Information Rights Procedure
This procedure sets out how the University processes all personal data regardless of format and location. It covers requests made by prospective, current and former students, staff and job applicants, research participants, and other individuals whose personal data has been processed by the University.
On this page
1. Introduction & Scope
1.1. The UK General Protection Regulation (UK GDPR) and Data Protection Act 2018 provide individuals with several statutory rights in relation to the information the University holds about them. This procedure sets out how the University manages and responds to requests from individuals exercising these rights.
1.2. This procedure is governed by the University’s Data Protection Policy. In the event of a conflict between this procedure and the Data Protection Policy, the Data Protection Policy will take precedence.
1.3. This procedure is supported by the following resources:
-
The University’s Data Protection webpages and relevant internal resources
1.4. The University’s Data Protection Policy provides an explanation of what is meant by “Personal Data” and “Special Category Personal Data” and what “Processing” personal data means.
1.5. This procedure applies to all personal data processed by the University, regardless of format or location. It covers requests made by prospective, current and former students, staff and job applicants, research participants, and other individuals whose personal data has been processed by the University.
2. Responsibilities
2.1. The Director of Governance and University Secretary. The Director of Governance and University Secretary has overall responsibility to ensure that the University meets its legal and regulatory responsibilities under the UK GDPR.
2.2. Data Protection Officer. The University’s Data Protection Officer (DPO) is responsible for oversight and implementation of this procedure and for ensuring compliance with data protection legislation.
2.3. Other members of the University. All members of the University, including staff, students and visitors, must comply with any instructions given by the Data Protection Officer or the Information Compliance Team under this procedure. All staff must recognise and promptly forward any information rights request to the Information Compliance Team at data-protection@bristol.ac.uk. Delays can impact compliance with statutory deadlines.
2.4. Data Processors. All data processors acting on behalf of the University must comply with any instructions given by the University under this procedure. Processors will handle their own requests and other matters where applicable in line with their contract with the university.
3. Data Subject Rights
3.1. Data Subjects have the following rights under data protection legislation:
-
-
The right to be informed
-
The right of access
-
The right to correction
-
The right to erasure
-
The right to restrict processing
-
The right to data portability
-
The right to object
-
Rights in relation to automated decision making and profiling
-
The right to object to direct marketing
-
The right to be notified of a personal data breach
-
The right to complain
-
The right to be informed
3.2. You have the right to be informed about the collection and use of your personal data, including:
-
-
the purpose(s) for which your personal data will be processed;
-
the legal basis for the processing;
-
the retention period(s) for that personal data;
-
details of who the personal data will be shared with; and
-
your rights under the UK GDPR.
-
3.3. As part of our commitment to handling personal data in a fair and transparent way we publish information about how we process personal data in our privacy notices and Information Compliance policies. The Data Protection Officer will work with relevant areas of the University to ensure that privacy notices are regularly reviewed and updated where necessary.
The right of access
3.4. This is commonly known as a Subject Access Request (SAR). This enables you to request a copy of your personal data and to check that it is being lawfully processed. Please see further guidance on this below in section 4.
The right to correction
3.5. This enables you to ask the University to correct any incomplete or inaccurate information we hold about you.
3.6. On receipt of a request, the University will consider whether the data is accurate and will rectify it if necessary. We will also consider whether it is appropriate to inform third parties to whom the data has been disclosed of any rectification. It may be appropriate to restrict processing of personal data while the request is being considered.
The right to erasure
3.7. This enables you to request deletion or removal of your personal data in certain circumstances as follows:
-
-
The University no longer needs your personal data for the reason we originally collected it;
-
You have withdrawn consent to processing and there is no other legal basis for processing that data;
-
Where the processing is undertaken based on the legitimate interests of the Controller (i.e. the University), and you object to the processing and there are no overriding legitimate grounds for the processing;
-
The personal data are processed for direct marketing purposes and you object to that processing;
-
The personal data has been unlawfully processed;
-
The personal data needs to be erased to comply with a legal obligation; and/or
-
The personal data has been collected in relation to the offer of information society services to a child.
-
3.8. The University will also consider whether it is appropriate to inform third parties to whom data has been disclosed of the need to erase the data.
3.9. The right to erasure is not an absolute right and erasure of personal data will not always be required or appropriate.
3.10. The University will not delete your data if any of the following applies:
-
-
Deleting your information would compromise the University's right of freedom of expression;
-
We need to retain the information to comply with the law;
-
Deleting the information would be against the public interest in maintaining public health;
-
Where the University needs to keep records for archiving, research, historical, or statistical purposes, and deleting the data would make that work impossible or seriously difficult;
-
Deleting your information would prevent the University defending legal claims in the future.
-
The right to restrict processing
3.11. This enables you to ask us to suspend the processing of your personal data in the following circumstances:
-
-
You dispute the accuracy of your personal data;
-
The processing is unlawful, but you request that the personal data is restricted, rather than erased;
-
The University no longer needs to retain the personal data, but you request that the University retains it for the establishment, exercise or defence of legal claims; and/or
-
You object to the processing (as described below under the right to object to processing), and the University is considering whether or not there are overriding grounds to continue processing the personal data.
-
The right to data portability
3.12. You have the right to obtain and reuse your personal data for your own purposes. This allows personal data to be moved, copied or transferred easily from one IT environment to another in a commonly used digital format.
The right to object
3.13. You can tell us to stop processing your personal data if we are using it for our public duties or legitimate interests (or the legitimate interests of a third party), and you have a personal reason why you do not want us to use your data in this way.
Rights in relation to automated decision making and profiling
3.14. You have the right not to be subject to a decision based solely on automated processing. This means that you can object to important decisions about you that are made only by automated means. You can ask for a real person to review the decision. Please see the ICO’s webpage for more details.
The right to object to direct marketing
3.15. You can ask us to stop using your personal data for direct marketing at any time. This includes any profiling of data that is related to direct marketing. This is an absolute right, which means that once we receive this request, we must comply. However, we may suppress your details as opposed to deleting them. This means that we will keep just enough information about you to ensure that your preference not to receive direct marketing is respected in future.
The right to be notified of a personal data breach
3.16. You have the right to be informed, without undue delay, when a breach of personal data is likely to result in a high risk to your rights and freedoms. Examples of such high risk include:
-
-
Identity theft or fraud
-
Financial loss
-
Loss of confidentiality (e.g. medical, criminal, or sensitive data leaked)
-
Risk to reputation or safety
-
3.17. If we contact you to advise you of a personal data breach, we will include the following detail:
-
-
What happened (nature of the breach)
-
What type of data was affected
-
The likely consequences for you
-
What we are doing to fix it
-
What you can do to protect yourself
-
How to contact us for further help or information
-
3.18. If the risk is low, we may not have to notify you, but we will record the breach.
The right to complain
3.19. You have the right to make a complaint to the Information Commissioner’s Office (ICO) or another appropriate supervisory authority. We also have an internal complaint procedure which you can use. Further details can be found in the complaints section below.
4. Subject Access Requests (SAR)
4.1. If you want to access your personal data that is held by the University you should complete a Subject Access Request form if possible or provide sufficient information to enable the Information Compliance team to comply with the request.
4.2. When you make a subject access request, you should include the following information to help the University process your request efficiently:
-
-
Full name and contact information of the data subject
-
Date of birth and other identifying information (such as student number)
-
Course (for student or alumni) or department (for current staff or former employees)
-
Details of the personal data requested such as:
-
Students: Student record, student support or disability records.
-
Staff: HR records such as employment file, misconduct reports, occupational health records.
-
-
Location where the information is likely to be held (e.g. relevant departments or faculties).
-
Names of staff members who are likely to hold the information.
-
Proof of identity (see Section 5.2).
-
Evidence of consent to act on the data subject’s behalf, where the person submitting a request is not the data subject (see section 6 below).
-
Preferred method of response (e.g. secure email, postal delivery)
-
5. How to make an information rights request
5.1. Your request should state clearly which right(s) you wish to exercise and include sufficient detail to enable us to process your request. You may submit your request via the following channels:
-
-
-
Email to data-protection@bristol.ac.uk
-
Postal correspondence
-
Verbally to a member of staff (written confirmation may be requested to ensure accuracy)
-
Social media via direct message or in a public post addressed to the University.
-
-
5.2. The University may need to request additional information from you to confirm your identity or to clarify the scope of your request.
5.3. An official form of ID should be included with the request for the University to verify your identity. The following forms of identification are acceptable:
-
-
Driving Licence (photocopy acceptable)
-
Passport (photocopy acceptable)
-
Student card (if current student)
-
Staff Ucard (if current staff member)
-
Alternatively, if you are a student or member of staff we may accept an email from your University (@bristol.ac.uk) email address as evidence of your identity.
5.4. Where an original document is provided, the University will return this via standard postage.
5.5. If we cannot verify your identity, we may need to request additional proof before processing begins. The one-month statutory response period begins once a valid request and verification are received (see section 7 below).
6. Third Party Representatives
6.1. Where you have appointed someone to act on your behalf (e.g. a solicitor), we will need the following additional information to help us ensure the request is legitimate:
-
-
Signed consent or an explicit authorisation from you confirming that the requester is acting on your behalf.
-
Verification of your identity as the data subject
-
The scope of the request
-
7. Timescales
7.1. The Information Compliance team will aim to acknowledge receipt of a request within five working days (excluding University closure days) and will respond to requests within one calendar month (provided sufficient information has been given to the University to enable the University to process the request).
7.2. If, however, the request is complex, or if there are multiple requests, an extension by up to a further two months could be made. Where this is necessary, this will be communicated to you or your representative within one month of receipt of the request.
7.3. Where you make a request for exam marks before the results are announced, the University will provide a response within five months from the date the request was received.
8. Exemptions and Refusals
8.1. In some limited circumstances, the University can restrict your information rights by using exemptions. We only use an exemption where it is lawful and necessary to do so.
8.2. We may use an exemption where giving you the information would:
-
-
Interfere with the prevention or investigation of crime, or the prosecution of offenders.
-
Prejudice a regulatory or disciplinary investigation.
-
Harm national security or public safety.
-
Prejudice ongoing negotiations with you.
-
Reveal information covered by legal professional privilege (for example, confidential legal advice).
-
Unfairly disclose the personal data of another person.
-
Breach a duty of confidentiality owed to someone else.
-
Prejudice the proper conduct of examinations or assessments before results are announced.
-
Seriously impair research, statistical or archiving work carried out in the public interest.
-
8.3. If we apply an exemption, we will:
-
-
Only limit your rights as much as is necessary.
-
Give you as much information as we lawfully can.
-
Explain why we cannot fully comply with your request, unless the law prevents us from doing so.
-
8.4. Further information on exemptions can be found on the ICO website.
8.5. In addition, if you make a request to exercise a data subject right under this procedure that we consider to be “manifestly unfounded or excessive”, which may be because it is part of a string of repetitive requests, the University may take one of the following actions:
-
-
Refuse to comply with the request
-
Charge a reasonable fee to comply with the request, which will normally consider the administrative costs of doing so.
-
8.6. Where a request is refused in this way, you will be given written reasons for the decision and informed of your right to complain.
9. Other Requests
9.1. Requests for academic transcripts or evidence of student status should be made directly to the Student Support Team.
10. Retention
10.1 Records relating to information rights requests shall be retained in accordance with the University’s Records Retention Schedule. Records will be kept securely and accessed only by authorised personnel.
11. Complaints
11.1. If you are not happy about how the University has responded to your information rights request, you can make a complaint under the Data Protection Complaints Procedure. These requests must be sent to us within 12 months following our response to you, or 12 months from your last meaningful contact with the University. Complaints submitted beyond this time limit will be considered at the discretion of the Data Protection Officer. Please refer to the Data Protection Complaint Procedure for further details.
11.2. If you remain dissatisfied following the outcome of your complaint, you have the right under data protection legislation to escalate your concerns directly to the Information Commissioner. The University may need to share information relating to you and your complaint with the Information Commissioner to assist their review.
11.3. The Information Commissioner can be contacted at the following address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
11.4. Further information is available on their website: Make a complaint | ICO