Data Protection & Privacy Policy
Introduction
Yokohama International School is committed to safeguarding all personal information collected, stored and processed during the course of all educational activities and school operations. All data is handled in accordance with legal requirements including Japan’s Act on the Protection of Personal Information (APPI).
This Data Protection Policy should be read in conjunction with the school’s other policies and terms and conditions which make reference to personal data.
This policy applies to all personal information processed about current, past, and prospective students, parents / guardians, staff / faculty members, donors, suppliers / contractors, and any other parties with whom the school communicates or engages. These parties are collectively referred to as “data subjects” throughout this policy.
All YIS staff members are required to comply with this policy when processing personal data as part of their role.
The School Leadership Team is responsible for ensuring compliance with this policy.
This policy is overseen by the school’s Data Protection Officer (dpo@yis.ac.jp).
Data Protection Principles
YIS handles all personal information in accordance with key data protection principles which guide how it collects, uses, stores, and protects data.
Data Minimization
YIS only collects the personal information needed to fulfill the school’s educational mission and to operate the school effectively.
Storage Limitation
YIS only keeps personal data for as long as necessary. A retention schedule specifies how long different types of information are kept, and data is deleted or destroyed once it is no longer required.
Accuracy
YIS keeps personal data accurate and up to date through regular verification processes and data update requests.
Security and Confidentiality
YIS protects personal data using security measures such as requiring strong passwords, 2-Step verification, and encrypted data storage to prevent unauthorized or unlawful access, loss, destruction, or damage. There are organizational and technical safeguards in place to ensure the confidentiality, integrity, and availability of the personal information processed. Security practices are regularly reviewed and assessed in order to maintain data protection and integrity.
Types of Personal Data
There are two categories of personal data collected and processed by the school.
Personal Data / Personal Information
Personal information is any information relating to an individual who can be identified using that information.
This includes:
- Names and contact information
- Images and videos
- Family information
- Dates of birth
- Nationality and ethnicity
- Educational history and academic records
- ID numbers related to official documents
- Payment and donation records
- Employment information
- Other information necessary for school operations
This data is collected through various means including forms, applications, and direct communication with the data subject(s). In some cases, data is collected from third parties, such as previous schools or organizations as a part of engagement with YIS.
Special Categories of Personal Data (Sensitive Information)
Some personal information is highly sensitive and requires additional care. This includes:
- Medical information
- Social Status
- Victim Status
- Criminal Record
These categories are handled with extra security measures and information in this category is only collected when necessary for school operations or when voluntarily provided.
Consent
Personal data is processed whenever a data subject communicates or interacts with YIS — for example, when asking general questions or requesting a school tour. This data is handled in accordance with the principles described in this policy.
When candidates apply for enrollment or employment, or when a student is enrolled at YIS, more detailed personal information is collected, processed and stored, including sensitive data such as medical information, as described in this policy.
Personal Information Processing
Personal information collected by YIS is solely used to operate the school and to provide educational services to the school community. Information is only used for school operational purposes.
These purposes include:
- Admissions and enrollment procedures
- Managing classes and educational programs
- Student learning and development
- Communication with community members (emails, notices, emergency contacts)
- Safety and security (emergency contacts, medical needs, bus information)
- Events and activities
- Creating student and family directories
- Issuing certificates and transcripts
- Financial aid management
- Fundraising activities
- Facility management and IT services
- Compliance with legal requirements
- Synchronizing data between digital platforms in order to provide school functions and services
- School operations and administration procedures
Data Access
YIS shares personal information within the school, and with select parties outside the school, only in ways which support school operations and student wellbeing, as follows:
Data Access Within YIS
Personal Data / Personal Information is accessed by:
- staff and faculty, for academic and support purposes
- parents, via school-managed platforms, in order to engage with their child’s learning and school community
Special-Category Personal Data (Sensitive Information) is accessed by:
- health staff, in order to provide health care to students & staff
- designated staff, in order to securely record and access behavioural, social-emotional, learning support, safeguarding, and child protection information in order to support student wellbeing, safety, and learning
- school staff, for use during sports trips or field trips in order to ensure safety, such as providing emergency contact or allergy information
Data Access Outside of YIS
Personal Data / Personal Information is provided to:
- vetted third-party service providers, in order to provide services such as school expeditions and trips
- schools and universities for university applications by way of transcripts or other academic records
- government bodies via data requests when required for legal compliance or regulatory purposes
Special-Category Personal Data (Sensitive Information) is provided to:
- vetted third-party service providers, in order to provide services such as medical or emergency care to students on expeditions and trips
- medical institutions, as required in order to provide health and emergency care to students and staff
YIS never sells personal information. YIS never divulges personal information to any third party except as described above.
Data Storage Locations
YIS uses cloud-based services and vendors to store and manage data. Some services store school data on servers located outside of Japan. The school selects reputable cloud-based service providers which are committed to maintaining high security standards and reputable data protection practices in accordance with applicable legal requirements.
Data Rights
Data subjects have important rights regarding how their personal information is used. YIS is committed to honoring these rights and making it easy for data subjects to exercise them.
Right to Disclosure
Data subjects have the right to request information about the personal data held on them. This allows subjects to understand what information the school holds about them and how it is used.
Right to Rectification
The school provides ways for data subjects to directly provide, update, or correct details for themselves and/or their families, such as email addresses and telephone numbers. Data subjects have the right to ask the school to correct any inaccurate personal information held about them.
Right to Erasure
Data subjects have the right to request that the school delete their personal data in certain circumstances, such as when the data is no longer needed for its original purpose. However, there are some exceptions where the school must retain data due to legal obligations, safeguarding requirements, or operational purposes. There are also exceptions where the data has already entered the public domain and deletion is not possible or impractical, such as in the case of widely circulated publications. Depending on the scope of the request, erasure may take up to 30 days to complete.
Right to Freedom From Discrimination
All data subjects are entitled to exercise their data rights without facing discriminatory treatment. Where the withdrawal of consent affects the availability of certain services or tools, the school will make reasonable efforts to ensure that the quality of a student’s educational experience is maintained.
Right to Object
Data subjects have the right to object to certain uses of their personal data. When an objection is raised, the school will stop processing the data for those purposes unless there are compelling legitimate grounds to continue.
Right to Withdraw Consent
When the school relies on consent as the legal basis for processing personal data, data subjects have the right to withdraw that consent at any time. However, some data processing is essential for the school to provide educational services and fulfill its operational responsibilities. If consent is withdrawn for processing that is necessary for enrollment or employment, it may affect the school’s ability to continue that relationship.
Exercising Data Subject Rights
All data requests should be directed to the school’s Data Protection Officer (dpo@yis.ac.jp).
Incidents and Breaches
The school manages data protection incidents in accordance with the process set out in its Incident & Breach Policy. As part of this process, all staff members are required to follow specific guidelines on reporting data incidents, including completing a data incident form which will be investigated and logged.
Impact Assessments
The school carries out a Data Protection Impact Assessment when the processing of personal data may present a risk to the rights and freedoms of individuals. This process is designed to identify the nature of the risks so that mitigating actions can be taken to reduce or eliminate these risks.
The school has a process in place for staff members to follow, which includes guidance about when a Data Protection Impact Assessment is required.
Policy Review and Updates
This policy is reviewed annually and updated as needed to reflect changes in school operations or legal requirements. Parents are notified of material changes to this policy by email, and the updated policy is posted in the school handbooks. The current version of this policy can be found in the school handbooks and as part of applications for enrollment and employment.