Privacy Policy
Introduction
1. Introduction
This Privacy Policy explains how Chiswick Education Institute Ltd collects, uses, stores, and protects personal data belonging to students, staff, contractors, and website users.
As a UKābased educational provider, we act as a Data Controller and follow the UK GDPR and Data Protection Act 2018. UK schools must process data lawfully, fairly, transparently, and integrate data protection into all activities (“data protection by design and by default”). [eani.org.uk]
We also follow current UK government guidance for data protection in educational settings, including responsibilities, lawful bases, and breach management procedures. [gov.uk]
2. Personal data
2. What personal data we collect
Chiswick Education Institute Ltd may collect and process the following categories of data:
2.1 Student Data
-
Full name, date of birth, and contact details
-
Visa and passport information (for international students)
-
Emergency contact details
-
Special category data where relevant (e.g., health information, specific learning needs)
-
Attendance records, progress reports, assessments.
Educational institutions in the UK commonly process highly sensitive student information such as identification, health, safeguarding concerns, and learning records. [cpdonline.co.uk]
2.2 Staff and contractor data
-
Identification and contact details
-
Employment records, qualifications, payroll information
-
Background checks (e.g., DBS).
2.3 Website and communication data
-
Contact form submissions
-
IP address and browsing behaviour (collected via analytics tools)
-
Cookies (see our Cookie Policy)
3. Lawful bases for processing
We process personal data using the lawful bases identified under the UK GDPR, including:
-
Contract – to provide students with educational services
-
Legal obligation – safeguarding, immigration compliance, recordākeeping
-
Public task / legitimate interests – delivering education and maintaining school operations
-
Consent – used only when no other lawful basis applies (e.g., for marketing communications).
Educational institutions in the UK must ensure lawful, fair, and transparent processing and base all activity on one of the legal grounds, in the UK, GDPR. [sprintlaw.co.uk]
4. How we use personal data
Chiswick Education Institute Ltd uses data to:
-
Provide English language education services to mature students
-
Ensure student welfare and safeguarding
-
Communicate with students, staff, contractors, agents, corporate clients
-
Process payments and manage accounts
-
Support visa applications (when applicable)
-
Monitor progress, attendance, and performance
-
Improve teaching, administration, and digital tools
-
Meet regulatory and inspection requirements.
5. Special category data
Special category data (e.g., health information or specific learning differences) is processed only when strictly necessary and in accordance with UK GDPR safeguards for sensitive data, which educational institutions frequently handle. [cpdonline.co.uk]
6. Sharing personal data
Chiswick Education Institute Ltd may share data with:
-
Staff members with authorised access
-
Immigration authorities (where required)
-
Accreditation bodies and inspectors
-
Payment processors
-
Health and welfare services
-
IT service providers (e.g., cloud platforms, learning tools).
Any thirdāparty suppliers must comply with UK GDPR and maintain strong data security measures. Educational institutions are responsible for ensuring digital tools and external providers meet data protection standards. [sprintlaw.co.uk]
7. International Data Transfers
Where data is transferred outside the UK (e.g., thirdāparty digital tools), we ensure adequate safeguards such as:
-
UKāapproved adequacy regulations
-
Standard Contractual Clauses (SCCs).
8. Data retention
Chiswick Education Institute Ltd retains personal data only as long as necessary for the purposes collected and in accordance with UK government retention guidelines for education providers. [gov.uk]
9. Data security
Chiswick Education Institute Ltd uses appropriate administrative, technical, and physical safeguards to protect data from loss, misuse, or unauthorised access. Robust data security practices are essential for UK schools and educational institutions especially given the sensitivity of data collected by educational institutions. [sprintlaw.co.uk]
Security measures include:
-
Secure password protocols
-
Encrypted storage
-
Access controls
-
Staff training
-
Regular system audits
-
Secure data disposal procedures.
10. Your data protection rights
Under UK GDPR, individuals have the right to:
-
Access their personal data (Subject Access Request)
-
Request correction of inaccurate data
-
Request deletion (where applicable)
-
Request restriction or objection to processing
-
Data portability
-
Withdraw consent (where processing is based on consent).
Educational institutions must handle Subject Access Requests and other information rights requests appropriately and without undue delay, as required by UK guidance. [gov.uk]
11. Data protection Officer
11. Data Protection Officer (DPO)
Chiswick Education Institute Ltd appoints a Data Protection Officer (or equivalent) who oversees compliance, as recommended for educational institutions. [sprintlaw.co.uk]
Contact:
DPO – Anna Miller
Contact details: www.Chiswickeducationinstitute.com
12. Data breaches
In line with UK government guidance, the company maintains procedures for detecting, reporting, and investigating data breaches promptly. [gov.uk]
Where a breach poses a risk to individuals, we will notify:
-
The Information Commissioner’s Office (ICO)
-
Affected data subjects within required timeframes.
13. Complaints
If you have concerns about how we handle your data, you may contact the ICO:
Information Commissioner’s Office
Website: https://ico.org.uk
Phone: 0303 123 1113
Educational institutions must also support individuals who wish to make complaints about data use, including offering electronic complaint options as part of evolving UK legislation requirements. Please refer to the Complaints section on the website.
14. Updates to This Policy
Chiswick Education Institute Ltd reviews this policy regularly to ensure compliance with UK GDPR and new guidance issued by the ICO or UK government. Updates will be published on our website.
