Policy Statement: Liffey College is dedicated to upholding high standards in data protection, cybersecurity and information governance. This policy ensures that all personal data is: ➤ Processed lawfully, fairly and transparently. ➤ Collected and used for specified purposes only. ➤ Stored securely with access controls and encryption. ➤ Retained only for as long as necessary. ➤ Protected from unauthorised access, loss or misuse.
1. Scope & Applicability This policy applies to: ➤ Learners, staff, external partners and third-party service providers who process or access personal data on behalf of Liffey College. ➤ All personal data collected, stored, processed and disposed of, including: – Learner records (e.g., enrolment, academic performance). – Employee data (e.g., HR files, payroll information). – IT & Digital Records (e.g., databases, cloud storage). – Financial transactions and communications.
2. Data Protection Principles Liffey College adheres to the seven core principles of GDPR: Lawfulness, Fairness and Transparency, Data is collected and processed only on a lawful basis and with transparency. ➤ Purpose Limitation – Personal data is used only for the purposes for which it was collected. ➤ Data Minimisation – Only necessary data is collected, stored and processed. ➤ Accuracy – Data must be accurate and up to date.Storage Limitation – Data is retained for a defined period and securely disposed of thereafter. ➤ Integrity & Confidentiality (Security) – Appropriate technical and organisational security measures are implemented to protect data. ➤ Accountability – The College ensures compliance through audits, documentation and governance policies.
3. Data Subject Rights Individuals have the right to: ➤ Access their personal data and request copies. ➤ Rectification – Request correction of inaccurate data. ➤ Erasure (“Right to be Forgotten”) – Request data deletion, subject to legal obligations. ➤ Restrict Processing – Request limitations on data use. ➤ Data Portability – Receive data in a structured format. ➤ Object – Opt out of specific data processing (e.g., marketing). Data Access Requests: Requests must be made in writing to the Data Protection Officer (DPO) Haseeb Ahmed at haseeb@liffeycollege.ie
4. IT Security & Third-Party Data Management Liffey College has outsourced IT security and data processing to DigitalSofts Ltd., ensuring compliance with GDPR and industry security standards. Security Measures Implemented: ➤ Data Encryption – All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). ➤ Access Controls – Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) restrict data access to authorised personnel. ➤ Network Security – Firewalls, intrusion detection systems and strong password policies safeguard IT infrastructure. ➤ Data Processing Agreements (DPA) – All third-party processors (e.g., AWS, OVH) comply with ISO 27001 security standards.
Third-Party Data Processing & Storage: ➤ Cloud Hosting: Data is hosted securely in AWS (London) and OVH (France). ➤ External IT Support: DigitalSofts Ltd. is responsible for system monitoring, IT risk assessments and cybersecurity compliance.
5. Data Breach Management Liffey College follows a structured Data Breach Response Plan: ➤ Low-Risk Breaches: Managed internally with corrective actions. ➤ High-Risk Breaches: – Reported to the DPO and Board of Directors within 72 hours. – If required, notified to the Data Protection Commission (DPC). – Affected individuals will be informed as per GDPR guidelines.
6. Data Retention & Secure Disposal Retention Periods: ➤ Learner records: 6 years after course completion. HEIs generally retain student records for 6 years after course completion for audit, accreditation and compliance purposes. This aligns with QQI’s statutory QA guidelines for learner records and institutional reviews. (Quality and Qualifications Ireland (QQI) – Statutory Quality Assurance Guidelines – https://www.qqi.ie) ➤ Employee records: 7 years post-employment. Payroll, contracts and HR records must be retained for a minimum of 6 years for tax and employment law compliance. An extra year is often included for any potential disputes or audits. (Irish Revenue – Employment Records Retention Guidance https://www.revenue.ie/en/employing-people/index.aspx ) ➤ Financial records: 6 years. Irish law mandates that financial records (including invoices, payroll andtax-related documents) must be retained for at least 6 years for audit and compliance with Revenue requirements. (Companies Act 2014 (Ireland) – Section 281 https://www.irishstatutebook.ie/eli/2014/act/38/enacted/en/html ) ➤ IT system logs: 1 year. IT logs, including system access and authentication logs, should only be retained for as long as necessary to fulfil security and compliance obligations. Best practice suggests retaining logs for 12 months unless a longer retention period is justified (e.g., legal investigations, regulatory requirements). ISO 27001 & IT Security Standards also recommend minimizing long-term storage of sensitive IT logs to reduce security risks. (EU General Data Protection Regulation (GDPR) – Recital 39 & Article 5 https://gdpr.eu/) Secure Disposal Methods: ➤ Physical documents – Shredding or secure destruction. ➤ Electronic records – Permanent deletion with data-wiping technology.
7. Compliance, Oversight & Policy Review ➤ The Data Protection Officer (DPO) ensures compliance, staff training and risk monitoring. ➤ Annual audits assess IT security risks and policy effectiveness. ➤ This policy is reviewed annually and updated based on legal or operational changes. For questions regarding data protection, contact: Data Protection Officer (DPO) Haseeb Ahmed – haseeb@liffeycollege.ie |