Student whistleblowing privacy notice

This Privacy Notice outlines how Canterbury Christ Church University (the Data Controller) collects, uses, and protects personal data in relation to whistleblowing. It applies to any students who raise concerns under the Whistleblowing Policy.

We are committed to handling your personal data responsibly and transparently, in accordance with the Data Protection Act 2018 and UK General Data Protection Regulations (GDPR) and any other relevant legislation. This notice is intended to ensure you are fully informed about how your personal information is used and the rights you have in relation to it.

You can access our Data Protection Policy here.

1. What personal information do we collect about you?

When you raise a concern by whistleblowing at the University, we collect and retain relevant personal data. This information is used for the purposes set out in Section 3 of this Privacy Notice.

We may process the following categories of personal data about you:

About the person raising the concern:

  • Name

  • Student ID number, where provided

  • Course, School, or faculty

  • Apprenticeship or placement details, where relevant

  • Partner institution details, where relevant

  • Contact details

  • Confidentiality preferences and whether you wish to remain anonymous

  • Wellbeing or support needs you have disclosed

About the concern:

  • Details of the alleged wrongdoing

  • Dates, times, and locations

  • Details of staff, students, contractors, placement providers, or partner institution staff involved

  • Evidence provided, such as emails, screenshots, documents, messages, or other records

  • Information about whether the issue affects others or raises wider public-interest concerns, including matters relating to student consumer protection, equality, safeguarding, or health and safety

About individuals implicated in a concern:

  • Name, role, and relevant employment or student details

  • Information about alleged conduct or wrongdoing

  • Records arising from the investigation, including interview notes and findings

About third parties (for example, witnesses or supporting students):

  • Names and contact details, where relevant to the investigation

  • Accounts or information provided in the course of an investigation

Some disclosures may involve special category personal data, including data relating to health and wellbeing, racial or ethnic origin, or trade union membership. Disclosures may also involve safeguarding information, sexual harassment or misconduct allegations, equality-related concerns, criminal allegations, or disciplinary matters. This information is handled with enhanced confidentiality and access controls and will be processed where permitted by law.

Anonymous reporting

You may raise a concern anonymously. Where you do so, we will not hold identifying information about you. However, anonymous reports may limit our ability to:

  • Seek clarification or further information from you

  • Gather additional evidence that only you can provide

  • Provide you with updates on the progress or outcome of the investigation

  • Offer you appropriate wellbeing or pastoral support

  • Take steps to protect yourself from any detriment arising from your disclosure

2. How do we collect your information?

The University may collect your personal data through a range of methods and sources, depending on your relationship with us and the nature of our interaction. We may collect your personal information:

  • Directly from you – through the online reporting form, emails, written disclosures or meetings.

  • Through automated technologies – from University systems and records relevant to the subject of the concern. 

  • From third parties – from witnesses or other students supporting the concern, from placement, apprenticeship or work based learning records or from partner institution liaison teams. From safeguarding, student wellbeing, complaints or student conduct teams. From investigators, auditors or regulators involved in the investigation.

3. How do we use your personal data?

The University may process your personal data for the following purposes:

  • To receive and log concerns

  • Assess whether the concern falls within the scope of the Whistleblowing Policy

  • Investigate suspected wrongdoing

  • Protect students, staff, and others from harm

  • Support safeguarding, student wellbeing, and health and safety interventions

  • Support fraud prevention and legal compliance

  • Fulfil student consumer protection and student protection obligations, including concerns about the accuracy of information provided about courses, teaching, assessment, or services

  • Refer matters to student complaints, conduct, or other University procedures where appropriate

  • Identify themes, trends, and systemic risks

  • Inform governance oversight and improve internal controls and student protection arrangements

We may also produce anonymised or pseudonymised trend analysis, assurance reporting, and risk theme summaries from whistleblowing data to improve student protection and institutional oversight. This information does not identify individuals.

4. The lawful basis we use to process your data

Data protection law sets out reasons for collecting and processing your personal data. In this section, we outline the legal bases the University uses.

We will be processing your data under:

  • Article 6(1)(e) Public Task "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller"

We will process your personal data under this legal basis for the purposes of investigation the concern and determining action as well as reporting to the Audit Committee and Governing Body. We may process your personal data when referring matters to external regulators.

  • Article 6(1) (f) Legitimate Interests "processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child"

We may process personal data under this legal basis where it is in our interests to do so in order to protect the discloser from detriment.

We may need to process your data in order to ensure we are complying with our statutory obligations and legal requirements.

  • Article 6(1)(c) Legal obligation "processing is necessary for compliance with a legal obligation to which the controller is subject"

We will process your personal data under this legal basis for the purpose of complaying with our obligations relating to student consumer protection, or in order to refer matters to external regulators or law enforcement agencies.

Where we process Special Category Data, we will do so under the following legal basis:

  • Article 9(2)(b) Employment, social security and social protection (if authorised by law)

  • Article 9(2)(g) Reasons of substantial public interest (with a basis in law)

We have an Appropriate Policy Document in place which records our processing in relation to Special Category Data and Criminal Offence Data. If you are a student, you may access the document here.

5. Who do we share your personal data with

The University will take all reasonable steps to protect your identity and preserve confidentiality throughout the process of receiving and investigating your concern. Anonymous reports are accepted, though this may limit the University's ability to investigate fully, provide updates, offer support, or protect you from any detriment.

Sometimes confidentiality cannot be maintained. These circumstances include:

  • Where safeguarding action is required because of a risk to someone's health, safety, or wellbeing

  • Where fairness to another individual requires that they be told of the allegations against them

  • Where legal or regulatory proceedings arise, and disclosure is required by law

  • Where a criminal investigation requires disclosure to law enforcement

  • Where a regulator or other prescribed body directs the University to disclose

In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law.

We may also share your personal data internally, recipients may include: 

  • Other departments at the University such as Governance and Legal Services, Student Wellbeing and Support, placement or apprenticeship teams, the Student Governance team, or academic schools

  • Safeguarding leads

  • Partner institution relationship managers, where the concern relates to the provision delivered through a partner institution

  • Senior officers, where required for escalation or governance oversight

  • Internal investigators appointed to examine the concern

Whoever we share your information with, we will only share what is relevant and necessary to perform the specific task or to meet our legal obligations.

In some circumstances, the University may lawfully limit the information it provides, including to the person who raised a concern, where disclosure would:

  • Prejudice a fraud or criminal investigation

  • Compromise a safeguarding or student protection process

  • Breach another student's or individual's confidentiality or right to a fair process

  • Interfere with complaints, conduct, or disciplinary proceedings

  • Undermine legal professional privilege

  • Prejudice against regulatory or law enforcement activity

It means, for example, that a subject access request made by a person implicated in a concern will be reviewed carefully to ensure it does not reveal the identity of the student who raised the concern or otherwise compromise the investigation. The University will rely on the appropriate exemptions under the Data Protection Act 2018 where necessary.

Your right to be informed may also be limited where the University has a legal duty not to make you aware of the processing, for example, in connection with the prevention or detection of crime. The University will apply these limitations only to the extent necessary and proportionate.

6. How long do we keep your personal data

We retain personal data only for as long as is necessary to fulfil the purposes set out in this Privacy Notice, including to satisfy legal, regulatory, and contractual obligations. This includes our obligations under the Data Protection Act 2018 and UK GDPR.

In relation to whistleblowing reports and investigations, we normally retain personal data for six years from the conclusion of the matter, in line with the Limitation Act 1980,to allow for resolving any subsequent employment tribunal or legal proceedings. Retention periods may be extended where a matter is subject to ongoing litigation, regulatory scrutiny, or governance review.

When identifiable records are no longer required for the purposes set out in this Privacy Notice, they are either anonymised or securely disposed of according to our Confidential Waste Policy.

7. How do we protect and store your personal information

We are committed to safeguarding the personal data we process and have robust internal policies and controls to prevent unauthorised access, accidental loss, destruction, misuse, or disclosure of personal data. Access to personal information is strictly limited to authorised University personnel who require it for the performance of their duties in connection with whistleblowing.

Where personal data is shared with third-party processors, such parties are contractually required to act solely on our instructions, implement appropriate technical and organisational safeguards, and comply fully with the requirements of the Data Protection Act 2018 and UK GDPR.

8. The data controller and further information

Canterbury Christ Church University is the Data Controller for this personal data.

Please click the link below to access further information regarding:

Version control

Title: Student Whistleblowing Privacy Notice

Process Owner: University Solicitor & Clerk to the Governing Body

Department responsible: Governance & Legal Services

Date approved: 24 June 2026

Date of review: 24 June 2028

Date last amended: 24 June 2026