East Kent Colleges Group (EKC Group, “the Group”) is a data controller as defined by the UK General Data Protection Regulation and the Data Protection Act 2018. Our ROPA describes how and why we use personal information. As a data subject, you have a number of rights. You can:
- access and obtain a copy of your data via a subject access request
- require the Group to change incorrect or incomplete data
- require the Group to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing
- to restrict the processing of your personal data in certain ways
- to withdraw consent where we have requested and obtained your consent
- to object to certain processing of your personal data by us
- where our lawful basis is consent or performance of a contract we will allow portability of your data.
If you would like to exercise any of these rights, please contact your College or training provider.
The Group needs to collect and process personal data in order to provide services to students, manage its operations effectively, and meet legal requirements. The Record of Processing Activity (ROPA) details the categories of data subjects and personal data that we process, as well as the purpose of the processing along with any recipients the personal data may be shared with.
Personal data is information that relates to an identifiable individual. It can also include ‘special category data’, which is sensitive information for example data related to your racial or ethnic origin, religious or other beliefs, physical or mental health, the processing of which is subject to strict requirements. Similarly, information about criminal convictions and offences is also subject to strict requirements.
Purposes for processing information
The Group processes large volumes of personal data for several purposes, for example:
- Providing education and support services to our students and apprentices.
- Delivering the services agreed in our contracts.
- Safeguarding the health and safety of our staff, students, apprentices and third parties.
- Management and administration of research.
- Financial purposes.
- Data security and integrity management.
- Statutory returns and other legal obligations.
- The prevention and detection of crime.
- Marketing and event promotion.
- Recruitment (students and staff).
Through all stages of our data processing, we remain compliant with the Data Protection Act 2018 (‘DPA’).
Categories of data subjects
- Students and apprentices (current, prospective, withdrawn)
- Parents, guardians, and carers of students and apprentices (current, prospective, withdrawn)
- Staff (current, prospective, and unsuccessful applicants)
- Former staff
- Volunteers, students on work placements
- Employers and business contacts
- Professional, statutory and regulatory bodies
- Contractors
- Visitors
- Guests (of The Yarrow Hotel)
- Third parties participating in research, teaching or placements
- Complainants, enquirers and persons who may be the subject of an enquiry
- Individuals captured by CCTV or photography
- Suppliers, professional advisers and consultants
- Landlords and tenants
Categories of personal data
- Biographical information and contact details
- Education details and pupil records
- Employment records and data
- Financial details
- Health and disability data
- Lifestyle and social circumstances data
- Misconduct, disciplinary and grievances investigations and outcomes
- Next of kin and emergency contact information
- Qualifications and professional memberships information
- Students and apprentices record, attendance, and academic data
- Survey/feedback information
- Vetting and barring checks
- Visual images (for identification, publicity, security, and promotions)
We may also process the following special categories of personal data (for example, in the case that you choose to provide these to us or for us to meet our statutory obligations):
- Racial or ethnic origin
- Political opinion
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (where used for the purpose of identifying a person)
- Health data
- Sex life or sexual orientation
- Criminal conviction information (where required)
Recipients of personal data
In certain circumstances we must share personal data with a third party if this is required by law or because it otherwise deems it to be necessary to achieve a specified purpose. The Group complies with the UK General Data Protection Regulation and the Data Protection Act 2018 when disclosing personal data.
The types of people and organisations that we may be required to share personal data with is as follows:
- Auditors (internal and external)
- Employers (previous and current)
- Financial organisations, debt collection and tracing agencies
- Governmental bodies including UKVI, ESFA, and DSA
- Healthcare, social and welfare organisations
- Local Authorities
- Third party statistical agencies
- Official bodies requiring information for legal purposes (e.g. police, solicitors etc.)
- Professional and regulatory bodies, including examining and accreditation bodies
- Suppliers and service providers, including consultants and professional advisers
- Parents, guardians, carers
- Work experience or other placement providers
Transfers of data to a third country
It may be necessary for us to transfer personal data outside the UK where our data processors hold servers outside the UK or where suppliers, service providers and research partners are based outside the UK.
Where we transfer personal data outside of the UK as part of these relationships, we ensure appropriate contracts or other safeguards are in place.
Retention of data
The Group only holds personal data for as long as is necessary for the purpose(s) for which it is collected. The Group have a detailed Record Retention Policy in place.
Technological and organisational security measures
The Group takes the security of your data seriously. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
We will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place as appropriate to protect the data and to comply with our data protection, confidentiality and security standards.
Privacy notices
Privacy notices exist within the Group in respect of data held, you will be presented with these as and when you access services or use facilities. You will also find them here.
Complaints
The Data Protection Officer is responsible for advising the Group on compliance with data protection legislation and monitoring its performance against it. If you have any concerns regarding the way in which the Group is processing your personal data, please contact the DPO named below.
| ROPA for |
EKC Group (“The Group”) |
| ICO Registration Number |
Z7597166 |
| Date Registered |
2018 |
| Data Controller |
EKC Group |
| Data Protection Officer (DPO) |
Jack Collison
01843 605034
dpo@eastkent.ac.uk |
If you are unsatisfied with the way we have processed your personal data, or have any questions or concerns about your data please contact the DPO (details above). If we are not able to resolve the issue to your satisfaction, you have the right to apply to the Information Commissioner’s Office (ICO).
Last review: 04/12/2024