This Privacy Notice outlines how Canterbury Christ Church University (the Data Controller) collects, uses, and protects personal data in relation to whistleblowing. It applies to staff who raise a concern under the Whistleblowing Policy.
We are committed to handling your personal data responsibly and transparently, in accordance with the Data Protection Act 2018 and UK General Data Protection Regulations (GDPR) and any other relevant legislation. This notice is intended to ensure you are fully informed about how your personal information is used and the rights you have in relation to it.
You can access our Data Protection Policy here.
When you raise a concern by whistleblowing at the University we collect and retain relevant personal data. This information is used for the purposes set out in Section 3 of this Privacy Notice.
We may process the following categories of personal data:
About the person raising the concern:
Name
Job title
School, department, or service
Work contact details
Confidentiality preferences
Correspondence records and meeting notes
Any support needs you have disclosed
About the concern being reported:
Details of the alleged wrongdoing
Dates, times, and locations
Evidence provided, such as emails, screenshots, documents, or messages
Names or roles of individuals involved
Whether the concern relates to fraud, safeguarding, sexual harassment, governance, legal compliance, or health and safety
About individuals implicated in a concern:
Name, role, and employment details
Information about alleged conduct or wrongdoing
Records arising from the investigation, including interview notes and findings
About third parties (for example, witnesses):
Names and contact details, where relevant to the investigation
Accounts or information provided during an investigation
Some disclosures may involve special category personal data, including data relating to health, racial or ethnic origin, or trade union membership.
Disclosures may also involve safeguarding data, sexual harassment allegations, criminal allegations, or disciplinary matters.
This information is subject to enhanced confidentiality controls and will be processed where permitted by law.
You may raise a concern anonymously. Where you do so, we will not hold identifying information about you, but this may limit our ability to investigate fully or to keep you informed of progress and outcomes.
There may be times when confidentiality cannot be maintained. These include:
Legal or regulatory proceedings where disclosure is required by law
Safeguarding where there is a risk to someone's health, safety, or wellbeing
Criminal investigations where law enforcement requires disclosure
Directions from a regulator or other prescribed body
Where fairness to another individual requires that they be told of the allegations against them
In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law or would present a risk to others.
The University may collect your personal data through a range of methods and sources, depending on your relationship with us and the nature of our interaction. We may collect your personal information:
Directly from you – through the online reporting form, emails, meetings or written disclosures.
Through automated technologies – from University systems and records relevant to the subject of the concern.
From third parties – through the Designated Officers who receive your concern. From witnesses, investigators, auditors or regulators involved in an investigation. From HR, safeguarding, disciplinary or governance processes.
The University may process your personal data for the following purposes:
To receive and log disclosures
Assess whether concerns fall within the scope of the Policy
Investigate alleged wrongdoing
Protect staff, students, and others from harm
Support fraud prevention and legal compliance
Enable safeguarding and health and safety responses
Support disciplinary, legal, or regulatory referrals
Identify themes, lessons learned, and control improvements
Inform governance oversight and the annual Audit Committee report on the operation of the whistleblowing arrangements
We may also create anonymised or pseudonymised management information, trend analysis, and risk assessments from whistleblowing data to improve internal controls and assurance planning. This information does not identify individuals.
Data protection law sets out reasons for collecting and processing your personal data. In this section, we outline the legal bases the University uses.
We will be processing your data under:
Article 6(1)(e) Public Task "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller"
We will process your personal data under this legal basis for the purposes of investigation the concern and determining action as well as reporting to the Audit Committee and Governing Body. We may process your personal data when referring matters to external regulators.
Article 6(1) (f) Legitimate Interests "processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child"
We may process personal data under this legal basis where it is in our interests to do so in order to protect the discloser from detriment.
We may need to process your data in order to ensure we are complying with our statutory obligations and legal requirements.
Article 6(1)(c) Legal obligation "processing is necessary for compliance with a legal obligation to which the controller is subject"
We will process your personal data under this legal basis for the purpose of complying with our obligations under the Employment Rights Act 1996. It is also a legal obligation to protect the discloser from detriment and to refer matters to law enforcement where necessary.
Where we process Special Category Data, we will do so under the following legal basis:
Article 9(2)(b) Employment, social security and social protection (if authorised by law)
Article 9(2)(g) Reasons of substantial public interest (with a basis in law)
We have an Appropriate Policy Document in place which records our processing in relation to Special Category Data and Criminal Offence Data. If you are a member of staff, you may access the document here.
The University will take all reasonable steps to preserve confidentiality and protect the identity of those raising concerns. Anonymous reports are accepted, though this may limit the University's ability to investigate or provide updates fully.
Sometimes confidentiality cannot be maintained. These include:
Legal or regulatory proceedings where disclosure is required by law
Safeguarding where there is a risk to someone's health, safety, or wellbeing
Criminal investigations where law enforcement requires disclosure
Directions from a regulator or other prescribed body
Where fairness to another individual requires that they be told of the allegations against them
In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law or would present a risk to others.
We may also share your personal data internally, recipients may include:
Designated Officers named in the Policy (Director of Finance, Chief People Officer, University Solicitor, Vice-Chancellor and Principal, or the Chairs of the Governing Body and Audit Committee), according to the concern
Other teams within the University such as Governance and Legal Services, People Directorate and Finance
Internal Auditors
Safeguarding leads
Senior officers, where required for governance oversight or escalation
Internal investigators appointed to examine the concern
Whoever we share your information with, we will only share what is relevant and necessary to perform the specific task or to meet our legal obligations.
In some circumstances, the University may lawfully limit the information it provides, including to the person who raised a concern, where disclosure would:
Prejudice a fraud or criminal investigation
Compromise a safeguarding process
Breach another individual's confidentiality or right to a fair process
Interfere with disciplinary proceedings
Undermine legal professional privilege
Prejudice against regulatory or law enforcement activity
It means, for example, that a subject access request made by a person implicated in a concern will be reviewed to ensure it does not reveal the identity of the discloser or otherwise compromise the investigation. The University will rely on the appropriate exemptions under the Data Protection Act 2018 where necessary.
Your right to be informed may also be limited where the University has a legal duty not to make you aware of the processing, for example, in connection with the prevention or detection of crime. The University will apply these limitations only to the extent necessary and proportionate.
We retain personal data only for as long as is necessary to fulfil the purposes set out in this Privacy Notice, including to satisfy legal, regulatory, and contractual obligations. This includes our obligations under the Data Protection Act 2018 and UK GDPR.
In relation to whistleblowing reports and investigations, we normally retain personal data for six years from the conclusion of the matter, in line with the Limitation Act 1980, to allow for resolving any subsequent employment tribunal or legal proceedings. Retention periods may be extended where a matter is subject to ongoing litigation, regulatory scrutiny, or governance review.
When identifiable records are no longer required for the purposes set out in this Privacy Notice, they are either anonymised or securely disposed of according to our Confidential Waste Policy.
We are committed to safeguarding the personal data we process and have robust internal policies and controls to prevent unauthorised access, accidental loss, destruction, misuse, or disclosure of personal data. Access to personal information is strictly limited to authorised University personnel who require it for the performance of their duties in connection with whistleblowing reports and investigations.
Where personal data is shared with third-party processors, such parties are contractually required to act solely on our instructions, implement appropriate technical and organisational safeguards, and comply fully with the requirements of the Data Protection Act 2018 and UK GDPR.
Canterbury Christ Church University is the Data Controller for this personal data.
Please click the link below to access further information regarding:
Title: Staff Whistleblowing Privacy Notice
Process Owner: University Solicitor & Clerk to the Governing Body
Department responsible: Governance & Legal Services
Date approved: 24 June 2026
Date of review: 24 June 2028
Date last amended: 24 June 2026