University of Oxford positive coronavirus result reporting form: Privacy Notice
In the course of completing and submitting this form you will provide information about yourself or someone else who has given you permission to do so (‘personal data’). We (the University of Oxford) are the ‘data controller’ for this information, which means we decide how to use it and are responsible for looking after it in accordance with the General Data Protection Regulation and associated data protection legislation.
How we use your data
We will use your data to promote health and safety in the University of Oxford and its Colleges by:
- Making sure the appropriate people in your department and/or College are aware of your coronavirus infection so they can:
- support you and provide relevant advice to you during your self isolation
- support and provide advice to others on self-isolation and the need to get tested if they have been in close contact with you for any length of time and could be infectious themselves.
- take measures such as extra deep cleaning to prevent others from becoming infected.
We need to process your data for these purposes to ensure the health and safety of staff and students in the University of Oxford and to protect the wider Oxford Community. This is a task we carry out in the public interest.
Data concerning health is special category data which means that we must meet additional requirements to process it. The additional requirement we meet to process your health data is that the processing is necessary for the purpose of meeting our health and safety obligations to our employees.
We will only use your data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another related reason and that reason is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will seek your consent to use it for that new purpose.
Who has access to your data?
Access to your data within the University will be provided to those who need to view it as part of their work in carrying out the purposes described above and those providing essential IT services to keep it secure and available to those who need to view it. We will minimise the sharing of your personal data and where possible we will consider pseudonymisation or anonymisation to protect your data.
We may also share your data with companies and other organisations who provide services to us. Any other organisation who receives your data are required to take appropriate security measures to protect your data in line with our policies. We do not allow them to use your data for their own purposes. We permit them to process your data only for specified purposes and in accordance with our instructions.
We will share your data with the following organisations for the reasons indicated:
- Your college and/or department (where applicable) and Public Health England to protect your health and wellbeing and to minimise the risk of transmission of COVID-19.
Where we share your data with a third party, we will seek to share the minimum amount necessary.
Retaining your data
We will only retain your data for as long as we need it to meet our purposes, including any relating to legal, accounting, or reporting requirements.
Your data will be held securely in accordance with the University’s policies and procedures. Further information is available on the University’s Information Security website.
Where we store and use your data
We store and use your data on and outside University premises, in both a manual and electronic form.
Automated decision making
No automated processed will be applied to any data you submit using the University of Oxford positive coronavirus result reporting form.
Please click for an explanation of Information on your rights in relation to your personal data.
If you wish to raise any queries or concerns about our use of your data, please contact us at email@example.com.