Introduction
We value the privacy and protection of personal data for all our External Examiners. The University of Derby ("we," "our," or "us") is the data controller responsible for the personal data you provide as an External Examiner.
This privacy notice outlines how we collect, use, and protect the personal data of External Examiners ("you" or "your"). It also explains our expectations where you access University systems or data, including the requirement to use secure, up-to-date devices in line with the UK Government’s Cyber Essentials scheme.
We are committed to ensuring that your privacy is protected and that we comply with all applicable data protection legislation, including the UK GDPR and the Data Protection Act 2018.
Role of External Examiners
External Examiners are appointed to report on the maintenance of nationally comparable standards across Higher Education institutions. They act as independent and impartial advisors to the University and provide informed comment on the standards set and student achievement in relation to those standards.
Data Collection
We collect the following types of personal data from External Examiners:
- Identity Data: Name, date of birth, sex, nationality
- Contact Data: Address, email, phone number
- Professional Data: Qualifications, employment history, other higher education institutions you work with, professional memberships
- Financial Data: Bank account information, payment details
- Legal Data: Right to work information, HMRC information
- Feedback Data: Annual External Examiner Reports, External Examiner Feedback Form
- Equal Opportunities Data: Information that may be provided throughout your tenure
- Special Category Data: Sensitive information such as racial or ethnic origin, disability information (required for HESA reporting), and any health or sexual orientation information you choose to provide, collected and processed under the lawful bases described in section 4
Purpose and Lawful Basis
| Purpose |
What this covers |
Lawful basis (Article 6) |
Special category basis (Article 9) |
| Appointment and Verification |
Assessing suitability and confirming appointment |
Contract - 6 (1)(b) |
N/A |
| Communication |
Contact relating to duties and administration |
Contract - 6(1)(b) |
N/A |
| Payment and Adminstration |
Paying fees; HR/Payroll processes |
Contract – 6(1)(b);
Legal Obligation – 6(1)(c)
|
N/A |
| Legal & Regulatory Compliance |
Right‑to‑work, audit, regulatory reporting |
Legal Obligation – 6(1)(c) |
N/A |
| HESA Staff Return |
Mandatory reporting of staff characteristics (age, sex, ethnicity, disability) where External Examiners are included in the HESA staff record. |
Legal Obligation – 6(1)(c) |
Employment, Social Security & Social Protection Law – 9(2)(b) |
| Quality Assurance |
Use of examiner reports to assure academic standards |
Legitimate Interests – 6(1)(f) |
N/A |
| EDI Monitoring (beyond HESA) |
Equality, diversity, and inclusion monitoring that is voluntary and not required for HESA reporting. |
Legitimate Interests – 6(1)(f) |
Explicit Consent – 9(2)(a) OR
Substantial Public Interest – 9(2)(g) (DPA Sch1 Para8)
|
| Reasonable Adjustments |
Supporting your duties where health/disability information is shared |
Contract – 6(1)(b) |
Explicit Consent – 9(2)(a) |
Data Sharing
We may share your personal data with the following parties:
- Internal departments involved in external examiner process
- Accreditation Bodies
- Academic and Industry Partners
- Governmental and Regulatory Authorities
- Service Providers under confidentiality agreements (e.g., HR and payroll systems)
- External Bodies, such as tax authorities where required by law
- Third‑party service providers, including identity‑verification systems and external quality‑monitoring platforms (e.g. Yoti – Right to Work Checks, CPS - Quality Monitoring and Evaluation Platform (QMEP))
All third‑party service providers are contractually required to process personal data only on the University’s documented instructions, apply appropriate confidentiality and security measures, and not use your personal data for their own purposes.
Data Security
We have implemented appropriate technical and organisational measures to protect your data from unauthorised access, alteration, disclosure, or destruction.
Use of Personal Devices and Security Requirements
Devices used to access University systems must meet Cyber Essentials standards.
- Supported operating systems
- Automatic updates
- Encryption, firewall, anti‑malware
- Strong authentication
- Non‑shared access
Please see more information on our University of Derby Website and External Examiner pages.
International Data Transfers
If your data is transferred outside the UK/EEA, we apply appropriate safeguards such as Standard Contractual Clauses.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Here are some examples:
- Appointment Records: Retained for 6 years after the end of the appointment period.
- Financial Information: Retained for 7 years to comply with financial regulations and audit requirements.
- Professional Correspondence and Reports: Retained for a period of 6 years following the end of the appointment.
- Legal Documentation: Retained for 2 years following the end of the engagement.
- Equal Opportunities Data: Retained as long as necessary for reporting purposes, typically anonymised and kept longer if required for statistical purposes.
Upon the conclusion of your appointment, your personal data will be securely archived or deleted in accordance with our data retention and data destruction policies.
Retention policy here: UOD - Record of processing activities - University of Derby
External Examiners must securely delete or destroy any University data/personal they hold once their appointment ends and the data is no longer required
Your Rights
You have the following rights regarding your personal data:
- Access: To request access to the personal data we hold about you.
- Correction: To request correction of any inaccurate or incomplete data.
- Erasure: To request the deletion of your personal data under certain conditions.
- Restriction: To request the restriction of processing of your personal data.
- Portability: To request the transfer of your personal data to another organisation.
- Objection: To object to the processing of your personal data under certain conditions.
To exercise any of these rights, please contact our Assurance Service Team, at GDPR@derby.ac.uk
Contact Us
If you have any questions, concerns, or requests regarding your personal data, please contact our Data Protection Officer at GDPR@derby.ac.uk.
Data Controller Information
The University is the data controller. You can contact our Data Protection Officer at:
DPO: James Fussell, Associate Director, Legal, Governance and Assurance Services
Email: DPO@derby.ac.uk
Legal, Governance & Assurance Services, University of Derby, Kedleston Road, DE22 1GB
Changes to this Privacy Notice
This privacy notice may be updated periodically to reflect changes in our practices or legal requirements. Any changes will be posted on our website, and where appropriate, notified to you via email.
Effective Date
This privacy notice is effective as of 01/01/2026.