Skip to content ↓


City of London Freemen's School Privacy Notice 

For details of how we manage your data during the current pandemic, please click here.

Please download the Privacy Notice for Managing Delivery of Covid-19 Testing, click here.

1. Data Controller

The City of London Freemen’s School is part of the City of London Corporation (CoL), and it is CoL that is registered with the Information Commissioner’s Office as the Data Controller (registration number Z5996206).  

The Data Protection Officer is the CoL Comptroller & City Solicitor, who can be contacted at  

The Data Protection contact at the School is the Bursar, who can be contacted at

This Notice describes how the City of London Freemen’s School (Ashtead Park, Ashtead Surrey, KT21 1ET), collects and uses personal information about you, in accordance with the relevant legislation (United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018).  

The Notice will be reviewed periodically and may be updated at any time, we will always inform you of any substantive changes to the way we process your data. 

This Notice relates to prospective, current and past staff, pupils and parents. A separate Privacy Notice covers Alumni and Development

2. Overview 

In order to carry out its ordinary duties to staff, pupils and parents, the School collects and processes personal data about individuals (including current, past and prospective staff, pupils or parents) as part of its daily operation. The information in this Privacy Policy is provided in accordance with the rights of individuals under Data Protection Law to understand how their data is used. Parents, pupils and staff are all encouraged to read this Privacy Notice and understand the School’s obligations to them. 

Some of this activity the School will need to carry out in order to fulfil its legal rights, duties or obligations, including those under a contract with its Staff, or Parents of its Pupils. Other uses of personal data will be made in accordance with the School’s legitimate interests, or the legitimate interests of another, provided that these are not outweighed by the impact on individuals, and provided it does not involve special or sensitive types of data. The School may also collect, process and store in the short-term data pertaining to job applicants and contractors. The legal basis for processing and storing this information is legitimate business interest. 

This Privacy Notice applies alongside any other information the School may provide about a particular use of personal data, for example when collecting data via an online or paper form. 

This Privacy Notice also applies in addition to the School's other relevant terms and conditions and policies, including: 

  • any contract between the School and its staff or the parents of pupils; 

  • the School's policy on taking, storing and using images of children; 

  • the School’s CCTV and/or biometrics policy; 

  • the School’s retention of records policy; 

  • the School's safeguarding, pastoral, or health and safety policies, including as to how concerns or incidents are recorded; and 

  • the School's IT policies, including its Acceptable Use policies and Online Safety policy 

3. Types of data collected and held by the School 

When you request information from the School, we will require some personal information about you, including your name, address, email address and telephone number. This information allows the School to fulfil your request and keep you informed. This may be provided by you or third parties electronically or on paper. The data the School holds will be the minimum it requires to form and maintain the contract between you and the School. 

Where payments are made to the School, details of payment card numbers and expiry dates will go through a secure server operated by the School's Payment Service Provider. 

If you are a parent, some of the personal information held about you will include:  

  • Your name, title, gender, nationality and date of birth.  

  • Your home address, email address and telephone numbers.  

  • Your bank account number, name and sort code (used for processing Direct Debits). 

  • correspondence with and concerning pupils and parents past and present. 

  • your visa status if your child’s permission to study is by virtue of other status. 

If you are a pupil, former pupil or prospective pupil, some of the personal information held about you will include:  

  • Your name, title, gender, nationality and date of birth.  

  • Your home address, email address and telephone numbers.  

  • Start date, previous academic record, references, relevant medical information, attendance data, disciplinary records, learning support information, examination scripts and marks.  

  • Right to study within the UK including passport details, visa status if applicable. 

  • correspondence with and concerning pupils and parents past and present. 

  • Images, including the image stored on the School’s Management of Information System, images of you engaging in School activities and images captured by the School’s CCTV system. 

  • Year at School, leaving date. 

If you are a member of staff, former member of staff or prospective member of staff, some of the personal information held about you will include: 

  • Your name, title, gender, nationality and date of birth.  

  • Your home address, email address and telephone numbers.  

  • Start date, references, relevant medical information, bank details. 

  • Right to work within the UK including passport details, visa status if applicable. 

  • Images, including the image stored on the School’s Management of Information System and images captured by the School’s CCTV system. 

  • Year at School, leaving date. 

In addition, personal data will also be processed for the purposes of providing further educational resources to ensure the continuing education for all pupils during lockdown or periods of self isolation, following the outbreak of Covid-19 and to assist in skill development in practical subjects including PE and Drama in the form of recorded lessons.  

Please also see the privacy notice for Alumni and Development. 

4. Why the School needs to process personal data 

In order to carry out its ordinary duties to pupils and parents, the School needs to process a wide range of personal data about individuals (including current, past and prospective, pupils or parents) as part of its daily operation. 

Some of this activity the School will need to carry out in order to fulfil its legal rights, duties or obligations – including those under a contract with parents of its pupils. 

Other uses of personal data will be made in accordance with the School’s legitimate interests, or the legitimate interests of another, provided that these are not outweighed by the impact on you, and provided it does not involve special or sensitive types of data. 

The School expects that the following uses will fall within that category of its “legitimate interests”: 

  • For the purposes of pupil selection (and to confirm the identity of prospective pupils and their parents). 

  • To provide education services, including musical education, physical training, career services, and extra-curricular activities to pupils, and monitoring pupils' progress and educational needs. 

  • For the purposes of management planning and forecasting, research and statistical analysis, including that imposed or provided for by law (such as tax, diversity or gender pay gap analysis). 

  • To enable relevant authorities to monitor the School's performance and to intervene or assist with incidents as appropriate. 

  • To give and receive information and references about past, current and prospective pupils, including relating to outstanding fees or payment history, to/from any educational institution that the pupil attended or where it is proposed they attend; and to provide references to potential employers of past pupils. 

  • To enable pupils to take part in national or other assessments, and to publish the results of public examinations or other achievements of pupils of the School. 

  • To safeguard pupils' welfare and provide appropriate pastoral care. 

  • To monitor (as appropriate) use of the School's IT and communications systems in accordance with the School's IT: acceptable use policy. 

  • To make use of photographic images of pupils in School publications, on the School website and (where appropriate) on the School's social media channels in accordance with the School's policy on taking, storing and using images of children. 

  • For security purposes, including biometrics and CCTV in accordance with the School’s biometrics or CCTV policy.

  • To carry out or cooperate with any School or external complaints, disciplinary or investigation process; and 

  • Where otherwise reasonably necessary for the School's purposes, including to obtain appropriate professional advice and insurance for the School. 

  • In addition, the School will on occasion need to process special category personal data (concerning health, ethnicity, religion, biometrics or sexual life) in accordance with rights or duties imposed on it by law, including as regards safeguarding, or from time to time by explicit consent where required.  

  • To notify and / or supply information relating to a child’s right to enter, reside and / or study in the United Kingdom to the United Kingdom Visas and Immigration (UKVI) unit of the Home Office, in compliance with the School’s responsibilities as a Tier 4 sponsor. 

These reasons will include: 

  • To safeguard pupils' welfare and provide appropriate pastoral (and where necessary, medical) care, and to take appropriate action in the event of an emergency, incident or accident, including by disclosing details of an individual's medical condition or other relevant information where it is in the individual's interests to do so: for example for medical advice, for social protection, safeguarding, and cooperation with police or social services, for insurance purposes or to caterers or organisers of School trips who need to be made aware of dietary or medical needs.

  • To provide educational services in the context of any special educational needs of a pupil. 

  • To run any of its systems that operate on biometric data, such as for security and other forms of pupil identification (door entry systems, lunch etc.).

  • As part of any School or external complaints, disciplinary or investigation process that involves such data, for example if there are SEN, health or safeguarding elements; or 

  • For legal and regulatory purposes (for example child protection, diversity monitoring and health and safety) and to comply with its legal obligations and duties of care. 

5. How the School processes data 

Generally, the School receives personal data from the individual directly (including, in the case of pupils, from their parents). This may be via a form, or simply in the ordinary course of interaction or communication (such as email or written assessments). 

However in some cases personal data will be supplied by third parties (for example another School, or other professionals or authorities working with that individual). 

6. Who has access to data 

Access to personal data is restricted to those members of staff who have a requirement to maintain a relationship with you, and is controlled through password protection and user security profiles. All School staff that are given access to personal data receive mandatory Data Protection training and have a duty to maintain confidentiality under the Data Protection Act. Access to special category data is restricted to key personnel and staff with such access receive a higher level of training.  

For example:  

  • medical records are held and accessed only by the School Nurse, Designated Safeguarding Lead and Head of Boarding; 

  • safeguarding files are restricted to the Head and the Head’s EA, the Designated Safeguarding Lead (DSL) and deputy DSLs, and the DSL’s administrative assistant;  

  • pastoral files are restricted to the Deputy Head Pastoral, Heads of Section and Heads of Year. However, information regarding pastoral concerns and safeguarding and child protection concerns may be shared confidentially with other members of staff on a ‘need to know’ basis;  

  • Learning Support information, which may include special category data, is shared in part with staff in the context of providing the necessary care and education that the pupil requires.  

Personal data is processed by the School to:  

  • Keep you informed of your progress (pupils) or to keep you informed about your child’s progress (parents);  

  • Promote events;  

  • Send news and updates;  

  • Recruit alumni volunteers and mentors;  

  • Provide community news. 

7. With whom does the School share data 

Personal data is never sold to third parties. In many circumstances we will not disclose personal data without consent. However, there may be occasions, such as pupils changing Schools, when we will need to share personal information with the organisation concerned and with other relevant bodies.  

Occasionally the School will need to share personal information relating to its community with third parties, such as professional advisers (lawyers and accountants) or relevant authorities (HMRC, police or the City of London Corporation, the local authority). 

Information about employees may also be disclosed where required by law, or in connection with legal proceedings, or for the prevention / detection of crime, or assessment / collection of tax.  

The School is required to disclose some personal data to the Department of Education, e.g. data related to students continuing with sixth form studies.  

The School may share personal data with third party organisations which carry out contracts on behalf of the School (such as Sodexo our Catering supplier, Agents or Guardians of our international students). The School will only share personal data that is relevant and proportionate. All data processing activities are logged and reviewed from time to time. Should a safeguarding issue arise, personal data may be shared after consultation with the DSL (Designated Safeguarding Lead).  

Finally, in accordance with Data Protection Law, some of the School’s processing activity is carried out on its behalf by third parties, such as IT systems, web developers or cloud storage providers. This is always subject to contractual assurances that personal data will be kept securely and only in accordance with the School’s specific directions. 

8. How is your data stored 

Personal data is stored electronically in the School’s MIS, IT Systems, and, in some instances, in paper record. Paper records of special category data and higher category sensitive information are kept under lock and key. 

Although most of the information we store and process stays within the UK, some information may be transferred to countries outside the European Economic Area (EEA). This may occur if, for example, one of our trusted partner’s servers are located in a country outside the EEA. These countries may not have similar data protection laws to the UK; however, we will take steps to ensure they provide an adequate level of protection in accordance with UK data protection law by the use of EU model contract clauses or, for 6 organisations that we work with who process personal information in the USA, verification that their data processing standards meet the EU-US Privacy Shield. By submitting your personal information to us you agree to this transfer, storing or processing at a location outside the EEA. 

9. How long will we keep your data? 

The School will retain personal data securely and only in line with how long it is necessary to keep for a legitimate and lawful reason. Typically, the legal recommendation for how long to keep ordinary staff and pupil personnel files is up to seven years following departure from the School. However, incident reports and safeguarding files will need to be kept much longer, in accordance with specific legal requirements. Currently, the Independent Inquiry into Child Sexual Abuse is reviewing historic cases.  The School has been advised to retain all records until the Inquiry has concluded and any recommendations on record retention have been made.  

If you have any specific queries about how our retention policy is applied, or wish to request that personal data that you no longer believe to be relevant is considered for erasure, please contact the Bursar However, please bear in mind that the School will often have lawful and necessary reasons to hold on to some personal data even following such request. 

A limited and reasonable amount of information will be kept for archiving purposes, for example; and even where you have requested we no longer keep in touch with you, we will need to keep a record of the fact in order to fulfil your wishes (called a "suppression record"). 

10. Cookies 

Cookies are text files which identify a user’s computer to our server. Cookies in themselves do not identify the individual user, just the computer used. The Freemen’s website uses persistent cookies – these are used to track returning visitors. They expire after 12 months and enable us to compare website traffic from month to month. Cookies help us to identify which pages are most visited and which events or activities are of most interest. This information can be used to help us improve our website and services and ensure we provide you with the best service. Wherever possible, the information we use for this purpose will be aggregated or anonymised (i.e. it will not identify you as an individual visitor to our website). You can reject cookies. Most browsers allow you to refuse cookies – consult the ‘help’ section of the browser toolbar. Information on controlling or rejecting cookies is available from several sources. For a list of cookies used, go to  

11. Analytics 

The Freemen’s website uses Google Analytics tracking codes to measure performance enabling us to enhance and improve services for our audiences. However, we do not collect personally-identifiable information (PII) as all data collected is anonymous. If you do not want Google Analytics to use your data then please visit Google Analytics opt-out browser add-on. 

12. Your rights

Individuals have various rights under Data Protection Law to access and understand personal data about them held by the School, and in some cases ask for it to be erased or amended or for the School to stop processing it, but subject to certain exemptions and limitations.  

Any individual wishing to access or amend their personal data, or wishing it to be transferred to another person or organisation, should email their request to  

The School will endeavour to respond to any such written requests as soon as is reasonably practicable and in any event within statutory time-limits, which is one month (from May 2018) in the case of Subject Access Requests. The School will be better able to respond quickly to smaller, targeted requests for information. If the request is manifestly excessive or similar to previous requests, the School may ask you to reconsider or charge a proportionate fee, but only where Data Protection Law allows it.  

You should be aware that certain data is exempt from the right of access. This may include information which identifies other individuals, or information which is subject to legal professional privilege. The School is also not required to disclose any pupil examination scripts (though examiners' comments may fall to be disclosed), nor any confidential reference given by the School for the purposes of the education, training or employment of any individual. 

Pupils aged 13 or over have the same rights as adults over their personal data and may submit their own Subject Access Requests. A subject access request from a pupil under the age of 13 may be considered if, in the opinion of the School, the pupil is of sufficient maturity. More usually, a person with parental responsibility will generally be expected to make a subject access request on behalf of younger pupils. However, the information in question is always considered to be the child’s at law. A pupil of any age may ask a parent or other representative to make a subject access request on their behalf, and moreover (if of sufficient age) their consent or authority may need to be sought by the parent. All subject access requests from pupils will therefore be considered on a case by case basis. 

Where the School is relying on consent as a means to process personal data, any person may withdraw this consent at any time (subject to similar age considerations as above). Please be aware however that the School may have another lawful reason to process the personal data in question even without your consent. That reason will usually have been asserted under this Privacy Policy or may otherwise exist under some form of contract or agreement with the individual (e.g. an employment or parent contract, or because a purchase of goods, services or membership of an organisation has been requested.) 

The rights under Data Protection Law belong to the individual to whom the data relates. However, the School will often rely on parental consent to process personal data relating to pupils (if consent is required) unless, given the nature of the processing in question, and the pupil's age and understanding, it is more appropriate to rely on the pupil's consent. Parents should be aware that in such situations they may not be consulted, depending on the interests of the child, the parents’ rights at law or under their contract, and all the circumstances.  

In general, the School will assume that pupils’ consent is not required for ordinary disclosure of their personal data to their parent (e.g. for the purposes of keeping parents informed about the pupil's activities, progress and behaviour, and in the interests of the pupil's welfare) unless, in the School's opinion, there is a good reason to do otherwise. However, where a pupil seeks to raise concerns confidentially with a member of staff and expressly withholds their agreement to their personal data being disclosed to their parents, the School may be under an obligation to maintain confidentiality unless, in the School's opinion, there is a good reason to do otherwise (e.g. where the School believes disclosure will be in the best interests of the pupil or other pupils, or if required by law). 

Pupils are required to respect the personal data and privacy of others, and to comply with the School's Acceptable Use Policy (Pupils) and the School Standards (Rules and Regulations). Staff are under professional duties to do the same, as covered under the School’s Acceptable Use Policy (Staff) and all other relevant staff policies. 

13. Data Accuracy and Security  

The School will endeavour to ensure that all personal data held in relation to an individual is as up to date and accurate as possible. Individuals must notify the School of any changes to information held about them (please contact  

An individual has the right to request that any inaccurate or out-of-date information about them is erased or corrected (subject to certain exemptions and limitations under Act; please see above).  

The School will take appropriate technical and organisational steps to ensure the security of personal data about individuals, including policies around use of technology and devices, and access to School systems. All Staff and Governors will be made aware of this policy and their duties under Data Protection Law and will receive relevant training 

14.  Links to other websites  

This privacy notice does not cover the links within this site linking to other websites. We encourage you to read the privacy policies / notices / statements on the other websites you visit. 

15.  Queries or Complaints 

Any comments or queries on this policy should be directed to the School at  

If an individual believes that the School has not complied with this policy or acted otherwise than in accordance with Data Protection Law, they should utilise the School’s complaints procedure and should also notify the School at  

You can also make a referral to or lodge a complaint with the Information Commissioner’s Office (, although the ICO recommends that steps are taken to resolve the matter with the School before involving the regulator. 

COVID 19 Privacy Notice 

This Privacy Notice should be read in conjunction with our standard Privacy Notice above.

 What information are we collecting?

The categories of information that we collect, hold and share include the following:

  • Basic personal information (e.g. name, pupil number, DOB and address) (pupils, parents and staff)
  • Safeguarding information (pupils)
  • Job role and evidence of employment in this role (parents)
  • Attendance information (pupils and staff)
We will also process information which may include ‘special category’ data about our pupils including:
  • Relevant medical information (pupils and staff)

Any personal data that we process about our pupils and parents is done so in accordance with Article 6 and Article 9 of GDPR:
Article 6 (c) legal obligation Article 6 (d) public task Article 6(b) contract (for staff)
Article 9 (b) Employment, social security and social protection (for staff) Article 9 (g) Reasons of substantial public interest 
Please refer to our Privacy Notice above for further information about the lawful basis we rely upon to process your data.

Who do we obtain your information from?

Most of the information will come from you. We will also process information received from:

  •  Department for Education (DfE)
  • Holiday Health Questionnaires

Please see the general privacy notice above for rights you have over your data.

NHS Test and Trace

All UK schools have an obligation to respond appropriately to the Government’s advice regarding coronavirus. In order to aid the Government in fighting COVID-19 (coronavirus) and to help keep everyone safe as children return to school, the school will take part in the NHS “Test and Trace” service.

If there is a suspected or confirmed case of COVID-19 then we may be required to share staff, students, parents and visitor’s personal data with NHS Test and Trace, who act as a Data Controller in their own right. We may also share this information with the Local Authority, who will use it for the purposes of COVID-19 prevention and detection only. This information may include:

  • Your full name
  • Your date of birth
  • Your contact details
  • Relevant medical information

We will keep a record of any information shared.

If the NHS Test and Trace service contacts you, the service will use text messages, email or phone.

All information which we share through this service is shared in accordance with Article 6 and 9 of the GDPR:

Article 6(1)(e) ‘processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller’

 Article 9(2)(i) ‘processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of healthcare’

 For more information about the service please see the Government guidance and Public Health England’s privacy notice: