Legal & Compliance

Privacy Policy

UK GDPR Compliant — how Vanguard Assessment & Consultancy Services collects, uses, and protects personal data.

Effective Date: July 2026 Last Updated: July 2026

Vanguard Assessment & Consultancy Services (“VACS”, “we”, “our”, or “us”) is committed to protecting the privacy, security, and integrity of personal data processed through our website and assessment consultancy operations. This Privacy Policy outlines how we collect, use, store, and protect personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

01

Important Information and Who We Are

VACS acts as both a Data Controller (in respect of our direct B2B client contact details, website analytics, and business communications) and a Data Processor (in respect of learner portfolio evidence, assessment tracking data, and e-portfolio records processed on behalf of Independent Training Providers and Awarding Organisations).

If you have any questions about this Privacy Policy or our data protection practices, please contact our Quality Directorate:

Legal Entity

Vanguard Assessment & Consultancy Services (VACS)

Primary Compliance Officer

Quality & Data Protection Director

02

The Personal Data We Collect

We may collect, use, store, and transfer different kinds of personal data depending on your interaction with us:

A. Direct B2B Contact & Client Data (Data Controller)

  • Identity Data: First name, last name, job title, organizational affiliation.
  • Contact Data: Work email address, telephone numbers, business postal address.
  • Commercial Data: Contract details, milestone billing records, invoice histories, and communications regarding qualification assessment cohorts.
  • Technical & Usage Data: IP address, browser type, site navigation patterns, and cookie preferences collected during website interactions.

B. Learner & Candidate Portfolio Data (Data Processor)

When providing independent assessment, Lead Internal Quality Assurance (IQA), or audit defense services to Independent Training Providers (ITPs), we process learner data contained within portfolios or e-portfolio systems (e.g., OneFile, Aptem, Smart Assessor, Quals Direct, or cloud drives). This may include:

  • Learner names, unique learner numbers (ULNs), and registration details.
  • Work-based evidence, assignment submissions, professional discussion audio recordings, observation reports, and employer witness testimonies.
  • Assessment marking feedback, unit sign-offs, and Lead IQA sampling logs.
03

How We Collect Personal Data

We collect personal data through:

Direct Interactions

Filling in web forms on our site, requesting quotes, or communicating via email.

Client System Provisioning

Access granted by ITP clients to their secure e-portfolio platforms or shared cloud folders.

Automated Technologies

Cookie tracking and website analytics tools (Google Analytics).

04

Legal Basis for Processing

We process personal data under the following UK GDPR legal grounds:

1

Contractual Necessity (Art. 6(1)(b))

To fulfill our B2B service contracts, deliver assessment and Lead IQA reviews, and process milestone invoices.

2

Legitimate Interests (Art. 6(1)(f))

To manage client relationships, defend against compliance disputes, and ensure network/website security.

3

Legal Compliance (Art. 6(1)(c))

To comply with statutory quality framework mandates, Awarding Organisation audit standards, and tax accounting regulations.

05

Third-Party Access & Platform Credentials

VACS operates on a strict shared-login access model for candidate assessment. VACS does not provision independent e-portfolio software; instead, assessors and IQAs access client systems strictly through secure credentials provisioned directly by our ITP partners.

We do not sell, rent, or commercialize personal data. Data may be shared only with:

  • Regulated Awarding Organisations (AOs) and External Quality Assurance (EQA) auditors during formal audit proceedings.
  • Professional IT, cloud infrastructure, and security sub-processors under strict confidentiality agreements.
  • Statutory or legal enforcement bodies where mandated by UK law.
06

Data Security & International Transfers

We implement robust administrative, technical, and physical security measures to safeguard personal data against loss, unauthorized access, or disclosure.

  • All data transmissions are encrypted using standard SSL/TLS protocols.
  • Access to candidate data is strictly restricted to authorized Lead IQAs, Assessors, and Subject Matter Experts.
  • Where operational data is accessed across divisions, all processing strictly complies with UK International Data Transfer Agreements (IDTAs) and standard contractual clauses (SCCs) to ensure equivalent UK GDPR protection levels.
07

Data Retention

Client Business Records

Retained for 6 years following contract completion in accordance with UK statutory accounting rules.

Assessment & Sampling Records

Retained in accordance with specific Awarding Organisation requirements or returned/purged from local administrative caches upon final EQA sign-off.

08

Your Legal Rights

Under UK GDPR, individuals have rights regarding their personal data, including the right to request:

Access Rectification Erasure Restriction of Processing Data Portability

Note: Where VACS acts as a Data Processor for learner portfolios, learners should direct their primary data requests to their respective Training Provider (the Data Controller).

To exercise any data protection rights, please contact enquiries@vanguardacservices.com. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).

Questions About This Policy?

Reach out to our Quality Directorate for anything related to how your data is handled.

Email enquiries@vanguardacservices.com