POLICY STATEMENT
SCOPE OF THE POLICY
DEFINITIONS
ROLES AND RESPONSIBILITIES
You can reach out to the DPO with any questions or concerns about data protection at dpo@pembrokehouse.com
PRINCIPLES OF DATA PROTECTION
PRIVACY BY DESIGN AND BY DEFAULT
GUIDELINES FOR HANDLING PERSONAL DATA RELATING TO SCHOOL VISITORS
Types of Data Collected:
When handling visitors’ data as part of your job requirements, take note of the following:
Example: When a visitor arrives at the school, ask them to sign in and provide their name, identification information, contact information, and purpose of visit. All visitors must always wear badges.
HANDLING PERSONAL DATA RELATED TO PARENTS AND PUPILS
Types of Data Collected:
When handling parents and pupils’ data as part of your job requirements, take note of the following:
Practical Example: School Event Registration: When organising a school event, collect only the information required for the event, such as the names of attendees and emergency contact details. Avoid asking for unnecessary details like medical history unless it is relevant to the event (e.g., a sports day).
HANDLING EMPLOYEE-RELATED DATA
Types of Data Collected:
When handling employee data as part of your job requirements, take note of the following:
Practical Example: During onboarding, collect only the necessary data from new staff, such as bank details for payroll and emergency contact information. Ensure that sensitive data, such as medical history, is collected only if it directly impacts job performance or workplace safety.
HANDLING HEALTH INFORMATION
Types of Data Collected:
When handling health data as part of your job requirements, take note of the following:
Practical Example: Before a school field trip, collect updated health information and emergency contacts for all participating pupils. Ensure that teachers and trip organisers have access to this information during the trip. In addition, if a pupil has a medical emergency, provide the relevant health information (e.g., allergies, chronic conditions) to emergency responders to ensure they can provide appropriate care.
HANDLING ALUMNI DATA
Types of Data Collected:
Practical Example: When organising an alumni event, collect only the necessary information such as names, contact details, and RSVP status. Ensure that you obtain consent from the alumni and that data used for event organisation is protected and used solely for the event’s purpose.
DATA SUBJECT RIGHTS
WORKING WITH THIRD PARTIES
RESPONDING TO A PERSONAL DATA BREACH
In the event of a personal data breach:
CONSEQUENCES OF NON-COMPLIANCE
Non-compliance with this policy can result in: –
MONITORING AND REVIEW
This Policy shall be reviewed annually, or more frequently if appropriate, to be consistent with future developments, industry trends and/or any changes in legal or regulatory requirements.