On the 25th May 2018, the General Data Protection Regulation (GDPR) came into force in the UK.
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU).
The GDPR require public authorities and businesses to identify the lawful basis for storing personal data, audit information we already hold and take a ‘data protection by design and default’ approach to personal data.
At St Cross Catholic Primary School, we take data protection very seriously. In line with GDPR requirements, we have appointed a Data Protection Officer (DPO) to oversee our approach to data management and protection. Our DPO is Mrs Hollie Drake.
In order to ensure that we fully comply with the new regulations, we are reviewing our current policies and practices. We have already updated our privacy notices in line with the new requirements. Once approved, these will be available on our website, under Important Information/ GDPR, along with our revised Data Protection Policy.
As part of the compliance process, we are also seeking to update the consent forms we have received from parents and pupils. The new regulations are clear that consent must be up-to-date and clearly recorded. From now on, lack of response cannot be interpreted as implied consent. Reviewed consent forms will be distributed in due course. We ask that you return the consent forms by return.
Draft Policies are uploaded here, pending approval by the Governing Body.