Difference between revisions of "GDPR"

Line 1: Line 1:
__NOTOC__
__NOTOC__
<div style="column-count:2;-moz-column-count:2;-webkit-column-count:2">
<div style="column-count:2;-moz-column-count:2;-webkit-column-count:2">
The UK / EU General Data Protection Regulation (GDPR) replaces the existing 1995 EU Data Protection Directive (European Directive 95/46/EC), it imposes strict controls on how all organisations collect and process personal data within the UK / EU and/or the personal data of UK / EU citizens.  We are constantly improving the technical and organisational security measures we have in place to protect your data and are committed to being fully compliant with GDPR and our role as a data processor.  
Personal data in the United Kingdom is governed by the '''UK GDPR''' and the '''Data Protection Act 2018''', as amended by the '''Data (Use and Access) Act 2025'''.  Schools in the EU/EEA are covered by the EU GDPR.  These impose strict controls on how organisations collect and process personal data.


It is our policy to keep data private, secure, and safe.  We do this in several ways, including:
Under this legislation '''your school is the data controller''' and '''we are a data processor''' acting on your documented instructions.  We are committed to meeting our obligations in that role, and we keep our technical and organisational security measures under continual review.
 
It is our policy to keep data private, secure and safe.  We do this in several ways, including:


* Data is collected only for specific, explicit and legitimate purposes.
* Data is collected only for specific, explicit and legitimate purposes.
* Sensitive data is encoded whilst on and before it leaves your computer.
* Sensitive data is encoded whilst on, and before it leaves, your computer.
* Data is also further encrypted with AES-256 encryption locally and/or with us (optionally turned off).
* Data is further encrypted with AES-256 encryption locally and/or with us (optionally turned off — see below).
* Passwords are stored with us as one-way salted hashes.
* Passwords are stored with us as one-way salted hashes.
* SSL technology is used to ensure data is private during communication.
* TLS is used to ensure data is private during communication.
* Data is retained only for as long as necessary.
* Data is retained only for as long as necessary, and to a published schedule.
* Regular backups are made in-case we ever need to recover data.
* Regular backups are made in case we ever need to recover data.
* Personal data can be exported in a machine-readable format.
* Personal data can be exported in a machine-readable format at any time.
 
===Why encryption is optional for some customers:===
A small number of our customers are outside the UK and EU.  In those cases we necessarily send data to those countries so that the school can edit its own reports.  Some of those countries do not permit the use of encryption, and for that reason we provide the option to turn off local and/or server-side encryption.  The default is '''local off, server on'''.  In any event, data is encoded and is never stored in plain text.


===Why data may sometimes be sent outside of the UK / EU<span style="display:none;"> or outside the Privacy Shield</span> and why encryption is optional:===
The settings are found in '''Admin > School Details'''. We recommend leaving local encryption off so that, in the event of a local hard drive fault, recovery software has a better chance of working.
A small percentage of our customers are not within the UK / EU<span style="display:none;"> or the Privacy Shield</span>, in that unusual case we will have to send data outside of the UK / EU<span style="display:none;"> or Privacy Shield</span> to those specific customers - this is so they can edit their reports.  The customers in some of those countries may also not legally be allowed to encrypt data, for that reason we have the option to turn off either local and/or server encryption for their data.  The default for these settings is 'local off, server on'.  In any event, data is also encoded and not stored in plain text.  The settings for encryption are in Admin>School Details.   The reason we recommend local encryption off is so that if you have a local hard drive fault then recovery software will have a better chance of working.


===Where is data stored?===
===Where is data stored?===
We use DreamHost to store data.  DreamHost has included the Model Clauses in its Data Processing Addendum which is legally sufficient for meeting the GDPR's requirements for exporting data to a non-EU country in lieu of Privacy Shield: https://www.dreamhost.com/legal/customer-data-processing-addendum/ (Please see Section 6 and Schedule B.)
Our servers and data storage are provided by '''DreamHost''' (DreamHost, LLC, Brea, California, USA)Backups are held on a secure server managed by '''Deluxe Pixel Limited in Preston, United Kingdom'''.
 
Because DreamHost processes data in the United States, this involves a '''restricted transfer''' under UK GDPR.  That transfer is covered by appropriate safeguards under Article 46:
 
* DreamHost's [https://www.dreamhost.com/legal/customer-data-processing-addendum/ Customer Data Processing Addendum] incorporates the '''Standard Contractual Clauses''' approved by the European Commission in 2021 (Schedule D, Module Two — controller to processor).
* These are supplemented by the '''International Data Transfer Addendum''' issued by the UK Information Commissioner's Office (Annex III; ICO template B.1.0, laid before Parliament on 2 February 2022).
 
<span style="display:none;">We have carried out a '''Transfer Risk Assessment''' in line with ICO guidance, and review it periodically.  A copy is available to schools on request.</span>
 
''Note: the EU–US Privacy Shield framework, referred to in earlier versions of this page, was invalidated by the Court of Justice of the European Union in July 2020.  We do not rely on it, nor on its successor the UK Extension to the EU–US Data Privacy Framework.  Our transfers rest on the contractual safeguards described above, which are not affected by changes to those adequacy arrangements.''
 
===Our sub-processors:===
We use the following sub-processors in providing the service:
 
{| class="wikitable"
! Sub-processor !! Purpose !! Location
|-
| DreamHost, LLC || Hosting, data storage and backup || USA
|-
| Deluxe Pixel Limited || Off-site backup || United Kingdom
|-
| ''(add any e-mail, payment or AI providers here)'' || ||
|}
 
We will give schools notice before adding or replacing a sub-processor.
 
===How long we keep data:===
{| class="wikitable"
! Data !! Retention
|-
| Reports and report data || Retained while the licence is active, and for ''[period]'' after it ends unless the school asks in writing for earlier deletion
|-
| Pupil photographs and artwork || Deleted at the end of the academic year in which they were uploaded
|-
| Backups || Overwritten on a rolling ''[period]'' cycle
|-
| Website logs || Encrypted and deleted after 72 hours
|}


<span style="display:none;">===What is the Privacy Shield:===</span>
Schools may request deletion of their data at any time by writing to usAdministrators can also export all school data to a machine-readable file at any point — see [[GDPR backups]].
<span style="display:none;">The EU and UK data adequacy finding states that data transfers are covered by the EU-US / UK-US Privacy Shield frameworkThe Privacy Shield places requirements on US companies certified by the scheme to protect personal data and provides for redress mechanisms for individuals. US Government departments such as the Department of Commerce oversee certification under the scheme.  The privacy shield allows us to use servers that make our service more cost-effective.</span>
<span style="display:none;">Our website and data storage is managed on servers run by Raging Wire: https://www.privacyshield.gov/participant?id=a2zt0000000TVX5AAO  (USA, East Coast)</span>
<span style="display:none;">Our general e-mail is managed on servers run by Flexential Corp: https://www.privacyshield.gov/participant?id=a2zt0000000GnYlAAK  (USA, West Coast)</span>


===Why we would sometimes provide third parties with your information:===
===Why we would sometimes provide third parties with your information:===
An example of an abnormal condition that could arise would be if we were asked by a school to directly interface with a third-party support team that the school uses or if we were forced to provide information to a third party if we are requested by the police/court - e.g. for a set of past school reports for a particular pupil.
Examples of circumstances in which this could arise are if a school asked us to work directly with a third-party support team it uses, or if we were legally compelled to provide information — for example on a valid request from the police or a court, such as for a set of past reports for a particular pupil.
 
We will not disclose school data to any third party except where legally required, and we will notify the school of any such request unless we are prohibited from doing so.


===Who has access to your information:===
===Who has access to your information:===
Only a few select staff have access to the school licence name and password - our admin system checks their IP address as well as their password and will prevent logging in if incorrect. All our staff are DBS (Disclosure and Barring Service) checked. All passwords are stored using a one-way salted hash code - that is why we can't recover teacher passwords, just replace them. Our server checks IP addresses for direct data access and only allows specific IP addresses to directly log into the database, everything else must through our web API which requires the username and password to gain access. Our web API does not use cookies or sessions to prevent things like cookie hijacking and session fixation attacks. Full backups are made daily between 2 am and 3 am to a secure machine in a different location to the main server.
* Only a small number of staff have access to school licence credentials.  Our admin system checks IP address as well as password and will refuse a login if either is incorrect.
* All our staff are '''DBS (Disclosure and Barring Service) checked'''.
* All passwords are stored as one-way salted hashes — which is why we cannot recover a teacher's password, only replace it.
* Direct database access is restricted to specific IP addresses.  All other access must go through our web API, which requires a valid username and password.
* Our web API does not use cookies or sessions, which avoids cookie hijacking and session fixation attacks.
* Full backups are taken daily between 2am and 3am to a secure machine in a separate location from the main server.
</div>


Data is backup up on average once per 24 hours and is stored on a secure server managed by Deluxe Pixel Limited in Preston, United Kingdom.
Website logs are encrypted and deleted after 72 hours.
</div>
===Our registration with the ICO:===
===Our registration with the ICO:===
The enforcement of the GDPR is overseen by the United Kingdom’s supervisory authority, the Information Commissioner’s Office (ICO). It ensures that everyone is playing by the rules and that the rights of data subjects - the people whose data is being processed - are correctly protected.
Enforcement of the UK GDPR is overseen by the United Kingdom's supervisory authority, the '''Information Commissioner's Office (ICO)'''. It ensures that organisations follow the rules and that the rights of data subjects the people whose data is being processed are properly protected.


We are registered with the Information Commissioner's Office in the UK (ID: [https://ico.org.uk/ESDWebPages/Entry/ZA551060 ZA551060]).  You can download a copy of our certificate [https://deluxepixel.com/downloads/pdf/ico.pdf here].
We are registered with the Information Commissioner's Office (ID: [https://ico.org.uk/ESDWebPages/Entry/ZA551060 ZA551060]).  You can download a copy of our certificate [https://deluxepixel.com/downloads/pdf/ico.pdf here].


===Your school contact:===
===Your data protection contact:===
[[file:gdpr.png|thumb|right|Specify your data protection contact]]
[[file:gdpr.png|thumb|right|Specify your data protection contact]]
Under the GDPR, those collecting or processing data at 'large scale', collecting or processing certain types of sensitive data, or who is a 'public authority or body' may need to designate a Data Protection Officer (DPO) and/or a UK / EU representative.   This is the person who we would normally contact regarding data protection.
Under the UK GDPR, organisations processing personal data at large scale, processing certain special categories of data, or which are a public authority or body, may need to designate a '''Data Protection Officer (DPO)''' and, where relevant, a UK or EU representative. This is the person we would normally contact about data protection matters.


Administrators will see a screen similar to this one if we do not yet know who to contact at your school.


Administrators will see a screen similar to this if we do not know who to contact regarding data protection.
Within the program, administrators will also find a GDPR option in the Administrator menu showing who you told us about and when.


Within the program, administrators will also see a GDPR option in the Administrator menu that shows who and when you informed us who your data protection contact is.
Administrators can also [[GDPR backups|back up]] all school data to a machine-readable file.


Administrators also have the option of [[GDPR backups|backing up]] all the school data to a machine-readable file.
===Rights of individuals:===
Because your school is the data controller, requests from parents, pupils or staff to access, correct or delete personal data should be made to the school in the first instance.  We will assist you in responding to any such request.  If a request is made directly to us, we will pass it to the school rather than responding ourselves.


If you ever want to contact us about GDPR, data protection or to find out more about how we process your data, please feel free to drop an email to our [mailto:dpo@reportcomplete.com?subject=GDPR Data Protection Officer (DPO)] and they will get back to you as soon as possible.
===Contact us:===
If you would like to discuss GDPR, data protection, or how we process data, please email our [mailto:dpo@reportcomplete.com?subject=GDPR Data Protection Officer] and we will get back to you as soon as possible.

Revision as of 11:09, 8 August 2026

Personal data in the United Kingdom is governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Schools in the EU/EEA are covered by the EU GDPR. These impose strict controls on how organisations collect and process personal data.

Under this legislation your school is the data controller and we are a data processor acting on your documented instructions. We are committed to meeting our obligations in that role, and we keep our technical and organisational security measures under continual review.

It is our policy to keep data private, secure and safe. We do this in several ways, including:

  • Data is collected only for specific, explicit and legitimate purposes.
  • Sensitive data is encoded whilst on, and before it leaves, your computer.
  • Data is further encrypted with AES-256 encryption locally and/or with us (optionally turned off — see below).
  • Passwords are stored with us as one-way salted hashes.
  • TLS is used to ensure data is private during communication.
  • Data is retained only for as long as necessary, and to a published schedule.
  • Regular backups are made in case we ever need to recover data.
  • Personal data can be exported in a machine-readable format at any time.

Why encryption is optional for some customers:

A small number of our customers are outside the UK and EU. In those cases we necessarily send data to those countries so that the school can edit its own reports. Some of those countries do not permit the use of encryption, and for that reason we provide the option to turn off local and/or server-side encryption. The default is local off, server on. In any event, data is encoded and is never stored in plain text.

The settings are found in Admin > School Details. We recommend leaving local encryption off so that, in the event of a local hard drive fault, recovery software has a better chance of working.

Where is data stored?

Our servers and data storage are provided by DreamHost (DreamHost, LLC, Brea, California, USA). Backups are held on a secure server managed by Deluxe Pixel Limited in Preston, United Kingdom.

Because DreamHost processes data in the United States, this involves a restricted transfer under UK GDPR. That transfer is covered by appropriate safeguards under Article 46:

  • DreamHost's Customer Data Processing Addendum incorporates the Standard Contractual Clauses approved by the European Commission in 2021 (Schedule D, Module Two — controller to processor).
  • These are supplemented by the International Data Transfer Addendum issued by the UK Information Commissioner's Office (Annex III; ICO template B.1.0, laid before Parliament on 2 February 2022).

We have carried out a Transfer Risk Assessment in line with ICO guidance, and review it periodically. A copy is available to schools on request.

Note: the EU–US Privacy Shield framework, referred to in earlier versions of this page, was invalidated by the Court of Justice of the European Union in July 2020. We do not rely on it, nor on its successor the UK Extension to the EU–US Data Privacy Framework. Our transfers rest on the contractual safeguards described above, which are not affected by changes to those adequacy arrangements.

Our sub-processors:

We use the following sub-processors in providing the service:

Sub-processor Purpose Location
DreamHost, LLC Hosting, data storage and backup USA
Deluxe Pixel Limited Off-site backup United Kingdom
(add any e-mail, payment or AI providers here)

We will give schools notice before adding or replacing a sub-processor.

How long we keep data:

Data Retention
Reports and report data Retained while the licence is active, and for [period] after it ends unless the school asks in writing for earlier deletion
Pupil photographs and artwork Deleted at the end of the academic year in which they were uploaded
Backups Overwritten on a rolling [period] cycle
Website logs Encrypted and deleted after 72 hours

Schools may request deletion of their data at any time by writing to us. Administrators can also export all school data to a machine-readable file at any point — see GDPR backups.

Why we would sometimes provide third parties with your information:

Examples of circumstances in which this could arise are if a school asked us to work directly with a third-party support team it uses, or if we were legally compelled to provide information — for example on a valid request from the police or a court, such as for a set of past reports for a particular pupil.

We will not disclose school data to any third party except where legally required, and we will notify the school of any such request unless we are prohibited from doing so.

Who has access to your information:

  • Only a small number of staff have access to school licence credentials. Our admin system checks IP address as well as password and will refuse a login if either is incorrect.
  • All our staff are DBS (Disclosure and Barring Service) checked.
  • All passwords are stored as one-way salted hashes — which is why we cannot recover a teacher's password, only replace it.
  • Direct database access is restricted to specific IP addresses. All other access must go through our web API, which requires a valid username and password.
  • Our web API does not use cookies or sessions, which avoids cookie hijacking and session fixation attacks.
  • Full backups are taken daily between 2am and 3am to a secure machine in a separate location from the main server.

Our registration with the ICO:

Enforcement of the UK GDPR is overseen by the United Kingdom's supervisory authority, the Information Commissioner's Office (ICO). It ensures that organisations follow the rules and that the rights of data subjects — the people whose data is being processed — are properly protected.

We are registered with the Information Commissioner's Office (ID: ZA551060). You can download a copy of our certificate here.

Your data protection contact:

Specify your data protection contact

Under the UK GDPR, organisations processing personal data at large scale, processing certain special categories of data, or which are a public authority or body, may need to designate a Data Protection Officer (DPO) and, where relevant, a UK or EU representative. This is the person we would normally contact about data protection matters.

Administrators will see a screen similar to this one if we do not yet know who to contact at your school.

Within the program, administrators will also find a GDPR option in the Administrator menu showing who you told us about and when.

Administrators can also back up all school data to a machine-readable file.

Rights of individuals:

Because your school is the data controller, requests from parents, pupils or staff to access, correct or delete personal data should be made to the school in the first instance. We will assist you in responding to any such request. If a request is made directly to us, we will pass it to the school rather than responding ourselves.

Contact us:

If you would like to discuss GDPR, data protection, or how we process data, please email our Data Protection Officer and we will get back to you as soon as possible.