Privacy Notice
Effective Date: 1 September 2026
Service name
Baskerville National Compute Resource
Service description
Baskerville is a High-Performance Computing (HPC) service providing computational resources and associated facilities to researchers and their collaborators.
Scope
This notice explains how personal data is processed in connection with the operation, administration, support, and security of the Baskerville service.
This notice should be read alongside the University of Birmingham’s Privacy Notices, Data Protection Policy, Baskerville NCR Acceptable Use Policy and other applicable University policies.
Data Controller
University of Birmingham
Edgbaston
Birmingham B15 2TT
United Kingdom
Service Contact: dataprotection@contacts.bham.ac.uk
Data Protection Officer
The University’s Data Protection Officer can be contacted at:
The Data Protection Officer
Legal Services
The University of Birmingham
Edgbaston
Birmingham
B15 2TT
Email: dataprotection@contacts.bham.ac.uk
Telephone: +44 (0)121 414 3916
Jurisdiction and supervisory authority
The service is operated by the University of Birmingham in England, United Kingdom.
Information about data protection rights and how to make a complaint to the Information Commissioner’s Office (ICO) is available through the University’s privacy webpages and the ICO website.
Personal data processed
Information provided by your home organisation
Where federated authentication is used, the service may receive:
- Unique user identifier
- Username
- Name
- Email address
- Institutional affiliation
- Organisation
- Affiliation and entitlement information provided by identity federations
- Project allocation information
- Other attributes required to provide access to the service
Information generated through use of the service
The service may process:
- Account and project membership information
- Authentication and access records
- Resource usage information
- Security and audit logs
- Support requests and correspondence
Purpose of processing
Personal data is processed for the purposes of:
- Providing access to the service
- Authenticating and authorising users
- Managing accounts and project memberships
- Operating, maintaining, and securing the service
- Providing user support
- Monitoring service usage and performance
- Investigating misuse, incidents, or security concerns
- Meeting legal, regulatory, contractual, and reporting obligations
Disclosure of personal data
Personal data may be shared where necessary with:
- Authorised University staff responsible for operating, supporting and securing the service
- Project administrators for service administration purposes
- UK Research and Innovation (UKRI) where required for service governance, reporting, allocation management, audit, or compliance purposes
- Approved contractors or service providers providing support, maintenance, or security services to the platform where access is necessary to perform those functions
- Regulators, law enforcement agencies, or other bodies where disclosure is required by law
Transfer of personal data
The University may share personal data with approved contractors, service providers, and partners where necessary to provide, maintain, support, secure, or govern the Baskerville service.
We require those companies to keep your personal data confidential and secure and to protect it in accordance with the law and our policies. They are only permitted to process your data for the lawful purpose for which it has been shared and in accordance with our instructions.
Data held and used by the University are compliant with GDPR. Personal data stored by a service provider within the cloud may be stored outside of the European Economic Area.
Research data
Researchers are responsible for ensuring that any research data stored or processed using Baskerville complies with applicable legal, ethical, regulatory, and contractual requirements, including data protection legislation where personal data forms part of a research dataset.
Your rights
- You have the right to information about what personal data we process, how and on what basis, as set out in this policy.
- You have the right to access your own personal data by way of a Subject Access Request (see below).
- You can correct any inaccuracies in your personal data.
- You have the right to request that we erase your personal data where we were not entitled under the law to process it or it is no longer necessary to process it for the purpose it was collected. To do so you should contact the University Data Protection Officer.
- While you are requesting that your personal data is corrected or erased or are contesting the lawfulness of our processing, you can apply for its use to be restricted whilst your request is being evaluated and actioned. To do so you should contact the University Data Protection Officer.
- You have the right to object to data processing where we are relying on a legitimate interest to do so, and you think that your rights and interests outweigh our own and you wish us to stop.
- You have the right to receive a copy of your personal data and to transfer your personal data to another Data Controller. We will not charge for this and will in most cases aim to do this within one month.
- With some exceptions, you have the right not to be subjected to automated decision making.
- You have the right to be notified of a data security breach concerning your personal data.
- In most situations we will not rely on your consent as a lawful ground to process your data. If we do, however, request your consent to the processing of your personal data for a specific purpose, you have the right not to consent or to withdraw your consent later. To withdraw your consent, you should contact the University Data Protection Officer.
Subject Access Requests and complaints
Data Subjects may make a Data Subject Access Request (“DSAR”) to find out the information we hold about them. This request must be made in writing.
If you would like to make a DSAR in relation to your own personal data, you should make this request in writing to the University Data Protection Officer. We will respond within one month unless the request is complex or numerous, in which case the period in which we must respond can be extended by a further two months.
There is no fee for making a DSAR. However, if your request is manifestly unfounded or excessive we may charge a reasonable administrative fee or refuse to respond to your request.
Additionally, any data subject can make a complaint about the way we process personal data. A data protection complaint may arise where an individual believes that the University has:
- Processed their personal data unlawfully, unfairly, or without transparency
- Failed to uphold their data protection rights (e.g. access, rectification, erasure, restriction, objection)
- Lost, misused, or disclosed personal data without authorisation
- Failed to keep personal data accurate or secure
- Retained personal data for longer than necessary
Complaints or DSARs should be submitted to the University Data Protection Officer and should specify, where possible:
- The complainant’s name and contact details
- A clear description of the concern
- Relevant dates and supporting information
- Any steps already taken to resolve the issue
Complaints may be made in writing or by email. Reasonable adjustments will be made to support accessibility requirements.
Escalation of a complaint
If the complainant or requestor is dissatisfied with the outcome of a complaint or data subject rights, you may request a review of the decision. You also have the right to complain at any time to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Website: https://www.ico.org.uk
Helpline: 0303 123 1113
Data retention
Personal data will be retained only for as long as necessary to operate, secure, and support the service and to meet legal requirements.