DATA PROTECTION POLICY
To comply to GDPR, Skills and Fitness need to embed six privacy principles within their operations:
1. Lawfulness, fairness and transparency
Transparency: Full explanation of what data processing will be done, and why. Fair: What is processed must match up with how it has been described. Lawful: Assessment Data will not be shared with third parties
2. Purpose limitations
Personal data can only be obtained for “specified and legitimate purposes”. Data can only be used for a specific processing purpose that the subject has been made aware of and no other, without further consent.
3. Data minimisation
Data collected on a subject should be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. In other words, no more than the minimum amount of data should be kept for specific use.
4. Accuracy
Data must be “accurate and where necessary kept up to date”. Baselining ensures good protection and protection against identity theft.
5. Storage limitations
Skills and Fitness expects personal data to be “kept in a form which permits identification of data subjects for no longer than necessary".
6. Integrity and confidentiality
Requires processors to handle data “in a manner [ensuring] appropriate security of the personal data including protection against unlawful processing or accidental loss, destruction or damage”.
These 6 principles give a top level overview of the areas covered by the new regulation.
COMPLAINTS/CONTACTS
Complaints about the above procedures should be made to the company director Mr J Hogan B.Sc (Hons), who can be reached through the contact form on our website www.skillsandfitness.co.uk.
INFORMATION AUDIT
Getting ready for GDPR
Description Why is the data held and what is it used for Who holds the data and who can access it? What security controls are in place?
How long is data kept for? Is this covered by our privacy notice?
Pupil names + Assessment scores
Demonstrating progress P.E Specialist – Passed on to school Safely stored on 1 drive 3 years Yes Password protected
School Names + addresses
Invoicing Company Director Safely stored on 1 drive 7 years Yes Password protected
Employee Names + Addresses, Email addresses
Payments, Communication, Review, Session Planning support.
Company Director
Electronically stored on 1 drive
On- going for as long as employed by Skills and Fitness
Yes
Password protected
Insurance information
School and Company Records Company Director 1 Drive Renewed / Replaced each year Yes Password Protected
The policy will be reviewed annually
Author: Mr James Hogan B.Sc (Hons)
Review date : January 2021