Transparency, accountability and independent oversight are at the heart of everything we do. This Trust Centre provides information about our privacy practices, governance standards, quality assurance processes and compliance commitments.
✓ UK GDPR Compliant
✓ ICO Registered
✓ Independent Accreditation Body
✓ Secure Data Handling
Core Compliant is committed to protecting personal information and processing data fairly, lawfully and transparently. We only collect information necessary to deliver our services, communicate effectively and meet legal obligations. Personal information is handled responsibly, protected through appropriate safeguards and never sold to third parties. We are committed to respecting individual privacy rights and maintaining trust through clear, transparent data handling practices.
Strong governance helps ensure consistency, accountability and professional oversight across all Core Compliant activities. Decision-making processes are supported by defined responsibilities, documented procedures and quality controls. Governance frameworks help maintain fairness, transparency and integrity throughout accreditation and assessment activities while supporting continuous improvement and accountability.
We use appropriate technical and organisational measures to protect information against unauthorised access, loss, misuse or disclosure. Security controls include access management, secure hosting, monitoring processes and staff confidentiality requirements. Information security is regularly reviewed as part of our commitment to protecting customer and stakeholder information.
Quality assurance is central to maintaining confidence in accreditation decisions and professional standards. Our review processes support consistency, fairness and continual improvement. Quality controls help ensure assessments remain objective, reliable and aligned with established requirements while supporting the long-term integrity of accredited programmes and frameworks.
Core Compliant follows the principles of lawfulness, fairness, transparency, accuracy, accountability and data minimisation. We ensure that data is processed legally and fairly, with transparency, and that all data is kept accurate and up-to-date. Our policies and procedures reflect these principles, ensuring accountability and compliance with the UK GDPR.
The UK Data Protection Act 2018 plays a key role in supporting our privacy obligations. It ensures that personal data is processed in accordance with the law, with adequate protection against unauthorised or unlawful processing and accidental loss, destruction, or damage.
ICO registration signifies our commitment to data protection and privacy. It demonstrates our adherence to the UK’s data protection laws and assures stakeholders of our dedication to safeguarding their data.
Governance controls and review processes are essential to maintaining integrity and accountability. Our independent oversight ensures that all practices are conducted with transparency and are subject to regular review, fostering trust and reliability in our operations.
Accountability is central to our compliance management. We maintain comprehensive records and assign clear responsibilities to ensure that all processes are managed effectively and in accordance with legal and regulatory requirements.
Continuous improvement is at the heart of our quality assurance efforts. We regularly monitor and review our processes to ensure they meet high standards and support the integrity of our services and accreditations.
We collect information such as names, organisations, contact details, applications, correspondence, and service-related information. This data is essential for delivering our services and communicating effectively with clients and partners.
Information is used for service delivery, communications, support, security, administration, and compliance. We ensure that all data usage is aligned with our legal obligations and privacy commitments.
We process data based on contract, legitimate interests, legal obligations, and consent. Each processing activity is evaluated to ensure it complies with the relevant legal requirements and respects individual rights.
Our data retention policies ensure that information is kept only as long as necessary and deleted responsibly. We adhere to legal and regulatory requirements to manage data retention and disposal effectively.
Technical and organisational controls are in place to protect data against unauthorized access and breaches. Our security measures are regularly reviewed and updated to maintain high standards of data protection.
Where international data transfers occur, we apply robust safeguards and protections to ensure compliance with data protection laws and protect individual privacy rights.
You have the right to request access to your personal data and obtain information about how it is processed. We are committed to facilitating access rights in a transparent and timely manner.
If you believe that any data we hold about you is incorrect or incomplete, you have the right to request rectification. We will promptly address such requests to ensure data accuracy.
Also known as the 'right to be forgotten', this right allows you to request the deletion of your personal data under certain conditions. We respect this right and will act in accordance with legal obligations.
You can request the restriction of processing your data in certain circumstances. We will ensure that any restrictions are respected and inform you of any changes to processing activities.
You have the right to object to the processing of your data for specific purposes. We will review and respond to your objections promptly, ensuring compliance with data protection laws.
This right allows you to obtain and reuse your personal data across different services. We provide data in a structured, commonly used, and machine-readable format to facilitate portability.
Our hosting solutions are designed with security in mind, utilizing modern infrastructure and encryption to protect data from unauthorized access and breaches.
We enforce strict access controls, ensuring that only authorized personnel have access to sensitive information. Access rights are regularly reviewed and adjusted as necessary.
All staff members are subject to confidentiality agreements and undergo regular training to ensure compliance with data protection and privacy obligations.
Continuous monitoring and protective measures are in place to detect and respond to potential security incidents swiftly, minimizing impact and safeguarding information.
Our quality assurance processes are designed to ensure that all services meet high standards, providing confidence in the integrity and reliability of our operations.
We are committed to continuous improvement, regularly reviewing and updating our policies and procedures to enhance data protection and quality assurance practices.
If you have questions regarding privacy, governance, compliance or data protection matters, our team is available to help.
Contact UsProtecting information, maintaining quality and operating transparently are central to our commitment to professional accreditation.
Contact Us