Risk Assessment Procedure - Privacy Notice
This notice was last updated on 4 June 2026
Risk Assessment Procedure - Privacy Notice
This privacy notice tells you what to expect us (the University of South Wales) to do with your personal data when you:
- Are subject of a case under the University’s Risk Assessment Procedure;
- Are related to a case under the University’s Risk Assessment Procedure.
A Risk Assessment Panel is required to make recommendations for precautionary action where necessary and appropriate, in the context of safeguarding the Responding Student, the Reporting Party, other members of the University community, and/or the University’s reputation. For more information, please see the University’s Risk Assessment Procedure.
The University is the ‘controller’ of the personal data and the University’s Data Protection Officer can be contacted at [email protected].
How is personal data used and what legal basis allows us to process the personal data for these purposes?
The Student Casework Unit processes personal data in order to be able to apply its regulations and their associated procedures, including the Risk Assessment Procedure.
This Privacy Notice explains how your data will be used where you are the subject of, or related to, a case under the Risk Assessment Procedure. For information on how the University processes information in relation to other casework procedures, please see the overarching Privacy Notice for Student Casework.
Our purpose is to assess cases that present as high-risk and arrange qualified Risk Assessment Panels who may implement precautionary, temporary and neutral action (such as a campus suspension) to sufficiently bring down the level of risk and safeguard the University community.
Information relating to course location and term and home time addresses is collected under this procedure to be able to appropriately assess risk; e.g. will students named in a risk assessment be likely to come into contact with one another.
For students reporting a matter of potential risk to the University, it is the student’s decision how much personal data to provide.
For staff of the University, staff are expected (as part of their employment contract) to provide information that is relevant to cases on request, for the University to be able to conduct its procedures. However, staff would not be expected to provide personal information about themselves, aside from their name and contact details and any relevant personal information contained within their version of events.
Disclosure of information including personal data is necessary to verify the facts provided by the student and ensure the University is acting in the best interests of the students, colleagues and the local community in carrying out its public duties. If the University relies on the information provided by students alone in our Risk Assessment Procedure, important, relevant facts may be omitted which will impact on the outcome of the assessment and may place members of our community at unnecessary risk.
The lawful basis we rely on to process personal data relating to staff and other individuals relating to cases is Article 6(1)(e) of the UK GDPR, which allows us to process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. As a higher education corporation, the University’s powers derive from the Education Reform Act 1988 (“the Act”). The primary power conferred on the University under the Act (by section 124(1)(a)) is the provision of higher education. However, in accordance with section 124(2) of the Act, the University has the “power to do anything which appears to the corporation to be necessary or expedient for the purpose of or in connection with the exercise of any of the powers conferred on the corporation by [the Act]. This lawful basis applies when the processing is necessary for the purposes of providing higher education services to students in a safe environment.
We may need to process ‘Special Category’ personal data for the purposes of a Risk Assessment. If the information we collect or otherwise process contains special category data, such as health, religious, sexuality or ethnicity information, the lawful basis we rely on to process it will be Article 9(2)(f) - statutory etc and government purposes’ or Article 9(2)(g) - ‘substantial public interest’ of the UK GDPR, which relates to reasons of substantial public interest with a basis in law and the safeguarding of your fundamental rights, and where a condition from Schedule 1 of the DPA2018 applies (either safeguarding or legal claims). We will only process information relating to criminal offences where a condition from Schedule 1 of the DPA 2018 applies. We will only collect this type of information where it is relevant to the investigation or case, or where we are legally obliged to record it.
What information do we collect for these purposes?
When a risk assessment case is opened with the Student Casework Unit, we will create a case file. This file will store all the information and data gathered in the process of carrying out that procedure, for as long as the precautionary restrictions are required and the case remains open.
It should be noted that a risk assessment case may run parallel to a case under the Student Misconduct & Fitness to Practise Regulations. This is usually where precautionary action needs to remain in place until the misconduct case has reached a conclusion (at which point, any precautionary measures can be replaced by a permanent outcome or closed). For how data is used in relation to the Student Misconduct & Fitness to Practise Regulations, please refer to the overarching Student Casework Privacy Notice.
The Student Casework Unit gathers HESA data for students who are the subject of a risk assessment. HESA data is information provided by students to the University at the beginning of each year specifying protected characteristics, such as religion or disability. However, this is for annual reporting purposes only and is not otherwise shared or used. On reporting, HESA data is always presented anonymously, meaning that it is not possible to identify any individual.
Personal data relating to individuals who are reporting a matter of potential risk in relation to a student:
For reporting students, the data we gather includes:
- Name;
- Contact details;
- Course information and, where relevant, academic data;
- Address (see “how is personal data used?”);
- Relationship to Support Services (where relevant to assessing risk to welfare);
- Visa status (if applicable and where relevant to assessing risk to welfare);
- Relevant background / details including the evidence, information and representations put forward in the assessment of risk.
For reporting staff members, the data we gather includes:
- Name;
- Professional role;
- University contact details;
- Relevant background / details including the evidence, information and representations put forward in the assessment of risk.
Personal data relating to students who are the subject of a case under the Risk Assessment Procedure (Responding Students):
This usually includes students who are reported in relation to a matter of potential risk. The data we gather includes:
- Name;
- Contact details;
- Address (see “how is personal data used?”);
- Visa status (if applicable);
- Relationship to Support Services (where relevant to assessing risk to welfare);
- Course information and, where relevant, academic data;
- Relevant background / details including the evidence, information and representations put forward in the assessment of risk. This includes information relating to criminal offences (please see section below).
What information does the University receive from third parties?
Where the matter of potential risk relates to a possible criminal offence, the University may request information from relevant third parties such as the police. This may include, but is not limited to:
- Confirmation of the status of an investigation;
- Confirmation of an outcome of an investigation;
- Confirmation as to whether the responding/reporting party has been spoken to by the police;
- Confirmation of whether the responding/reporting party is a student;
- Confirmation of any police/court bail conditions;
- Confirmation of released under investigation date;
- Any other information of which we need to be aware in relation to risks to any of the individuals involved.
The University requires the above information to be able to mirror any conditions implemented by the police at a university level, and to properly assess the level of risk presented to the University community and take safeguarding action as needed.
The University may request information from any third party who might be able to provide information that is relevant to be able to appropriately assess the risk. For example, if someone is a witness to an incident. This could be a member of the University (staff or student) or, on occasion, it will be necessary to invite someone external to the University to provide their account.
Note on data sharing where the reporting party wishes to remain anonymous or does not support formal action being taken:
A Risk Assessment Panel may still be convened to assess risk where a reporting party wishes to remain anonymous or does not want a responding individual to be contacted by the University. This is because the University has a duty of care and needs to properly consider any information that may fall under the University’s Safeguarding Policy. In such cases, the Panel will take the reporting party’s wishes into account but will make a decision as to whether the case reaches such a threshold that action should be taken without the reporting party’s agreement. The level of information shared with the Risk Assessment Panel in such cases will be that which is determined proportionate to assess the risk.
For example, if disclosure of the information is necessary to protect the reporting party, or others, from harm or prevent a further crime taking place, it may be appropriate for the University to make a report to the police, or to engage its own procedures. Please see the University’s Sexual Misconduct and Violence Policy for further information.
Where subsequent action taken relates to a University procedure, please see the overarching Student Casework Privacy Notice for how this data is processed.
Who might your personal data be shared with?
Student Casework will always make appropriate redactions before information is shared to ensure that only relevant and necessary information is provided.
Personal data relating to individuals who are reporting a matter of potential risk in relation to a student:
Where a matter of potential risk is reported to the University, information relevant to the case may be shared with:
- The Responding Student;
- A Risk Assessment Panel (for information on the constitution of the Risk Assessment Panel, please see the Risk Assessment Procedure);
- The police, where information is provided which is relevant to an ongoing police matter;
- The police, where the case meets a threshold that a police report should be made without the agreement of the reporting party;
- University staff as necessary to implement precautionary restrictions decided by a Risk Assessment Panel (this may include the University’s partner institutions, if applicable);
- Individuals specified under the overarching Student Casework Privacy Notice, where the case initially opened under the Risk Assessment Procedure leads to a case being opened under a different procedure; e.g. in relation to student misconduct.
Personal data relating to students who are the subject of a case:
- A Risk Assessment Panel (for information on the constitution of the Risk Assessment Panel, please see the Risk Assessment Procedure);
- The Reporting Party, where the nature of precautionary action implemented is relevant for them to be aware of (e.g. a no contact agreement or order);
- The police, where information is provided which is relevant to an ongoing police matter, or where information is provided that meets a threshold for the University to make a report to the police;
- University staff as necessary to implement precautionary restrictions decided by a Risk Assessment Panel (this may include the University’s partner institutions, if applicable);
- Individuals specified under the overarching Student Casework Privacy Notice, where the case initially opened under the Risk Assessment Procedure leads to a case being opened under a different procedure; e.g. in relation to student misconduct.
Information regarding activity under the Risk Assessment Procedure may be shared with the Office of Independent Adjudicator (OIA), insurers or legal advisors if necessary.
In some cases, we may also be required to share information with the police, the courts and/or teams responsible for safeguarding (e.g. the Local Authority Designated Officer (LADO) or Designated Safeguarding Officer (DSO) within the local authority or council). In such cases, we will ensure that the disclosure has lawful basis.
We will only share personal data with legal advisors if it is necessary for the exercise or defence of legal claims.
Personal data relating to staff members/students who are related to a case:
Where individuals provide an account in respect of a risk assessment case, this will form part of the case file and as such may be referenced in the findings of a subsequent investigation under the Student Misconduct & Fitness to Practise Regulations.
Personal data will not be shared with the parties unless it is necessary and relevant. Please see the Student Casework Privacy Notice for information on how data arising from the Risk Assessment Procedure might be shared if a subsequent case under another procedure arises.
We do not use any sub-processors to process data in relation to Student Casework investigations, other than Microsoft. We may share personal data with other agencies if there is a lawful basis, for example - if it is necessary for the purposes of a legal claim or a police or regulatory investigation.
How long will personal data be held for?
Student Casework files are held for six years from the last date of action on the case. If action is ongoing, or continues after the case has closed, the date for deletion of the case file will extend in line with this.
Individual Data Protection Rights
Individuals have the right to access their personal information, to object to the processing of their personal data, to rectify, to erase, to restrict and to port personal information. Further detail can be found on the Information Commissioner's website.
Any requests or objections should be made in writing to the Data Protection Officer –[email protected]
Where individuals are not satisfied with the University’s response or believe that the University is not processing personal data in accordance with the law then they may complain to the Data Protection Officer at the above address.
If the matter is not resolved and you remain dissatisfied then you have the right to apply directly to the Information Commissioner for a decision. The Information Commissioner can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF