The Glasgow School of Music · Cookies
Cookie Policy
How cookies and other storage and access technologies are used on our website.
This Cookie Policy explains how The Glasgow School of Music uses cookies and other technologies that store information on, or access information from, a visitor’s device, what they are used for and how visitors can exercise consent or objection choices.
Last updated: 25 July 20261. What are cookies?
Cookies are small text files placed on a device when a website is used. They can support security, session management, preferences, website measurement and third-party features.
The same legal rules can also apply to other storage and access technologies, including local storage, tracking pixels, scripts, tags, link decoration, device fingerprinting and embedded third-party tools.
First-party technologies are set or controlled through the GSofM website. Third-party technologies are supplied by another provider, for example an embedded media, analytics, security, payment or administration service. The legal requirements depend on purpose and operation, not merely on whether a technology is first party or third party.
2. How we use cookies
The Glasgow School of Music website may use storage and access technologies for the purposes below, depending on the features and services currently enabled:
- Providing requested website functions, session handling and security
- Recording cookie consent, rejection and objection choices
- Remembering a visitor-selected display or functional preference
- Operating forms, fraud prevention and technical fault detection
- Collecting limited aggregate statistics to improve the website, where the statutory statistical-purpose exception is fully satisfied
- Operating consent-based analytics where the use goes beyond that narrow exception
- Loading embedded maps, videos, media, forms or other third-party features where enabled and lawfully activated
- Advertising, campaign measurement or profiling only where deliberately enabled and valid prior consent has been obtained
This policy does not state that every technology or provider mentioned is active. The live cookie register and consent controls should reflect the website’s current configuration.
3. Consent requirements and legal exceptions
Communication and strictly necessary uses
Consent is not required where storage or access is solely necessary to transmit a communication or is technically essential to provide an online service requested by the visitor. Examples may include load balancing, authentication, requested form operation, security, fraud prevention or remembering cookie choices.
A technology is not strictly necessary merely because it is useful to GSofM, improves general convenience or supports advertising revenue. The assessment is made from the visitor’s perspective and the use must not be extended to another purpose.
Statistical-purpose exception
From the 2026 PECR changes, a narrow statistical-purpose exception may apply where the sole purpose is collecting statistical information about how the website is used with a view to improving it.
To rely on this exception, the information must be used for aggregate website statistics rather than identifying, tracking, profiling or making decisions about individuals. Individual-level personal data must not be retained longer than necessary for aggregation, any provider must act only to help improve the service, visitors must receive clear information, and a simple free means of objecting must be available.
If the analytics are also used for advertising, cross-site tracking, profiling, audience creation or another purpose, the exception does not apply and prior consent is required.
Appearance and functionality exception
A narrow appearance exception may apply where the sole purpose is adapting how the website appears or functions in line with a visitor’s preference, such as remembering a selected language, display setting or suitable interface preference.
This exception requires clear information and a simple free means of objecting. It does not cover personalised content, behavioural recommendations, profiling or advertising.
Consent-based functional and analytics uses
Functional or analytics technologies that do not satisfy an exception must remain disabled until the visitor gives valid consent. Consent must be freely given, specific, informed and indicated by a clear positive action.
Advertising, marketing and profiling
Storage and access technologies used for advertising, remarketing, advertising measurement, cross-site or cross-device tracking, audience creation or profiling require prior consent. GSofM cannot rely on the statistical, appearance or strictly necessary exceptions for those purposes.
Third-party and embedded technologies
Third-party status does not itself determine whether consent is needed. Each provider, purpose and data flow must be assessed. An embedded feature that uses non-exempt technologies should normally be blocked until consent or activated only after a sufficiently informed and deliberate user request where the requested-feature rules apply.
4. Current cookie and technology register
The exact technologies can change when website plugins, forms, media, analytics, security or consent settings change. GSofM should maintain an up-to-date live register through the active consent preference panel or an equivalent cookie declaration.
| Purpose | Possible legal route | Required control |
|---|---|---|
| Transmission, requested service, security, authentication, fault detection or consent storage. | Communication or strictly necessary exception, where every condition is met. | Clear information; no consent required for the exempt purpose. |
| Aggregate statistics used solely to improve the GSofM website. | Statistical-purpose exception where the use remains aggregate, limited and non-advertising. | Clear information and a simple free means of objecting. |
| Remembering or adapting a visitor-selected appearance or functional preference. | Appearance exception where the sole-purpose and data-minimisation conditions are met. | Clear information and a simple free means of objecting. |
| Functional, analytics or embedded technologies outside an exception. | Prior consent. | Off by default, granular choice and equally accessible rejection. |
| Advertising, remarketing, profiling, cross-site tracking or advertising measurement. | Prior consent; no PECR exception applies. | Off by default, explicit purpose information and consent withdrawal. |
The live register should identify each technology’s name, provider, purpose, category, first-party or third-party status and expiry or storage period. Durations should be no longer than necessary. The register and consent banner must match the technologies actually deployed; generic examples are not a substitute for a current technical audit.
5. Managing consent and objection preferences
Where consent is required, the website’s consent mechanism should provide equally prominent options to accept or reject non-exempt technologies and a clear route to customise different purposes. Non-exempt toggles must be off by default.
Consent is not given by silence, inactivity, scrolling or continuing to use the website. Rejecting non-exempt technologies must be as easy as accepting them.
Visitors should be able to manage choices by:
- Using the cookie banner or persistent Cookie Settings control on the website
- Accepting, rejecting or customising non-exempt purposes
- Objecting to statistical-purpose or appearance uses where GSofM relies on those exceptions
- Withdrawing consent later with the same ease as giving it
- Using browser controls to block or delete stored technologies as an additional measure
Browser settings alone are not treated as the website’s consent or objection mechanism. Blocking some technologies may prevent an optional embedded feature or preference from operating, but refusal must not prevent access to the website’s core information unless the technology is genuinely necessary for the requested service.
6. Consent, objections and changing choices
Where no exception applies, GSofM must obtain prior consent before storing information on, or accessing information from, a visitor’s device. Associated personal-data processing should normally use consent as the UK GDPR lawful basis where PECR consent is required.
The consent mechanism must function as described, record the choice appropriately, provide granular purpose controls and prevent non-exempt technologies from loading before consent. Legitimate interests cannot be used inside the consent mechanism to bypass PECR consent requirements.
Consent can be withdrawn at any time with the same ease as it was given. Withdrawal should stop the technologies and associated consent-based processing, remove them where technically possible, and communicate the withdrawal to relevant third parties where required.
Where GSofM relies on the statistical-purpose or appearance exception, visitors must instead receive clear information and a simple free way to object. Once a visitor objects, the exempt storage or access must stop unless the visitor later changes that choice.
GSofM should not repeatedly prompt a visitor who has rejected non-exempt technologies. A fresh request may be appropriate after a reasonable period or where the purposes, providers or technologies materially change. ICO guidance identifies approximately six months as a general benchmark before routinely requesting consent again after refusal.
7. Third-party services and embedded content
Some website functions may depend on third-party services. Depending on the current site configuration, these can include WordPress or hosting technology, security and performance services, form tools, analytics, maps, video or media, consent management, payments, and student administration or booking links.
The appearance of a provider in this list does not confirm that it is currently active or that it sets cookies. The live register should identify the providers actually deployed and their purposes.
Non-exempt third-party scripts and embedded content should not load before the required consent. A blocked map or video may offer a feature-led choice: after clear information, a visitor can deliberately request that specific content, at which point technology strictly necessary to provide the requested feature may be activated. Any tracking or additional purpose beyond the requested feature still requires the appropriate consent.
Following an ordinary external link takes the visitor to another provider’s website, where that provider’s own privacy and cookie information applies. GSofM should assess its own responsibility for technologies embedded directly into the GSofM website, including provider contracts, data sharing and international transfers where personal data is involved.
8. Updates to this Cookie Policy
We may update this Cookie Policy if our website, plugins, providers, storage and access technologies, consent settings or legal obligations change.
The cookie register and consent mechanism should be reviewed whenever a relevant technology, provider or purpose changes and periodically through a technical scan. Material changes to a consent-based purpose require fresh consent before the changed use begins.
The latest version will be published on this page with the updated date shown above.
9. Contact us
If you have a question, believe a technology has loaded contrary to your choice, or cannot access the preference controls, contact GSofM. A data-protection concern may also use the Privacy Policy or Complaints, Concerns & Feedback route.
The Glasgow School of Music
542 Scotland Street West, Kinning Park, Glasgow, G41 1BZ
Email: info@theglasgowschoolofmusic.co.uk
Telephone: 07922 546713
Need to change your cookie preferences?
Use the persistent Cookie Settings control supplied by the active consent mechanism. It should allow consent withdrawal, rejection and objection choices without requiring an email. Browser controls remain an additional way to delete or block stored technologies.
Cookie support
Questions about cookies or website tracking?
Contact the school if you have questions about this Cookie Policy, privacy settings or how website technologies may be used.