Student privacy notice

  • Student Personal Data

    Oxford Brookes University (the University) is the Data Controller of any personal data that you provide or we obtain with regard to your studies. This means that we will make decisions on how your data is used and for what reasons. 

    The purpose of this privacy notice is to:

    • be transparent about the information we collect and store about you and its use 
    • comply with our obligations under UK data protection and privacy law

    The University publishes additional privacy notices applicable to other groups, facilities and activities.  Subject to your circumstances, other notices may also apply to you so please read this privacy notice in conjunction with other applicable privacy notices that may be accessed via the University website.

  • The majority of the personal data we hold about you is directly related to the administration of your studies with the University.  This includes your use of associated services such as IT, libraries and other facilities. 

    The University will also use your personal data for management purposes and working to improve the student experience as well as complying with our legal obligations, for instance the University is required by law to provide limited personal data to external bodies such as Higher Education Statistics Agency (HESA) and the Office for Students (OfS, previously known as the Higher Education Funding Council for England or ‘HEFCE’). 

    The University will need to know if you have a disability, special need or medical condition so that we know if you require additional support or special facilities. We also record information on ethnic origin and other protected characteristics to monitor equal opportunities. 

    Below we provide more detail on the different purposes your personal data is used for and any third parties this data is shared with. 

    UK data protection law requires us to determine a relevant legal basis for each data processing activity we undertake with your personal data, one example of a data processing activity we undertake is the sharing of personal data with statutory bodies such as HESA described above. 

    The lawful grounds that apply to the processing of data undertaken by the University include:

    1. Consent - under certain circumstances, such as participating in third party surveys, we will only process your personal data with your explicit consent. Explicit consent requires you to make a positive, affirmative action and be fully informed as to what you are consenting to. 
    2. Necessary for the provision of a contract - much of the personal information Oxford Brookes processes is necessary to meet its commitments to you, for example processing related to teaching and assessment. 
    3. Necessary to fulfil a legal obligation - we must process your personal data when required to do so under UK law, for instance sharing information with statutory bodies like HESA and OfS or when making reasonable adjustments required by the Equality Act 2010. 
    4. Necessary to protect the vital interest of you or another person - under extreme circumstances we share your personal data with third parties to protect your interests or those of another person, for example providing medical or emergency contact information to emergency services personnel. 
    5. Processing is necessary for the performance of a public task - Oxford Brookes University is a higher education institute that will sometimes process your personal data in the public interest. 
    6. Processing is necessary for fulfilling the legitimate interests of Oxford Brookes University - Oxford Brookes has a right to pursue its own organisational interests and can process your personal data in pursuit of these providing it does not override your fundamental right to privacy. For instance, Oxford Brookes uses Google services for email and productivity applications which means your personal data may be stored on their servers. Oxford Brookes feels that using a third party to provide these services is in our interests but takes appropriate actions to ensure your privacy is respected. 

    In situations where the personal data is defined as sensitive or special category data (for example ethnicity, criminal conviction information and health or medical data) we must select one of the following lawful bases in order to process it: 

    1. Explicit consent (see above). 
    2. Processing is necessary for reasons of substantial public interest - for example the need to ask for criminal conviction data when applying to or studying courses with fitness to practice requirements. 
    3. Processing is necessary to establish a legal claim or administer justice - we may be required to release third parties to authorised agencies. 
    4. For research and statistical purposes - sensitive personal data about you may be used for research purposes without your explicit consent providing sufficient safeguards are in place. 

    In the “How are you using my data and who is it shared with” section below we provide details of the different processing activities undertaken by Oxford Brookes together with their associated lawful bases.

    Most of the personal data we process will have been collected directly from you; either at enrolment or as and when you use University services such as IT, libraries or sports centres.

    We may also receive personal data from third parties such as UCAS, associate colleges or the Student Loans Company. Where we receive such information we always ensure that the party supplying it can lawfully share it with us. 

    If you applied to Oxford Brookes though UCAS we receive the following data from them: 

    • Name 
    • Residency Status 
    • Address
    • Educational Qualifications and Experience
    • Employment History 
    • Fee Payment Details 
    • Contact Details
    • Disability & Special Needs 
    • Unique Learner Reference Number 
    • Care Leaver Status
    • Passport & Visa Details (for non-EU residents) 
    • Parental Data, including Contact Details, Qualifications and Occupational Background
    • Nationality 
    • Personal References

    Most personal data processed by Oxford Brookes is directly related to the administration of your studies, this includes your use of associated services such as IT, libraries and other facilities. Whilst many processing activities are conducted within Oxford Brookes we use a number of third party providers to support our day to day activities, from IT providers to our security contractors. A full list of third parties that we may share your personal data can be found at: Student Privacy Notice - addendum.

    The table below lists the main purposes for which we will process your personal data together with the associated lawful basis for processing.

    Purpose - Teaching and Research Lawful Basis for Processing 
    Recruitment and admission of students  Necessary for the provision of a contract 
    Widening access to University to other students. You may be invited to participate in research to encourage widening participation, or generally. Necessary to fulfil the performance of a  public task
    Provisioning teaching and associated academic services including examinations  Necessary for the provision of a contract 
    Video recording and transmission of lectures  Necessary for the provision of a contract
    Facilitating accreditation with professional & industrial bodies  Necessary for the provision of a contract 
    Managing and administrating students educational contracts  Necessary for the provision of a contract 
    Recording and managing student conduct (including disciplinary procedures, exam or course moderation)  Necessary for the provision of a contract 
    Maintaining student records  Necessary for the provision of a contract 
    Management and administration of student finance (including bursaries and scholarships)  Necessary for the provision of a contract 
    Data sharing with third parties to facilitate the  manufacture of a certificate to evidence the achievement Necessary for the provision of a contract
    Delivering plagiarism checking and academic validation services  Necessary for the provision of a contract 
    Management and administering of Ethics Applications submitted Necessary for the provision of a contract
    Data sharing with third parties necessary for provision of the purposes listed above Processing is necessary for fulfilling the legitimate interest of Oxford Brookes University

     

    Purpose - Other  Lawful Basis for Processing 
    Providing services necessary for the student experience (Including Library, IT and communication services).   Some telephone communications (e.g. exchanges with the IT Service Desk) may be recorded Necessary for the provision of a contract 
    Providing support and maintenance services (including IT, estates and accommodation) Necessary for the provision of a contract

    Providing student support services including: 

    - Disability and learning support services 

    - Careers and employment advice and services 

    - Health and wellbeing services 

    - Brookes Medical centre 

    Necessary for the provision of a contract


    Additional information will be processed with your consent 

    Graduation (including award, classification and images published in the graduation media)  Necessary for the provision of a contract 
    Records of cultural life such as staff or student photos for events and occasions Necessary for the provision of a contract 
    There may be ancillary processing for such as meal bookings, meeting bookings, passports for overseas events and the like  Necessary for the provision of a contract
    Information sharing with host organisations in relation to student work placements (bespoke privacy notices aligned with the respective placement will be put in place prior to the start of work placements) Necessary for the provision of a contract
    Information sharing with home universities (incoming exchange students only)  Necessary for the provision of a contract
    Information sharing with Brookes Union  Processing is necessary for fulfilling the legitimate interest of Oxford Brookes University
    Monitoring equal opportunities  Necessary to fulfil a legal obligation 
    Safeguarding and promoting welfare of students  Necessary for the provision of a contract
    Providing Closed Circuit Television (CCTV footage and Body Worn Video (BWV) footage as required by public authorities    Necessary to fulfil a legal obligation
    Providing Closed Circuit Television (CCTV footage and Body Worn Video (BWV) footage within Oxford Brookes University, as required to address disciplinary and other matters  Necessary for the provision of a contract
    Managing student accommodation  Necessary for the provision of a contract
    Social media interactions including images and media posted on the University website (academic) to acknowledge and celebrate student achievements You consent to providing it to us 
    Management of car parking, CCTV, BWV and security access systems  Processing is necessary for fulfilling the legitimate interest of Oxford Brookes 
    Providing prospective employers with confirmation of qualification and provision of references  Necessary to fulfil a public task
    Your personal information can be be shared with a third party upon your request, for example to fulfill a request for a reference or if you are supported by a Union (or other) representative  You consent to providing it to us 
    Performing research and statistical analysis  Processing is necessary for fulfilling the legitimate interest of Oxford Brookes 
    Performing audits (for regulatory and legal obligations)  Necessary to fulfil a legal obligation
    Providing safety and operational information  Necessary to fulfil a legal obligation
    Promoting our services (e.g. summer schools, student exchanges, or other events happening on and off campus) You consent to providing it to us 
    Providing careers and placement advice and services  Necessary for the provision of a contract 
    Preventing and detecting crime  Necessary to fulfil a legal obligation
    Administration of insurance and legal claims  Necessary to fulfil a legal obligation 
    Assessment of Council Tax  Necessary to fulfil a public task
    Complaints may be progressed to the Office of the Independent Adjudicator for Higher Education Necessary to fulfil a legal obligation
    Personal and special category data may be shared with the Brookes Data Protection Officer   Necessary to fulfil a legal obligation
    Medical information and information relevant to self isolation is collated (e.g. about Coronavirus) is disseminated internally and may be shared with Government Agencies, medical professionals, families and others as necessary, as well as in accordance with the University’s Pandemic policy and public health requirements. The processing is in the legitimate interests of those involved including the wider student and staff community and may be to protect vital interests in extremis or otherwise to promote public health. The processing is in the legitimate interests of those involved including the wider student and may be to protect vital interests in extremis or otherwise to promote public health.
    Data sharing with third parties necessary for provision of the purposes listed above Processing is necessary for fulfilling the legitimate interest of Oxford Brookes 
    The management of data protection subject rights requests and the associated logs Necessary to fulfil a legal obligation

    Where not explicit above, Oxford Brookes may also share your data with the following third parties: 

    • The Higher Education Statistics Agency (HESA) - necessary to fulfil a legal obligation.
    • The Office for Students (OfS), previously known as the Higher Education Funding Council for England (HEFCE) - necessary to fulfil a legal obligation. 
    • Education & Skills Funding Agency - necessary to fulfil a legal obligation.
    • Other relevant training & development agencies - necessary to fulfil a legal obligation.
    • Police and other law enforcement agencies - necessary to fulfil a legal obligation. 
    • Officers of the Court - necessary to fulfil a legal obligation.
    • United Kingdom Visas & Immigration (a government agency) - necessary for fulfilling our legal duties as a sponsor of international students. 

    Yes, in some instances your personal data will be shared with third parties outside of the UK, for example the EEA, North America and Australia. Oxford Brookes will only transfer your personal data outside of the UK when one of the following conditions have been met: 

    1. You have given us explicit consent for the transfer.
    2. The country has adequate data protection laws (this is determined by the Information Commissioner’s Office, not us). 
    3. There are adequate safeguards in place, for example international data sharing frameworks or we have sufficiently robust contracts in place with the international third party. 

    You have the following rights under UK data protection law:

    • the right to be informed 
    • the right of access to your data
    • the right to withdraw your consent where that is the legal basis of our processing
    • the right to correct data 
    • the right to ask for your data to be deleted 
    • the right to restrict use of the data we hold 
    • the right to data portability 
    • the right to object to Oxford Brookes using your data 

    Your rights will depend on the legal ground used to process your data.

    Please see the ICO website for further information on the above rights.

    Yes, in many cases we will not be able to meet our commitments to you if we do not collect and store your personal data. 

    In a situation where your explicit consent is required we will make clear the specific consequence of not providing your data. 

    No, Oxford Brookes does not currently undertake any automated decision making or profiling using your personal data that falls within the scope of UK law.

    Oxford Brookes will only retain personal data for as long as necessary to: 

    1. Fulfil the purpose for which the data was collected or obtained. 
    2. Fulfil our own obligations under UK law. 

    Your personal data will be securely deleted once either of these conditions no longer apply. For more information on retention periods (the exact length of time Oxford Brookes retains each category of personal information) please refer to the University record retention schedule.

    Please contact the IT Services Information Security Management team - email info.sec@brookes.ac.uk

    In certain circumstances we may refer your query or concern to the University Data Protection Officer (DPO), a semi-independent role at Brookes required by UK law. If you would prefer to contact the DPO directly please email brookesdpo@brookes.ac.uk

    The ICO is the UK's independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. While we recommend that you raise any concerns or queries with us first you have the right to complain to the ICO directly if you believe Brookes is using your personal data unlawfully.

    Please visit www.ico.org.uk for information on how to make a complaint or would like independent and impartial guidance on data protection and privacy.

    We keep our privacy notice under regular review.  This privacy notice was last updated on 30 June 2021.