ACCELERATE INTERNATIONAL ACADEMY LTD
UK GDPR DATA PROTECTION POLICY & PROCEDURES
Version: 2.0
Effective Date: 01 MARCH 2025
Review Date: Annually (or upon legal/regulatory change)
Approved by: Director(s) of Accelerate International Academy Ltd
1. POLICY STATEMENT
Accelerate International Academy Ltd (“AIA”, “we”, “us”) is committed to protecting the rights and freedoms of individuals whose personal data we process, including learners, applicants, staff, freelancers, partners, and stakeholders.
We comply with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
We process personal data lawfully, fairly, transparently, and securely, and we can demonstrate compliance at all times.
2. SCOPE
This policy applies to:
- All staff (employed, freelance, contractors, volunteers)
- All learners and applicants
- All digital systems (LMS, CRM, email platforms, cloud storage)
- All data processing activities undertaken by AIA in the UK and internationally
3. DATA PROTECTION PRINCIPLES
AIA adheres to the seven UK GDPR principles:
We ensure data is:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit, legitimate purposes
- Adequate, relevant, and limited to what is necessary
- Accurate and kept up to date
- Stored only as long as necessary
- Processed securely using appropriate technical/organisational measures
- Accountable – we can demonstrate compliance
4. ROLES AND RESPONSIBILITIES
4.1 Data Controller
Accelerate International Academy Ltd is the Data Controller for all personal data it determines the purposes and means of processing.
4.2 Senior Responsibility
The Director(s) are ultimately responsible for GDPR compliance.
4.3 Data Protection Lead (DPL)
Responsible for:
- Compliance oversight
- Managing subject access requests (SARs)
- Breach coordination
- Policy implementation
- Staff training coordination
4.4 Staff Responsibilities
All staff must:
- Handle data in line with this policy
- Complete GDPR training
- Report breaches immediately
- Only access data required for their role
5. LAWFUL BASIS FOR PROCESSING
AIA will only process personal data where a lawful basis applies:
We rely on:
- Contract (learner enrolment, programme delivery)
- Legal obligation (funding/reporting requirements)
- Legitimate interests (programme improvement, safeguarding systems)
- Consent (marketing communications where required)
Special category data (e.g. health, ethnicity, safeguarding) is processed under:
- Explicit consent OR
- Substantial public interest (e.g. safeguarding obligations)
6. TYPES OF DATA PROCESSED
We may process:
Learner Data
- Name, DOB, contact details
- Education history
- Employment or Education status
- Programme engagement records
- Assessment and progression data
Special Category Data (where applicable)
- Disability and support needs
- Ethnicity
- Health information (reasonable adjustments)
- Wellbeing status
- Safeguarding concerns
Staff/Contractor Data
- Payroll details
- DBS checks
- Training records
Digital Data
- IP addresses
- LMS activity logs
- Email correspondence
7. DATA COLLECTION AND TRANSPARENCY (PRIVACY NOTICES)
At the point of collection, AIA will provide a clear privacy notice including:
- Identity of controller
- Purpose and lawful basis
- Data retention periods
- Data sharing arrangements
- Individual rights
- Complaint rights (ICO)
Privacy notices will be:
- Written in plain English
- Accessible on all forms and digital systems
- Reviewed annually
8. DATA SHARING
We may share data with:
- Local authorities
- Funding bodies
- Referral partners (e.g. employers, placement partners)
- Safeguarding partners (when necessary)
- Approved subcontractors (training delivery)
- Approved suppliers (workbook printers, IT systems)
9. DATA RETENTION
AIA applies strict retention rules:
| Data Type | Retention Period |
| Learner records | 7 years after programme completion |
| Safeguarding records | 25 years or statutory requirement |
| Finance records | 7 years |
| Staff records | 7 years after employment ends |
| Marketing data | Until consent withdrawn or 24 months inactivity |
Data is securely deleted or anonymised at end of retention.
10. INDIVIDUAL RIGHTS PROCEDURE
All individuals have rights under UK GDPR:
- Right of access (SAR)
- Right to rectification
- Right to erasure (where applicable)
- Right to restrict processing
- Right to data portability
- Right to object
- Rights relating to automated decision-making
SAR Procedure
- Request received (any format)
- Identity verification
- Logged in SAR register
- Response within 1 calendar month
- Extensions only where legally justified
- Redactions applied where third-party data exists
11. DATA SECURITY MEASURES
AIA implements appropriate security controls:
Technical Controls
- Password protection & MFA
- Encrypted cloud storage
- Access control restrictions
- Secure backups
- Antivirus/firewall protection
Organisational Controls
- Role-based access
- Confidentiality agreements
- Staff training
- Clean desk policy
- Device security requirements
12. DATA BREACH PROCEDURE
A breach includes accidental or unlawful:
- Loss
- Alteration
- Disclosure
- Access
Procedure:
- Immediate reporting to Data Protection Lead
- Containment actions taken
- Risk assessment completed
- Breach logged in register
- ICO notified within 72 hours if required
- Affected individuals notified if high risk
- Post-incident review completed
13. TRAINING AND AWARENESS
All staff must complete GDPR training:
- Induction training (mandatory)
- Annual refresher training
- Role-specific safeguarding/data training
Training includes:
- Data handling
- Security procedures
- Subject rights
- Breach identification
Records are maintained for audit purposes.
14. DATA PROCESSING RECORDS (ROPA)
AIA maintains a Record of Processing Activities including:
- Purpose of processing
- Categories of data
- Legal basis
- Data sharing
- Retention periods
- Security measures
This is reviewed quarterly and annually or when processes change.
15. DATA PROTECTION IMPACT ASSESSMENTS (DPIA)
A DPIA is required when processing is likely to result in high risk, such as:
- Large-scale learner tracking
- Use of new digital platforms
- Special category data processing
DPIAs are approved by senior management before implementation.
16. INTERNATIONAL DATA TRANSFERS
If data is transferred outside the UK:
- Adequacy decision must exist OR
- Standard Contractual Clauses (SCCs) must be in place
- Additional risk assessments completed
17. COMPLAINTS AND ESCALATION
Individuals may:
- Contact AIA directly at info@accelerate-international.com
- Escalate to Data Protection Lead
- Contact the Information Commissioner’s Office (ICO)
18. MONITORING AND AUDIT
We will:
- Conduct annual GDPR compliance reviews
- Audit data processing systems
- Monitor training completion
- Review breaches and incidents
- Update policies in line with legal changes
19. POLICY GOVERNANCE
This policy is:
- Approved by AIA Directors
- Reviewed annually
- Updated in response to ICO guidance or legal changes
- Communicated to all staff and subcontractors