Skip to main content

Choose your sector

Education and childcare

Use this tool to create a bespoke privacy notice for your customers or suppliers. The privacy notice generator is only suitable for the sector it’s designed for, for their collection and use of customer and supplier personal information.

The tool will ask you questions broken down into simple steps, and then generate a privacy notice that you can download (or copy and paste) and add your own branding. You can then share your privacy notice with people outside your organisation.

This tool is for small and medium-sized businesses and charities. It’s not suitable for organisations that:

Where this is the case, the generated privacy notice may not be compliant with the law without significant restructuring and amendments being made.

Before you start

Make sure you have the following information to hand before you create your privacy notice:

 A basic understanding of data protection and how it applies to your business

What does this mean?

If you’re new to data protection, we suggest you read our beginner’s guide before using this tool. There are some steps you might need to take before you’re able to get started.

You should also be familiar with key data protection terms including what personal information is. 

What personal information you collect or use

What does this mean?

Personal information is any information that identifies and relates to a living person. Read our guidance to find out more about what’s considered personal information.

You first need to understand all the types of personal information you are collecting or using in your organisation.

Why you collect and use information

What does this mean?

You need to know why you’re collecting and using people's information. For example, your reasons might be to provide education and welfare support or handle disciplinary matters.

You should also identify the minimum amount of personal information you need to fulfil your purpose. You should hold that much information, but no more. Read our guidance on data minimisation for further information. 

 Whose personal information you collect

What does this mean?

You need to know whose personal information you’re collecting. You also need to understand your target audience so you can make sure your privacy notice is accessible and appropriate for everyone it applies to. You may need to provide different versions depending on who your data subjects are eg consumers or businesses. 

You must think about whether you’re collecting information about children, as they need special protection in how their data is used. If you’re providing online services likely to be accessed by children in the UK, you must take into account the best interests of the child. Read our guidance on the children’s code for further information.

 An understanding of your role and your relationships under data protection law

What does this mean?

You need to understand if you are using personal information as a controller, joint controller or processor. These technical terms are explained in our guidance

Next, look at your contracts or terms and conditions with your customers, suppliers, service providers, insurers, accountants and any others. These may be small or large businesses, charities, clubs and other organisations or sole traders. We use the word “organisation” to mean any of those. 

In these documents you may find helpful information, in particular:

  • Whether you or the other organisation is acting as a controller, joint controller or processor.
  • Why you’re collecting and using personal information.

Read our guidance for further information. 

Why you are allowed to use personal information

What does this mean?

You need to know all the reasons you can rely on to collect and use personal information (known as lawful bases). You may have a different lawful basis for each of the reasons you use this information. The six lawful bases are: consent, contract, legal obligation, vital interests, public task and legitimate interests. Read our guidance for further information.

If you haven’t decided which lawful basis to rely on, you can use our interactive tool to help you. 

Where you get people’s information from

What does this mean?

You need to know where you collect people's information from. It may be directly from the person or it may be from other sources, including public sources. There are lots of places you may receive information from, such as from parents or carers, local authorities or other education establishments.

How long you keep people’s information

What does this mean?

You need to know how long you keep information for, and how you delete or destroy it when you no longer need it. If you don’t have a specific timeframe for how long you keep information, you must tell people how you decide how long you’ll keep their information, eg until a contract ends. Read our guidance on retention for further information.

Which organisations you share information with, and why

What does this mean?

You need to know which organisations you share information with, including any data processors. Your contract with the organisation should set out if they are a processor.

If you use a service provider to store your data, or to provide your email and other administrative services (these may be cloud services), you will be sharing personal information with them. 

If you allow an organisation to access personal information, which remains on your system, this is also sharing information. 

If you share personal information overseas

What does this mean?

You need to know if you’re sharing information with a separate organisation based outside the UK. 

You will not be sharing information outside of the UK if the other organisation is a UK based company. Check your contracts or terms and conditions to see if the other organisation is UK based. 

Sharing data overseas could include:

  • Sending information outside the UK by email.
  • Giving a non-UK organisation access to your database.
  • Using a non-UK company as your service provider, for example cloud services, storage or support.

This does not include sending information to a non-UK consumer. A consumer is a living person that you’re providing goods or services to for their own domestic or household purposes, and not relating to their trade, business or profession.

If you’re using a UK based processor, it also includes where that UK processor is sharing information with its sub-processors which are non-UK companies. Your contract with the UK processor should set out this information.

Read our guidance to learn more about transferring personal information outside of the UK.


Please note:
 This privacy notice is not written for children under 18. Where you collect or use personal information of people under 18, you must present your privacy information in a way that can be understood by them. For more information, see our guidance on designing data transparency for children.

This privacy notice is not written for people who are unable to read English or people with a learning disability. This is because they may not understand it and therefore cannot make an informed choice about providing their personal information to you. 

Using this tool will help you tell your customers and suppliers how you use their information, but it’s your responsibility to comply with the law.

This privacy notice generator is in beta phase. This means it is being tested, amended and updated following review and feedback. If you use this privacy notice generator while it is in beta phase you must review your privacy notice and update it once the privacy notice generator is in final form, in the next 12 months.

In any event, in accordance with data protection law you should regularly review your privacy notice to ensure it remains accurate and up to date. We recommend that you review your privacy notice at least every 12 months, or sooner if you make significant changes.

The privacy notice generator does not cover the use of cookies. Read our cookies guidance.

 

The information you input will be retained until midnight on the day you submit it. This is necessary so the tool can produce your bespoke privacy notice. The ICO will not access or use this information.