Data Protection Policy

Principles and practical procedures for responsible handling of college records and responding to privacy or security concerns.

This version issued:

1. Scope and accountability

ASAS EXCELLENCE COLLEGE LTD is responsible for personal data processed for its own purposes. We apply applicable UK data protection law, including the UK GDPR and Data Protection Act 2018 as amended. The Privacy Policy explains the categories, purposes and individual rights relevant to the website.

Data protection enquiries and reports should be sent to info@asas-college.com. This contact route does not imply that a statutory Data Protection Officer has been appointed.

2. Rules for handling records

Personal data must be handled lawfully, fairly and transparently; collected for specified purposes; limited to what is needed; kept accurate; retained only for justified periods; and protected appropriately. Staff should use authorised systems and access only information necessary for their responsibilities.

A new use, new provider or significant change to a learning process should be assessed for its privacy impact before implementation. Where required by law, an impact assessment and additional safeguards must be completed.

3. Access, security and sharing

Access should be based on role and need. Account access, permissions, secure transmission, updates and appropriate backup arrangements must reflect the risks of the service. Learners should use unique passwords, avoid sharing accounts and report unexpected access or messages.

Providers processing data on the college’s behalf must be subject to appropriate instructions and contractual controls. Data sharing with another college, ASAS company or certificate issuer requires a defined purpose, lawful basis and clear information for the affected learner. A common brand alone is not a basis for unrestricted sharing.

4. Sensitive records and identity checks

Information about health, disability or other sensitive matters must be requested only where necessary, through an appropriate route and with the required legal conditions explained. Supporting an adjustment does not justify wider disclosure of a learner’s circumstances.

Identity verification should be proportionate to the request. Do not email passwords or full payment card information. Ask for a secure method before providing an identity document or sensitive evidence.

5. Retention, correction and deletion

Retention must be linked to the record’s purpose and applicable obligations, including course administration, certification verification, financial records and specific disputes. Records that no longer have a justified purpose should be securely deleted or anonymised. A documented legal hold may require particular information to be kept longer.

Tell us if a record is inaccurate or ask for the retention criteria applying to your information. We will consider a deletion or restriction request against the relevant rights and any lawful need to retain the record, and explain the result.

6. Reporting a suspected incident

Report suspected loss, unauthorised disclosure, an email sent to the wrong person or compromised account access promptly to info@asas-college.com. Include the time, affected service and what you observed; avoid copying the exposed information more widely. A report is assessed so the incident can be contained and any required notifications considered.

Where a personal data breach must be reported to the ICO, the legal requirement is to do so without undue delay and, where feasible, within 72 hours of becoming aware. Where the law requires notification to affected individuals, they must be informed without undue delay. These are statutory obligations, not a guarantee that every technical problem is a reportable breach.

7. Requests and independent oversight

You can exercise applicable access, correction, erasure, restriction, objection and portability rights through the contact address above. We will explain reasonable identity checks, the applicable deadline and any lawful limit on the request. The college’s complaint process is available if you are dissatisfied, and you can also raise the matter with the ICO.

ICO information on your data protection rights

Contact the college

For questions about this policy: info@asas-college.com

ASAS EXCELLENCE COLLEGE LTD · Company number 17318908

115 London Road, Morden, England, SM4 5HP

This page sets out the current policy. Changes carry a new issue date; updating the website does not remove your statutory rights. Contact Us