University Council members
The University of Exeter (the “University”) is a data controller and is committed to protecting your personal data and working in accordance with all relevant data protection legislation. The University collects and processes personal data relating to members of Council and Council Committees in order to fulfil its legal and regulatory responsibilities, and ensure governance arrangements are in place to manage the effective operation of Council. The information is also utilised to support members to discharge their responsibilities and to help support their ongoing training and development
This Privacy Notice explains how the University will collect, use and share your personal data. It sets out your rights in relation to your personal data and your responsibility should we need to share other people’s personal data with you.
What data do we hold
Governance Services will collect and store data relating to your membership of Council and its Committees. This may include:
- Name
- Date of birth
- Protected characteristics and any other relevant personal information for inclusion in the Council Skills matrix
- Contact information (including Email address, postal address, telephone numbers)
- Emergency contact details
- CVs (including job title, employment history, educational background, qualifications, employment history, board experience and voluntary appointments)
- Register of interests
- Reasonable adjustments and access requirements
- Dietary requirements
- Bank account details to enable us to reimburse Council member expenses
- Copies of passport
- Car registration number
- A professional portrait photograph
- Electronic signature
- Biographical details
- Skills and experience
Some of the information collected by the University may constitute "special category" personal data under UK data protection legislation, including information relating to protected characteristics, health conditions, reasonable adjustments, accessibility requirements and certain dietary requirements. The University will only process such information where necessary and where an appropriate lawful basis and condition for processing applies.
Where your data is collected from
Your personal data is collected from the following sources:
- Information you provide directly through application forms, CVs, correspondence, identity documents, interviews and discussions with the University.
- Governance Services declaration forms completed during your term of office and information provided during meetings, consultations and other governance activities.
- Third parties, including referees provided as part of your application or appointment process.
- Publicly available sources, including company registers, charity registers, professional profiles, regulatory publications, websites and open-source information where this is necessary to undertake due diligence checks, verify information provided by you, assess eligibility for appointment, or fulfil regulatory obligations such as the Fit and Proper Person Assessment requirements.
How we use your data
The University will use your data to fulfil a range of duties aligned with legal obligations, regulatory requirements and governance duties.
| Area | Requirement |
|---|---|
| Office for Students | The University must comply with the OfS regulatory framework as set out in the Higher Education and Research Act 2017. This includes compliance with ongoing conditions of registration with the Office for Students (OfS), including the E Conditions (Good Governance). |
| Employment regulations | The Governance Services team collect personal information for recruitment in line with the right to work guidance and the Equality Act 2010. |
| Financial regulations | The Finance Act 2010, UK Money Laundering Regulations 2007, The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and the Economic Crime and Corporate Transparency Act 2023. |
| Charity Law | The University of Exeter is an exempt charity under the terms of the Charities Act 2011 (Schedule 3) and is required to adhere to charity law. The University also follows Charity Commission guidance on conflicts of interest for charity trustees. |
The University will process your personal data for the following purposes:
- Information required by the OfS, such as details of all other directorships and trusteeships held at other organisations or changes to the Membership of the University Council
- Conducting a Fit and Proper Person Assessment in accordance with the requirements of the Regulator and the CUC HE Code of Governance
- Publishing a Register of Interests containing declarations from each Member of the Council
- Maintaining a skills matrix to ensure the Council has the optimal range of skills, expertise and backgrounds to effectively govern the Institution and a robust framework to support succession planning and recruitment
- Preparing audited annual reports and financial statements, including individual attendance records at Council and Council Committee meetings
- Preparing the University’s annual data submission to the Higher Education Statistics Agency (HESA) regarding the governing body
- Facilitating attendance at institutional events (including degree congregation ceremonies)
- Committee and meeting management, including making arrangements for attendance at meetings, external training sessions or conferences
- Publishing an individual biography for each Council Member on the University’s website
- Publishing individual portrait photographs and group photographs on the University’s website
- Developing a skills and experience matrix to aid the University in recruiting new Members to Council
- Processing Members’ expenses claims
- Monitoring levels of engagement, including pre-reading materials
- Managing Members’ access to University facilities, including: buildings, digital and IT systems
- The University may undertake identity verification, sanctions screening, insolvency checks and regulatory due diligence checks where required for governance and regulatory compliance. This strengthens transparency around the passport copy, date of birth and public register searches.
Special category personal data
Where necessary, the University may process special category personal data relating to protected characteristics, reasonable adjustments, accessibility requirements, health information or dietary requirements to:
- Meet its obligations under equality and accessibility legislation
- Ensure appropriate support and adjustments can be provide
- Monitor the diversity, effectiveness and composition of Council membership
- Facilitate safe participation in meetings, events and University activities
The University will only process such information where a valid condition under Article 9 UK GDPR applies.
How we will share your data
Your information will be shared internally with University staff who need the information for administrative purposes, this may include:
- IT Services to ensure you can access the information required to fulfil your role effectively
- Event Exeter to ensure appropriate dietary and access requirements are accommodated
- Estate Patrol to facilitate car parking
The information will be placed in the public domain in respect of:
- Members’ biographies published on the University website
- The University Register of Interests
- The University annual report and financial statements
- Live-streamed graduation / institutional celebratory events
- Other University publications
It will be necessary to share your University email address with the University’s board portal provider to ensure that you can access meeting papers and key information provided to support you in your role.
It may also be necessary to share your personal data with:
- The Office for Students (OfS)
- The Higher Education Statistics Agency (HESA)
- The University’s banks, insurers, legal advisors, and internal and external auditors
- UK government bodies and departments responsible for public funding, statistical analysis, monitoring and auditing, sponsorship, or regulatory matters
- External training providers, sector networks or bodies, when making bookings on Members’ behalf
- Hotels, travel and transport providers, when making bookings on Members’ behalf
- Contractors or suppliers the University might engage to carry out services that may involve or require Members’ data
Where the University engages third parties to process personal data on its behalf, they do so on the basis of written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
International transfer
The University does not routinely transfer personal data relating to Council Members outside the United Kingdom. Where it is necessary for personal data to be transferred internationally, including through the use of third-party service providers, the University will ensure that appropriate safeguards are in place in accordance with UK data protection legislation.
How we protect your data
The University takes the security of your personal data seriously. Your data will be stored securely within the University’s document and email systems. Access to the data is controlled. Staff processing the data receive relevant training on data protection and information security. Where there is a statutory obligation to publish this data, you will be notified of such instances, for example, publication of your Declaration of Interest.
Personal data will only be retained for as long as necessary to fulfil the purposes for which it was collected, meet legal and regulatory obligations, resolve disputes, maintain governance records and comply with statutory retention requirements.
Your Rights and Preferences
The University will contact you by email, telephone, post or other means where necessary to administer your membership of Council and its Committees and fulfil its legal, regulatory and governance responsibilities. In limited circumstances, where consent is relied upon, you may withdraw that consent at any time.
Subject to applicable data protection legislation, you have the right to:
- Request access to your personal data;
- Request correction of inaccurate or incomplete personal data;
- Request erasure of your personal data in certain circumstances;
- Request restriction of processing in certain circumstances;
- Object to processing where the University relies on legitimate interests as its lawful basis;
- Request transfer of your personal data to another organisation where applicable;
- Withdraw your consent at any time where processing is based on consent;
- Lodge a complaint with the Information Commissioner's Office (ICO).
On completion of your term of office as a Council Member or Committee Member, the University will retain your personal data in accordance with its records retention requirements. Detailed records relating to your membership will normally be retained for six years following the end of your appointment unless a longer retention period is required by law or for regulatory purposes.
The University will retain a permanent historical record of your membership, including your name, dates of service and positions held, as part of the University's corporate governance record and institutional archive.
Financial records will be retained for the period required by law and financial regulations.
Data sharing obligations
On occasions, you may be required to process personal data on behalf of the University. You must ensure that you only use the personal information for the reasons specified and in particular you must take reasonable steps to ensure the security of the information in line with data protection legislation. You must not disclose any Personal Data to any third party other than at the request of the University. You must notify the University immediately if any personal data is lost or damaged, or if you become aware of any unauthorised access or use of the personal data (the University has an obligation to report data breaches to the ICO within 72 hours). If a data security incident occurs, you must immediately notify the University's Information Governance Team at InformationGovernance@exeter.ac.uk
You must delete or return the data to the University when you are no longer using it on behalf of the University.
Automated decision-making
The University does not use your personal data for solely automated decision-making, including profiling, that produces legal effects or similarly significant effects on you.
Legal basis
The University processes your personal data under the following lawful bases set out in Article 6 UK GDPR:
- Article 6(1)(c) - Legal obligation, where processing is necessary to comply with legal and regulatory requirements, including those arising under charity law, higher education regulation, financial legislation and other statutory obligations.
- Article 6(1)(e) - Public task, where processing is necessary for the University to carry out its functions as a higher education provider and exempt charity.
- Article 6(1)(f) - Legitimate interests, where processing is necessary for the effective governance, management and administration of the University, provided these interests are not overridden by your rights and freedoms.
Where the University processes special category personal data, it will do so in accordance with Article 9 UK GDPR and applicable provisions of the Data Protection Act 2018, including where processing is necessary for reasons of substantial public interest, equality monitoring, or to fulfil obligations relating to accessibility and inclusion.
In limited circumstances, the University may rely on consent as its lawful basis for specific processing activities. Where consent is relied upon, you may withdraw that consent at any time.
Further information
If you have any questions regarding this Privacy Notice please do not hesitate to contact us at governance-services@exeter.ac.uk
This Privacy Notice was last updated in August 2026.