Data Protection Policy
Official School Policy Document
SV Academy - Data Protection, Privacy and Use of Images Policy
Including Privacy Notice
Policy Owner | Executive Headteacher |
Operational Lead | Headteacher, supported by Data Protection Lead / DPO where designated |
Approved By | Directors / Proprietor of SV Academy |
Date Approved | September 2026 |
Last Reviewed | September 2026 |
Next Review | September 2027 or sooner if law/guidance or processing changes |
Version | 2026.1 |
Policy status: This policy replaces the previous Data Protection Policy and Privacy Notice, including previous image-use provisions. Operational first-aid and medical-care procedures are governed by separate Academy arrangements; this policy covers the data-protection aspects of health and medical information.
1. Statement of Intent
SV Academy is committed to protecting the privacy, dignity and rights of students, parents/carers, staff, applicants, volunteers, contractors, visitors and other individuals whose personal data it processes. The Academy will process personal data lawfully, fairly, transparently and securely, and will use only the information reasonably necessary for legitimate educational, safeguarding, employment, regulatory and operational purposes.
Data protection is a shared responsibility. It must support, not obstruct, effective safeguarding. Where information needs to be shared to protect a child or another person, staff must act promptly, lawfully and proportionately and record the reasons for their decision.
2. Scope
This policy applies to all personal data processed by or on behalf of SV Academy in paper, electronic, audio-visual, cloud, communication, CCTV and other formats. It applies to both compulsory-school-age/statutory or commissioned provision and Post-16 provision, and to current, former and prospective students, staff and other members of the Academy community.
It applies to all staff, volunteers, contractors, agency workers and third parties who process personal data for the Academy. Separate privacy notices may provide additional information for pupils/students, parents/carers, staff, job applicants, website users or other groups.
3. Legal and Guidance Framework
This policy is informed by current data protection, education and safeguarding law and guidance, including:
UK General Data Protection Regulation (UK GDPR), as amended.
Data Protection Act 2018.
Data (Use and Access) Act 2025, including data protection complaint-handling and changes to information rights.
Privacy and Electronic Communications Regulations 2003 (PECR), as amended, where applicable to electronic marketing and communications.
Human Rights Act 1998 and the common law duty of confidentiality.
Education (Independent School Standards) Regulations 2014, as amended.
Keeping Children Safe in Education 2026 and current statutory safeguarding/information-sharing guidance.
Freedom of Information Act 2000 only where it applies to the Academy or a particular function; it should not be assumed to apply merely because a request is received.
Current Department for Education and Information Commissioner's Office guidance on data protection, privacy notices, photographs/video, CCTV, AI, data breaches and information rights.
4. Data Protection Principles
SV Academy will apply the UK GDPR principles to all personal-data processing:
Principle | Academy expectation |
|---|---|
Lawfulness, fairness and transparency | Use personal data only where there is a valid lawful basis, in a fair way, and explain the processing clearly. |
Purpose limitation | Collect personal data for specified, explicit and legitimate purposes and do not use it incompatibly without a lawful basis. |
Data minimisation | Collect and share only the personal data that is adequate, relevant and necessary. |
Accuracy | Take reasonable steps to keep personal data accurate and correct or complete it where necessary. |
Storage limitation | Keep identifiable personal data only for as long as there is a lawful and documented need. |
Integrity and confidentiality | Protect data against unauthorised or unlawful access, disclosure, loss, destruction or damage. |
Accountability | Be able to demonstrate compliance through policies, records, training, contracts, audits, DPIAs and appropriate governance. |
5. Roles and Responsibilities
Role | Key responsibilities |
|---|---|
Directors / Proprietor | Overall governance and assurance that appropriate data protection arrangements, resources and oversight are in place. |
Executive Headteacher | Strategic oversight of data protection, privacy, information governance and significant compliance risks; escalates material issues to Directors. |
Headteacher | Day-to-day implementation across the Academy, including ensuring staff follow procedures and that operational decisions are lawful and documented. |
Data Protection Lead / DPO where designated | Advises on compliance, monitors practice, supports rights requests, privacy notices, DPIAs, contracts, complaints and breach response. Where the Academy is legally required to appoint a DPO, that role will be independent and have direct access to senior leadership. |
DSL and safeguarding team | Ensure safeguarding data is recorded, shared and transferred lawfully and securely. Data protection must not be used as a barrier to protecting a child. |
IT Lead / IT Support | Implements technical security, access control, backups, logging, patching and cyber incident response in accordance with Academy policies. |
All staff, volunteers and contractors | Use personal data only for authorised purposes, follow need-to-know access, keep data secure, report incidents immediately and complete required training. |
SV Academy is the data controller for personal data where it determines the purposes and means of processing. In some arrangements another organisation may also be an independent or joint controller.
6. Personal Data We Process
Depending on the relationship with the Academy and the services being provided, personal data may include:
identity and contact data, including names, addresses, dates of birth and emergency contacts
admission, enrolment, attendance, timetable and programme information
academic, assessment, examination, qualification and destination information
SEND, disability, reasonable-adjustment and support information
health, medical, dietary, welfare and pastoral information
safeguarding and child-protection information
behaviour, disciplinary, complaints, allegations and incident records
financial, funding, bursary, free-school-meal and socio-economic information where relevant
staff recruitment, employment, payroll, pension, performance and training data
DBS and other criminal-offence information where the Academy is lawfully entitled to process it
photographs, video, audio and CCTV images
online identifiers, account, device, network, email and security log information
information received from referring schools, local authorities, commissioners, awarding organisations, employers, health professionals, social care and other authorised third parties.
7. Lawful Bases for Processing
The Academy will identify and document the appropriate lawful basis for each processing activity. The basis depends on the purpose and context and may include:
Lawful basis | When it may apply |
|---|---|
Contract | Where processing is necessary to enter into or perform a contract, for example certain employment or fee/service arrangements. |
Legal obligation | Where the Academy must process data to comply with law, regulatory duties, safeguarding, employment, tax, attendance, examination or other requirements. |
Legitimate interests | Where the Academy or a third party has a legitimate interest, the processing is necessary, and the interests and rights of the individual do not override it. |
Recognised legitimate interests | Where a recognised legitimate interest prescribed by data protection law applies, subject to the conditions of that legislation. |
Vital interests | Where processing is necessary to protect somebody's life or vital interests, particularly in emergencies. |
Consent | Where consent is the appropriate lawful basis. Consent must be freely given, specific, informed and capable of withdrawal. |
Public task | Only where a particular Academy function is supported by law and the public-task basis is applicable. |
Special category and criminal-offence data will only be processed where the additional legal conditions are met.
8. Privacy Information and Collection of Data
SV Academy will provide clear and accessible privacy information explaining what data is collected, why it is used, the lawful basis, who it may be shared with, how long it is retained, whether it may be transferred internationally, and the rights available to individuals. Privacy notices will be reviewed at least annually and whenever there is a significant change in processing.
Personal data may be collected directly from the individual or their parent/carer, or received from schools, local authorities, commissioners, awarding organisations, employers, health professionals, social care, government bodies, public sources or other authorised organisations. Where data is obtained indirectly, the Academy will provide privacy information where required by law.
9. Children, Young People and Post-16 Learners
Children and young people have their own data-protection rights. There is no single fixed age in UK data-protection law at which a pupil automatically exercises all rights independently; the Academy will consider the young person's age, maturity and understanding, the nature of the request and any safeguarding implications.
Parents/carers are routinely provided with appropriate educational, attendance, pastoral and welfare information where there is a lawful basis to do so. However, personal data about a child belongs to the child. A parent requesting data under subject access may need to demonstrate authority to act for the child, particularly where the young person is sufficiently mature to exercise their own rights.
For Post-16 students, the Academy will normally communicate directly with the student as well as with parents/carers where appropriate, lawful and consistent with the student's rights, funding or safeguarding arrangements.
10. Sharing Personal Data and Safeguarding
Personal data will be shared only where there is a lawful basis, for a defined purpose and with appropriate security. Consent is not always required and should not be sought where the Academy already has another lawful basis or a legal/safeguarding duty to share.
Safeguarding information must be shared when necessary to protect a child. Staff should not delay necessary safeguarding action because they are uncertain about data protection. The DSL or deputy and, where appropriate, the Data Protection Lead should be consulted, but immediate protection of the child takes priority. Decisions to share or not share should be recorded with the rationale.
Recipients may include:
parents/carers and pupils/students where lawful and appropriate
referring schools, local authorities and commissioners
Department for Education, Ofsted and other regulators where required
awarding organisations, examination boards and qualification regulators
children's social care, LADO, police, health services and safeguarding partners
employers, work-experience providers and careers/progression partners where appropriate
professional advisers, insurers, auditors, accountants and legal advisers
IT, MIS, cloud, communications, payment, website and other service providers acting under appropriate contracts
other recipients where disclosure is required or permitted by law or where a valid lawful basis has been established.
11. Commissioned and Statutory Placements
For students placed or commissioned by a school, local authority or other body, SV Academy may need to exchange personal data about attendance, progress, safeguarding, SEND, behaviour, risk, funding and placement review. The Academy and commissioner remain responsible for establishing their respective lawful bases and controller/processor roles. Information-sharing arrangements should be proportionate and documented where appropriate.
12. Service Providers, EdTech, Cloud Services and International Transfers
Before appointing a supplier that processes personal data, the Academy will carry out proportionate due diligence, identify the supplier's data-protection role, and put in place the contract terms required by law. Access must be limited to what is necessary and suppliers must provide appropriate security and breach-reporting arrangements.
Where personal data is transferred outside the UK, SV Academy will ensure that a valid transfer mechanism and appropriate safeguards are in place. The Academy will consider international transfers, sub-processors and data locations when procuring cloud, communication, AI and EdTech services.
13. Data Protection Impact Assessments and Privacy by Design
The Academy will consider data protection from the start of any new project, system or process. A Data Protection Impact Assessment (DPIA) will be completed where processing is likely to result in high risk to individuals, and may also be used as good practice for new technologies, extensive monitoring, sensitive data sharing, CCTV, biometric systems, AI, profiling or significant changes to existing systems.
14. Artificial Intelligence and Automated Processing
Personal, safeguarding, SEND, health, staff or other confidential information must not be entered into an unapproved public AI system. Where the Academy proposes to use AI with personal data, the tool must be approved, the processing must be covered by the Academy's privacy information, and the Data Protection Lead / IT Lead must be satisfied that the tool, contract, security, retention and training arrangements are appropriate.
SV Academy will be transparent where AI is used to process personal data. It will not rely on a solely automated decision producing legal or similarly significant effects on an individual unless this is lawful and appropriate safeguards, including meaningful human review where required, are in place.
15. Information Security and Access Control
Personal data will be protected by appropriate technical and organisational measures. Controls will reflect the sensitivity of the data and may include role-based access, strong authentication, multi-factor authentication, encryption, secure backups, patching, endpoint protection, filtering/monitoring, audit logs, secure disposal, staff training and approved storage locations.
Use Academy-approved systems and accounts for Academy personal data unless a documented exception has been authorised.
Do not send personal data to personal email accounts or store it on unapproved personal cloud services.
Lock devices when unattended and keep confidential papers secure.
Remove or change access promptly when a person changes role or leaves.
Report suspected phishing, unauthorised access, loss, disclosure or other security incidents immediately.
16. Personal Data Breaches
A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. All suspected breaches must be reported immediately to the Headteacher and Data Protection Lead / DPO and, where relevant, the IT Lead and DSL.
Contain the incident and protect affected systems or individuals.
Record what happened, what data and people may be affected, and when the Academy became aware.
Assess likely risk to individuals.
Notify the ICO without undue delay and, where feasible, within 72 hours where required.
Inform affected individuals without undue delay where the breach is likely to result in high risk.
Record all breaches and remedial actions.
17. Individual Rights and Subject Access Requests
Individuals have rights under data-protection law, subject to conditions and exemptions.
A subject access request (SAR) may be made verbally or in writing and does not need to use legal terminology or a specific form. SV Academy will respond without undue delay and normally within one month after the applicable time period begins. Where permitted by law, the period may be extended for complex or multiple requests. If clarification is reasonably required to identify the information requested, the time limit may be paused in accordance with current law.
The Academy may need proportionate evidence of identity or authority before releasing information. Third-party information, legal privilege, examination material, confidential references and other exempt information will be handled in accordance with the applicable law. The Academy will make a reasonable and proportionate search for information within the scope of a valid request.
to be informed about how personal data is used
to request access to their personal data (subject access)
to request correction of inaccurate or incomplete data
to request erasure in circumstances where the right applies
to request restriction of processing in circumstances where the right applies
to object to certain processing, including direct marketing
to data portability where the legal conditions apply
to withdraw consent at any time where consent is the lawful basis
to safeguards in relation to solely automated decision-making where applicable
to complain to the Academy and, if unresolved, to the Information Commissioner's Office.
18. Data Protection Complaints
SV Academy provides a clear route for individuals to complain about how their personal data has been handled. A data-protection complaint should be sent to the Data Protection Lead / DPO through the School Office. In accordance with the Data (Use and Access) Act 2025 requirements in force in 2026, the Academy will acknowledge a complaint within 30 days, investigate and respond without undue delay, keep the complainant informed as appropriate, and explain the right to complain to the Information Commissioner's Office.
19. Retention, Archiving and Secure Disposal
SV Academy will maintain and periodically review a retention schedule. It will not apply a single blanket retention period such as seven years to all records. Different categories of records have different statutory, safeguarding, employment, examination, contractual and operational retention needs.
Records that are no longer required will be securely deleted, anonymised, archived or destroyed in accordance with the retention schedule. Destruction must be appropriate to the medium and sensitivity of the data and, where required, documented.
20. Taking, Storing and Using Photographs and Video
Images of identifiable individuals are personal data and must have a lawful basis. The Academy may use photographs/video for educational activities, records, identification, displays, newsletters, website content, social media, trips, performances, sports, publicity and other legitimate purposes.
For public-facing promotional or social-media use involving students, SV Academy will normally use recorded consent or another clearly documented lawful basis after considering the child's rights and safeguarding circumstances. Consent may be withdrawn for future use. Where consent is not the lawful basis, a valid objection will still be considered in accordance with data-protection law.
Check restrictions, safeguarding concerns, court orders or opt-outs before publishing.
Do not normally publish a student's full name with a public image unless specifically justified and authorised.
Use Academy-approved devices and storage for official images. Personal devices are not to be used unless a documented exception is authorised.
Transfer images promptly to approved storage and retain only as long as necessary.
External photographers, volunteers and contractors acting for the Academy must follow Academy policies.
Assess new platforms, AI/image tools and cloud services before uploading identifiable images.
21. CCTV
Where CCTV is used, SV Academy will operate it for defined purposes such as site security, safeguarding, incident management and protection of people/property. CCTV will be subject to a documented lawful basis, appropriate signage, access restrictions, retention arrangements and security controls. CCTV will not normally be installed in toilets or changing areas.
22. Personal Photography and Filming at Academy Events
The Academy may permit parents/carers and family members to take photographs or video for personal use at specified events. Data-protection law does not normally apply to purely personal or household use, but the Academy may impose safeguarding, privacy, copyright, safety or event-management restrictions. Public posting of identifiable images of other pupils may create privacy and safeguarding risks and families are asked not to publish such images without appropriate permission.
23. Student Use of Cameras, Phones and Recording Equipment
Students must follow the Academy's Acceptable Use of Technology, Online Safety and Behaviour policies. Recording another person without permission, recording in private areas, sharing intimate or humiliating images, using images to bully or impersonate another person, or creating harmful manipulated/deepfake content may result in disciplinary and/or safeguarding action and referral to external agencies where appropriate.
24. Health, Medical and Welfare Information
Health and medical information is special category personal data and will be processed only where there is a lawful basis and an appropriate special-category condition. Access will be restricted to staff who need the information to keep the student safe or provide appropriate education, pastoral support, first aid or reasonable adjustments.
Relevant health information may be shared with emergency services, healthcare professionals, trip staff, caterers or others where necessary and lawful. Routine immunisation programmes and medical services will follow the consent and confidentiality arrangements applicable to the service and the young person's competence.
This policy does not authorise Academy staff to give legal consent to medical treatment on behalf of a parent. In an emergency, staff should call 999 and provide relevant information. Healthcare professionals may provide necessary treatment in accordance with applicable law and the patient's best interests where consent cannot be obtained. The Academy will make reasonable efforts to contact parents/carers promptly.
25. Direct Marketing, Newsletters and Keeping in Touch
Operational communications about education, safeguarding, attendance, contracts or Academy services are not treated in the same way as optional marketing. Where SV Academy sends direct marketing, fundraising or promotional electronic communications, it will identify an appropriate lawful basis and comply with PECR where applicable. Recipients will be given a straightforward way to opt out, and suppression records may be retained so that their preference can be respected.
26. Training, Monitoring and Audit
Staff who handle personal data will receive appropriate data-protection and information-security training at induction and refresher training thereafter. The Academy will monitor compliance through audits, access reviews, incident/breach logs, rights requests, complaints, supplier reviews, DPIAs, retention reviews and safeguarding/cyber-security assurance.
27. Monitoring and Review
The Executive Headteacher will maintain strategic oversight of this policy. The Headteacher and Data Protection Lead / DPO will review implementation and recommend changes. The policy and related privacy notices will be reviewed at least annually and sooner where legislation, guidance, technology, processing activities or safeguarding risks change materially.
Appendix A - SV Academy Privacy Notice Summary
Data Controller: SV Academy, 6 Eltham High Street, London SE9 1DA.
Data protection contact: Data Protection Lead / DPO (where designated), via the School Office. Email: info@streetvibes.org. Telephone: 0203 031 8240.
Why we use personal data: to provide education and support, administer admissions/enrolment and attendance, safeguard students, meet SEND/health needs, run assessments and qualifications, manage staffing and finance, comply with legal/regulatory duties, communicate with families and commissioners, maintain security and manage the Academy efficiently.
How long we keep data: according to the Academy retention schedule, legal requirements and safeguarding/operational needs. We do not keep all records for the same period.
Your rights: see section 17. Requests and questions may be sent to the Data Protection Lead / DPO through the School Office. Individuals may also complain to the Information Commissioner's Office (ICO).
Appendix B - Quick Staff Data Protection Check
Do I need this personal data for a clear Academy purpose?
What is the lawful basis, and is special-category or criminal-offence data involved?
Am I collecting or sharing only the minimum necessary?
Does the person know how their data will be used?
Is the information accurate and up to date?
Am I using an approved system, device, AI tool or supplier?
Is access limited to people who need it?
Do I need a DPIA or advice from the Data Protection Lead, DSL or IT Lead?
Can I share this securely, and have I checked the recipient?
If something goes wrong, have I reported it immediately?
Appendix C - Key External Guidance
Department for Education - Privacy notices for schools and local authorities
Department for Education - Taking and using photos and videos, and using CCTV in schools
Department for Education - Generative AI and data protection in schools
Information Commissioner's Office - Data protection guidance
Information Commissioner's Office - Data protection complaints