Central Compliance Portal

Access operational systems, submit assessments, and review official ADE UK compliance guidance.

Governance Applications
Information Asset Register

Data Assets and Retention schedules. Authorized staff can update, track, and monitor department records.

Access Register
SAR & Breach Management

Incident breach logging, Subject Access Request tracking, automated email workflows, and DPO guidance notifications.

DPO Portal
DPIA Submissions

Self-register to complete Data Protection Impact Assessments, generate PDF outputs, and submit for DPO review.

Submit DPIA
Need to report a Data Incident or SAR?

If you suspect a personal data breach or have received a Subject Access Request, inform the Data Protection Officer immediately.

Data Protection Guidance
All Staff Should Know
UK Data Protection Law

The UK Data Protection Act 2018 and UK GDPR set out how we, as a private higher education provider, must handle personal data. We process data lawfully, transparently, and securely to protect individuals’ rights, such as those of our students and staff.

Core Duty: Only collect what’s necessary, keep it secure, and use it for specific purposes like education or employment. Breaches, like unauthorised data sharing, can lead to fines or reputational harm, so always follow our data protection policies and report concerns to the Data Protection Officer immediately (dpo@ad-education.ac.uk).
SAR Requests (Subject Access Requests)

A Subject Access Request (SAR) is when someone asks to see their personal data we hold, such as their student records. They’re entitled to know what data we have, why we use it, and who it’s shared with.

Action Required: If you receive a SAR, inform the Data Protection Officer straight away. We must respond within one month, providing the information clearly and securely after verifying the requester’s identity. Exemptions may apply, so never share data without guidance.
FOIA Requests (Freedom of Information Act)

As a private higher education provider, we’re not strictly subject to the Freedom of Information Act 2000, which applies to public bodies. However, we may still receive FOIA requests asking for non-personal information like policies or financial data.

Action Required: If you get one, don’t respond directly; forward it to the Data Protection Officer for evaluation. They’ll assess the request and decide how to proceed, ensuring we handle it appropriately.
DPIAs (Data Protection Impact Assessments)

A Data Protection Impact Assessment (DPIA) is required for projects that might pose risks to personal data, like implementing a new student database or systems. It helps us identify and mitigate risks to ensure compliance.

Action Required: If you’re involved in a new initiative, alert the Data Protection Officer to determine if a DPIA is needed. They’ll work with relevant teams to assess risks and safeguard data before proceeding.