The Union is responsible for managing data about students, the organisation and its activities. This could be anything - student e-mail address sign-ups, club/society memberships, event attendances, e-mails from individual students, etc.
As staff, we need to make sure we keep information secure. To help with this, we have a policy, that makes it clear to students and other stakeholders what data we have, and what we do with it.
Data protection and privacy policy
This page gives you some broad things to be thinking about in performing your role at the Union.
What data should I worry about?
Any information that can identify an individual - student, staff, member of the public, etc. Some information we might know about them is more sensitive, e.g. health, sexuality, religion, etc.
What are my responsibilities?
- Only collect data you need for the Union's service
- Be clear to the person what you are going to do with the data, and get explicit consent where possible
- Use secure IT systems, with strong passwords - preferably UCL's or the Union's, and never using something like your personal Gmail account - see Union IT - what to use for what
- Restrict access to the data to only those who need it - but make sure it's not just you! (e.g. include your manager or colleague)
- Don't share data outside the Union - this includes UCL! Only share if it is already covered by our data protection and privacy policy
- Delete data when you no longer need it, bearing in mind UCL's retention policy
- Have clear ways of accessing and managing the data, e.g. keeping it on a shared drive rather than a personal folder, so that the organisation can help individuals can exercise their rights around it
- Anonymise data if you only need data for statistical purposes (delete any identifying data, e.g. e-mails etc)
- Report any data breaches or issues immediately to [email protected]
What rights do individuals have?
Individuals whose data we hold have the right to control what we do with data - and the right to revoke any permissions they have granted us (except where legislation or specific compliance needs require us to keep some information, e.g. HR or financial records).
Basically, individuals have these rights for nearly all data about them we may have, in any system:
- Know what we collect and what we do with it
- Access the data
- Correct errors in the data
- Delete the data
- Restrict what we do with the data
- Get a copy of the data
- Object to our use of the data
It's important we manage our data in ways that make it easy for people to exercise those rights.