This Privacy Notice outlines how Canterbury Christ Church University (the Data Controller) collects, uses, and protects personal data in relation to whistleblowing. It applies to any students who raise concerns under the Whistleblowing Policy.
We are committed to handling your personal data responsibly and transparently, in accordance with the Data Protection Act 2018 and UK General Data Protection Regulations (GDPR) and any other relevant legislation. This notice is intended to ensure you are fully informed about how your personal information is used and the rights you have in relation to it.
You can access our Data Protection Policy here.
When you raise a concern by whistleblowing at the University, we collect and retain relevant personal data. This information is used for the purposes set out in Section 3 of this Privacy Notice.
We may process the following categories of personal data about you:
About the person raising the concern:
Name
Student ID number, where provided
Course, School, or faculty
Apprenticeship or placement details, where relevant
Partner institution details, where relevant
Contact details
Confidentiality preferences and whether you wish to remain anonymous
Wellbeing or support needs you have disclosed
About the concern:
Details of the alleged wrongdoing
Dates, times, and locations
Details of staff, students, contractors, placement providers, or partner institution staff involved
Evidence provided, such as emails, screenshots, documents, messages, or other records
Information about whether the issue affects others or raises wider public-interest concerns, including matters relating to student consumer protection, equality, safeguarding, or health and safety
About individuals implicated in a concern:
Name, role, and relevant employment or student details
Information about alleged conduct or wrongdoing
Records arising from the investigation, including interview notes and findings
About third parties (for example, witnesses or supporting students):
Names and contact details, where relevant to the investigation
Accounts or information provided in the course of an investigation
Some disclosures may involve special category personal data, including data relating to health and wellbeing, racial or ethnic origin, or trade union membership. Disclosures may also involve safeguarding information, sexual harassment or misconduct allegations, equality-related concerns, criminal allegations, or disciplinary matters. This information is handled with enhanced confidentiality and access controls and will be processed where permitted by law.
You may raise a concern anonymously. Where you do so, we will not hold identifying information about you. However, anonymous reports may limit our ability to:
Seek clarification or further information from you
Gather additional evidence that only you can provide
Provide you with updates on the progress or outcome of the investigation
Offer you appropriate wellbeing or pastoral support
Take steps to protect yourself from any detriment arising from your disclosure
The University may collect your personal data through a range of methods and sources, depending on your relationship with us and the nature of our interaction. We may collect your personal information:
Directly from you – through the online reporting form, emails, written disclosures or meetings.
Through automated technologies – from University systems and records relevant to the subject of the concern.
From third parties – from witnesses or other students supporting the concern, from placement, apprenticeship or work based learning records or from partner institution liaison teams. From safeguarding, student wellbeing, complaints or student conduct teams. From investigators, auditors or regulators involved in the investigation.
The University may process your personal data for the following purposes:
To receive and log concerns
Assess whether the concern falls within the scope of the Whistleblowing Policy
Investigate suspected wrongdoing
Protect students, staff, and others from harm
Support safeguarding, student wellbeing, and health and safety interventions
Support fraud prevention and legal compliance
Fulfil student consumer protection and student protection obligations, including concerns about the accuracy of information provided about courses, teaching, assessment, or services
Refer matters to student complaints, conduct, or other University procedures where appropriate
Identify themes, trends, and systemic risks
Inform governance oversight and improve internal controls and student protection arrangements
We may also produce anonymised or pseudonymised trend analysis, assurance reporting, and risk theme summaries from whistleblowing data to improve student protection and institutional oversight. This information does not identify individuals.
Data protection law sets out reasons for collecting and processing your personal data. In this section, we outline the legal bases the University uses.
We will be processing your data under:
Article 6(1)(e) Public Task "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller"
We will process your personal data under this legal basis for the purposes of investigation the concern and determining action as well as reporting to the Audit Committee and Governing Body. We may process your personal data when referring matters to external regulators.
Article 6(1) (f) Legitimate Interests "processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child"
We may process personal data under this legal basis where it is in our interests to do so in order to protect the discloser from detriment.
We may need to process your data in order to ensure we are complying with our statutory obligations and legal requirements.
Article 6(1)(c) Legal obligation "processing is necessary for compliance with a legal obligation to which the controller is subject"
We will process your personal data under this legal basis for the purpose of complaying with our obligations relating to student consumer protection, or in order to refer matters to external regulators or law enforcement agencies.
Where we process Special Category Data, we will do so under the following legal basis:
Article 9(2)(b) Employment, social security and social protection (if authorised by law)
Article 9(2)(g) Reasons of substantial public interest (with a basis in law)
We have an Appropriate Policy Document in place which records our processing in relation to Special Category Data and Criminal Offence Data. If you are a student, you may access the document here.
The University will take all reasonable steps to protect your identity and preserve confidentiality throughout the process of receiving and investigating your concern. Anonymous reports are accepted, though this may limit the University's ability to investigate fully, provide updates, offer support, or protect you from any detriment.
Sometimes confidentiality cannot be maintained. These circumstances include:
Where safeguarding action is required because of a risk to someone's health, safety, or wellbeing
Where fairness to another individual requires that they be told of the allegations against them
Where legal or regulatory proceedings arise, and disclosure is required by law
Where a criminal investigation requires disclosure to law enforcement
Where a regulator or other prescribed body directs the University to disclose
In each of these situations, the University will inform you that confidentiality cannot be maintained unless doing so is prevented by law.
We may also share your personal data internally, recipients may include:
Other departments at the University such as Governance and Legal Services, Student Wellbeing and Support, placement or apprenticeship teams, the Student Governance team, or academic schools
Safeguarding leads
Partner institution relationship managers, where the concern relates to the provision delivered through a partner institution
Senior officers, where required for escalation or governance oversight
Internal investigators appointed to examine the concern
Whoever we share your information with, we will only share what is relevant and necessary to perform the specific task or to meet our legal obligations.
In some circumstances, the University may lawfully limit the information it provides, including to the person who raised a concern, where disclosure would:
Prejudice a fraud or criminal investigation
Compromise a safeguarding or student protection process
Breach another student's or individual's confidentiality or right to a fair process
Interfere with complaints, conduct, or disciplinary proceedings
Undermine legal professional privilege
Prejudice against regulatory or law enforcement activity
It means, for example, that a subject access request made by a person implicated in a concern will be reviewed carefully to ensure it does not reveal the identity of the student who raised the concern or otherwise compromise the investigation. The University will rely on the appropriate exemptions under the Data Protection Act 2018 where necessary.
Your right to be informed may also be limited where the University has a legal duty not to make you aware of the processing, for example, in connection with the prevention or detection of crime. The University will apply these limitations only to the extent necessary and proportionate.
We retain personal data only for as long as is necessary to fulfil the purposes set out in this Privacy Notice, including to satisfy legal, regulatory, and contractual obligations. This includes our obligations under the Data Protection Act 2018 and UK GDPR.
In relation to whistleblowing reports and investigations, we normally retain personal data for six years from the conclusion of the matter, in line with the Limitation Act 1980,to allow for resolving any subsequent employment tribunal or legal proceedings. Retention periods may be extended where a matter is subject to ongoing litigation, regulatory scrutiny, or governance review.
When identifiable records are no longer required for the purposes set out in this Privacy Notice, they are either anonymised or securely disposed of according to our Confidential Waste Policy.
We are committed to safeguarding the personal data we process and have robust internal policies and controls to prevent unauthorised access, accidental loss, destruction, misuse, or disclosure of personal data. Access to personal information is strictly limited to authorised University personnel who require it for the performance of their duties in connection with whistleblowing.
Where personal data is shared with third-party processors, such parties are contractually required to act solely on our instructions, implement appropriate technical and organisational safeguards, and comply fully with the requirements of the Data Protection Act 2018 and UK GDPR.
Canterbury Christ Church University is the Data Controller for this personal data.
Please click the link below to access further information regarding:
Title: Student Whistleblowing Privacy Notice
Process Owner: University Solicitor & Clerk to the Governing Body
Department responsible: Governance & Legal Services
Date approved: 24 June 2026
Date of review: 24 June 2028
Date last amended: 24 June 2026