Data Protection Policy and Procedures

Purpose

The purpose is to set out the College’s approach to Data protection and related procedures, in compliance with the Data Protection Act 2018.

The College ensures that:

  • Proper procedures are in place for the processing and management of personal data.
  • The Principal has specific responsibilities for data protection compliance.
  • A supportive culture of best practice is adopted when personal data is provided for staff.
  • Staff clearly understand their responsibilities when processing personal data.
  • Staff understand that subject access requests (and other relevant requests) need to be dealt with promptly and courteously.
  • Individuals submitting a subject access request or exercising any other individual right are aware of what to do and who to contact.
  • Individuals’ personal data is processed in accordance with the data protection principles, that it is secure, and safe from unauthorised access, alteration, use or loss.
  • Other organisations with whom personal data is shared or transferred, meet compliance requirements.
  • Any new systems being implemented are assessed using a Data Protection Impact Assessment to determine whether they will hold personal data, whether the system presents any privacy risks, damage or impact to individuals’ data and that it meets this policy’s requirements.

Scope

This policy has been written with reference to the key GDPR principles found in the Information Commissioner’s Office guidelines: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/

The General Data Protection Regulation (GDPR) contains six “Data Protection Principles” set out in Article 5. These specify that personal data must be:

  1. Processed lawfully, fairly and in a transparent manner in relation to individuals.
  2. Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
  3. Adequate, relevant, and limited to what is necessary in relation to the purposes.
  4. Accurate and, where necessary, kept up to date.
  5. Kept in a form which permits identification of data subjects for no longer than is necessary.
  6. Processed in a manner that ensures adequate security of the personal data, using appropriate technical or organisational measures.

Article 5(2) also sets out an overarching accountability principle ‘the controller shall be responsible for, and be able to demonstrate, compliance with the principles.’

Individual rights are set out in a separate part of the GDPR. In brief, the GDPR provides the following rights for individuals:

  • The right to be informed.
  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object.
  • Rights in relation to automated decision making and profiling.

This policy applies to all College staff (whether permanent, temporary, contractors, consultants) and students.

all personal data and special categories of data (sensitive personal data) collected and processed by the Northern College of Acupuncture, in electronic format in any medium and within structured paper filing systems.

Disciplinary action may be taken against staff failing to comply with this policy.

The Northern College of Acupuncture is the Data Controller and is registered with the Information Commissioner’s Office (ICO) for collecting and using personal data. The registration reference is Z5842620.

Policy Statement

The Northern College of Acupuncture is a warm and friendly Higher Education provider dedicated to supporting students, staff and visitors as much as possible. We strive to maintain an atmosphere that is welcoming to all.

The Northern College of Acupuncture is the Data Controller and is registered with the Information Commissioner’s Office (ICO) for collecting and using personal data. The registration reference is Z5842620.

Staff are formally consulted whenever the Data Protection policy is reviewed for change.

Individuals can discuss Data Protection concerns at any point with a student representative, Student Services, their line manager, or with the Principal.

Implementation

In order to meet the requirements of the data protection principles and individual rights set out in the GDPR, the Northern College of Acupuncture adheres to the following principles and procedures when processing personal data:

Fair Collection and Processing

  • The specific conditions relating to the fair collection and use of personal data are.
  • Individuals will be informed that their information has been collected and the intended use of the data will be specified either on collection or at the earliest opportunity following collection through relevant privacy notices.
  • Personal data will be collected and processed only to the extent that it is needed to fulfil business needs or legal requirements.
  • Personal data held will be kept up to date and accurate, where necessary.
  • We will apply strict checks to determine the length of time information is held Retention of personal data will be appraised and risk assessed to determine and meet business needs and legal requirements, with the appropriate retention schedules applied to that data.
  • Personal data will be processed in accordance with the rights of the individuals about whom the personal data are held.
  • It is important that there is a lawful basis for processing any personal data and the College has documented this. A ‘cease processing request’ from an individual will be acknowledged within 3 working days, with the final response within 21 days. The final response will state whether the College intends to comply with the request and to what extent or will state the reasons why it is felt the requestor’s notice is unjustified.
  • Staff will advise the Principal in the event of any intended new purposes for processing personal data. The Principal will then arrange for a Data Protection Impact Assessment to be conducted. This is now a legal requirement.

Security

Appropriate technical, organisational and administrative security measures to safeguard personal data will be in place.

Staff will report any actual, near miss, or suspected data breaches to the Principal for investigation. Lessons learnt during the investigation of breaches will be relayed to those processing information to enable necessary improvements to be made. The Principal will report any ‘serious’ breaches to the Information Commissioner’s Office as necessary, within 72 hours of the breach being reported internally. Any unauthorised use of corporate email by staff, including sending of sensitive or personal data to unauthorised persons, or use that brings the College into disrepute, will be regarded as a breach of this policy.

Relevant Data Protection Awareness Training will be provided to staff to keep them informed of relevant legislation and guidance regarding the processing of personal information. Data protection training will also promote awareness of the College’s data protection and information security policies, procedures and processes. Staff are required to complete this training during induction and to renew their training thereafter. For key staff involved in processing personal data, renewal will be at least biannual.

Sharing and disclosure of personal information

  • The College will routinely make certain personal information publicly available. Examples include publication of degree results in graduation booklets, contact details on the website, names of Directors/Trustees, photos of staff, etc. On application to, and agreement by, the Principal the College will undertake to cease such activity, where possible, for any data subject on the grounds of such disclosure causing damage and distress.
  • Regular information sharing with third parties, where there is a valid business reason for sharing information, shall be carried out under a written agreement setting out the scope and limits of sharing. Data Processing Agreements will be applied to all contracts and management agreements where the College is the data controller contracting out services and processing of personal data to third parties (data processors). These agreements will clearly outline the roles and responsibilities of both the data controller and the data processor.
  • All data processors shall agree to conform to this policy and the GDPR, and as far as possible to indemnify the College against any prosecution, claim, proceeding, action or payments of compensation or damages without limitation and provide any personal information specified on request to the Principal.
  • As part of all relevant privacy notices the College will inform individuals of the identity of third parties with whom we may share, disclose or be required to pass on information, whilst accounting for any exemptions which may apply under the GDPR and other relevant legislation.

Personal data will not be transferred outside the European Economic Area unless that country or territory can ensure a suitable level of protection for the rights and freedoms of the data subjects in relation to the processing of their personal data.

Access

  • Members of staff will have access to personal data only where it is required as part of their functional remit;
  • All data subjects have a right of access to their own personal data. Advice will be provided to data subjects on how to request or access their personal data held by the College;
  • Staff are made aware that in the event of a Subject Access Request being received in the Northern College of Acupuncture, their emails may be searched, and relevant content disclosed, whether marked as personal or not;
  • A relevant contact address will be made available on the College website (nca.ac.uk) for data subjects to use should they wish to submit a Subject Access Request, or to make a comment or complaint about how the Northern College of Acupuncture is processing their data, or about our handling of their request for information;
  • A Subject Access Request will be acknowledged to the data subject within 3 working days, with the final response and disclosure of information (subject to exemptions) within 1 calendar month;
  • A data subject’s personal information will not be disclosed to them until their identity has been verified;
  • Third party personal data will not be released by the Northern College of Acupuncture when responding to a Subject Access Request or Freedom of Information Request (unless consent is specifically obtained, obliged to be released by law or necessary in the substantial public interest).

Links with the Freedom of Information Act 2000

The Freedom of Information Act 2000 enables greater public access to information processed by public bodies such as the Northern College of Acupuncture. However, personal data continues to be protected by the GDPR, and is therefore exempt from disclosure under the Freedom of Information Act (Section 40).

Procedures for Staff

All staff members will take steps to ensure that personal data is kept secure at all times against unauthorised or unlawful loss or disclosure and will ensure that:

  • Paper files and other records or documents containing personal/sensitive data are kept in a secure environment;
  • Personal data held on computers and computer systems is protected by the use of controlled access rights and/or secure passwords;
  • Individual passwords are such that they are not easily compromised.

All self-employed staff members (i.e., staff members holding a self-employed contract to provide services to and for the College) who hold personal data outside of the College’s control must:

  • Ensure that they are aware of this policy and are fully trained in and are aware of their duties and responsibilities under the GDPR. Any breach of any provision of GDPR will be deemed as being a breach of any contract between the College and that individual, company, partner or firm;
  • Allow data protection audits by the College of data held on its behalf (if requested);

All contractors (i.e., persons contracted to provide a specific service to the College who are not self-employed staff members, such as counsellors and educational psychologists) who are users of personal information supplied by the College will be required to confirm that they will abide by GDPR requirements with regards information supplied by the College.

If and when, as part of their responsibilities, staff collect information about other people (e.g., about students’ course work, opinions about students’ ability or fitness to practice, references to other academic institutions, details of personal circumstances, or information about patients/clients attending our clinics), they must ensure that:

  • Any personal data held is kept securely.
  • Personal information is not disclosed either orally or in writing or accidentally or otherwise to any unauthorised third party.

Staff should note that unauthorised disclosure and/or failure to adhere to the requirements below will usually be a disciplinary matter, and in some cases may be considered gross misconduct.

Personal information should:

  • if it is electronic data, be access-controlled or password protected; or
  • when in transit on portable media the files themselves must be password protected;
  • if it is in the form of paper records, be kept in a locked filing cabinet; or
  • in a locked drawer

With some exceptions, personal data should not be stored at staff members’ homes, whether in manual or electronic form, on laptop computers or other personal portable devices or at other remote sites other than approved virtual servers with secure access control and password protection. Ordinarily, personal data should not be processed at staff members’ homes, whether in manual or electronic form, on laptop computers or other personal portable devices or at other remote sites. In cases where such off-site processing is felt to be necessary or appropriate, the agreement of the Principal must be obtained, and all the security guidelines given in this document must still be followed.

Exceptions to the above are:

  1. Student information, such as assessments, marks and feedback, and data held on the College database or filing system, when this information/data is held on College approved virtual servers with secure access control and password protection (such as www.elearnwithnca i.e. Moodle) can be viewed by staff members on their own devices but must not be downloaded or stored;
  2. Emails downloaded to staff members’ electronic devices, and other selected information shared with staff by members of the management team to assist staff in their work educating and supporting students (for example information on a student’s particular support needs, which the student has agreed can be shared with staff). Devices used to store this information must comply with all the security guidelines given in this document.

Patient/client information which can be linked to an identifiable individual should never be stored on staff members’ own electronic devices. Patient/client information held on College approved virtual servers with secure access control and password protection (such as www.elearnwithnca i.e. Moodle) can be viewed by staff members on their own devices but must not be downloaded or stored.

 

Student obligations

All students are to be made fully aware of this policy and of their duties and responsibilities under GDPR.

When working in the College, including the teaching clinics, all students will take steps to ensure that personal data is kept secure at all times against unauthorised or unlawful loss or disclosure and in particular will ensure that:

  • Paper files and other records or documents containing personal/sensitive data are kept in a secure environment;
  • Personal data held on computers and computer systems is protected by the use of controlled access rights or secure passwords;
  • Individual passwords are such that they are not easily compromised.

Students who use the College computer facilities may, from time to time, process personal data, for example as part of their clinical studies. If they do so they must follow the data security and protection guidelines.

Students must not under any circumstances remove from the College and its clinics any patient or client information which can be linked to an identifiable individual, in hard copy or electronic form (including scans and photographs). Patient or client information which can be linked to an identifiable individual should never be stored on students’ own electronic devices. Patient or client information held on College approved virtual servers with secure access control and password protection (such as elearnwithnca on Moodle) can be viewed by students on their own devices but must not be downloaded or stored. A failure to comply with these rules will be treated as a disciplinary offence under the Procedures for Probation, Suspension and Exclusion.

Retention of Data

The College will keep some forms of information for longer than others. It can be to the advantage of students and alumni that information about students’ achievements and awards is kept for a long period of time, so that we can provide references, replacement copies of academic transcripts and certificates, etc. However, because of storage capacities, the College cannot guarantee that this information about students will be kept indefinitely, unless there are specific requests to do so. We will in general retain such information about students for at least ten years after they leave the College.

This will include:

  • name and contact details,
  • academic achievements, including marks for coursework, academic transcripts, awards,
  • copies of any references written.

All other information, including any information about health, additional needs, or protected characteristics will be destroyed within 2 years of the student ending their studies at the College. Information on disciplinary matters will be destroyed within 7 years of the student ending their studies at the College.

In general, most information about staff will be kept for 5 years after a member of staff leaves the College. Some information however will be kept for much longer. This will include information necessary in respect of pensions, taxation, potential or current disputes or litigation regarding their employment, and information required for job references.

Patient/client notes will be kept for 8 years from the last treatment/consultation date, or until a child reaches 25 (or 26 if attendance in clinic ends when they are 17). If a consultation with a patient/client is video recorded, we will ask for explicit consent to retain the video for educational or research purposes for 30 days or 10 years. Anonymised patient/client data with all identifying information removed may be used in student assessments which are retained for 5 years in compliance with Office for Students requirements. Anonymised patient/client data with all identifying information removed which is used in research by the College or our students is retained for 10 years.

Notification to the Information Commissioner

The Information Commissioner maintains a public register of data controllers. The Northern College of Acupuncture is registered as such, and we are required to notify and renew our notification on an annual basis. Failure to do so is a criminal offence. The Principal reviews the Data Protection Register annually, prior to notification to the Information Commissioner. Any changes to the register must be notified to the Information Commissioner, within 28 days. To this end, any changes made between reviews will be brought to the attention of the Principal immediately.

Raising matters

Staff are formally consulted whenever the policy is reviewed for change.

Individuals can discuss concerns about data protection at any point with a student representative, line manager, student services, or directly with the Principal.

 

Data Protection Responsibilities

 

Who

What

College as a corporate body

Data Controller

Board of Directors/Trustees

Ultimately responsible for compliance with the GDPR.

College Information Officer, the Principal, with assistance from the College Services Manager

Maintain the College notification with the ICO.

Advise staff on data protection compliance.

Coordinate responses for subject access requests.

Report any personal data breaches to the ICO/police as appropriate.

Issue data sharing guidance and oversee data sharing agreements between the College and third parties.

Develop, administer, disseminate, review and support application of this policy.

Ensure adequate policies are in place for security of electronic information.

Line managers

Support and encourage staff to comply with the Policy.

Ensure that line reports process personal data in line with the requirements of the principles and individuals’ data protection rights.

All staff

Be familiar with and comply with the policy.

Ensure that information provided in connection with employment is up-to-date and accurate.

Observe and comply with the data protection principles and individuals’ data protection rights.

Bring queries and issues around data protection to the attention of the College Services Manager or Principal.

Do not attempt to gain access to information that it is not necessary to hold, know or process.

Report subject access and other requests to Information Governance staff.

Note that unauthorised disclosure will usually be a disciplinary matter and may be considered gross misconduct in some cases. It may also result in a personal liability for the staff member as there is provision within the legislation to prosecute individuals for certain offences.

All students

Be familiar with the policy and comply where necessary.

Ensure that personal information provided is up-to-date and accurate.

Observe and comply with the data protection principles and individuals’ data protection rights.

Note that unauthorised disclosure of personal data will usually be a disciplinary matter.

Related policies and documents

The following are filed internally on SharePoint

  • Northern College of Acupuncture Data Breach Procedure
  • Data Breach Incident Report
  • Checklist for handling requests for personal information
  • Creating a strong password
  • NCA Staff Member Privacy Notice
  • BYOD (bring your own device) policy
  • Registration Certificate (ICO)
  • Data Protection Policy (this document)
  • Statement of Data Processing
  • Information Security Policy (relating to the processing of credit and debit card payments)
  • Subject Access Request Form
  • Code of Practice for Research
  • Privacy and Cookies Policy
  • CCTV code of practice, policy and procedures

 

Related documents for the teaching clinics are at the following links:

NCA Chinese Herbal Medicine Clinic Data Processing Agreement

Notes from your consultations - your informed consent (Herbs clinic)

Policy Review Date: 20 June 2023

Signed off by Senior Management Team: 22 June 2023

Next Review date (biannual): June 2025

Related Articles