GDPR & Data Protection Policy
Last Updated: 09.06.2026
1. Introduction
ELD Training (“we”, “our”, “us”) is committed to protecting the privacy, confidentiality, and security of personal data. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, international data protection laws.
As a provider of vocational training, assessor qualifications, internal quality assurance (IQA) training, external quality assurance (EQA) training, and professional development programmes, we collect and process personal information to deliver our services effectively and responsibly.
This policy explains how we collect, use, store, protect, and manage personal data.
2. Who We Are
ELD Training is a UK-based training organisation delivering vocational education, assessment, quality assurance, and professional development services to learners, employers, training providers, awarding organisations, and other stakeholders worldwide.
For the purposes of data protection legislation, ELD Training acts as a Data Controller when determining how personal information is processed.
For data protection enquiries, please contact:
Data Protection Officer / Data Protection Contact
ELD Training
Email: info@eld.training
Website: www.eld.training
3. Personal Data We Collect
We may collect and process the following categories of personal information:
Learner Information
- Full name
- Date of birth
- Contact details (email address, telephone number, postal address)
- Learner registration details
- Qualification and assessment records
- Evidence portfolios and coursework submissions
- Attendance and achievement records
Client and Employer Information
- Contact names
- Job titles
- Business contact details
- Training requirements and records
Website Information
- IP addresses
- Browser type and device information
- Website usage data
- Cookie and analytics information
Financial Information
- Payment and invoicing details
- Transaction records
Special Category Data
Where required for training, assessment, accessibility, safeguarding, or legal compliance, we may process limited special category data such as:
- Health information relevant to reasonable adjustments
- Accessibility requirements
- Equality and diversity monitoring information
Such information is only collected when necessary and processed in accordance with applicable legal requirements.
4. How We Collect Personal Data
We collect information through:
- Website enquiry forms
- Course registrations and applications
- Learner enrolment forms
- Email correspondence
- Telephone communications
- Online learning platforms
- Assessment and quality assurance activities
- Employers, awarding organisations, and partner organisations
- Cookies and website analytics tools
5. Lawful Bases for Processing
Under UK GDPR, we process personal data under one or more of the following lawful bases:
Contractual Necessity
To provide training, assessment, certification, and related services.
Legal Obligation
To comply with legal, regulatory, awarding organisation, and funding requirements.
Legitimate Interests
To manage and improve our services, maintain records, communicate with clients, and ensure quality assurance.
Consent
Where required, such as for marketing communications or optional data collection activities.
Vital Interests
Where necessary to protect an individual’s wellbeing or safety.
6. How We Use Personal Data
We may use personal information to:
- Deliver training and educational services
- Register learners with awarding organisations
- Conduct assessments and quality assurance activities
- Issue certificates and qualification records
- Communicate with learners, employers, and stakeholders
- Manage customer enquiries
- Process payments and maintain financial records
- Improve our services and website functionality
- Meet legal and regulatory obligations
- Prevent fraud and maintain security
7. Sharing Personal Data
We do not sell personal information.
We may share personal data where necessary with:
- Awarding organisations
- Qualification regulators
- Employers sponsoring learners
- Professional advisers
- IT service providers and learning management systems
- Payment processing providers
- Government agencies and regulatory authorities where legally required
All third parties are required to protect personal information and process it in accordance with applicable data protection laws.
8. International Data Transfers
As an international training provider, personal data may occasionally be transferred outside the United Kingdom.
Where international transfers occur, we ensure appropriate safeguards are in place, including:
- Adequacy regulations approved by the UK Government
- International Data Transfer Agreements (IDTAs)
- Standard Contractual Clauses where applicable
- Appropriate contractual and organisational safeguards
9. Data Security
We implement appropriate technical and organisational measures to protect personal information from:
- Unauthorised access
- Loss or theft
- Accidental disclosure
- Alteration or destruction
- Cybersecurity threats
Security measures may include:
- Secure servers and encrypted systems
- Password-protected access controls
- Staff confidentiality obligations
- Secure backup procedures
- Regular security monitoring
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Legal obligations
- Regulatory requirements
- Awarding organisation requirements
- Quality assurance obligations
- Legitimate business needs
Retention periods vary according to the type of information held and applicable legal requirements.
When personal information is no longer required, it will be securely deleted or anonymised.
11. Your Data Protection Rights
Subject to applicable law, individuals have the right to:
- Access their personal data
- Request correction of inaccurate information
- Request erasure of personal data
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
Requests should be submitted using the contact details provided in this policy.
12. Cookies and Website Analytics
Our website may use cookies and similar technologies to:
- Improve website functionality
- Analyse visitor behaviour
- Enhance user experience
- Monitor website performance
Users can manage cookie preferences through their browser settings or our cookie management tools where available.
For further information, please refer to our Cookie Policy.
13. Marketing Communications
Where permitted by law, we may send information regarding:
- Training programmes
- Professional development opportunities
- Events and webinars
- Industry updates
Recipients may unsubscribe from marketing communications at any time by using the unsubscribe link provided or contacting us directly.
14. Data Breaches
ELD Training maintains procedures for identifying, investigating, managing, and reporting personal data breaches.
Where required by law, relevant breaches will be reported to the Information Commissioner’s Office (ICO) and affected individuals within the required timescales.
15. Complaints
If you have concerns regarding how we process your personal information, please contact us first so we can attempt to resolve the matter.
You also have the right to lodge a complaint with:
Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: https://www.ico.org.uk
16. Changes to This Policy
We reserve the right to update this Data Protection Policy from time to time to reflect changes in legislation, regulatory requirements, business practices, or technology.
Any updates will be published on this page, and the revised version will take effect from the date of publication.
Contact Us
If you have any questions regarding this Data Protection Policy or the handling of your personal information, please contact:
ELD Training
Website: www.eld.training
Email: info@eld.training
Telephone: +447902144126
