INSTITUTIONAL POLICY: DATA PROTECTION AND GDPR COMPLIANCE
D
- ocument Reference: CMC-QA-POL-002
- Version: 2026.1
- Regulatory Compliance: UK Data Protection Act 2018 / General Data Protection Regulation (GDPR) / Ofqual Condition C2
- Scope: Applies to all student academic records, financial transactions, staff data, and digital interactions within the CMC ecosystem.
1. Executive Summary and Purpose
As a registered United Kingdom distance learning institution operating a borderless digital campus, Cambridge Modern College is structurally committed to protecting the privacy, confidentiality, and digital autonomy of its international learners, faculty, and corporate partners. This policy outlines the strict operational and technical protocols deployed by the College to ensure full compliance with the UK Data Protection Act and the General Data Protection Regulation (GDPR). The College operates under the core principle that personal and academic data must be collected lawfully, processed transparently, and secured against unauthorized access or systemic breaches.
2. Core Data Processing Principles
The College mandates that all personal data captured via the official web domain (
cambridgemoderncollege.com) or the integrated Learning Management System (LMS) must satisfy the following criteria:
- Lawfulness, Fairness, and Transparency: Data is gathered only with the explicit, unambiguous digital consent of the user, and is utilized solely for legitimate educational administration and qualification delivery.
- Purpose Limitation: Information collected for student enrollment, identity verification, or academic assessment cannot be cross-utilized, rented, or transferred for commercial marketing purposes.
- Data Minimization: The College restricts data collection to the absolute necessary infrastructure metrics (e.g., identity verification documents, course progress, and secure billing information).
- Storage Limitation: Personal data and academic scripts are retained only as long as required to satisfy UK Awarding Body auditing cycles and formal certification verifications.
3. Operational Categories of Data Collected
To maintain a verified, high-integrity student record database, the CMC digital platform processes the following data segments:
- Identity and Demographic Data: Full legal name, passport or national identification numbers, physical address, and verified email contact parameters.
- Academic Performance Metrics: Continuous assignment submissions, grades, assessor feedback, internal verification reports, and continuous learning analytics.
- Financial Transaction Data: Encrypted payment confirmations and billing records managed via verified, secure third-party payment gateways (e.g., Stripe, PayPal). The College does not store raw credit card numbers on its native servers.
- Technical Usage Logs: IP addresses, browser types, and digital access timestamps captured securely to monitor portal stability and prevent unauthorized account access.
4. Technical and Administrative Security Measures
To prevent data manipulation, accidental deletion, or external cyber threats, the College implements an advanced digital security matrix:
- Encryption Standards: All data transmitted between the student's browser and the CMC portal is protected utilizing end-to-end Transport Layer Security (TLS) and Advanced Encryption Standard (AES-256) frameworks.
- Access Controls (Role-Based Access): Academic records and student profiles are locked under a strict permission matrix. Assessors can only access modules they actively teach, and financial records are restricted strictly to authorized corporate accounting personnel.
- Server Infrastructure: Student data is hosted on highly secure, GDPR-compliant cloud servers that feature routine automated daily backups and real-time perimeter threat detection.
5. Student Rights Under GDPR
Every learner registered with Cambridge Modern College holds specific, enforceable digital rights regarding their personal data, including:
- The Right of Access: Students can request a comprehensive digital transcript of all personal data and academic records held by the institution at any time without administrative charge.
- The Right to Rectification: The right to demand immediate corrections to any inaccurate or outdated personal profile parameters.
- The Right to Erasure (The Right to be Forgotten): A learner can request the complete deletion of their account data, provided it does not conflict with mandatory academic record retention laws enforced by UK Awarding Bodies for qualification verification.
- The Right to Data Portability: The right to receive their academic data in a structured, commonly used, and machine-readable format to facilitate transfer to another institution.
6. Data Breach Notification Protocol
In the highly unlikely event of a systemic data breach or unauthorized perimeter penetration, the College adheres to a strict emergency response roadmap:
- Regulatory Reporting: The Academic Board will formally notify the UK Information Commissioner’s Office (ICO) within 72 hours of breach discovery.
- User Notification: If the breach poses any risk to individual data privacy or identity security, all affected learners will receive a high-priority, comprehensive digital notice detailing the nature of the breach and immediate protective measures taken by the tech infrastructure team.