Privacy Notice 2022
Privacy Notice for the Exmoor Federation
Our school needs to use data on pupils in order to be able to keep you safe and deliver the best education possible. Only essential data is held, and we always follow the law when we collect use, store and share your data. The Federation's Data Protection Policy can be found here: Model Data Protection Policy (primarysite-prod-sorted.s3.amazonaws.com)
You have a legal right to be informed about how our school uses any personal information that we hold about you. This privacy notice explains how we collect, store and use personal data about you.
We have updated this privacy notice with information about how we may share your data for ‘test and trace’ services to support public health.
We, The Exmoor Federation, are the ‘data controller’ for the purposes of data protection law.
Our Data Protection Officer (DPO) is Amy Brittan (see ‘Contact us’ below).
The personal data we hold on you
We hold some personal information about you to make sure we can help you learn and look after you at school.
For the same reasons, we get information about you from some other places too – like other schools, the local council and the government.
This information includes but is not limited to:
- Your contact details
- Assessments of your work
- Your attendance records
- Your characteristics, like your ethnic background or any special educational needs
- Any medical conditions you have
- Details of any behaviour issues or exclusions
- Photographs
The personal data we hold on your parents
We hold some personal information about your parents to make sure we can help you learn and look after you at school.
- Contact details
- Payment details (for nursery fees)
- Payment details (if using a payment system where the data is stored in school and not with the payment company)
- We may also hold some information about your parents if you have a safeguarding folder
Why we use this data
We use this data to help run the school, including to:
- Get in touch with you and your parents when we need to
- Check how you’re doing in all subjects and work out whether you or your teachers need any extra help
- Provide remote learning opportunities during periods of lockdown
- Track how well the school as a whole is performing
- Look after your wellbeing
Our legal basis for using this data
- We need to comply with the law (Article 6(1)(c) of UK GDPR)
- We need to use it to carry out a task in the public interest (in order to provide you with an education) (Article 6(1)(e) of UK GDPR)
Sometimes, we may also use your personal information where:
- You, or your parents/carers have given us permission to use it in a certain way (Article 6(1)(a) of UK GDPR)
- We need to protect your interests (or someone else’s interest) e.g. in a life or death situation (Article 6(1)(d) of UK GDPR)
We may also collect and use information about your health or other protected characteristics such as your religion or ethnicity. These are special categories of personal information, and we will only collect and use it when it is necessary for public health, e.g. protecting against serious threats to health. The legal basis here is Article 9(2)(i) of UK GDPR.
Public Health England also has special permission from the Secretary of State for Health and Social Care to use personally identifiable information without your permission where this is in the public interest. This is known as ‘Section 251’ approval and includes the use of the information collected by NHS Test and Trace to help protect the public from coronavirus. The part of the law that applies here is Section 251 of the National Health Service Act 2006 and the associated Health Service (Control of Patient Information) Regulations 2002.
Where we have got permission to use your data, you or your parents/carers may withdraw this at any time. We will make this clear when we ask for permission and explain how to go about withdrawing consent.
Some of the reasons listed above for collecting and using your information overlap, and there may be several grounds which mean we can use your data.
Collecting this information
While in most cases you, or your parents/carers, must provide the personal information we need to collect, there are some occasions when you can choose whether or not to provide the data. We will always tell you if it’s optional. If you must provide the data, we will explain what might happen if you don’t.
Data sharing
We do not share personal information about you with anyone outside the school without permission from you or your parents/carers, unless the law and our policies allow us to do so.
Where it is legally required, or necessary for another reason allowed under data protection law, we may share personal information about you with:
Who we share with | Why we share |
Our local authority | To meet our legal duties to share certain information with it, such as concerns about pupils’ safety and exclusions |
The Department for Education | We have to do this by law. This data sharing underpins school funding, educational policy and funding |
Your family and representatives | To ensure that they know how you are doing and to protect your welfare |
Police forces, courts, tribunals and security services | As we are required to by law |
Educators and examining bodies
| To ensure that you are entered for exams and your results are recorded |
Health and social welfare organisations
| Such as the school nurse and the Education Welfare Officer to help look after your health and wellbeing |
Our payment service providers | So that you can pay for meals, trips resources and activities.
|
Providers of electronic learning resources | To allow you to use their resources in class and at home |
Google Classroom | A suite of online tools that can be used by the school. The tools include a class ‘blog’, the ability for us to set tasks for learners and provide feedback. It has online software including Google versions of Word, PowerPoint and Excel. |
International transfers of personal data
We have audited where we store all the personal data processed in school and by third party services. If a third party service stores data in the EU or US, we have ensured that safeguards such as standard contractual clauses are in place to allow the safe flow of data to and from the school.
How we store this data
We will keep personal information about you while you are a pupil at our school. We may also keep it after you have left the school, where we are required to by law.
Our record retention schedule/records management policy is based on the Information and Records Management Society’s toolkit for schools and sets out how long we keep information about pupils.
National Pupil Database
We are required to provide information about you to the Department for Education (a government department) as part of data collections such as the school census.
Some of this information is then stored in the National Pupil Database, which is managed by the Department for Education and provides evidence on how schools are performing. This, in turn, supports research.
It is held in electronic format for statistical purposes. This information is securely collected from a range of sources including schools, local authorities and awarding bodies.
To find out more about the NPD, go to https://www.gov.uk/government/publications/national-pupil-database-user-guide-and-supporting-information
Sharing by the Department for Education (DfE)
The law allows the Department to share pupils’ personal data with certain third parties, including:
schools and local authorities
researchers
organisations connected with promoting the education or wellbeing of children in England
other government departments and agencies
organisations fighting or identifying crime
For more information about the Department’s NPD data sharing process, please visit:
https://www.gov.uk/data-protection-how-we-collect-and-share-research-data
Organisations fighting or identifying crime may use their legal powers to contact the DfE to request access to individual level information relevant to detecting that crime. Whilst numbers fluctuate slightly over time, the DfE typically supplies data on around 600 pupils per year to the Home Office and roughly 1 per year to the Police.
For information about which organisations the Department has provided pupil information, (and for which project) or to access a monthly breakdown of data share volumes with Home Office and the Police please visit the following website: https://www.gov.uk/government/publications/dfe-external-data-shares
Your rights
How to access personal information we hold about you
You can find out if we hold any personal information about you, and how we use it, by making a ‘subject access request’, as long as we judge that you can properly understand your rights and what they mean.
If we do hold information about you, we will:
- Give you a description of it
- Tell you why we are holding and using it, and how long we will keep it for
- Explain where we got it from, if not from you or your parents
- Tell you who it has been, or will be, shared with
- Let you know if we are using your data to make any automated decisions (decisions being taken by a computer or machine, rather than by a person)
- Give you a copy of the information
You may also ask us to send your personal information to another organisation electronically in certain circumstances.
If you want to make a request please contact our data protection officer.
How to find out what personal information the DfE hold about you
Under the terms of the Data Protection Act 2018, you are entitled to ask the Department:
- if they are processing your personal data
- for a description of the data they hold about you
- the reasons they’re holding it and any recipient it may be disclosed to
- for a copy of your personal data and any details of its source
If you want to see the personal data held about you by the Department, you should make a ‘subject access request’. Further information on how to do this can be found within the Department’s personal information charter that is published at the address below:
To contact the DfE: https://www.gov.uk/contact-dfe
Your other rights over your data
You have other rights over how your personal data is used and kept safe, including the right to:
- Say that you don’t want it to be used if this would cause, or is causing, harm or distress
- Stop it being used to send you marketing materials
- Say that you don’t want it used to make automated decisions (decisions made by a computer or machine, rather than by a person)
- Have it corrected, deleted or destroyed if it is wrong, or restrict our use of it
- Claim compensation if the data protection rules are broken and this harms you in some way
Complaints
We take any complaints about how we collect and use your personal data very seriously, so please let us know if you think we’ve done something wrong.
You can make a complaint at any time by contacting our data protection officer.
You can also complain to the Information Commissioner’s Office in one of the following ways:
- Report a concern online at https://ico.org.uk/concerns/
- Call 0303 123 1113
- Write to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact us
If you have any questions, concerns or would like more information about anything mentioned in this privacy notice, please contact our data protection officer:
Amy Brittan DPO Schools dposchools@somerset.gov.uk
This notice is based on the Department for Education’s model privacy notice for pupils, amended to reflect the way we use data in this school.