Records Management & Information Governance
This privacy notice is for agents submitting and managing applications on behalf of individuals intending to study at the University of York and Hull York Medical School (HYMS). It sets out the ways in which the University of York gathers, uses, stores and shares your data. It also sets out how long we keep your data and what rights you have in relation to your data under the UK General Data Protection Regulation (GDPR).
For the purposes of this privacy notice, University of York is the Data Controller as defined in the General Data Protection Regulation. For the University’s registration with the Information Commissioner’s Office, see the Information Commissioner's Register of Fee Payers. Our registration number is: Z4855807.
The organisation collects information from you in a variety of ways. These include:
Personal data including:
Typically, data will be processed:
The University will process your personal data for the following purposes:
The University may share your data with:
The University takes information security extremely seriously and has implemented appropriate technical and organisational measures to protect personal data and special category data. Access to information is restricted on a need-to-know basis and security arrangements are regularly reviewed to ensure their continued suitability. Access to information is restricted on a need-to-know basis and security arrangements are regularly reviewed to ensure their continued suitability. For further information please see our IT Security webpages.
In certain circumstances, it is necessary to transfer your Personal Data outside the European Economic Area. In respect of such transfers, the University will comply with our obligations under UK GDPR and ensure an adequate level of protection for all transferred data.
The University will retain your data in line with legal requirements or where there is a business need. Retention timeframes will be determined in line with the University’s Records Retention Schedule.
Under the UK General Data Protection Regulation, you have a right of access to your data, a right to rectification, erasure (in certain circumstances), restriction, objection or portability (in certain circumstances). You also have a right to withdraw consent. If you would like to exercise any of these rights please contact firstname.lastname@example.org. For further information see our guidance on your rights under UK GDPR.
If you have any questions about this privacy notice or concerns about how data is being processed, please contact the University’s Data Protection Officer at email@example.com.
If you are unhappy with the way in which the University has handled your personal data, you have a right to complain to the Information Commissioner’s Office. For information on reporting a concern to the Information Commissioner’s Office, see their complaints guidance.
We keep our privacy notice under regular review. This notice was last updated on 14th July, 2021.