GDPR & Data Protection Policy
Company Name: \[Your Company Name\] Policy Owner: Director/Data Protection Lead Version: 1.0 Effective Date: \[Date\] Review Date: \[Date\]
1. Policy Statement
\[Your Company Name\] is committed to protecting the privacy and personal data of all students, parents/carers, staff, tutors, contractors, and partner organisations.
We will process personal data in accordance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Any other applicable data protection legislation
We recognise our responsibility to ensure that personal information is collected, stored, used, and deleted lawfully, fairly, and securely.
2. Purpose
This policy explains:
- What information we collect
- Why we collect information
- How information is stored and protected
- Individuals' rights regarding their personal data
- How data breaches will be managed
3. Scope
This policy applies to:
- Employees
- Tutors
- Contractors
- Volunteers
- Students
- Parents and carers
- Any individual whose personal data is processed by the company
4. Data Protection Principles
We will ensure personal data is:
Lawful, Fair and Transparent
Information will only be collected and used where there is a lawful basis to do so.
Collected for Specified Purposes
Information will only be used for legitimate educational and business purposes.
Adequate and Relevant
Only information necessary for our services will be collected.
Accurate
Reasonable steps will be taken to ensure information remains accurate and up to date.
Storage Limitation
Information will not be kept longer than necessary.
Secure
Appropriate technical and organisational measures will be used to protect data.
5. Personal Data We Collect
We may collect:
Student Information
- Name
- Date of birth
- Address
- School or educational setting
- SEN/EHCP information
- Attendance records
- Educational progress records
- Medical information relevant to tuition
Parent or Carer Information
- Name
- Address
- Telephone number
- Email address
- Emergency contact information
- Billing information
Staff and Tutor Information
- Name
- Address
- Contact details
- DBS information
- Qualifications
- Employment records
- Training records
- Bank details (where applicable)
6. Lawful Basis for Processing
We process personal data under one or more of the following lawful bases:
Contract
To provide educational services requested by parents, carers, schools or local authorities.
Legal Obligation
To comply with safeguarding, employment, tax, and regulatory requirements.
Legitimate Interests
To manage and improve our services.
Consent
Where consent is required, such as:
- Marketing communications
- Photographs
- Testimonials
- Certain special category information
Individuals may withdraw consent at any time.
7. Special Category Data
We may process sensitive personal information relating to:
- Health conditions
- Special educational needs
- Disabilities
- Safeguarding concerns
Such information will only be processed where necessary and lawful and will receive additional protection.
Access will be restricted to those who require the information to perform their role.
8. How We Use Personal Data
Personal information may be used to:
- Deliver tuition services
- Assess educational needs
- Communicate with parents and carers
- Monitor progress and attendance
- Manage safeguarding concerns
- Process payments
- Recruit and manage staff
- Comply with legal obligations
Information will never be sold to third parties.
9. Information Sharing
Information may be shared where necessary with:
- Parents and carers
- Schools
- Local authorities
- Examination bodies
- Safeguarding agencies
- Police or other statutory authorities where legally required
Information will only be shared where lawful and necessary.
10. Data Security
We are committed to keeping information secure.
Measures may include:
- Password-protected devices
- Secure cloud storage
- Restricted access permissions
- Encryption where appropriate
- Secure disposal of records
- Staff training on data protection
All staff are responsible for protecting personal information.
11. Working from Home and Home Tuition
Tutors and staff must:
- Keep records secure at all times
- Avoid discussing confidential information in public places
- Lock devices when unattended
- Use secure passwords
- Store paper records securely
- Report any data loss immediately
When visiting homes, confidential information must not be left unattended or accessible to others.
12. Data Retention
Information will only be retained for as long as necessary.
Retention periods may vary depending on:
- Legal requirements
- Safeguarding responsibilities
- Financial regulations
- Educational service requirements
Once no longer required, information will be securely deleted or destroyed.
13. Individual Rights
Individuals have the right to:
Be Informed
Know how their information is being used.
Access Their Data
Request a copy of personal information held.
Rectification
Request correction of inaccurate information.
Erasure
Request deletion of personal data where applicable.
Restriction
Request limits on data processing.
Data Portability
Receive personal information in a transferable format where appropriate.
Object
Object to certain types of processing.
Withdraw Consent
Where processing is based on consent.
Requests should be submitted in writing to the Data Protection Lead.
14. Subject Access Requests
Requests for personal information should:
- Be submitted in writing
- Include sufficient identification details
We will normally respond within one calendar month.
15. Data Breaches
A data breach may include:
- Loss of devices
- Unauthorised access
- Accidental disclosure
- Cyber attacks
- Misdirected emails
All breaches must be reported immediately to the Data Protection Lead.
The company will:
1. Investigate the breach.
2. Assess risks to individuals.
3. Take steps to limit harm.
4. Notify the Information Commissioner's Office (ICO) where required.
5. Inform affected individuals where necessary.
16. Staff Responsibilities
All staff and tutors must:
- Follow this policy.
- Complete data protection training.
- Keep information secure.
- Report concerns promptly.
- Use company systems appropriately.
- Maintain confidentiality.
Failure to comply with this policy may result in disciplinary action.
17. Complaints
Individuals who are unhappy with how their information has been handled should first contact:
Data Protection Lead
\[Name\] \[Email Address\] \[Telephone Number\]
Individuals also have the right to complain to the Information Commissioner's Office (ICO).
Website: https://www.ico.org.uk
18. Policy Review
This policy will be reviewed annually or sooner if legislation, guidance, or operational requirements change.
Approval
Approved By: Claire Blood
Position: CEO
Signature: C E Blood
Date: 11/08/26

