I. WHAT IS THE PURPOSE OF THIS DOCUMENT?
Where we refer in this policy to your ‘personal data’, we mean any recorded information that is about you and from which you can be identified, whether directly or indirectly. It does not include data where your identity has been removed (anonymous data). Where we refer to the ‘processing’ of your personal data, we mean anything that we do with that information, including collection, use, storage, structuring, disclosure or deletion.
III. WHO IS USING YOUR PERSONAL DATA?
Linacre College is the “data controller” for the information that we hold about you as a student or former student. This means that we decide how to use it and are responsible for looking after it in accordance with the GDPR. Access to your student record and other data will be provided to the academic and support staff, who need to view it as part of their work in carrying out the purposes set out in Section VI. It will also be shared with the third parties described in Section VIII.
IV. THE TYPES OF DATA WE HOLD ABOUT YOU
The information we hold about you may include the following:
Personal details such as name, title, address, telephone number, email address, marital status, nationality, date of birth, sex and gender identity, ID Photograph, household income, parental status, details of dependants; Revised August 2019
Emergency contact information;
National Insurance number (where you have voluntarily provided it);
Education and employment information (including the school(s), sixth form college(s) and other colleges or universities you have attended and places where you have worked, the courses you have completed, dates of study and examination results);
Other personal background information collected during the admissions process, such as dietary requirements;
Examination records (including records relating to assessments of your work, details of examinations taken, and your predicted and actual examination grades);
Information captured in your student record including progression, achievement of milestones and progression reports;
Visa, passport and immigration information;
Fees and financial support record (including records relating to the fees paid, Student Loan Company transactions and financial support, scholarships, and sponsorship);
Supervision, teaching, and tutorial activities; and training needs analysis and skills acquisition records;
Placement and internship record or study at another institution as an established component of your course of studies, or career development opportunity;
Information about your engagement with the Language Centre, Careers Support, University sport facilities and the Counselling Service;
Information about your use of library facilities, including borrowing and fines;
Information about disciplinary actions (including academic misconduct), dispensations from regulations, and about any appeals and complaints raised;
Attendance at University degree and award ceremonies; and
Information about your use of our information and communications systems;
Information from our security systems, including CCTV and building access information. We may also process the following “special categories” of more sensitive personal data:
Information about your race or ethnicity;
Information about your health, including any disability and/or medical condition;
Information about criminal convictions and offences, including proceedings or allegations. Revised August 2019
V. HOW THE COLLEGE OBTAINED YOUR DATA
The University collects the vast majority of the information directly from you, through the application process and during on line registration. Some of this is then passed to College. We may also collect additional information from third parties, including other colleges, higher education institutions, and government departments and agencies. We will collect and generate additional information about you throughout the period of your study.
VI. HOW LINACRE COLLEGE USES YOUR DATA
We process your data for a number of purposes connected with your studies, including teaching, academic assessment and supervision, pastoral support, funding and financial support, research related administration, discipline or the provision of facilities and services e.g. access to IT facilities, libraries, accommodation, etc. We set out below those circumstances where it is necessary for us to process your data. (These circumstances are not mutually exclusive; we may use the same information under more than one heading.)
1. Because we have a contract with you We need to process your data in order to meet our obligations or exercise rights under our contract with you. Information processed for this purpose includes, but is not limited to, the data listed in section IV. We also need to process your data under this heading where Linacre College is working with a third party in order to offer you services, for example, sponsors (such as research councils) or scholarship benefactors. See section VIII for further information on the sharing of data with third parties.
2. Where it is necessary to meet a task in the public interest As indicated above, we need to process your data for the purpose academic assessment and supervision. Information processed under this heading includes, but is not limited to, the data listed in section IV.
3. Where it is necessary to meet our legitimate interests We need to process your data in order to meet our legitimate interests relating to student administration, alumni relations or similar activities; or to meet the legitimate interests of others.
4. Where we have your consent There may be situations where we ask for your consent to process your data e.g. where we ask you to volunteer information about yourself for a survey or where we ask for your permission to share sensitive information. If you fail to provide personal information under VI1 above If you fail to provide certain information when requested under the circumstances described in VI1 above, we may not be able to meet our contractual obligations to you or comply with our other legal obligations. Revised August 2019 Change of purpose We will only process your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another related reason and that reason is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will seek your consent to use it for that new purpose. Please note that we may process your data without your knowledge or consent, where this is required or permitted by law.
VII. SPECIAL CATEGORY DATA AND CRIMINAL CONVICTION DATA
Special category data and criminal conviction data require a higher level of protection. Listed below are examples of processing activities that we regularly undertake in respect of these types of data. In addition to the activities listed below, it may sometimes be necessary to process this sort of information for exceptional reasons, for example, because it is necessary to protect your vital interests or those of another person.
1. Health (Including disability) We will process data about your health where it is necessary to make reasonable adjustments for disability and/or to monitor equal opportunities. Processing of this nature is necessary to meet contractual or other legal obligations. There may also be situations where we ask for your explicit consent to share information about your health.
2. Criminal conduct (including convictions, proceedings or allegations) Data about certain unspent criminal convictions, including whether or not you have such a conviction, is gathered during the process of applying for a course with the University once you have been offered a place. Data about barring decisions will only be collected if you have applied for and been accepted onto certain courses, and where we are legally required to do so. Processing of this nature is carried out in order to protect our legitimate interests including to protect members of the University and College community from a foreseeable risk of harm. For certain courses this processing is also necessary to meet our legal obligations. Such processing will be subject to suitable safeguards. We may also process data about criminal conduct while you are on course in accordance with the terms of our contract with you, in order to comply with our legal obligations or to meet our legitimate interests, including protecting other individuals from a foreseeable risk of harm and for disciplinary purposes. Such processing will be subject to suitable safeguards.
3. Racial or ethnic origin, sexual orientation Data about your racial and ethnic origin and sexual orientation will only be processed where you have volunteered it and where we need to process it in order to meet our statutory obligations under equality and/or other legislation. This processing is considered to meet a substantial public interest, and will be subject to suitable safeguards.
VIII. DATA SHARING WITH THIRD PARTIES
In order to perform our contractual and other legal responsibilities or purposes, we may, from time to time, need to share your information with the following types of organisation:
Revised August 2019
Recognised Independent Centres(For more information on Recognised Independent Centres visit http://www.ox.ac.uk/about/rics)
Your funders and/or sponsors, including the Student Loan Company and research councils;
If you have or are seeking a particular relationship with a third party, for example, other universities, schools, health care providers or providers of external training and placements;
Employers or prospective employers and other educational institutions;
Any relevant professional statutory regulatory bodies, including the General Medical Council;
Office for the Independent Adjudicator (OIA);
Relevant public bodies, including but not limited to the UK Home Office; HM Revenue and Customs; and local authorities;
The National Health Service or other medical practitioners (to support medical provision). Where information is shared with third parties, we will seek to share the minimum amount necessary. For example, we may share only your student number and not your name (this is known as pseudonymisation). All third-party service providers that process data on our behalf are required to take appropriate security measures to protect your data in line with our policies. We do not allow them to use your data for their own purposes. We permit them to process your data only for specified purposes and in accordance with our instructions.
IX. TRANSFERS OF YOUR DATA OUTSIDE OF THE EUROPEAN ECONOMIC AREA (EEA) [The EU plus Norway, Iceland and Lichtenstein]
There may be occasions when we transfer your data outside the EEA, for example, if we communicate with you using a cloud based service provider that operates outside the EEA or for scholarships where selection takes place overseas, or returns to bodies overseas such as those offering international opportunities. Such transfers will only take place if one of the following applies:
the country receiving the data is considered by the EU to provide an adequate level of data protection;
the organisation receiving the data is covered by an arrangement recognised by the EU as providing an adequate standard of data protection e.g. transfers to companies that are certified under the EU US Privacy Shield;
the transfer is governed by approved contractual clauses;
the transfer has your consent;
the transfer is necessary for the performance of a contract with you or to take steps requested by you prior to entering into that contract; Revised August 2019
the transfer is necessary for the performance of a contract with another person, which is in your interests;
the transfer is necessary in order to protect your vital interests or of those of other persons, where you or other persons are incapable of giving consent;
the transfer is necessary for the exercise of legal claims; or
the transfer is necessary for important reasons of public interest.
X. DATA SECURITY
We have put in place measures to protect the security of your information. Details of these measures (in line with the University’s Information Security Policy and Implementation Guidance) are available from the University’s Information Security website.
XI. RETENTION PERIOD
We will retain your data only for as long as we need it to meet our purposes, including any relating to legal, accounting, or reporting requirements. Details of the retention periods (in line with the University’s retention schedules) for different types of student data are available here.
XII. YOUR RIGHTS
Under certain circumstances, by law you have the right to: Request access to your data (commonly known as a “subject access request”). This enables you to receive a copy of your data and to check that we are lawfully processing it. Request correction of your data. This enables you to ask us to correct any incomplete or inaccurate information we hold about you. Request erasure of your data. This enables you to ask us to delete or remove your data under certain circumstances, for example, if you consider that there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your data where you have exercised your right to object to processing (see below). Object to processing of your data where we are processing it in order to meet our public interest tasks or legitimate interests (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your data for direct marketing purposes. Request the restriction of processing of your data. This enables you to ask us to suspend the processing of your data, for Revised August 2019 example if you want us to establish its accuracy or the reason for processing it. Request the transfer of your data to another party. Depending on the circumstances and the nature of your request it may not be possible for us to do what you have asked, for example, where there is a statutory or contractual requirement for us to process your data and it would not be possible to fulfil our legal obligations if we were to stop. However, where you have consented to the processing, you can withdraw your consent at any time. In this event, we will stop the processing as soon as we can. If you choose to withdraw consent it will not invalidate past processing. Further information on your rights is available from the Information Commissioner’s Office (ICO). If you want to exercise any of the rights described above or are dissatisfied with the way we have used your information, please contact the College’s Information Compliance Team at firstname.lastname@example.org. We will seek to deal with your request without undue delay, and in any event in accordance with the requirements of the GDPR. Please note that we may keep a record of your communications to help us resolve any issues which you raise. If you remain dissatisfied, you have the right to lodge a complaint with the ICO at https://ico.org.uk/concerns/.
XIII. KEEPING YOUR DATA UP-TO-DATE
It is important that the data we hold about you is accurate and current. Please keep us informed of any changes that may be necessary during your time at Linacre College.