Policy

GDPR & Data Protection Policy

How CTS collects, stores, uses and deletes personal data.

GDPR & Data Protection Policy

Company Name: \[Your Company Name\] Policy Owner: Director/Data Protection Lead Version: 1.0 Effective Date: \[Date\] Review Date: \[Date\]

1. Policy Statement

\[Your Company Name\] is committed to protecting the privacy and personal data of all students, parents/carers, staff, tutors, contractors, and partner organisations.

We will process personal data in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Any other applicable data protection legislation

We recognise our responsibility to ensure that personal information is collected, stored, used, and deleted lawfully, fairly, and securely.

2. Purpose

This policy explains:

  • What information we collect
  • Why we collect information
  • How information is stored and protected
  • Individuals' rights regarding their personal data
  • How data breaches will be managed

3. Scope

This policy applies to:

  • Employees
  • Tutors
  • Contractors
  • Volunteers
  • Students
  • Parents and carers
  • Any individual whose personal data is processed by the company

4. Data Protection Principles

We will ensure personal data is:

Lawful, Fair and Transparent

Information will only be collected and used where there is a lawful basis to do so.

Collected for Specified Purposes

Information will only be used for legitimate educational and business purposes.

Adequate and Relevant

Only information necessary for our services will be collected.

Accurate

Reasonable steps will be taken to ensure information remains accurate and up to date.

Storage Limitation

Information will not be kept longer than necessary.

Secure

Appropriate technical and organisational measures will be used to protect data.

5. Personal Data We Collect

We may collect:

Student Information

  • Name
  • Date of birth
  • Address
  • School or educational setting
  • SEN/EHCP information
  • Attendance records
  • Educational progress records
  • Medical information relevant to tuition

Parent or Carer Information

  • Name
  • Address
  • Telephone number
  • Email address
  • Emergency contact information
  • Billing information

Staff and Tutor Information

  • Name
  • Address
  • Contact details
  • DBS information
  • Qualifications
  • Employment records
  • Training records
  • Bank details (where applicable)

6. Lawful Basis for Processing

We process personal data under one or more of the following lawful bases:

Contract

To provide educational services requested by parents, carers, schools or local authorities.

Legal Obligation

To comply with safeguarding, employment, tax, and regulatory requirements.

Legitimate Interests

To manage and improve our services.

Consent

Where consent is required, such as:

  • Marketing communications
  • Photographs
  • Testimonials
  • Certain special category information

Individuals may withdraw consent at any time.

7. Special Category Data

We may process sensitive personal information relating to:

  • Health conditions
  • Special educational needs
  • Disabilities
  • Safeguarding concerns

Such information will only be processed where necessary and lawful and will receive additional protection.

Access will be restricted to those who require the information to perform their role.

8. How We Use Personal Data

Personal information may be used to:

  • Deliver tuition services
  • Assess educational needs
  • Communicate with parents and carers
  • Monitor progress and attendance
  • Manage safeguarding concerns
  • Process payments
  • Recruit and manage staff
  • Comply with legal obligations

Information will never be sold to third parties.

9. Information Sharing

Information may be shared where necessary with:

  • Parents and carers
  • Schools
  • Local authorities
  • Examination bodies
  • Safeguarding agencies
  • Police or other statutory authorities where legally required

Information will only be shared where lawful and necessary.

10. Data Security

We are committed to keeping information secure.

Measures may include:

  • Password-protected devices
  • Secure cloud storage
  • Restricted access permissions
  • Encryption where appropriate
  • Secure disposal of records
  • Staff training on data protection

All staff are responsible for protecting personal information.

11. Working from Home and Home Tuition

Tutors and staff must:

  • Keep records secure at all times
  • Avoid discussing confidential information in public places
  • Lock devices when unattended
  • Use secure passwords
  • Store paper records securely
  • Report any data loss immediately

When visiting homes, confidential information must not be left unattended or accessible to others.

12. Data Retention

Information will only be retained for as long as necessary.

Retention periods may vary depending on:

  • Legal requirements
  • Safeguarding responsibilities
  • Financial regulations
  • Educational service requirements

Once no longer required, information will be securely deleted or destroyed.

13. Individual Rights

Individuals have the right to:

Be Informed

Know how their information is being used.

Access Their Data

Request a copy of personal information held.

Rectification

Request correction of inaccurate information.

Erasure

Request deletion of personal data where applicable.

Restriction

Request limits on data processing.

Data Portability

Receive personal information in a transferable format where appropriate.

Object

Object to certain types of processing.

Withdraw Consent

Where processing is based on consent.

Requests should be submitted in writing to the Data Protection Lead.

14. Subject Access Requests

Requests for personal information should:

  • Be submitted in writing
  • Include sufficient identification details

We will normally respond within one calendar month.

15. Data Breaches

A data breach may include:

  • Loss of devices
  • Unauthorised access
  • Accidental disclosure
  • Cyber attacks
  • Misdirected emails

All breaches must be reported immediately to the Data Protection Lead.

The company will:

1. Investigate the breach.

2. Assess risks to individuals.

3. Take steps to limit harm.

4. Notify the Information Commissioner's Office (ICO) where required.

5. Inform affected individuals where necessary.

16. Staff Responsibilities

All staff and tutors must:

  • Follow this policy.
  • Complete data protection training.
  • Keep information secure.
  • Report concerns promptly.
  • Use company systems appropriately.
  • Maintain confidentiality.

Failure to comply with this policy may result in disciplinary action.

17. Complaints

Individuals who are unhappy with how their information has been handled should first contact:

Data Protection Lead

\[Name\] \[Email Address\] \[Telephone Number\]

Individuals also have the right to complain to the Information Commissioner's Office (ICO).

Website: https://www.ico.org.uk

18. Policy Review

This policy will be reviewed annually or sooner if legislation, guidance, or operational requirements change.

Approval

Approved By: Claire Blood

Position: CEO

Signature: C E Blood

Date: 11/08/26

All policies