Privacy Policy
Last updated 3 July 2026
This privacy notice for Datalaw Ltd (“we”, “us”, or “our”) explains how and why we collect, use, store, share and otherwise process your personal information when you interact with our services. It applies when you:
- visit our website at https://datalawonline.co.uk or any other website we operate that links to this notice;
- register for, purchase, or use any of our continuing professional development (CPD), legal training, accreditation, or apprenticeship services;
- are an apprentice or learner enrolled on a programme delivered by Datalaw under a contract with the Department for Education (DfE), an awarding body, or an end-point assessment organisation;
- attend our live online training, workshops, or induction sessions; or
- engage with us in any other way, including through marketing, events, or correspondence.
This notice is governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUAA), as well as the Privacy and Electronic Communications Regulations 2003 (PECR) where relevant.
Note: since 31 March 2025 the Department for Education (DfE) has taken over the functions of the former Education and Skills Funding Agency (ESFA). References in this notice to the DfE include those former ESFA functions.
If you have questions or want to exercise any of your rights, you can contact our Data Protection Officer at dpo@datalaw.org. Full contact details are at the end of this notice.
Summary of key points
This summary gives the headline points. Each topic links to the relevant section below for the detail.
What personal information do we process? Account, contact, billing, professional, learning, and limited sensitive data when you register, learn, purchase, or correspond with us. See Section 1.
Do we process any sensitive personal information? Yes – limited categories, with your explicit consent or under a specific UK GDPR Article 9 condition. See Section 1.
Do we record training sessions? Yes. We record our live apprenticeship training, workshops and induction sessions, which capture participants’ image, voice and contributions; we rely on our legitimate interests to do this, not on your consent. We also record the live webinars we run for our courses, but published recordings capture only the presenter. See Section 4.
Do we use AI? Yes – clearly labelled AI assistants and AI-supported reporting tools. We explain providers, training-data position, automated decision-making, and human review in Section 7.
Do we share your information? Only with named categories of recipients – sub-processors, regulators, and education partners – under written agreements. See Section 5.
How long do we keep it? Only for as long as necessary, with documented retention periods. See Section 9.
What are your rights? UK GDPR rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Plus the new right under DUAA 2025 to complain directly to us before going to the Information Commissioner. See Section 12.
Table of contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- Recording of live training sessions
- When and with whom do we share your personal information?
- Cookies and other tracking technologies
- AI Products and automated processing
- International data transfers
- How long do we keep your information?
- How we keep your information safe
- Children, young people and apprentices
- Your privacy rights
- Data breaches
- Updates to this notice
- How to contact us
- How to make a subject access or other rights request
1. What information do we collect?
Personal information you provide to us
In Short: We collect personal information you give us when you register, learn, purchase, or contact us.
Depending on how you interact with us, this may include:
- Identity and contact data – name, job title, employer, work address, email address, phone number;
- Account data – username, password (hashed), contact preferences;
- Billing data – billing address, invoice details, VAT number where applicable;
- Learning data – courses purchased, course progress, assessment results, certificates issued, attendance records, CPD logs, and session recordings (image, voice, and contributions from live online sessions – see Section 4);
- Apprenticeship data – Unique Learner Number (ULN), date of birth, prior qualifications, employer details, off-the-job training records, end-point assessment data, DfE-required information;
- Communications – emails, support tickets, feedback, survey responses;
- Payment data – payment instrument number and security code where you pay by card, and bank account details where you pay for a subscription by Direct Debit. Card payments are handled by Stripe and Direct Debit payments by GoCardless; neither your card number nor your bank details are stored on our systems. See https://stripe.com/gb/privacy and https://gocardless.com/privacy.
Sensitive personal information
We process special category data and other sensitive data only where strictly necessary, on a documented Article 9 UK GDPR condition (and where applicable a Schedule 1 DPA 2018 condition). The categories we may process are:
- Information revealing racial or ethnic origin – collected solely for equal-opportunities monitoring on apprenticeship and accreditation programmes; lawful basis Article 9(2)(g) UK GDPR / DPA 2018 Schedule 1 Part 2 paragraph 8 (equality of opportunity or treatment);
- Health information – only where you tell us about a reasonable adjustment requirement for an examination, live session or assessment; Article 9(2)(b) employment, social security and social protection law, or 9(2)(h) provision of social care, as applicable;
- National Insurance number – for apprenticeship learners only, required by the DfE and the awarding body; lawful basis Article 6(1)(c) legal obligation.
We do not process special category data for marketing purposes or to make automated decisions about you.
Information collected automatically
In Short: We automatically collect technical and usage information when you visit our services.
This information does not on its own identify you. It includes IP address, device and browser characteristics, operating system, language, referring URL, country, page-level usage, error reports, and similar telemetry. We collect it to keep the services secure, diagnose problems, and produce aggregate analytics. See our Cookie Policy for the technologies used.
Information from third parties
We may receive information from public databases, professional registers (for example the Solicitors Regulation Authority public roll), employer-provided learner enrolment lists, marketing partners, and from social media platforms where you have chosen to share it.
Google API
Where we use Google APIs, our use complies with the Google API Services User Data Policy, including the Limited Use requirements.
2. How do we process your information?
In Short: We process your information to deliver, improve, and administer our services, communicate with you, comply with legal obligations, and prevent fraud.
Specifically, we process your personal information to:
- create and administer your account;
- deliver the courses, accreditations, CPD, and apprenticeship programmes you enrol on;
- record and quality-assure our live training sessions, and evidence off-the-job training for funding, audit, and inspection purposes (see Section 4);
- fulfil payment, invoicing, and renewal processes;
- respond to your enquiries and provide support;
- send service communications (course access, certificates, renewals, terms changes);
- send marketing communications where you have opted in or where we are entitled to rely on the soft opt-in under PECR Regulation 22(3);
- report to regulators and funders (DfE, Ofsted, awarding bodies, end-point assessment organisations) where we are contractually or statutorily required;
- monitor service performance, prevent and detect fraud, and protect the safety of our staff, learners, and other users;
- comply with our legal and regulatory obligations and to defend or pursue legal claims.
3. What legal bases do we rely on?
In Short: We process your information on one of the six lawful bases set out in Article 6 UK GDPR, and where the data is special category, on an Article 9 condition.
The bases we rely on are:
Consent (Article 6(1)(a)) – For most direct marketing to consumers, optional cookies, and the AI features described in Section 7 where consent is the chosen basis. You can withdraw consent at any time without affecting earlier processing.
Contract (Article 6(1)(b)) – For processing necessary to perform our contract with you – account creation, course delivery, payment, certification, technical support, and similar.
Legal obligation (Article 6(1)(c)) – For processing required by law – for example, retention of accounting records under the Companies Act 2006, DfE reporting for apprentices, safeguarding records, and disclosures required by HMRC or by court order.
Vital interests (Article 6(1)(d)) – In rare cases – for example, sharing information with emergency services where a life is at risk.
Public task (Article 6(1)(e)) – Where we process apprentice information as part of the publicly funded apprenticeship system, in conjunction with the DfE and Ofsted.
Legitimate interests (Article 6(1)(f), as amended by DUAA 2025) – Where we have assessed that our (or a third party’s) legitimate interests are not overridden by your rights and freedoms. We rely on this for delivering, recording, and quality-assuring our training and apprenticeships (see Section 4), service improvement, fraud prevention, B2B marketing under PECR, network and information security, and for the recognised legitimate interests introduced by the DUAA 2025 (including direct marketing in defined circumstances and intra-group sharing for administrative purposes). We document a Legitimate Interests Assessment for each such use; you can request a summary by contacting our DPO.
Where we process special category data, we also rely on a UK GDPR Article 9 condition. The conditions we use are 9(2)(a) explicit consent, 9(2)(b) employment / social security law, 9(2)(g) reasons of substantial public interest (with a DPA 2018 Schedule 1 Part 2 condition, typically equality of opportunity or treatment), and 9(2)(h) provision of social care.
4. Recording of live training sessions
In Short: We record our live online training, workshops, and induction sessions, and rely on our legitimate interests to do so.
As part of our apprenticeships, we record live online sessions delivered via Microsoft Teams or Zoom. These recordings capture participants’ image, voice and spoken contributions, in both one-to-one and group sessions. We also record the live webinars we run for our courses so they can be made available on demand. Webinar recordings are edited before publication to capture only the presenter: spoken questions and audience contributions are removed. Where a question is particularly useful, we may reflect it in the course notes or slides in summarised form, without identifying who asked it.
Why we do this. We record sessions so that:
- learners and their employers or mentors can re-watch them to consolidate learning and revisit tasks or information;
- we can evidence and quality-assure delivery of the apprenticeship, including off-the-job training, in line with DfE funding rules and Ofsted expectations, and support audit, assurance, and end-point-assessment readiness;
- learners who miss a group session are not disadvantaged; and
- we hold an accurate record for safeguarding, complaints, and dispute-resolution purposes.
Our legal basis. We rely on our legitimate interests (Article 6(1)(f) UK GDPR) for this processing. We do not rely on your consent, because recording is an integral part of how the training is delivered and quality-assured.
How we protect recordings. Recordings are stored on a secure platform that is encrypted and password-protected, with access restricted, on a permission basis, to those who require it – the relevant learner, their employer or mentor, other members of the same cohort (for group sessions only), and authorised Datalaw staff. Recordings are never used for marketing or sales purposes.
How long we keep recordings. We retain session recordings with the apprenticeship record – for the duration of the apprenticeship and for 6 years after it ends – in line with our record-keeping obligations as a DfE-funded training provider (see Section 9).
What we ask of participants. Learners are reminded at appropriate points not to disclose confidential client information, individual case details, or third-party personal data during sessions. Confidentiality remains a shared responsibility between the learner and their employer, and employers are encouraged to remind learners of their duties. In line with our Camera On Policy, learners participate with cameras on as a safeguarding measure and to confirm attendance; camera-off participation can be agreed where a medical condition or reasonable adjustment applies.
Your rights. You have the right to object to this processing (see Section 12). If you object, we will consider your objection and will stop unless we have compelling legitimate grounds to continue. As recording is an integral part of how the apprenticeship is delivered and quality-assured, there may be circumstances in which we cannot deliver the programme in its current form without it; wherever possible we will discuss reasonable adjustments (such as participating with your camera off) with you.
5. When and with whom do we share your personal information?
In Short: Only with named categories of recipients, under written agreements that protect your data.
We share personal information with the following categories of recipients:
Sub-processors and service providers
- Cloud hosting and storage – Amazon Web Services (UK / EU regions, with backup to Amazon S3 Glacier);
- Payment processing – Stripe and GoCardless;
- Email delivery and marketing – SendGrid and Elastic Email;
- Live chat and support – Crisp;
- Analytics and tag management – Google Analytics, Google Tag Manager, and Kissmetrics (cookie-based – see Section 6);
- Advertising and retargeting – Google Ads / DoubleClick, the Meta (Facebook) Pixel, and the LinkedIn Insight Tag (cookie-based – see Section 6);
- On-site engagement and product tours – Optinly and Produktly;
- Scheduling – Calendly (appointment booking embeds);
- AI services – Anthropic and Amazon Transcribe (see Section 7);
- Performance monitoring – New Relic (page performance and error telemetry);
- Video conferencing and session recording – Microsoft Teams and Zoom;
- Video and content – Vimeo, YouTube;
We put written contracts in place with our sub-processors, incorporating UK GDPR Article 28 clauses requiring confidentiality, security, and onward processing only on documented instructions. We review these contracts periodically, and where a vendor’s terms fall short of our requirements we remediate or replace the vendor.
Education and apprenticeship partners
- Department for Education (DfE), including through the Individualised Learner Record (ILR) and the Learning Records Service (LRS);
- Ofsted (where it inspects our provision);
- Awarding bodies and end-point assessment organisations;
- Apprentice employers (for off-the-job training records, session recordings, and progress reports);
- The Solicitors Regulation Authority (where applicable to qualification recording).
Privacy notices provided at onboarding. When you enrol as an apprentice, we ask you to review and confirm that you have read this privacy notice, together with the DfE’s ILR privacy notice and the Learning Records Service (LRS) privacy notice, which explain how those bodies use your personal data. You confirm this by ticking the relevant box on the onboarding registration form, and a record of your confirmation is kept; enrolment cannot be completed without it.
Other recipients
- Professional advisers (lawyers, auditors, insurers) under duties of confidentiality;
- Regulators and law enforcement where required by law;
- An acquirer or successor in the event of a merger, sale, or other corporate transaction;
- Other users – only where you choose to post Contributions in public areas of the services (see our Terms and Conditions).
We do not sell your personal information.
6. Cookies and other tracking technologies
In Short: We use a small number of cookies and similar technologies. Full details, including how to consent, refuse, or withdraw consent, are in our Cookie Policy.
Our cookie banner offers “Allow all” and “Reject all” options of equal prominence, with per-category choices under “Show details”. Non-essential cookies are not set unless you allow them. You can change or withdraw your choices at any time through the cookie settings link on our website. Full details of the cookies we use, their durations, and how to manage them are in our Cookie Policy.
7. AI Products and automated processing
In Short: We use AI to support specific features. Where you interact directly with an AI assistant we tell you so, and we never use AI alone to make a decision that significantly affects you.
Where we use AI
As of the date of this notice, we use AI services in the following ways:
- AI-supported reporting and document drafting on the apprenticeship and CPD reporting workflows used by our internal team – your data is processed only insofar as it forms the input to a report request;
- Optional in-product AI assistants for learner Q&A on selected courses (clearly labelled as AI in the relevant interface);
- Internal operations support (for example summarising support tickets and generating draft responses for staff review).
Who provides our AI
Our primary AI provider is Anthropic (Claude family of models). We also use Amazon Transcribe, an Amazon Web Services AI service, for audio transcription. Anthropic and AWS act as our sub-processors under contracts that include UK GDPR Article 28 obligations and a UK Addendum to the EU SCCs (or the UK International Data Transfer Agreement) covering any transfer of personal information to the United States.
Training-data position
Under our commercial contracts, your inputs and the AI outputs are not used to train Anthropic’s or AWS’s foundation models. Inputs are retained only for the limited operational and abuse-prevention periods set out in those contracts.
Automated decision-making (Article 22 UK GDPR)
We do not make any decision that produces legal effects concerning you, or similarly significantly affects you, based solely on automated processing – including any AI feature. Outputs from AI are reviewed by a human before any consequential decision is made about, for example, course progression, accreditation, employment, or apprenticeship achievement.
EU AI Act transparency
Where the EU AI Act Article 50 transparency obligations apply (binding from 2 August 2026), we will additionally label AI-generated content where it is presented as if it could plausibly be human-authored, and we will tell you when you are interacting with an AI system rather than a person.
8. International data transfers
Most of our processing happens in the UK or in the European Economic Area (EEA). Where personal information is transferred outside the UK – primarily to the United States in connection with AWS, Microsoft, Zoom, Anthropic, Stripe, SendGrid, Google, Meta, LinkedIn, New Relic, Kissmetrics, and Calendly services – we rely on one of the following safeguards under Articles 44-46 UK GDPR:
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to the European Commission’s Standard Contractual Clauses;
- the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) where the recipient is certified;
- an adequacy regulation under section 17A DPA 2018 (where one applies).
You can request a copy of the safeguard relevant to a particular transfer by contacting our DPO.
9. How long do we keep your information?
In Short: Only for as long as necessary, with documented retention periods.
Indicative retention periods:
- Account and learning records – for the life of your account plus 6 years (limitation period);
- Apprenticeship records (including session recordings and evidence of off-the-job training) – for the life of the apprenticeship plus the period required by DfE funding rules (currently a minimum of 6 years after the end of the apprenticeship, calculated from the financial year end following the last funding payment), retained for funding-audit, safeguarding, quality-assurance, and inspection (including Ofsted) purposes;
- Individualised Learner Record (ILR) data – data we submit is separately retained by the DfE for 20 years for operational purposes (such as funding learning and publishing official statistics), and thereafter in research databases as described in the ILR privacy notice;
- Accreditation and certification records – full records for 6 years from issue; after that we keep only a minimal register of certificates issued (name, course, date and certificate number) so we can verify or reissue a certificate on request;
- Financial records – 6 years (Companies Act 2006, VAT regulations);
- Marketing preferences – until you withdraw consent or unsubscribe;
- Live chat transcripts – 12 months unless required for an investigation.
When the retention period ends, we delete or anonymise the data, or where deletion is not technically feasible (for example, encrypted backup tapes), we isolate it and delete it on the next backup cycle.
You can read the DfE record-keeping and retention guidance for training providers at https://www.gov.uk/government/publications/record-keeping-and-retention-guidance-for-fe-training-providers.
10. How we keep your information safe
We have implemented technical and organisational measures appropriate to the risks of our processing. These include role-based access controls, encryption in transit and at rest, regular vulnerability scanning, secure software development practice, regular staff data-protection training, vendor due diligence, and a documented incident response plan. No system can be guaranteed 100% secure, but we work to minimise risk and respond quickly if an incident occurs.
11. Children, young people and apprentices
In Short: We accept apprentices and learners aged 16 and over. We do not knowingly market to or collect personal information from children under 16.
Datalaw delivers apprenticeship programmes from Level 3 (Paralegal) upwards. Some apprentices begin their programme at age 16 or 17. For learners under 18 we:
- collect only the personal information necessary for the apprenticeship and required by the DfE / the awarding body;
- apply the standards of the ICO Age Appropriate Design Code (the “Children’s Code”) to any online service used by under-18s;
- rely on Article 6(1)(c) legal obligation and Article 6(1)(e) public task as the lawful bases for the apprenticeship-related processing, supported by parental notification where appropriate, and apply additional safeguards appropriate to the learner’s age (including in relation to session recording);
- have a documented safeguarding procedure overseen by our designated Safeguarding Officer.
We do not knowingly accept or onboard children under 16. If you believe we hold information about a child under 16 that should not be in our systems, contact our DPO and we will investigate and, where required, delete it.
12. Your privacy rights
In Short: UK GDPR gives you a set of rights over your personal information, and the DUAA 2025 adds a new right to complain to us directly.
Subject to certain conditions and exemptions, you have the right to:
- access the personal information we hold about you (a “subject access request”);
- have inaccurate information corrected (“rectification”);
- have your information deleted (“erasure” / “right to be forgotten”);
- restrict our processing of your information;
- receive your information in a portable format and have it transferred to another controller;
- object to processing based on legitimate interests, including direct marketing and our recording of training sessions (see Section 4);
- withdraw any consent you have given;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22).
In addition, since 19 June 2026 you have the right under section 164A of the Data Protection Act 2018 (inserted by the Data (Use and Access) Act 2025) to complain to us directly if you think we have infringed data protection law in handling your personal information. The easiest way is to use the data protection complaints form on our website (https://pages.datalawonline.co.uk/make-a-data-protection-complaint/), or you can email dpo@datalaw.org, call, or write to us. We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you informed of progress, and tell you the outcome and any action we have taken. We aim to resolve most complaints within 30 days. You can still complain to the Information Commissioner’s Office at any time, with or without complaining to us first.
We respond to rights requests within one month, extendable by a further two months for complex requests, in line with Article 12(3) UK GDPR. We may need to verify your identity before we can act.
How to exercise your rights
Email dpo@datalaw.org or use our online subject access request form. We do not charge a fee for routine requests.
Right to complain to the regulator
You can complain to the Information Commissioner’s Office (https://ico.org.uk, helpline 0303 123 1113). We would appreciate the opportunity to address your concerns first.
13. Data breaches
Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, in line with Article 33 UK GDPR. Where the breach is likely to result in a high risk, we will also notify you directly without undue delay.
14. Updates to this notice
We will update this notice as our services, providers, or the law change. The “Last updated” date at the top of this notice indicates the current version. Where the changes are material, we will tell you (for example, by email or by a prominent notice on the website). The previous version is archived; you can request a copy by emailing dpo@datalaw.org.
15. How to contact us
Datalaw Ltd is the data controller for the personal information described in this notice.
Data Protection Officer – Henry Dean Email: dpo@datalaw.org Phone: 0151 236 2024
Postal address Datalaw Ltd 3A Bridgewater Street Liverpool Merseyside L1 0AR United Kingdom
Company information – Datalaw Ltd, registered in England and Wales. VAT number 712456061.
16. How to make a subject access or other rights request
To request a copy of your personal information, or to exercise any of the other rights in Section 12:
- email dpo@datalaw.org with the subject line “Rights Request”, telling us which right you wish to exercise and including enough information for us to identify you;
- or write to the postal address in Section 15;
- or use the rights-request form on our website.
We respond within one month. If your request is complex, we may extend by a further two months and will tell you so within the first month. Where the request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, in line with Article 12(5) UK GDPR. In line with the DUAA 2025, we will carry out a reasonable and proportionate search for your personal information, and the response period pauses while we verify your identity or await any clarification we have asked for.