General Data Protection Regulations (GDPR) for Schools 

Schools handle a large amount of personal data. This includes information on pupils, staff, governors, volunteers and job applicants.

Schools also handle what the GDPR refers to as special category data such as race, ethinic origin or trade union membership.

GDPR requires organisations to document how and why they process all personal data and gives rights to the individual.

GDPR has six main principles which states that personal data should be:

  • Processed fairly, lawfully and in a transparent manner
  • Used for  specified, explicit and legitimate purposes
  • Used in a way that is  adequate, relevant and limited
  • Accurate and up to date
  • Kept no longer than necessary
  • Processed in a manner that ensures appropriate security of the data

 

Click to Download Data Protection [pdf 278KB] Click to Download
Click to Download Protection of Biometric Information of Children in Schools [pdf 433KB] Click to Download
Click to Download Integra Privacy Notice - Pupils [pdf 181KB] Click to Download
Click to Download Retention of Records 23 [pdf 855KB] Click to Download
Click to Download Subject Access Request Policy and Procedure [pdf 681KB] Click to Download