Research Privacy Notice

Research Privacy Notice

This Privacy Notice outlines how Canterbury Christ Church University (the Data Controller) collects, uses, and protects personal data in relation to research projects. It applies to participants of research projects performed at, or on behalf of, Canterbury Christ Church University, where the University controls that personal data.

We are committed to handling your personal data responsibly and transparently, in accordance with the Data Protection Act 2018 and UK General Data Protection Regulations (GDPR) and any other relevant legislation. This notice is intended to ensure you are fully informed about how your personal information is used and the rights you have in relation to it.

You can access our Data Protection Policy here.

1. What personal information do we collect about you?

When you engage with the University in relation to a research project, we collect and retain relevant personal data. This information is used for the purposes set out in Section 3 of this Privacy Notice.

The type of personal information collected and used depends on the research project. The Participation Sheet will set out the data the researchers intend to collect.

As unnecessary or unrelated personal data is not processed for research purposes, we require all research projects to pass a Public Interest test embedded in our research ethics process.

The public interest test for research aims to justify:

  • why the same aims pursued by the research cannot be achieved using non-personal data (i.e. anonymised personal data);

  • why collection and processing of the identified personal data is needed to ensure advancement in the particular field the research relates to; and

  • that the purposes of the research can be fulfilled whilst complying with technical and organisational safeguards, including pseudonymisation, and to ensure, in particular, the principle of data minimisation.

Our researchers will include the above information clearly within the Participant Information Sheet concerning the specific research project.

For some kinds of research, our researchers may process some data about you that is ‘sensitive’ and requires further protection.

Sensitive Data includes ‘special category’ data,’ e.g. information concerning

  • your religious beliefs

  • sexual orientation

  • ethnicity

  • gender identity; or

  • health.

It may also include criminal conviction data.

The processing of such data is carefully controlled, and an appropriate internal or external ethics committee will approve the arrangements. You will receive explicit information about this in your Participant Information Sheet.

2. How do we collect your information?

The University may collect your personal data through a range of methods and sources, depending on your relationship with us and the nature of our interaction. We may collect your personal information:

  • Directly from you – when you fill in forms and questionnaires or take part in interviews or activities related to the research project.

The specifics of how your personal data will be collected will be detailed in the Participant Information Sheet.

3. How do we use your personal data?

The University may process your personal data for the following purposes:

  • To enable researchers to meet the objectives of their research.

  • To meet the requirements set out by research funders.

  • To comply with statutory and regulatory requirements, including those under the Data Protection Act 2018, UK GDPR and other relevant legislation.

  • We aim to conduct research following the highest standards of research integrity. We have policies and procedures in place to ensure we comply with regulations that govern the conduct of research, including data protection and research ethics.

We respect the confidentiality of personal data relating to research participants, whether provided to us directly or obtained from other organisations. We will not use your data in a way that you would not reasonably expect. In the Participation Information Sheet, our researchers will explain how they collect and intend to use your data. The researchers will use your data only for the research you are participating in and will not usually use your data or contact you for any purpose other than research unless you agree. The Participation Information Sheet and/or Consent Form will make this clear.

Where possible, our researchers will anonymise, pseudonymise (by removing identifiers such as your name and using a unique code) or delete collected personal data as soon as possible. They may provide further information in the Participation Information Sheet.

4. The lawful basis we use to process your data

Data protection law sets out reasons for collecting and processing your personal data. In this section, we outline the legal bases the University uses. In cases where the legal bases differ this will be clearly stated within the Participant Information Sheet.

We will be processing your data under:

  • Article 6(1)(e) Public Task "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller"

Where we process Special Category Data, we will do so under the following legal basis:

  • Article 9(2)(j) Archiving, research and statistics (with a basis in law)

5. Who do we share your personal data with?

We may share your personal data with trusted third-party service providers who act as data processors on our behalf. These partners are researchers at other institutions, Qualtrics and Pure Elsevier who support with the administration and operation of the research project, such as providing a platform for researchers to collate data or by analysing data on our researchers behalf. All third parties are required to handle your data securely and in accordance with data protection legislation.

Details relating to who your data will be shared with for the research project you are participating in will be provided in the Participant Information Sheet.

We may also disclose your personal data where necessary to meet our legal or statutory obligations under the Data Protection Act 2018 and UK GDPR. This may include sharing information with government departments, regulatory bodies, funding agencies, or law enforcement authorities where disclosure is legally required.

Whoever we share your information with, we will only share what is relevant and necessary to perform the specific task or to meet our legal obligations.

6. How long do we keep your personal data?

We retain personal data only for as long as is necessary to fulfil the purposes set out in this Privacy Notice, including to satisfy legal, regulatory, and contractual obligations. This includes our obligations under the Data Protection Act 2018 and UK GDPR.

In relation to data collected for the purposes of research, identifiable data will be stored for no longer than the minimum period of time the data is needed after all activities related to the research are concluded. The Participant Information Sheet provided to you before you agree to take part in any Canterbury Christ Church University research project, will state how long your data will be held after the completion of the project. After this time, we will destroy your data securely.

When identifiable records are no longer required for the purposes set out in this Privacy Notice, they are either anonymised or securely disposed of according to our Confidential Waste Policy.

7. How do we protect and store your personal information?

We are committed to safeguarding the personal data we process and have robust internal policies and controls to prevent unauthorised access, accidental loss, destruction, misuse, or disclosure of personal data. Access to personal information is strictly limited to authorised University personnel who require it for the performance of their duties in connection with the relevant research project.

Where personal data is shared with third-party processors, such parties are contractually required to act solely on our instructions, implement appropriate technical and organisational safeguards, and comply fully with the requirements of the Data Protection Act 2018 and UK GDPR.

8. The data controller and further information

Canterbury Christ Church University is the Data Controller for this personal data.

Please click the link below to access further information regarding:

Version control

Title: Research Privacy Notice

Process Owner: Director of Research, Enterprise & Innovation Services

Department responsible: Research, Enterprise & Innovation Services

Date approved: 20th August 2026

Date of review: 20th August 2028

Date last amended: 20th August 2026