Brasenose College Employee / Worker / Contractor / Committee Member Privacy Notice (v1.4)

A summary of what this notice explains

Brasenose College is committed to protecting the privacy and security of personal data.

This notice explains what personal data Brasenose College holds about current staff, office holders and senior members (including Research Fellows) (“you”), how we use it internally, how we share it, how long we keep it and what your legal rights are in relation to it. It also applies to self-employed providers, contractors, workers, and volunteers assisting the College (e.g. fundraising, projects, events).

This notice does not form part of any contract of employment or other contract to provide services.

For the parts of your personal data that you supply to us, this notice explains the basis on which you are required or requested to provide the information. For the parts of your personal data that we generate or receive from others, it explains the source of the data.

There are some instances where we process your personal data on the basis of your consent. This notice sets out those categories and purposes.

Other applicable privacy notices

  1. Current students
  2. Alumni and donors
  3. Archives
  4. Security, maintenance and health and safety (including CCTV)
  5. Website and cookies
  6. IT systems (including internet and email monitoring)

These are available at:
https://www.bnc.ox.ac.uk/privacypolicies

What is your personal data and how does the law regulate our use of it?

“Personal data” means information relating to you as a living, identifiable individual.

  • To process your data lawfully, fairly, and transparently;
  • To collect it for explicit, legitimate purposes;
  • To ensure it is relevant and limited to those purposes;
  • To keep it accurate and up to date;
  • To retain it only as long as necessary; and
  • To protect it with appropriate security measures.

Brasenose College’s Contact Details

The Data Protection Officer
Brasenose College
Radcliffe Square
Oxford OX1 4AJ
data.protection@bnc.ox.ac.uk

What personal data we hold about you and how we use it

  • Contact details (names, addresses, telephone numbers).
  • Position, role, contract terms, grade, salary, benefits and entitlements.
  • Recruitment records: applications, qualifications, references, special arrangements, decisions, and reports.
  • Criminal convictions and DBS check information (for relevant roles).
  • Passports, right-to-work documents, visas and immigration data.
  • Medical issues or disabilities notified to us, including reasonable adjustments.
  • Equality monitoring data and dietary requirements.
  • Financial details: bank account, NI number, tax codes, payslips, and payment details.
  • Pension membership data: identification numbers, contributions, and benefits.
  • Learning and development records (training, accreditations, etc.).
  • Capability, promotion, progression, grievance, disciplinary, and absence records.
  • Photographs, audio and video recordings.
  • Computing and email information: login credentials, IP addresses, and IT access logs.

Full processing details are set out in our ROPA:
https://www.bnc.ox.ac.uk/privacypolicies

The lawful basis on which we process your data

  • To perform a contract we have entered into with you;
  • To comply with a legal obligation;
  • For public-interest tasks;
  • For our legitimate interests (or those of a third party), where your rights do not override them;
  • To protect vital interests in emergencies; and
  • On the basis of consent where applicable.

Special Categories of personal data

These include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, and data concerning sex life or orientation.

We may process such data where:

  • Required by law for employment, social security, or social protection;
  • With your explicit consent;
  • In the substantial public interest (e.g. equal opportunities monitoring);
  • For archiving, research, or statistical purposes under safeguards.

Criminal convictions and allegations of criminal activity

We may process such data on the same bases as above, for example to comply with legal obligations or assess suitability for positions of trust.

Data you provide and consequences of not providing it

Most data is required for contractual or legal reasons, e.g.:

  • Passports, right-to-work and visa information (UK Immigration compliance);
  • Financial and tax data for payroll and payments;
  • Disclosure of conflicts of interest (College governance integrity).

Failure to provide mandatory data may prevent employment or continuation of service. Optional data (e.g. equality or health information) is voluntary but helps us meet obligations under the Equality Act 2010.

Other sources of your data

  • Data we generate about you (applications, payments, accommodation).
  • The University of Oxford (teaching allocations and records).
  • References from previous employers or educational institutions.
  • Information provided by colleagues, family members, or visitors.

How we share your data

We do not sell your data. We share it only where legally required or permitted.

Required by law:

Organisation Why?
Home Office / UK Visas and Immigration To fulfil College obligations as a visa sponsor.
Disclosure and Barring Service (DBS) For roles requiring suitability checks (working with children/vulnerable adults).
HEFCE (Higher Education Funding Council for England) For the Research Excellence Framework (REF) assessment of higher education research.
HM Revenue & Customs (HMRC) To collect tax, NI, and student loan repayments, and report statutory benefits.

Voluntary disclosures:

Organisation Why?
Other Colleges / PPHs within the University of Oxford Where members are jointly employed or providing services across the collegiate University.
Crime prevention or tax authorities For prevention, detection, or investigation of crime, or for public/national interest purposes.
Mortgage lenders and letting agencies To verify employment for mortgages or tenancy agreements (on written request).
USS, OSPS, and NEST Workplace Pensions For the provision of pension benefits.
Higher Education Statistics Agency (HESA) For statistical analysis and government reporting (usually pseudonymised).
Occupational Health providers To enable the provision of health services.
Third-party service providers To facilitate College operations under formal agreement.

Third-party providers must protect your data and process it only under our instructions. More information appears in the Brasenose Data Sharing table:
https://www.bnc.ox.ac.uk/privacypolicies

Sharing your data outside the UK / European Economic Area (EEA)

Data may flow between the UK and EEA under adequacy decisions. Transfers outside these areas will only occur with safeguards or adequacy decisions in place, or where necessary to perform a contract.

Automated decision-making

We do not make decisions about you based solely on automated means. If this changes, you will be notified.

How long we keep your data

We retain your personal information as long as needed for its purpose and legal requirements. Retention details are in our ROPA:
https://www.bnc.ox.ac.uk/privacypolicies

Anonymised statistical data may be kept indefinitely.

Your legal rights over your data

  • Right to access your data and information about its use;
  • Right to correct inaccuracies or complete incomplete data;
  • Right to request erasure in certain circumstances;
  • Right to restrict processing;
  • Right to receive and transfer your data to another controller;
  • Right to object to direct marketing;
  • Right to object to processing based on legitimate interest or public-interest tasks;
  • Right to object to automated decision-making with legal or significant effects;
  • Right to withdraw consent at any time (where applicable).

Contact:

The Data Protection Officer
Brasenose College
Radcliffe Square
Oxford OX1 4AJ
data.protection@bnc.ox.ac.uk

Further guidance: https://ico.org.uk/
Complaints: https://ico.org.uk/concerns/

Future changes to this privacy notice

We may update this notice periodically if laws, technology, or University procedures change. For material changes, at least two months’ notice will be given by email or in writing.

Past versions are available at:
https://www.bnc.ox.ac.uk/privacypolicies

Version control: v1.4 (February 2024)

Last Review Date: February 2024
Next Review Date: February 2025