Data and Document Management Policy
Policy Title: Data and Management Policy
Version: 1.0
Date: 2026.06.01
Next Review: 2027.06.01
Approved By: Jason Beese Owner/Director

1. Purpose
This policy outlines TrainAssure’s approach to the secure collection, storage, processing, retention, and disposal of learner and assessment data.
It ensures compliance with:
- General Data Protection Regulation (GDPR)
- Data Protection Act 2018
- Awarding body audit expectations
- Internal quality assurance procedures

2. Scope
This policy applies to:
- All learner records
- Assessment documentation
- Internal quality assurance records
- Trainer and assessor documentation
- Digital and paper‑based data
- All staff, contractors, and associates handling TrainAssure data

3. Policy Statement
TrainAssure is committed to:
- Protecting personal and sensitive data
- Ensuring accurate and secure record keeping
- Maintaining full audit trails for awarding body compliance
- Allowing access to authorised personnel only
- Ensuring data is retained and disposed of in line with regulatory requirements
- Ensuring transparency with learners regarding how their data is used

4. Data Collected
TrainAssure collects only the data necessary for qualification delivery and certification, including:
- Learner personal details (name, DOB, contact information)
- Assessment records and results
- Attendance registers
- Reasonable adjustment and special consideration records
- Trainer, assessor, and IQA documentation
- Centre‑based quality assurance records
No unnecessary or excessive data is collected.

5. Data Storage and Security
5.1 Digital Data
- Stored on secure, password‑protected systems
- Access restricted to authorised staff only
- Encrypted storage used where appropriate
- Regular backups maintained
- Cloud‑based systems must meet UK GDPR compliance standards
5.2 Paper Records
- Stored in locked cabinets or secure offices
- Access limited to authorised personnel
- Transported securely when taken off‑site
5.3 Assessment Evidence
- Stored securely until the end of the retention period
- Protected from loss, damage, or unauthorised access

6. Data Retention
TrainAssure follows Qualsafe Awards retention requirements:
- Assessment records: Minimum 3 years
- Internal quality assurance records: Minimum 3 years
- Learner registration and certification data: Minimum 3 years
- Reasonable adjustment/special consideration records: Minimum 3 years
- Complaints, appeals, and malpractice records: Minimum 3 years
Where awarding body requirements exceed these periods, the longer period will apply.

7. Data Disposal
At the end of the retention period:
- Paper records are shredded or securely destroyed
- Digital records are permanently deleted from all systems
- Backups containing expired data are overwritten during routine cycles
Disposal must ensure data cannot be reconstructed.

8. Access Control
Access to data is restricted based on role:
- Training Manager: Full access to learner and assessment data
- Assessors and Trainers: Access to records relevant to their learners
- IQA: Access to assessment and sampling records
- Administrative Staff: Access to registration and certification data
- External Auditors (Qualsafe Awards): Controlled access during audits
All staff must follow confidentiality requirements.

9. Data Accuracy and Integrity
TrainAssure ensures:
- Data is accurate, complete, and up to date
- Assessment decisions are recorded clearly and legibly
- Any errors are corrected promptly and transparently
- Version control is used for all policy and procedural documents

10. Data Sharing
Data may be shared with:
- Qualsafe Awards (for registration, certification, and audit)
- Regulatory bodies where legally required
- Employers or clients (with learner consent)
Data is never sold or shared with third parties for marketing.

11. Learner Rights
In accordance with GDPR, learners have the right to:
- Access their personal data
- Request corrections
- Request deletion (where legally permissible)
- Withdraw consent (where applicable)
- Be informed about how their data is used
Requests must be responded to within 30 days.

12. Incident Reporting
Any data breach or suspected breach must be reported immediately to the Training Manager.
Actions include:
- Containment of the breach
- Investigation and documentation
- Notification to affected individuals where required
- Reporting to the ICO if the breach poses a risk to individuals

13. Monitoring and Review
- Data management practices are reviewed annually
- Internal audits ensure compliance with Qualsafe requirements
- Records are sampled as part of IQA activity
- This policy is updated in line with regulatory or awarding body changes

14. Contact Details
TrainAssure
Email: info@trainassure.co.uk. Telephone: 0117 956 1184
Website: TrainAssure.co.uk