Accessibility statement

Information Policy Compliance

Related pages

This policy explains how the University and individuals comply with legal requirements and University information policies. It also outlines how compliance is monitored and reviewed.

It applies to everyone - all staff, students, associates, and anyone else authorised to use University IT facilities and information.

1. Compliance with Legal Requirements

1.1 The University will comply with all relevant statutory and regulatory requirements whether or not those requirements are explicitly stated in its internal policy documentation.

1.2 The University will inform its staff and students of legal obligations by creating and circulating policies and explanatory information about legal compliance matters. Further guidance and advice will be available from specialist staff.

1.3 Heads of Departments, line managers and academic supervisors must inform their staff and students of the requirement to comply with statutory and regulatory requirements if their activities require it.

1.4 Individuals are responsible for ensuring that they do not break the law. Responsibilities with respect to the use of information and IT systems are set out in the University Ordinances and Regulations, and for employees in the Terms and Conditions of Employment.

1.5 As part of the introduction of new or changed systems and processes, a Data Protection Impact Assessment must be undertaken. In addition, where data is to be hosted in the cloud, a cloud computing assessment should be completed.

1.6 The University will monitor legal compliance through internal review processes and through the University’s internal and external Audit processes.