Data Protection Policy


The AQ Khan Schooling Systems Schools collect and use personal information about staff, pupils, parents and other individuals who come into contact with the school. This information is gathered in order to enable it to provide education and other associated functions. In addition, there may be a legal requirement to collect and use information to ensure that the school complies with its statutory obligations.


Information – covers any information, including electronic capture and storage, manual paper records, video and audio recordings and any images, however created.

Personal Data – Any data which can be used to identify a living person. This includes names, birthday and anniversary dates, addresses, telephone numbers, fax numbers, email addresses and so on. It applies only to that data which is held, or intended to be held, on computers (‘equipment operating automatically in response to instructions given for that purpose’), or held in a ‘relevant filing system’. This includes paper filing systems.

Strong Password – Password which is 8 characters minimum length, contains upper and lower case alphabetical characters and numbers or punctuation characters. It should not contain dictionary words, the owner’s date of birth or car registration number.

Encryption – Process of transforming information (referred to as plaintext) using an algorithm (called a cipher) to make it unreadable to anyone except those possessing special knowledge, usually referred to as a key.


This policy is intended to ensure that personal information is dealt with correctly and securely, and other related legislation. It will apply to information regardless of the way it is collected, used, recorded, stored and destroyed, and irrespective of whether it is held in paper files or electronically.

All staff involved with the collection, processing and disclosure of personal data will be aware of their duties and responsibilities by adhering to these guidelines.

What is Personal Information?

Personal information or data is defined as data which relates to a living individual who can be identified from that data, or other information held.

Data Protection Principles

  1. Personal data shall be processed fairly and lawfully;
  2. Personal data shall be obtained only for one or more specified and lawful purposes;
  3. Personal data shall be adequate, relevant and not excessive;
  4. Personal data shall be accurate and where necessary, kept up to date;
  5. Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose or those purposes;
  6. Personal data shall be kept secure e. protected by an appropriate degree of security;

General Statement

The school is committed to maintaining the above principles at all times. Therefore the school will:

  • Inform individuals why the information is being collected when it is collected
  • Inform individuals when their information is shared, and why and with whom it was shared
  • Check the quality and the accuracy of the information it holds
  • Ensure that information is not retained for longer than is necessary
  • Ensure that when obsolete information is destroyed that it is done so appropriately and securely
  • Ensure that clear and robust safeguards are in place to protect personal information from loss, theft and unauthorised disclosure, irrespective of the format in which it is recorded
  • Share information with others only when it is legally appropriate to do so
  • Ensure our staff are aware of and understand our policies and procedures


This policy will be reviewed as it is deemed appropriate, but no less frequently than every 2 years. The policy review will be undertaken by the Headteacher, or nominated representative.