Data Protection, Privacy and GDPR

TEFL Society is committed to protecting the privacy, confidentiality, integrity, and security of personal data. This policy explains how we collect, use, store, share, and protect personal data in compliance with:  

We recognise the importance of handling personal data lawfully, fairly, and transparently.

  1. Data Protection Principles

In accordance with Article 5 UK GDPR and the Data Protection Act 2018, TEFL Society shall ensure personal data is:

1.1 Processed lawfully, fairly, and transparently

1.2 Collected for specified, explicit, and legitimate purposes

1.3 Adequate, relevant, and limited to what is necessary

1.4 Accurate and kept up to date

1.5 Retained only as long as necessary

1.6 Processed securely using appropriate technical and organisational measures

1.7 Accountable, with evidence of compliance

  1. Lawful Basis for Processing

We process personal data only where a lawful basis applies, including:

2.1 Consent

2.2 Performance of a contract

2.3 Compliance with legal obligations

2.4 Protection of vital interests

2.5 Legitimate interests pursued by the TEFL Society or a third party

Where special category data is processed, we will identify an additional lawful condition under the Data Protection Act 2018 and UK GDPR.

  1. Personal Data We May Collect

Depending on our relationship with individuals, we may collect:

3.1 Name, address, email address, telephone number

3.2 Date of birth

3.3 Employment and payroll details

3.4 Bank/payment details

3.5 Identification documents

3.6 Health information where required for employment

  1. How We Use Personal Data

We may use personal data for:

4.1 Providing products and services

4.2 Managing customer relationships

4.3 Recruitment and employment administration

4.4 Legal and regulatory compliance

4.5 Health and safety obligations

4.6 Marketing communications (where lawful)

4.7 Improving services and website functionality

  1.  Data Sharing

We may share personal data with:

5.1 Professional advisers like auditors from the awarding body

5.2 IT service providers and software platforms

5.3 Government bodies, regulators, or law enforcement where required

5.4 Approved subcontractors and service partners

All third-party processors must provide sufficient guarantees regarding data security and compliance with UK GDPR.

  1.  International Transfers

Where personal data is transferred outside the UK, TEFL Society will ensure appropriate safeguards are in place, including:

6.1 UK adequacy regulations

6.2 International Data Transfer Agreements (IDTAs)

6.3 Standard contractual clauses or other lawful mechanisms

  1.  Data Security

We implement appropriate technical and organisational security measures, including:

7.1 Access controls and user permissions

7.2 Password protection and multi-factor authentication

7.3 Encryption where appropriate

7.4 Secure backups

7.5 Anti-virus and cyber security controls

7.6 Confidentiality obligations for staff

  1.  Data Retention

8.1 Personal data will only be retained for as long as necessary for business, legal, tax, regulatory, or contractual purposes.

8.2 When data is no longer required, it will be securely deleted.

  1.  Individual Rights

Under UK GDPR, individuals may have the right to:

9.1 Be informed about processing

9.2 Access their personal data

9.3 Rectify inaccurate data

9.4 Erase data (“right to be forgotten”)

9.5 Restrict processing

9.6 Data portability

9.7 Object to processing

9.8 Object to automated decision-making and profiling

Requests should be submitted to info@teflsociety.org. We will respond within statutory timeframes.

  1. Data Breaches

10.1 Any actual or suspected personal data breach must be reported immediately to Daniel Parrott though info@teflsociety.org

10.2 We will investigate breaches promptly and, where required, notify affected individuals where there is a high risk

  1. Employee Responsibilities

All staff must:

11.1 Handle personal data confidentially

11.2 Follow TEFL Society procedures

11.3 Report breaches immediately

11.4 Complete relevant data protection training

11.5 Only access personal data where authorised

Failure to comply may result in disciplinary action.

  1.  Complaints

Individuals have the right to complain to the Information Commissioner’s Office (ICO) if they believe their data has been handled unlawfully.

Website: https://ico.org.uk

This policy will be reviewed annually or sooner if required due to legislative, regulatory, or operational changes. Last reviewed 29/05/26

All reference to TEFL Society refers to Gotoco trading as TEFL Society