International Teachers Association (ITA)
Data Protection Policy
| Organisation | International Teachers Association (ITA), registered in Bristol, United Kingdom |
| Company number | 15988200 |
| ICO registration number | [insert] |
| Policy owner | Dr. Peter Cooper, Chairman |
| Data protection contact | info@internationalteachersassociation.com |
| Version / date | 1.0 / 1st October 2026 |
| Next review | [12 months after approval] |
1. Purpose and scope
ITA is committed to protecting the personal data of everyone it works with. This policy explains how ITA collects, uses, stores, shares and protects personal data, and sets out the responsibilities of everyone acting for ITA.
It applies to all trustees/directors, officers, staff, volunteers, contractors, partner representatives and country or regional office representatives who handle personal data on behalf of ITA, in any country and in any format (digital or paper).
2. Legal framework
ITA is established in the UK and follows:
- the UK General Data Protection Regulation (UK GDPR);
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations (PECR) for email marketing and cookies.
Where ITA offers services to, or monitors individuals in, the European Economic Area (for example members, teachers or course participants in Germany or other EU states), ITA also respects the EU GDPR and applicable local data protection laws. Where local law is stricter, the stricter rule applies.
3. Definitions
- Personal data: any information relating to an identifiable living person (name, email, address, ID or passport details, qualifications, photographs, IP address, etc.).
- Special category data: data revealing racial or ethnic origin, religion, health, trade union membership, biometric data and similar. ITA aims not to collect it unless strictly necessary.
- Processing: anything done with personal data, including collecting, storing, sharing and deleting.
- Controller: the organisation deciding why and how data is used. ITA is the controller for most data described in this policy.
- Processor: a third party processing data on ITA's instructions (for example email, hosting or payment providers).
4. Whose data ITA holds and why
| Group | Examples of data | Main purpose | Typical lawful basis |
|---|---|---|---|
| Members and teachers | Name, contact details, qualifications, employment history, country | Membership administration, recognition, communication | Contract; legitimate interests |
| Course participants (e.g. TEFL/TESOL) | Identity and contact details, study records, assessment results, certificates | Delivering courses, assessment, certification, verification of certificates | Contract; legal obligation |
| Educational institutions seeking accreditation | Contact persons, institutional documents, inspection or review records | Accreditation and quality assurance | Contract; legitimate interests |
| Partners and collaborators | Contact details, agreement and MoU records | Managing collaborations | Legitimate interests; contract |
| Donors and supporters | Name, contact details, donation records | Fundraising, record keeping, tax and accounting | Consent; legal obligation; legitimate interests |
| Website visitors and subscribers | IP address, cookies, newsletter signup, enquiry messages | Running the website, responding to enquiries, news and updates | Consent; legitimate interests |
| Job applicants, volunteers, contractors | CV, references, contact details | Recruitment and engagement | Contract; legitimate interests |
Lawful bases are set out in Article 6 of the UK GDPR. ITA records the lawful basis for each processing activity in its Record of Processing Activities (section 14).
5. Data protection principles
ITA ensures personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes only;
- adequate, relevant and limited to what is necessary (data minimisation);
- accurate and kept up to date;
- kept no longer than necessary (storage limitation);
- kept secure (integrity and confidentiality);
- handled with accountability: ITA can demonstrate compliance.
6. Transparency and privacy notices
ITA publishes a Privacy Notice on its website and provides a short notice at every point where data is collected (forms, course enrolment, membership applications, accreditation applications). Notices explain who ITA is, what data is collected, why, the legal basis, who receives it, how long it is kept, international transfers, and individuals' rights.
7. Consent and marketing
- Consent must be freely given, specific, informed and unambiguous, and can be withdrawn at any time as easily as it was given.
- Newsletters and promotional emails are sent only to people who have opted in (or where PECR's limited soft opt-in rules apply). Every message contains an unsubscribe link.
- Non-essential cookies are used only after consent, with a cookie banner and cookie policy on the website.
- Photographs and videos of identifiable people (for example for the ITA Educational News Channel, events or social media) require written or recorded consent, which can be withdrawn.
8. Individual rights
Individuals have the right to:
- be informed;
- access their data (subject access request);
- have inaccurate data corrected;
- have data erased ("right to be forgotten") where applicable;
- restrict processing;
- data portability;
- object to processing, including direct marketing;
- not be subject to solely automated decisions with significant effects;
- withdraw consent at any time;
- complain to the supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk; individuals in the EU may also contact their national authority).
Process: requests may be made to the data protection contact in any form. ITA acknowledges requests promptly, verifies identity where needed, and responds within one month (extendable by up to two further months for complex requests, with notice). Requests are free unless manifestly unfounded or excessive. All requests are logged.
9. Data security
ITA applies appropriate technical and organisational measures, including:
- strong, unique passwords and two-factor authentication on email, website, cloud and payment accounts;
- access limited to those who need the data for their role (least privilege);
- encryption of laptops, phones and portable storage; encrypted transfer of sensitive documents;
- regular software updates, antivirus and secure website (HTTPS);
- regular backups, tested periodically;
- no personal data on personal or shared devices without ITA's approval and safeguards;
- secure disposal of paper and electronic records;
- confidentiality undertakings for staff, volunteers and contractors;
- awareness training at onboarding and at least annually.
10. Sharing data and using processors
ITA shares personal data only where necessary and lawful, for example with:
- accreditation, examination or certification partners;
- IT, hosting, email, learning platform and payment providers;
- accountants, auditors and legal advisers;
- regulators or authorities where legally required.
ITA does not sell personal data. Before engaging any processor, ITA checks that it offers adequate security and signs a written data processing agreement that meets Article 28 requirements. Data sharing with partner organisations (including collaborations under an MoU) is covered by a data sharing agreement or clause that defines roles, purposes and safeguards.
11. International transfers
ITA operates internationally, so personal data may be transferred outside the UK and EEA, including to ITA offices, partners and service providers. ITA only makes such transfers where:
- the destination is covered by UK adequacy regulations (or an EU adequacy decision, for EU-origin data); or
- appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or EU Standard Contractual Clauses, together with a transfer risk assessment where required; or
- a specific, documented exception under Article 49 applies.
Overseas offices and country representatives act on ITA's instructions and must follow this policy, and any additional local legal requirements are documented in a local annex.
12. Retention and deletion
Personal data is kept only as long as needed for its purpose. Indicative periods (to be confirmed against legal advice and recorded in the Retention Schedule):
| Record type | Indicative retention |
|---|---|
| Course and certification records (to verify certificates) | [e.g. permanently, or as stated in the privacy notice] |
| Membership records | Duration of membership plus [6] years |
| Accreditation files | Duration of accreditation plus [6] years |
| Financial and donation records | [6] years from end of the financial year (UK legal requirement) |
| Unsuccessful job applications | [6] months |
| Newsletter subscribers | Until unsubscribe or [2] years of inactivity |
| Website enquiries | [12] months after resolution |
At the end of the retention period, data is securely deleted or anonymised.
13. Personal data breaches
A personal data breach is any security incident that leads to accidental or unlawful loss, alteration, unauthorised disclosure of or access to personal data.
- Report immediately to the data protection contact (within 24 hours of discovery) with whatever is known.
- Contain and assess: stop the breach, assess the risk to individuals.
- Notify the ICO within 72 hours of becoming aware, if the breach is likely to result in a risk to individuals' rights and freedoms (and the relevant EU authority where EU GDPR applies).
- Inform affected individuals without undue delay if the risk is high.
- Record every breach in the breach log, with facts, effects and actions taken, and review lessons learned.
14. Accountability and governance
- Responsibility: The Chairman, Dr. Peter Cooper, holds overall responsibility for data protection at ITA and the board/trustees receive at least an annual report. ITA will appoint a Data Protection Lead (and a Data Protection Officer if required by law or considered good practice).
- ICO registration: ITA registers with the ICO and pays the data protection fee, unless exempt.
- Records of Processing Activities (RoPA): maintained and reviewed at least annually.
- Data Protection Impact Assessments (DPIA): carried out before high-risk processing, new systems, large-scale use of data, or new overseas offices.
- Privacy by design and default: considered in every new project, form or system.
- Training: all people handling personal data are trained on joining and annually.
- Audit and review: this policy is reviewed at least annually, and after any significant breach, legal change or structural change (including any conversion to charitable status).
15. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Chairman / Board | Approves policy, ensures resources, receives reports |
| Data Protection Lead | Advises, monitors compliance, handles requests and breaches, maintains records |
| Managers, country/regional representatives | Apply the policy in their area, report issues |
| All staff, volunteers, contractors | Follow the policy, complete training, report breaches immediately |
Breach of this policy by staff or volunteers may lead to disciplinary action or termination of engagement.
16. Children's data
ITA's services are aimed at adults. Where ITA collects data about children (for example in connection with school projects or fundraising for schools), it collects the minimum necessary, uses clear age-appropriate notices, relies on parental or school authorisation where appropriate, and takes particular care with images and identifying details.
17. Contact and complaints
Questions, requests and concerns:
International Teachers Association Data Protection Contact: Dr. Peter Cooper Email: info@internationalteachersassociation.com Address: Bloomfield Rd, Brislington, Bristol, United Kingdom, BS4 3QP
If you are unhappy with our response, you may complain to the Information Commissioner's Office (ico.org.uk, tel. 0303 123 1113) or to the data protection authority in your country of residence.
Approval
Approved by the Chairman on behalf of the Board:
Name: Dr. Peter Cooper Signature: Peter Cooper Date: 1st October 2026/p>