Policies & GDPR

1. Introduction
We (the “School”, “we”, “our” or “us”) are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and disclose personal data about individuals in accordance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR (as applicable), and the Data Protection Act 2018.

This Policy applies to all personal data processed by or on behalf of the School, including data collected through our website, in writing, by telephone, or in person.

2. Data Controller
The School is the data controller responsible for your personal data. Our contact details and those of our Data Protection Officer (DPO) are provided at the end of this Policy.

3. What Personal Data We Collect
We may collect and process the following categories of personal data:

  • Identity and contact information: names, addresses, email addresses, telephone numbers;
  • Education-related information: student records, class information, academic results, attendance data;
  • Communications: correspondence between you and the School;
  • Financial information: where applicable, payment details and transaction records;
  • Safeguarding and health data: medical or social care information needed to provide safe and effective services;
  • Online identifiers: IP addresses and cookie data when you use our website.

4. How We Use Personal Data (Purposes & Lawful Bases)
We process personal data for a range of legitimate purposes, including:

  • Providing educational and wellbeing support;
  • Administering admissions, enrolment and school operations;
  • Communicating with students, parents, staff and stakeholders;
  • Complying with legal obligations (for example, safeguarding and statutory reporting);
  • Managing health, safety and security on our premises.

Where required by law, we rely on one or more lawful bases for processing, including: contract performance, legal obligation, legitimate interests, consent (where applicable), and protection of vital interests.

5. Sharing Your Personal Data
We may share personal data with:

  • Local or national authorities (such as educational bodies or regulators);
  • Service providers and partners who assist us in the operation of our services (e.g. IT, transport, catering, extracurricular programme providers);
  • Law enforcement or other bodies where required by law.

Where data is transferred outside the UK or the European Economic Area (EEA), appropriate safeguards are in place to protect your personal data.

6. Data Security and Storage
We implement appropriate technical and organisational measures to safeguard personal data against unauthorised access, loss or damage. Personal data is retained only for as long as necessary for the purposes for which it was collected and in accordance with legal and regulatory requirements.

7. Your Rights
Under GDPR, you have the right to:

  • Be informed about how your personal data is used;
  • Request access to your personal data;
  • Request correction of inaccurate data;
  • Request erasure in certain circumstances;
  • Restrict or object to processing;
  • Request data portability;
  • Lodge a complaint with a supervisory authority.

If you wish to exercise any of these rights, please contact the School’s DPO using the details below.

8. Cookies and Online Tracking
Our website uses cookies and similar technologies to improve functionality and user experience. You can manage your cookie preferences through the cookie consent settings provided on our website.

9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law or our data practices. The latest version will always be published on our website.


Contact Details / Data Protection Contacts

Data Controller:
Prague British International School, s.r.o.
K Lesu 558/2, 142 00 Praha 4 – Kamýk, Czech Republic
Company ID (IČO): 27653048

Primary Contact Information:
Tel: +420 226 096 200
General Email: info@pbis.cz
Admissions Email: admissions@pbis.cz
Website: www.nordangliaeducation.com/pbis-prague

Data Protection Officer (DPO):
Email: privacy@pbis.cz
(Note: This is the contact address listed for the DPO role in the official policy.)

Supervisory Authority:
• For Czech Republic (EEA): The Office for Personal Data Protectionhttps://www.uoou.cz/en/
• For UK (if applicable): Information Commissioner’s Office (ICO)https://ico.org.uk/

If you wish to exercise any data protection rights — including requests for access, correction, deletion, restriction, objection or data portability — or if you have any questions regarding this Privacy Policy or the processing of your personal data, please contact the School’s Data Protection Officer at the email address above.