Somerville College nursery attendees, parents, guardians and others with parental responsibility – privacy notice
Privacy notice – Somerville College nursery attendees, parents, guardians and others with parental responsibility
A summary of what this notice explains
Somerville College is committed to protecting the privacy and security of personal data.
This notice explains what personal data Somerville College holds about nursery attendees, parents, guardians and others with parental responsibility (“you”), how we use it internally, how we share it, how long we keep it and what your legal rights are in relation to it.
For the parts of your personal data that you supply to us to us, this notice also explains the basis on which you are required or requested to provide the information. For the parts of your personal data that we generate about you, or that we receive from others, it explains the source of the data.
There are some instances where we process your personal data on the basis of your consent. This notice sets out the categories and purposes of data where your consent is needed.
Somerville College has also published separate notices here, which are applicable to other groups and activities. Those notices may also apply to you, depending on your circumstances, and it is important that you read this privacy notice together with other applicable privacy notices including:
- current students
- security and monitoring activities
- current staff and senior members
What is your personal data and how does the law regulate our use of it?
“Personal data” is information relating to you as a living, identifiable individual. We refer to this as “your data”.
Data protection law requires Somerville College (“us” or “we”), as data controller for your data:
- To process your data in a lawful, fair and transparent way;
- To only collect your data for explicit and legitimate purposes;
- To only collect data that is relevant, and limited to the purpose(s) we have told you about;
- To ensure that your data is accurate and up to date;
- To ensure that your data is only kept as long as necessary for the purpose(s) we have told you about;
- To ensure that appropriate security measures are used to protect your data.
Somerville College’s Contact Details
If you need to contact us about your data, please contact: firstname.lastname@example.org
What personal data we hold about you and how we use it
We may hold and use a range of data about you at different stages of our relationship with you. We might receive this data from you; we might create it ourselves, or we might receive it from someone else (for example if someone provides us with a reference about you).
Categories of data that we collect, store and use include (but are not limited to):
- Contact details that you provide to us, including names, addresses and telephone numbers.
- Enrolment records, including application paperwork, details of hours requested, “All About Me” and similar documentation, and settling in arrangements.
- Copies of passports and/or birth certificates.
- Details of any medical issues and/or disabilities that are notified to us, including any consideration and decisions on reasonable adjustments made as a result.
- Attendance records.
- Development and learning records of attendees, including notes of discussions with parents, individual learning plans, projections, and assessments made by reference to the Early Years Foundation Scheme (where applicable).
- Intervention and behaviour management plans.
- Financial information including bank/building society account numbers, sort codes, credit/debit card numbers, childcare vouchers, childcare entitlements, invoices and outstanding payment information.
- Dietary requirements
- Equality monitoring data.
- Photographs, audio and video recording of nursery activities and events.
- Computing and email information, including parent site login information, IP address(es) and records of network access.
Further categories of data that we hold in relation to nursery attendees, parents, guardians and others with parental responsibility are set out in our Record of Processing Activity which may be viewed by contacting email@example.com.
The lawful basis on which we process your data
The law requires that we provide you with information about the lawful basis on which we process your personal data, and for what purpose(s).
Most commonly, we will process your data on the following lawful grounds:
- Where it is necessary to perform the contract we have entered into with you;
- Where necessary to comply with a legal obligation;
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
We may also use your personal information, typically in an emergency, where this is necessary to protect your vital interests, or someone else’s vital interests. In a small number of cases where other lawful bases do not apply, we will process your data on the basis of your consent.
How we apply further protection in the case of “Special Categories” of personal data
“Special categories” of particularly sensitive personal information require higher levels of protection. We need to have further justification for collecting, storing and using this type of personal information.
The Special Categories of personal data consist of data revealing:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership.
They also consist of the processing of:
- genetic data;
- biometric data for the purpose of uniquely identifying someone;
- data concerning health;
- data concerning someone’s sex life or sexual orientation.
We may process special categories of personal information in the following circumstances:
- With your explicit written consent; or
- Where it is necessary in the substantial public interest, in particular:
- for the exercise of a function conferred on Somerville College or anyone else by an enactment or rule of law; or
- for equal opportunities monitoring;
- Where the processing is necessary for archiving purposes in the public interest, or for scientific or historical research purposes, or statistical purposes, subject to further safeguards for your fundamental rights and interests specified in law.
We have in place appropriate policy documents and/or other safeguards which we are required by law to maintain when processing such data.
Less commonly, we may process this type of information where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent, or where you have already made the information public.
Criminal convictions and allegations of criminal activity
Further legal controls apply to data relating to criminal convictions and allegations of criminal activity. We may process such data on the same grounds as those identified for “special categories” referred to above.
Details of our processing activities, including our lawful basis for processing
Details of the lawful bases we rely on for the processing of the categories of data that we hold in relation to nursery attendees, parents, guardians and others with parental responsibility are set out in our Record of Processing Activity. Details of retention periods, plus details of parties to whom we transfer data, and on what basis, are available by contacting firstname.lastname@example.org.
Data that you provide to us and the possible consequences of you not providing it
Most data that you provide to us is processed by us in order that we, and you, can each fulfil our contractual obligations and/or comply with obligations imposed by law. For example:
- Copies of attendee passports and/or birth certificates are collected on enrolment, as proof of attendee identity and age, and are further required to confirm entitlement to state-funded childcare provision.
- Financial information, as listed above, must be provided as part of any contract for the provision of childcare services, to enable payments to be taken.
The consequences for any failure to provide such data will depend on the particular circumstances. For example, a failure to provide the relevant financial information will mean that we are unable to process any payment from you and may not be able to enter into the relevant contract with you.
Some data that you give to us is provided on a wholly voluntary basis – you have a choice whether to do so. Examples include:
- Equality monitoring data, which is requested by the nursery as part of the equality monitoring that we undertake pursuant to our legal obligations under the Equality Act 2010.
- Disability and health condition information, which you may choose to provide to us in order that we can take this information into account when considering whether to make a reasonable adjustment.
Other sources of your data
Apart from the data that you provide to us, we may also process data about you from a range of sources. These include:
- Data that we generate about you, such as during our communications with you, in the course of providing childcare to attendees, or producing relevant reports;
- Third parties who provide statutory or voluntary services to attendees and/or their families;
- Family members, friends, visitors to the nursery and other contacts who may provide us with information about you if and when they contact us, or vice versa.
Our Record of Processing Activity indicates the sources of each of the various categories of data that we process and may be viewed by contacting email@example.com.
How we share your data
We do not, and will not, sell your data to third parties. We will only share it with third parties external to the College if we are allowed or required to do so by law.
Examples of bodies to whom we may be required by law to disclose certain data include, but are not limited to:
|Agencies with responsibilities for the prevention and detection of crime, apprehension and prosecution of offenders.||For the prevention, detection or investigation of crime, for the location and/or apprehension of offenders, and/or for the protection of the public. [in cases where the law places a duty on us to report]|
|HM Revenues & Customs (HMRC)||Invoicing information to the extent required to fulfil Somerville College nursery’s tax reporting obligations.||
|Agencies with responsibilities for safeguarding minors||Early years providers have a duty under s.40 of the Childcare Act 2006 to comply with the welfare requirements of the Early Years Foundation Stage, including making appropriate referrals where there are concerns about the safety and well-being of a child.|
|OFSTED||To the extent necessary to comply with requirements surrounding inspections of our provision, or to address queries regarding our provision of EYFS services.|
|Local Authority departments with responsibility for managing the provision of state-funded childcare hours.||To the extent necessary to enable those departments to check compliance with requirements surrounding the provision of state-funded childcare.|
Examples of bodies to whom we may voluntarily disclose data, in appropriate circumstances, include but are not limited to:
|Third party service providers||To facilities activities of Somerville College nursery. Any transfer will be subject to an appropriate, formal agreement between Somerville College and the processor.|
|Agencies with responsibilities for the prevention and detection of crime, apprehension and prosecution of offenders.||For the prevention, detection or investigation of crime, for the location and/or apprehension of offenders, and/or for the protection of the public.|
Where information is shared with third parties, we will seek to share the minimum amount of information necessary to fulfil the purpose.
All our third party service providers are required to take appropriate security measures to protect your personal information in line with our policies, and are only permitted to process your personal data for specific purposes in accordance with our instructions. We do not allow our third party providers to use your personal data for their own purposes.
Sharing your data outside the European Union
The law provides various further safeguards where data is transferred outside of the EU.
When you are resident outside the EU in a country where there is no “adequacy decision” by the European Commission, and an alternative safeguard is not available, we may still transfer data to you which is necessary for performance of your contract with us .
We do not envisage that any decisions will be taken about you based solely on automated means, however we will notify you in writing if this position changes.
How long we keep your data
We retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purpose of satisfying any legal, accounting or reporting requirements.
Details of expected retention periods for the different categories of your personal information that we hold are set out in our Record of Processing Activity.
Retention periods may increase as a result of legislative changes, e.g. an increase in limitation periods for legal claims would mean that Somerville College is required to retain certain categories of personal data for longer. Any such changes will be reflected in updated versions of our Record of Processing Activity.
If there are legal proceedings, a regulatory, disciplinary or criminal investigation, suspected criminal activity, or relevant requests under data protection or freedom of information legislation, it may be necessary for us to suspend the deletion of data until the proceedings, investigation or request have been fully disposed of.
Please note that we may keep anonymised statistical data indefinitely, but you cannot be identified from such data.
Your legal rights over your data
Subject to certain conditions and exception set out in UK data protection law, you have:
- The right to request access to a copy of your data, as well as to be informed of various information about how your data is being used;
- The right to have any inaccuracies in your data corrected, which may include the right to have any incomplete data completed;
- The right to have your personal data erased in certain circumstances;
- The right to have the processing of your data suspended, for example if you want us to establish the accuracy of the data we are processing.
- The right to receive a copy of data you have provided to us, and have that transmitted to another data controller (for example, another University or College).
- The right to object to any direct marketing (for example, email marketing or phone calls) by us, and to require us to stop such marketing.
- The right to object to the processing of your information if we are relying on a “legitimate interest” for the processing or where the processing is necessary for the performance of a task carried out in the public interest. The lawful basis for any particular processing activity we carry out is set out in our detailed table of processing activities
- The right to object to any automated decision-making about you which produces legal effects or otherwise significantly affects you.
- Where the lawful basis for processing your data is consent, you have the right to withdraw your consent at any time. This will not affect the validity of any lawful processing of your data up until the time when you withdrew your consent. You may withdraw your consent by contacting the College Data Protection Officer at firstname.lastname@example.org
If you wish to exercise any of your rights in relation to your data as processed by Somerville College please contact our Data Protection Officer at email@example.com. Some of your rights are not automatic, and we reserve the right to discuss with you why we might not comply with a request from you to exercise them.
Further guidance on your rights is available from the Information Commissioner’s Office (https://ico.org.uk/). You have the right to complain to the UK’s supervisory office for data protection, the Information Commissioner’s Office at https://ico.org.uk/concerns/ if you believe that your data has been processed unlawfully.
Future changes to this privacy notice
We may need to update this notice from time to time, for example if the law or regulatory requirements change, if technology changes or to make the College’s or the University’s operations and procedures more efficient. If the change is material, we will give you not less than two months’ notice of the change so that you can exercise your rights, if appropriate, before the change comes into effect. We will notify you of the change by email
Version control: V.1.1 (April2018)