Erin College Data Protection & Data Management Policy (2026)
Introduction
Erin College is committed to protecting the privacy, rights, and freedoms of all individuals whose personal data we process, including students, staff, contractors, applicants, and website users.
This policy is aligned with:
- EU General Data Protection Regulation (GDPR) (EU) 2016/679.
- Irish Data Protection Act 2018.
- ePrivacy Regulations (Cookies & Electronic Communications).
It establishes a unified framework for data collection, processing, storage, security, retention, and governance across all operations of Erin College.
Scope
This policy applies to:
- Students (prospective, current, former);
- Employees, contractors, and job applicants;
- Website users and visitors;
- Third-party partners and service providers.
It covers:
- Personal data;
- Biometric data;
- CCTV footage;
- Digital and physical records.
Data Protection Principles
Erin College adheres to GDPR principles:
- Lawfulness, Fairness, and Transparency: Data will be processed lawfully, fairly, and in a transparent manner.
- Purpose Limitation: Data will only be collected for specific, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data Minimisation: Only the minimum amount of data necessary for the intended purpose will be collected and processed.
- Accuracy: Personal data will be kept accurate and, where necessary, up to date.
- Storage Limitation: Data will not be retained longer than necessary for the purpose for which it was collected.
- Integrity and Confidentiality: Data will be processed securely to prevent unauthorized access, loss, or damage.
Categories of Data Collected
Personal Data
Includes:
- Name, address, email, phone number, nationality;
- Date of birth, identification documents (passport/visa);
- Academic records (attendance, results, certifications);
- Financial/payment details;
- Employment records (HR);
- Communication records.
Special Category Data
Processed only where necessary:
- Health/medical information (insurance, welfare);
- Safeguarding-related data.
Biometric Data
- Facial recognition and/or fingerprint data;
- Used strictly for attendance monitoring and identity verification;
- Processed under strict safeguards and legal basis (public interest / legal obligation for immigration compliance).
Non-Personal Data
- Aggregated analytics;
- Anonymised IP addresses;
- Website usage statistics.
Legal Basis for Processing
Data is processed under the following lawful bases:
- Contractual necessity (student enrolment, employment);
- Legal obligation (immigration, tax, compliance);
- Consent (marketing, optional services);
- Legitimate interests (administration, security);
- Vital interests (health/safety situations).
Purpose of Data Processing
Student Data
- Enrolment and academic administration;
- Attendance monitoring (including biometric systems);
- Immigration and visa compliance;
- Accommodation and welfare support;
- Insurance (medical and learner protection);
- Communication and academic updates.
HR Data
- Recruitment and onboarding;
- Payroll, tax, and legal compliance;
- Performance management;
- Health and safety obligations.
Website Data
- Website functionality and optimisation;
- Analytics and performance tracking;
- User communication and enquiries.
Data Sharing and Transfers
Internal Access
Access is restricted to authorised personnel on a need-to-know basis.
Third-Party Sharing
Data may be shared with:
- Payment processors
- Immigration authorities
- Insurance providers
- Accommodation providers
- Payroll and HR service providers
- IT and cloud service providers (e.g. Google Drive)
All third parties are subject to:
- Data Processing Agreements (DPAs)
- GDPR compliance obligations
International Transfers
Where data is transferred outside the EEA:
- Standard Contractual Clauses (SCCs) or equivalent safeguards are applied
Data Security Measures
Erin College implements technical and organisational safeguards:
Technical Measures
- Encryption (especially biometric data)
- Firewalls and antivirus systems
- Secure cloud storage (e.g. Google Drive)
- Password protection and access logs
Organisational Measures
- Role-based access controls
- Staff training on GDPR
- Confidentiality agreements
- Regular audits and reviews
Data Retention Policy
Personal data will only be retained for as long as necessary for the purposes for which it was collected, in compliance with legal requirements. For example, employee records will be kept for the duration of employment and an additional period in accordance with statutory retention periods.
Data Disposal
When data is no longer needed, it will be securely deleted or shredded (if in paper form). Digital records are all stored on Google Drive and once files are deleted and the trash has been emptied, retrieving files is no longer possible.
General Personal Data
- Retained for duration of relationship + legal retention periods
Student Data
- Retained for academic, legal, and immigration compliance purposes
- May be retained longer where required by regulation
HR Data
- Retained for duration of employment + statutory retention periods
Biometric Data
- Retained during enrolment
- Deleted within 12 months after course completion
9.5 CCTV Data
- Retained for 28 days
- Extended retention only for investigations or legal purposes
CCTV Policy
CCTV is used for:
- Security and safety
- Protection of property
- Incident investigation
Measures include:
- Clearly visible signage
- Restricted access to footage
- Controlled monitoring
- Disclosure only when legally required
Cookies and Website Analytics
Erin College uses cookies for:
- Website functionality
- User preferences
- Analytics (e.g. Google Analytics)
Users can:
- Accept or refuse cookies
- Adjust browser settings
- Use opt-out tools for analytics tracking
Data Subject Rights
Individuals have the following rights regarding their data:
- Right to Access: Employees and other data subjects can request access to their personal data held by the HR department.
- Right to Rectification: Individuals can request the correction of inaccurate or incomplete data.
- Right to Erasure (“right to be forgotten”): Under certain circumstances, individuals can request the deletion of their personal data.
- Right to Restrict Processing: Individuals can request restrictions on the processing of their data, assuming that does not interfere with the company’s legal requirements.
- Right to Object: Individuals can object to the processing of their data under certain conditions.
- Withdraw consent
- Lodge a complaint with the Data Protection Commission (Ireland)
Requests contact: [email protected]
Data Breach Management
In case of a data breach:
- Incident is assessed immediately
- Reported within 72 hours to the Data Protection Commission (if required)
- Affected individuals notified where there is risk
- Mitigation measures implemented
Governance and Accountability
Data Protection Officer (DPO)
Erin College appoints a DPO responsible for:
- Monitoring compliance
- Advising on GDPR obligations
- Handling data protection queries
Training
All management personnel receive training on data protection and GDPR compliance. Staff are required to understand their responsibilities under this policy and adhere to data protection best practices.
Audits
Data protection procedures are periodically reviewed and updated and with legal updates as necessary.
Policy Review
This policy will be reviewed annually, or more frequently if needed, to ensure it remains up-to-date with legal requirements and best practices. Any changes will be communicated to relevant staff members.
Last Updated: February 2026
Contact Information
Erin College 42-43 North Great George’s Street Dublin, Ireland – D01 N6P2
Email: [email protected]