Data Protection, Privacy and GDPR
TEFL Society is committed to protecting the privacy, confidentiality, integrity, and security of personal data. This policy explains how we collect, use, store, share, and protect personal data in compliance with:
- The UK General Data Protection Regulation (UK GDPR)
- The Data Protection Act 2018
- The Privacy and Electronic Communications Regulations (PECR) (where applicable)
- Data (use and access) Act 2025
- Other applicable UK privacy and data protection laws
We recognise the importance of handling personal data lawfully, fairly, and transparently.
- Data Protection Principles
In accordance with Article 5 UK GDPR and the Data Protection Act 2018, TEFL Society shall ensure personal data is:
1.1 Processed lawfully, fairly, and transparently
1.2 Collected for specified, explicit, and legitimate purposes
1.3 Adequate, relevant, and limited to what is necessary
1.4 Accurate and kept up to date
1.5 Retained only as long as necessary
1.6 Processed securely using appropriate technical and organisational measures
1.7 Accountable, with evidence of compliance
- Lawful Basis for Processing
We process personal data only where a lawful basis applies, including:
2.1 Consent
2.2 Performance of a contract
2.3 Compliance with legal obligations
2.4 Protection of vital interests
2.5 Legitimate interests pursued by the TEFL Society or a third party
Where special category data is processed, we will identify an additional lawful condition under the Data Protection Act 2018 and UK GDPR.
- Personal Data We May Collect
Depending on our relationship with individuals, we may collect:
3.1 Name, address, email address, telephone number
3.2 Date of birth
3.3 Employment and payroll details
3.4 Bank/payment details
3.5 Identification documents
3.6 Health information where required for employment
- How We Use Personal Data
We may use personal data for:
4.1 Providing products and services
4.2 Managing customer relationships
4.3 Recruitment and employment administration
4.4 Legal and regulatory compliance
4.5 Health and safety obligations
4.6 Marketing communications (where lawful)
4.7 Improving services and website functionality
- Data Sharing
We may share personal data with:
5.1 Professional advisers like auditors from the awarding body
5.2 IT service providers and software platforms
5.3 Government bodies, regulators, or law enforcement where required
5.4 Approved subcontractors and service partners
All third-party processors must provide sufficient guarantees regarding data security and compliance with UK GDPR.
- International Transfers
Where personal data is transferred outside the UK, TEFL Society will ensure appropriate safeguards are in place, including:
6.1 UK adequacy regulations
6.2 International Data Transfer Agreements (IDTAs)
6.3 Standard contractual clauses or other lawful mechanisms
- Data Security
We implement appropriate technical and organisational security measures, including:
7.1 Access controls and user permissions
7.2 Password protection and multi-factor authentication
7.3 Encryption where appropriate
7.4 Secure backups
7.5 Anti-virus and cyber security controls
7.6 Confidentiality obligations for staff
- Data Retention
8.1 Personal data will only be retained for as long as necessary for business, legal, tax, regulatory, or contractual purposes.
8.2 When data is no longer required, it will be securely deleted.
- Individual Rights
Under UK GDPR, individuals may have the right to:
9.1 Be informed about processing
9.2 Access their personal data
9.3 Rectify inaccurate data
9.4 Erase data (“right to be forgotten”)
9.5 Restrict processing
9.6 Data portability
9.7 Object to processing
9.8 Object to automated decision-making and profiling
Requests should be submitted to info@teflsociety.org. We will respond within statutory timeframes.
- Data Breaches
10.1 Any actual or suspected personal data breach must be reported immediately to Daniel Parrott though info@teflsociety.org
10.2 We will investigate breaches promptly and, where required, notify affected individuals where there is a high risk
- Employee Responsibilities
All staff must:
11.1 Handle personal data confidentially
11.2 Follow TEFL Society procedures
11.3 Report breaches immediately
11.4 Complete relevant data protection training
11.5 Only access personal data where authorised
Failure to comply may result in disciplinary action.
- Complaints
Individuals have the right to complain to the Information Commissioner’s Office (ICO) if they believe their data has been handled unlawfully.
Website: https://ico.org.uk
This policy will be reviewed annually or sooner if required due to legislative, regulatory, or operational changes. Last reviewed 29/05/26
All reference to TEFL Society refers to Gotoco trading as TEFL Society