Data Protection and Processing Policy

1. Policy Statement

ES Solutions Group Ltd is committed to protecting the privacy and security of personal data. We process personal information in a lawful, fair, and transparent manner in accordance with:     

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • APSCo Codes of Conduct and best practice standards\

We recognise the importance of safeguarding personal data, particularly in the education sector, where sensitive information relating to children and vulnerable individuals may be processed.

2. Scope

This policy applies to:

  • Candidates (temporary, permanent, supply staff)
  • Clients (schools, academies, trusts)
  • Contractors and third parties
  • All data processing activities conducted by ES Solutions Group Ltd

3. Definitions

Personal Data

Any information relating to an identifiable individual

Special Category Data

Sensitive data including health, ethnicity, criminal records (including DBS checks) Processing
Any activity involving data (collection, storage, use, sharing, deletion)

Data Controller

ES Solutions Group Ltd (determines purpose and means of processing)

Data Processor

Third parties processing data on our behalf

4. Data Protection Principles

ES Solutions Group Ltd complies with the UK GDPR principles:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

5. Types of Data Processed

5.1 Candidate Data

  • Personal identification details
  • Employment history and qualifications
  • References
  • DBS and safeguarding checks
  • Right to work documentation
  • Payroll and banking details
  • Equality and diversity data (where required)

5.2 Client Data

  • Contact details
  • School safeguarding contacts (e.g., DSLs)
  • Booking and placement records

5.3 Employee Data

  • HR records
  • Payroll and performance information

6. Lawful Basis for Processing

ES Solutions Group Ltd processes personal data under the following lawful bases:

  • Contractual necessity – to provide recruitment services
  • Legal obligation – safeguarding, compliance, DBS checks
  • Legitimate interests – recruitment operations and business improvement
  • Consent – where required (e.g. marketing communications)
  • Vital interests – safeguarding and child protection situations

7. Special Category Data & Criminal Data

Due to the nature of education recruitment:

We process criminal offence data (DBS checks) under legal obligations Special category data is processed only where:

  • Necessary for employment law obligations
  • Required for safeguarding purposes
  • Explicit consent is obtained (where appropriate)

All such data is handled with enhanced security and limited access controls.

8. Data Security Measures

ES Solutions Group Ltd implements appropriate technical and organisational measures:

  • Secure IT systems and encrypted storage
  • Access controls (role-based permissions)
  • Password protection and multi-factor authentication
  • Staff training in data protection
  • Secure document handling and disposal
  • Data breach detection and management procedures

9. Data Sharing

We may share data with:

  • Schools and education clients (for placements)
  • Umbrella/payroll providers
  • DBS and screening providers
  • Regulatory authorities (where required)
  • Law enforcement or safeguarding agencies

All third parties are required to:

  • Comply with GDPR
  • Process data securely
  • Only use data for agreed purposes

10. International Data Transfers

ES Solutions Group Ltd does not transfer data outside the UK unless:

Adequate safeguards are in place (e.g. UK adequacy regulations) Standard contractual clauses are used

11. Data Retention

Data is retained only as long as necessary:

  • Candidate records: typically up to 2 years after last activity
  • Payroll data: 6 years (HMRC requirement)
  • Safeguarding records: in line with legal and safeguarding obligations
  • Data is securely deleted or anonymised when no longer required.

12. Data Subject Rights

Individuals have the right to:

  • Access their data (Subject Access Request – SAR)
  • Rectify inaccurate data
  • Request erasure (where applicable)
  • Restrict processing
  • Object to processing
  • Data portability (where applicable)
  • Requests must be responded to within one calendar month.

13. Data Breach Management

A data breach includes any loss, unauthorised access, or disclosure of data. ES Solutions Group Ltd will:

Investigate all breaches promptly

  • Report notifiable breaches to the Information Commissioner’s Office (ICO) within 72 hours Inform affected individuals where there is a high risk
  • Maintain a breach register

14. Safeguarding & Data Protection

Due to our role in education:

  • Safeguarding information may need to be shared without consent where necessary to protect a child Data protection does not override safeguarding responsibilities
  • All safeguarding data is handled securely and confidentially

15. Responsibilities

15.1 Management

  • Ensure compliance with data protection laws
  • Provide training and oversight
  • Maintain policies and procedures

15.2 Employees

  • Handle data responsibly
  • Follow policies and security protocols
  • Report any data breaches immediately

16. Training and Awareness

All staff receive:

  • Data protection training at induction
  • Regular refresher training
  • Updates on legal and regulatory changes

17. Monitoring and Compliance

ES Solutions Group Ltd:

  • Conducts regular audits
  • Reviews data protection processes
  • Maintains records of processing activities

18. Complaints

If individuals have concerns about how their data is handled:

Contact: ES Solutions Group Ltd
If unresolved, individuals may contact the:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk/

19. Review of Policy

This policy is reviewed:

  • Annually
  • Following legislative changes
  • As part of APSCo compliance reviews

Data Breach Response Procedure

1. Purpose

This procedure outlines how ES Solutions Group Ltd identifies, manages, investigates, and reports personal data breaches in line with:

  • UK GDPR
  • Data Protection Act 2018
  • ICO (Information Commissioner’s Office) requirements APSCo standards

2. Definition of a Data Breach

A personal data breach is:

  • A security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Examples include:

  • Sending candidate data to the wrong recipient
  • Loss or theft of devices containing personal data
  • Unauthorised access to systems
  • Disclosure of DBS/safeguarding information
  • Cyberattacks (phishing, ransomware)

3. Key Roles and Responsibilities

  • Data Protection Lead (DPL)
  • Name: Chris Griffin
  • Email: chris@equitasstaffing.com

Responsible for:

  • Managing breach response
  • Assessing risk
  • Reporting to ICO
  • Maintaining breach records

4. Data Breach Response – Step-by-Step Process

STEP 1: Identify & Report (Immediate)

All staff must:

  • Report any suspected or actual breach immediately (no delay) Notify the Data Protection Lead or senior manager
  • Internal reporting should include:
  • What happened
  • When it occurred
  • Type of data involved
  • Individuals affected

STEP 2: Contain the Breach

Take immediate action to limit impact:

  • Recall or delete wrongly sent emails
  • Disable compromised accounts
  • Recover lost data or devices (if possible)
  • Shut down affected systems if require

STEP 3: Assess the Risk

The Data Protection Lead will assess:

  • Type and sensitivity of data (e.g. DBS, safeguarding data = high risk) Number of individuals affected
  • Potential consequences (identity theft, harm to children, reputational risk) Whether the data is encrypted or protected

Risk Levels:

  • Low risk: unlikely to affect individuals
  • Medium risk: potential inconvenience or minor harm
  • High risk: significant harm (especially safeguarding-related data)

STEP 4: Record the Breach

  • All breaches (even minor ones) must be recorded in a Breach Register, including: Date and time
  • Description of incident
  • Data affected
  • Actions taken
  • Outcome of risk assessment

STEP 5: Decide on ICO Notification

Under UK GDPR:

Report to the ICO within 72 hours if there is a risk to individuals’ rights and freedoms No reporting required if risk is negligible (but must still be recorded)

STEP 6: Notify Affected Individuals (if required)

If the breach is high risk, ES Solutions Group Ltd must inform affected individuals without undue delay.

Notification must include:

  • Description of the breach
  • Likely consequences
  • Actions taken
  • Advice to protect themselves
  • Contact details for further support

STEP 7: External Reporting (Where Applicable)

Depending on the breach, notify:

  • ICO (Information Commissioner’s Office)
  • Client schools (especially where safeguarding data is involved) Local Authority / DSL (if safeguarding risk identified)
  • Police (where criminal activity suspected)\

STEP 8: Investigate the Cause

A full investigation must identify:

  • Root cause (human error, system failure, cyberattack)
  • Process weaknesses
  • Any policy breaches

STEP 9: Implement Corrective Actions

Actions may include:

  • Staff retraining
  • Policy updates
  • System security improvements
  • Disciplinary action (if required)

STEP 10: Review & Learn

  • Review breach handling effectiveness
  • Update procedures if necessary
  • Report findings to senior management
  • Use lessons learned to prevent recurrence

5. Breach Severity Examples (Education Sector)

Severity                                         Example

Low                                                Internal admin error with no data exposure

Medium                                         Email sent to wrong school containing CV

High                                               Disclosure of DBS/safeguarding concerns or child-related data

6. Safeguarding Considerations

Where a breach involves safeguarding data:

  • Treat as high priority
  • Immediately notify:
  • ES Solutions Group Ltd DSL
  • School DSL
  • Follow Safeguarding & Child Protection Policy
  • Data protection must not delay safeguarding action

7. Timeframes Summary

Action                                            Deadline

 Internal reporting                        Immediately

 Containment                                Immediately

 ICO notification                           Within 72 hours

 Notify individuals                         Without undue delay

8. Staff Responsibilities

All staff must:

  • Complete data protection training
  • Follow secure data handling procedures
  • Report breaches immediately
  • Cooperate with investigations

Approved By:

Christian Walshe, Managing Director

Signed date: 1 September 2025

Policy review date: 1 September 2026