Data Protection
Data Protection Policy
The Independent Grammar School: Durham
IGS: Durham is responsible for ensuring that all records are maintained in accordance with the law as it applies to education in general and to personal information specifically. The relevant legislation is the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. We will respond to changes in legislation and guidance and ensure that our policies and practices continue to be appropriate.
Data Controller
The Education Partnership (UK) Ltd, which operates IGS: Durham, is the data controller for personal data processed for the school’s purposes. The Principal is the school’s designated data protection lead and first point of contact for data protection enquiries, requests and complaints. The School Board oversees compliance. If a Data Protection Officer is appointed or required by law, their role and contact details will be set out in the school’s privacy notices.
What the Policy Involves
The school will obtain and process personal data fairly, lawfully and transparently by making all data subjects (i.e. people about whom the school holds data) aware of why information about them is being held, how it will be used, who might access that information and their rights. Forms used to gather personal information will include appropriate privacy information or a clear reference to the relevant privacy notice.
The school will identify and record an appropriate lawful basis for processing. Consent will be used where appropriate, but is not required for every use or disclosure of personal data. Where consent is used, it must be freely given, specific, informed and capable of being withdrawn. Special category data and criminal offence data require additional legal conditions and safeguards.
Privacy notices will explain the controller’s identity, contact details, purposes and lawful bases, recipients, retention arrangements, relevant international transfers, individuals’ rights and the routes for complaints to the school and the Information Commissioner’s Office (ICO).
Definitions
Some useful definitions are:
- “Processing” means obtaining, recording, holding, using, sharing or deleting personal information.
- “Data subject” is the person who is the subject of the information being obtained, recorded etc.
- “Personal data” means any information relating to an identified or identifiable living person. This includes names and addresses and may also include photographs (see Photography Policy).
- “Special category data” includes information about health, racial or ethnic origin, religion and other categories given additional protection under the UK GDPR.
- “Parent” includes a person with parental responsibility for a child; references to parents in education legislation includes guardians etc,
Obtaining and Keeping Reliable Data
In general terms, we aim to do this by ensuring the following:
- Data is used fairly, lawfully and transparently.
- Data is collected for specified, legitimate purposes and used compatibly with those purposes.
- Data is adequate, relevant and limited to what is necessary.
- Data is accurate and kept up to date where necessary.
- Data is retained only for as long as necessary.
- Data is protected against unauthorised access, loss, damage or disclosure.
The school will maintain appropriate records to demonstrate compliance.
Data Accuracy
We will maintain data which is as up to date and as accurate as possible. If a data subject lets us know of any changes to his or her personal information, we will make the change promptly, subject to appropriate verification. Every data subject will receive a copy of their personal data sheet every two years so it can be verified, and may notify changes at any time. Should a data subject challenge the accuracy of data shown, and we cannot amend it straightaway, the disputed information will be marked accordingly and any necessary restriction on its use considered until the matter is resolved. The Principal will investigate and record the outcome, with School Board oversight where necessary. Requests to rectify personal data will be handled within the applicable statutory timescale, normally one month.
Length of Time
Data should not be kept longer than is necessary. The school will maintain a retention schedule based on relevant legal requirements and published guidance, including requirements for safeguarding, personnel and examination records. The Principal will ensure that retention arrangements are reviewed and implemented. Paper records will be securely shredded or destroyed through an approved confidential disposal service. Electronic records will be securely deleted, including through appropriate arrangements for backups. Records subject to a continuing legal, safeguarding or evidential need will not be destroyed prematurely.
Complaints Relating to Data Protection
Parents, pupils, staff and others may raise concerns about the handling of their personal data with the Principal, as data protection lead, through the school office or in writing to the school. An accessible complaint form will be available electronically and in paper form; use of the form is not compulsory. A complaint about the Principal’s handling of personal data may be addressed to the Chairman of the School Board through the school office.
The school will:
- Acknowledge receipt within 30 days, including during school holidays.
- Investigate and take appropriate steps without undue delay.
- Keep the complainant informed of progress.
- Communicate the outcome and any corrective action without undue delay.
- Record the complaint, acknowledgement, enquiries, action and outcome securely.
The school’s Complaints Policy provides further information about the internal process. This process must be accessible to pupils, staff and other data subjects as well as parents. Individuals retain the right to complain to the ICO at ico.org.uk or on 0303 123 1113. The ICO will normally expect them to raise the matter with the school first. Complaints and subject access requests have different timescales; raising a complaint does not suspend a subject access deadline.
Individuals’ Rights
Under the UK GDPR, individuals have the following rights, subject to the applicable legal conditions and exemptions:
- The right to be informed.
- The right of access.
- The right to rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability where applicable.
- The right to object.
- Rights and safeguards relating to solely automated decisions with legal or similarly significant effects, including information, an opportunity to make representations, human intervention and the ability to contest decisions where required.
IGS: Durham will ensure that those rights are respected. Not every right applies to every form of processing. Where portability applies, the school will provide the relevant data in a structured, commonly used, machine-readable format. Transfers to another school will be considered under the appropriate lawful basis and carried out securely.
Subject Access Requests
Individuals may make subject access requests verbally or in writing, without using a particular form or legal wording. Requests should be referred promptly to the Principal. All requests will be recorded securely, including the date received, requester, data subject, information requested, applicable deadline, action taken and response.
The school will respond without undue delay and normally within one month. Where permitted by law, the period may be extended by up to a further two months for complex or multiple requests, with the requester informed within the initial month and given reasons. Necessary identity checks and reasonably required clarification will be handled in accordance with current ICO guidance; any lawful adjustment to the deadline will be explained and recorded. The school will make a reasonable and proportionate search and supply information securely in an accessible form. Requests will normally be free of charge; any refusal or charge must have a lawful justification and be explained with information about complaint rights.
Access rights belong to the pupil. There is no general age 16 or age 13 threshold for exercising these rights. The school will consider the pupil’s maturity, understanding, wishes and best interests. A parent may act on behalf of a pupil who is not competent to exercise the right, or with the authority of a competent pupil. Parental responsibility does not automatically confer access to all of a competent pupil’s personal data. Applicable exemptions, safeguarding risks and the rights of other individuals will be considered before disclosure.
As an independent school in England, IGS: Durham is not subject to the separate 15-school-day parental education-record access requirement applying to maintained schools. Subject access requests will be handled under the UK GDPR timescales above.
Authorised Disclosures
The school will disclose personal information only where there is an appropriate lawful basis and any additional conditions are met. Relevant disclosures may include:
- Pupil data necessary for the school to perform its legal duties.
- Information shared with appropriate professionals or agencies to safeguard a child or protect health and safety.
- Appropriate information to parents about a child’s progress and welfare, taking account of the child’s rights and circumstances.
- Staff data released to relevant authorities, for example in respect of payroll.
- Information accessed by approved service providers under appropriate confidentiality, security and data-processing arrangements.
Only authorised and appropriately trained staff may disclose personal data to external bodies. All staff must refer safeguarding concerns promptly to the DSL. Data protection law must not be used as a reason to delay necessary safeguarding information sharing. Consent is not normally required for appropriate safeguarding disclosures. Information shared must be relevant, necessary, proportionate, accurate and secure. Decisions to share or withhold safeguarding information, and the reasons, will be recorded.
No person other than a member of the School Board or teaching staff or an authorised member of the administration or support teams may use the staff room. All staff are responsible for keeping information displayed on staff-room notice boards confidential. Parents and other visitors must not be allowed to enter the staff room. Disclosures must be assessed for risks to a pupil’s health, welfare or safety; this does not prevent necessary disclosures to appropriate safeguarding agencies.
Data Security
The school will use appropriate physical and technical safeguards for both paper and electronic records, in accordance with its Cyber Security Policy. Paper records will be securely stored and accessible only to authorised persons. Filing cabinets and offices where data is held are locked when unattended. All visitors to school are required to sign in, wear a visitor badge and where appropriate be accompanied at all times.
Electronic data may be held only on approved, secure devices and services. Access will be limited to authorised users according to their roles, protected by strong passwords and multi-factor authentication where available. Shared passwords and insecure recording of credentials must be avoided. Access permissions will be reviewed and removed when no longer needed. Security updates, protected backups and tested recovery arrangements will be maintained.
Filtering and monitoring records, including staff and pupil browsing data, will be handled as personal data. Monitoring must be necessary, proportionate and transparent, with appropriate restrictions on access and retention and explanations in privacy notices. The school will assess privacy risks and undertake a data protection impact assessment where processing is likely to result in high risk, including when introducing relevant monitoring or AI systems. Personal data must not be entered into unapproved AI tools. Service providers must be subject to appropriate checks and contracts; international transfers require applicable legal safeguards.
Personal Data Breaches
All suspected loss, unauthorised access or disclosure of personal data must be reported immediately to the Principal. The DSL must also be informed where safeguarding is affected. The school will contain the incident, preserve relevant evidence, assess risks and record all personal data breaches and decisions about notification.
The school will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals will be informed without undue delay, subject to applicable legal exceptions. Incident handling and recovery will follow the Cyber Security Policy.
Training
All staff will receive regular training in data protection. Training will include confidentiality, secure handling, recognising requests and complaints, reporting breaches and appropriate safeguarding information sharing. Relevant temporary staff, volunteers and contractors will receive appropriate instructions for their roles.
Responsibilities
Day-to-day responsibility for implementing this policy lies with the Principal. All staff have responsibility for ensuring that procedures are followed and should refer questions or uncertainties to the Principal. Data protection training will be included in induction. The School Board will oversee compliance by the data controller. Data protection will be a standing item at School Board meetings, at which the Principal will report on the effectiveness of policies, emerging risks and potential or actual breaches, with due regard to confidentiality.
This policy should be read in conjunction with the Safeguarding Policy, Photography Policy, Complaints Policy, Cyber Security Policy, relevant online safety and acceptable use policies, and the school’s privacy notices.
May 2026. Reviewed: September 2026. Next Review: September 2027
Data Protection Policy
The Independent Grammar School: Durham
IGS: Durham is responsible for ensuring that all records are maintained in accordance with the law as it applies to education in general and to personal information specifically. The relevant legislation is the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. We will respond to changes in legislation and guidance and ensure that our policies and practices continue to be appropriate.
Data Controller
The Education Partnership (UK) Ltd, which operates IGS: Durham, is the data controller for personal data processed for the school’s purposes. The Principal is the school’s designated data protection lead and first point of contact for data protection enquiries, requests and complaints. The School Board oversees compliance. If a Data Protection Officer is appointed or required by law, their role and contact details will be set out in the school’s privacy notices.
What the Policy Involves
The school will obtain and process personal data fairly, lawfully and transparently by making all data subjects (i.e. people about whom the school holds data) aware of why information about them is being held, how it will be used, who might access that information and their rights. Forms used to gather personal information will include appropriate privacy information or a clear reference to the relevant privacy notice.
The school will identify and record an appropriate lawful basis for processing. Consent will be used where appropriate, but is not required for every use or disclosure of personal data. Where consent is used, it must be freely given, specific, informed and capable of being withdrawn. Special category data and criminal offence data require additional legal conditions and safeguards.
Privacy notices will explain the controller’s identity, contact details, purposes and lawful bases, recipients, retention arrangements, relevant international transfers, individuals’ rights and the routes for complaints to the school and the Information Commissioner’s Office (ICO).
Definitions
Some useful definitions are:
- “Processing” means obtaining, recording, holding, using, sharing or deleting personal information.
- “Data subject” is the person who is the subject of the information being obtained, recorded etc.
- “Personal data” means any information relating to an identified or identifiable living person. This includes names and addresses and may also include photographs (see Photography Policy).
- “Special category data” includes information about health, racial or ethnic origin, religion and other categories given additional protection under the UK GDPR.
- “Parent” includes a person with parental responsibility for a child; references to parents in education legislation includes guardians etc,
Obtaining and Keeping Reliable Data
In general terms, we aim to do this by ensuring the following:
- Data is used fairly, lawfully and transparently.
- Data is collected for specified, legitimate purposes and used compatibly with those purposes.
- Data is adequate, relevant and limited to what is necessary.
- Data is accurate and kept up to date where necessary.
- Data is retained only for as long as necessary.
- Data is protected against unauthorised access, loss, damage or disclosure.
The school will maintain appropriate records to demonstrate compliance.
Data Accuracy
We will maintain data which is as up to date and as accurate as possible. If a data subject lets us know of any changes to his or her personal information, we will make the change promptly, subject to appropriate verification. Every data subject will receive a copy of their personal data sheet every two years so it can be verified, and may notify changes at any time. Should a data subject challenge the accuracy of data shown, and we cannot amend it straightaway, the disputed information will be marked accordingly and any necessary restriction on its use considered until the matter is resolved. The Principal will investigate and record the outcome, with School Board oversight where necessary. Requests to rectify personal data will be handled within the applicable statutory timescale, normally one month.
Length of Time
Data should not be kept longer than is necessary. The school will maintain a retention schedule based on relevant legal requirements and published guidance, including requirements for safeguarding, personnel and examination records. The Principal will ensure that retention arrangements are reviewed and implemented. Paper records will be securely shredded or destroyed through an approved confidential disposal service. Electronic records will be securely deleted, including through appropriate arrangements for backups. Records subject to a continuing legal, safeguarding or evidential need will not be destroyed prematurely.
Complaints Relating to Data Protection
Parents, pupils, staff and others may raise concerns about the handling of their personal data with the Principal, as data protection lead, through the school office or in writing to the school. An accessible complaint form will be available electronically and in paper form; use of the form is not compulsory. A complaint about the Principal’s handling of personal data may be addressed to the Chairman of the School Board through the school office.
The school will:
- Acknowledge receipt within 30 days, including during school holidays.
- Investigate and take appropriate steps without undue delay.
- Keep the complainant informed of progress.
- Communicate the outcome and any corrective action without undue delay.
- Record the complaint, acknowledgement, enquiries, action and outcome securely.
The school’s Complaints Policy provides further information about the internal process. This process must be accessible to pupils, staff and other data subjects as well as parents. Individuals retain the right to complain to the ICO at ico.org.uk or on 0303 123 1113. The ICO will normally expect them to raise the matter with the school first. Complaints and subject access requests have different timescales; raising a complaint does not suspend a subject access deadline.
Individuals’ Rights
Under the UK GDPR, individuals have the following rights, subject to the applicable legal conditions and exemptions:
- The right to be informed.
- The right of access.
- The right to rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability where applicable.
- The right to object.
- Rights and safeguards relating to solely automated decisions with legal or similarly significant effects, including information, an opportunity to make representations, human intervention and the ability to contest decisions where required.
IGS: Durham will ensure that those rights are respected. Not every right applies to every form of processing. Where portability applies, the school will provide the relevant data in a structured, commonly used, machine-readable format. Transfers to another school will be considered under the appropriate lawful basis and carried out securely.
Subject Access Requests
Individuals may make subject access requests verbally or in writing, without using a particular form or legal wording. Requests should be referred promptly to the Principal. All requests will be recorded securely, including the date received, requester, data subject, information requested, applicable deadline, action taken and response.
The school will respond without undue delay and normally within one month. Where permitted by law, the period may be extended by up to a further two months for complex or multiple requests, with the requester informed within the initial month and given reasons. Necessary identity checks and reasonably required clarification will be handled in accordance with current ICO guidance; any lawful adjustment to the deadline will be explained and recorded. The school will make a reasonable and proportionate search and supply information securely in an accessible form. Requests will normally be free of charge; any refusal or charge must have a lawful justification and be explained with information about complaint rights.
Access rights belong to the pupil. There is no general age 16 or age 13 threshold for exercising these rights. The school will consider the pupil’s maturity, understanding, wishes and best interests. A parent may act on behalf of a pupil who is not competent to exercise the right, or with the authority of a competent pupil. Parental responsibility does not automatically confer access to all of a competent pupil’s personal data. Applicable exemptions, safeguarding risks and the rights of other individuals will be considered before disclosure.
As an independent school in England, IGS: Durham is not subject to the separate 15-school-day parental education-record access requirement applying to maintained schools. Subject access requests will be handled under the UK GDPR timescales above.
Authorised Disclosures
The school will disclose personal information only where there is an appropriate lawful basis and any additional conditions are met. Relevant disclosures may include:
- Pupil data necessary for the school to perform its legal duties.
- Information shared with appropriate professionals or agencies to safeguard a child or protect health and safety.
- Appropriate information to parents about a child’s progress and welfare, taking account of the child’s rights and circumstances.
- Staff data released to relevant authorities, for example in respect of payroll.
- Information accessed by approved service providers under appropriate confidentiality, security and data-processing arrangements.
Only authorised and appropriately trained staff may disclose personal data to external bodies. All staff must refer safeguarding concerns promptly to the DSL. Data protection law must not be used as a reason to delay necessary safeguarding information sharing. Consent is not normally required for appropriate safeguarding disclosures. Information shared must be relevant, necessary, proportionate, accurate and secure. Decisions to share or withhold safeguarding information, and the reasons, will be recorded.
No person other than a member of the School Board or teaching staff or an authorised member of the administration or support teams may use the staff room. All staff are responsible for keeping information displayed on staff-room notice boards confidential. Parents and other visitors must not be allowed to enter the staff room. Disclosures must be assessed for risks to a pupil’s health, welfare or safety; this does not prevent necessary disclosures to appropriate safeguarding agencies.
Data Security
The school will use appropriate physical and technical safeguards for both paper and electronic records, in accordance with its Cyber Security Policy. Paper records will be securely stored and accessible only to authorised persons. Filing cabinets and offices where data is held are locked when unattended. All visitors to school are required to sign in, wear a visitor badge and where appropriate be accompanied at all times.
Electronic data may be held only on approved, secure devices and services. Access will be limited to authorised users according to their roles, protected by strong passwords and multi-factor authentication where available. Shared passwords and insecure recording of credentials must be avoided. Access permissions will be reviewed and removed when no longer needed. Security updates, protected backups and tested recovery arrangements will be maintained.
Filtering and monitoring records, including staff and pupil browsing data, will be handled as personal data. Monitoring must be necessary, proportionate and transparent, with appropriate restrictions on access and retention and explanations in privacy notices. The school will assess privacy risks and undertake a data protection impact assessment where processing is likely to result in high risk, including when introducing relevant monitoring or AI systems. Personal data must not be entered into unapproved AI tools. Service providers must be subject to appropriate checks and contracts; international transfers require applicable legal safeguards.
Personal Data Breaches
All suspected loss, unauthorised access or disclosure of personal data must be reported immediately to the Principal. The DSL must also be informed where safeguarding is affected. The school will contain the incident, preserve relevant evidence, assess risks and record all personal data breaches and decisions about notification.
The school will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals will be informed without undue delay, subject to applicable legal exceptions. Incident handling and recovery will follow the Cyber Security Policy.
Training
All staff will receive regular training in data protection. Training will include confidentiality, secure handling, recognising requests and complaints, reporting breaches and appropriate safeguarding information sharing. Relevant temporary staff, volunteers and contractors will receive appropriate instructions for their roles.
Responsibilities
Day-to-day responsibility for implementing this policy lies with the Principal. All staff have responsibility for ensuring that procedures are followed and should refer questions or uncertainties to the Principal. Data protection training will be included in induction. The School Board will oversee compliance by the data controller. Data protection will be a standing item at School Board meetings, at which the Principal will report on the effectiveness of policies, emerging risks and potential or actual breaches, with due regard to confidentiality.
This policy should be read in conjunction with the Safeguarding Policy, Photography Policy, Complaints Policy, Cyber Security Policy, relevant online safety and acceptable use policies, and the school’s privacy notices.
May 2026. Reviewed: September 2026. Next Review: September 2027

Discover more
If you would like to know more about life at IGS, or to book an in-person visit, contact us now.

Discover more
If you would like to know more about life at IGS, or to book an in-person visit, contact us now.