GDPR Statement

GDPR: General Data Protection Regulation Statement

The General Data Protection Regulation (GDPR) comes into force on 25th May 2018. It is a new piece of EU legislation (Regulation (EU) 2016/679) that will replace the Data Protection Act 1998 and will be in force in the UK until the UK leaves the EU. A new Data Protection Act (DPA), currently going through Parliament, will apply post Brexit.

While it is true that the EU is a signatory to the UN Convention on the Rights of the Child, which defines a child as someone who is under the age of 18, the text of the GDPR uses the age of 16 as its cut-off point. The British government subsequently confirmed through the UK Data Protection Bill that it will be adopting the lowered cut-off point of 13 years of age.

Under the GDPR, organisations are required to provide individuals with information about the use and processing of their personal data (see note 1). Heads Up Now Ltd. want the way we deal with personal data to continue to be transparent. This note is intended to help individuals and organisations we work with understand how they can maintain control of their information that we hold.

The introduction of the GDPR means parental/guardian consent is necessary before a company, such as Heads Up Now, can process the personal data of minors that we receive, for example from a school. Heads Up Now already ensure parent or guardian consent is obtained, either directly between Heads Up Now and parents, or through the appropriate authorising person within a sponsoring school where the minor is studying. This consent process continues to be a matter of course, and we always request in writing that a school has obtained this consent.

PERSONAL DATA 

Under the GDPR we are ‘data controllers’ of some personal information. We are called ‘controllers’ because, although we don’t use data to prepare marketing materials to individuals, we ‘process’ personal data when we carry out basic activities like storing, deleting and changing the information that we hold on our computer systems. Therefore, Heads Up Now Ltd. are fully registered with the ICO, the Information Commissioner’s Office with a named Data Protection Officer (DPO).

We do hold the following information: Personal names, location of school, if a person (including a minor) accessing coaching has been (a)  prescribed medication by a GP (no specific details are held); (b) referred to another agency such as CAMHS (no specific details are held).

We do not hold information on: Personal phone numbers; residential addresses; social media identifiers; bank details; photographs.

We take our obligation to protect personal information given to us very seriously, and we always take care when using and processing it. Occasionally some data we hold is classed as special category information which requires more protection (see note 2). This is usually related to a specific situation, problem or challenge where an individual (for example, a student or adult) faces risks to others, or themselves, or from others. Where such information is provided that is not in the public domain (for example, a teacher providing information about a student being on prescribed medication), we ensure we have clear and appropriate consent before using it (for example in making a referral to another agency). This is ensured through written confirmation from a school (or other organisation) that individual consent has been gained.

COLLECTING AND USING PERSONAL DATA 

We collect data about individuals when we enter into a contract to deliver work. We receive information about individuals via our web-based contact form or by email. We receive information about an individual’s name, age (but not date of birth) and town of location (but not specific residential address). We also receive some information regarding a personal situation, if the individual has been referred to other agencies for support (such as CAMHS or the GP) and if an individual is on prescribed medication. We use this information to carry out our contractual and ethical obligations to deliver work towards agreed outcomes and to uphold our safeguarding duty. Personal information is used in pursuance of our legitimate business interests in relation to the rights granted us.

In addition, Heads Up Now Ltd. take compliance with the EMCC Code of Ethics seriously in how we contract, liaise with and deliver work for individuals and organisations. A copy of the EMCC Code can be found here.

We do not use individual details to tailor marketing campaigns. We do not issue newsletters or surveys with personal information on. Any survey-based data we work with is completed with express consent in conjunction with a third party (for example, a school). We ensure that there is full compliance with GDPR and transparency about how survey-generated information is used. We do not pass data onto, or sell data to other parties.

SECURITY AND DATA PROCESSING 

We hold personal data on our UK-based server. We take all reasonable precautions to ensure that personal data remains secure. We have adequate procedures to avoid data security breaches (such as virus protection software, computer passwords and online security features) and to protect data from accidental or unlawful disclosure, damage, destruction or loss. Personal information is processed within Heads Up Now Ltd. for internal management reports and accounting.

DATA SHARING AND RETENTION

We keep personal data in accordance with our legal obligations as a private limited company. Reliable third parties operating under our instruction, for example a school, may have access to personal information (such as a minor) for the purposes of processing their data on our behalf as explained above (for example, a coaching report). Where this happens, we will require these third parties to keep personal information confidential and comply with applicable data protection laws. Except for that, in our role as data controller of personal data, we will not share personal information with any third-party data controllers without prior consent of the individual.

With explicit permission we do share individual feedback about work delivered with the sponsoring school / organisation (for example student feedback from coaching work). With explicit permission in advance we occasionally use feedback on our website or other promotional materials but ensure a person cannot be identified if they are under 18 years of age. A person can withhold or withdraw this permission at any time by contacting us.

INDIVIDUAL RIGHTS 

GDPR is about protecting individuals and their rights in respect of their personal information. It is designed to ensure that an individual can maintain control over their information. Under GDPR individuals can:

  • Request access to, deletion of, or correction of their personal data
  • Request personal data be transferred to another person
  • Complain to a supervisory body

WHERE TO FIND MORE INFORMATION AND WHO TO CONTACT 

We hope this information is useful. Please contact us directly if you have any questions about this note, your rights, or the information we hold about you. You can contact us at hello@headsupnow.uk or via our website www.headsupnow.uk

_____

1 ’Personal data’ means any information relating to an individual who can be identified from that data.
2 This comprises details relating to an individual’s health, ethnic origin, political, religious or philosophical beliefs, genetic or biometric data, sexual life or orientation or any criminal record.

Leave a Reply

Your email address will not be published. Required fields are marked *