top of page

GDPR and Privacy Policy


1. Introduction
This document outlines the GDPR and Privacy Policy for PENINSULA MUSIC CO-OPERATIVE LIMITED ("We", "Our", "Us"). It details how we handle the personal information of Teacher-members, Clients, and other stakeholders, ensuring transparency and providing contact information for data inquiries.
We prioritize our obligations under the Data Protection Act 2018 (GDPR), acknowledging the importance of maintaining professional trust and public credibility. This policy defines our management of these responsibilities.
The Board oversees compliance with this policy. Inquiries or concerns regarding data implementation should be directed to the Chair, acting as the Data Protection Officer.
Teacher-members are expected to adhere to these regulations and established protocols; failure to do so may result in termination of membership. Data protection is a collective responsibility, and this framework clarifies our standards for handling Personal Data.
This policy spans all Personal Data processed by the Co-operative, regardless of storage media, covering past and present Teacher-members, Clients, suppliers, and third parties.


2. Data Management
Under the Act, the Co-operative serves as the Data Controller, managing personal information related to Teacher-members, students, parents, and contractors involved in our daily operations (Data Subjects).
Processing of Personal Data is strictly confined to providing essential services and support to our Teacher-members.
Key Definitions
Data Controller: The entity determining the purpose and methods of data processing, responsible for upholding GDPR standards.
Data Protection Officer: The Chair of the Board, responsible for overseeing compliance.
Data Subject: A living individual who is the subject of personal data.
Personal Data: Any information relating to an identifiable living person, collected for specific purposes.
Processing: Any activity involving personal data, including collection, recording, storage, retrieval, disclosure, or deletion.
Privacy Notice: A document informing Data Subjects about the specific collection of their information.
Special Category Data: Highly sensitive information such as ethnic origin, beliefs, health conditions, or biometric data, processed only under strict legal conditions.
Principles of Data Protection
Personal data must be:
- Processed fairly, lawfully, and transparently, often requiring consent.
- Collected for specific, legitimate goals without incompatible further processing.
- Adequate, relevant, and restricted to what is necessary.
- Accurate and kept current.
- Retained only for as long as needed for its original purpose.
- Secured via technical measures against loss or unauthorized access.
- Transferred internationally only with adequate safeguards and notification.
- Accessible to Data Subjects, ensuring they can exercise their legal rights.
Lawful processing includes fulfilling contracts, meeting legal obligations, protecting vital interests, or pursuing legitimate business interests that do not infringe on individual freedoms.
When we collect data directly, we inform subjects of:
- Our role as Data Controller.
- The legal basis and timeframe for data retention.
- Third parties involved in data sharing.
- Rights to access, correct, delete, or object to processing.
- The right to lodge complaints with the Information Commissioner’s Office (ICO).


3. The Information Commissioner’s Office (ICO)
While not currently required to register with the ICO, the Co-operative regularly reviews this status. The ICO is an independent body that monitors data laws and can issue enforcement notices, audit requests, or financial penalties for non-compliance.
We provide annual GDPR compliance information to members and perform internal audits. Teacher-members remain personally responsible for their own ICO registration regarding private, non-Co-operative activities.


4. Third-Party Processors
When external vendors process data on our behalf, the Co-operative retains ultimate responsibility for its security. We ensure processors provide rigorous security guarantees and maintain formal, compliant written contracts.


5. Subject Access Requests (DSAR)
Data Subjects may request copies of their data at no charge, unless the request is excessive or repeated. We aim to respond within one month, though complex cases may extend this by two months. Identity verification is required to prevent unauthorized disclosure.


6. Data Breaches
We report significant data breaches to the ICO and affected individuals as legally required. If you suspect a breach, contact the Chair immediately and preserve all relevant evidence for our records.


7. Compliance Checklist
- Is this information truly necessary?
- do I have a clear purpose for it?
- Do subjects understand how their data is used?
- Is the data stored securely?
- Is access restricted to those with a need-to-know?
- Am I destroying data once it is no longer required?


Detailed Privacy Provisions


This section explains how we manage data for private music tuition. We collect student details (progress, age, records), parent information (billing, contact), and administrative schedules.


Teacher Members

we collect identification, financial details, work history, references, and necessary safeguarding credentials like DBS checks.
Usage and Sharing:
Data is used to deliver lessons, communicate scheduling, manage finances, and meet mandatory safeguarding standards. We share data only with schools, relevant authorities, or essential administrative service providers. We never sell data for marketing.
Storage and Rights:
Records are kept securely for the duration of tuition/membership plus six years for legal and safety purposes. Individuals have the right to access, correct, or request the deletion of their information. Concerns regarding data should be directed to the Board.

Website enquiries

We collect name and contact details, and details of the query

Data is used to respond to queries and consent is given on the contact form.

Records are kept securely for six years for legal and safety purposes. Individuals have the right to access, correct, or request the deletion of their information. Concerns regarding date should be directed to the board at admin@peninsulamusic.co.uk.


Policy Updates:
This policy is reviewed periodically. Significant changes will be communicated to members and stakeholders as needed.

bottom of page