Information governance

Data Protection and Confidentiality

ICEQC limits collection, access, use, retention and public disclosure of information according to purpose, sensitivity, authority and applicable legal obligations.

Digital information review in an education setting

Information ICEQC handles

Public information

Standards, institutional identity, authorized publications, certificate scope and status records.

Application information

Legal identity, scope, personnel roles, systems, providers, evidence indexes and assessment communications.

Assessment evidence

Documents, data, interviews, samples, demonstrations, specialist records, findings and corrective action.

Rights and accountability records

Complaints, concerns, appeals, conflict declarations, decisions, access events and security reports.

Handling principles

  • Collect information for a defined and authorized purpose.
  • Request only information proportionate to the applicable activity and evidence need.
  • Restrict access by role, assignment and sensitivity.
  • Use secure authenticated channels for confidential evidence.
  • Separate public register fields from controlled assessment records.
  • Retain and dispose of information under applicable record and legal controls.

Public disclosure and rights

Public certificate information is limited to authorized identity, scope, edition, dates, status and related notice fields. Assessment evidence and personal information are not published as part of the certificate record.

A request concerning access, correction, restriction or another applicable data right should identify the person, the relevant ICEQC interaction and the requested action. ICEQC may need to verify identity and may retain information where required for legal, certification-integrity or dispute purposes.