The new requirement to have a lawful basis to process personal data replaces and mirrors the previous requirement to satisfy one of the ‘conditions for processing’ under the Data Protection Act 1998. However, the GDPR places more emphasis on being accountable for and transparent about a lawful basis for processing. We must have a valid lawful basis to process personal data. There are six available lawful bases for processing. We have identified ‘legitimate interests’ as our lawful basis for processing personal information. We take on the extra responsibility for considering and protecting people’s rights and interests here.

Our Legitimate Interests are:

1. To establish overall physical health scores for individual pupils – as the basis to inform and engage all school stakeholders, and as a means to track physical health progress.

2. To provide badges for pupils to work towards – as a motivational tool for improving their existing level of physical health

3. To provide individual and year group information to the school or organisation – which can be used for report writing and future physical health planning

4. To establish a developing national picture for pupils’ physical health – imperative for future physical health planning on a larger scale

We cannot reasonably achieve these outcomes in a less intrusive way. We have balanced our interests against the individual’s when taking the decision to process this information. We will process all personal data lawfully, fairly and in a transparent manner.