Data Protection and GDPR Policy

Version: 1.2

Last reviewed: 14 September 2027

1. Purpose

This policy explains how Eclipse Academy Ltd complies with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable privacy requirements.

It establishes standards for the lawful, fair, secure and transparent handling of personal information.

2. Scope

This policy applies to:

  • directors and employees;
  • tutors, assessors and internal quality assurers;
  • temporary staff and contractors;
  • recruiters and referral partners;
  • volunteers;
  • learners and applicants where relevant; and
  • third parties processing personal information on behalf of Eclipse Academy.

It covers personal information held electronically, on paper, verbally or through any other format.

3. Roles and responsibilities

The Director has overall responsibility for data-protection compliance.

The Centre Manager is responsible for:

  • responding to data-protection enquiries;
  • maintaining appropriate records;
  • coordinating rights requests;
  • managing data incidents; and
  • ensuring this policy is reviewed.

All staff and contractors must:

  • handle personal information only for authorised purposes;
  • maintain confidentiality;
  • follow security procedures;
  • report inaccuracies and security incidents immediately; and
  • complete appropriate data-protection training.

4. Data-protection principles

Personal information must be:

  • processed lawfully, fairly and transparently;
  • collected for specified, explicit and legitimate purposes;
  • adequate, relevant and limited to what is necessary;
  • accurate and kept up to date;
  • retained for no longer than necessary;
  • protected through appropriate security; and
  • processed in a way that demonstrates accountability.

5. Personal information processed

Eclipse Academy may process:

  • identity and contact details;
  • date of birth and demographic information;
  • educational history and qualifications;
  • identification and eligibility documents;
  • course applications and enrolment records;
  • Unique Learner Numbers;
  • attendance, assessment and achievement records;
  • internal and external quality-assurance records;
  • certification and progression information;
  • financial and payment records;
  • staff and contractor records;
  • complaints, appeals and disciplinary information;
  • safeguarding information; and
  • special-category information such as health, disability or special educational needs where necessary.

Only information reasonably necessary for a defined purpose should be collected.

6. Lawful processing

Before processing personal information, Eclipse Academy must identify and document an appropriate lawful basis, including:

  • contract;
  • legal obligation;
  • legitimate interests;
  • consent;
  • vital interests; or
  • public task where applicable.

Where legitimate interests are used, the interests and impact on individuals must be considered.

Consent must be freely given, specific, informed, unambiguous and recorded. It must be as easy to withdraw as it is to provide.

Processing special-category information requires both an Article 6 lawful basis and an appropriate Article 9 condition. Any additional conditions or documentation required by the Data Protection Act 2018 must also be satisfied.

7. Transparency

Individuals must receive appropriate privacy information when their information is collected or within the legally required period if it is obtained from another source.

Privacy information must explain:

  • who controls the information;
  • what is collected;
  • the purposes and lawful bases;
  • recipients;
  • retention;
  • individual rights;
  • international transfers;
  • complaint rights; and
  • automated decision-making where applicable.

The Website Privacy Notice must remain accessible through the website footer and close to online forms where practical.

8. Data minimisation and accuracy

Staff must collect only information needed for an identified purpose.

Reasonable steps must be taken to keep information accurate. Individuals should be given appropriate opportunities to update their details, and confirmed inaccuracies must be corrected promptly.

9. Information sharing

Personal information may only be shared when:

  • there is a lawful and legitimate purpose;
  • the recipient is authorised;
  • only necessary information is disclosed; and
  • appropriate security arrangements are used.

This may include sharing with awarding organisations, regulators, funders, educational institutions, service providers or public authorities.

Appropriate data-processing or information-sharing agreements must be established where required.

10. Security

Eclipse Academy will apply security measures proportionate to the sensitivity and risk of the information, including:

  • individual user accounts and secure passwords;
  • access controls;
  • locked storage for paper records;
  • secure backups;
  • supported and updated software;
  • malware and security protection;
  • secure methods of transferring sensitive information;
  • confidentiality obligations;
  • staff training; and
  • secure disposal.

Personal information must not be stored on unauthorised personal devices, accounts or applications.

11. Data retention and disposal

Personal information must be retained in accordance with Eclipse Academy’s retention requirements and any legal, contractual, regulatory, funding or awarding-organisation rules.

General periods include:

  • enquiries: normally up to 12 months;
  • unsuccessful applications: normally up to 12 months;
  • learner and qualification records: normally for at least three years after completion or withdrawal, or longer where required;
  • financial records: normally six years;
  • staff records: normally six years after employment ends; and
  • marketing information: until consent is withdrawn, an objection is received or the information is no longer required.

Information reaching the end of its retention period must be securely deleted, destroyed or anonymised unless continued retention is justified and documented.

12. Individual rights

Eclipse Academy will recognise applicable rights concerning:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent; and
  • automated decision-making.

Requests must be sent promptly to the Centre Manager. Identity may be verified before information is disclosed.

Requests will normally be answered within one month, subject to any lawful extension or exception.

13. Data breaches

A personal-data breach includes accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure; or
  • unauthorised access.

All suspected breaches must be reported immediately to the Centre Manager. Staff must not attempt to conceal or independently investigate a breach without authorisation.

The Centre Manager will:

  • contain and investigate the incident;
  • assess the likelihood and severity of risk;
  • document the facts, effects and remedial action;
  • notify the ICO without undue delay and, where feasible, within 72 hours of awareness when the legal reporting threshold is met; and
  • inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

All breaches must be recorded, whether or not reported externally.

14. Third-party processors

Before appointing a processor, Eclipse Academy must obtain reasonable assurance that it can protect personal information.

A written agreement must address:

  • processing instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • rights requests;
  • breach assistance;
  • deletion or return of information; and
  • audit and compliance information.

15. International transfers

Personal information must not be transferred outside the United Kingdom unless an appropriate safeguard or lawful exception applies.

Relevant safeguards and transfer-risk considerations must be documented.

16. Data protection by design

Privacy and security must be considered when:

  • introducing a new course or system;
  • changing website forms;
  • appointing a new provider;
  • collecting new categories of information; or
  • undertaking processing likely to create a high risk.

A Data Protection Impact Assessment must be completed where required.

17. Training and compliance

Staff who handle personal information must receive appropriate training and updates.

Failure to comply with this policy may result in disciplinary or contractual action and may be reported to relevant authorities where required.

18. Review

This policy will be reviewed annually and whenever there is a significant change in:

  • data-protection law;
  • organisational activities;
  • technology;
  • regulatory or awarding-organisation requirements; or
  • the nature of personal information processed.

19. Contact details

Eclipse Academy Ltd
Cranbrook House, Suite 7D, Second Floor
61 Cranbrook Road
Ilford
IG1 4PG

Telephone: 0333 335 7619
Email: admin@eclipse-academy.org

Scroll to Top