Policy

Data Protection and Privacy Policy

Approved by: ManagementEffective date: 10 September 2026
Next review: 10 September 2027Version: 1.0

Policy owner: Data Protection Officer / Designated Data Protection Lead

1. Policy Statement

Jokings International Business College ("the College" or "JIBC") is committed to protecting the privacy, dignity, and personal information of its students, applicants, parents, guardians, employees, volunteers, contractors, visitors, alumni, suppliers, and other members of the College community.

The College will collect, use, store, disclose, transfer, archive, and dispose of personal data fairly, lawfully, transparently, and securely. Personal data will be used only for legitimate educational, administrative, safeguarding, employment, legal, and operational purposes.

The College recognises that children and young people may require additional protection. Their personal data will be handled with particular care, and their best interests will be a primary consideration where appropriate.

2. Purpose

This policy establishes the principles, responsibilities, and procedures governing the College's handling of personal data.

Its purposes are to:

  • Protect the privacy rights of individuals.
  • Ensure personal data is processed lawfully, fairly, and transparently.
  • Explain why the College collects and uses personal data.
  • Promote accurate, secure, and responsible record-keeping.
  • Prevent unauthorised access, disclosure, alteration, loss, or destruction of data.
  • Establish procedures for responding to data requests and security incidents.
  • Ensure staff understand their responsibilities.
  • Support compliance with applicable data-protection and privacy requirements.

3. Legal and Regulatory Framework

The College will process personal data in accordance with applicable data-protection and privacy legislation, regulatory guidance, contractual obligations, and recognised good practice.

This may include, where applicable:

  • The Nigeria Data Protection Act and related regulatory guidance.
  • The General Data Protection Regulation ("GDPR"), where its territorial requirements apply.
  • Requirements relating to education, safeguarding, employment, financial reporting, and electronic communications.
  • Obligations imposed by awarding bodies, educational partners, regulators, and public authorities.

Where different legal requirements apply, the College will follow the requirement applicable to the relevant processing activity and individual.

4. Scope

This policy applies to:

  • Students and prospective students.
  • Parents, guardians, sponsors, and authorised representatives.
  • Employees and job applicants.
  • Governors, directors, and members of management.
  • Volunteers, interns, and temporary workers.
  • Contractors, consultants, service providers, and educational partners.
  • Visitors, alumni, suppliers, and other stakeholders.

It applies to personal data processed:

  • In paper records.
  • In electronic systems and databases.
  • Through email and other communications.
  • On the College website and student portals.
  • Through virtual learning environments and educational applications.
  • In photographs, audio recordings, and video recordings.
  • Through CCTV, access-control, and security systems.
  • On College-owned or authorised devices.
  • By third parties processing information on the College's behalf.

All persons who handle personal data for or on behalf of the College must comply with this policy.

5. Definitions

5.1 Personal Data

Personal data is any information relating to an identified or identifiable individual. It may include:

  • Names and contact details.
  • Dates of birth.
  • Student or employee identification numbers.
  • Photographs and video recordings.
  • Identification and immigration documents.
  • Educational and attendance records.
  • Assessment results and academic reports.
  • Financial and payment information.
  • Online identifiers, usernames, and device information.
  • Employment and recruitment records.
  • Disciplinary and complaints records.
  • Safeguarding and welfare information.
  • Health, disability, or support information.

5.2 Sensitive or Special-Category Data

Sensitive personal data requires additional protection. Depending on applicable law, it may include information about:

  • Health or disability.
  • Race or ethnic origin.
  • Religious or philosophical beliefs.
  • Political opinions.
  • Trade-union membership.
  • Genetic or biometric information.
  • Sex life or sexual orientation.
  • Criminal allegations, proceedings, or convictions.
  • Safeguarding concerns.

5.3 Processing

Processing includes any operation performed on personal data, including collecting, recording, organising, storing, viewing, changing, sharing, transferring, analysing, archiving, or destroying it.

5.4 Data Subject

A data subject is the individual to whom personal data relates.

5.5 Data Controller

The data controller determines why and how personal data is processed. JIBC will normally act as the data controller for personal data it collects for its own institutional purposes.

5.6 Data Processor

A data processor is a person or organisation that processes personal data on behalf of the College and according to its documented instructions.

5.7 Personal Data Breach

A personal data breach is a security incident resulting in the accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to personal data.

6. Data Protection Principles

The College is accountable for ensuring that personal data is:

6.1 Processed Lawfully, Fairly, and Transparently

Personal data will be processed on a valid legal basis and in a manner individuals can reasonably understand.

6.2 Collected for Specified and Legitimate Purposes

The College will identify why information is required and will not use it for an incompatible purpose without an appropriate legal basis and, where necessary, further notice.

6.3 Adequate, Relevant, and Limited

The College will collect only the personal data reasonably necessary for the intended purpose.

6.4 Accurate and Up to Date

Reasonable steps will be taken to ensure personal data is accurate. Incorrect or incomplete information will be corrected or updated when identified.

6.5 Retained Only as Long as Necessary

Personal data will not be kept for longer than required for its original purpose or an applicable legal, safeguarding, regulatory, academic, financial, or contractual reason.

6.6 Kept Secure

Appropriate technical and organisational measures will protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction.

6.7 Processed Accountably

The College will maintain appropriate policies, records, contracts, training, and controls to demonstrate compliance.

7. Personal Data Collected by the College

The College may collect and process:

  • Personal and contact details.
  • Emergency-contact information.
  • Parent, guardian, and sponsor information.
  • Previous education and qualifications.
  • Applications, references, and admissions information.
  • Attendance and participation records.
  • Academic progress, assessment, and examination results.
  • Learning-support and accessibility information.
  • Health and medical information relevant to safety or support.
  • Safeguarding and welfare records.
  • Behavioural, disciplinary, complaint, and appeal records.
  • Identification, nationality, immigration, and visa information.
  • Tuition, payment, scholarship, and sponsorship information.
  • Photographs, recordings, and student work.
  • Website, network, email, and learning-platform usage information.
  • CCTV and building-access records.
  • Recruitment, employment, payroll, and performance information.
  • Communications with students, families, employees, and external agencies.

The College will not request personal data that is excessive or unrelated to a legitimate purpose.

8. Sources of Personal Data

Personal data may be collected directly from the individual or from:

  • Parents, guardians, or authorised representatives.
  • Previous schools or educational institutions.
  • Sponsors and scholarship providers.
  • Awarding organisations and educational partners.
  • Examination and assessment bodies.
  • Government departments, regulators, and public authorities.
  • Safeguarding, healthcare, or emergency services.
  • References and recruitment agencies.
  • College websites, portals, learning platforms, and security systems.
  • Third-party service providers acting on the College's behalf.

Where required, individuals will be informed of the source and purpose of the information.

9. Purposes for Processing Personal Data

The College may process personal data to:

  • Manage enquiries, applications, admissions, and enrolment.
  • Deliver teaching, assessment, and academic support.
  • Record attendance, progress, achievement, and qualifications.
  • Provide pastoral, welfare, health, disability, and safeguarding support.
  • Communicate with students, parents, guardians, and sponsors.
  • Administer fees, refunds, scholarships, and financial records.
  • Verify identity, qualifications, and immigration status.
  • Manage complaints, appeals, disciplinary matters, and academic misconduct.
  • Recruit, manage, train, and pay employees.
  • Provide information technology, library, accommodation, and student services.
  • Maintain campus safety, security, and access control.
  • Monitor and improve educational quality and institutional performance.
  • Meet legal, regulatory, inspection, accreditation, and contractual obligations.
  • Prevent and investigate fraud, misconduct, security incidents, or unlawful activity.
  • Promote College activities where a valid basis exists.

10. Lawful Bases for Processing

The College will identify and document an appropriate lawful basis before processing personal data.

Depending on the circumstances, processing may be necessary:

  • To perform a contract or take steps before entering a contract.
  • To comply with a legal obligation.
  • To protect a person's vital interests.
  • To perform a task in the public interest or under official authority.
  • For the College's legitimate interests or those of another person, provided individual rights do not override those interests.
  • On the basis of valid consent.

Sensitive or special-category data will be processed only where an additional lawful condition applies.

Consent will not be used where another lawful basis is more appropriate or where the individual cannot freely refuse without disadvantage.

11. Consent and Withdrawal of Consent

Where processing is based on consent, the College will ensure that consent is:

  • Freely given.
  • Specific and informed.
  • Expressed through a clear affirmative action.
  • Written in plain, accessible language.
  • Properly recorded.
  • Separate from unrelated terms where appropriate.

Where the individual is a child or young person, the College will assess whether the student can provide valid consent or whether consent from a parent or guardian is required.

An individual may withdraw consent at any time by contacting the Data Protection Officer or designated lead. It must be as easy to withdraw consent as it was to give it.

Withdrawal will not affect processing lawfully undertaken before consent was withdrawn. It may also not prevent processing that is required or permitted under another lawful basis.

12. Student and Children's Data

The College will give particular attention to the privacy rights and interests of students who are children or young people.

The College will:

  • Use clear and age-appropriate privacy information.
  • Collect only information necessary for education, support, administration, or safety.
  • Avoid using children's information in ways they would not reasonably expect.
  • Apply strong access controls to safeguarding, health, and welfare records.
  • Consider the student's maturity, understanding, and best interests.
  • Obtain parental or guardian consent where legally required.
  • Recognise that privacy rights belong to the student, subject to age, capacity, safeguarding duties, and applicable law.

Information will not automatically be disclosed to a parent, guardian, or sponsor merely because they pay fees. The College will consider the student's age, capacity, consent, safety, and the applicable legal basis before making a disclosure.

13. Privacy Notices

The College will provide appropriate privacy notices explaining:

  • The identity and contact details of the College.
  • What personal data is collected.
  • Why and how the data is used.
  • The lawful basis for processing.
  • Who may receive the data.
  • Whether data may be transferred internationally.
  • How long the data will be retained.
  • The individual's rights.
  • How to raise a concern or complaint.
  • Whether providing the information is mandatory.
  • The possible consequences of not providing required information.
  • Whether automated decision-making or profiling is used.

Privacy notices may be provided through application forms, enrolment documents, employment materials, the College website, student portals, or other appropriate channels.

14. Data Accuracy

Students, parents, guardians, employees, and other individuals should notify the College promptly if their personal information changes.

The College will provide reasonable methods for individuals to update details such as:

  • Name.
  • Address.
  • Telephone number.
  • Email address.
  • Emergency contacts.
  • Medical or support information.
  • Sponsorship or payment details.

Staff must record information accurately, distinguish facts from opinions, and correct verified errors promptly.

15. Access to Personal Data

Access to personal data will be granted only to authorised individuals who require it for legitimate duties.

The College will:

  • Apply role-based access controls.
  • Review access permissions periodically.
  • Remove or amend access when roles change.
  • Require secure authentication.
  • Monitor access to sensitive systems where appropriate.
  • Prohibit the sharing of passwords or access credentials.
  • Restrict access to safeguarding, medical, financial, and disciplinary records.

Employees must not access personal data out of curiosity or for personal purposes.

16. Data Security

The College will implement proportionate technical and organisational safeguards, which may include:

  • Secure passwords and multi-factor authentication.
  • Encryption of devices, systems, and transfers where appropriate.
  • Anti-malware, firewalls, and secure network controls.
  • Regular software updates and security testing.
  • Secure backups and recovery procedures.
  • Locked cabinets and restricted storage areas.
  • Clear-desk and secure-printing practices.
  • Confidential waste disposal and document shredding.
  • Controls over portable devices and removable media.
  • Secure remote-working arrangements.
  • Restrictions on downloading or transferring sensitive information.
  • Staff training and confidentiality obligations.
  • Incident monitoring and response procedures.

Personal data must not be stored in unauthorised personal email accounts, devices, cloud services, messaging applications, or removable storage.

17. Paper Records

Paper records containing personal data must:

  • Be stored securely when not in use.
  • Be accessible only to authorised persons.
  • Not be left unattended in classrooms, offices, vehicles, or public areas.
  • Be transported only where necessary and with appropriate safeguards.
  • Be disposed of through confidential shredding or another secure method.

18. Email and Electronic Communications

Before sending personal data electronically, staff must:

  • Confirm the identity and address of the recipient.
  • Use official College accounts and approved systems.
  • Include only the information necessary.
  • Apply encryption or password protection where appropriate.
  • Avoid placing sensitive information in subject lines.
  • Use blind-copy functions appropriately when emailing groups.
  • Report messages sent to the wrong recipient immediately.

Personal data must not be communicated through informal or unauthorised channels.

19. Data Sharing

The College may share personal data with:

  • Parents, guardians, or authorised representatives, where appropriate.
  • Awarding bodies and educational partners.
  • Examination and accreditation organisations.
  • Government departments and regulators.
  • Safeguarding, healthcare, or emergency services.
  • Law-enforcement bodies and courts.
  • Sponsors and scholarship providers.
  • Banks, auditors, insurers, and professional advisers.
  • Information-technology, learning-platform, and other service providers.

Before sharing personal data, the College will consider:

  • Whether there is a lawful basis.
  • Whether the disclosure is necessary and proportionate.
  • Whether the recipient is authorised.
  • Whether the information is accurate.
  • Whether a contract or data-sharing agreement is required.
  • What security measures are necessary.

Consent is not required where disclosure is authorised or required by law, necessary to protect a person from serious harm, or supported by another valid lawful basis.

20. Safeguarding and Emergency Disclosures

The College may share personal data without consent where necessary to:

  • Protect a student or another person from abuse, neglect, exploitation, or serious harm.
  • Respond to a medical emergency.
  • Make a safeguarding referral.
  • Support a lawful investigation.
  • Comply with a court order or statutory duty.

Only relevant information will be shared, and the reason for the disclosure will be recorded where appropriate.

Data protection must not be used as a reason to delay necessary safeguarding action.

21. Service Providers and Data Processors

Third parties that process personal data on behalf of the College must:

  • Act only on the College's documented instructions.
  • Maintain appropriate confidentiality and security.
  • Limit access to authorised personnel.
  • Notify the College promptly of a suspected breach.
  • Assist the College in responding to individual rights requests.
  • Return or securely delete data at the end of the service, where required.
  • Permit appropriate compliance checks or provide suitable assurance.

The College will conduct proportionate checks before appointing a processor and will use written contracts containing appropriate data-protection terms.

22. International Data Transfers

Personal data will not be transferred outside the country in which it was collected unless:

  • The transfer is lawful.
  • The receiving country or organisation provides an adequate level of protection; or
  • Appropriate contractual, regulatory, or other safeguards are in place; or
  • A lawful exception applies.

Individuals will be informed of relevant international transfers through appropriate privacy notices.

23. Photographs, Video, and Student Work

The College may use photographs, recordings, or student work for educational, administrative, security, or promotional purposes where a valid lawful basis exists.

For promotional use, the College will normally:

  • Explain how and where the material will be used.
  • Obtain consent where required.
  • Avoid publishing unnecessary identifying information.
  • Respect a valid withdrawal of consent for future use.
  • Apply additional safeguards for children and sensitive circumstances.

Withdrawal of consent will not normally require the College to recall materials already lawfully printed, published, or distributed, but the College will stop future use where reasonably practicable.

24. CCTV and Monitoring

The College may operate CCTV, access-control systems, network monitoring, or other security measures for legitimate purposes such as:

  • Protecting students, staff, visitors, and property.
  • Preventing and investigating misconduct or crime.
  • Managing access to College premises.
  • Maintaining the security and proper operation of information systems.

Monitoring will be proportionate, appropriately communicated, securely managed, and retained only as long as necessary.

Covert monitoring will be used only in exceptional circumstances where lawful, necessary, and authorised.

25. Data Retention and Disposal

The College will maintain a records-retention schedule specifying how long different categories of personal data should be kept.

Retention periods will reflect:

  • The purpose for which the information was collected.
  • Academic and certification requirements.
  • Safeguarding considerations.
  • Legal limitation periods.
  • Financial, tax, audit, and regulatory requirements.
  • Contractual obligations.
  • The need to respond to complaints or legal claims.

At the end of the applicable retention period, records will be securely deleted, anonymised, or destroyed unless there is a lawful reason to retain them longer.

The College will suspend routine destruction where records are relevant to an active complaint, investigation, safeguarding matter, audit, or legal proceeding.

26. Individual Rights

Subject to applicable law and any valid limitations, individuals may have the right to:

  • Be informed about the collection and use of their data.
  • Request access to their personal data.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of personal data.
  • Request restriction of processing.
  • Receive eligible data in a portable format.
  • Object to certain processing.
  • Withdraw consent where processing relies on consent.
  • Object to direct marketing.
  • Challenge certain decisions based solely on automated processing.
  • Lodge a complaint with the appropriate data-protection authority.

These rights are not absolute. The College may refuse or limit a request where permitted or required by law and will explain the reason where appropriate.

27. Requests to Exercise Data Rights

A request concerning personal data should be submitted to the Data Protection Officer or designated lead.

The College may request sufficient information to:

  • Confirm the requester's identity.
  • Identify the records concerned.
  • Verify the requester's authority to act for another person.
  • Clarify the scope of the request.

The College will respond within the period required by applicable law. Requests will normally be handled without charge, although a lawful fee may be applied where a request is manifestly unfounded, excessive, or repetitive.

Information relating to another person may be withheld or redacted where necessary to protect that person's rights or comply with confidentiality obligations.

28. Automated Decision-Making and Profiling

The College will not make a decision producing a significant legal or similar effect solely through automated processing unless:

  • The processing is lawful.
  • Appropriate safeguards are provided.
  • The individual is informed.
  • A means of requesting human review is available where required.

The College will explain the general basis and likely consequences of qualifying automated decisions.

29. Personal Data Breach Management

All suspected or confirmed personal data breaches must be reported immediately to the Data Protection Officer or designated lead.

Examples include:

  • Sending information to the wrong recipient.
  • Losing a laptop, telephone, storage device, or paper file.
  • Unauthorised access to a student or staff record.
  • Disclosure of passwords or login credentials.
  • Malware, ransomware, or account compromise.
  • Accidental publication of confidential information.
  • Improper destruction or disposal of records.
  • Accessing data without a legitimate reason.

The College will:

  • Contain the incident and protect affected systems or records.
  • Assess the nature, extent, and likely consequences of the breach.
  • Preserve relevant evidence.
  • Record the incident and response.
  • Notify management and other appropriate persons.
  • Notify the relevant authority within the legally required period where necessary.
  • Inform affected individuals where the breach is likely to create a significant risk.
  • Take corrective action to prevent recurrence.

Staff must not conceal, delete evidence of, or attempt to investigate a breach without authorisation.

30. Roles and Responsibilities

30.1 Management

Management is responsible for:

  • Approving this policy.
  • Providing appropriate resources for data protection.
  • Promoting a culture of privacy and accountability.
  • Ensuring significant risks and breaches are addressed.

30.2 Data Protection Officer or Designated Lead

The Data Protection Officer or designated lead is responsible for:

  • Advising the College on data-protection obligations.
  • Monitoring compliance with this policy.
  • Maintaining relevant processing and breach records.
  • Coordinating responses to individual rights requests.
  • Advising on privacy risks and impact assessments.
  • Supporting staff training.
  • Liaising with regulators where necessary.
  • Reviewing contracts and data-sharing arrangements.

30.3 Department Heads and Managers

Managers must ensure that:

  • Personal data within their departments is handled appropriately.
  • Access is limited to authorised individuals.
  • Staff receive relevant guidance and training.
  • New activities involving personal data are reviewed before implementation.
  • Breaches and risks are reported promptly.

30.4 Staff, Volunteers, and Contractors

All individuals handling personal data must:

  • Read and comply with this policy.
  • Complete required training.
  • Use personal data only for authorised purposes.
  • Maintain confidentiality.
  • Follow access and security controls.
  • Keep information accurate.
  • Report errors, risks, or breaches immediately.
  • Seek advice when uncertain.

31. Data Protection Impact Assessments

The College will conduct a data-protection impact assessment before beginning processing that is likely to create a high risk to individuals.

This may include:

  • Introducing significant new technology.
  • Conducting large-scale monitoring.
  • Processing extensive sensitive or safeguarding information.
  • Using biometric identification.
  • Introducing qualifying automated decision-making.
  • Sharing large or sensitive datasets with new partners.

The assessment will identify the purpose, necessity, risks, safeguards, and approval requirements associated with the proposed activity.

32. Training and Awareness

The College will provide appropriate data-protection and information-security training to staff, volunteers, and relevant contractors.

Training will cover:

  • Recognising personal and sensitive data.
  • Secure handling of paper and electronic records.
  • Password, email, and device security.
  • Confidentiality and appropriate disclosure.
  • Data-subject rights.
  • Safeguarding-related information sharing.
  • Recognising and reporting data breaches.
  • Secure disposal of records.

Training will be provided during induction and refreshed periodically.

33. Breaches of This Policy

Failure to comply with this policy may result in:

  • Withdrawal of access to College systems or records.
  • Additional training or supervision.
  • Disciplinary action.
  • Termination of employment, enrolment, appointment, or contract.
  • Referral to a professional, regulatory, or law-enforcement authority.
  • Civil or criminal action where applicable.

Any action taken will be proportionate and handled under the relevant College procedure.

34. Complaints

An individual who is concerned about how the College has handled personal data should first contact the Data Protection Officer or designated lead.

If the matter is not resolved, the individual may use the College's Complaints Policy and may also have the right to complain to the relevant data-protection authority.

No person will be penalised for raising a genuine data-protection concern in good faith.

35. Policy Review

This policy will be reviewed regularly and whenever there is:

  • A material change in applicable law or regulatory guidance.
  • A significant data breach.
  • A change in College systems or processing activities.
  • A recommendation arising from an audit, investigation, or impact assessment.
  • Evidence that existing controls are ineffective.

Updated versions will be communicated through appropriate College channels.

36. Contact Information

Questions, concerns, rights requests, and data-breach reports should be directed to:

Officer: Data Protection Officer / Designated Data Protection Lead

Institution: Jokings International Business College

Address: No. 5 Kazuare Street, Area 2, Section 1, Garki, Abuja, Nigeria

Email: admin@jibcnigeria.co.uk

Telephone: +234 707 509 8790

Office hours: Monday to Friday, 10:00 a.m. – 4:00 p.m., excluding public holidays

Approved by: Kingsley Ibeji

Position: President

Signature: Kingsley

Date: 10 September 2026