Draft proposition · model document v1.0 · not yet approved
← Back to model documents Draft model document · v1.0 · not yet approved

Information and Record-Keeping

For adoption or adaptation by registered providers

Use
Provider: [Provider name] · Responsible person: [Name or role] · Review date: [Date]

Our commitment

We keep accurate training records, protect personal information and avoid collecting information we do not need.

Records we keep

Depending on the course and our role, records may include:

  • learner name and contact details;
  • course title, date and location;
  • attendance;
  • assessment decisions;
  • certificates issued;
  • trainer and assessor details;
  • agreed learner adjustments;
  • feedback, complaints or appeals;
  • quality checks and significant incidents.

Accuracy

Records should be completed at the time of the activity or as soon as practical afterwards.

Errors are corrected without hiding the original history where that history matters.

Access and security

Electronic information is protected by suitable passwords, access controls and backups.

Paper records are stored securely and are available only to people who need them.

Personal information is not shared without a proper reason.

Retention

We keep records only for as long as there is a clear operational, contractual, insurance, legal or quality reason.

Our retention periods are recorded in a simple retention schedule and reviewed regularly.

When information is no longer needed, it is securely deleted or destroyed.

Learner rights

People may ask how their information is used and may request access or correction where applicable.

Requests are handled promptly and passed to [responsible person or privacy contact].

Data incidents

Loss, unauthorised access or accidental disclosure is reported immediately to the responsible person.

We take steps to contain the issue, assess the risk and make any required notification.

Use of systems and suppliers

Where we use an online platform, cloud service or subcontractor to handle information, we take reasonable steps to check that it is suitable and secure.

Audit and investigation

Relevant records may be provided to IVOSA or another authorised party during a valid audit or justified investigation, subject to appropriate confidentiality and data-protection controls.

Privacy notice

We provide a separate short privacy notice explaining what personal information we collect, why we use it, how long we keep it and how people can contact us.

Review

We review this policy at least once a year and after any significant information incident or system change.

This is a draft IVOSA model document (v1.0), for design and governance/legal review. It is not yet approved for live use.