What information do we collect from you?
USSU’s Central Services hold and processes personal data concerning:
- Financial records;
- Legal information;
- Code of conduct information;
- Staff information;
- Staff photographs.
How is data is collected:
- Financial records – correspondence including emails and invoices/credit notes/statements/chasers;
- Legal information – correspondence including emails and contracts/agreements;
- Code of conduct information – forms signed by subject;
- Staff information – payroll system -Staff Savvy and Miracle systems;
- Staff photographs -photograph taken.
Why do we collect this information?
USSU collects only the data we need, and we keep the data up to date and only for as long as it is needed.
We collect your personal data in order to:
- Financial records – information necessary for financial processes and liability;
- Legal information -information necessary for legal processes and liability;
- Code of conduct information – information necessary for legal processes and liability;
- Staff information -legitimate interest in reviewing staff progress and for identity processes;
- Staff photographs -identity.
We take our obligations for data handling very seriously and it is therefore important for you to know the lawful basis for us processing your information:
We process data to meet our statutory, legal and contractual requirements; as determined by the relevant records we hold relating to:
- Financial records;
- Legal information;
- Code of conduct information;
- Staff information;
- Staff photographs.
We also process the above stated data in our legitimate interests to facilitate and administer our services to staff, students and our customers/suppliers. These legitimate interests are determined through an assessment made by weighing our requirements against the impact of the processing on you. Our legitimate interests will never override your right to privacy and the freedoms that require the protection of your personal data. If you are interested in learning more about this legitimate interest assessment, please contact dataprotection@surrey.ac.uk.
What do we do with your information?
- Financial records – processing payments and maintaining financial records;
- Legal information – facilitate legal services and provisions;
- Code of conduct information – stored for necessary compliance records;
- Staff information – facilitate employment contract and staff progression including processing of salaries/wages;
- Staff photographs – public display.
USSU processes personal data and special category data in accordance with data protection legislation and its own Data Protection Policy.
How long do we keep your information?
- Financial records – 7 years;
- Legal information – 7 years and/or end of incident/matter;
- Code of conduct information – end of academic year;
- Staff information – end of relationship with staff member;
- Staff photographs – end of relationship with staff member.
Who do we share your information with?
- Financial records – USSU’s appointed external auditors and USSU’s insurers where relevant;
- Legal information – USSU’s appointed external auditors an USSU’s insurers where relevant;
- Code of conduct information – n/a;
- Staff information -n/a;
- Staff photographs – USSU website.