Staff privacy notice
Document reference: OCTA/DP/2026/01 · Version 1.0 · Approved 19 August 2026
Document history and approval
Version history
| Version | Date | Author | Summary of changes |
|---|---|---|---|
| 1.0 | 19/08/2026 | Y Mohamed Yusuf | First issue. |
1. Purpose and scope
This notice explains how personal information about members of staff is used when leave and absence are requested, recorded and approved in the OASIS Leave Suite. It is issued so that every member of staff can establish, without having to ask, what is held about them, who can see it, how long it is kept and what they can do about it.
The OASIS Leave Suite is an internal system used to calculate leave entitlement and balances, to record annual leave, sickness and other absence, to route requests to the appropriate approver, and to give managers a view of who is available so that cover can be arranged. It replaces the spreadsheets and email trails previously used for the same purpose.
This notice is provided to meet the requirements of Articles 13 and 14 of the UK General Data Protection Regulation. It sits alongside, and does not replace, the general staff privacy notice issued on appointment. Where the two differ on a point specific to leave and absence, this notice applies.
1.1 Scope
This document applies to:
- OASIS Care and Training Agency (registered charity 1044521); and
- OASIS Workforce Solutions Limited.
It applies to every member of staff who holds an account on the OASIS Leave Suite, and to every record held in that system.
1.2 Exclusions
This notice does not cover care workers whose leave is administered through Access People Planner rather than the Leave Suite, and it does not cover any personal information held in other systems, including payroll, recruitment, training and care records. Each of those is covered by its own notice or by the general staff privacy notice.
2. Who is responsible for this information
Each organisation is the controller of the information relating to its own staff. Because the two organisations share a single system, a single database and a single set of administrators, they act as joint controllers for the operation, security and administration of that system. The division of responsibility is set out in the joint controller arrangement at Annex A of the Data Protection Framework, and its essence is summarised below.
| Responsibility | Held by |
|---|---|
| Setting entitlement, approving leave, and the accuracy of an individual record | The employing organisation |
| Operating, securing and administering the system, and holding the supplier contracts | OASIS Care and Training Agency |
| Responding to requests from staff about their own information | Either organisation; a request made to one is handled by both |
| Assessing and reporting a personal data breach to the Information Commissioner | OASIS Care and Training Agency, on behalf of both |
KEY POINT
A member of staff may exercise every right described in this notice against either organisation. There is no need to establish which of the two holds a particular record before making a request.
3. Information held in the OASIS Leave Suite
| Category | What this includes |
|---|---|
| Identity and contact | Name, work email address and initials |
| Employment | Job title, organisation, branch, department, employment start date, contracted working pattern, and the names of the primary and second approver |
| Entitlement and balance | Annual leave entitlement, any pro-rata calculation applied to it, days carried over from the previous leave year, days taken, days booked and days remaining |
| Leave and absence records | The dates and length of each period of leave or absence, the type of leave, whether a half day was taken, any note added to a request, and the status of that request |
| Absence attributed to sickness | That a period of absence was recorded as sickness, and its dates. Where a fit note is required, that one has been provided and the dates it covers |
| Approval and decision | Who approved or declined each request and when, together with any reason given for a decline, withdrawal, cancellation or amendment |
| Account and security | Account status, enrolment in multi-factor authentication, the date the password was last changed, and sign-in activity |
| Audit records | A permanent record of actions taken in the system: who did what, to which record, and when |
CAUTION
The OASIS Leave Suite holds no medical or clinical information. It does not record a diagnosis, a symptom, a treatment, the content of a fit note or any opinion expressed by a clinician. Where sickness absence is recorded, only the fact of the absence and its dates are held.
It does not hold salary, bank details, home address, next of kin, disciplinary records or performance records. Any request to add such information to the system must be refused and referred to the Compliance Officer.
3.1 Where the information comes from
- Name, work email, job title, branch, department, working pattern, start date and approver are taken from the employment record at the point the account is created.
- Entitlement and opening balance for the current leave year were transferred from the leave records held before the Leave Suite was introduced.
- Requests, and any note attached to them, are entered by the member of staff.
- Absence reported by telephone, and any absence recorded on a person’s behalf, is entered by a manager or an administrator.
- Bank holidays and office closure days are entered centrally and applied to everyone.
4. Purposes and lawful basis
A lawful basis under Article 6 of the UK GDPR is required for everything done with this information. Where information concerns health, a further condition under Article 9 and, in most cases, a condition in Schedule 1 to the Data Protection Act 2018 is also required.
| Purpose | Lawful basis (Article 6) | Further condition where health data is involved |
|---|---|---|
| Calculating leave entitlement and balance, and recording leave taken | Article 6(1)(b) — necessary for the performance of the contract of employment | Not applicable |
| Meeting statutory obligations on working time and holiday, and keeping the records required by law | Article 6(1)(c) — necessary for compliance with a legal obligation, principally the Working Time Regulations 1998 and the Employment Rights Act 1996 | Not applicable |
| Recording and managing sickness absence, including fit note dates and return to work | Article 6(1)(c) — necessary for compliance with a legal obligation in the field of employment | Article 9(2)(b), read with paragraph 1 of Schedule 1 to the Data Protection Act 2018 (employment, social security and social protection). An Appropriate Policy Document is in place, as that condition requires |
| Planning cover so that services to people supported by OASIS are not interrupted, and identifying clashes before leave is approved | Article 6(1)(f) — the legitimate interests of the organisation in maintaining safe staffing and continuity of care | Not applicable |
| Maintaining the security of the system, controlling access and keeping an audit trail | Article 6(1)(f) — the legitimate interests of the organisation in protecting the integrity of its systems and records | Not applicable |
| Producing management and payroll reports on leave and absence | Article 6(1)(b) and Article 6(1)(f) | Where a report includes sickness absence, Article 9(2)(b) as above |
Where the organisation relies on legitimate interests, it has assessed whether those interests are outweighed by the interests, rights and freedoms of the individual. They are not, because the information involved is limited to dates and availability, because it is used only for planning and for security and never to assess an individual as an employee, and because the right to object remains available and will be considered on its merits. A copy of that assessment is available from the Compliance Officer.
REGULATORY REQUIREMENT
Where sickness absence is processed under paragraph 1 of Schedule 1 to the Data Protection Act 2018, an Appropriate Policy Document must be in place for the duration of the processing and retained for six months after it ends.
Source: Data Protection Act 2018, Schedule 1, Part 4, paragraph 5.
5. Access and visibility
Access to the OASIS Leave Suite is controlled by role. No account has access beyond what its role requires, and every action taken against a record is capable of being audited.
| Role | What the role can see | Who holds it |
|---|---|---|
| Individual | Their own record in full: entitlement, balance, and every request and its outcome | Every member of staff |
| Primary and second approver | The requests, balance and absence dates of the staff who report to them | Line managers and, where one is appointed, a named deputy |
| Department and branch scope | Absence dates and leave type for staff within that department or branch, for cover planning | Managers responsible for that area |
| Organisation scope | Absence dates and leave type across both organisations | A small number of named staff holding an absence administration role |
| Administrator | Account details, entitlements and balances, in order to maintain them | A small number of named staff |
| Super user | All of the above, together with the audit log | Two named individuals, each of whom reviews the activity of the other |
5.1 What colleagues can see
The shared calendar shows colleagues within the relevant scope that a person is absent, on which dates, and the type of absence recorded — for example annual leave, unpaid leave or sickness. It shows no reason for the absence, no medical information, and no note attached to a request.
This position is deliberate. Absence must be visible for cover to be arranged, and colleagues are in any event aware when a person is not at work. What the calendar does not do, and will not be configured to do, is disclose why.
6. Automated decision-making
There is no automated decision-making within the OASIS Leave Suite that produces a legal effect, or a similarly significant effect, on any member of staff within the meaning of Article 22 of the UK GDPR. As a matter of policy:
- no absence score, trigger point or index — including the Bradford Factor or any comparable measure — is calculated or held;
- no warning, referral, review or other consequence is generated automatically from any pattern of absence; and
- every approval and every decline is made by a named individual, whose identity is recorded.
The system does perform calculations: the number of working days a request consumes, the resulting balance, and the number of colleagues already absent on a given date. These are arithmetic, they are visible to the individual concerned, and they inform a decision rather than making one.
7. Disclosure and processors
Information held in the OASIS Leave Suite is not sold and is not used for marketing. It is disclosed only to the suppliers who operate parts of the system on the organisation’s behalf, and only to the extent necessary. Each is bound by a written contract under Article 28 of the UK GDPR permitting it to act solely on documented instructions.
| Supplier | Function | Location of data | What is received |
|---|---|---|---|
| Railway Corporation | Hosts the application and its database | European Union — Amsterdam | All information held in the Leave Suite |
| Plus Five Five, Inc. (Resend) | Delivers system emails, such as notification of an approval | Ireland, for message delivery | Name, work email address, and the subject and content of the message |
| Microsoft | Provides the corporate mailboxes to which those emails are delivered | United Kingdom and European Union | The delivered message |
| Amazon Web Services | Provides underlying infrastructure to Railway and to Resend | European Union | Only in its capacity as a sub-processor to the above |
Information may also be disclosed where the organisation is required to do so by law, by a regulator including the Care Quality Commission, or by a court; where it is necessary to establish, exercise or defend a legal claim; and to professional advisers bound by a duty of confidence.
The sub-processors engaged by each supplier are listed publicly by that supplier, and the current list is verified and recorded in the processor register maintained by the Compliance Officer. A copy is available on request.
7.1 Transfers outside the United Kingdom
The OASIS Leave Suite is hosted in the European Union, which the United Kingdom has recognised as providing an adequate level of protection. Information is stored there and is not stored in the United States.
Two of the suppliers named above are companies established in the United States, and their personnel may be able to access data held in the European Union in the course of supporting the service. That access is a restricted transfer under United Kingdom data protection law. It is covered by the International Data Transfer Addendum to the European Commission’s standard contractual clauses, and a transfer risk assessment has been carried out and recorded. A copy of that assessment is available on request.
8. Retention
| Record | Retention period | Basis |
|---|---|---|
| Leave and absence records, entitlements and balances | Six years from the end of the leave year to which they relate, or six years from the end of employment if later | The period within which a claim relating to holiday or working time may be brought |
| Sickness absence dates and fit note dates | Six years from the end of employment | As above, together with duties under health and safety and equality legislation |
| Account records, sign-in activity and security settings | Deleted or disabled within one month of the end of employment | No longer required once access ceases |
| Audit log entries | Six years from the date of the entry | To evidence that the system and its controls operated as described |
| Backups | Overwritten on a rolling cycle and not retained beyond it | Backups exist to restore service, not to retain records |
At the end of a retention period the record is deleted. Where a record is subject to a legal hold, an investigation or a regulatory request, it is retained until that matter concludes and is then deleted.
These periods are consistent with the retention periods applied to staff employment records across the organisation.
9. Security
- Multi-factor authentication is required on every account without exception, including administrator and Super user accounts.
- Access is restricted by role, and each account sees only what its role requires.
- Information is encrypted in transit and at rest.
- An audit log records actions taken in the system. It cannot be edited or deleted, including by an administrator, and this restriction is enforced by the database itself.
- The two Super users review each other’s activity, so that no individual can act without oversight.
- Backups are taken automatically to durable storage held separately from the running system, on a daily schedule. Continuous point-in-time recovery is also in place, so the database can be restored to a recent moment rather than only to the most recent daily backup.
- Temporary credentials are issued to corporate mailboxes only and are spent at first use.
- Any personal data breach is assessed without delay and, where the threshold is met, reported to the Information Commissioner within 72 hours and to those affected where the risk to them is high.
10. Rights of individuals
The following rights apply to the information held in the OASIS Leave Suite. They are free to exercise, and no member of staff will be treated less favourably for exercising them.
| Right | How it applies here |
|---|---|
| To be informed | To be told what is done with the information, which is the purpose of this notice |
| Of access | To receive a copy of the information held. Much of it is visible at any time by signing in to the system |
| To rectification | To have inaccurate information corrected — for example an entitlement, a working pattern or an opening balance. A correction is made and the correction itself recorded |
| To erasure | To request deletion. This right is limited here, because most of what is held is necessary to meet a legal obligation or to defend a claim. Where a request cannot be met, the reason is explained |
| To restrict processing | To request that use of the information is paused while a dispute about its accuracy is resolved |
| To object | To object to processing carried out on the basis of legitimate interests, namely cover planning, security and reporting. Processing stops unless compelling grounds are demonstrated |
| To data portability | To receive information provided by the individual in a portable format. This applies to a limited part of what is held |
| Not to be subject to automated decisions | As stated at section 6, no such decisions are made |
| To complain | To the organisation, and to the Information Commissioner’s Office |
A request is acknowledged and answered within one month. Where a request is complex, that period may be extended by up to two further months; the individual is told within the first month if it is, and why.
10.1 Where information must be provided
The information held in the OASIS Leave Suite is required in order to administer employment. Without a working pattern and an entitlement, leave cannot be calculated correctly; without a record of a request, leave cannot be approved or paid. No part of this processing relies on consent, so there is nothing here that a member of staff is asked to agree to and nothing that can later be withdrawn.
11. Roles and responsibilities
| Role | Responsibility under this document |
|---|---|
| Board of Trustees | Accountability for data protection compliance across the organisation, receiving assurance annually |
| Executive Director | Overall responsibility for implementation and resourcing, and accountable owner of this notice |
| Compliance Officer | Maintaining this notice, the processor register and the related data protection documents; handling requests from individuals; assessing and reporting breaches |
| Super users | Operating the system within the access model described, and reviewing each other’s activity |
| Administrators | Maintaining accounts, entitlements and balances accurately, and recording corrections |
| Approvers | Deciding requests, and using absence information only for cover planning |
| All staff | Keeping their own record accurate, reporting anything that appears wrong, and reporting any suspected misuse or breach without delay |
12. Monitoring, review and assurance
| Assurance activity | Method | Frequency | Reported to |
|---|---|---|---|
| Review of the audit log | Sample of administrative and Super user actions | Quarterly | Executive Director |
| Verification of the processor register and sub-processor lists | Check of each supplier’s published list against the register | Quarterly | Compliance Officer |
| Review of access and role assignments | Full listing of accounts, scopes and administrator flags | Six-monthly | Executive Director |
| Test restoration of a backup | Restoration of a recent backup into a separate database, and confirmation that the restored records are complete | Annual, and following any change to the backup arrangements | Compliance Officer |
| Review of this notice against the system as built | Comparison of the notice with the current data model and access model | Annual, or on material change | Executive Director |
Where a change to the system materially affects what is held, who can see it, or how long it is kept, this notice is amended and staff are told directly rather than being left to notice the change. The current version is linked from the footer of every page of the OASIS Leave Suite.
13. Contact and complaints
| Purpose | Contact |
|---|---|
| Any question about this notice, or to exercise a right | Yusuf Mohamed Yusuf, Compliance Officer — ymohamed@oasiscareandtraining.org.uk, or Ibrahim Ileye, Quality Monitoring Officer — i.ileye@oasiscareandtraining.org.uk |
| A correction to an entitlement, balance or leave record | The individual’s line manager in the first instance, or the Compliance Officer |
| To report a suspected data breach or misuse of the system | Either address above, immediately and without waiting for certainty |
| Accountable owner | Mohamed Yusuf, Executive Director |
| Registered office | 24–32 Murdock Street, London, SE15 1LW |
An individual who is not satisfied with the response received may complain to the Information Commissioner’s Office. The organisation asks to be given the opportunity to resolve the matter first, but there is no obligation to do so.
| Information Commissioner’s Office | Contact |
|---|---|
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
| Telephone | 0303 123 1113 |
| Website | www.ico.org.uk |
14. Related documents and references
- Data Protection Framework, OASIS/DP/FRAMEWORK/001, including Annex A joint controller arrangement.
- Staff Leave Suite Data Protection Impact Assessment, OASIS/DP/DPIA/002.
- Appropriate Policy Document, OASIS/DP/APD/001.
- Transfer Risk Assessment, OASIS/DP/TRA/001.
- UK General Data Protection Regulation, in particular Articles 5, 6, 9, 13, 14, 22, 28, 32 and 44 to 49.
- Data Protection Act 2018, in particular Schedule 1, Part 1, paragraph 1 and Part 4, paragraph 5.
- Working Time Regulations 1998; Employment Rights Act 1996.
- Information Commissioner’s Office, Employment practices and data protection: workers’ health, 2023.