General Data Protection Regulation
The UK General Data Protection Regulation (UK GDPR) balances an individual’s rights to privacy and the lawful processing of personal data undertaken by organisations in the course of their business. It aims to protect the rights of individuals about whom data is obtained, stored, processed or supplied and requires organisations to ensure data collected and stored is:
- handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
- used fairly, lawfully and transparently
- used for specified, explicit purposes
- used in a way that is adequate, relevant and limited to only what is necessary
- accurate and, where necessary, kept up to date
- kept for no longer than is necessary.
If you have any questions about how the GDPR affects you, our how our school is preparing, you can contact Paige Allister (Data Protection Lead).