Staff whistleblowing privacy notice

This Privacy Notice outlines how Canterbury Christ Church University (the Data Controller) collects, uses, and protects personal data in relation to whistleblowing. It applies to staff who raise a concern under the Whistleblowing Policy.

We are committed to handling your personal data responsibly and transparently, in accordance with the Data Protection Act 2018 and UK General Data Protection Regulations (GDPR) and any other relevant legislation. This notice is intended to ensure you are fully informed about how your personal information is used and the rights you have in relation to it.

You can access our Data Protection Policy here.

1. What personal information do we collect about you?

When you raise a concern by whistleblowing at the University we collect and retain relevant personal data. This information is used for the purposes set out in Section 3 of this Privacy Notice.

We may process the following categories of personal data:

About the person raising the concern:

  • Name

  • Job title

  • School, department, or service

  • Work contact details

  • Confidentiality preferences

  • Correspondence records and meeting notes

  • Any support needs you have disclosed

About the concern being reported:

  • Details of the alleged wrongdoing

  • Dates, times, and locations

  • Evidence provided, such as emails, screenshots, documents, or messages

  • Names or roles of individuals involved

  • Whether the concern relates to fraud, safeguarding, sexual harassment, governance, legal compliance, or health and safety

About individuals implicated in a concern:

  • Name, role, and employment details

  • Information about alleged conduct or wrongdoing

  • Records arising from the investigation, including interview notes and findings

About third parties (for example, witnesses):

  • Names and contact details, where relevant to the investigation

  • Accounts or information provided during an investigation

Some disclosures may involve special category personal data, including data relating to health, racial or ethnic origin, or trade union membership.

Disclosures may also involve safeguarding data, sexual harassment allegations, criminal allegations, or disciplinary matters.

This information is subject to enhanced confidentiality controls and will be processed where permitted by law.

Anonymous reporting

You may raise a concern anonymously. Where you do so, we will not hold identifying information about you, but this may limit our ability to investigate fully or to keep you informed of progress and outcomes.

There may be times when confidentiality cannot be maintained. These include:

  • Legal or regulatory proceedings where disclosure is required by law

  • Safeguarding where there is a risk to someone's health, safety, or wellbeing

  • Criminal investigations where law enforcement requires disclosure

  • Directions from a regulator or other prescribed body

  • Where fairness to another individual requires that they be told of the allegations against them

In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law or would present a risk to others.

2. How do we collect your information?

The University may collect your personal data through a range of methods and sources, depending on your relationship with us and the nature of our interaction. We may collect your personal information:

  • Directly from you – through the online reporting form, emails, meetings or written disclosures.

  • Through automated technologies – from University systems and records relevant to the subject of the concern.

  • From third parties – through the Designated Officers who receive your concern. From witnesses, investigators, auditors or regulators involved in an investigation. From HR, safeguarding, disciplinary or governance processes.

3. How do we use your personal data?

The University may process your personal data for the following purposes:

  • To receive and log disclosures

  • Assess whether concerns fall within the scope of the Policy

  • Investigate alleged wrongdoing

  • Protect staff, students, and others from harm

  • Support fraud prevention and legal compliance

  • Enable safeguarding and health and safety responses

  • Support disciplinary, legal, or regulatory referrals

  • Identify themes, lessons learned, and control improvements

  • Inform governance oversight and the annual Audit Committee report on the operation of the whistleblowing arrangements

We may also create anonymised or pseudonymised management information, trend analysis, and risk assessments from whistleblowing data to improve internal controls and assurance planning. This information does not identify individuals.

4. The lawful basis we use to process your data

Data protection law sets out reasons for collecting and processing your personal data. In this section, we outline the legal bases the University uses.

We will be processing your data under:

  • Article 6(1)(e) Public Task "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller"

We will process your personal data under this legal basis for the purposes of investigation the concern and determining action as well as reporting to the Audit Committee and Governing Body. We may process your personal data when referring matters to external regulators.

  • Article 6(1) (f) Legitimate Interests "processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child" 

    We may process personal data under this legal basis where it is in our interests to do so in order to protect the discloser from detriment.

We may need to process your data in order to ensure we are complying with our statutory obligations and legal requirements.

  • Article 6(1)(c) Legal obligation "processing is necessary for compliance with a legal obligation to which the controller is subject"

We will process your personal data under this legal basis for the purpose of complying with our obligations under the Employment Rights Act 1996. It is also a legal obligation to protect the discloser from detriment and to refer matters to law enforcement where necessary.

Where we process Special Category Data, we will do so under the following legal basis:

  • Article 9(2)(b) Employment, social security and social protection (if authorised by law)

  • Article 9(2)(g) Reasons of substantial public interest (with a basis in law)

We have an Appropriate Policy Document in place which records our processing in relation to Special Category Data and Criminal Offence Data. If you are a member of staff, you may access the document here.

5. Who do we share your personal data with

The University will take all reasonable steps to preserve confidentiality and protect the identity of those raising concerns. Anonymous reports are accepted, though this may limit the University's ability to investigate or provide updates fully.

Sometimes confidentiality cannot be maintained. These include:

  • Legal or regulatory proceedings where disclosure is required by law

  • Safeguarding where there is a risk to someone's health, safety, or wellbeing

  • Criminal investigations where law enforcement requires disclosure

  • Directions from a regulator or other prescribed body

  • Where fairness to another individual requires that they be told of the allegations against them

In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law or would present a risk to others.

We may also share your personal data internally, recipients may include:

  • Designated Officers named in the Policy (Director of Finance, Chief People Officer, University Solicitor, Vice-Chancellor and Principal, or the Chairs of the Governing Body and Audit Committee), according to the concern

  • Other teams within the University such as Governance and Legal Services, People Directorate and Finance

  • Internal Auditors

  • Safeguarding leads

  • Senior officers, where required for governance oversight or escalation

  • Internal investigators appointed to examine the concern

Whoever we share your information with, we will only share what is relevant and necessary to perform the specific task or to meet our legal obligations.

In some circumstances, the University may lawfully limit the information it provides, including to the person who raised a concern, where disclosure would:

  • Prejudice a fraud or criminal investigation

  • Compromise a safeguarding process

  • Breach another individual's confidentiality or right to a fair process

  • Interfere with disciplinary proceedings

  • Undermine legal professional privilege

  • Prejudice against regulatory or law enforcement activity

It means, for example, that a subject access request made by a person implicated in a concern will be reviewed to ensure it does not reveal the identity of the discloser or otherwise compromise the investigation. The University will rely on the appropriate exemptions under the Data Protection Act 2018 where necessary.

Your right to be informed may also be limited where the University has a legal duty not to make you aware of the processing, for example, in connection with the prevention or detection of crime. The University will apply these limitations only to the extent necessary and proportionate.

6. How long do we keep your personal data

We retain personal data only for as long as is necessary to fulfil the purposes set out in this Privacy Notice, including to satisfy legal, regulatory, and contractual obligations. This includes our obligations under the Data Protection Act 2018 and UK GDPR.

In relation to whistleblowing reports and investigations, we normally retain personal data for six years from the conclusion of the matter, in line with the Limitation Act 1980, to allow for resolving any subsequent employment tribunal or legal proceedings. Retention periods may be extended where a matter is subject to ongoing litigation, regulatory scrutiny, or governance review.

When identifiable records are no longer required for the purposes set out in this Privacy Notice, they are either anonymised or securely disposed of according to our Confidential Waste Policy.

7. How do we protect and store your personal information

We are committed to safeguarding the personal data we process and have robust internal policies and controls to prevent unauthorised access, accidental loss, destruction, misuse, or disclosure of personal data. Access to personal information is strictly limited to authorised University personnel who require it for the performance of their duties in connection with whistleblowing reports and investigations.

Where personal data is shared with third-party processors, such parties are contractually required to act solely on our instructions, implement appropriate technical and organisational safeguards, and comply fully with the requirements of the Data Protection Act 2018 and UK GDPR.

8. The data controller and further information

Canterbury Christ Church University is the Data Controller for this personal data.

Please click the link below to access further information regarding:

Version control

Title: Staff Whistleblowing Privacy Notice

Process Owner: University Solicitor & Clerk to the Governing Body

Department responsible: Governance & Legal Services

Date approved: 24 June 2026

Date of review: 24 June 2028

Date last amended: 24 June 2026