Skip to main content
How can we help you today?

Data protection and GDPR policy

Learner privacy notice

Privacy notice for pupils, students, Learners, and trainees.

The information you supply is used by the Learning Records Service (LRS). The LRS issues Unique Learner Numbers (ULN) and creates Personal Learning Records across England, Wales, and Northern Ireland, and is operated by the Department for Education (DfE) in England. This privacy notice explains how we use your personal information. For the purposes of relevant data protection legislation, the DfE is the data controller for personal information processed.

Who we are?

The LRS supports the DfE by collecting learner information from training providers and awarding organisations. For the purposes of relevant data protection legislations, the DfE is the data controller for personal information we process.

How we will use your information

We receive your personal data from:

  • Schools, colleges, local authorities, and training/learning providers.
  • Accredited achievement data supplied by awarding organisations.

The aims of LRS are to:

  • Create a trusted and verified record of learning for citizen across England, Wales, and Northern Ireland.
  • Enable education organisations to access these records when required to support individuals with enrolment to education and careers advice, ensuring they get access to the correct education and Government funding.
  • Issue you with a Unique Learner Number (ULN).
  • Create your Personal Learning Record (PLR).
  • Collect entries and results data that is used to create national statistical publications.

The nature of your personal data that LRS will process

The categories of personal data that can be processed in LRS includes:

  • Personal contact details.
  • Data related to an individual’s learning.
  • Data and information about your learning, including courses and qualifications you are taking or have taken.

To ensure that our records are accurate, it may be necessary for training providers to collect further personal information from you. This information will be used to identify the correct learner where their personal information is similar to other learners (e.g. name(s) and date of birth).

Where further information is required to distinguish between learners, the following personal information is deemed as mandatory:

  • last known post code
  • date of birth
  • gender

Why our use of your personal data is lawful

For our use of your personal data to be lawful, we need to meet one (or more) conditions in the data protection legislation. For LRS, the relevant conditions are:

  • Article 6(1)(e) UK General Data Protection Regulations (GDPR), to perform a public task as part of our function as a department.

We also rely on legitimate interests, where we may need to collect additional personal information, to distinguish you from another individual. This is:

  • Article 6(1)(f) of the UK General Data Protection Regulations.

Who we will make your personal data available to

We sometimes need to make personal data available to other organisations. These might include contracted partners (who we have employed to process your personal data on our behalf) and/or other organisations (with whom we need to share your personal data for specific purposes).

Where we need to share your personal data with others, we ensure that this data sharing complies with data protection legislation. For LRS we share your personal data with the following:

  • Schools, colleges, local authorities, and training/learning providers when you enrol onto a course.
  • Awarding bodies to record achievement/attainment information such as exam or course grades.
  • Permitted organisations such as Federation for Industry Skills & Standards (FISSS) and Universities and Colleges Admissions Service (UCAS) to record or verify individual’s qualifications.

How we will long keep your personal data

The PLR is a lifetime record of achievement for all learners.

All data in LRS will be retained until a learner is 80 years old and has not engaged with a learning provider for 7 years.

Your data protection rights

You have specific rights under data protection law. You can request a copy of all information relating to you held by the DfE. You can do this by making a Subject Access Request using the DfE Contact Form. DfE processes your personal information on LRS in the exercise of its official authority under the Education Act 2011 and the Apprenticeships, Skills, Children & Learning Act 2009.

This allows us to ensure that training providers are claiming for the correct Government funding, safeguard public money and prevent fraud. More information about how the DfE handles personal information is published in the DfE Personal Information Charter. If you need to contact us regarding any of the above, please do so via the DfE site using the DfE Contact Form.

If you are unable to use the online contact form, you can write to us at the address provided on Waverley Training Services | Waverley Borough Council. Further information about your data protection rights appears on the Information Commissioner’s website at Information Commissioners Office - Individual Rights.

Access the LRS privacy notice

Aims and scope

This document applies to all relevant legislation and regulations in relation to the process of handling and sharing data including but not limited to the Data Protection Act 2018, and the UK General Data Protection Regulation (UK GDPR) which provides the legal framework for this policy.

Waverley Training Services (WTS) will endeavour to ensure that all personal data relating to access, use, disclosure, and storage for internal and external stakeholders is held and managed in conjunction with current legislation.

This policy sets out how WTS handles the personal data of its employees, Learners and other third parties. We recognise that the correct and lawful treatment of personal data and protecting the confidentiality and integrity of personal data, is a critical responsibility and must be taken seriously at all times.

It applies to all personal data processed regardless of the media to which that data has been stored or whether it relates to past or present employees, Learners, employers, or other data subjects.

WTS Data Protection Officer/Controller: Charmaine Winter

WBC Data Protection Officer

Purpose

The purpose of this policy is to provide support, clarification, and guidance by outlining WTS duty in complying with data protection law. We fully endorse and adhere to the principles of data protection as detailed in the Data Protection Act 2018 and other corresponding legislation.

The eight guiding principles of Data Protection:

  1. Data is processed fairly and lawfully.
  2. Data is obtained only for specific, and lawful purposes.
  3. Data is adequate, relevant, and not excessive.
  4. Data is accurate and kept up to date.
  5. Data is not to be held for any longer than necessary.
  6. Data is to be processed in accordance with the data subject’s rights.
  7. Data is protected by the appropriate security measures.
  8. Data is not to be transferred outside of the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection.

The purpose of this document is to outline how data will be shared between WTS (“Data Controller”) and another partner organisation/training provider or Employer (“Data Processor”).

Additionally, this document outlines the adequate safeguards in place to ensure data is stored securely and that the processing of personal data is in accordance with the Data Controller's and Data Processor's legal obligations.

The Data Controller determines the purposes and methods of processing of personal data and retains formal control of and all ownership and rights to the personal data.

The Data Processor has no rights in or to the Personal Data other than the non-exclusive, revocable and time limited right other than use for the approved purpose.

In some instances, WTS will be both the data controller and the data processor.

This policy applies to:

  • All Senior Management.
  • All employees including tutors, assessors, other third parties working on behalf of WTS.
  • All Learners involved with WTS.
  • Employers.
  • All third parties carrying out services on behalf of WTS.

The data we collect

The below lists all the data that WTS holds relating to identifiable individuals but is not limited to names, addresses, email addresses, telephone numbers and other personal information relating to individuals.

The categories of information that we process include:

  • Personal identifiers and contacts (such as name, Unique Learner number (ULN), contact details and address).
  • Characteristics (such as ethnicity, language, and free school meal eligibility).
  • Safeguarding information (such as court orders and professional involvement).
  • Special educational needs (including the needs and documents pertaining to EHC plans).
  • Medical and administration (allergies, medication).
  • Attendance (such as sessions attended, number of absences, absence reasons).
  • Assessment and attainment (certificates of prior achievements, Personal Learning Record (PLR)).
  • Behavioural information (such as exclusions and any warnings).
  • Next of kin (such as providing name(s) and contact details for emergencies).
  • Financial support (such as bursary applications, this will include bank details and proof of eligibility).
  • Surveys (such as requests to complete Employer or Apprentice Reviews).

How we collect information

We collect information about Learners through a variety of methods:

  1. Application form and supporting documents including skill scan assessment, bursary, and EHC plan.
  2. PLR – Prior Learning Records checks.
  3. Other agencies (such as youth support agencies).
  4. Employers.

Why we collect data

WTS is required to collect and process data about employees, Learners and others including, Employers for several reasons including but not limited to:

  • The recruitment of staff.
  • Learner application and enrolment.
  • Employers Service Level Agreements (SLA’s).
  • The administration of programmes of study and qualifications. 
  • Registration with Awarding Organisations, End Point Organisations, and their examinations.
  • Recording Learner attendance, progress, and conduct.
  • Sharing information for contractual obligations with the Department for Education (DfE).
  • Keeping our employees and Learners safe.
  • Complying with legal obligations to funding bodies and government.

Department for Education

The Department for Education (DfE) collects personal data from educational settings and local authorities via various statutory data collections. We are required to share information about our Learners with the DfE either directly or via our local authority for the purpose of those data collections.

All data is transferred securely and held by the DfE under a combination of software and hardware controls, which meet the current government security policy framework.

By entering a contract with WTS and the DfE, we collect information to meet the following purposes:

  1. To support learning.
  2. To monitor and report on Learner attainment and progress.
  3. To provide appropriate pastoral care.
  4. To assess the quality of our services.
  5. To ensure appropriate safeguarding.
  6. To meet the statutory duties placed upon WTS for DfE data collections.

Under UK General Data Protection Regulation (GDPR), the lawful basis we rely on for processing information are:

Article 6, processing is necessary for the performance of a contract to which the data subject is party to, or in order to take steps at the request of the data subject prior to entering into a contract.

Article 9, processing is necessary for reasons of substantial public interest under the equality of treatment.

The processing of personal data shall only take place in technological environments controlled by the Data Controller/Data Processor in approved territory. For the avoidance of doubt, processing also includes accessing personal data remotely.

Learners’ information is held securely on our MIS system and on our Cloud storage and both can only be accessed by authorised personnel only.

We will not hold data for any longer than is necessary. The necessity will be determined by the circumstances of each case and why the information was obtained. It will also depend on contractual obligations with third parties including the DfE who state that Learner details must be stored securely and retained for seven years.

Other retention periods are as instructed by policies on retention as set by WBC or by Awarding Organisations.

Any processing of Personal Data for any other purpose, or by unauthorised personnel is strictly forbidden and will be considered a material breach of contract.

Data sharing is the process of making an organisations data resource available to multiple applications, users, and other organisations. Effective data sharing involves a combination of technologies, practices, legal frameworks, and organisational efforts to facilitate secure access for multiple entities without compromising data integrity.

WTS will only share personal data with specified third parties and will ensure that safeguards and contractual arrangements have been implemented.

We regularly share information with the below third parties:

  • Employers.
  • Local Authorities.
  • Department for Education (DfE).
  • Awarding Organisations (AOs)
  • End Point Assessment organisations (EPAOs).
  • Apprenticeship Assessment organisations (AAOs).

When sharing information, the following points should be considered before any sharing of the information requested.

  1. Employees are only to share the personal data we hold with another member of WTS if the recipient has a work - related need to know the information.
  2. Employees may only share the personal data that WTS holds with third parties, such as our service providers, if:
  3. They have a need to know the information for the purposes of providing the contracted service.
  4. Sharing the personal data complies with the Privacy Notice provided to the Data subject and, if required, the Data’s Subject consent has been obtained.
  5. The third party has agreed to comply with the required data security standards, policies and procedures and put adequate security measures in place.

Employees must not disclose personal data with anyone unless it complies with the above.

We will also share certain information for Learners aged 16-19 with our local authority and/or provider of youth support services who have responsibilities in the education or training of 13-19-year-olds under section 507B of the Education Act 1996.

This enables them to provide services as follows:

  • Post-16 education and training providers.
  • Youth support services
  • Careers advisers.

For more information about services for young people, please visit our local authority website www.waverley.gov.uk.

The only authorised personnel to access data covered in this policy should be those who need it for their work. Data must not be shared informally. When access to confidential information is required, employees can submit a request to the Data and Administration Manager.

WTS will provide training to all employees to support them in understanding their responsibilities regarding handling data.

Employees must ensure as far as reasonably practicable that they keep all data secure, by taking precautions and following the below:

  • Strong passwords must be used and never shared.
  • Personal data should not be disclosed to unauthorised personnel, either internally or externally.
  • Data should be regularly reviewed and updated if it is identified to be out of date, or if it is no longer required, it should be deleted.
  • Employees should request support from their line manager or the Data and Administration Manager if they are unsure about any aspect of data protection.

We process data on the basis of informed consent, all data subjects (employees, Learners, employers and other third parties) are informed that records of their dealings with WTS for example training and employment records are kept and processed electronically.

Learners are provided information on for what purpose their data is captured and used, alongside explanations as to why, at the point of application.

Concerns of safeguarding could result in personal data being shared without consent of the data subject, the data protection regulations do not apply whereby a child, young person or vulnerable adult is at risk of immediate harm.

The individual will be informed that any disclosure made cannot be withheld if there is a risk of immediate harm, the individual will be kept up to date as to any action taken and with whom.

Any safeguarding concerns should be reported the Designated Safeguarding Lead (DSL) and/or Deputy Designated Safeguarding Lead (DDSL) who will make the timely decision on whether information on data subjects should be shared where risk of harm is presented.

Designated Safeguarding Lead : Krystel Rajewski

Deputy Designated Safeguarding Lead: Charmaine Winter

Data subjects have the right to request access to information about them that we hold. To make a request for the personal information we hold, or if a data subject wishes to discuss anything in this privacy notice, please contact the WTS Data Protection Officer.

If you have a concern or complaint about the way we are collecting or using your personal data, you should raise your concern with us in the first instance or directly to the Information Commissioner’s Office (ICO).

Other notifications

The Data Processor shall without delay and in writing notify the Data Controller of any planned changes to personal data. Within five calendar days and in writing, notify the Data Controller if the following are received:

  • A request from a data subject to have access to their own Personal Data.
  • A complaint or request relating to the Data Controllers customers obligations.
  • By signing any training plan or service level agreement, all parties outlined in the document will be entering into a contract with WTS and the DfE for the duration of the qualification.

Disclosure of data for other reasons

In certain circumstances, the Data Protection Act allows personal data to be disclosed to local agencies such as the police or social services without the consent of the Data subject.

In the event that this information is requested, WTS will disclose the requested information.

However, the Data Protection Officer will ensure that the request is from a legitimate source.

Data protection risks

This policy is to protect WTS along with all its internal and external stakeholders from all security risks including to but not limited to:

  • Breaches in confidentiality. For example, data being shared inappropriately.
  • Failing to offer choice; for example, all individuals should be made aware of how their data is going to be used and be free to choose how the company uses data in relation to them.
  • Reputational damage: for example, the company could suffer a data compromise if cyber protection best practices are not followed.

Breaches

Any personal data breaches must be reported to the Data Protection Officer immediately. If the DPO deems that the breach is likely to result in a risk to the rights and freedoms of data subjects that may lead to the following but not limited to:

  • Financial loss.
  • Breach of confidentiality.
  • Discrimination.
  • Reputational Damage.
  • Other significant damage such as social or economic.

If a data processor becomes aware of any Personal Data breach, the Data Processor shall without delay and within 24 hours notify the Data Controller and fully cooperate to remedy the issue as soon as is reasonably practicable. The notice shall contain the following information (if available):

  • Description of the personal data breach including, date and time of incident, the nature and content of the personal data affected and a summary of the incident that caused the personal data breach.
  • Description of recommended measures to mitigate any adverse effects of the personal data breach.
  • Description of the likely consequences and potential risk that the Personal data breach may have towards the affected data subject(s).
  • Description of the measures proposed or taken by the Data Processor to address the personal data breach.

Depending on the nature of the Personal Data breach the Data Controller may be obliged to make a report to the ICO whereby additional information may be reasonably requested.

The DPO will inform the Information Commissioners Office without delay and within 72 hours.