KIC DANCE: Confidentiality and Data Protection
The Data Protection Act 1998 (UK)
The European Union General Data Protection Regulation (EU GDPR)
About the Data Protection Act 1998 (UK)
The Data Protection Act 1998 came into force on 1 March 2000 and the full provisions of the Act came into force on 24 October 2001.
About EU GDPR
On May 25, 2018 the European Union (EU) implemented the General Data Protection Regulation (GDPR) (Regulation (UE) 2016/679). This regulation is intended to strengthen and unify data protection for all individuals within the EU and addresses the export of personal data outside the EU.
To comply with the new regulations we, (KIC Dance), must inform you of the personal data we hold, why we hold it, who we share it with and where it is stored.
Your explicit permission is required.
You can opt-in or opt-out via one of our paper or email registration forms.
If you opt-out, regrettably, you may be unable to access some or all Our Services.
Confidentiality and Data Protection Policy
1. Definitions and Interpretation
In this Policy the following terms shall have the following meanings:
“Data” means collectively all information that you submit to KIC Dance. This definition shall, where applicable, incorporate the definitions provided in the Data Protection Act 1998 (UK) and the European Union General Data Protection Regulation (EU GDPR);
“Service/Services” means in-person services provided by KIC Dance, such as dance tuition, classes, examinations, performances; digital services provided via Our Website, such as blog articles, information, communication facilities and email newsletters; and the management of those services.
“User/Visitor/You/Your/Pupil/Student” means any third party that accesses Our Services &/or Our Website and is not employed by or contracted to KIC Dance and acting in the course of their employment;
“Website/Site” means the website www.kicdance.co.uk and any sub-domains of the Site unless expressly excluded by their own terms and conditions; and
“We/Us/Our” means KIC Dance
“Staff” means our employees and specific contractors, such as regular class teachers.
2. Scope of this Policy
This Policy applies only to the actions of KIC Dance and users.
3. Data Collected and Held
KIC Dance is committed to ensuring that the collection and processing of personal data is only undertaken in the legitimate operation of our business. We collect and use the following Data for legitimate purposes only and Data is not disclosed to any third party unlawfully.
We do NOT collect or store financial information such as credit/debit card numbers.
Without limitation, any of the following Data may be collected:
3.1 PERSONAL DATA:
3.1.1 your name and child/ren’s name (if provided by you);
3.1.2 your child/ren’s date of birth &/or age (if provided by you);
3.1.3 contact information such as email addresses, postal addresses and telephone numbers (if provided by you);
3.1.4 demographic information such as profession, preferences and interests (if provided by you);
3.1.5 your messages (if provided by you);
3.1.6 your feedback and reviews (if provided by you);
3.1.7 photos and videos (if permission is given by you);
3.1.8 gender identity
3.1.9 invoice payments;
3.2 Non-personally-identifiable data collected via Our Website:
3.2.1 IP address (automatically collected);
3.2.2 web browser type and version (automatically collected);
3.2.3 operating system (automatically collected);
3.2.4 a list of URLs starting with a referring site, and the site you exit to (automatically collected); and
3.2.5 your activity on our Website (automatically collected);
No personally-identifiable information is used when:
ordering uniform, dancewear, costume and dance shoes;
or when sharing photos on our website or on social media of students under 18.
3.4 In addition to choosing what Data you share, you may choose the WAY in which you share Data with us. Data is collected via:
Paper forms and methods
Digital forms and methods
Secure online forms
4. Our Use of Data – Why We Hold Personal Data
4.1 KIC Dance Data users must comply with the eight Data Protection Principles:
Personal data shall be processed fairly and lawfully.
Personal data shall be held only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or purposes.
Personal data shall be adequate, relevant and not excessive in relation to the purpose for which it is processed.
Personal data shall be accurate and where necessary kept up to date.
Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
Personal data shall be processed in accordance with the rights of data subject under the DPA.
Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of the data.
Personal data shall not be transferred to a country or a territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
4.1.1 Any personal Data you submit will be retained by KIC Dance.
4.1.2 Data provided by Users will NOT be sold to third parties.
4.2 Unless we are obliged or permitted by law to do so, and subject to Clause 5, your personal Data will NOT be disclosed to third parties.
4.3 All personal Data is stored securely in accordance with the principles of the Data Protection Act 1998. For more details on security see Clause 11 below.
4.4 Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Services. Specifically, Data may be used by us for the following reasons:
4.4.1 internal record keeping;
4.4.2 improvement of our products/services;
4.4.3 transmission by email or post of information regarding your use of Our Services;
4.4.4 transmission by email or post of promotional materials that may be of interest to you;
4.4.5 contact for market research purposes which may be done using email, telephone, or post;
4.4.6 illustrate, customise or update Our Services.
4.5 With your permission, photographs and videos of our Students and Service Users are used for illustrative purposes on our website and may be used on our social media channels and marketing materials.
4.5.1 Photographs and videos of Students and Service Users under 18 will NOT have their names or other personally-identifiable data attached;
4.5.2 Photographs and videos of Students and Service Users over 18 MAY have their names attached.
5. Sharing Your Data and Third-Party Services
5.1 KIC Dance may, from time to time, employ the services of other parties for dealing with matters that may include, but are not limited to:
5.1.1 Website use;
5.1.2 search engine facilities;
5.1.3 communications and newsletter transmission;
5.1.4 advertising and marketing;
5.1.5 feedback and reviews;
5.1.6 Service use.
Excluding our secure email service provider (if health/medical data is provided by you via email), the providers of such services do NOT have access to sensitive Data provided by Users of Our services.
Third-party providers MAY have access to some personal Data provided by Users of Our services.
5.2 Third-Party providers for in-person Service use include:
5.2.1 Examination Boards:
5.2.2 College course-related third parties:
5.2.3 Third Party service providers:
Google (email messages; storage of photos, videos, blank forms and marketing files): Policies;
5.3 We may share personal and sensitive Data with KIC Dance employees and teachers, where it is necessary to do so for the safety and wellbeing of our students, staff and other service users.
6.1 Sensitive data such as health, medical (such as allergies) or learning support requirements, if provided by you is only collected via secure methods.
6.1.1 Subject to Clauses 4, 5 and 3.4, students’ personal and sensitive Data are confidential information and will not be shared in full with anyone apart from the Director, the Administrator and the appropriate teachers or. The only exception to this will be if we are required to fulfill our obligations under our relevant Child Protection Policy. If you would like further information regarding our Child Protection Policy please speak to a member of KIC Dance.
6.1.2 Subject to Clauses 4 and 5, some personally-identifiable Data may need to be shared, for example, for the purpose of examinations we must share a student’s name and date of birth for an Identification Number to be issued.
6.1.3 A register is taken at the start of each class and a record is kept of attendance.
6.1.4 Where applicable, student examination certificates are recorded.
6. Where We Store Data
Subject to Clauses 4, 5 and 3.4, personal Data is kept on a database on our office PC; and personal, sensitive and confidential information is kept in a secure cabinet and is not available to anyone other than the Director, the Administrator and appropriate teacher.
7. Controlling Use of Your Data
7.1 Wherever you are required to submit Data, you will be given options to restrict our use of that Data. This may include the following:
7.1.1 use of Data for direct marketing purposes;
7.1.2 sharing Data with third parties; and
7.1.3 taking photographs and video footage (see Clause 4).
8. Your Right to Withhold Information
8.1 You may access certain areas of Our Website and some of Our Services (such as our “Drop In” classes) without providing any Data at all. However, to use all features and functions available on the Website and fully use Our services, you may be required to submit certain Data.
8.3 Your explicit permission is required.
8.3.1 You may “opt-out” of providing certain Data. If you opt-out, regrettably, you may be unable to access some or all of Our Services.
8.4 You may request your Data is rectified, restricted, blocked, erased or destroyed.
8.5 You may notify us of any change in Data permissions, for example, you may request photographs and videos to be removed from this Website by contacting our Website Manager.
9. Your Right to Access Your Own Data
You have the right to ask for a copy of any of your personal Data held by KIC Dance (where such data is held). We will not charge you for this.
10.1 Data security is of great importance to KIC Dance and to protect your Data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure Data collected.
10.2 It is universally accepted that it is impossible to construct “complete internet security”. We have appropriate security measures in place and many of our third-party providers, such as our email service providers, use encryption.
Policy Updated November 2018