Data Protection – GDPR
At St Brendan’s RCP School, we are committed to protecting the personal data of our pupils, parents, staff and visitors.
Click here for our Data Protection Officer’s (DPO) contact details.
The General Data Protection Regulation (GDPR) sets out how organisations must collect, use and protect personal information. Schools have a legal duty to comply with this legislation and to be transparent about how personal data is handled.
Most of the personal data we process is necessary for the safe and effective running of the school and is carried out under a legal basis known as public task. This means we do not usually need consent to process personal data as part of our normal school activities. Where consent is required (for example, for the use of photographs or certain third-party services), this will always be clearly requested and can be withdrawn at any time.
GDPR also gives individuals stronger rights over their personal data and places greater responsibility on schools to keep information secure, accurate and up to date.
More information can be found in the links below or via the ICO (Information Commissioner’s Office) website.
- GDPR – Model Information Management Policy for Maintained Schools
- Form for submitting a Subject Access Request (SAR) to School
- GDPR – Information Security, Data Protection and Freedom of Information for School
- Privacy Notices – Governors
- Privacy Notices – Pupil Information
- Privacy Notices – School Workforce