Data Protection Policy
Read the latest version of the data protection policy adopted by the London Institute of Business and Technology.
1. Purpose and scope
This policy sets out how LIBT collects, uses, stores, and disposes of personal data belonging to students, staff, and other individuals it deals with. It applies to every LIBT student, member of staff, consultant, and visitor whose personal data LIBT processes, and to every person or system that processes personal data on LIBT's behalf.
LIBT's legal obligation is under the Isle of Man's Data Protection Act 2018 and the Data Protection (Application of UK GDPR) Order 2020. In addition, LIBT applies EU GDPR as a further good-practice standard, even where it is not the legal minimum. This is consistent with the Quality Framework Statement's approach of voluntarily benchmarking against a stronger external standard. Where EU GDPR sets a higher standard than Isle of Man law on a specific point, this policy applies the higher EU standard. Examples include the scope of data subject rights, breach notification timescales, and the lawful bases for processing.
2. Principles
Personal data processed by LIBT is processed lawfully, fairly, and transparently. It is collected for a specified, legitimate purpose, and not used in a way that is incompatible with that purpose. It is adequate, relevant, and limited to what's necessary. It is accurate and kept up to date. It is kept no longer than necessary. It is processed securely. It is processed consistently with the data subject rights in section 5.
3. Roles and responsibilities
The Data Controller for LIBT is the Academic Registry, which is responsible for day-to-day compliance with this policy, for responding to data subject requests, and for reporting a personal data breach. This is a named role, not a named individual, so a change of postholder doesn't require a change to this policy. The current postholder is published in the Governance Register.
Every member of staff who handles personal data as part of their role must keep it secure. They must not disclose it to anyone without authorisation, whether inside or outside LIBT. They must inform the Academic Registry promptly of any error, loss, or unauthorised disclosure they become aware of. A student is responsible for keeping the personal data they provide to LIBT accurate and up to date, and for telling LIBT promptly of a change, for example a change of address.
4. Lawful basis for processing
LIBT processes personal data on one of the following bases, as applicable. It may be based on performance of the contract with a student or employee, or on compliance with a legal obligation, for example reporting to an Awarding Body or regulator. It may be based on LIBT's legitimate interests, balanced against the individual's rights. It may also be based on the individual's consent, where none of the other bases apply. Special category data (for example, health, disability, or religious belief, where relevant to a reasonable adjustment or special consideration request) is processed only with explicit consent or another basis permitted under EU GDPR and Isle of Man law. It is processed only for the specific purpose it was provided for.
5. Data subject rights
Under the higher EU GDPR standard that LIBT applies, an individual has a number of rights. They can access the personal data LIBT holds about them. They can have inaccurate data corrected, and have data erased where there is no continuing lawful reason to keep it. They can restrict processing while a dispute about accuracy or lawfulness is resolved. They can receive their own data in a portable format, where technically feasible, and object to processing based on legitimate interests. Finally, they have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on them, without the right to request human review.
A request under any of these rights is made in writing to the Academic Registry. There is no fee for a standard request. LIBT responds within 30 calendar days, or explains the reason for any delay in writing. A fee, or a refusal to act, is only ever considered where a request is manifestly unfounded or excessive, for example a repeat request within a very short period with no new basis. See section 5.1.
5.1 Manifestly unfounded or excessive requests
Any exception to the "no fee" rule in section 5 must be judged narrowly, case by case, by the Academic Registry, and recorded with reasons. Manifestly excessive normally means a materially identical request repeated shortly after a previous one was already fulfilled, not simply that a request takes time to answer. LIBT does not apply a standard or default fee to subject access requests.
6. International transfers
Where LIBT transfers personal data outside the Isle of Man or the European Economic Area, it does so only where the destination has an adequacy decision recognised under EU GDPR, or an equivalent recognised safeguard is in place, such as Standard Contractual Clauses with the receiving party. Transfers of this kind include transfers to an Awarding Body, a cloud service provider, or a partner institution. LIBT does not transfer personal data internationally on an ad hoc basis without one of these safeguards.
7. Security
Personal data is kept secure, appropriate to its sensitivity. Physical records are kept in lockable storage and not left on unattended desks. Electronic devices used off-site are password-protected and encrypted where they hold personal data. Access to LIBT's systems is limited to staff who need it for their role. Personal data is disclosed to a third party only with the individual's consent, or where LIBT is legally required to disclose it to a regulator or statutory body.
8. Retention
Personal data is retained in line with Awarding Body requirements and for a maximum of 6 years, whichever is shorter, except where a longer period is required by law. After that period, LIBT retains only what's needed to verify a former student's identity and confirm their award and transcript. All other personal data is securely destroyed. Staff personnel records are retained for 6 years from the end of employment, consistent with the Staff Conduct, Grievance, and Whistleblowing Policy and the Staff Development Policy.
9. Breach reporting
A suspected personal data breach is reported to the Academic Registry immediately. Where required by law, the Academic Registry reports a qualifying breach to the relevant regulator without undue delay. This is normally within 72 hours of becoming aware of it, which is the timescale EU GDPR requires. The Academic Registry also notifies affected individuals directly where the breach is likely to result in a high risk to their rights.
10. Review
This policy is reviewed annually by the Board of Directors. Any change must be checked against the Cross-Reference Map, in particular against the Student Contract and Terms and Conditions, the Recruitment and Admissions Policy, the Staff Development Policy, and the IT Policy.
Company information: London Institute of Business & Technology Limited (LIBT) Hillary House, Prospect Hill, Douglas, IM1 1EQ, Isle of Man, British Isles.
