Data protection is an important concern for us. The Ron Grimley Undergraduate Centre (RGUC) websites, mobile apps and learning management systems are Dudley Group NHS Foundation Trust (DGNFT) systems, hosted off-site by a third party called RapidSwitch. The information below will inform you about how we process your data. Please read the following data protection information very carefully.
RGUC has a responsibility to ensure that the information/data managed across our sites and services (which includes your personal email data) is processed in accordance with the principles of Data Protection Legislation and, more recently, the General Data Protection Regulations (GDPR). GDPR came into force on 25th May 2018, introducing the biggest change in data protection law for 20 years. The purpose of this Privacy Statement is to:
- Inform you why we collect some personal information
- Inform you how we use your personal information
- How long we store your information
What information does the GDPR apply to?
The GDPR applies to `personal data’, meaning any information relating to an identifiable person who can be directly or indirectly identified. The RGUC collects the following types of personal data:
Personal information including your email address
2. How does the Ron Grimley Undergraduate Centre process your personal information?
GDPR applies to both electronic personal data and to structured manual filing systems containing personal data. It can also include personal data that has been pseudonymised. For example, where identifiers have been hidden and can be accessed via a `key reference’.
DGNFT will process this type of data under the GDPR legal basis Article 6
6(1)(b) – Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract.
- RGUC Learning Management Systems
An email address is required if users wish to be registered on any of the RGUC learning management systems. If the user is manually registered, log in credentials are emailed to the user confirming registration completion. Email addresses are securely stored on the learning management systems and are hosted on the RGUC servers. No other registered members can access email addresses or personal data added by users in the personal profile section on the system.
- RGUC mobile apps
Some of our mobile applications require certain types of personal information to be input by an RGUC administrator into a calendar database for the app features to be of benefit to users. Depending on the type of app, examples of this information could include:
- Student’s name
- Year group
- Firm number
3. How long does RGUC store your personal information?
All RGUC learning management systems retain user registration information for a duration of six years. When six years has elapsed, your user registration will expire and all profile and course information linked to your account will be deleted from the learning management system.
4. Collection and storage of personal data as well as type and purpose of their use
When visiting all websites, mobile apps and learning management systems produced by RGUC, the browser on your device automatically sends information to the server (RapidSwitch) that hosts the service. This information is temporarily stored in a so-called `log file’. The following information is recorded without your intervention and stored until it is automatically deleted:
- IP address of the requesting computer or device
- The date and time of access
- Name and URL of the downloaded file
- Size of the data transferred
- An indication of whether or not the download was successful
- The website from which access is made (referrer URL)
- The browser used and, if applicable, the operating system of your computer as well as the name of your access provider.
- The following individuals will process the data listed above:
RGUC Online Learning Platform – RGUC media team administrators
Medics and Nurses Moodle Platform – Clinical skills administrators (DGNFT)
iClinical Moodle Platform – RGUC media team administrators
RGUC Connect – RGUC administrators and media team
The data will be processed for the following purposes:
- Ensuring a smooth connection
- Evaluation of system security and stability
- Other administrative purposes
Under no circumstances do we or any other persons use the data collected for any other purpose of drawing conclusions about you personally.
Cookies – Use of your information
Sharing of data
- Online Learning Platform (Moodle)
Your personal data will be stored on a third party secure server provided by RapidSwitch. RapidSwitch will not transmit your data to any other third parties.
- RGUC Connect app
Your personal data will be stored on a third party calendar application provided by Google. Google will not transmit your data to any other third parties.
Right to Rectification
If you are aware of information that we hold about you, that you believe to be incorrect or misleading, you have the right to make a request for rectification under Article 16 of the GDPR. In most cases, you may also be able to request that incomplete personal data be completed. Requests can be made verbally or in writing by contacting RGUC. We will respond to all requests for rectification within one month of receipt. Please note that in certain circumstances, we may either extend the response time or refuse a request for rectification based on the complexity of the request.
The right of Restriction of Processing
Under Article 18 of the GDPR, in certain circumstances, you have the right to restrict the processing of personal data we hold about you. This means that you can limit the way that we use your data. This is an alternative to requesting the erasure of your data.
You have the right to request the restriction in the processing of your personal data in the following circumstances:
- You contest the accuracy of your personal data and we are verifying the accuracy of the data;
- The data has been unlawfully processed (ie in breach of the lawfulness requirement of the first principle of the GDPR) and you oppose erasure and request restriction instead;
- We no longer require the personal data but you need us to keep it in order to establish, exercise or defend a legal claim; or
- You have objected to us processing your data under Article 21(1), and we are considering whether our legitimate grounds override those of yours.
Requests to restrict processing of your data can be made verbally or in writing by contacting RGUC. We will respond to all requests within one month of receipt.
The Data Controller responsible for keeping your information confidential is:
Dudley Group NHS Foundation Trust
Russells Hall Hospital
If your require any further information regarding General Data Protection Regulations (GDPR) please click to view the privacy statement on the Dudley Group NHS Foundation Trust website – http://dudleygroup.nhs.uk/about us/patient-privacy-and-accessibility/
RGUC – Ron Grimley Undergraduate Centre – website administrators
DGNFT – Dudley Group NHS Foundation Trust
RapidSwitch the Data Processor (our third party)
Google – hosts the calendar functionality for the RGUC Connect app
Last updated November 2018