Glossary of terms
Please find below a glossary of information compliance terms arranged alphabetically.
A
Information that does not relate to an identifiable person, either in isolation of when combined with information from other sources.
Long-term research value for cultural purposes. University records with archival value are those which provide the essential evidence of the University's most significant functions and activities, and also serve legitimate research needs of the University and wider academic and public user community.
University records with archival value collectively show how the University was organised and operated, its effect on the wider community and what it did and why.
Any form of processing (including profiling) that is undertaken by automated means to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning, for example, their suitability for a position or programme applied for, performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
A Business Classification Scheme (BCS) is a conceptual representation of an organisation’s business. It describes an organisation’s business functions and activities, and the relationships between them. The objective is to manage information according to its business context irrespective of where it’s created, used, maintained, and disposed within an organisation.
Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear positive action, signifies agreement to the processing of personal data about them.
Personal data relating to criminal convictions, the commission or alleged commission of an offence, proceedings for the commission or alleged commission of an offence, and sentencing.
An organisation holding personal data who determines the purposes for which, and the manner in which, it is to be processed. In some circumstances it could be a person, and the processing may be carried out jointly or in common with other data controllers. The University is a data controller for the personal data it holds.
An organisation (or in some circumstances it could be a person) who processes personal information on a data controller's behalf. For example, outsourcing the disposal of confidential waste to an external company - that company is a data processor.
UK law that establishes rules for how organizations must handle personal data. The Act gives individuals rights over their personal data and protects them from the erroneous use of their personal data. The Act also imposes responsibilities and requirements on any organisation that handles personal data, obligating them to comply with a number of important principles and legal obligations.
A tool used to identify and reduce the risks of a processing activity, and which must be undertaken in certain circumstances specified in the GDPR.
A person required to be appointed by an organisation in specific circumstances under the GDPR and who must have expert knowledge of data protection law and practice, being the organisation’s main representative on data protection matters.
A living individual who can be identified from personal data.
Disclosing can take the form of paper documents, viewing of a screen, telling someone the content of records, playing audiotapes - anything that passes personal data to another person.
The definition of "environmental information" in the EIRs is very wide, it is any information on the state of the environment. Environmental Information Regulations 2004 are based on a European Union Directive on public access to environmental information. They are based on European legislation and give a statutory right of access to environmental information held by public authorities, which includes the University.
EIR applies to requests for ‘recorded information’ covering information held in digital files, paper documents, videos - essentially, any request that asks for recorded information, or which quotes EIR.
The 28 countries in the European Union and Iceland, Lichtenstein and Norway.
A higher standard of consent that requires a very clear and specific statement rather than an action which is suggestive of consent, and is the requirement when processing special category data on the basis on consent.
A notice setting out information that must be provided to data subjects before collecting personal data from them, including notices aimed at a specific group of individuals or notices that are presented to data subjects (also known as ‘privacy notice’ or ‘data protection notice’).
The Freedom of Information Act (FOIA) was introduced in 2005 to promote transparency in public bodies. It introduces a public "right to know" and is often used by journalists, researchers and campaigning groups.
FOIA applies to requests for ‘recorded information’. This includes requests for information held in digital files, paper documents, videos - essentially, any request that asks for recorded information, or which quotes the FOIA.
Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.
An information asset is valuable information the University holds, which would pose a significant risk if lost. Information assets can come in the form of data (often personal) or documents and can be in digital or physical form.
Responsible for supporting IAOs with operational management of information assets. The Information Asset Owner (IAO) and Information Asset Assistant (IAA) are roles for business departments in public sector organisations, with responsibility for ensuring information assets are maintained and managed appropriately.
Role holders are expected to manage information assets in compliance with statutory obligations such as Freedom of Information Act 2000 and the UK General Data Protection Regulation (UK GDPR). Performing the role effectively brings significant benefits to the University and its compliance with UK GDPR.
Senior staff responsible for managing information assets, risks, and assurance. The Information Asset Owner (IAO) and Information Asset Assistant (IAA) are roles for business departments in public sector organisations, with responsibility for ensuring information assets are maintained and managed appropriately.
Role holders are expected to manage information assets in compliance with statutory obligations such as Freedom of Information Act 2000 and the UK General Data Protection Regulation (UK GDPR). Performing the role effectively brings significant benefits to the University and its compliance with UK GDPR.
The University’s Information Asset Register (IAR) is an inventory of all information assets held by Professional Services divisions, or by academic Schools and Faculties. The IAR helps us ensure that the University complies with the requirements of the UK General Data Protection Regulation (GDPR), and that information is managed consistently across the organisation.
The University’s Information Security Classification Scheme identifies information based on the level of harm that would result if the information were lost, stolen, or accidentally disclosed to others. The Scheme provides examples of the main kinds of information used by the University in each category and gives practical advice on how to store the information, communicate the information and securely destroy the information when no longer needed.
An international data transfer occurs when you send, store, or allow access to personal data outside the UK. Under UK GDPR, this is called a restricted transfer. This applies to when personal data leaves the UK , is sent to a separate organisation outside of the UK or when data remains in the UK but an organisation located outside the UK accesses it.
Restricted transfers require additional safeguards, such as an International Data Transfer Agreement (IDTA).
An International Data Transfer Agreement (IDTA) ensures UK GDPR level protections apply to personal data being transferred to a country which does not meet the has full UK adequacy regulations. A full list of countries which meet the requirements can be found on the Information Commissioner's Office website.
An IDTA places obligations on the receiving organisation to protect data subjects’ rights. Common examples include research activities, commercial arrangements and procurement. A Transfer Risk Assessment (TRA) accompanies the IDTA to assess the level of risk of the transfer.
Applied to records that are due for disposition but need to be retained longer for legal reasons. Legal (disposition) holds can be requested by Information Asset Owners or Information Asset Assistants and must be authorised by the Data Protection Officer or the General Counsel and Director of Legal Services. For example, where records are the subject of an FOI request which is within the review or appeal period, or where records are needed for litigation purposes.
Notification is the process by which a data controller's processing details are added to a the register of data controllers held by the Information Commissioner's Office. Under the Act, every data controller processing personal information needs to notify unless they are exempt. Failure to notify is a criminal offence. Even if a data controller is exempt from notification, they must still comply with the data protection principles.
Any information identifying a data subject or information relating to a data subject that can be identified (directly or indirectly) from that data alone or in combination with other identifiers that are possessed or can be reasonably accessed.
- Personal Data includes criminal convictions and offences data, special categories of Personal Data, and pseudonymised Personal Data, but excludes anonymous data which has had the identity of an individual permanently removed.
- Personal data can be factual (for example, a name, email address, location, or date of birth) or an opinion about that person's actions or behaviour.
A breach of security leading to an accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. It could include an email containing personal data being sent to the wrong recipient, or high level serious systems failures or compromise.
Any activity or set of activities which involves Personal Data, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or making available, alignment or combination, restriction, erasure or destruction.
Replacing information that directly or indirectly identifies an individual with one or more artificial identifiers (for example, a numerical identifier or other code) or pseudonyms so that the data subject cannot be identified without combining the identifier or pseudonym with other information which has been kept separately and securely. Personal data that has been pseudonymised is still treated as personal data (unlike personal data which has been anonymised).
Recorded information or data (in any format) created, received, or maintained by the University (or someone working or acting on its behalf) in the transaction of university business or conduct of university affairs and kept as evidence of those activities for business, regulatory, legal or accountability purposes.
- ‘Business purposes’ are any purposes which support the University’s functions and activities.
- ‘Regulatory purposes’ are any purposes which support or demonstrate the University’s compliance with regulatory requirements.
- ‘Legal purposes’ are any purposes which support or demonstrate the University’s compliance with any legal obligation.
- ‘Accountability purposes’ are any purposes whereby the University needs to answer for its conduct.
A record of all the personal data processing activities carried out by the University.
Records maintained as a unit because they result from the same business process or activity and/or have a particular format. Examples include: committee papers and minutes; student complaint files; information request case files.
The field of management and organisational function responsible for the systematic control of the creation, receipt, maintenance, use, and disposition of records.
A Records Retention Schedule (RRS) is a standard produced by organisations to guide how long information should be kept and when it can be disposed providing legal and business justifications.
The Records Storage & Retrieval Services (RSRS) provides secure off-site storage for physical records. The service is provided under contract by a third-party supplier. Some schools and professional services have an account and at least one ‘authorised user’.
Authorised users are responsible for monitoring the expiry dates of boxes in their account and requesting the timely disposition of boxes by informing Records Management at the point of transfer or if stored boxes have no disposal/review dates.
Assumes executive responsibility for information risk management.
Sensitive data means data containing any of the following information:
- Racial or ethnic origin;
- Political opinions;
- Religious or other similar beliefs;
- Trade Union membership;
- Physical or mental health condition;
- Sexual life or orientation;
- Biometrics (used for ID purposes);
- Genetic data;
- The commission or alleged commission of an offence (and any related legal proceedings).
While financial information is not classified as sensitive data under the Act, it should be afforded a similar level of security given the damage that could be caused to an individual if it were to be accessed without authorisation.
The University’s agents, consultants, contractors, employees, representatives, trustees, and other representatives, including hourly paid staff and students holding a position of employment.
A Subject Access Request (SAR) is a request from an individual to exercise their right to find out what data is being held about them and how it is being used. Individuals may also ask for a copy of the data itself. SARs are the right for any individual to access personal data held about them by the University, and to receive a copy if they wish.
A third party is any person or organisation other than the data subject or data controller. This includes parents, family members, friends and official agencies.
'Transitory Information' is information which has only temporary value. It is produced: In the completion of routine actions (ephemeral records); In the preparation of other records which supersede them (temporary records) and for convenience of reference. Transitory information has no significant informational or evidential value after it has served its primary purpose. It can usually be disposed of within no more than 6 months.
UK law that replaced the EU's GDPR establishing rules for how organisations in the UK must collect, use, and store personal data. It is part of the UK's data protection framework, alongside the Data Protection Act 2018 (DPA 2018). The regulation introduces more stringent requirements for protection and accountability, and gives individuals more control over their personal data.
All organisations, including the University, that handle personal data need to ensure that their systems and processes are compliant with the GDPR.