GDPR

Text

Text

At Tyntesfield Primary School, we are committed to protecting the privacy of everyone in our school community. This includes pupils, parents and carers, staff, governors and partners.

How we collect, use and protect personal information

We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These laws explain how personal information must be collected, used, kept safe and shared.

This Privacy Notice explains:

  • what personal data we collect

  • why we collect it

  • how we use and protect it

  • who we share it with

  • your rights

Expanders

Expanders

  • Who is responsible for your data?

    Tyntesfield Primary School is the data controller.

    This means we decide how and why personal data is used.

    The Headteacher acts on behalf of the school for data protection matters and will consult with the DPO (Judicium) for advice and support where required.

    Contact details:

    📧 Tyntesfieldadmin@inspiringlearners.co.uk 

  • Why we collect and use personal data

    We collect and use personal data to:

    • support pupil learning and development

    • monitor and report on pupil progress

    • provide pastoral care and meet safeguarding duties

    • manage admissions, attendance and behaviour

    • assess and improve the quality of our provision

    • communicate with parents, carers and partners

    • meet our legal duties under education law

  • Lawful basis for processing data

    We process personal data under the lawful bases set out in Articles 6 and 9 of UK GDPR, including:

    • legal obligation

    • public task (education and safeguarding duties)

    • consent (where required)

    We also comply with education and safeguarding legislation, including requirements set by the Department for Education (DfE).

  • What information we collect

    Pupil Information Parent/Carer Information Governor Information

    This may include:

    • name, date of birth, address and pupil number

    • attendance and assessment information

    • behaviour and safeguarding records

    • medical and health information

    • Special Educational Needs and Disabilities (SEND) information

    • ethnicity, language and nationality

    • eligibility for free school meals

    • photographs and images used for school purposes

    This may include:

    • names and contact details

    • emergency contacts

    • relationship to the child

    • payment information for school services

    This may include:

    • name and contact details

    • declaration of interests

    • DBS status

    • appointment, training and attendance records

  • How we collect information

    We collect information from:

    • admission and registration forms

    • communication with parents and carers

    • consent forms

    • school management systems

    • approved educational platforms

    We may also receive information from third parties, such as previous schools or the Local Authority. All information is handled in line with data protection law.

  • Who we share information with

    We only share personal data where the law allows or requires us to do so. This may include sharing information with:

    • the Department for Education (DfE), including the National Pupil Database

    • the Local Authority

    • safeguarding and child protection agencies

    • health services (for example, school nursing or vaccination programmes)

    • approved software providers and service suppliers

    All third‑party providers must keep data safe and use it only for agreed purposes.

    We do not share personal data for marketing purposes.

  • How long we keep information (retention)

    We keep personal data only for as long as necessary.

    Retention periods follow:

    • school and Trust retention schedules

    • legal and safeguarding requirements

    • guidance from the DfE

    When information is no longer needed, it is securely deleted or destroyed according ot our Tryst Data Retention Policy.

  • How we keep data safe

    We take appropriate technical and organisational measures to protect personal data from:

    • loss or theft

    • unauthorised access

    • accidental disclosure

    • misuse

    Access to personal data is limited to authorised staff and approved providers only.

  • Your rights

    Under UK GDPR, individuals have the right to:

    • be informed about how their data is used

    • access their personal data

    • request correction of inaccurate information

    • request deletion (in some circumstances)

    • restrict or object to processing

    • withdraw consent where consent is used

    Requests should be made in writing to the school office.

  • Data Protection Officer (DPO)

    The Trust has appointed a Data Protection Officer (DPO) who provides independent advice and oversight.

    Trust DPO details:

    Judicium Consulting Limited

    📍 72 Cannon Street, London, EC4N 6AE

    📧 dataservices@judicium.com 

    🌐 www.judiciumeducation.co.uk 

    ☎️ 0203 326 9174

    Lead Contact: Craig Stilwell

    You may contact the DPO if you have concerns about how personal data is being handled.

  • Complaints

    If you have concerns about how we use personal data, please contact the school in the first instance.

    You also have the right to complain to the Information Commissioner’s Office (ICO):

    ☎️ 0303 123 1113

    🌐 https://ico.org.uk 

Text

Text

Changes to this Privacy Notice

This Privacy Notice is reviewed regularly and updated when necessary to reflect changes in legislation, guidance or school practice.

Policies

Policies