Data Protection
The GDPR (General Data Protection Regulation) protects personal data privacy, ensuring individuals control how their data is collected and used. This page is designed to inform all stakeholders how schools in the Bright Futures Federation process personal data of pupils, parents, staff, governors and other individuals fairly and lawfully.
Data Processing
St Giles CE Primary School ensures that personal data is accurate, kept secure, processed fairly and lawfully, and is retained for no longer that is deemed necessary. As a school, our main legal grounds for processing data is 'public task'. This means that we process personal data to carry out our official function in the public interest. When necessary, we also use 'consent' where the grounds for processing data may not be seen as necessary but supports the work of the school.
Data Controller
Each school within the Bright Futures Federation is a Data Controller in its own right, but operates under the shared policies, procedures, and oversight of the Federation.
St Giles CE Primary School complies with the GDPR and is registered as a 'Data Controller' with the Information Commissioner's Office (ICO) reference number: Z6505429. As part of the regulation, the school is required to appoint a named Data Protection Officer. Any enquiries about data should be sent to the Data Protection Officer via email to office@stgilesprimary.co.uk.
Policies & Privacy Notices
The following policies and privacy notices set out the manner in which personal data of pupils, parents, staff, governors, volunteers and other individuals is processed fairly and lawfully. The School collects and uses personal information about individuals who come into contact with the School in order to enable it to provide education and other associated functions. In addition, there may be a legal requirement to collect and use information to ensure that the School complies with its statutory obligations.
This area will show all documents uploaded to the /docs/Policies/Data_Protection folder.
FOLDER=Policies/Data. Protection|sortorder=AZ|quantity=All|showicons=y|showyears=n|ShowDate=n|ShowSearch=n|layoutchoice=boxwithpreview
Further details of the school's purpose for holding and processing data can be viewed on the data protection register: https://ico.org.uk/ESDWebPages/Entry/Z6505429
Third Parties
St Giles CE Primary School uses a number of third party IT systems to process data such as attendance, communication and assessment information. Information about these providers and their GDPR compliance can be found below:
Bromcom Management Information System (MIS) is a cloud based system used by the majority of maintained schools in West Sussex. It is an electronic database that holds pupil information that is required during their time in education. This includes contact details for the pupils and parents/ guardian, as well as any special educational needs and medical information. Some of this information is passed to a school that a pupil transfers to, for example when moving to secondary school. This system also provides the government with details for census and assessment purposes, as well as registration and attendance data. To view Bromcom's privacy notice please visit: bromcom.com/privacy
ParentMail is our chosen communication and parental engagement system run by IRIS Software Group. It is used to send emails and text messages to parents, distribute letters and collect electronic payments for school visits and other events. To view ParentMail's privacy policy please visit: www.iris.co.uk/privacy-policy
FFT (Fischer Family Trust) is a UK-based non-profit organization that provides data analysis, pupil tracking, and research to schools and local authorities to improve education outcomes. As a school we make use of FFT Aspire, a school data analysis tool, and some of their literacy programmes such as Lightning Squad. To view FFT's privacy information please visit: fft.org.uk/privacy
Class Dojo is an online platform used to share learning, celebrate achievements and communicate with parents. It helps strengthen the link between home and school by keeping families informed. To view Class Dojo's privacy policy please visit: https://www.classdojo.com/en-gb/privacy
Travel Tracker is a simple web based tool run by Living Streets and used to log journeys to school. No personal details are shared with Living Streets. The Walk Once a Week (WOW) campaign promotes walking and cycling as it is good for children's health and the environment. To view the WOW Travel Tracker privacy policy please visit: www.traveltracker.org.uk/privacy
Cool Milk supply milk to pupils in our school. To enable this to happen, a pupil's name, date of birth and class are shared with the company. To view Cool Milk's GDPR privacy policy please visit: coolmilk.com/privacy-policy
Chartwells are part of the Compass Group and are the chosen hot school meals provider for the majority of schools in West Sussex. Infant age pupils automatically received hot school meals but in Key Stage 2, some pupil information is shared when parents sign up via the West Sussex Meal Selector. To view the Compass Group privacy policy please visit: www.compass-group.com/en/site-services/privacy-notice.html
Virtual IT (previously JSPC) provide IT technical support to many schools in and around West Sussex. They supply and maintain software, hardware and our school network. At times they may provide support troubleshooting systems that handle personal data. To read Virtual IT's customer privacy policy please visit: virtualit.cloud/privacy-policy
Microsoft 365 Education is a collection of online services that allows pupils and staff to collaborate and share their learning. Our school utilises many Microsoft software packages including Outlook, Word, Excel, PowerPoint, and Teams through an annual licensing agreement. Whilst at St Peter's, both staff and pupils will be provided with a 365 account which is managed by our IT support provider, Virtual IT. To view Microsoft's Privacy Statement please visit: privacy.microsoft.com/en-gb/privacystatement
All providers are GDPR compliant and have strict procedures in place to protect any data that they hold on our behalf.
