Logo

Data Protection Policy

Official School Policy Document

SV Academy - Data Protection, Privacy and Use of Images Policy

Including Privacy Notice

Policy Owner

Executive Headteacher

Operational Lead

Headteacher, supported by Data Protection Lead / DPO where designated

Approved By

Directors / Proprietor of SV Academy

Date Approved

September 2026

Last Reviewed

September 2026

Next Review

September 2027 or sooner if law/guidance or processing changes

Version

2026.1

Policy status: This policy replaces the previous Data Protection Policy and Privacy Notice, including previous image-use provisions. Operational first-aid and medical-care procedures are governed by separate Academy arrangements; this policy covers the data-protection aspects of health and medical information.

1. Statement of Intent

SV Academy is committed to protecting the privacy, dignity and rights of students, parents/carers, staff, applicants, volunteers, contractors, visitors and other individuals whose personal data it processes. The Academy will process personal data lawfully, fairly, transparently and securely, and will use only the information reasonably necessary for legitimate educational, safeguarding, employment, regulatory and operational purposes.

Data protection is a shared responsibility. It must support, not obstruct, effective safeguarding. Where information needs to be shared to protect a child or another person, staff must act promptly, lawfully and proportionately and record the reasons for their decision.

2. Scope

This policy applies to all personal data processed by or on behalf of SV Academy in paper, electronic, audio-visual, cloud, communication, CCTV and other formats. It applies to both compulsory-school-age/statutory or commissioned provision and Post-16 provision, and to current, former and prospective students, staff and other members of the Academy community.

It applies to all staff, volunteers, contractors, agency workers and third parties who process personal data for the Academy. Separate privacy notices may provide additional information for pupils/students, parents/carers, staff, job applicants, website users or other groups.

3. Legal and Guidance Framework

This policy is informed by current data protection, education and safeguarding law and guidance, including:

  • UK General Data Protection Regulation (UK GDPR), as amended.

  • Data Protection Act 2018.

  • Data (Use and Access) Act 2025, including data protection complaint-handling and changes to information rights.

  • Privacy and Electronic Communications Regulations 2003 (PECR), as amended, where applicable to electronic marketing and communications.

  • Human Rights Act 1998 and the common law duty of confidentiality.

  • Education (Independent School Standards) Regulations 2014, as amended.

  • Keeping Children Safe in Education 2026 and current statutory safeguarding/information-sharing guidance.

  • Freedom of Information Act 2000 only where it applies to the Academy or a particular function; it should not be assumed to apply merely because a request is received.

  • Current Department for Education and Information Commissioner's Office guidance on data protection, privacy notices, photographs/video, CCTV, AI, data breaches and information rights.

4. Data Protection Principles

SV Academy will apply the UK GDPR principles to all personal-data processing:

Principle

Academy expectation

Lawfulness, fairness and transparency

Use personal data only where there is a valid lawful basis, in a fair way, and explain the processing clearly.

Purpose limitation

Collect personal data for specified, explicit and legitimate purposes and do not use it incompatibly without a lawful basis.

Data minimisation

Collect and share only the personal data that is adequate, relevant and necessary.

Accuracy

Take reasonable steps to keep personal data accurate and correct or complete it where necessary.

Storage limitation

Keep identifiable personal data only for as long as there is a lawful and documented need.

Integrity and confidentiality

Protect data against unauthorised or unlawful access, disclosure, loss, destruction or damage.

Accountability

Be able to demonstrate compliance through policies, records, training, contracts, audits, DPIAs and appropriate governance.

5. Roles and Responsibilities

Role

Key responsibilities

Directors / Proprietor

Overall governance and assurance that appropriate data protection arrangements, resources and oversight are in place.

Executive Headteacher

Strategic oversight of data protection, privacy, information governance and significant compliance risks; escalates material issues to Directors.

Headteacher

Day-to-day implementation across the Academy, including ensuring staff follow procedures and that operational decisions are lawful and documented.

Data Protection Lead / DPO where designated

Advises on compliance, monitors practice, supports rights requests, privacy notices, DPIAs, contracts, complaints and breach response. Where the Academy is legally required to appoint a DPO, that role will be independent and have direct access to senior leadership.

DSL and safeguarding team

Ensure safeguarding data is recorded, shared and transferred lawfully and securely. Data protection must not be used as a barrier to protecting a child.

IT Lead / IT Support

Implements technical security, access control, backups, logging, patching and cyber incident response in accordance with Academy policies.

All staff, volunteers and contractors

Use personal data only for authorised purposes, follow need-to-know access, keep data secure, report incidents immediately and complete required training.

SV Academy is the data controller for personal data where it determines the purposes and means of processing. In some arrangements another organisation may also be an independent or joint controller.

6. Personal Data We Process

Depending on the relationship with the Academy and the services being provided, personal data may include:

  • identity and contact data, including names, addresses, dates of birth and emergency contacts

  • admission, enrolment, attendance, timetable and programme information

  • academic, assessment, examination, qualification and destination information

  • SEND, disability, reasonable-adjustment and support information

  • health, medical, dietary, welfare and pastoral information

  • safeguarding and child-protection information

  • behaviour, disciplinary, complaints, allegations and incident records

  • financial, funding, bursary, free-school-meal and socio-economic information where relevant

  • staff recruitment, employment, payroll, pension, performance and training data

  • DBS and other criminal-offence information where the Academy is lawfully entitled to process it

  • photographs, video, audio and CCTV images

  • online identifiers, account, device, network, email and security log information

  • information received from referring schools, local authorities, commissioners, awarding organisations, employers, health professionals, social care and other authorised third parties.

7. Lawful Bases for Processing

The Academy will identify and document the appropriate lawful basis for each processing activity. The basis depends on the purpose and context and may include:

Lawful basis

When it may apply

Contract

Where processing is necessary to enter into or perform a contract, for example certain employment or fee/service arrangements.

Legal obligation

Where the Academy must process data to comply with law, regulatory duties, safeguarding, employment, tax, attendance, examination or other requirements.

Legitimate interests

Where the Academy or a third party has a legitimate interest, the processing is necessary, and the interests and rights of the individual do not override it.

Recognised legitimate interests

Where a recognised legitimate interest prescribed by data protection law applies, subject to the conditions of that legislation.

Vital interests

Where processing is necessary to protect somebody's life or vital interests, particularly in emergencies.

Consent

Where consent is the appropriate lawful basis. Consent must be freely given, specific, informed and capable of withdrawal.

Public task

Only where a particular Academy function is supported by law and the public-task basis is applicable.

Special category and criminal-offence data will only be processed where the additional legal conditions are met.

8. Privacy Information and Collection of Data

SV Academy will provide clear and accessible privacy information explaining what data is collected, why it is used, the lawful basis, who it may be shared with, how long it is retained, whether it may be transferred internationally, and the rights available to individuals. Privacy notices will be reviewed at least annually and whenever there is a significant change in processing.

Personal data may be collected directly from the individual or their parent/carer, or received from schools, local authorities, commissioners, awarding organisations, employers, health professionals, social care, government bodies, public sources or other authorised organisations. Where data is obtained indirectly, the Academy will provide privacy information where required by law.

9. Children, Young People and Post-16 Learners

Children and young people have their own data-protection rights. There is no single fixed age in UK data-protection law at which a pupil automatically exercises all rights independently; the Academy will consider the young person's age, maturity and understanding, the nature of the request and any safeguarding implications.

Parents/carers are routinely provided with appropriate educational, attendance, pastoral and welfare information where there is a lawful basis to do so. However, personal data about a child belongs to the child. A parent requesting data under subject access may need to demonstrate authority to act for the child, particularly where the young person is sufficiently mature to exercise their own rights.

For Post-16 students, the Academy will normally communicate directly with the student as well as with parents/carers where appropriate, lawful and consistent with the student's rights, funding or safeguarding arrangements.

10. Sharing Personal Data and Safeguarding

Personal data will be shared only where there is a lawful basis, for a defined purpose and with appropriate security. Consent is not always required and should not be sought where the Academy already has another lawful basis or a legal/safeguarding duty to share.

Safeguarding information must be shared when necessary to protect a child. Staff should not delay necessary safeguarding action because they are uncertain about data protection. The DSL or deputy and, where appropriate, the Data Protection Lead should be consulted, but immediate protection of the child takes priority. Decisions to share or not share should be recorded with the rationale.

Recipients may include:

  • parents/carers and pupils/students where lawful and appropriate

  • referring schools, local authorities and commissioners

  • Department for Education, Ofsted and other regulators where required

  • awarding organisations, examination boards and qualification regulators

  • children's social care, LADO, police, health services and safeguarding partners

  • employers, work-experience providers and careers/progression partners where appropriate

  • professional advisers, insurers, auditors, accountants and legal advisers

  • IT, MIS, cloud, communications, payment, website and other service providers acting under appropriate contracts

  • other recipients where disclosure is required or permitted by law or where a valid lawful basis has been established.

11. Commissioned and Statutory Placements

For students placed or commissioned by a school, local authority or other body, SV Academy may need to exchange personal data about attendance, progress, safeguarding, SEND, behaviour, risk, funding and placement review. The Academy and commissioner remain responsible for establishing their respective lawful bases and controller/processor roles. Information-sharing arrangements should be proportionate and documented where appropriate.

12. Service Providers, EdTech, Cloud Services and International Transfers

Before appointing a supplier that processes personal data, the Academy will carry out proportionate due diligence, identify the supplier's data-protection role, and put in place the contract terms required by law. Access must be limited to what is necessary and suppliers must provide appropriate security and breach-reporting arrangements.

Where personal data is transferred outside the UK, SV Academy will ensure that a valid transfer mechanism and appropriate safeguards are in place. The Academy will consider international transfers, sub-processors and data locations when procuring cloud, communication, AI and EdTech services.

13. Data Protection Impact Assessments and Privacy by Design

The Academy will consider data protection from the start of any new project, system or process. A Data Protection Impact Assessment (DPIA) will be completed where processing is likely to result in high risk to individuals, and may also be used as good practice for new technologies, extensive monitoring, sensitive data sharing, CCTV, biometric systems, AI, profiling or significant changes to existing systems.

14. Artificial Intelligence and Automated Processing

Personal, safeguarding, SEND, health, staff or other confidential information must not be entered into an unapproved public AI system. Where the Academy proposes to use AI with personal data, the tool must be approved, the processing must be covered by the Academy's privacy information, and the Data Protection Lead / IT Lead must be satisfied that the tool, contract, security, retention and training arrangements are appropriate.

SV Academy will be transparent where AI is used to process personal data. It will not rely on a solely automated decision producing legal or similarly significant effects on an individual unless this is lawful and appropriate safeguards, including meaningful human review where required, are in place.

15. Information Security and Access Control

Personal data will be protected by appropriate technical and organisational measures. Controls will reflect the sensitivity of the data and may include role-based access, strong authentication, multi-factor authentication, encryption, secure backups, patching, endpoint protection, filtering/monitoring, audit logs, secure disposal, staff training and approved storage locations.

  • Use Academy-approved systems and accounts for Academy personal data unless a documented exception has been authorised.

  • Do not send personal data to personal email accounts or store it on unapproved personal cloud services.

  • Lock devices when unattended and keep confidential papers secure.

  • Remove or change access promptly when a person changes role or leaves.

  • Report suspected phishing, unauthorised access, loss, disclosure or other security incidents immediately.

16. Personal Data Breaches

A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. All suspected breaches must be reported immediately to the Headteacher and Data Protection Lead / DPO and, where relevant, the IT Lead and DSL.

  1. Contain the incident and protect affected systems or individuals.

  2. Record what happened, what data and people may be affected, and when the Academy became aware.

  3. Assess likely risk to individuals.

  4. Notify the ICO without undue delay and, where feasible, within 72 hours where required.

  5. Inform affected individuals without undue delay where the breach is likely to result in high risk.

  6. Record all breaches and remedial actions.

17. Individual Rights and Subject Access Requests

Individuals have rights under data-protection law, subject to conditions and exemptions.

A subject access request (SAR) may be made verbally or in writing and does not need to use legal terminology or a specific form. SV Academy will respond without undue delay and normally within one month after the applicable time period begins. Where permitted by law, the period may be extended for complex or multiple requests. If clarification is reasonably required to identify the information requested, the time limit may be paused in accordance with current law.

The Academy may need proportionate evidence of identity or authority before releasing information. Third-party information, legal privilege, examination material, confidential references and other exempt information will be handled in accordance with the applicable law. The Academy will make a reasonable and proportionate search for information within the scope of a valid request.

  • to be informed about how personal data is used

  • to request access to their personal data (subject access)

  • to request correction of inaccurate or incomplete data

  • to request erasure in circumstances where the right applies

  • to request restriction of processing in circumstances where the right applies

  • to object to certain processing, including direct marketing

  • to data portability where the legal conditions apply

  • to withdraw consent at any time where consent is the lawful basis

  • to safeguards in relation to solely automated decision-making where applicable

  • to complain to the Academy and, if unresolved, to the Information Commissioner's Office.

18. Data Protection Complaints

SV Academy provides a clear route for individuals to complain about how their personal data has been handled. A data-protection complaint should be sent to the Data Protection Lead / DPO through the School Office. In accordance with the Data (Use and Access) Act 2025 requirements in force in 2026, the Academy will acknowledge a complaint within 30 days, investigate and respond without undue delay, keep the complainant informed as appropriate, and explain the right to complain to the Information Commissioner's Office.

19. Retention, Archiving and Secure Disposal

SV Academy will maintain and periodically review a retention schedule. It will not apply a single blanket retention period such as seven years to all records. Different categories of records have different statutory, safeguarding, employment, examination, contractual and operational retention needs.

Records that are no longer required will be securely deleted, anonymised, archived or destroyed in accordance with the retention schedule. Destruction must be appropriate to the medium and sensitivity of the data and, where required, documented.

20. Taking, Storing and Using Photographs and Video

Images of identifiable individuals are personal data and must have a lawful basis. The Academy may use photographs/video for educational activities, records, identification, displays, newsletters, website content, social media, trips, performances, sports, publicity and other legitimate purposes.

For public-facing promotional or social-media use involving students, SV Academy will normally use recorded consent or another clearly documented lawful basis after considering the child's rights and safeguarding circumstances. Consent may be withdrawn for future use. Where consent is not the lawful basis, a valid objection will still be considered in accordance with data-protection law.

  • Check restrictions, safeguarding concerns, court orders or opt-outs before publishing.

  • Do not normally publish a student's full name with a public image unless specifically justified and authorised.

  • Use Academy-approved devices and storage for official images. Personal devices are not to be used unless a documented exception is authorised.

  • Transfer images promptly to approved storage and retain only as long as necessary.

  • External photographers, volunteers and contractors acting for the Academy must follow Academy policies.

  • Assess new platforms, AI/image tools and cloud services before uploading identifiable images.

21. CCTV

Where CCTV is used, SV Academy will operate it for defined purposes such as site security, safeguarding, incident management and protection of people/property. CCTV will be subject to a documented lawful basis, appropriate signage, access restrictions, retention arrangements and security controls. CCTV will not normally be installed in toilets or changing areas.

22. Personal Photography and Filming at Academy Events

The Academy may permit parents/carers and family members to take photographs or video for personal use at specified events. Data-protection law does not normally apply to purely personal or household use, but the Academy may impose safeguarding, privacy, copyright, safety or event-management restrictions. Public posting of identifiable images of other pupils may create privacy and safeguarding risks and families are asked not to publish such images without appropriate permission.

23. Student Use of Cameras, Phones and Recording Equipment

Students must follow the Academy's Acceptable Use of Technology, Online Safety and Behaviour policies. Recording another person without permission, recording in private areas, sharing intimate or humiliating images, using images to bully or impersonate another person, or creating harmful manipulated/deepfake content may result in disciplinary and/or safeguarding action and referral to external agencies where appropriate.

24. Health, Medical and Welfare Information

Health and medical information is special category personal data and will be processed only where there is a lawful basis and an appropriate special-category condition. Access will be restricted to staff who need the information to keep the student safe or provide appropriate education, pastoral support, first aid or reasonable adjustments.

Relevant health information may be shared with emergency services, healthcare professionals, trip staff, caterers or others where necessary and lawful. Routine immunisation programmes and medical services will follow the consent and confidentiality arrangements applicable to the service and the young person's competence.

This policy does not authorise Academy staff to give legal consent to medical treatment on behalf of a parent. In an emergency, staff should call 999 and provide relevant information. Healthcare professionals may provide necessary treatment in accordance with applicable law and the patient's best interests where consent cannot be obtained. The Academy will make reasonable efforts to contact parents/carers promptly.

25. Direct Marketing, Newsletters and Keeping in Touch

Operational communications about education, safeguarding, attendance, contracts or Academy services are not treated in the same way as optional marketing. Where SV Academy sends direct marketing, fundraising or promotional electronic communications, it will identify an appropriate lawful basis and comply with PECR where applicable. Recipients will be given a straightforward way to opt out, and suppression records may be retained so that their preference can be respected.

26. Training, Monitoring and Audit

Staff who handle personal data will receive appropriate data-protection and information-security training at induction and refresher training thereafter. The Academy will monitor compliance through audits, access reviews, incident/breach logs, rights requests, complaints, supplier reviews, DPIAs, retention reviews and safeguarding/cyber-security assurance.

27. Monitoring and Review

The Executive Headteacher will maintain strategic oversight of this policy. The Headteacher and Data Protection Lead / DPO will review implementation and recommend changes. The policy and related privacy notices will be reviewed at least annually and sooner where legislation, guidance, technology, processing activities or safeguarding risks change materially.

Appendix A - SV Academy Privacy Notice Summary

Data Controller: SV Academy, 6 Eltham High Street, London SE9 1DA.

Data protection contact: Data Protection Lead / DPO (where designated), via the School Office. Email: info@streetvibes.org. Telephone: 0203 031 8240.

Why we use personal data: to provide education and support, administer admissions/enrolment and attendance, safeguard students, meet SEND/health needs, run assessments and qualifications, manage staffing and finance, comply with legal/regulatory duties, communicate with families and commissioners, maintain security and manage the Academy efficiently.

How long we keep data: according to the Academy retention schedule, legal requirements and safeguarding/operational needs. We do not keep all records for the same period.

Your rights: see section 17. Requests and questions may be sent to the Data Protection Lead / DPO through the School Office. Individuals may also complain to the Information Commissioner's Office (ICO).

Appendix B - Quick Staff Data Protection Check

  1. Do I need this personal data for a clear Academy purpose?

  2. What is the lawful basis, and is special-category or criminal-offence data involved?

  3. Am I collecting or sharing only the minimum necessary?

  4. Does the person know how their data will be used?

  5. Is the information accurate and up to date?

  6. Am I using an approved system, device, AI tool or supplier?

  7. Is access limited to people who need it?

  8. Do I need a DPIA or advice from the Data Protection Lead, DSL or IT Lead?

  9. Can I share this securely, and have I checked the recipient?

  10. If something goes wrong, have I reported it immediately?

Appendix C - Key External Guidance