Privacy Notice
PART 1 – GENERIC PRIVACY NOTICE
Durham University has a responsibility under data protection legislation to provide individuals with information about how we process their personal data. We do this in a number of ways, one of which is the publication of privacy notices. Organisations variously call them a privacy statement, a fair processing notice or a privacy policy.
To ensure that we process your personal data fairly and lawfully we are required to inform you:
- Why we collect your data
- How it will be used
- Who it will be shared with
We will also explain what rights you have to control how we use your information and how to inform us about your wishes. Durham University will make the Privacy Notice available via the website and at the point we request personal data.
Our privacy notices comprise two parts – a generic part (ie common to all of our privacy notices) and a part tailored to the specific processing activity being undertaken.
Data Controller
The Data Controller is Durham University. If you would like more information about how the University uses your personal data, please see the University’s Information Governance webpages or contact Information Governance Unit:
Telephone: (0191 33) 46246 or 46103
E-mail: information.governance@durham.ac.uk
Information Governance Unit also coordinate response to individuals asserting their rights under the legislation. Please contact the Unit in the first instance.
Data Protection Officer
The Data Protection Officer is responsible for advising the University on compliance with Data Protection legislation and monitoring its performance against it. If you have any concerns regarding the way in which the University is processing your personal data, please contact the Data Protection Officer:
Jennifer Sewel
University Secretary
Telephone: (0191 33) 46144
E-mail: university.secretary@durham.ac.uk
Your rights in relation to your personal data
Privacy notices and/or consent
You have the right to be provided with information about how and why we process your personal data. Where you have the choice to determine how your personal data will be used, we will ask you for consent. Where you do not have a choice (for example, where we have a legal obligation to process the personal data), we will provide you with a privacy notice. A privacy notice is a verbal or written statement that explains how we use personal data.
Whenever you give your consent for the processing of your personal data, you receive the right to withdraw that consent at any time. Where withdrawal of consent will have an impact on the services we are able to provide, this will be explained to you, so that you can determine whether it is the right decision for you.
Accessing your personal data
You have the right to be told whether we are processing your personal data and, if so, to be given a copy of it. This is known as the right of subject access. You can find out more about this right on the University’s Subject Access Requests webpage.
Right to rectification
If you believe that personal data we hold about you is inaccurate, please contact us and we will investigate. You can also request that we complete any incomplete data.
Once we have determined what we are going to do, we will contact you to let you know.
Right to erasure
You can ask us to erase your personal data in any of the following circumstances:
- We no longer need the personal data for the purpose it was originally collected
- You withdraw your consent and there is no other legal basis for the processing
- You object to the processing and there are no overriding legitimate grounds for the processing
- The personal data have been unlawfully processed
- The personal data have to be erased for compliance with a legal obligation
- The personal data have been collected in relation to the offer of information society services (information society services are online services such as banking or social media sites).
Once we have determined whether we will erase the personal data, we will contact you to let you know.
Right to restriction of processing
You can ask us to restrict the processing of your personal data in the following circumstances:
- You believe that the data is inaccurate and you want us to restrict processing until we determine whether it is indeed inaccurate
- The processing is unlawful and you want us to restrict processing rather than erase it
- We no longer need the data for the purpose we originally collected it but you need it in order to establish, exercise or defend a legal claim and
- You have objected to the processing and you want us to restrict processing until we determine whether our legitimate interests in processing the data override your objection.
Once we have determined how we propose to restrict processing of the data, we will contact you to discuss and, where possible, agree this with you.
Retention
The University keeps personal data for as long as it is needed for the purpose for which it was originally collected. Most of these time periods are set out in the University Records Retention Schedule.
Making a complaint
If you are unsatisfied with the way in which we process your personal data, we ask that you let us know so that we can try and put things right. If we are not able to resolve issues to your satisfaction, you can refer the matter to the Information Commissioner’s Office (ICO). The ICO can be contacted at:
Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: Information Commissioner’s Office
PART 2 – TAILORED PRIVACY NOTICE
This section of the Privacy Notice provides you with the privacy information that you need to know before you provide personal data to the University for the particular purpose(s) stated below.
Project Title: Triple-A Online Training Tool
Type(s) of personal data collected and held by the researcher and method of collection:
Personal information (email; IP addresses), demographic data and answers to the learning questions will be collected through our bespoke website and stored on a database. Email/IP addresses are needed in order for participants to create log-ins for the site, and for server security. Personal information will not be connected to any information data collected as part of the training (i.e. answers to learning questions, feedback), therefore data collected during the training will be anonymous. Towards the end of the training, we will also separately ask people for permission to use their emails to contact them for a follow-up questionnaire in 6-12 months time (opt-in).
Lawful Basis
- Collection of data and use of personal data is carried out under the University’s public task, which includes teaching, learning and research.
- For further information see: https://durham.ac.uk/research.innovation/governance/ethics/governance/dp/legalbasis/
How personal data is stored:
Personal data (emails, IPs) will be collected and stored securely within the website, up to a period of 24 months following the user’s last log-in. After this point they will be automatically deleted.
Anonymous data collected during the training ( i.e. demographic data and answers to learning questions) will be transferred to a database for analysis by the team at the Centre for Neurodiversity and Development. The data will be stored a secure server within Durham University, accessible only to authorized members of the CN&D team and members of the technical team in the Department of Psychology.
Email addresses provided by participants who wish to be contacted for follow-up research (opt-in) will be stored on a password protected database, held on a Durham University secure server.
How personal data is processed:
We will use data collected during the training (answers to learning questions) to analyse how much participants have learned from taking part in the training. We will not link this data in any way to email addresses.
To encourage completion of the training, we will send reminder emails to users after periods of inactivity. For example, a system-generated automatic email will be sent to users if the training has been started but not completed, or there has been no progression within a week. We will send up to 3 reminder emails (with a week between each one). Please email the responsible researchers if you wish us to stop sending reminders.
We will ask permission from participants to follow-up with them in 6-12 months time with an evaluation questionnaire. We will only do this with people who opt-in to be followed up, and email addresses will be stored separately to data collected during the training.
Who the researcher shares personal data with:
The researchers will not share identifiable data outside of Centre team at Durham University (note Curious 12 are part of this team for the period that they are hosting the website). We will use the anonymised data in publications and reports about the impact of the training.
How long personal data is held by the researcher:
Personal data (e.g. email/IP addresses) will be held for two years after completion of the training and the user’s last log-in, after which point they will be automatically deleted. Data collected during the training to assess learning will be anonymised and kept for the standard period of 10 years following publication.
How to object to the processing of your personal data for this project:
If you have any concerns regarding the processing of your personal data, contact Dr Mary Hanley (mary.hanley@durham.ac.uk), or Prof Debbie Riby (deborah.riby@durham.ac.uk ).
Further information:
Mary Hanley (mary.hanley@durham.ac.uk) CN&D Email (neurodev@durham.ac.uk)