Privacy Policy

Introduction

Lantra (“we”, “our”, “us”) is the Sector Skills Council for land-based and environmental industries in the UK. We are a data controller for the personal data we collect and process in relation to our qualifications, training, assessments, awards, membership services, events and websites. We comply with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • UK Data (Use & Access) Act 2025 (DUAA).

Lantra, Stoneleigh Park, Warwickshire CV8 2LG

Email: Data Protection Officer at [email protected]

Personal Data

  • Learners: name, address, contact details, date of birth, qualification records, unique learner numbers, reasonable adjustments and in some cases driving license numbers.
  • Trainers / Assessors / Providers: contact details, qualifications, DBS results, bank details (for payments).
  • Employers / Organisations: business contacts, correspondence, purchase history.
  • Website Visitors: IP address, device ID, cookies, analytics data.
  • Staff / Applicants: HR records, payroll details, references (covered by HR policies).
  • Event Participants: photographs taken at events for reporting and promotional purposes, processed in line with consent, safeguarding, and data protection requirements (with the option to opt out at the event).

Where we process special category data (e.g., health) or criminal offence data (e.g., DBS results), we do so under an Appropriate Policy Document (APD) as required by the Data Protection Act 2018.

We rely primarily on Legitimate Interests to operate our services effectively and securely. Where the DUAA identifies Recognised Legitimate Interests (RLI) (for example fraud prevention, security and safeguarding), we rely on these and document safeguards.

We also rely on:

  • Contract where processing is strictly necessary to deliver a service you request
  • Legal Obligation where required by law or regulation
  • Consent for non-essential cookies and certain marketing activities

We perform a Legitimate Interests Assessment (LIA) for each activity relying on legitimate interests and maintain an RLI Register.

 

Purpose Main Data Lawful Basis (Art. 6) DUAA RLI (if used) Notes
Learner registration, training delivery and certification Identifiers; qualification data Legitimate Interests; Contract Service delivery LIA on file
Trainers, Providers and Assessors Contact details; credentials; DBS status Legitimate Interests; Legal Obligation Safeguarding APD in place
Fraud prevention and IT security Identifiers; technical logs Legitimate interests Crime prevention Proportionate logging
Quality Analytics (non-advertising) Online identifiers Legitimate interests Quality improvement Non profiling
Marketing to existing contacts Contact details Legitimate Interests (PECR soft opt-in) Service communications Opt-out available
Marketing to new contacts Contact details Consent Recorded and withdrawable
Payments and statutory finance Financial data Legal Obligation HMRC
Reasonable adjustments Health data Art. 9 condition APD applies

  • Lantra applies the data minimisation principle under UK GDPR Article 5(1)(c) and the proportionate access and use principles reinforced by the UK Data (Use & Access) Act 2025.

    This means that we:

    • Collect personal data only where it is relevant, adequate and necessary
    • Do not collect data “just in case” or for undefined future use
    • Use the least intrusive data available
    • Clearly identify optional information
    • Review forms, systems and processes to remove unnecessary data

    Access controls and oversight

    Access to personal data is:

    • Role-based
    • Limited to authorised personnel
    • Subject to oversight and accountability

    Internal access is governed to ensure it is lawful, necessary, proportionate and auditable.

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request restriction of processing
  • Object to processing based on legitimate interests
  • Withdraw consent where relied upon

The DUAA clarifies that we may pause statutory response times (“stop-the-clock”) while verifying identity or clarifying scope, and that searches will be reasonable and proportionate.

We apply enhanced protections for children’s data, including:

  • Collecting only what is strictly necessary
  • Default privacy-protective settings
  • Parental oversight where required

We share personal data with awarding bodies, training providers, assessors, IT providers and regulators where necessary.

All processors are subject to Article 28 UK GDPR data processing agreements and due diligence.

Where data is transferred outside the UK, we:

  • Conduct a Transfer Risk Assessment (TRA)
  • Use the UK IDTA or UK Addendum
  • Apply supplementary safeguards where required

We apply appropriate technical and organisational measures, including:

  • Encryption
  • Access controls
  • Logging and monitoring
  • Staff training
  • Incident response procedures

We retain personal data only for as long as necessary.

Record Type Typical Retention Rationale Disposal
Learner records Review every 5-7 years Certification integrity / Regulatory / Audit Secure deletion
Assessment evidence 3-7 years Awarding rules Secure deletion
Trainer/Provider records 7 years Contractual Secure deletion
Financial records 7 years HMRC Secure deletion
Security logs 12-24 months Security Secure deletion
Marketing records Until opt-out + 24 months PECR Suppression
Data Complaints 6 years Defence Secure deletion
Products or Service Complaints 6-12 months Defence Secure deletion
Special category data Duration + 12 months APD Secure deletion

If you have a concern about how we handle your personal data, you may contact our Data Protection Officer in the first instance:

Email: [email protected]

We aim to acknowledge data protection complaints promptly and respond without undue delay.

If you are not satisfied with our response, you have the right to raise a complaint with the Information Commissioner’s Office (ICO):
www.ico.org.uk

Further Information

Marketing and cookies are managed in line with UK GDPR and PECR.

Our website uses a consent mechanism with Accept / Reject / Manage options. Further details are provided in our Cookies Policy.

We maintain:

  • Records of Processing Activities (RoPA)
  • Legitimate Interests Assessments (LIA) and Recognised Legitimate Interests (RLI)
  • Data Protection Impact Assessments (DPIA) and Transfer Risk Assessments (TRA)

These are reviewed regularly and made available to regulators on request.