The five key points every member of staff needs to know.
- Individuals have the right to ask to see any information the University of Edinburgh holds about them. We have 40 calendar days to respond. If someone asks to see information that you hold about them, contact your local freedom of information practitioner as soon as possible.
- You must tell individuals what you do with information regarding them, including to whom you disclose it.
- You must keep and dispose of personal data securely. Appropriate measures include locking doors and filing cabinets, password security and encryption.
- If you pass personal data outside of the University, follow University policies and procedures, including when you put personal information on the internet, allow contractors access to systems, or share personal data with government agencies and others.
- Do not keep personal data for longer than is necessary. Consult the University's retention schedules for advice on how long to keep things.
For advice on data protection or if you have concerns about disclosing any information, contact the Records Management Section.