Staff privacy notice

Document reference: OCTA/DP/2026/01 · Version 1.0 · Approved 19 August 2026

Document history and approval

Version history

Table 1 — Version history
VersionDateAuthorSummary of changes
1.019/08/2026Y Mohamed YusufFirst issue.

1. Purpose and scope

This notice explains how personal information about members of staff is used when leave and absence are requested, recorded and approved in the OASIS Leave Suite. It is issued so that every member of staff can establish, without having to ask, what is held about them, who can see it, how long it is kept and what they can do about it.

The OASIS Leave Suite is an internal system used to calculate leave entitlement and balances, to record annual leave, sickness and other absence, to route requests to the appropriate approver, and to give managers a view of who is available so that cover can be arranged. It replaces the spreadsheets and email trails previously used for the same purpose.

This notice is provided to meet the requirements of Articles 13 and 14 of the UK General Data Protection Regulation. It sits alongside, and does not replace, the general staff privacy notice issued on appointment. Where the two differ on a point specific to leave and absence, this notice applies.

1.1 Scope

This document applies to:

  • OASIS Care and Training Agency (registered charity 1044521); and
  • OASIS Workforce Solutions Limited.

It applies to every member of staff who holds an account on the OASIS Leave Suite, and to every record held in that system.

1.2 Exclusions

This notice does not cover care workers whose leave is administered through Access People Planner rather than the Leave Suite, and it does not cover any personal information held in other systems, including payroll, recruitment, training and care records. Each of those is covered by its own notice or by the general staff privacy notice.

2. Who is responsible for this information

Each organisation is the controller of the information relating to its own staff. Because the two organisations share a single system, a single database and a single set of administrators, they act as joint controllers for the operation, security and administration of that system. The division of responsibility is set out in the joint controller arrangement at Annex A of the Data Protection Framework, and its essence is summarised below.

Table 4 — Joint controller responsibilities
ResponsibilityHeld by
Setting entitlement, approving leave, and the accuracy of an individual recordThe employing organisation
Operating, securing and administering the system, and holding the supplier contractsOASIS Care and Training Agency
Responding to requests from staff about their own informationEither organisation; a request made to one is handled by both
Assessing and reporting a personal data breach to the Information CommissionerOASIS Care and Training Agency, on behalf of both

KEY POINT
A member of staff may exercise every right described in this notice against either organisation. There is no need to establish which of the two holds a particular record before making a request.

3. Information held in the OASIS Leave Suite

Table 5 — Categories of personal data held
CategoryWhat this includes
Identity and contactName, work email address and initials
EmploymentJob title, organisation, branch, department, employment start date, contracted working pattern, and the names of the primary and second approver
Entitlement and balanceAnnual leave entitlement, any pro-rata calculation applied to it, days carried over from the previous leave year, days taken, days booked and days remaining
Leave and absence recordsThe dates and length of each period of leave or absence, the type of leave, whether a half day was taken, any note added to a request, and the status of that request
Absence attributed to sicknessThat a period of absence was recorded as sickness, and its dates. Where a fit note is required, that one has been provided and the dates it covers
Approval and decisionWho approved or declined each request and when, together with any reason given for a decline, withdrawal, cancellation or amendment
Account and securityAccount status, enrolment in multi-factor authentication, the date the password was last changed, and sign-in activity
Audit recordsA permanent record of actions taken in the system: who did what, to which record, and when

CAUTION
The OASIS Leave Suite holds no medical or clinical information. It does not record a diagnosis, a symptom, a treatment, the content of a fit note or any opinion expressed by a clinician. Where sickness absence is recorded, only the fact of the absence and its dates are held.

It does not hold salary, bank details, home address, next of kin, disciplinary records or performance records. Any request to add such information to the system must be refused and referred to the Compliance Officer.

3.1 Where the information comes from

  • Name, work email, job title, branch, department, working pattern, start date and approver are taken from the employment record at the point the account is created.
  • Entitlement and opening balance for the current leave year were transferred from the leave records held before the Leave Suite was introduced.
  • Requests, and any note attached to them, are entered by the member of staff.
  • Absence reported by telephone, and any absence recorded on a person’s behalf, is entered by a manager or an administrator.
  • Bank holidays and office closure days are entered centrally and applied to everyone.

4. Purposes and lawful basis

A lawful basis under Article 6 of the UK GDPR is required for everything done with this information. Where information concerns health, a further condition under Article 9 and, in most cases, a condition in Schedule 1 to the Data Protection Act 2018 is also required.

Table 6 — Purposes and lawful basis
PurposeLawful basis (Article 6)Further condition where health data is involved
Calculating leave entitlement and balance, and recording leave takenArticle 6(1)(b) — necessary for the performance of the contract of employmentNot applicable
Meeting statutory obligations on working time and holiday, and keeping the records required by lawArticle 6(1)(c) — necessary for compliance with a legal obligation, principally the Working Time Regulations 1998 and the Employment Rights Act 1996Not applicable
Recording and managing sickness absence, including fit note dates and return to workArticle 6(1)(c) — necessary for compliance with a legal obligation in the field of employmentArticle 9(2)(b), read with paragraph 1 of Schedule 1 to the Data Protection Act 2018 (employment, social security and social protection). An Appropriate Policy Document is in place, as that condition requires
Planning cover so that services to people supported by OASIS are not interrupted, and identifying clashes before leave is approvedArticle 6(1)(f) — the legitimate interests of the organisation in maintaining safe staffing and continuity of careNot applicable
Maintaining the security of the system, controlling access and keeping an audit trailArticle 6(1)(f) — the legitimate interests of the organisation in protecting the integrity of its systems and recordsNot applicable
Producing management and payroll reports on leave and absenceArticle 6(1)(b) and Article 6(1)(f)Where a report includes sickness absence, Article 9(2)(b) as above

Where the organisation relies on legitimate interests, it has assessed whether those interests are outweighed by the interests, rights and freedoms of the individual. They are not, because the information involved is limited to dates and availability, because it is used only for planning and for security and never to assess an individual as an employee, and because the right to object remains available and will be considered on its merits. A copy of that assessment is available from the Compliance Officer.

REGULATORY REQUIREMENT
Where sickness absence is processed under paragraph 1 of Schedule 1 to the Data Protection Act 2018, an Appropriate Policy Document must be in place for the duration of the processing and retained for six months after it ends.
Source: Data Protection Act 2018, Schedule 1, Part 4, paragraph 5.

5. Access and visibility

Access to the OASIS Leave Suite is controlled by role. No account has access beyond what its role requires, and every action taken against a record is capable of being audited.

Table 7 — Access by role
RoleWhat the role can seeWho holds it
IndividualTheir own record in full: entitlement, balance, and every request and its outcomeEvery member of staff
Primary and second approverThe requests, balance and absence dates of the staff who report to themLine managers and, where one is appointed, a named deputy
Department and branch scopeAbsence dates and leave type for staff within that department or branch, for cover planningManagers responsible for that area
Organisation scopeAbsence dates and leave type across both organisationsA small number of named staff holding an absence administration role
AdministratorAccount details, entitlements and balances, in order to maintain themA small number of named staff
Super userAll of the above, together with the audit logTwo named individuals, each of whom reviews the activity of the other

5.1 What colleagues can see

The shared calendar shows colleagues within the relevant scope that a person is absent, on which dates, and the type of absence recorded — for example annual leave, unpaid leave or sickness. It shows no reason for the absence, no medical information, and no note attached to a request.

This position is deliberate. Absence must be visible for cover to be arranged, and colleagues are in any event aware when a person is not at work. What the calendar does not do, and will not be configured to do, is disclose why.

6. Automated decision-making

There is no automated decision-making within the OASIS Leave Suite that produces a legal effect, or a similarly significant effect, on any member of staff within the meaning of Article 22 of the UK GDPR. As a matter of policy:

  • no absence score, trigger point or index — including the Bradford Factor or any comparable measure — is calculated or held;
  • no warning, referral, review or other consequence is generated automatically from any pattern of absence; and
  • every approval and every decline is made by a named individual, whose identity is recorded.

The system does perform calculations: the number of working days a request consumes, the resulting balance, and the number of colleagues already absent on a given date. These are arithmetic, they are visible to the individual concerned, and they inform a decision rather than making one.

7. Disclosure and processors

Information held in the OASIS Leave Suite is not sold and is not used for marketing. It is disclosed only to the suppliers who operate parts of the system on the organisation’s behalf, and only to the extent necessary. Each is bound by a written contract under Article 28 of the UK GDPR permitting it to act solely on documented instructions.

Table 8 — Processors engaged
SupplierFunctionLocation of dataWhat is received
Railway CorporationHosts the application and its databaseEuropean Union — AmsterdamAll information held in the Leave Suite
Plus Five Five, Inc. (Resend)Delivers system emails, such as notification of an approvalIreland, for message deliveryName, work email address, and the subject and content of the message
MicrosoftProvides the corporate mailboxes to which those emails are deliveredUnited Kingdom and European UnionThe delivered message
Amazon Web ServicesProvides underlying infrastructure to Railway and to ResendEuropean UnionOnly in its capacity as a sub-processor to the above

Information may also be disclosed where the organisation is required to do so by law, by a regulator including the Care Quality Commission, or by a court; where it is necessary to establish, exercise or defend a legal claim; and to professional advisers bound by a duty of confidence.

The sub-processors engaged by each supplier are listed publicly by that supplier, and the current list is verified and recorded in the processor register maintained by the Compliance Officer. A copy is available on request.

7.1 Transfers outside the United Kingdom

The OASIS Leave Suite is hosted in the European Union, which the United Kingdom has recognised as providing an adequate level of protection. Information is stored there and is not stored in the United States.

Two of the suppliers named above are companies established in the United States, and their personnel may be able to access data held in the European Union in the course of supporting the service. That access is a restricted transfer under United Kingdom data protection law. It is covered by the International Data Transfer Addendum to the European Commission’s standard contractual clauses, and a transfer risk assessment has been carried out and recorded. A copy of that assessment is available on request.

8. Retention

Table 9 — Retention periods
RecordRetention periodBasis
Leave and absence records, entitlements and balancesSix years from the end of the leave year to which they relate, or six years from the end of employment if laterThe period within which a claim relating to holiday or working time may be brought
Sickness absence dates and fit note datesSix years from the end of employmentAs above, together with duties under health and safety and equality legislation
Account records, sign-in activity and security settingsDeleted or disabled within one month of the end of employmentNo longer required once access ceases
Audit log entriesSix years from the date of the entryTo evidence that the system and its controls operated as described
BackupsOverwritten on a rolling cycle and not retained beyond itBackups exist to restore service, not to retain records

At the end of a retention period the record is deleted. Where a record is subject to a legal hold, an investigation or a regulatory request, it is retained until that matter concludes and is then deleted.

These periods are consistent with the retention periods applied to staff employment records across the organisation.

9. Security

  • Multi-factor authentication is required on every account without exception, including administrator and Super user accounts.
  • Access is restricted by role, and each account sees only what its role requires.
  • Information is encrypted in transit and at rest.
  • An audit log records actions taken in the system. It cannot be edited or deleted, including by an administrator, and this restriction is enforced by the database itself.
  • The two Super users review each other’s activity, so that no individual can act without oversight.
  • Backups are taken automatically to durable storage held separately from the running system, on a daily schedule. Continuous point-in-time recovery is also in place, so the database can be restored to a recent moment rather than only to the most recent daily backup.
  • Temporary credentials are issued to corporate mailboxes only and are spent at first use.
  • Any personal data breach is assessed without delay and, where the threshold is met, reported to the Information Commissioner within 72 hours and to those affected where the risk to them is high.

10. Rights of individuals

The following rights apply to the information held in the OASIS Leave Suite. They are free to exercise, and no member of staff will be treated less favourably for exercising them.

Table 10 — Rights and how they apply
RightHow it applies here
To be informedTo be told what is done with the information, which is the purpose of this notice
Of accessTo receive a copy of the information held. Much of it is visible at any time by signing in to the system
To rectificationTo have inaccurate information corrected — for example an entitlement, a working pattern or an opening balance. A correction is made and the correction itself recorded
To erasureTo request deletion. This right is limited here, because most of what is held is necessary to meet a legal obligation or to defend a claim. Where a request cannot be met, the reason is explained
To restrict processingTo request that use of the information is paused while a dispute about its accuracy is resolved
To objectTo object to processing carried out on the basis of legitimate interests, namely cover planning, security and reporting. Processing stops unless compelling grounds are demonstrated
To data portabilityTo receive information provided by the individual in a portable format. This applies to a limited part of what is held
Not to be subject to automated decisionsAs stated at section 6, no such decisions are made
To complainTo the organisation, and to the Information Commissioner’s Office

A request is acknowledged and answered within one month. Where a request is complex, that period may be extended by up to two further months; the individual is told within the first month if it is, and why.

10.1 Where information must be provided

The information held in the OASIS Leave Suite is required in order to administer employment. Without a working pattern and an entitlement, leave cannot be calculated correctly; without a record of a request, leave cannot be approved or paid. No part of this processing relies on consent, so there is nothing here that a member of staff is asked to agree to and nothing that can later be withdrawn.

11. Roles and responsibilities

Table 11 — Roles and responsibilities
RoleResponsibility under this document
Board of TrusteesAccountability for data protection compliance across the organisation, receiving assurance annually
Executive DirectorOverall responsibility for implementation and resourcing, and accountable owner of this notice
Compliance OfficerMaintaining this notice, the processor register and the related data protection documents; handling requests from individuals; assessing and reporting breaches
Super usersOperating the system within the access model described, and reviewing each other’s activity
AdministratorsMaintaining accounts, entitlements and balances accurately, and recording corrections
ApproversDeciding requests, and using absence information only for cover planning
All staffKeeping their own record accurate, reporting anything that appears wrong, and reporting any suspected misuse or breach without delay

12. Monitoring, review and assurance

Table 12 — Monitoring and assurance
Assurance activityMethodFrequencyReported to
Review of the audit logSample of administrative and Super user actionsQuarterlyExecutive Director
Verification of the processor register and sub-processor listsCheck of each supplier’s published list against the registerQuarterlyCompliance Officer
Review of access and role assignmentsFull listing of accounts, scopes and administrator flagsSix-monthlyExecutive Director
Test restoration of a backupRestoration of a recent backup into a separate database, and confirmation that the restored records are completeAnnual, and following any change to the backup arrangementsCompliance Officer
Review of this notice against the system as builtComparison of the notice with the current data model and access modelAnnual, or on material changeExecutive Director

Where a change to the system materially affects what is held, who can see it, or how long it is kept, this notice is amended and staff are told directly rather than being left to notice the change. The current version is linked from the footer of every page of the OASIS Leave Suite.

13. Contact and complaints

Table 13 — Contact points
PurposeContact
Any question about this notice, or to exercise a rightYusuf Mohamed Yusuf, Compliance Officer — ymohamed@oasiscareandtraining.org.uk, or Ibrahim Ileye, Quality Monitoring Officer — i.ileye@oasiscareandtraining.org.uk
A correction to an entitlement, balance or leave recordThe individual’s line manager in the first instance, or the Compliance Officer
To report a suspected data breach or misuse of the systemEither address above, immediately and without waiting for certainty
Accountable ownerMohamed Yusuf, Executive Director
Registered office24–32 Murdock Street, London, SE15 1LW

An individual who is not satisfied with the response received may complain to the Information Commissioner’s Office. The organisation asks to be given the opportunity to resolve the matter first, but there is no obligation to do so.

Table 14 — Information Commissioner’s Office
Information Commissioner’s OfficeContact
AddressWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone0303 123 1113
Websitewww.ico.org.uk

14. Related documents and references

  • Data Protection Framework, OASIS/DP/FRAMEWORK/001, including Annex A joint controller arrangement.
  • Staff Leave Suite Data Protection Impact Assessment, OASIS/DP/DPIA/002.
  • Appropriate Policy Document, OASIS/DP/APD/001.
  • Transfer Risk Assessment, OASIS/DP/TRA/001.
  • UK General Data Protection Regulation, in particular Articles 5, 6, 9, 13, 14, 22, 28, 32 and 44 to 49.
  • Data Protection Act 2018, in particular Schedule 1, Part 1, paragraph 1 and Part 4, paragraph 5.
  • Working Time Regulations 1998; Employment Rights Act 1996.
  • Information Commissioner’s Office, Employment practices and data protection: workers’ health, 2023.