Data Policy
DATA PROTECTION POLICY
1. PURPOSE
Elevate Learning Provision is committed to complying with data protection legislation and ensuring that all personal data is handled lawfully, fairly, and transparently.
We recognise the importance of protecting the privacy, rights, and trust of all individuals we work with, including pupils, parents, staff, and partner organisations
2. SCOPE
This policy applies to all personal data processed by Elevate Learning Provision, including data relating to:
Pupils and families
Job applicants
Current and former employees
Volunteers and placement students
Contractors and agency staff
This policy does not form part of any employee’s contract of employment and may be updated at any time.
3. DEFINITIONS
Personal Data Information relating to an identifiable individual (e.g. name, address, ID number, location data, online identifiers).
Special Category Data Includes sensitive data such as health, ethnicity, religion, sexual orientation, and biometric data.
Criminal Offence Data Includes DBS information and criminal history. Elevate Learning Provision does not retain DBS certificates. We record:
Certificate number
Date and level of check
Outcome/decision
Any retained copies are securely destroyed within 6 months.
Data Processing Any activity involving personal data (e.g. collection, storage, sharing, deletion).
Lawful Bases We process data under:
Contract
Legal obligation
Legitimate interests
Vital interests
For sensitive data, we rely on UK GDPR Article 9 conditions (e.g. safeguarding, health, public interest).
4. TYPES OF DATA HELD
Elevate Learning Provision processes data across:
Safeguarding and welfare
Education delivery and progress tracking
Attendance and behaviour monitoring
HR and recruitment
IT systems and security monitoring
Communication with parents, schools, and local authorities
Examples include:
Personal details (name, DOB, contact information)
Parent/carer details
School placement information
Safeguarding and behavioural records
Attendance data
Medical and SEND/EHCP information
Staff employment and training records
Full details are recorded in our Record of Processing Activities (ROPA).
5. DATA PROTECTION PRINCIPLES
All data processed by Elevate Learning Provision will be:
Lawful, fair, and transparent
Collected for specific and legitimate purposes
Relevant and limited to what is necessary
Accurate and kept up to date
Retained only as long as necessary
Secure and protected from unauthorised access or loss
Compliant with international transfer requirements where applicable
6. INDIVIDUAL RIGHTS
Individuals have the right to:
Be informed about how their data is used
Access their personal data
Correct inaccurate data
Request deletion (where applicable)
Restrict processing
Data portability
Object to processing
Protection from automated decision-making
7. PROCEDURES AND GOVERNANCE
Elevate Learning Provision ensures compliance by:
Appointing a Data Protection Officer (DPO)
Maintaining a ROPA (Article 30)
Conducting Data Protection Impact Assessments (DPIAs)
Maintaining an Appropriate Policy Document (APD)
Providing staff training on data protection
Implementing clear accountability across leadership and staff
We regularly review risks and update procedures to maintain compliance.
8. CONSENT
Where consent is required:
It is freely given, specific, informed, and unambiguous
Individuals can withdraw consent at any time
Records of consent are maintained
9. ACCESS TO DATA (SUBJECT ACCESS REQUESTS)
Individuals may request access to their data:
Requests must be made in writing to the DPO
Identity will be verified
Responses are provided within 1 month (extendable to 3 months if complex)
No fee is charged unless requests are excessive or repetitive
We may apply legal exemptions where appropriate (e.g. safeguarding concerns).
10. DATA SHARING AND DISCLOSURES
We may share data where necessary with:
Commissioning schools and Local Authorities
Safeguarding partners (e.g. social care, police)
Health professionals
External service providers (under contract)
All sharing is:
Lawful and proportionate
Recorded with a clear legal basis
Governed by data sharing agreements
11. DATA SECURITY
We implement strong security measures, including:
Role-based access controls
Multi-factor authentication (MFA)
Encryption (in transit and at rest)
Secure storage systems
Monitoring and logging
Staff must:
Keep information secure at all times
Not share passwords
Avoid using personal email or devices for sensitive data
Ensure screens and documents are not visible to unauthorised individuals
Failure to comply may result in disciplinary action.
12. INTERNATIONAL DATA TRANSFERS
Where data is transferred outside the UK:
Approved safeguards are used (e.g. UK IDTA)
Risk assessments are completed
Data is protected through technical and organisational measures
13. DATA BREACHES
All data breaches must be reported immediately.
Elevate Learning Provision will:
Assess the level of risk
Notify the ICO within 72 hours where required
Inform affected individuals where the risk is high
Record all breaches and actions taken
14. TRAINING
All staff:
Receive data protection training during induction
Complete regular refresher training
Understand their responsibilities for safeguarding data
15. RECORD KEEPING
We maintain records of:
Processing activities
Data sharing
Retention schedules
Security measures
These are regularly reviewed and updated.
16. DATA PROTECTION OFFICER
Data Protection Officer: Gareth Ewers-Cobb[Text Wrapping Break]Email: Admin@Elevatelearningprovision.co.uk
All data protection concerns, breaches, and requests must be reported to the DPO.
17. THIRD PARTIES
We may engage third-party providers. All providers:
Are vetted for compliance
Operate under written contracts
Meet UK GDPR requirements
18. ALTERNATIVE PROVISION CONTEXT
Elevate Learning Provision operates as a non-school Alternative Provision (AP).
Commissioning schools and Local Authorities retain statutory responsibilities
We share attendance and safeguarding data daily, where required
Data is shared under formal agreements
Headstart operates as a data controller, working controller-to-controller with commissioning bodies.
19. LEGAL FRAMEWORK
This policy complies with:
Data Protection Act 2018
UK GDPR
Human Rights Act 1998
Digital Economy Act 2017
PECR 2003
20. RELATED DOCUMENTS
Privacy Notice
Safeguarding Policy
Safer Recruitment Policy
Disciplinary Policy
Staff Code of Conduct