Specialist Post-16 Special Educational Needs and Disabilities (SEND) Further Education | EHCP-Led Provision
0330 043 6730 info@thearkcollege.com

Data Protection Policy

Data Protection Policy

Explains how we handle personal data, comply with UK GDPR and protect the privacy of our learners, families and staff.

1. Purpose and Scope

This policy sets out The Ark Specialist College's commitment to protecting personal data and ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all personal data processed by the college, whether held electronically or in paper form.

2. Data Protection Principles

We adhere to the following data protection principles:

  • Lawfulness, fairness and transparency β€” we process data lawfully and openly
  • Purpose limitation β€” we only use data for specified, explicit purposes
  • Data minimisation β€” we collect only what is necessary
  • Accuracy β€” we keep data accurate and up to date
  • Storage limitation β€” we retain data only as long as needed
  • Integrity and confidentiality β€” we keep data secure
  • Accountability β€” we demonstrate our compliance

3. Roles and Responsibilities

The Principal is the Data Protection Officer (DPO) for the college, supported by the administration team. All staff are responsible for handling personal data securely and in accordance with this policy. Training is provided to all staff on data protection and information security.

4. Data Subject Rights

Individuals whose data we hold have the following rights:

  • Right of access (Subject Access Request)
  • Right to rectification
  • Right to erasure ('right to be forgotten')
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making

Requests to exercise these rights should be made in writing to the Principal at info@thearkcollege.com.

5. Data Security

We implement appropriate technical and organisational measures to safeguard personal data, including: secure storage, access controls, encryption, regular backups, staff training, and incident response procedures. In the event of a personal data breach, we will notify the ICO and affected individuals in accordance with our legal obligations.

6. Data Sharing

We share personal data only when necessary and lawful. This may include sharing with local authorities, health professionals, Ofsted, and other regulatory bodies. We do not sell or rent personal data.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Retention periods are set out in our retention schedule and are reviewed regularly. Records are disposed of securely when no longer needed.

Policy Enquiries or Request a Policy

If you cannot find the policy you are looking for, please contact the college office. We can provide information in a suitable format where possible.

15A Wedge Street, Walsall, WS1 2HQ