top of page
GDPR and Data Protection Policy

Last Updated: 1st May 2026

1. Policy Statement

 

Creative Media Skills Institute (CMSI) is committed to protecting the privacy and personal data of students, learners, staff, tutors, contractors, suppliers, partners, visitors, and other individuals whose personal information it processes.

 

CMSI recognises that the lawful, fair, transparent, and secure handling of personal data is an important responsibility and is committed to complying with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as applicable.

 

CMSI will ensure that personal data is:

 

·Processed lawfully, fairly, and transparently

·Collected for specified and legitimate purposes

·Adequate, relevant, and limited to what is necessary

·Accurate and kept up to date where necessary

·Retained only for as long as necessary

·Processed securely and protected against unauthorised access, loss, or misuse

 

CMSI recognises the importance of protecting personal data relating to students and learners and will take appropriate measures to ensure that student information is handled responsibly.

 

As an organisation working in academic partnership with Capital City College, CMSI recognises that personal data may need to be shared with Capital City College and other relevant organisations for legitimate academic, administrative, quality assurance, regulatory, funding, safeguarding, and legal purposes.

 

CMSI will ensure that such information sharing is carried out lawfully, securely, and transparently and in accordance with the requirements of the academic partnership.

 

 

2. Purpose of the Policy

 

The purpose of this policy is to:

 

·Establish CMSI's commitment to data protection and privacy

·Ensure compliance with applicable UK data protection legislation

·Explain how CMSI collects, uses, stores, and protects personal data

·Define the responsibilities of CMSI and individuals who process personal data

·Protect the rights and freedoms of individuals

·Ensure personal data is processed only for legitimate purposes

·Ensure appropriate safeguards are applied when sharing personal data

·Provide a framework for responding to data breaches

·Explain individuals' rights in relation to their personal data

·Support compliance with academic partnership requirements

·Promote awareness and good data protection practices throughout CMSI

 

3. Scope

 

This policy applies to all personal data processed by CMSI, whether held electronically, digitally, or in physical form. It applies to:

 

·Students and learners

·Applicants and prospective students

·Employees and workers

·Freelance tutors and visiting lecturers

·Contractors and consultants

·Suppliers and service providers

·Partners and third parties

·Visitors

·Directors and management

·Any other individuals whose personal data is processed by CMSI

 

It applies to personal data processed through:

 

·Student and learner records

·Applications and admissions

·Teaching and learning systems

·Assessment and examination records

·Attendance records

·Email and communication systems

·HR and personnel systems

·Payroll and financial systems

·Marketing systems

·CCTV, where applicable

·Websites and online forms

·Cloud-based systems

·Paper records

·Mobile devices and laptops

·Other systems used by CMSI

 

4. CMSI Responsibilities

 

CMSI will:

 

·Process personal data lawfully and fairly

·Maintain appropriate data protection policies and procedures

·Ensure individuals are provided with appropriate privacy information

·Identify appropriate lawful bases for processing personal data

·Maintain appropriate security measures

·Limit access to personal data to authorised individuals

·Ensure personal data is accurate and appropriately maintained

·Retain personal data only for as long as necessary

·Securely delete or dispose of information when it is no longer required

·Respond appropriately to data subject rights requests

·Manage and investigate personal data breaches

·Maintain appropriate records of processing activities where required

·Ensure appropriate arrangements are in place when using third-party data processors

·Provide appropriate data protection training and awareness

·Monitor compliance with this policy

·Cooperate with the Information Commissioner's Office (ICO) where required

·Cooperate with Capital City College where appropriate in relation to shared data protection responsibilities

 

CMSI will seek to ensure that its data protection arrangements are proportionate to the nature, size, and complexity of its activities.

 

5. Individual Responsibilities

 

All individuals who process personal data on behalf of CMSI must:

 

·Handle personal data responsibly

·Follow CMSI's data protection and information security procedures

·Only access personal data required for their role

·Keep personal data secure

·Not share personal data without appropriate authorisation

·Avoid discussing confidential information in inappropriate public settings

·Use approved CMSI systems wherever practicable

·Take care when sending emails containing personal data

·Check recipients before sending sensitive or confidential information

·Use secure passwords and authentication methods

·Report suspected data breaches promptly

·Ensure personal data is not retained unnecessarily

·Complete required data protection training

 

Individuals must not:

 

·Access personal data without a legitimate reason

·Use personal data for unauthorised purposes

·Share personal data with unauthorised individuals

·Copy or remove personal data without appropriate authority

·Store CMSI personal data on personal devices or accounts unless authorised

·Deliberately alter or destroy personal data without authorization

 

6. Data Protection Principles

 

CMSI will comply with the key data protection principles established by UK data protection law.

 

Lawfulness, Fairness and Transparency

 

·Personal data will be processed lawfully, fairly, and transparently.

·Individuals will be informed about how their personal data is used through appropriate privacy notices and communications.

 

Purpose Limitation

 

·Personal data will be collected for specified, explicit, and legitimate purposes and will not be used in ways that are incompatible with those purposes.

 

Data Minimisation

 

·CMSI will collect and process only personal data that is adequate, relevant, and necessary for the purpose.

 

Accuracy

 

·CMSI will take reasonable steps to ensure personal data is accurate and kept up to date where necessary.

 

Storage Limitation

 

·Personal data will not be retained for longer than necessary.

·CMSI's Data Retention Policy provides further information about retention periods and secure disposal.

 

Integrity and Confidentiality

 

·Personal data will be protected using appropriate technical and organisational measures.

 

Accountability

 

·CMSI will take reasonable steps to demonstrate compliance with applicable data protection requirements.

 

7. Lawful Basis for Processing

 

CMSI will identify and document an appropriate lawful basis for processing personal data. Depending on the circumstances, lawful bases may include:

 

·Consent

·Performance of a contract

·Compliance with a legal obligation

·Protection of vital interests

·Performance of a task carried out in the public interest or in the exercise of official authority, where applicable

·Legitimate interests

 

CMSI will ensure that the chosen lawful basis is appropriate for the specific processing activity. Where consent is relied upon, consent must be:

 

·Freely given

·Specific

·Informed

·Unambiguous

·Capable of being withdrawn

 

CMSI will not assume that consent is required where another lawful basis applies.

 

8. Special Category and Sensitive Personal Data

 

CMSI recognises that certain types of personal data require additional protection.

 

This may include information relating to:

 

·Health

·Disability

·Racial or ethnic origin

·Religious or philosophical beliefs

·Trade union membership

·Sexual orientation

·Genetic or biometric information used for identification

 

CMSI will only process special category data where an appropriate lawful basis and additional condition for processing applies. Access to sensitive information will be restricted to individuals who have a legitimate need to access it.

 

Examples may include information required for:

 

·Reasonable adjustments

·Student support

·Safeguarding

·Health and safety

·Occupational health

·Equality monitoring

·Legal obligations

 

9. Student and Learner Data

 

CMSI recognises the importance of protecting student and learner information.

 

Personal data relating to students may include:

 

·Name and contact details

·Date of birth

·Identification information

·Application information

·Enrolment information

·Attendance records

·Academic progress

·Assessment and examination information

·Achievement and progression

·Support requirements

·Reasonable adjustments

·Equality and diversity information

·Safeguarding information

·Complaints and appeals

·Disciplinary or academic misconduct information

·Funding and eligibility information

 

CMSI will process student information only where there is an appropriate lawful basis and legitimate purpose.

 

Student information will be accessed only by individuals who require it for legitimate academic, administrative, safeguarding, operational, or legal purposes.

 

10. Academic Partnership with Capital City College

 

CMSI recognises that the delivery of academic programmes may require personal data to be shared with Capital City College.

 

Information may be shared where necessary for:

 

·Admissions and enrolment

·Student administration

·Academic records

·Assessment and examination

·Certification and awards

·Quality assurance

·Academic monitoring

·Student support

·Funding and reporting

·Regulatory requirements

·Safeguarding

·Complaints and appeals

·Academic misconduct or disciplinary matters

 

CMSI will ensure that personal data shared with Capital City College is:

 

·Shared only where there is a lawful basis

·Relevant and proportionate

·Accurate where reasonably practicable

·Transmitted securely

·Accessible only to authorised individuals

·Handled in accordance with applicable data protection requirements

 

Where appropriate, CMSI will cooperate with Capital City College in responding to data subject rights requests, data breaches, complaints, and other data protection matters involving shared personal data. Where the academic partnership arrangements define specific responsibilities for data protection, CMSI will follow those arrangements.

 

11. Privacy Notices

 

CMSI will provide appropriate privacy information to individuals explaining:

 

·What personal data is collected

·Why it is collected

·How it is used

·The lawful basis for processing

·Who it may be shared with

·How long it will be retained

·Individuals' rights

·How to contact CMSI about data protection matters

·How to raise concerns with the Information Commissioner's Office

 

CMSI may provide privacy information through:

 

·Privacy notices

·Student handbooks

·Application forms

·Staff documentation

·Website information

·Email communications

·Contracts

·Other appropriate communications

 

Privacy information will be reviewed periodically and updated when necessary.

 

12. Data Sharing

 

CMSI may share personal data with third parties where there is a lawful basis and a legitimate purpose.

 

This may include:

 

·Academic partners

·Awarding bodies

·Funding organisations

·Regulators

·Government departments

·Professional advisers

·IT and technology providers

·Payroll providers

·Financial service providers

·Safeguarding partners

·Emergency services

·Law enforcement agencies

·Other service providers

 

CMSI will seek to ensure that information is shared only to the extent necessary. Where CMSI uses a third-party data processor, appropriate contractual arrangements will be maintained where required.

 

13. Data Security

 

CMSI will implement appropriate technical and organisational measures to protect personal data.

 

These may include:

 

·Password protection

·Multi-factor authentication where appropriate

·Access controls

·Secure cloud systems

·Encryption where appropriate

·Antivirus and security software

·Regular software updates

·Secure backups

·Physical security

·Staff training

·Confidentiality requirements

·Secure disposal procedures

 

Access to personal data will be based on role and legitimate business need wherever practicable.

 

14. Email and Electronic Communication

 

Individuals must take care when sending personal data by email or electronic communication.

 

Before sending personal data, individuals should:

 

·Check the recipient carefully

·Confirm that the recipient is authorised to receive the information

·Check attachments before sending

·Use secure methods for sensitive information where appropriate

·Avoid sending unnecessary personal data

 

Where an email is sent to the wrong recipient or personal data is otherwise disclosed incorrectly, the incident must be reported promptly in accordance with CMSI's data breach procedures.

 

15. Personal Devices and Remote Working

 

CMSI recognises that staff and tutors may sometimes work remotely. Where remote working is authorised, individuals must:

 

·Use appropriate security measures

·Keep devices secure

·Use strong passwords

·Avoid leaving devices unattended in public places

·Avoid accessing confidential information on insecure public networks where possible

·Prevent unauthorised individuals from viewing personal data

·Store information using approved CMSI systems

·Report lost or stolen devices promptly

 

CMSI personal data must not be stored on personal devices or personal cloud accounts unless specifically authorised.

 

16. Data Subject Rights

 

CMSI recognises the rights individuals have under UK data protection legislation.

 

Depending on the circumstances, individuals may have the right to:

 

·Be informed about the processing of their personal data

·Request access to their personal data

·Request correction of inaccurate data

·Request erasure of personal data in certain circumstances

·Request restriction of processing

·Object to certain processing activities

·Request data portability in certain circumstances

·Withdraw consent where consent is the lawful basis for processing

·Raise a concern with the Information Commissioner's Office

 

Requests relating to personal data should be directed to CMSI management or the person responsible for data protection matters. CMSI will respond to valid requests within the applicable legal timescales. The rights of individuals are not absolute and may be subject to legal exemptions or other applicable requirements.

 

 

17. Data Breaches

 

A personal data breach may include:

 

·Loss or theft of personal data

·Sending information to the wrong person

·Unauthorised access

·Unauthorised disclosure

·Hacking or cyberattack

·Loss of a laptop or mobile device

·Accidental deletion

·Damage to records

·Misuse of personal data

 

All suspected or actual personal data breaches must be reported to CMSI management immediately.

 

CMSI will:

 

·Assess the nature and scope of the breach

·Take steps to contain and minimise the impact

·Assess risks to affected individuals

·Record the breach appropriately

·Determine whether notification to the ICO is required

·Notify affected individuals where legally required or appropriate

·Notify Capital City College where the breach involves shared partnership data and notification is required

·Take steps to prevent recurrence

 

Where legally required, CMSI will notify the ICO within the applicable statutory timeframe.

 

 

18. Data Protection Impact Assessments

 

CMSI will consider whether a Data Protection Impact Assessment (DPIA) is required before undertaking processing that is likely to result in a high risk to individuals' rights and freedoms.

 

A DPIA may be considered where CMSI proposes to:

 

·Introduce new technology involving personal data

·Process large amounts of sensitive information

·Undertake systematic monitoring

·Introduce significant new data processing activities

·Use innovative technologies that may create increased privacy risks

 

Where appropriate, CMSI will consult relevant stakeholders and implement measures to reduce identified risks.

 

19. Data Retention

 

CMSI will not retain personal data for longer than is necessary for the purpose for which it was collected, unless there is a legitimate reason to retain it for longer.

 

Retention periods will take account of:

 

·Legal requirements

·Academic partnership requirements

·Funding requirements

·Regulatory requirements

·Contractual requirements

·Safeguarding responsibilities

·Legal claims

·Operational requirements

 

CMSI's Data Retention Policy provides further information about retention periods and secure disposal.

 

20. Data Protection by Design and Default

 

CMSI will seek to consider data protection and privacy at the earliest appropriate stage when introducing new systems, processes, or services.

 

Where appropriate, CMSI will consider:

 

·What personal data is necessary

·Whether less data could be collected

·Who needs access

·How information will be secured

·How long it will be retained

·Whether the processing creates risks to individuals

·Whether a DPIA is required

 

CMSI will seek to ensure that privacy is built into processes rather than addressed only after problems arise.

 

21. Monitoring and Compliance

 

CMSI will monitor compliance with this policy through appropriate measures, which may include:

 

·Reviewing data protection practices

·Monitoring data breaches

·Reviewing access to information

·Reviewing data retention arrangements

·Reviewing third-party data processing arrangements

·Providing training

·Conducting periodic reviews

·Investigating concerns

 

Where weaknesses are identified, CMSI will take proportionate steps to improve data protection arrangements.

 

22. Training and Awareness

 

CMSI will provide appropriate data protection training and awareness to staff, tutors, and other individuals who process personal data as part of their role.

 

Training may cover:

 

·UK GDPR principles

·Data Protection Act 2018

·Personal data

·Special category data

·Lawful bases for processing

·Data security

·Phishing and cyber security

·Email security

·Data breaches

·Data subject rights

·Data retention

·Secure disposal

·Academic partnership data sharing

Relevant staff may be required to complete data protection training during induction and periodically thereafter. CMSI will maintain appropriate records of mandatory training completion.

 

23. Complaints and Concerns

 

Individuals who have concerns about the way CMSI processes their personal data should raise the matter with CMSI management in the first instance. CMSI will investigate concerns appropriately and seek to resolve them wherever possible.

 

Individuals also have the right to raise concerns directly with the Information Commissioner's Office (ICO) where they believe their data protection rights have not been respected. Where a concern relates to data shared with or processed by Capital City College, CMSI will cooperate with Capital City College as appropriate.

 

24. Policy Review

 

This policy will be reviewed:

 

·At least annually

·Following significant changes to data protection legislation

·Following significant changes to CMSI's activities or systems

·Following a significant personal data breach

·Following changes to the academic partnership with Capital City College

·Where regulatory guidance changes

·Where monitoring identifies a need for improvement

 

The policy will be updated where necessary to reflect changes in legislation, regulatory guidance, CMSI's activities, technology, or academic partnership arrangements.

 

 

25. Implementation Decision

 

CMSI confirms that:

 

·Personal data will be processed lawfully, fairly, and transparently

·CMSI will comply with applicable UK GDPR and data protection requirements

·Personal data will only be collected and processed for legitimate purposes

·Personal data will be limited to what is necessary

·Appropriate security measures will be implemented

·Access to personal data will be appropriately controlled

·Personal data will not be retained for longer than necessary

·Individuals will be informed about how their personal data is used

·Data subject rights will be respected

·Suspected data breaches will be reported and managed promptly

·Appropriate arrangements will be maintained for sharing data with Capital City College

·Staff and tutors will receive appropriate data protection training

·CMSI will monitor and review its data protection arrangements

·The policy will be reviewed annually or following significant change

26. Contact

For questions or concerns regarding this policy, please contact:

CMS Institute (Creative Media Skills Group Ltd)
Pinewood Studios, Pinewood Road,
Buckinghamshire, SL0 0NH, United Kingdom
info@creative-media-skills.com
01753 656168

 

© CMS Institute / Creative Media Skills Group Ltd. All rights reserved.

bottom of page