Data Processing Agreement

Version: 23 August 2026

The Compliance Classroom – Organisational Licences

This Data Processing Agreement (“DPA”) forms part of the agreement between The Compliance Classroom (“Processor”) and the education setting, educational organisation or other customer purchasing an organisational training licence (“Controller”).

1. Purpose

The Controller uses The Compliance Classroom to provide online compliance training to authorised members of its workforce.

The Processor will process personal data only as necessary to provide, administer, support and secure the training service and in accordance with the Controller’s documented instructions, unless otherwise required by applicable law.

This DPA relates to personal data processed by The Compliance Classroom on behalf of the Controller in connection with organisational training. It does not apply to personal data processed by The Compliance Classroom for its own purposes as an independent controller, such as information provided through general website enquiries, customer account administration or optional marketing preferences.

2. Details Of The Processing

Subject Matter:
Provision and administration of online compliance training.

Duration:
For the duration of the Organisation’s licence and for any limited period thereafter where retention is necessary in accordance with the Controller’s instructions, applicable legal requirements, legitimate technical requirements or The Compliance Classroom’s Data Retention Policy.

Nature And Purpose:
Creation and administration of learner accounts; course enrolment; delivery of online training; assessment; recording progress and completion; certificate generation; reporting to authorised organisational administrators; technical support; and platform security.

Categories Of Data Subjects:
Employees, workers and other individuals authorised by the Controller to undertake training.

Types Of Personal Data:
Normally:

  • first name;
  • surname;
  • work or education setting email address;
  • organisation or group membership;
  • course enrolment;
  • course progress;
  • assessment results;
  • completion records; and
  • certificates.

The Controller must not provide special category personal data or other unnecessary personal information through the platform unless this has been expressly agreed in writing with The Compliance Classroom and an appropriate lawful basis and processing arrangement has been established.

Further information about how personal data is handled is available in our Privacy Notice, Learner Privacy Notice and School Administrator Privacy Notice.

3. Controller Responsibilities

The Controller is responsible for:

  • determining an appropriate lawful basis for processing its staff information;
  • ensuring that individuals are appropriately informed about the processing;
  • providing only personal information necessary for the training service;
  • ensuring information supplied to the Processor is accurate;
  • appointing appropriate authorised administrators;
  • maintaining appropriate security over administrator credentials;
  • ensuring administrator access to learner information is used only for legitimate organisational purposes; and
  • informing The Compliance Classroom where an instruction relating to personal data needs to be changed or withdrawn.

4. Processor Obligations

The Compliance Classroom will:

  • process personal data only on documented instructions from the Controller unless required otherwise by law;
  • inform the Controller where legally permitted if applicable law requires processing outside those instructions;
  • ensure persons authorised to process personal data are subject to appropriate confidentiality obligations;
  • implement appropriate technical and organisational security measures;
  • assist the Controller, where reasonably possible, with responding to individuals exercising their data protection rights;
  • provide reasonable assistance relating to security, personal data breaches and data protection impact assessments where required;
  • maintain appropriate records relating to its processing activities;
  • notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf; and
  • make information reasonably necessary to demonstrate compliance with these obligations available to the Controller.

If, in our reasonable opinion, an instruction from the Controller infringes applicable data protection law, we will inform the Controller where appropriate and legally permitted.

5. Security

The Processor will maintain appropriate technical and organisational measures proportionate to the nature and risk of the processing.

Measures may include:

  • access controls and role-based permissions;
  • secure authentication;
  • restricting organisational administrators to appropriate organisational information;
  • maintaining and updating the website and training platform;
  • appropriate hosting and infrastructure security;
  • backups and recovery arrangements where applicable;
  • appropriate controls over administrative access; and
  • measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

The Controller remains responsible for maintaining appropriate security over its own systems, devices, networks and administrator credentials.

6. Sub-Processors

The Controller provides general written authorisation for The Compliance Classroom to engage sub-processors where necessary to provide, maintain, secure or support the training service.

The Compliance Classroom will only appoint sub-processors that provide sufficient guarantees that appropriate technical and organisational measures will be implemented to protect personal data.

Where a sub-processor processes personal data on behalf of The Compliance Classroom, appropriate contractual data protection obligations will be imposed that provide a level of protection consistent with the requirements of this DPA and applicable data protection law.

The Compliance Classroom will remain responsible to the Controller for the performance of its data protection obligations where processing is carried out by its sub-processors, as required by applicable law.

The Compliance Classroom maintains a current Sub-Processor List, identifying relevant third-party providers used to deliver, maintain, secure and support the service, together with information about their purpose and relevant processing locations or international transfers.

Where required, Controllers will be informed of intended material changes involving the addition or replacement of relevant sub-processors and will be given an appropriate opportunity to raise reasonable data protection concerns.

7. International Transfers

Where personal data processed on behalf of the Controller is transferred outside the United Kingdom, The Compliance Classroom will ensure that the transfer is made in accordance with applicable UK data protection law.

Where required, an appropriate transfer mechanism will be used, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another legally recognised transfer mechanism.

Appropriate supplementary safeguards will be considered where required, having regard to the nature of the processing and the destination of the personal data.

Further information about relevant processing locations and international transfers is available in our Sub-Processor List.

8. Data Subject Requests

Where The Compliance Classroom receives a request from an individual relating to personal data processed on behalf of the Controller, the Processor may refer the request to the Controller.

Unless required otherwise by law, The Compliance Classroom will not respond substantively to a request relating to Controller personal data without the Controller’s authorisation.

The Compliance Classroom will provide reasonable assistance to enable the Controller to respond to valid requests in accordance with applicable data protection law.

9. Personal Data Breaches

The Compliance Classroom will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf.

Where reasonably available, we will provide information to assist the Controller in understanding:

  • the nature of the personal data breach;
  • the categories of individuals and personal data affected;
  • the likely consequences of the breach;
  • measures taken or proposed to address the breach; and
  • any steps taken to mitigate possible adverse effects.

The Compliance Classroom will provide reasonable cooperation to assist the Controller in meeting its applicable personal data breach obligations.

10. End Of Service

On termination or expiry of the service, personal data processed on behalf of the Controller will be handled in accordance with the Controller’s documented instructions, applicable data protection requirements and The Compliance Classroom’s retention arrangements.

Where required, personal data will be securely deleted or returned to the Controller, subject to any applicable legal retention requirements and limited technical retention within secure backup systems.

Personal data retained within backups will remain protected and will not be used for other purposes before being overwritten or securely deleted in accordance with the applicable backup cycle.

Further information about our approach to retaining and deleting personal information is available in our Data Retention Policy.

11. Audit And Compliance Information

The Compliance Classroom will provide information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Reasonable requests for further compliance information or audit activity will be considered having regard to the nature, risk and scale of the processing and the need to protect the security and confidentiality of other customers and systems.

Where an audit or inspection is reasonably required under applicable data protection law, the Parties will cooperate to agree an appropriate scope, method and timing designed to minimise unnecessary disruption and protect the confidentiality and security of other customers, users and systems.

12. Data Minimisation

The Controller must only provide personal information necessary for the delivery and administration of training.

The standard learner account requires only the minimum identifying information needed to establish an account and maintain an appropriate training record.

The Controller should not enter unnecessary personal information, special category data or confidential information into learner account fields, administrator notes or other areas of the platform unless this has been expressly agreed with The Compliance Classroom and is necessary for the service.

13. Relationship With The Main Agreement

This DPA forms part of the Controller’s agreement with The Compliance Classroom.

It should be read alongside the School & Organisation Licence Agreement and our Terms & Conditions.

If there is a conflict between this DPA and general commercial terms in relation to the processing of personal data, this DPA will take precedence to the extent of that conflict.