Privacy Policy

WHO WE ARE

Jersey College for Girls and Jersey College Preparatory School (referred to throughout this policy as ‘the College’), hold information on pupils in order to run the College and in doing so are registered data controllers with the Jersey Officer of Information Controller (Registration Nos 17281- JCG and 17301 – JCP).

For the purposes of this policy, “pupils” refers to any student or child throughout the College.

Both JCG and JCP and must comply with the Data Protection (Jersey) Law 2018 (DPJL 2018). This means that the personal data held on pupils, staff, governors and suppliers must only be used for specific purposes allowed by Law. This statement outlines the types of data held, why that data is held, and to whom it may be passed.

WHAT THIS PRIVACY NOTICE IS FOR

This policy is intended to provide information about how the College will use (or "process") personal data about individuals.

This information is provided because DPJL 2018 gives individuals rights to understand how their data is used. Individuals are all encouraged to read this Privacy Policy and understand the College’s obligations to its entire community.

This Privacy Policy also applies in addition to the College's other relevant terms and conditions and policies, including:

  • any contract between the College and its staff or the parents of pupils/children;

  • the College's policy on taking, storing and using images and audio of children;

  • the College’s facial recognition technology

  • the College’s CCTV

  • the College’s retention of records policy;

  • the College's safeguarding, pastoral, or health and safety policies, including as to how concerns or incidents are recorded; and

  • the College's IT policies, including its Acceptable Use policy, eSafety policy, WiFi policy, Remote Working policy and Bring Your Own Device policy.

(Policies can be viewed on our website)

RESPONSIBILITY FOR DATA PROTECTION 

The College has appointed the Bursar as Privacy and Compliance Officer who will deal with all your requests and enquiries concerning the College’s uses of your personal data (see section on Your Rights below) and endeavour to ensure that all personal data is processed in compliance with this policy and DPJL 2018.

DPJL 2018 requires that the DPO be appointed – this lies with the Bursar.

WHY THE COLLEGE NEEDS TO PROCESS PERSONAL DATA

In order to carry out its public function for pupils, their parents/carers and staff, the College needs to process a wide range of personal data about individuals (including current, past and prospective, pupils, parents or staff) as part of its daily operation.

Some of this activity the College will need to carry out in order to fulfil its statutory obligations – including those under a contract with its staff, or parents of its pupils and third parties.

Other uses of personal data will be made in accordance with the College’s legitimate interests, or the legitimate interests of another, provided that these are not outweighed by the impact on individuals and provided it does not involve special or sensitive types of data.

The College expects that the following uses will fall within that category of its (or its community’s) “legitimate interests”:

  • For the purposes of pupil selection (and to confirm the identity of prospective pupils and their parents);

  • For the purpose of validating parental responsibility (child’s birth certificate and parents’ passport/driving licences including electronic copies);

  • To provide education services, including musical education, physical training, career services, and extra-curricular activities to pupils, and monitoring pupils' progress and educational needs;

  • Maintaining relationships with PTA’s alumni and the College community, including direct marketing or fundraising activity;

  • For the purposes of donor due diligence, and to confirm the identity of prospective donors and their background and relevant interests;

  • For the purposes of management planning and forecasting, research and statistical analysis, including that imposed or provided for by law (such as tax, diversity or gender pay gap analysis);

  • To enable relevant authorities to monitor the College's performance and to intervene or assist with incidents as appropriate;

  • To give and receive information and references about past, current and prospective pupils or employees, including relating to outstanding fees or payment history, to/from any educational institution that the pupil attended or where it is proposed they attend; and to provide references to potential employers of past pupils;

  • To enable pupils to take part in national or other assessments, and to publish the results of public examinations or other achievements of pupils of the College;

  • To safeguard pupils' welfare and provide appropriate pastoral care;

  • To monitor (as appropriate) use of the College's IT and communications systems in accordance with the College's IT: acceptable use policy;

  • To make use of photographic and recorded images of pupils in College publications, on the College website and (where appropriate) on the College's social media channels in accordance with the College's policy on taking, storing and using images of children;

  • For pupils and staff to quickly access their cashless catering account in order to pay for meals, snacks etc. (Explicit consent will be obtained from parents, and for children aged 13 and over, from the pupil.)

  • For security purposes, including CCTV in accordance with the College’s CCTV Policy;

  • To carry out or cooperate with any College or external complaints, disciplinary or investigation process; and

  • Where otherwise reasonably necessary for the College's purposes, including to obtain appropriate professional advice.

In addition, the College will on occasion need to process special category personal data (concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic of biometric data, health data, sex life or sexual orientation and criminal records) in accordance with rights or duties imposed on it by law, including as regards safeguarding and employment, or from time to time by explicit consent where required. These reasons will include:

·       To safeguard pupils' welfare and provide appropriate pastoral (and where necessary, medical) care, and to take appropriate action in the event of an emergency, incident or accident, including by disclosing details of an individual's medical condition or other relevant information where it is in the individual's interests to do so: for example for medical advice, for social protection, safeguarding, and cooperation with police or social services, for insurance purposes or to caterers or organisers of school trips who need to be made aware of dietary or medical needs;

  • To provide educational services in the context of any special educational needs of a pupil;

  • In connection with its staff, e.g. details contained within DBS checks, welfare information, union membership;

  • As part of any College or external complaints, disciplinary or investigation process that involves such data, for example if there are SEN, health or safeguarding elements; or

  • For legal and regulatory purposes (for example child protection, diversity monitoring and health and safety) and to comply with its legal obligations and duties of care.

TYPES OF PERSONAL DATA PROCESSED BY THE COLLEGE

This will include by way of example:  

  • names, addresses, telephone numbers, e-mail addresses and other contact details;

  • car details (about those who use our car parking facilities);

  • bank details and other financial information, e.g., about parents who pay fees to the College;

  • past, present and prospective pupils' academic, disciplinary, admissions and attendance records (including information about any special needs), and examination scripts and marks;

  • where appropriate, information about individuals' health and welfare, and contact details for their next of kin;

  • references given or received by the College about pupils, and relevant information provided by previous educational establishments and/or other professionals or organisations working with pupils;

  • correspondence with and concerning staff, pupils and parents’ past and present; and

  • images of pupils (and occasionally other individuals) engaging in school activities, and recorded during meetings or during online lessons when consent was obtained;

  • and images captured by the College's CCTV system (in accordance with the College's policy);

HOW THE COLLEGE COLLECTS DATA

Generally, the College receives personal data from the individual directly (including, in the case of pupils, from their parents). This may be via a form, (including paper and electronic forms, e.g., via Applica) or simply in the ordinary course of interaction or communication (such as email or written assessments).

However, in some cases personal data will be supplied by third parties (for example another school, or other professionals or authorities working with that individual); or collected from publicly available resources.

USE OF FACIAL RECOGNITION TECHNOLOGY (FRT)

Where explicit consent has been provided, in partnership with CRB Cunninghams, the College uses FRT to improve user experience at the point of sale within our Catering Services.

Why are we using facial recognition?

Facial recognition converts physical characteristics into a unique digital signature that can be used to locate an individual’s cashless catering account quickly and securely. This helps speed up service and eliminates the requirement to carry cash or an alternative method of access, such as a card that can be lost or stolen.

How does it work?

When the individual looks at the camera, the software reads key features (distance between facial features) and compares this against the database of registered users. When it finds a match, it automatically opens their cashless catering account allowing the operator to complete the sale of their school meals.

Can these facials registrations be used by any other agency?

No, the software turns the individual’s physical characteristics into an encrypted (using AES 256) string of characters known as a template. Even if someone were to be able to gain access to the data and break the encryption, this template does not contain enough information to reverse engineer into a usable image.

What legal basis are you relying on for the processing?

Consent.

Parental consent for JCP pupils. At JCG, consent is first sought from parents; if they give consent, consent is then sought from pupils - this is to promote discussion between parent and child on the use of FRT. More information is available on our website: iPayimpact & Fusion | Jersey College for Girls 

What happens when an individual leaves the College?

When individuals leave the College, all data can be deleted very easily.

I don’t wish to give permission for my child to participate with FRT, can my child still purchase school meals?

Yes, an alternative method of authentication will always be available, for example smartcard or use of a QR code – the school Office can advise accordingly.

What if I change my mind?

If you initially opt-in to use, or for your child to use facial recognition but later change your mind, contact the College and we will remove the permission from the system. This will automatically remove any facial data associated with the individual and alternative methods of authentication can be provided.

Where is the facial recognition data stored?

The data is stored securely within the EEA. The Facial Recognition Templates are stored on the CPE-JCG-APP-01 server only, which is physically located in the Government of Jersey Data Centre. The Facial Recognition templates are not able to be converted back to an image or used for other platforms. Only users with access to JCG’s server can access the templates, (JCG IT Team, M&D Cloud and Platforms and Education IT. Remote access may be temporarily given to CRB for troubleshooting purposes, but this is monitored by a member of the JCG IT Team.

Where do I find out more information?

Please click here to view the CRB Cunninghams Privacy Policy.

WHO HAS ACCESS TO PERSONAL DATA AND WHO THE COLLEGE SHARES IT WITH

Occasionally, the College will need to share personal information relating to its community with third parties, such as: 

  • Management Information System, (e.g., SIMS and In Touch – owned by Education Software Solutions) 

  • Assessment and Examination Boards including AQA, OCR, Pearson, CIE, WJEC JCQ for Exam Access Arrangement Applications

  • Century Tech, (this list is subject to change and will be updated annually to reflect any changes) 

  • professional advisers (e.g., lawyers, insurers, advisers and accountants); 

  • Government of Jersey departments (e.g., police, Children’s Social Care); 

  • the Department for Children, Young People, Education and Skills; 

  • external suppliers where Data Sharing agreements and Data Processing Impact Assessments (DPIAs) exist, these include CRB Cunninghams, DBJ Limited who help digitally store all past student and staff records, in accordance with the Government of Jersey’s Retention Policy;  

  • schools and colleges on the Island that provide teaching to our pupils;  

  • JCG Foundation to maintain relationships with alumni and the College community including direct marketing or fundraising activity. 

For the most part, personal data collected by the College will remain within the College and will be processed by appropriate individuals only in accordance with access protocols (i.e., on a ‘need to know’ basis). Particularly strict rules of access apply in the context of special category information, e.g.

  • medical records; and

  • pastoral or safeguarding files.

However, a certain amount of any SEN pupil’s relevant information will need to be shared with staff more widely in the context of providing the necessary care and education that the pupil requires.

Staff, pupils and parents are reminded that the College is under duties imposed by law and statutory guidance to record or report incidents and concerns that arise or are reported to it, in some cases regardless of whether they are proven, if they meet a certain threshold of seriousness in their nature or regularity. This is likely to include file notes on personnel or safeguarding files, and in some cases referrals to relevant authorities. For further information about this, please view the College’s Safeguarding Policy.

In accordance with DPJL 2018, some of the College’s processing activity is carried out on its behalf by third parties, such as IT systems, web developers or cloud storage providers. This is always subject to contractual assurances that personal data will be kept securely and only in accordance with the College’s specific directions.

Finally, staff, pupils and parents should note that data will be taken off site by organisers of school trips or excursions. This is necessary to take appropriate action in the event of an emergency, incident or accident, including by disclosing details of an individual's medical condition or other relevant information where it is in the individual's interests to do so: for example, for medical advice.

HOW LONG WE KEEP PERSONAL DATA

The College will retain personal data securely and only in line with how long it is necessary to keep for under the Public Records (Jersey) Law 2002, as per the CYPES retention schedule for schools, which can be found here.

If you have any specific queries about how our retention policy is applied or wish to exercise any of your rights as a data subject, please contact the Bursar.

YOUR RIGHTS

Individuals have various rights under DPJL 2018 to access and understand personal data. 

Any individual wishing to exercise any of their rights, should put their request in writing to the Bursar. 

DATA ACCURACY AND SECURITY

The College will endeavour to ensure that all personal data held in relation to an individual is as up to date and accurate as possible.  Individuals must please notify the Office of any changes to information, such as contact details, held about them.   

The College will take appropriate technical and organisational steps to ensure the security of personal data about individuals, including policies around use of technology and devices, and access to College systems. All staff and governors will be made aware of this policy and their duties under DPJL 2018 and receive relevant training. 

THIS POLICY 

The College will update this Privacy Notice from time to time. Any substantial changes that affect your rights will be provided to you directly as far as is reasonably practicable.

QUERIES AND COMPLAINTS

Any comments or queries on this policy should be directed to the Bursar.

If an individual believes that the College has not complied with this policy or acted otherwise than in accordance with DPJL 2018, they should notify the Bursar.

The Office of the Bursar, Julie Forsyth, can be contacted in the following ways:

Telephone: +44 (0) 1534 516200

Email: j.forsyth@jcg.sch.je

Jersey College for Girls

Mont Millais

St Saviour

Jersey, JE2 7YB

You can also make a referral to or lodge a complaint with the Jersey Office of the Information Commissioner, although the JOIC recommends that steps are taken to resolve the matter with the College before involving the regulator. 

The Jersey Office of the Information Commissioner (JOIC) can be contacted in the following ways:

Telephone: +44 (0)1534 716530

Email: enquiries@jerseyoic.org

Office of the Information Commissioner

2nd Floor

5 Castle Street

St. Helier, Jersey, JE2 3BT

September 2026

Close

Select Language

Close