Policies

GDPR Data protection policy

Last updated 25/06/2026

At a Glance Summary

  • Malvern International, including Language in Action, commits to adhering to Data Protection legislation and processing personal data in line with the data protection principles.
  • The Data Protection Officer is responsible for monitoring compliance and can be contacted at gdpr@malvernplc.com.
  • All staff, contractors and suppliers must handle personal data appropriately and protect their credentials.
  • Malvern International operates on a least-privilege basis and staff should only access data relevant to their role.
  • Data subjects have rights regarding their personal data, including access requests managed by the Data Protection Officer.

Purpose

Malvern International is committed to conducting its business in accordance with all applicable Data Protection laws and regulations and in line with the highest standards of ethical conduct.

This policy sets out the expected behaviours and standards required of employees and third parties in relation to the collection, use, retention, transfer, disclosure and destruction of personal data.

Scope of the Policy

This policy applies to all Malvern International entities where a data subject’s personal data is processed and covers both electronic and structured manual records.

Policy Enforcement

The Leadership Team must ensure that all employees and third parties who process personal data comply with this policy. Appropriate assurances will be sought before granting third parties access to personal data.

Data Protection Principles

Lawfulness, Fairness and Transparency

Personal data must be processed lawfully, fairly and transparently, with clear records of processing activities maintained by the Data Protection Officer.

Purpose Limitation

Personal data shall only be collected for specified, explicit and legitimate purposes and must not be processed incompatibly with those purposes.

Data Minimisation

Only data necessary for the stated purpose shall be collected and retained.

Accuracy

Personal data must be kept accurate and up to date.

Storage Limitation

Data shall only be retained for as long as necessary and in accordance with retention schedules.

Integrity and Confidentiality

  • Do not share passwords or credentials.
  • Do not upload or forward company data to unauthorised third parties.
  • Do not disable security controls or anti-virus systems.

Accountability

Malvern International and its staff are responsible for demonstrating compliance with data protection legislation.

Company Personnel Responsibilities

  • Only access personal data required for authorised duties.
  • Keep personal data secure and confidential.
  • Use strong passwords and lock devices when unattended.
  • Do not store company data on personal devices.
  • Dispose of personal data securely when no longer required.

Data Collection

Personal data should normally be collected directly from the data subject unless a lawful exception applies. Data subjects must receive appropriate privacy information in line with legal requirements.

Digital Marketing

Promotional communications must comply with data protection law. Individuals must always have the right to object to direct marketing activities.

Data Retention

Personal data will only be retained for as long as necessary to fulfil legal, contractual and business requirements.

Security and Confidentiality

  • Prevent unauthorised access to systems.
  • Restrict access to authorised personnel only.
  • Maintain access logs.
  • Protect data during electronic transmission.
  • Provide mandatory staff training.

Data Subject Rights and Requests

Data subjects may request:

  • Access to their information.
  • Rectification of inaccurate data.
  • Erasure of data where appropriate.
  • Restriction of processing.
  • Data portability.
  • Objection to processing or automated decision-making.

Requests must be referred immediately to the Data Protection Officer.

Law Enforcement Requests and Disclosures

Personal data may be disclosed without consent where required for crime prevention, legal obligations, taxation matters or court orders.

Data Protection Training

All staff with access to personal data must complete mandatory data protection training as part of induction and ongoing compliance requirements.

Transfers Between Sites and Third Parties

Data transfers must only occur through authorised channels and be supported by appropriate agreements and safeguards.

Complaints Handling

Complaints regarding personal data processing should be directed to gdpr@malvernplc.com.

Breach Reporting

Any suspected personal data breach must be reported immediately to gdpr@malvernplc.com so that appropriate investigation and response measures can be implemented.

Policy Approval

Date: March 2025Version: 1
Author: Kelly McGrath, Head of HRReview date: March 2027
Approved by Chief Executive Officer
Richard Mace: