× Home About us Apprenticeships Employer engagement Leadership and Management Programmes Health and Social Care Programmes Advanced Learner Loans Learner support Join our team Contact us

Contact us 02920 799 133

Data Protection & Privacy Policy

.

General Statement

t2 group is committed to protecting and respecting the privacy of individuals and handling personal data responsibly, securely, and transparently in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations (PECR), and other applicable data protection legislation.

This policy explains how t2 group collects, uses, stores, shares, retains, and safeguards personal data and demonstrates the organisation’s commitment to accountability through appropriate governance, policies, technical and organisational measures, staff training, and ongoing monitoring.

The UK GDPR sets out the following key principles which t2 group will comply with:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

Personal data will only be processed where there is a clear lawful basis and where individuals would reasonably expect such processing to occur.

 

2. GDPR Compliance & Governance

.

All personal data processing at t2 group will be conducted in compliance with applicable data protection legislation. This includes implementing appropriate technical and organisational measures to ensure personal data is processed securely, lawfully and fairly.

This includes:

  • Maintaining appropriate data protection policies and procedures
  • Appointing a Data Protection Officer (DPO) or designated privacy lead
  • Conducting Data Protection Impact Assessments (DPIA) where appropriate
  • Ensuring staff receive data protection and information security training
  • Managing and recording personal data breaches
  • Monitoring compliance through periodic review and audit activities
  • Applying privacy by design and default principles to systems and processes

All employees, contractors, consultants, and temporary staff are expected to comply with this policy and associated procedures.

 

3. Lawful Basis for Processing

.

t2 group processes personal data under one of the six legal bases set out under Article 6 UK GDPR.

3.1 Consent

Processing where a clear and freely given opt-in is required, including certain electronic marketing communications and optional activities.

Individuals may withdraw consent at any time where consent is relied upon.

3.2 Contract

Processing necessary:

  • To fulfil contractual obligations with an individual
  • To deliver training, education, employment, or support services
  • To take steps prior to entering into contract

3.3 Legal Obligation

Processing required to comply with statutory, regulatory, safeguarding, employment, taxation, funding body or other legal obligations.

3.4 Vital Interests

Processing necessary to protect the vital interests of an individual or another person, including emergency situations involving health or safety.

3.5 Public Task

Where applicable, processing may be undertaken in connection with activities carried out in the public interest or under statutory authority, including publicly funded educational or training activities.

3.5 Legitimate Interest

Processing necessary for legitimate organisational or business interests, except where overridden by rights and freedoms of individuals.

Where legitimate interests are relied upon, t2 group will assess:

  • The purpose of the processing
  • Whether the processing is necessary
  • The impact on individuals’ rights and freedoms

Examples may include:

  • Fraud prevention
  • Information security
  • Internal investigations
  • Service improvement
  • Administrative management
  • Network and systems security

4. Special Category & Criminal Offence Data

.

t2 group may process special category data where permitted under Article 9 UK GDPR and Schedule 1 of the Data Protection 2018.

This may include:

  • Health data
  • Equality and diversity data
  • Safeguarding information
  • Trade union membership information
  • Biometric data where applicable

Processing will only occur where:

  • Appropriate lawful conditions apply
  • Processing is necessary and proportionate
  • Appropriate safeguards are implemented

Criminal offence data will only be processed where authorised by law and subject to appropriate confidentiality and security measures.

t2 group maintains an Appropriate Policy Document (APD) where required under the Data Protection Act 2018.

 

5. Retention of Data

.

Personal data will only be retained for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, safeguarding, contractual, funding, and operational requirements.

Data will be securely deleted, anonymised, archived, or disposed of I accordance with the organisation’s Data Retention Policy and records management procedures.

5.1 Employee Data

  • Retained in line with employment law, HMRC requirements, safeguarding obligations, and organisational retention schedules available on our website
  • Archived employee files are subject to restricted access controls and may only be accessed where necessary and authorised

5.2 Learner Data

  • Retained in compliance with funding body regulations (typically six years after completion) in line with our Data Retention Policy, available on our website
  • Any variances to this will be expressly agreed accordingly with the individual

 

6. Individual Rights

.

Under UK GDPR, individuals have the following rights regarding their personal data.

6.1 Right to Be Informed

Individuals have the right to receive clear and transparent information about how their personal data is processed.

6.2 Right of Access

Individuals may request access to their personal data.

Requests should be submitted to dataprotection@t2group.co.uk

t2 group will respond within one month of receipt or applicable statutory timeframe.

Where requests are complex or numerous, or where clarification or identity verification is required, the response timeframe may be extended in accordance with applicable data protection law.

6.3 Right to Rectification

Individuals may request correction of inaccurate data or incomplete personal data.

Where appropriate and feasible, relevant third parties will be informed of corrections.

6.4 Right to Erasure (“Right to be Forgotten”)

Individuals can request deletion of their data where there is no compelling reason for continued processing.

Requests will be assessed against applicable legal, contractual, safeguarding, funding, regulatory, and organisational purposes.

6.5 Right to Restriction of Processing

Individuals can request that processing of their personal data be limited in certain circumstances.

6.6 Right to Object

Individuals may object to processing based on legitimate interest or direct marketing purposes.

Objection requests can be submitted to dataprotection@t2group.co.uk

6.7 Right to Data Portability

Where applicable, individuals can request their personal data in a structured, commonly used, and machine-readable format.

6.8 Rights Related to Automated Decision-Making

t2 group does not currently undertake solely automated decision-making producing legal or similarly significant effects without human involvement.

Where automated processing is used, appropriate safeguards and human oversight will be implemented where required.

6.9 Right to Complain

Individuals have the right to raise concerns directly with t2 group and may also lodge a complaint with the Information Commissioner’s Office (ICO)

 

7. Data Breach Management

.

t2 group follows a Data Breach Response Plan to identify, assess, manage, and record personal data breaches.

This includes:

  • Internal reporting and escalation requirements
  • Breaches are assessed for risk to individuals' rights and freedoms
  • Containment and remediation measures
  • The ICO is notified within 72 hours if required
  • Affected individuals are informed where applicable
  • Maintenance of breach records and lessons learned reviews

All staff must report suspected personal data breaches immediately.

 

8. Privacy by Design & Security Measures

.

t2 group implements Privacy by Design and Default principles when implementing systems, processes and business activities.

Appropriate technical and organisational security measures may include:

  • Role-based access controls
  • Data encryption and anonymisation/pseudonymisation
  • Regular security audits
  • Multi-factor authentication where appropriate
  • Secure storage and disposal controls
  • Network and endpoint security measures
  • Access logging and monitoring
  • Vulnerability management and patching
  • Backup and recovery procedures
  • Confidentiality obligations for staff and suppliers

Data Protection Impact Assessments (DPIAs) will be undertaken where processing is likely to result in a high risk to individuals.

 

9. International Transfers

.

Where personal data is transferred outside the UK, t2 group will ensure appropriate safeguards are implemented in accordance with Chapter V UK GDPR.

Safeguards may include:

  • UK adequacy regulations
  • International Data Transfer Agreements (IDTAs)
  • Standard Contractual Clauses (SCCs)
  • Transfer risk assessments
  • Additional technical and organisational safeguards where appropriate

Data Protection Impact Assessments (DPIAs) will be undertaken where processing is likely to result in a high risk to individuals.

 

10. PECR, Cookies & Electronic Marketing

.

t2 group will comply with the Privacy and Electronic Communications Regulations (PECR) when undertaking electronic marketing activities or using cookies and similar technologies.

This includes:

  • Obtaining consent for non-essential cookies where required
  • Providing clear cookie information through cookie notices and banners
  • Respecting unsubscribe and marketing preference requests
  • Ensuring electronic marketing communications are lawful and transparent
  • Managing consent and communication preferences appropriately

Further details are available within the organisation’s Cookie Notice and Privacy Notices.

 

11. Third-Party Processors & Suppliers

.

Where third-party suppliers process personal data on behalf of t2 group, appropriate due diligence and contractual safeguards will be implemented.

This includes:

  • Data processing agreements compliant with Article 28 UK GDPR
  • Security and confidentiality obligations
  • International transfer safeguards where applicable
  • Ongoing supplier oversight where appropriate

 

12. Staff Training & Responsibilities

.

All staff are responsible for protecting personal data and complying with this policy.

t2 group will provide appropriate data protection, privacy, cybersecurity, and information governance training to staff on a periodic basis

Failure to comply with this policy may result in disciplinary action.

 

13. Amendments & Contact Information

.

t2 group reserves the right to amend this policy as needed.

For any questions or concerns, contact our Data Protection Officer:

Email: dataprotection@t2group.co.uk

Address: t2 group, Fern House, Unit 1, Links Court, Fortran Road, St. Mellons, CARDIFF CF3 0LT

This policy is reviewed annually to ensure continued compliance with UK GDPR and Data Protection Act 2018.

 

t2 group

t2 group
Head Office - Fern House, Unit 1 Links Court,
Fortran Road, St.Mellons,
Cardiff CF3 0LT

02920 799 133

Legal information

Report a Safeguarding Concern

Safeguarding iconNeed to report a Safeguarding concern? Click here.

Connect with us
Acumen Coaching

Acumen Coaching is a specialist Leadership and Management Division of the t2 group.

t2 group and Acumen Coaching are part of the Marr Corporation Ltd.