Data Policy


DATA PROTECTION POLICY 

 

1. PURPOSE 

Elevate Learning Provision is committed to complying with data protection legislation and ensuring that all personal data is handled lawfully, fairly, and transparently. 

We recognise the importance of protecting the privacy, rights, and trust of all individuals we work with, including pupils, parents, staff, and partner organisations 

 

2. SCOPE 

This policy applies to all personal data processed by Elevate Learning Provision, including data relating to: 

  • Pupils and families 

  • Job applicants 

  • Current and former employees 

  • Volunteers and placement students 

  • Contractors and agency staff 

This policy does not form part of any employee’s contract of employment and may be updated at any time. 

 

3. DEFINITIONS 

Personal Data Information relating to an identifiable individual (e.g. name, address, ID number, location data, online identifiers). 

Special Category Data  Includes sensitive data such as health, ethnicity, religion, sexual orientation, and biometric data. 

Criminal Offence Data Includes DBS information and criminal history. Elevate Learning Provision does not retain DBS certificates. We record: 

  • Certificate number 

  • Date and level of check 

  • Outcome/decision 

Any retained copies are securely destroyed within 6 months. 

Data Processing Any activity involving personal data (e.g. collection, storage, sharing, deletion). 

Lawful Bases We process data under: 

  • Contract 

  • Legal obligation 

  • Legitimate interests 

  • Vital interests 

For sensitive data, we rely on UK GDPR Article 9 conditions (e.g. safeguarding, health, public interest). 

 

4. TYPES OF DATA HELD 

Elevate Learning Provision processes data across: 

  • Safeguarding and welfare 

  • Education delivery and progress tracking 

  • Attendance and behaviour monitoring 

  • HR and recruitment 

  • IT systems and security monitoring 

  • Communication with parents, schools, and local authorities 

Examples include: 

  • Personal details (name, DOB, contact information) 

  • Parent/carer details 

  • School placement information 

  • Safeguarding and behavioural records 

  • Attendance data 

  • Medical and SEND/EHCP information 

  • Staff employment and training records 

Full details are recorded in our Record of Processing Activities (ROPA)

 

5. DATA PROTECTION PRINCIPLES 

All data processed by Elevate Learning Provision will be: 

  1. Lawful, fair, and transparent 

  1. Collected for specific and legitimate purposes 

  1. Relevant and limited to what is necessary 

  1. Accurate and kept up to date 

  1. Retained only as long as necessary 

  1. Secure and protected from unauthorised access or loss 

  1. Compliant with international transfer requirements where applicable 

 

6. INDIVIDUAL RIGHTS 

Individuals have the right to: 

  • Be informed about how their data is used 

  • Access their personal data 

  • Correct inaccurate data 

  • Request deletion (where applicable) 

  • Restrict processing 

  • Data portability 

  • Object to processing 

  • Protection from automated decision-making 

 

7. PROCEDURES AND GOVERNANCE 

Elevate Learning Provision ensures compliance by: 

  • Appointing a Data Protection Officer (DPO) 

  • Maintaining a ROPA (Article 30) 

  • Conducting Data Protection Impact Assessments (DPIAs) 

  • Maintaining an Appropriate Policy Document (APD) 

  • Providing staff training on data protection 

  • Implementing clear accountability across leadership and staff 

We regularly review risks and update procedures to maintain compliance. 

 

8. CONSENT 

Where consent is required: 

  • It is freely given, specific, informed, and unambiguous 

  • Individuals can withdraw consent at any time 

  • Records of consent are maintained 

 

9. ACCESS TO DATA (SUBJECT ACCESS REQUESTS) 

Individuals may request access to their data: 

  • Requests must be made in writing to the DPO 

  • Identity will be verified 

  • Responses are provided within 1 month (extendable to 3 months if complex) 

  • No fee is charged unless requests are excessive or repetitive 

We may apply legal exemptions where appropriate (e.g. safeguarding concerns). 

 

10. DATA SHARING AND DISCLOSURES 

We may share data where necessary with: 

  • Commissioning schools and Local Authorities 

  • Safeguarding partners (e.g. social care, police) 

  • Health professionals 

  • External service providers (under contract) 

All sharing is: 

  • Lawful and proportionate 

  • Recorded with a clear legal basis 

  • Governed by data sharing agreements 

 

11. DATA SECURITY 

We implement strong security measures, including: 

  • Role-based access controls 

  • Multi-factor authentication (MFA) 

  • Encryption (in transit and at rest) 

  • Secure storage systems 

  • Monitoring and logging 

Staff must: 

  • Keep information secure at all times 

  • Not share passwords 

  • Avoid using personal email or devices for sensitive data 

  • Ensure screens and documents are not visible to unauthorised individuals 

Failure to comply may result in disciplinary action. 

 

12. INTERNATIONAL DATA TRANSFERS 

Where data is transferred outside the UK: 

  • Approved safeguards are used (e.g. UK IDTA) 

  • Risk assessments are completed 

  • Data is protected through technical and organisational measures 

 

13. DATA BREACHES 

All data breaches must be reported immediately. 

Elevate Learning Provision will: 

  • Assess the level of risk 

  • Notify the ICO within 72 hours where required 

  • Inform affected individuals where the risk is high 

  • Record all breaches and actions taken 

 

14. TRAINING 

All staff: 

  • Receive data protection training during induction 

  • Complete regular refresher training 

  • Understand their responsibilities for safeguarding data 

 

15. RECORD KEEPING 

We maintain records of: 

  • Processing activities 

  • Data sharing 

  • Retention schedules 

  • Security measures 

These are regularly reviewed and updated. 

 

16. DATA PROTECTION OFFICER 

Data Protection Officer: Gareth Ewers-Cobb[Text Wrapping Break]Email: Admin@Elevatelearningprovision.co.uk 

All data protection concerns, breaches, and requests must be reported to the DPO. 

 

17. THIRD PARTIES 

We may engage third-party providers. All providers: 

  • Are vetted for compliance 

  • Operate under written contracts 

  • Meet UK GDPR requirements 

 

18. ALTERNATIVE PROVISION CONTEXT 

Elevate Learning Provision operates as a non-school Alternative Provision (AP)

  • Commissioning schools and Local Authorities retain statutory responsibilities 

  • We share attendance and safeguarding data daily, where required 

  • Data is shared under formal agreements 

Headstart operates as a data controller, working controller-to-controller with commissioning bodies. 

 

19. LEGAL FRAMEWORK 

This policy complies with: 

  • Data Protection Act 2018 

  • UK GDPR 

  • Human Rights Act 1998 

  • Digital Economy Act 2017 

  • PECR 2003 

 

20. RELATED DOCUMENTS 

  • Privacy Notice 

  • Safeguarding Policy 

  • Safer Recruitment Policy 

  • Disciplinary Policy 

  • Staff Code of Conduct