CINXE.COM
Privacy information | HESA
<!DOCTYPE html> <html class="no-js no-touch" lang="en" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/terms/" xmlns:foaf="http://xmlns.com/foaf/0.1/" xmlns:og="http://ogp.me/ns#" xmlns:rdfs="http://www.w3.org/2000/01/rdf-schema#" xmlns:sioc="http://rdfs.org/sioc/ns#" xmlns:sioct="http://rdfs.org/sioc/types#" xmlns:skos="http://www.w3.org/2004/02/skos/core#" xmlns:xsd="http://www.w3.org/2001/XMLSchema#"> <head><script type="text/javascript" src="/_static/js/bundle-playback.js?v=HxkREWBo" charset="utf-8"></script> <script type="text/javascript" src="/_static/js/wombat.js?v=txqj7nKC" charset="utf-8"></script> <script>window.RufflePlayer=window.RufflePlayer||{};window.RufflePlayer.config={"autoplay":"on","unmuteOverlay":"hidden"};</script> <script type="text/javascript" src="/_static/js/ruffle/ruffle.js"></script> <script type="text/javascript"> __wm.init("http://web.archive.org/web"); __wm.wombat("https://www.hesa.ac.uk/about/website/privacy","20230605103039","http://web.archive.org/","web","/_static/", "1685961039"); </script> <link rel="stylesheet" type="text/css" href="/_static/css/banner-styles.css?v=S1zqJCYt" /> <link rel="stylesheet" type="text/css" href="/_static/css/iconochive.css?v=3PDvdIFv" /> <!-- End Wayback Rewrite JS Include --> <title>Privacy information | HESA</title> <meta name="viewport" content="width=device-width, initial-scale=1"/> <meta http-equiv="cleartype" content="on"/> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"/> <link rel="apple-touch-icon-precomposed" sizes="57x57" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-57x57.png"/> <link rel="apple-touch-icon-precomposed" sizes="114x114" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-114x114.png"/> <link rel="apple-touch-icon-precomposed" sizes="72x72" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-72x72.png"/> <link rel="apple-touch-icon-precomposed" sizes="144x144" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-144x144.png"/> <link rel="apple-touch-icon-precomposed" sizes="60x60" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-60x60.png"/> <link rel="apple-touch-icon-precomposed" sizes="120x120" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-120x120.png"/> <link rel="apple-touch-icon-precomposed" sizes="76x76" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-76x76.png"/> <link rel="apple-touch-icon-precomposed" sizes="152x152" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/apple-touch-icon-152x152.png"/> <link rel="icon" type="image/png" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/favicon-196x196.png" sizes="196x196"/> <link rel="icon" type="image/png" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/favicon-96x96.png" sizes="96x96"/> <link rel="icon" type="image/png" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/favicon-32x32.png" sizes="32x32"/> <link rel="icon" type="image/png" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/favicon-16x16.png" sizes="16x16"/> <link rel="icon" type="image/png" href="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/favicons/favicon-128.png" sizes="128x128"/> <meta name="msapplication-TileColor" content="#FFFFFF"/> <meta name="msapplication-TileImage" content="/sites/all/themes/hesa/favicons/mstile-144x144.png"/> <meta name="msapplication-square70x70logo" content="/sites/all/themes/hesa/favicons/mstile-70x70.png"/> <meta name="msapplication-square150x150logo" content="/sites/all/themes/hesa/favicons/mstile-150x150.png"/> <meta name="msapplication-wide310x150logo" content="/sites/all/themes/hesa/favicons/mstile-310x150.png"/> <meta name="msapplication-square310x310logo" content="/sites/all/themes/hesa/favicons/mstile-310x310.png"/> <script> var GTMID = 'GTM-WM8325T'; (function (w, d, s, l, i) { w[l] = w[l] || []; w[l].push({ 'gtm.start': new Date().getTime(), event: 'gtm.js' }); })(window, document, 'script', 'dataLayer', GTMID); (function (w, d, s, l, i) { var f = d.getElementsByTagName(s)[0], j = d.createElement(s), dl = l != 'dataLayer' ? '&l=' + l : ''; j.async = true; j.src = 'http://web.archive.org/web/20230605103039/https://www.googletagmanager.com/gtm.js?id=' + i + dl; f.parentNode.insertBefore(j, f); })(window, document, 'script', 'dataLayer', GTMID); </script> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link rel="canonical" href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/about/website/privacy"/> <link rel="shortlink" href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/node/411"/> <link type="text/css" rel="stylesheet" href="http://web.archive.org/web/20230605103039cs_/https://www.hesa.ac.uk/files/css/css_fncS-7zbIZ96_cAOhMstFXZ9r7ch0ucyDNZ1bM59C0w.css" media="all"/> <link type="text/css" rel="stylesheet" href="http://web.archive.org/web/20230605103039cs_/https://www.hesa.ac.uk/files/css/css_8Mv8U09WxD3oamjWR5OQxfdZ76AR07ALOYFNEGDTvhk.css" media="all"/> <link type="text/css" rel="stylesheet" href="http://web.archive.org/web/20230605103039cs_/https://www.hesa.ac.uk/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css" media="all"/> <link href="/web/20230605103039cs_/https://www.hesa.ac.uk/sites/all/themes/hesa/styles/basic.css" rel="stylesheet"/> <!--[if gt IE 8]><!--> <link href="/web/20230605103039cs_/https://www.hesa.ac.uk/sites/all/themes/hesa/styles/deluxe.css" rel="stylesheet"/> <!--<![endif]--> <link media="print" href="/web/20230605103039cs_/https://www.hesa.ac.uk/sites/all/themes/hesa/styles/print.css" rel="stylesheet"/> <!--[if lt IE 9]> <script src="http://html5shiv.googlecode.com/svn/trunk/html5.js"></script> <![endif]--> </head> <body class="html not-front not-logged-in no-sidebars page-node page-node- page-node-411 node-type-page"> <!-- Google Tag Manager (noscript) --> <noscript><iframe src="http://web.archive.org/web/20230605103039if_/https://www.googletagmanager.com/ns.html?id=GTM-WM8325T" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript> <!-- End Google Tag Manager (noscript) --> <a href="#main-content" class="element-invisible element-focusable">Skip to main content</a> <header class="header-site"> <div class="wrap"> <div class="inner"> <a class="toggle-nav-site" id="toggle-nav-site" href="#nav-site" aria-controls="nav-site" aria-expanded="false" aria-label="Toggle Main Navigation" role="button"></a> <a class="toggle-search" id="toggle-search" href="#search-block-form" aria-controls="search-block-form" aria-expanded="false" aria-label="Toggle Site Search" role="button"></a> <div class="primary"> <div class="logo"> <a href="/web/20230605103039/https://www.hesa.ac.uk/" title="Home" rel="home"> <img src="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/img/hesa-logo.jpg" alt="Home"/> </a> </div> </div> <div class="secondary"> <div class="region region-search-form"> <div id="block-search-form" class="block block-search"> <div class="content"> <form action="/web/20230605103039/https://www.hesa.ac.uk/about/website/privacy" method="post" id="search-block-form" accept-charset="UTF-8"><div><div class="container-inline"> <h2 class="element-invisible">Search form</h2> <div class="form-item form-type-textfield form-item-search-block-form"> <label class="element-invisible" for="edit-search-block-form--2">Search </label> <input title="Enter the terms you wish to search for." type="text" id="edit-search-block-form--2" name="search_block_form" value="" size="15" maxlength="128" class="form-text"/> </div> <div class="form-actions form-wrapper" id="edit-actions"><input type="submit" id="edit-submit" name="op" value="Search" class="form-submit"/></div><input type="hidden" name="form_id" value="search_block_form"/> </div> </div></form> </div> </div> </div> </div> </div> </div> <nav class="nav-site" id="nav-site" aria-label="Main Navigation"> <div class="wrap"> <div class="region region-main-menu"> <div id="block-system-main-menu" class="block block-system block-menu"> <div class="content"> <ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/data-and-analysis" title="">Open data</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/collection" title="">Data Collection</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/support" title="">Support</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about" title="">About</a></li> </ul> </div> </div> </div> </div> </nav> </header> <main id="main-content"> <div class="wrap" id="top"> <div class="breadcrumbs"><a href="/web/20230605103039/https://www.hesa.ac.uk/about">About us</a> » <a href="/web/20230605103039/https://www.hesa.ac.uk/about/website">Website and accessibility</a> » <a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/privacy" class="active">Privacy</a></div> <h1>Privacy information</h1> <ul class="action-links"></ul> <div class="region region-content"> <div id="block-system-main" class="block block-system"> <div class="content"> <div class="grid grid-spaced"> <div class="content-aside | col-1/3 | col-reverse"> <div class="accordion-item"> <nav class="nav-sub" aria-label="Section sub-navigation"> <a href="#after-nav-sub" class="element-invisible element-focusable">Skip sub-navigation</a> <a class="accordion-toggle | toggle-nav-sub" href="#nav-sub-content" aria-controls="nav-sub-content" aria-expanded="false" role="button">Also in this section</a> <div class="js-accordion-content | nav-sub-content" id="nav-sub-content"> <ul class="menu"><li class="first last expanded active-trail"><a href="/web/20230605103039/https://www.hesa.ac.uk/about" title="" class="active-trail">About us</a><ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/contact">Contact and find us</a></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/engage">Engage with us</a><ul class="menu"><li class="first last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/provider-forum" title="">Provider forum</a></li> </ul></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/what-we-do">Who we are and what we do</a><ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/what-we-do/designated-data-body">Designated Data Body for England</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/what-we-do/statutory-w-s-ni">Wales, Scotland and Northern Ireland</a></li> </ul></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation">Compliance and regulation</a><ul class="menu"><li class="first expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection">Data protection</a><ul class="menu"><li class="first expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices">Collection notices</a><ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices/previous">Collection notices (historical)</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/data-protection/notices/dlhe-c14018">Collection notice (DLHE C14018)</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices/dlhe-c15018">Collection notice (DLHE C15018)</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices/dlhe-c16018">Collection notice (DLHE C16018)</a></li> </ul></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/guidance">Data protection guidance for the HESA records</a><ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/guidance/LDLHE-faqs-graduates" title="">Frequently asked questions for HE leavers 2010/11 survey</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/guidance/LDLHE-faqs-providers" title="">Frequently asked questions for HE providers 2010/11 survey</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/guidance/LDLHE-agreement" title="">Data protection agreement between HESA and IFF Research</a></li> </ul></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/register">Data sharing register</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/rounding-and-suppression-anonymise-statistics">Rounding and suppression</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/ucas-data">HESA's processing of UCAS data</a></li> </ul></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics">Official statistics</a><ul class="menu"><li class="first expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics/pre-release">Pre-release access to official statistics</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics/confidentiality">Statistical confidentiality policy</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics/revisions">Revisions policy</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics/engagement-strategy" title="HESA user engagement strategy for statistics">User engagement strategy</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/official-statistics/quality-report">Student record quality report</a></li> </ul></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/foi">Freedom of information</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/regulation/complaints">Complaints</a></li> </ul></li> <li class="expanded"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/working-here" title="">Working here</a><ul class="menu"><li class="first last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/working-here/vacancies" title="">Current vacancies</a></li> </ul></li> <li class="last expanded active-trail"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website" class="active-trail">Website and accessibility</a><ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/site-map" title="">Site map</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/terms">Terms of use</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/accessibility">Accessibility statement</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/cookies">Cookies</a></li> <li class="leaf active-trail"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/privacy" class="active-trail active">Privacy</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/eduroam">eduroam</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/esignatures">HESA's use of electronic signatures</a></li> </ul></li> </ul></li> </ul> </div> </nav> </div> </div> <div class="content-main | col-2/3" id="after-nav-sub"> <div class="table-responsive"> <table border="1" cellpadding="1" cellspacing="1" style="width:100%;"> <tbody> <tr> <td style="background-color: rgb(223, 227, 235);"> <p><strong>NOTICE – change of controller</strong></p> <p>On 4 October 2022 the Higher Education Statistics Agency (HESA) merged with <a href="http://web.archive.org/web/20230605103039/https://www.jisc.ac.uk/" target="_blank">Jisc</a>. HESA is now part of Jisc.</p> <p>Any personal data processed by HESA as controller has now transferred to Jisc under the purposes set out in this collection notice and Jisc is now the controller of this personal data.</p> <p>Jisc is the controller of the HESA website and of any processing described on HESA’s website, unless otherwise indicated. This means it is Jisc who determines the manner and purpose of processing. Please see the Controllers and contact details section of this notice below for further information about Jisc.</p> <p>Under UK data protection laws, we are required to provide you with certain information about who we are, how we process your personal data and for what purposes and your rights in relation to your personal data. This information is provided in this collection notice. It is important that you read this information.</p> <p>Details of how to exercise your data protection rights can be found in this <a href="#your_rights">collection notice</a>. If you have any queries about how your personal data is processed, please contact <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#791d180d1857090b160d1c1a0d10161739111c0a1857181a570c12"><span class="__cf_email__" data-cfemail="72161306135c02001d061711061b1d1c321a1701135c13115c0719">[email protected]</span></a>.</p> </td> </tr> </tbody> </table> </div> <p class="intro">This page describes how Jisc processes personal data, and how Jisc complies with data protection legislation in connection with the activities of its Data Collection and Statistics Directorate.</p> <p>The job of the Data Collection and Statistics Directorate at Jisc is to collect, process and share data relating to higher education. Some of this data is personal data about students, graduates, and staff of higher education providers. Jisc also processes personal data in the course of its day-to-day business like any other company. If you wish to know more about Jisc’s processing activities relating to its other business functions and services, please see <a href="http://web.archive.org/web/20230605103039/https://www.jisc.ac.uk/website/privacy-notice" target="_blank">Jisc’s general Privacy Notice</a>.</p> <p>The sections below describe the different categories and types of personal data that Jisc processes. These include the purposes and legal basis for each type of processing, any transfers or third party recipients of personal data, and the timescales for storing and processing data. Legal basis information relates to the <a href="http://web.archive.org/web/20230605103039/http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN" target="_blank">General Data Protection Regulation</a> (GDPR) which came into force on 25 May 2018 (and has been retained as part of the UK’s data protection laws following its exit from the EU). More information can be found via our <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection">data protection pages</a>.</p> <p>Some sections link to other pages or documents where more detailed information can be found. The boxes below summarise the key information you need to know. Click on each box for more detail.</p> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#001" name="001">Controllers and contact details<br/> <span style="font-weight:normal">Jisc is the controller for the processing described on this page unless otherwise indicated.</span></a></p> <div class="accordion-content" id="001"> <p>On this page “Jisc” (or "we" or "us") refers to Jisc, a <a href="http://web.archive.org/web/20230605103039/https://www.jisc.ac.uk/about/corporate/company-and-charity-details" target="_blank">not-for-profit company</a> limited by guarantee, registered in England (company number: 05747339; charity number: 1149740).</p> <p>Jisc is the controller for the data processing described on this page. This means it is Jisc who determines the manner and purpose of processing.</p> <p>If you have any questions about Jisc and data protection please contact our Data Protection Officer:</p> <ul class="list-unbulleted"> <li><strong>Email:</strong> <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#ceaaafbaafe0bebca1baabadbaa7a1a08ea6abbdafe0afade0bba5"><span class="__cf_email__" data-cfemail="a9cdc8ddc887d9dbc6ddcccaddc0c6c7e9c1ccdac887c8ca87dcc2">[email protected]</span></a></li> <li><strong>Address:</strong> Jisc, 4 Portwall Lane, Bristol, BS1 6NB</li> </ul> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><p><a id="your_rights" name="your_rights"></a></p> <div class="accordion-item"><a class="accordion-toggle" href="#002" name="002">Your rights<br/> <span style="font-weight:normal">Data protection legislation gives you rights over your personal data. These include rights to know what information is processed about you and how it is processed.</span></a></p> <div class="accordion-content" id="002"> <p>You have the right to be informed about how your personal data is used. This Privacy Information is regularly reviewed to ensure that it accurately describes how personal data is used by Jisc. This information may be updated from time to time, for example when new legislation is enacted, or when new purposes or systems are added.</p> <p>You have the right to request access to your information held by Jisc.</p> <p>You have the right to request rectification of incorrect information.</p> <p>You may have the right to object to some processing. If your concern relates to the Graduate Outcomes survey, please see <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/innovation/outcomes/students">Information for students/graduates</a>.</p> <p>To exercise your data protection rights please contact our Data Protection Officer:</p> <ul class="list-unbulleted"> <li><strong>Email:</strong> <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#b0d4d1c4d19ec0c2dfc4d5d3c4d9dfdef0d8d5c3d19ed1d39ec5db"><span class="__cf_email__" data-cfemail="bcd8ddc8dd92ccced3c8d9dfc8d5d3d2fcd4d9cfdd92dddf92c9d7">[email protected]</span></a></li> <li><strong>Address:</strong> Jisc, 4 Portwall Lane, Bristol, BS1 6NB</li> </ul> <p>You have the right to complain to the Information Commissioner’s Office – please see <a href="http://web.archive.org/web/20230605103039/https://ico.org.uk/concerns/" target="_blank">the ICO website</a>.</p> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#003" name="003">Data transfers to other countries<br/> <span style="font-weight:normal">Some Jisc systems use cloud data storage and your information may be transferred to countries outside the European Union.</span></a></p> <div class="accordion-content" id="003"> <p>Our CRM, payment, and booking systems use cloud data storage. By default, data is stored at data centres located in the UK or the EU. In exceptional circumstances data may be processed at data centres in the USA or elsewhere.</p> <p>Emails to some generic team addresses are processed by <a href="http://web.archive.org/web/20230605103039/https://www.helpscout.com/company/legal/privacy/" target="_blank">Help Scout</a>. These emails may be processed outside the UK and European Economic Area. Team email addresses that use Help Scout include <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#68040109011b070628000d1b0946090b461d03"><span class="__cf_email__" data-cfemail="bdd1d4dcd4ced2d3fdd5d8cedc93dcde93c8d6">[email protected]</span></a>, <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#e38b868a878acd938f9690a38b869082cd8280cd9688"><span class="__cf_email__" data-cfemail="18707d717c713668746d6b58707d6b7936797b366d73">[email protected]</span></a>, <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#442821232528042c2137256a25276a312f"><span class="__cf_email__" data-cfemail="fb979e9c9a97bb939e889ad59a98d58e90">[email protected]</span></a> and <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#72111d1f1f071c1b1113061b1d1c01321a1701135c13115c0719"><span class="__cf_email__" data-cfemail="74171b1919011a1d1715001d1b1a07341c1107155a15175a011f">[email protected]</span></a>.</p> <p>When transferring your personal data outside the UK, appropriate measures are implemented to protect your personal data by:</p> <ul> <li>Ensuring that there is an adequacy decision by the Information Commissioner’s Office in respect of the countries data is transferred to; and/or</li> <li>Ensuring appropriate safeguards, such as the Standard Contractual Clauses are in place and by undertaking adequate risk assessments.</li> </ul> <p>Decisions on the adequacy of the protection of personal data in third countries are granted by the Secretary of State and published on the <a href="http://web.archive.org/web/20230605103039/https://www.gov.uk/government/publications/uk-approach-to-international-data-transfers/international-data-transfers-building-trust-delivering-growth-and-firing-up-innovation#uk-adequacy" target="_blank">UK Government’s website</a>.</p> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#004" name="004">Website privacy policy and cookies<br/> <span style="font-weight:normal">The HESA website uses cookies and logs IP addresses. </span></a></p> <div class="accordion-content" id="004"> <p>HESA is now part of <a href="http://web.archive.org/web/20230605103039/https://www.jisc.ac.uk/" target="_blank">Jisc</a>. Jisc is the controller for the HESA website and for any processing described on HESA’s website unless otherwise indicated.</p> <p>Browsing the HESA website will generate a log of your IP address. The website will also save cookies to your computer. Cookies make the website work properly for users and collect anonymous web metrics - <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/about/website/cookies">find out more about how we use cookies</a>.</p> <p>Our HESA website contains links to other websites. We are not responsible for the privacy practices or content of other sites. We encourage our visitors to be aware when they leave our website and to read the privacy policy of other sites that collect or use personal data.</p> <p>This policy applies only to this website, <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/">https://www.hesa.ac.uk</a>. This policy does not cover any other website operated by Jisc.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in providing a website that functions effectively for all users.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#005" name="005">Students, graduates and staff of higher education providers<br/> <span style="font-weight:normal">Jisc collects data from HE providers. Full information for data subjects is provided in the following Collection Notices.</span></a></p> <div class="accordion-content" id="005"> <p>Detailed information for students and staff can be found in the <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices">Student and Staff Collection Notices</a>.</p> <p>Information about the latest Destinations of Leavers from Higher Education (DLHE) survey can be found in the <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/about/regulation/data-protection/notices/dlhe-c16018">2016/17 DLHE Collection Notice</a>.</p> <p>Information for students about the Graduate Outcomes survey (starting December 2018) can be found here: <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/innovation/outcomes/students">Information for students/graduates</a>.</p> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#006" name="006">HE provider contacts<br/> <span style="font-weight:normal">Jisc holds personal data about staff at HE providers to administer the data collection process, including administering Jisc subscriptions, and to ensure security of its collections and systems. Access to Jisc’s collection systems is administered through the Identity System (IDS).</span></a></p> <div class="accordion-content" id="006"> <p>If you are involved in the submission or review of 'HESA data returns' you will need an account with the <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/support/user-guides/ids-guide">Identity System (IDS)</a>. You will need to provide personal data to create an account and accept an IDS role. Each IDS role has its own specific terms of use which give further information about how Jisc uses this data.</p> <p>The personal data provided to set up the account is used for administration of Jisc’s data collection and sharing process. This may include processing of your data in Jisc data collection systems (e.g. Aardvark, Issue Management System (IMS), the Data Platform, email) and sharing your information with statutory data users if this is necessary for the administration of the data collection process.</p> <p>Jisc may share HE provider contact details with the appropriate primary regulatory/funder for the purpose of administering "HESA subscriptions", including sharing contact information in connection with HE provider debt.</p> <p>If you are the nominated data protection contact for an HE provider, your personal data will be shared with Jisc and stored in Jisc’s CRM for the purpose of contacting relevant HE providers about data protection-related issues.</p> <p>Personal data relating to a User’s interactions with Jisc systems, including the creation of activity logs, is processed for auditing, security, performance monitoring, error reporting and investigation purposes. Jisc may process your personal data to provide you with technical assistance to access Jisc’s systems.</p> <p>It is the responsibility of HE providers to ensure that individuals hold appropriate IDS roles. Information about the IDS roles you have held will be retained for audit purposes.</p> <p>Data held in IDS will also be stored in Jisc’s Customer relationship management (CRM) system – see <a href="#015">CRM section</a> below.</p> <p><strong>Graduate Outcomes case studies</strong></p> <p>If you submit case studies to Jisc for the purpose of promoting the Graduate Outcomes survey your personal data including name, role, business email address will be published on HESA’s website, social media channels, at events or for training. Jisc will process the personal data of individuals contained in any case study materials, such as promotional videos or still images of individuals, under either consent or legitimate interest. Where consent is relied upon to process such personal data, Jisc relies upon a valid consent to have been obtained by the Higher Education Provider from the featured individual(s).</p> <p>HESA is now part of Jisc. Jisc is the controller for the HESA website and for any processing described on HESA’s website unless otherwise indicated.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(a)<br/> The data subject has given consent to the processing of his or her personal data.</p> <p style="font-size:smaller">GDPR Article 6(1)(e)<br/> Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.</p> <p style="font-size:smaller">GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in maintaining security of its collections, information and security monitoring of its collections and systems and performance monitoring and for the purpose of promoting the Graduate Outcomes survey.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#106" name="106">Email lists<br/> <span style="font-weight:normal">If you choose to sign up for emails about 'HESA' services we will send you the messages you’ve chosen until you unsubscribe. If you are an HE provider contact we may send you messages that are necessary to administer the data collection process.</span></a></p> <div class="accordion-content" id="106"> <p>We will hold your information in our <a href="#015">Customer relationship management (CRM)</a> system and send emails to the address you’ve specified. You can unsubscribe from an email list by clicking the ‘unsubscribe’ link at the bottom of an email.</p> <p>Exception: If you hold a relevant <a href="#006">IDS role</a> we may send you our Weekly update email where this contains information necessary for the administration of the data collection process. The ‘unsubscribe’ link will not cancel emails that are necessary for these purposes.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(a)<br/> The data subject has given consent to the processing of his or her personal data for one or more specific purposes.<br/> GDPR Article 6(1)(e)<br/> Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#007" name="007">Jisc statutory customers<br/> <span style="font-weight:normal">Jisc processes personal data about Statutory Customers to facilitate the collection, dissemination and publication of data from higher education providers, collaborative working, and monitoring of Jisc's systems access to Jisc’s collection systems administered through the Identity System (IDS).</span></a></p> <div class="accordion-content" id="007"> <p>If you are involved in the review and delivery of data returns you will need an account with the <a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/support/user-guides/ids-guide">Identity System (IDS)</a>. You will need to provide personal data to create an account and accept an IDS role. Each IDS role has its own specific terms of use which give further information about how Jisc uses this data.</p> <p>The personal data provided to set up the account is used for administration of Jisc’s data collection and sharing process. This may include processing of your data in data collection systems (e.g. Aardvark, Issue Management System (IMS), the Data Platform, email) and sharing your information with other users of these systems (including higher education providers and other Statutory Customers) if this is necessary for the administration of the data collection process.</p> <p>It is the responsibility of your organisation to ensure that individuals hold appropriate IDS roles. Information about the IDS roles you have held will be retained for audit purposes.</p> <p>Data held in IDS will also be stored in Jisc’s Customer relationship management (CRM) system – see <a href="#015">CRM section</a> below.</p> <p>Personal data relating to a User’s interactions with Jisc systems, including the creation of activity logs, is processed for auditing, security, performance monitoring, error reporting and investigation purposes. Jisc may process your personal data to provide you with technical assistance to access Jisc’s systems.</p> <p>We may record meetings via Microsoft Teams which may include the processing of visual and audio webcam footage and opinions expressed about yourself or others. The recordings may be shared:</p> <ul> <li>Within Jisc for the purpose of enabling minute-takers to fulfil their tasks, or to enable meeting participants or non-attendees to access a recording of a meeting.</li> <li>With other stakeholders, including key suppliers and other Statutory Customers, for the purpose of enabling collaboration with Jisc.</li> </ul> <p>The recordings may form part of Jisc’s business records.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis: </strong><br/> GDPR Article 6(1)(e)<br/> Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.</p> <p style="font-size:smaller">GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc's legitimate interests in maintaining information and security monitoring of its collections and systems and performance monitoring.</p> <p style="font-size:smaller">Processing is necessary for the purposes of Jisc's legitimate interests in facilitating collaborative working and maintaining its business records.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#008" name="008">Enquiry forms and emails<br/> <span style="font-weight:normal">If you enquire about Jisc services using a form or email we will process your data in order to deal with your enquiry.</span></a></p> <div class="accordion-content" id="008"> <p>We will hold your information in our <a href="#015">Customer relationship management (CRM)</a> system so that we can respond to your query effectively. If you or your organisation do not enter into a contract with us this information will be retained for 12 months, and then deleted.</p> <p>If you or your organisation go on to enter a contract (e.g. purchase a custom data licence) then we may hold your personal data for longer – see <a href="#009">Custom data and reports</a>.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in responding to enquiries from third parties and recording these responses.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#009" name="009">Custom data and reports<br/> <span style="font-weight:normal">If you buy a custom data licence or a bespoke report we will hold your personal data to administer the licence terms and conditions and carry out compliance assessments.</span></a></p> <div class="accordion-content" id="009"> <p>Custom data extracts and reports are supplied under an Agreement for the Supply of Information Services (<a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/files/New_Sample_Agreement_Supply_Information_Services.pdf">see sample agreement</a>). If you or your organisation enter an agreement with Jisc your data will be processed for the purpose of administering this agreement. Your personal data will also be processed when you interact with our OneTrust information security and data protection compliance assessments associated with the custom data and reports requested.</p> <p>Your personal data will be retained for seven years after the latest licence end date specified in any agreement with you.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis: </strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in maintaining a record of data supplied to third parties.<br/> GDPR Article 6(1)(c)<br/> Processing is necessary for demonstrating accountability with data protection requirements.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#010" name="010">Publications and online purchases<br/> <span style="font-weight:normal">HESA is now part of Jisc. Jisc is the controller of the HESA website and any processing described on HESA’s website, unless otherwise indicated.<br/> If you buy a product directly from the HESA website your personal data is processed for billing purposes. </span></a></p> <div class="accordion-content" id="010"> <p>When you or your organisation buy a publication or other product from the HESA website you will need to provide contact and billing details so that we can complete your order. Invoicing details are retained for accounting purposes.</p> <p>If you wish to pay by credit card payments are processed by <a href="http://web.archive.org/web/20230605103039/https://stripe.com/gb/privacy" target="_blank">Stripe</a>.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#011" name="011">Training<br/> <span style="font-weight:normal">We process data about training attendees and registrants in our event management system so that we can provide and administer the training.</span></a></p> <div class="accordion-content" id="011"> <p>We encourage individuals to only book training events for themselves, but when this is not possible, the attendee whose personal data is being provided to Jisc must be shown this privacy information.</p> <p>We will hold the personal data of attendees and registrants for three years from the date of the last event attended/booked so that we have a record of the training we have supplied.</p> <p>If you tell us about dietary or special requirements (including disabilities) we may use this information to make adjustments for attendees. We will request your explicit consent before processing your personal data relating to health and/or disability.</p> <p>It may also be necessary to share information with third party venue providers so that they have a register of attendees and are able to make any appropriate adjustments for attendees. Where it is necessary for us to share your personal data relating to your dietary or special requirements, we will request your permission before doing so.</p> <p>If you wish to withdraw your consent for the processing of information relating to your health and/or disability, you can do so by accessing your event booking using the email address you used for registration and your password (which you will be asked to create when you first access the booking system). Within the event booking you can change your consent preferences and remove any special category personal data provided.</p> <p>We may contact you to tell you about relevant events in future or to seek your feedback to improve our future training offerings, but you can opt out of receiving this information by emailing <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#0b7f796a626562656c4b636e786a256a68257e60"><span class="__cf_email__" data-cfemail="5f2b2d3e36313631381f373a2c3e713e3c712a34">[email protected]</span></a> or managing your preferences in the footer section of any communication</p> <p>Payments for training and seminars are processed by <a href="http://web.archive.org/web/20230605103039/https://stripe.com/gb/privacy" target="_blank">Stripe</a>. Invoicing details are retained for accounting purposes.</p> <p>For more details see the<a href="http://web.archive.org/web/20230605103039/https://www.hesa.ac.uk/services/training/terms"> training terms and conditions</a>.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in administering and maintaining records of training and seminars.<br/> GDPR Article 9(2)(a)<br/> The data subject has given explicit consent to the processing of personal data relating to health and disability.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#011a" name="011a">E-Learning<br/> <span style="font-weight:normal">If you undertake a HESA e-learning course or online webinar, our training systems will hold your name, email address, course results and a recording of your involvement in the session, where you have been notified. This information is only accessible to Jisc staff and only used to monitor use of the e-learning system or to enable meeting participants (or non-attendees) to access a recording of a meeting.</span></a></p> <div class="accordion-content" id="011a"> <p>We process data about e-learning users and webinar attendees so that we can provide and administer the training.</p> <p>We will hold the names and email addresses of users for 3 years so that we have a record of who has started and completed courses, and to allow users to continue courses that they have started.</p> <p>Some e-learning data protection courses are provided to meet the data protection requirements of Heidi Plus user agreements. We may contact Heidi Plus users with reminders to undertake data protection refresher training based on records maintained in the Easygenerator system.</p> <p>HESA Training webinars are recorded. This is primarily so that, if a delegate experiences technical issues during the webinar and misses content, we can share a recording with them at a later date. All delegates are notified on the event page that the webinar will be recorded and are reminded at the start of the session. Jisc takes steps to minimise the personal data that is collected through the recording of webinars.</p> <p>For more information about e-learning please contact <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#a4d0d6c5cdcacdcac3e4ccc1d7c58ac5c78ad1cf9bd7d1c6cec1c7d099f1cad7d1c6d7c7d6cdc6c1819694c2d6cbc9819694c1c9c5cdc8819694c9c5d6cfc1d0cdcac382c5c9d49fc6cbc0dd99f4c8c1c5d7c1819694d1cad7d1c6d7c7d6cdc6c1819694c9c1819694c2d6cbc9819694d0ccc1819694ece1f7e5819694d0d6c5cdcacdcac3819694c1c9c5cdc8819694c9c5d6cfc1d0cdcac3819694c8cdd7d08a"><span class="__cf_email__" data-cfemail="31454350585f585f5671595442501f50521f445a">[email protected]</span></a>.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in administering and maintaining records of training.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#012" name="012">Heidi Plus<br/> <span style="font-weight:normal">If you use Heidi Plus we will process personal data to administer your user agreement. We also log IP addresses to monitor and measure use of the Heidi Plus service. We will also use your personal data to carry out information security and compliance assessments.</span></a></p> <div class="accordion-content" id="012"> <p>Further details are available in the Heidi Plus privacy policy and user agreements. These can be found in the Heidi Plus Support centre project – workbook 7. Heidi Plus operational documentation. Your personal data will be processed when you interact with our OneTrust information security and data protection compliance assessments associated with your organisation’s Heidi Plus account.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in administering and monitoring use of the Heidi Plus business intelligence service.<br/> GDPR Article 6(1)(c)<br/> Processing is necessary for demonstrating accountability with data protection requirements.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#013" name="013">Suppliers of goods and services<br/> <span style="font-weight:normal">If you supply goods or services to Jisc we may process personal data about you in order to enter into agreements, make orders, pay your invoices, facilitate collaborative working, and monitor use of Jisc's systems.</span></a></p> <div class="accordion-content" id="013"> <p>Details of any personal data processing should be included in any agreement to supply goods and services to Jisc.</p> <p>Personal data relating to a User’s interactions with Jisc systems, including the creation of activity logs, is processed for auditing, security, performance monitoring, error reporting and investigation purposes.</p> <p>We may record meetings via Microsoft Teams which may include the processing of visual and audio webcam footage and opinions expressed about yourself or others. The recordings may be shared:</p> <ul> <li>Within Jisc for the purpose of enabling minute-takers to fulfil their tasks, or to enable meeting participants or non-attendees to access a recording of a meeting.</li> <li>With other stakeholders, including Statutory Customers, for the purpose of enabling collaboration with Jisc.</li> </ul> <p>The recordings may form part of Jisc’s business records.</p> <p>Invoicing and payment details are retained for seven years.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in obtaining goods and services necessary to its business.<br/> Processing is necessary for the purposes of Jisc's legitimate interests in maintaining information and security monitoring of its collections and systems and performance monitoring.<br/> Processing is necessary for the purposes of Jisc's legitimate interests in facilitating collaborative working and maintaining its business records.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#014" name="014">Job applications<br/> <span style="font-weight:normal">Personal data provided through unsuccessful job applications is held for two years and then deleted.</span></a></p> <div class="accordion-content" id="014"> <p>Information provided to HESA prior to it merging with Jisc in support of job applications is processed via People HR for the purpose of selecting suitable candidates for job vacancies. You may have submitted a written assessment, which will be reviewed as part of your application. Your CV and any assessments have been transferred to Jisc, which is now the controller of this data. Your personal information may be shared with Jisc's third party partners who may be involved in the interviewing process.</p> <p>If your application was not successful, your application form, any written assessment, CV, and covering letter will be held for one year from the date at which someone is appointed to the advertised position. Data is held for the purpose of monitoring the level of repeated applications and maintaining a talent pool of candidates who may be interested in other vacancies.</p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(b)<br/> Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.<br/> GDPR Article 6(1)(f)<br/> Processing including sharing with third party partners is necessary for the purposes of Jisc’s legitimate interests in recruiting qualified staff.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#015" name="015">Customer relationship management (CRM) system and marketing information<br/> <span style="font-weight:normal">As HESA is now part of Jisc, if you previously used HESA products or services your personal information has transferred to Jisc and may be held in our CRM system. We will only send you marketing information if you have given your permission, or if you were a customer of HESA or a current customer of Jisc.</span></a></p> <div class="accordion-content" id="015"> <p>The CRM enables us to keep track of our communications with you. We hold records on the CRM for as long as necessary for the reason we collected them – see the sections above for the different reasons we collect data.</p> <p>We like to keep people informed about the products and services that we offer, but we will only use your CRM record to send you marketing information if you are an individual and you consented to this, or to tell you about updates to something you’ve recently bought. If you are a business then Jisc will market to you as it is in our legitimate interests to communicate with customers, stakeholders, and business contacts. Any marketing communication will give you the opportunity to unsubscribe from these messages. </p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis for using CRM:</strong><br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in communicating with customers, stakeholders and business contact necessary to run its business.</p> <p style="font-size:smaller"> <strong>Legal basis for marketing:</strong><br/> If a business customer:<br/> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of Jisc’s legitimate interests in communicating with customers, stakeholders and business contact necessary to run its business.</p> <p style="font-size:smaller">If an individual customer:<br/> GDPR Article 6(1)(a)<br/> The data subject has given consent to the processing of those personal data for one or more specified purposes.</p> </div> </div> </div> <!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><!-------------------------------------------------><div class="accordion-item"><a class="accordion-toggle" href="#016" name="016">Consultations</a></p> <div class="accordion-content" id="016"> <p>Jisc carries out various consultations that include readiness surveys, sector Consultations, Graduate Outcomes brand research, recording reviews relating to proposed changes to collection fields, and training feedback surveys.</p> <p>If you take part in a consultation led by Jisc, Jisc will process your personal information via <a href="http://web.archive.org/web/20230605103039/https://www.delib.net/legal/privacy_notice" target="_blank">Citizen Space</a>.</p> <p>When you submit information to us using this service, it is treated sensitively in accordance with data protection principles. Your personal information will be used for:</p> <ul> <li>The purpose of conducting the surveys</li> <li>Contacting you to engage further with the consultation process or survey</li> </ul> <p>Email addresses are used to send an acknowledgement of response following submission. They may also be used to contact you in the future in relation to the consultation you have responded to.</p> <p>Where permission is given, we publish responses. We include personal data where permission has been given to do so. Email or postal addresses are never published.</p> <p>Your personal data will be held until one year after the closure of the consultation on the Hub. We will retain survey responses but will ensure that name or email address assigned to them will be removed. Please note retention periods may be extended where there is a statutory, regulatory, legal, operational, or security requirement to do so.</p> <p>We may share your survey responses with statutory customers, sector bodies or other organisations involved within the consultation. We will provide additional information on how responses will be used within each consultation. We will not disclose your name or email address to organisations we share responses with.</p> <p>On occasion, personal data may be shared with a third-party consultant, or independent chairperson who has been appointed to support the consultation process.</p> <p>If you share your personal information with us for the purpose of taking part in the Graduate Outcomes brand research, HESA will share your personal information with psLondon, a third party brand research consultancy. The consultancy will contact you directly to undertake brand research and will be joint controllers with Jisc of your personal information. Jisc is the lead controller for responding to rights requests and data protection queries. If you wish to exercise your data subject rights or make a complaint about the way your personal data is processed for the Graduate Outcomes brand research purposes, please contact <a href="/web/20230605103039/https://www.hesa.ac.uk/cdn-cgi/l/email-protection#a6c2c7d2c788d6d4c9d2c3c5d2cfc9c8e6cec3d5c788c7c588d3cd"><span class="__cf_email__" data-cfemail="71151005105f01031e05141205181e1f31191402105f10125f041a">[email protected]</span></a>. </p> <div style="padding: 2%; border: 1px solid black;"> <p style="font-size:smaller"><strong>Legal basis:</strong><br/> GDPR Article 6(1)(e)<br/> Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.</p> <p style="font-size:smaller"> GDPR Article 6(1)(f)<br/> Processing is necessary for the purposes of HESA’s legitimate interests to gain insights and feedback about the services HESA provides.</p> </div> </div> </div> <style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><p></p> <style type="text/css"> </style></p> <style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style><style type="text/css"> </style> </div> <div class="content-aside | col-1/3 | col-reverse"> </div> </div> </div> </div> </div> <div class="cms-controls"> <ul class="action-links"></ul> </div> </div> </main> <footer role="contentinfo" class="footer-site"> <div class="banner"> <div class="wrap"> <div class="grid | grid-spaced | grid-2-cols"> <div> <div class="region region-footer-menu"> <div id="block-menu-menu-footer-menu" class="block block-menu"> <div class="content"> <ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about" title="">About us</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/working-here" title="">Working here and vacancies</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/innovation/data-futures" title="">Data Futures</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/services/heidi-plus" title="">Heidi Plus</a></li> </ul> </div> </div> </div> </div> <div> <div class="region region-social-links-menu"> <div id="block-menu-menu-social-links-menu" class="block block-menu"> <div class="content"> <ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/contact" title="">Contact/find us</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/news" title="">Latest news and blogs</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/support" title="">Support materials</a></li> <li class="last leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/services" title="">Data analytics</a></li> </ul> </div> </div> </div> </div> </div> <div class="grid grid-spaced grid-2-cols"> <div> <div class="footer-meta"> <div class="region region-legal-footer-menu"> <div id="block-menu-menu-legal-footer-menu" class="block block-menu"> <div class="content"> <ul class="menu"><li class="first leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/site-map" title="">Site map</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/terms" title="">Terms of use</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/accessibility" title="">Accessibility</a></li> <li class="leaf"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/cookies" title="">Cookies</a></li> <li class="last leaf active-trail"><a href="/web/20230605103039/https://www.hesa.ac.uk/about/website/privacy" title="" class="active-trail active">Privacy</a></li> </ul> </div> </div> </div> </div> </div> <div> <div class="social"> <h4>Connect With Us:</h4> <a href="http://web.archive.org/web/20230605103039/https://twitter.com/ukhesa" class="follow-twitter"> <img src="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/img/icon-twitter.svg" alt="Twitter"> </a> <a href="http://web.archive.org/web/20230605103039/https://www.linkedin.com/company/higher-education-statistics-agency" class="follow-linkedin"> <img src="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/img/icon-linkedin.svg" alt="LinkedIn"> </a> </div> <figure class="footer-site__logos"> <a href="http://web.archive.org/web/20230605103039/https://www.jisc.ac.uk/"> <img src="/web/20230605103039im_/https://www.hesa.ac.uk/sites/all/themes/hesa/img/logo-jisc.png" alt="Part of Jisc"/> </a> </figure> </div> </div> </div> </div> </footer> <span class="footer-ident"></span> <script data-cfasync="false" src="/web/20230605103039js_/https://www.hesa.ac.uk/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script><script type="text/javascript" src="http://web.archive.org/web/20230605103039js_/https://ajax.googleapis.com/ajax/libs/jquery/1.11.2/jquery.min.js"></script> <script type="text/javascript" src="http://web.archive.org/web/20230605103039js_/https://www.hesa.ac.uk/files/js/js_DRszCILfNteakMtA9IaG5VfXMgclPUg36cL1gyTDqJk.js"></script> <script type="text/javascript" src="http://web.archive.org/web/20230605103039js_/https://www.hesa.ac.uk/files/js/js_llyw5VQhyqjUFjFU3io3JXNCJnPS-gHPikTyooRDQkA.js"></script> <script type="text/javascript" src="http://web.archive.org/web/20230605103039js_/https://www.hesa.ac.uk/files/js/js_kues2zzvQLidKOYpIlUW_RRunHMU5orRYqAyHv4H3zs.js"></script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- window.a2a_config=window.a2a_config||{};window.da2a={done:false,html_done:false,script_ready:false,script_load:function(){var a=document.createElement('script'),s=document.getElementsByTagName('script')[0];a.type='text/javascript';a.async=true;a.src='http://web.archive.org/web/20230605103039/https://static.addtoany.com/menu/page.js';s.parentNode.insertBefore(a,s);da2a.script_load=function(){};},script_onready:function(){da2a.script_ready=true;if(da2a.html_done)da2a.init();},init:function(){for(var i=0,el,target,targets=da2a.targets,length=targets.length;i<length;i++){el=document.getElementById('da2a_'+(i+1));target=targets[i];a2a_config.linkname=target.title;a2a_config.linkurl=target.url;if(el){a2a.init('page',{target:el});el.id='';}da2a.done=true;}da2a.targets=[];}};(function ($){Drupal.behaviors.addToAny = {attach: function (context, settings) {if (context !== document && window.da2a) {if(da2a.script_ready)a2a.init_all('page');da2a.script_load();}}}})(jQuery);a2a_config.callbacks=a2a_config.callbacks||[];a2a_config.callbacks.push({ready:da2a.script_onready});a2a_config.templates=a2a_config.templates||{}; //--><!]]> </script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- jQuery.extend(Drupal.settings, {"basePath":"\/","pathPrefix":"","ajaxPageState":{"theme":"hesa","theme_token":"6jXXWhtEXek3Afc7SEOuBGmXhhkYiJZ6l1oEdQhNRVs","js":{"0":1,"misc\/jquery.js":1,"misc\/jquery.once.js":1,"misc\/drupal.js":1,"misc\/jquery.cookie.js":1,"misc\/jquery.form.js":1,"misc\/ajax.js":1,"sites\/all\/modules\/authcache\/authcache.js":1,"sites\/all\/modules\/contrib\/views\/js\/base.js":1,"misc\/progress.js":1,"sites\/all\/modules\/contrib\/views\/js\/ajax_view.js":1,"sites\/all\/modules\/authcache\/modules\/authcache_p13n\/authcache_p13n.js":1,"sites\/all\/modules\/authcache\/modules\/authcache_ajax\/authcache_ajax.js":1,"sites\/all\/modules\/authcache\/modules\/authcache_menu\/authcache_menu.js":1,"1":1},"css":{"modules\/system\/system.base.css":1,"modules\/system\/system.menus.css":1,"modules\/system\/system.messages.css":1,"modules\/system\/system.theme.css":1,"sites\/all\/modules\/contrib\/date\/date_api\/date.css":1,"sites\/all\/modules\/contrib\/date\/date_popup\/themes\/datepicker.1.7.css":1,"modules\/field\/theme\/field.css":1,"modules\/node\/node.css":1,"modules\/search\/search.css":1,"modules\/user\/user.css":1,"sites\/all\/modules\/contrib\/views\/css\/views.css":1,"sites\/all\/modules\/contrib\/ckeditor\/css\/ckeditor.css":1,"sites\/all\/modules\/contrib\/ctools\/css\/ctools.css":1,"sites\/all\/modules\/contrib\/panels\/css\/panels.css":1,"sites\/all\/themes\/hesa\/ds_layouts\/menu_text_aside\/menu_text_aside.css":1,"sites\/all\/modules\/contrib\/addtoany\/addtoany.css":1,"sites\/all\/themes\/headscape\/css\/messages.css":1,"sites\/all\/themes\/headscape\/css\/menus.css":1,"sites\/all\/themes\/headscape\/css\/content.css":1,"sites\/all\/themes\/headscape\/system.menus.css":1,"sites\/all\/themes\/headscape\/system.base.css":1,"sites\/all\/themes\/headscape\/system.messages.css":1,"sites\/all\/themes\/headscape\/system.theme.css":1,"sites\/all\/themes\/headscape\/contextual.css":1,"sites\/all\/themes\/headscape\/comment.css":1,"sites\/all\/themes\/headscape\/field.css":1,"sites\/all\/themes\/headscape\/node.css":1,"sites\/all\/themes\/headscape\/search.css":1,"sites\/all\/themes\/headscape\/user.css":1,"sites\/all\/themes\/headscape\/ctools.css":1}},"authcache":{"q":"node\/411","cp":{"path":"\/","domain":".hesa.ac.uk","secure":true},"cl":1},"googleCSE":{"cx":"002272841509595808267:pl2berwxm3w","language":"","resultsWidth":600,"domain":"www.google.com"},"views":{"ajax_path":"\/views\/ajax","ajaxViews":{"views_dom_id:authcache-news-block-2":{"view_name":"news","view_display_id":"block_2","view_args":"","view_path":"node\/411","view_base_path":"news","view_dom_id":"authcache-news-block-2","pager_element":0}}},"urlIsAjaxTrusted":{"\/views\/ajax":true,"\/about\/website\/privacy":true},"better_exposed_filters":{"views":{"news":{"displays":{"block_2":{"filters":[]}}}}},"authcacheP13nAjaxFragments":{"views\/news\/block_2":{"\/sites\/all\/modules\/authcache\/modules\/authcache_p13n\/frontcontroller\/authcache.php?a=\u0026r=frag\/views\/news\/block_2\u0026o%5Bq%5D=node\/411":""}}}); //--><!]]> </script> <!-- <script src="https://use.typekit.net/iyl7xmz.js"></script> <script>try{Typekit.load({ async: true });}catch(e){}</script> --> <script src="http://web.archive.org/web/20230605103039js_/https://use.typekit.net/qsa5zsm.js"></script> <script>try{Typekit.load({ async: true });}catch(e){}</script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- da2a.targets=[ {title:"Privacy information",url:"http:\/\/web.archive.org\/web\/20230605103039\/https:\/\/www.hesa.ac.uk\/about\/website\/privacy"}]; da2a.html_done=true;if(da2a.script_ready&&!da2a.done)da2a.init();da2a.script_load(); //--><!]]> </script> <script src="/web/20230605103039js_/https://www.hesa.ac.uk/sites/all/themes/hesa/js/plugins.min.js"></script> <script src="/web/20230605103039js_/https://www.hesa.ac.uk/sites/all/themes/hesa/js/app.min.js"></script> </body> </html> <!-- FILE ARCHIVED ON 10:30:39 Jun 05, 2023 AND RETRIEVED FROM THE INTERNET ARCHIVE ON 16:34:14 Nov 24, 2024. JAVASCRIPT APPENDED BY WAYBACK MACHINE, COPYRIGHT INTERNET ARCHIVE. ALL OTHER CONTENT MAY ALSO BE PROTECTED BY COPYRIGHT (17 U.S.C. SECTION 108(a)(3)). --> <!-- playback timings (ms): captures_list: 0.953 exclusion.robots: 0.053 exclusion.robots.policy: 0.032 esindex: 0.016 cdx.remote: 4.355 LoadShardBlock: 301.536 (3) PetaboxLoader3.resolve: 351.614 (4) PetaboxLoader3.datanode: 134.844 (5) load_resource: 212.119 loaddict: 57.603 -->