Data Protection and GDPR Policy

Orvanta Open College

Purpose

The purpose of this policy is to ensure that Orvanta Open College complies fully with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other applicable data protection legislation. This policy outlines how personal data is collected, processed, stored, and shared to safeguard the rights and privacy of learners, staff, and stakeholders.

Scope

This policy applies to:

All learners enrolled on programmes delivered by the College.

All staff, contractors, and associates of the College.

All personal data collected, processed, or stored by the College in electronic or paper format.

Policy Statement

Orvanta Open College is committed to protecting personal data and upholding the rights of individuals. The College will ensure that all data is:

Processed lawfully, fairly, and transparently.

Collected for specified, explicit, and legitimate purposes.

Adequate, relevant, and limited to what is necessary.

Accurate and kept up to date.

Stored securely and retained only for as long as necessary.

Processed in a manner that ensures integrity and confidentiality.

Data Collected

The College may collect and process the following types of personal data:

Learner data – name, contact details, date of birth, enrolment records, assessment results, learning support requirements.

Staff data – employment records, qualifications, CPD records, payroll information.

Operational data – communications, feedback, complaints, and quality assurance documentation.

Roles and Responsibilities

Data Protection Officer (DPO): The Centre Director (or appointed nominee) is responsible for overall compliance with GDPR and acts as the Data Protection Officer.

Staff: All staff must handle personal data responsibly and in accordance with this policy.

Learners: Learners must provide accurate information and inform the College of any changes to their personal data.

Rights of Data Subjects

All individuals have the following rights under UK GDPR:

The right to be informed about how their data is used.

The right of access to personal data held by the College.

The right to rectification of inaccurate data.

The right to erasure (“right to be forgotten”).

The right to restrict or object to processing.

The right to data portability.

Requests under these rights must be submitted in writing to the DPO and will be responded to within 30 calendar days .

Data Security

All learner and staff data will be stored securely on password-protected systems and cloud platforms compliant with UK GDPR.

Access to personal data is restricted to authorised staff only.

Data transmitted electronically will be encrypted where possible.

Paper-based data (where unavoidable) will be kept in locked storage and securely destroyed when no longer required.

Data Sharing and Retention

Data will only be shared with awarding bodies, regulators, or statutory agencies where required by law or contractual obligation.

Personal data will not be shared with third parties for marketing purposes without explicit consent.

Retention periods will be in line with regulatory and awarding body requirements (normally 6 years after completion of studies).

Breach Management

Any suspected or actual data breach must be reported immediately to the DPO.

The DPO will investigate, record, and, where necessary, report the breach to the Information Commissioner’s Office (ICO) within 72 hours .

Monitoring and Review

Compliance with this policy will be monitored regularly through audits and staff training.

This policy will be reviewed annually, or earlier if legislative or regulatory changes occur.

Join a Global Network of Ambitious Learners

Study with an NCFE CACHE-approved UK college trusted by nurseries, schools, and care providers worldwide.

Follow us on social media

Orvanta Open College Data Protection and GDPR Policy