International Teachers Association

Data Protection Act

International Teachers Association (ITA)

Data Protection Policy

OrganisationInternational Teachers Association (ITA), registered in Bristol, United Kingdom
Company number15988200
ICO registration number[insert]
Policy ownerDr. Peter Cooper, Chairman
Data protection contactinfo@internationalteachersassociation.com
Version / date1.0 / 1st October 2026
Next review[12 months after approval]

1. Purpose and scope

ITA is committed to protecting the personal data of everyone it works with. This policy explains how ITA collects, uses, stores, shares and protects personal data, and sets out the responsibilities of everyone acting for ITA.

It applies to all trustees/directors, officers, staff, volunteers, contractors, partner representatives and country or regional office representatives who handle personal data on behalf of ITA, in any country and in any format (digital or paper).

2. Legal framework

ITA is established in the UK and follows:

  • the UK General Data Protection Regulation (UK GDPR);
  • the Data Protection Act 2018;
  • the Privacy and Electronic Communications Regulations (PECR) for email marketing and cookies.

Where ITA offers services to, or monitors individuals in, the European Economic Area (for example members, teachers or course participants in Germany or other EU states), ITA also respects the EU GDPR and applicable local data protection laws. Where local law is stricter, the stricter rule applies.

3. Definitions

  • Personal data: any information relating to an identifiable living person (name, email, address, ID or passport details, qualifications, photographs, IP address, etc.).
  • Special category data: data revealing racial or ethnic origin, religion, health, trade union membership, biometric data and similar. ITA aims not to collect it unless strictly necessary.
  • Processing: anything done with personal data, including collecting, storing, sharing and deleting.
  • Controller: the organisation deciding why and how data is used. ITA is the controller for most data described in this policy.
  • Processor: a third party processing data on ITA's instructions (for example email, hosting or payment providers).

4. Whose data ITA holds and why

GroupExamples of dataMain purposeTypical lawful basis
Members and teachersName, contact details, qualifications, employment history, countryMembership administration, recognition, communicationContract; legitimate interests
Course participants (e.g. TEFL/TESOL)Identity and contact details, study records, assessment results, certificatesDelivering courses, assessment, certification, verification of certificatesContract; legal obligation
Educational institutions seeking accreditationContact persons, institutional documents, inspection or review recordsAccreditation and quality assuranceContract; legitimate interests
Partners and collaboratorsContact details, agreement and MoU recordsManaging collaborationsLegitimate interests; contract
Donors and supportersName, contact details, donation recordsFundraising, record keeping, tax and accountingConsent; legal obligation; legitimate interests
Website visitors and subscribersIP address, cookies, newsletter signup, enquiry messagesRunning the website, responding to enquiries, news and updatesConsent; legitimate interests
Job applicants, volunteers, contractorsCV, references, contact detailsRecruitment and engagementContract; legitimate interests

Lawful bases are set out in Article 6 of the UK GDPR. ITA records the lawful basis for each processing activity in its Record of Processing Activities (section 14).

5. Data protection principles

ITA ensures personal data is:

  1. processed lawfully, fairly and transparently;
  2. collected for specified, explicit and legitimate purposes only;
  3. adequate, relevant and limited to what is necessary (data minimisation);
  4. accurate and kept up to date;
  5. kept no longer than necessary (storage limitation);
  6. kept secure (integrity and confidentiality);
  7. handled with accountability: ITA can demonstrate compliance.

6. Transparency and privacy notices

ITA publishes a Privacy Notice on its website and provides a short notice at every point where data is collected (forms, course enrolment, membership applications, accreditation applications). Notices explain who ITA is, what data is collected, why, the legal basis, who receives it, how long it is kept, international transfers, and individuals' rights.

7. Consent and marketing

  • Consent must be freely given, specific, informed and unambiguous, and can be withdrawn at any time as easily as it was given.
  • Newsletters and promotional emails are sent only to people who have opted in (or where PECR's limited soft opt-in rules apply). Every message contains an unsubscribe link.
  • Non-essential cookies are used only after consent, with a cookie banner and cookie policy on the website.
  • Photographs and videos of identifiable people (for example for the ITA Educational News Channel, events or social media) require written or recorded consent, which can be withdrawn.

8. Individual rights

Individuals have the right to:

  • be informed;
  • access their data (subject access request);
  • have inaccurate data corrected;
  • have data erased ("right to be forgotten") where applicable;
  • restrict processing;
  • data portability;
  • object to processing, including direct marketing;
  • not be subject to solely automated decisions with significant effects;
  • withdraw consent at any time;
  • complain to the supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk; individuals in the EU may also contact their national authority).

Process: requests may be made to the data protection contact in any form. ITA acknowledges requests promptly, verifies identity where needed, and responds within one month (extendable by up to two further months for complex requests, with notice). Requests are free unless manifestly unfounded or excessive. All requests are logged.

9. Data security

ITA applies appropriate technical and organisational measures, including:

  • strong, unique passwords and two-factor authentication on email, website, cloud and payment accounts;
  • access limited to those who need the data for their role (least privilege);
  • encryption of laptops, phones and portable storage; encrypted transfer of sensitive documents;
  • regular software updates, antivirus and secure website (HTTPS);
  • regular backups, tested periodically;
  • no personal data on personal or shared devices without ITA's approval and safeguards;
  • secure disposal of paper and electronic records;
  • confidentiality undertakings for staff, volunteers and contractors;
  • awareness training at onboarding and at least annually.

10. Sharing data and using processors

ITA shares personal data only where necessary and lawful, for example with:

  • accreditation, examination or certification partners;
  • IT, hosting, email, learning platform and payment providers;
  • accountants, auditors and legal advisers;
  • regulators or authorities where legally required.

ITA does not sell personal data. Before engaging any processor, ITA checks that it offers adequate security and signs a written data processing agreement that meets Article 28 requirements. Data sharing with partner organisations (including collaborations under an MoU) is covered by a data sharing agreement or clause that defines roles, purposes and safeguards.

11. International transfers

ITA operates internationally, so personal data may be transferred outside the UK and EEA, including to ITA offices, partners and service providers. ITA only makes such transfers where:

  • the destination is covered by UK adequacy regulations (or an EU adequacy decision, for EU-origin data); or
  • appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or EU Standard Contractual Clauses, together with a transfer risk assessment where required; or
  • a specific, documented exception under Article 49 applies.

Overseas offices and country representatives act on ITA's instructions and must follow this policy, and any additional local legal requirements are documented in a local annex.

12. Retention and deletion

Personal data is kept only as long as needed for its purpose. Indicative periods (to be confirmed against legal advice and recorded in the Retention Schedule):

Record typeIndicative retention
Course and certification records (to verify certificates)[e.g. permanently, or as stated in the privacy notice]
Membership recordsDuration of membership plus [6] years
Accreditation filesDuration of accreditation plus [6] years
Financial and donation records[6] years from end of the financial year (UK legal requirement)
Unsuccessful job applications[6] months
Newsletter subscribersUntil unsubscribe or [2] years of inactivity
Website enquiries[12] months after resolution

At the end of the retention period, data is securely deleted or anonymised.

13. Personal data breaches

A personal data breach is any security incident that leads to accidental or unlawful loss, alteration, unauthorised disclosure of or access to personal data.

  1. Report immediately to the data protection contact (within 24 hours of discovery) with whatever is known.
  2. Contain and assess: stop the breach, assess the risk to individuals.
  3. Notify the ICO within 72 hours of becoming aware, if the breach is likely to result in a risk to individuals' rights and freedoms (and the relevant EU authority where EU GDPR applies).
  4. Inform affected individuals without undue delay if the risk is high.
  5. Record every breach in the breach log, with facts, effects and actions taken, and review lessons learned.

14. Accountability and governance

  • Responsibility: The Chairman, Dr. Peter Cooper, holds overall responsibility for data protection at ITA and the board/trustees receive at least an annual report. ITA will appoint a Data Protection Lead (and a Data Protection Officer if required by law or considered good practice).
  • ICO registration: ITA registers with the ICO and pays the data protection fee, unless exempt.
  • Records of Processing Activities (RoPA): maintained and reviewed at least annually.
  • Data Protection Impact Assessments (DPIA): carried out before high-risk processing, new systems, large-scale use of data, or new overseas offices.
  • Privacy by design and default: considered in every new project, form or system.
  • Training: all people handling personal data are trained on joining and annually.
  • Audit and review: this policy is reviewed at least annually, and after any significant breach, legal change or structural change (including any conversion to charitable status).

15. Roles and responsibilities

RoleResponsibility
Chairman / BoardApproves policy, ensures resources, receives reports
Data Protection LeadAdvises, monitors compliance, handles requests and breaches, maintains records
Managers, country/regional representativesApply the policy in their area, report issues
All staff, volunteers, contractorsFollow the policy, complete training, report breaches immediately

Breach of this policy by staff or volunteers may lead to disciplinary action or termination of engagement.

16. Children's data

ITA's services are aimed at adults. Where ITA collects data about children (for example in connection with school projects or fundraising for schools), it collects the minimum necessary, uses clear age-appropriate notices, relies on parental or school authorisation where appropriate, and takes particular care with images and identifying details.

17. Contact and complaints

Questions, requests and concerns:

International Teachers Association Data Protection Contact: Dr. Peter Cooper Email: info@internationalteachersassociation.com Address: Bloomfield Rd, Brislington, Bristol, United Kingdom, BS4 3QP

If you are unhappy with our response, you may complain to the Information Commissioner's Office (ico.org.uk, tel. 0303 123 1113) or to the data protection authority in your country of residence.


Approval

Approved by the Chairman on behalf of the Board:

Name: Dr. Peter Cooper Signature: Peter Cooper Date: 1st October 2026/p>