General Privacy Notice
Introduction
This General Privacy Notice explains how University of Suffolk collects, uses, stores and shares personal data about individuals who interact with the University and who are not covered by our separate privacy notices for staff, students or alumni. This includes third parties, contractors, suppliers, research participants, members of the public, visitors and users of our services, systems, websites and premises.
We are committed to handling personal data lawfully, fairly and transparently, and this notice is designed to help you understand what personal data we process, why we use it, the lawful bases we rely on, who we share it with, how long we keep it, and the rights you have under data protection law.
The University of Suffolk is an institution dedicated to transformation - transforming individuals, our community, our region and beyond. Education, training and research are powerful tools to support transformation and change and to fulfil these obligations the University collects, stores, processes and shares personal data.
This privacy notice makes you aware of how and why your personal data will be used and how long it will usually be retained for. The University of Suffolk is a "data controller". This means that we are responsible for deciding how we hold and use personal information about you.
Personal data, or personal information, means any information about an individual from which that person can be identified. To communicate with you, to provide you with services or information, we may collect, use, store and transfer different kinds of personal data about you. Depending on your relationship with the University of Suffolk, this may include:
· Personal details (such as your name, contact details and email address) that you provide by contacting us, requesting information or submitting your information via the website.
· Personal details (such as names, titles and business contact information including addresses, telephone numbers and email addresses) for the employees and representatives of our suppliers and partners
· Your responses to surveys which we ask you to complete for research purposes.
· Any other information you post, email or otherwise send to us.
· How you use the website and where available, your IP address, operating system and browser type.
In some cases you may choose to provide information which we have not asked for. Where this is the case, this personal data will be handled with the same care as any other personal data we process and in accordance with data protection legislation as laid out in this notice.
We will also collect personal information about website usage through cookies in accordance with our Cookie Information.
Special category and criminal offence data
Some personal data needs extra protection under data protection law. We may process special category data. We may also process criminal offence information where required for safeguarding, security, regulatory obligations or other lawful purposes relevant to the activity involved.
Where we process this type of information, we will identify both a lawful basis and a separate condition under UK GDPR. We will only use this information where it is necessary and proportionate, and we will apply appropriate safeguards.
How we collect personal data
We collect personal data directly from you when you attend events, use our services, contact us, visit our premises, take part in research, submit forms, work with us as an external party or use our systems. We may also collect personal data from third parties, including employers, referees, professional bodies, partner institutions, funding bodies, government departments, sponsors, suppliers, regulatory bodies, law enforcement agencies and publicly available sources.
We must have a lawful basis for each purpose for which we use personal data. The lawful bases most commonly relied on by the University in this notice are contract, legal obligation, public task, legitimate interests, consent and vital interests. Where we rely on consent, you can withdraw that consent at any time, although this will not affect processing already carried out before withdrawal.
|
Purpose |
Examples of personal data used |
Likely lawful basis |
|
Research, innovation and knowledge exchange |
Participant information, consent records, research data, ethics records, project communications and outputs |
Public task, legitimate interests, consent where appropriate, and research conditions for special category data |
|
Security, safety and access management |
ID cards, access logs, CCTV, incident records, IT information and building access information |
Legal obligation, legitimate interests, public task and vital interests where necessary |
|
Finance, funding, audit and compliance |
Payment records, invoices, bank details, funding arrangements, audit records and regulatory returns |
Contract, legal obligation, public task and legitimate interests |
|
Complaints, appeals, conduct, legal claims and governance |
Case records, correspondence, investigation information, evidence, decisions and outcomes |
Legal obligation, public task, legitimate interests and legal claims conditions where relevant |
|
Assisting with enquiries or requests |
Name, email address |
Performance of a contract, public task, lawful interest |
|
Managing the relationship with our suppliers and partners |
Names, titles and business contact information including addresses, telephone numbers and email addresses |
Performance of a contract, legitimate interests (necessary to ensure our suppliers and partners carry out their tasks appropriately) |
We only share personal data where there is a lawful basis, and it is necessary and proportionate to do so. Depending on the circumstances, we may share personal data with:
- academic schools, professional services, committees and authorised staff within the University;
- partner institutions, placement providers, employers, sponsors, funding bodies and professional or regulatory bodies where relevant to the activity involved;
- public authorities and statutory bodies, including higher education regulators, government departments, local authorities, law enforcement agencies and courts;
- service providers and processors who support our systems, teaching, assessment, accommodation, IT, finance, communications, events, security, surveys, research and administration;
- affiliated organisations and event partners where necessary and lawful;
- emergency services, safeguarding organisations, healthcare providers;
- auditors, insurers, legal advisers and other professional advisers.
We may also receive requests from third parties with authority to obtain disclosure of personal data. We will only fulfil such requests where we are permitted to do so in accordance with applicable law or regulation.
We may use third party providers to deliver our services, such as externally hosted software or cloud providers, and those providers may involve transfers of personal data outside of the UK. Whenever we do this, to ensure that your personal data is treated by those third parties securely and in a way that is consistent with UK data protection law, we require such third parties to agree to put in place safeguards. This may include specific contracts approved for use in the UK which give personal data the same protection it has in the UK or other equivalent measures as required.
We retain personal data only for as long as it is necessary to fulfil the purposes for which it was collected or to comply with legal or regulatory requirements. Each School and Professional Service area of the Institution holds a Data Retention Schedule which specifies the nature of the data retained, the retention period, the reason for retention, and the action to be taken at the end of the retention period, including how the data are to be disposed of.
Generally, information you provide to us is stored on our secure servers, or on our cloud-based systems. These are located within the UK or in countries/areas which are considered to have adequate privacy and information security provisions, such as the European Economic Area (EEA). However, there are times when we will need to store information outside these locations to fulfil our purposes and where we do, we will carry out transfer risk assessments to ensure that appropriate security measures are taken to protect your privacy rights. This may mean imposing contractual obligations on the recipient of your personal information where no other relevant safeguards exist. Technical measures such as encryption will also be considered.
The University is required under data protection legislation to keep your information secure, and measures are in place to prevent unauthorised access and disclosure of your information. Only relevant members of staff who require access to your records will be authorised to do so. Systems and electronic files are subject to password restrictions and other security measures. Any paper files will be stored in secure areas with controlled access.
Some processing of your information may be undertaken on the University’s behalf by third party organisations. Organisations processing personal data on the University’s behalf are also bound by the GDPR and the University has sought assurances from these organisations to ensure they are aware of their obligations under the GDPR and resulting legislation.
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction. These measures include encryption, secure access controls, and regular monitoring of our IT systems.
Use of Artificial Intelligence (AI) in Minerva:
The University of Suffolk uses artificial intelligence (AI) within its Minerva service platform to support staff and student queries.
What this means
- You may interact with an AI-powered assistant when using Minerva
- The AI will only use University-approved knowledge base information
Your data
- Your personal data does not leave the University’s Minerva system
- Data is not shared with external AI providers
- Data is not used to train external AI models
- Confidential or sensitive enquiries are excluded from AI processing
Transparency
- You will always be informed when you are interacting with AI
- You may choose alternative support routes if you prefer
Safeguards
- The AI does not make decisions affecting you
- Staff review and validate outputs before action is taken
- If the AI cannot assist, or if your query relates to wellbeing or urgent support, it will direct you to appropriate human support services already identified on the safeguarding pages.
Your rights
- You retain all rights under UK GDPR, including access to your data and how it is used
- For queries relating to data use, please contact Data Governance
Under the UK GDPR, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your data where it is no longer necessary or where you have withdrawn consent. This right is not absolute and in many cases it will not apply. For example, we must retain a ‘core student record’ for every person who has studied at the University of Suffolk.
- Right to Restrict Processing: You can ask us to restrict how we use your data in certain circumstances.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used format.
- Right to Object: You can object to the processing of your data, including for direct marketing purposes.
If you wish to exercise any of these rights, please contact the Data Governance team on datagovernance@uos.ac.uk.
Updates to this Privacy Notice
This notice was updated in August 2026.
We may update this privacy notice from time to time in response to legal, regulatory, or operational requirements.
Contact Us
If you have any questions about this privacy notice or how your data is processed, please contact:
Data Governance and Legal Services Team
Address: University of Suffolk, Waterfront Building, Neptune Quay, Ipswich, IP41QJ
Email: datagovernance@uos.ac.uk
Phone: 01473 338240
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you have any concerns about your Data Protection Rights.
This is a general notice for individuals who are not covered by one of our separate privacy notices. Staff, students and alumni should refer to the relevant privacy notice for their relationship with the University. We may also provide more detailed or specific privacy notices for particular services or activities, such as CCTV or cookies. Those notices should be read alongside this General Privacy Notice where relevant.
Our website contains links to and from the websites of third parties. This privacy notice applies to the University of Suffolk website only so if you follow a link to other websites please note that these websites will have their own privacy policies and that we do not accept responsibility or liability for these policies. Please check these policies before you submit any personal data to these third-party websites.