As part of the College’s data processing activities we will process special category data and criminal offence data under Article 9 and 10 of the GDPR and Schedule 1 of the Data Protection Act 2018.
Pursuant to Schedule 1, Part 4 of the DPA 2018, this Appropriate Policy Document explains the processing that may occur and the relevant procedures the College follows to ensure compliance with data protection legislation and supplements information contained within the College’s privacy notices.
Special category data is defined under Article 9(1) of the GDPR;
'Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.'
Criminal Conviction data is defined under Section 11(2) of the DPA 2018;
'In Article 10 of the GDPR and section 10, references to personal data relating to criminal convictions and offences or related security measures include personal data relating to—
(a) the alleged commission of offences by the data subject, or
(b) proceedings for an offence committed or alleged to have been committed by the data subject or the disposal of such proceedings, including sentencing.'
Paragraph 1 – Employment, social security and social protection
Paragraph 4 – Research
Paragraph 8 – Equality of opportunity or treatment
Paragraph 10 – Preventing or detecting unlawful acts
Paragraph 11 – Protecting the public against dishonesty
Paragraph 12 – Regulatory requirements relating to unlawful acts and dishonesty
Paragraph 17 – Counselling
Paragraph 18 – Safeguarding of children and of individuals at risk
Accountability principle
Principle (a): lawfulness
Whenever personal data is processed by Imperial College London;
At least one condition under Schedule 1 has been identified or the data subject has given consent for the processing activity.
Data subjects have been provided transparency information at the point of data collection or processing is deemed to be lawful.
All special category data will be processed in line with Article 6(1) and 9(2) of the GDPR. For more information about the different types of legal basis please see the following - Processing personal data.
Principle (a): fairness and transparency
Imperial College makes appropriate privacy information available through Privacy Statements provided to data subjects in line with Article 13 or Article 14 respectively.
Examples of over-arching College notices are as follows;
Principle (b): purpose limitation
Special category data will be processed in line with the College’s Schedule 1 condition as set out above not further processed orreused for a different purpose as that originally collected unless an exception under data protection legislation applies.
All processing will be supported by suitable policies and / or guidelines to ensure it is conducted in a transparent and legally compliant manner. For example, potential processing of criminal data would form part of the following;
Principle (c): data minimisation
Special category data is only collected where necessary for our specified purposes. The College ensures that that we have adequate special category data to properly fulfil those purposes.
Principle (d): accuracy
We have appropriate processes in place to check / ensure the accuracy of the special category data we collect, and we record the source of that data.
Special category data will be updated as necessary.
We have a policy and procedures in place (see accountability principle above) that outline how we deal with challenges to the accuracy of data and how we ensure compliance with the individual’s right to rectification.
Principle (e): storage limitation
The data described in this statement will be retained in line with the College's Retention Schedule.
Data is reviewed annually to ensure that records that have exceeded this retention period are erased or managed automatically in line with the aforementioned retention schedules.
Principle (f): integrity and confidentiality (security)
Appropriate technical measures are in place to ensure that this data is held securely.
Access is limited to relevant staff and/or those providing the service who are all aware of their personal responsibilities in relation to data protection and the confidentiality of the information they handle.
The privacy of our website visitors is important to us so we do not track any individual visitors. As a visitor to the REMAP-ILD website:
We are committed to complying with The Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR) on our website and on our website analytics.
We use Cookie-free Analytics to collect some anonymous usage data for statistical purposes. The goal is to track overall trends in our website traffic, it is not to track individual visitors. All the data is in aggregate only. No personal data is collected.
The anonymised data collected includes: referral sources, pages visited, visit duration, information from the devices (device type, operating system, country and browser) used during the visit and more.
The only cookies collected are essential, namely: session cookies and load-balancing cookies, both of which are exempt from having to gain explicit user consent. See the Information Commissioner's Office (ICO) website for more information.