing information with parents
The student declaration on the enrolment form includes the statement “I understand that Colchester Institute may contact my parent/guardian regarding my attendance, progress, achievement, wellbeing, welfare and personal safety until the end of the academic year in which turn 18 years of age”, which provides consent for us to share appropriate information, including following up attendance, sending reports home and discussions at parent events.
If a parent/guardian of a student in this age range requests information about their son or daughter than this can be released provided they are named as the next of kin on EBS or ProMonitor and that the member of staff releasing the information has taken steps to ensure the authenticity of the enquirer, and the accuracy of the information given. To eliminate errors as many checks as possible relating to the subject of the inquiry must be made, e.g.
If the staff member is not satisfied that the enquirer is not genuine, or the named next of kin, then they must not release the information.
A student can provide up to date information about their next of kin at Registry or one of the Information Centres.
Students 19 and over
No information can be shared with the parent/guardian of a student aged 19 or over without the express consent of the student.
Personal Data and Academic References
All requests must be in in writing. The student’s permission will be required before the information is released. This will either be by the consent given at enrolment on the enrolment form, or if outside the remit of the criteria on the privacy statement additional written consent from the student will be required before any information is released. All written requests should be sent to:-
Personal Data:- Registry Department, Colchester Institute, Sheepen Road, Colchester, CO3 3LL
Academic References:- Requests should be emailed to academic.references@colchester.ac.uk
Any query regarding the implementation of this procedure or if individual cases occur where a member of staff is uncertain, reference must be made in the first instance to the relevant Data Controller. In no circumstances should students or other enquirers be given private addresses or telephone numbers of staff or other students.
See Appendix A, Procedures for the Release of Student Data for more information, including requests from individuals or agencies
Any other requests for information from external agencies should be referred in the first instance to Registry for action under these procedures.
College Publications
Personal information in the public domain for genuine business purposes, such as names, job titles, etc. included in marketing publications, telephone directory, notice boards, is exempt from the Act. However, any employee or student who has good reason for wishing to be excluded from such public information should contact the relevant Data Controller.
Use of CCTV
The College’s Closed Circuit Television Code of Practice complies with the ICO’s CCTV Code of Practice and is the responsibility of the Security Manager. Please refer to the College’s CCTV Code of Practice
Disposal of Confidential Waste
Employees must ensure that they dispose of all personal and sensitive data securely. E.g. Using the confidential waste bags or shredders. Documentation containing special category data must be kept secure whilst waiting to be confidentially shredded (eg Shredding sacks half-filled must be locked away). No documentation containing sensitive personal data will be placed in waste paper or re-cycling bins.
Other Relevant / Associated Policies Documents:
• CCTV Code of Practice
• IT Security Policy
• Mobile Device Acceptable Use Policy
• Retention of Records Policy
• Staff Disciplinary Policy