Privacy Policy
Introduction
Lantra (“we”, “our”, “us”) is the Sector Skills Council for land-based and environmental industries in the UK. We are a data controller for the personal data we collect and process in relation to our qualifications, training, assessments, awards, membership services, events and websites. We comply with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- UK Data (Use & Access) Act 2025 (DUAA).
Lantra, Stoneleigh Park, Warwickshire CV8 2LG
Email: Data Protection Officer at [email protected]
Personal Data
- Learners: name, address, contact details, date of birth, qualification records, unique learner numbers, reasonable adjustments and in some cases driving license numbers.
- Trainers / Assessors / Providers: contact details, qualifications, DBS results, bank details (for payments).
- Employers / Organisations: business contacts, correspondence, purchase history.
- Website Visitors: IP address, device ID, cookies, analytics data.
- Staff / Applicants: HR records, payroll details, references (covered by HR policies).
- Event Participants: photographs taken at events for reporting and promotional purposes, processed in line with consent, safeguarding, and data protection requirements (with the option to opt out at the event).
Where we process special category data (e.g., health) or criminal offence data (e.g., DBS results), we do so under an Appropriate Policy Document (APD) as required by the Data Protection Act 2018.
We rely primarily on Legitimate Interests to operate our services effectively and securely. Where the DUAA identifies Recognised Legitimate Interests (RLI) (for example fraud prevention, security and safeguarding), we rely on these and document safeguards.
We also rely on:
- Contract where processing is strictly necessary to deliver a service you request
- Legal Obligation where required by law or regulation
- Consent for non-essential cookies and certain marketing activities
We perform a Legitimate Interests Assessment (LIA) for each activity relying on legitimate interests and maintain an RLI Register.
| Purpose | Main Data | Lawful Basis (Art. 6) | DUAA RLI (if used) | Notes |
|---|---|---|---|---|
| Learner registration, training delivery and certification | Identifiers; qualification data | Legitimate Interests; Contract | Service delivery | LIA on file |
| Trainers, Providers and Assessors | Contact details; credentials; DBS status | Legitimate Interests; Legal Obligation | Safeguarding | APD in place |
| Fraud prevention and IT security | Identifiers; technical logs | Legitimate interests | Crime prevention | Proportionate logging |
| Quality Analytics (non-advertising) | Online identifiers | Legitimate interests | Quality improvement | Non profiling |
| Marketing to existing contacts | Contact details | Legitimate Interests (PECR soft opt-in) | Service communications | Opt-out available |
| Marketing to new contacts | Contact details | Consent | — | Recorded and withdrawable |
| Payments and statutory finance | Financial data | Legal Obligation | — | HMRC |
| Reasonable adjustments | Health data | Art. 9 condition | — | APD applies |
- Lantra applies the data minimisation principle under UK GDPR Article 5(1)(c) and the proportionate access and use principles reinforced by the UK Data (Use & Access) Act 2025.
This means that we:
- Collect personal data only where it is relevant, adequate and necessary
- Do not collect data “just in case” or for undefined future use
- Use the least intrusive data available
- Clearly identify optional information
- Review forms, systems and processes to remove unnecessary data
Access controls and oversight
Access to personal data is:
- Role-based
- Limited to authorised personnel
- Subject to oversight and accountability
Internal access is governed to ensure it is lawful, necessary, proportionate and auditable.
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request restriction of processing
- Object to processing based on legitimate interests
- Withdraw consent where relied upon
The DUAA clarifies that we may pause statutory response times (“stop-the-clock”) while verifying identity or clarifying scope, and that searches will be reasonable and proportionate.
We apply enhanced protections for children’s data, including:
- Collecting only what is strictly necessary
- Default privacy-protective settings
- Parental oversight where required
We share personal data with awarding bodies, training providers, assessors, IT providers and regulators where necessary.
All processors are subject to Article 28 UK GDPR data processing agreements and due diligence.
Where data is transferred outside the UK, we:
- Conduct a Transfer Risk Assessment (TRA)
- Use the UK IDTA or UK Addendum
- Apply supplementary safeguards where required
We apply appropriate technical and organisational measures, including:
- Encryption
- Access controls
- Logging and monitoring
- Staff training
- Incident response procedures
We retain personal data only for as long as necessary.
| Record Type | Typical Retention | Rationale | Disposal |
|---|---|---|---|
| Learner records | Review every 5-7 years | Certification integrity / Regulatory / Audit | Secure deletion |
| Assessment evidence | 3-7 years | Awarding rules | Secure deletion |
| Trainer/Provider records | 7 years | Contractual | Secure deletion |
| Financial records | 7 years | HMRC | Secure deletion |
| Security logs | 12-24 months | Security | Secure deletion |
| Marketing records | Until opt-out + 24 months | PECR | Suppression |
| Data Complaints | 6 years | Defence | Secure deletion |
| Products or Service Complaints | 6-12 months | Defence | Secure deletion |
| Special category data | Duration + 12 months | APD | Secure deletion |
If you have a concern about how we handle your personal data, you may contact our Data Protection Officer in the first instance:
Email: [email protected]
We aim to acknowledge data protection complaints promptly and respond without undue delay.
If you are not satisfied with our response, you have the right to raise a complaint with the Information Commissioner’s Office (ICO):
www.ico.org.uk
Further Information
We maintain:
- Records of Processing Activities (RoPA)
- Legitimate Interests Assessments (LIA) and Recognised Legitimate Interests (RLI)
- Data Protection Impact Assessments (DPIA) and Transfer Risk Assessments (TRA)
These are reviewed regularly and made available to regulators on request.