ICAEW.com works better with JavaScript enabled.

Student privacy notice

Published: 15 May 2018 Updated: 04 Apr 2023 Update History

This notice (referred to as this “privacy notice”) explains what Personal Data the Institute of Chartered Accountants in England and Wales (ICAEW) holds about ICAEW Students, Pathways applicants, those undertaking qualifications offered by ICAEW, potential students and those individuals who have not yet come into ICAEW membership (referred to in this privacy notice as you or students), how we collect it, and how we use and share Personal Data. Please ensure that you read this privacy notice and any other privacy notices we may provide to you from time to time when we collect or process Personal Data about you.

Who can I contact if I have any questions?

ICAEW is the controller for the Personal Data collected from website visitors and individuals who download data via OneDrive unless this is stated otherwise. ICAEW is registered with the Information Commissioner’s Office (ICO) with registration number (Z5765897). In this privacy notice, references to ‘we’, ‘us’ or ‘our’ mean ICAEW. You can contact ICAEW in a number of ways as follows:

  • Email: data.protection@icaew.com
  • Post: The Data Protection Office, ICAEW, Metropolitan House, 321 Avebury Boulevard, Milton Keynes, MK9 2FZ UK
  • Telephone: +44 (0)1908 248 250

What is Personal Data?

Personal Data is any information which directly or indirectly identifies an individual, for example, your name, address, membership and/or student number, NI number, qualifications, date of birth, photos, videos or voice recordings.

Special categories of Personal Data are a set of Personal Data that we are required to look after even more carefully. Special categories of Personal Data include details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. In limited circumstances, we collect special categories of Personal Data about you through the application process, for example, we may collect details of your health data to ensure that we can make reasonable adjustments for you.

We collect Personal Data about you when you are a student, and we also collect information about your criminal convictions and offences which is another type of Personal Data that we need to look after very carefully.

Personal Data we collect about you

We collect Personal Data about you when you give us Personal Data in direct interactions with us during your time as an ICAEW student, for example by completing the registration process, attending courses, internships, events and webinars, taking part in exams and other assessments. We also collect Personal Data from other sources as set out below.

Personal Data collected directly from you
Personal Data collected directly from you

Identity Data

Your name, title, date of birth, facial photographs, images of identification documents, such as driving license.

Contact Data

Your address and contact details, including email address and telephone numbers.

Education Data

Details of your academic and professional qualifications including educational establishments, dates of study, subjects studied and results.

Career Data

Employment history, including start and end dates with previous employers. Details of membership of Professional Bodies.

Student Data

ICAEW Student training records, details of your tutor organisation, awards you receive, unique learner number (ULN), employer’s reference number (ERN).

Financial Data

Details of your bank account.

Criminal Offence Data

Information about your criminal record, if applicable, is collected when you provide a declaration.

Equal Opportunities Data

Equal opportunities monitoring information, including information about your ethnic origin, gender, sexual orientation, socio-economic background, health and religion or belief.

Health Data

Information about your health, medical conditions or disabilities. 

Remote Invigilation Data

Data collected during your completion of online examinations while logged into the ICAEW remote invigilation platform consisting of images, video and audio recorded via your device while you are in the process of completing an exam which is invigilated online. This recording may capture; images of your face, desk and workspace recordings of your voice, visible or audible physical health data, racial/ethnic origin/religious beliefs (by virtue of video recording), IP address, browser agents, browser and operating system identifiers, screenshots of your PC, your exam setting (home, office etc.), all recorded video streams (computer, webcam and mobile), name of the exam you are sitting and other assessment based data that may be collected, including information about browser version, appVersion, appName, product and appCodeName, video frame size, type and library used for encoding, framerate, jitter, packet loss and bandwidth.

Website Data

Information collected during your use of our websites. Please see our website privacy notice (Website and email privacy notice | ICAEW policies | ICAEW) for more details.

Personal Data provided by third parties
Personal Data provided by third parties

Reference Data

Information supplied by former employers, education providers and recruitment agencies. For example, information about your previous academic or employment history, including details of any conduct grievance or performance issues, appraisals, time and attendance.

Contact Data

Information you supplied to an organisation with the explicit consent to share with us, for example, if you have chosen to hear about ICAEW services via another scheme. 

What if you do not supply your Personal Data

Some of the Personal Data we process is mandatory meaning that if you do not provide it to us, we will be u nable to provide some or all student services to you.  For example, if you don't enter the mandatory Personal Data when registering as a student with us, you will not be able to register as a student with us, sit or pass exams and assessments or gain ICAEW qualifications. We will explain at the point of data collection, which information is mandatory information, and which is optional.

Purposes and legal basis for which we will use your Personal Data

Processing Personal Data from students allows us to administer and manage the process of registering you as a student, provide courses to you and administer exams. In order to comply with Personal Data protection laws, we need a lawful basis to process your Personal Data. We use the following lawful bases to obtain and use your Personal Data.

  1. Performance of a Contract – We need to process your Personal Data to take steps at your request, prior to entering into a contract with you and for the performance of our contract with you as an ICAEW student.
  2. Consent – Some Personal Data is processed because you have given your consent. Consent can be withdrawn at any time by either logging into your online student account via our website and amending your preferences or by contacting us at dataprotection@icaew.com.
  3. Legal or Regulatory Obligation – In some cases, we need to process Personal Data to comply with a legal or regulatory obligation which we are subject to.
  4. Legitimate Interest – Where processing the Personal Data is in our legitimate interests (or those of a third party) provided that your fundamental rights do not override such interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process Personal Data for our legitimate interests.
  5. Public Interest – Where processing the personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

The table below describes the ways in which we use your Personal Data and the legal bases we rely on to do so. Where appropriate we have also set out our legitimate interests in processing your Personal Data.

Purpose and/or activity

Type of Data

Legal basis for processing

To register you as a student, provide you with advice in relation to your registration as a student, to enable you to sign up for and use a student account on our platforms, to administer and manage your student journey.

Identity Data
Contact Data
Criminal Data
Education Data
Financial Data

Performance of a contract: to enable you to register as a student and to communicate with you once you become a student.

To comply with our equal opportunities monitoring obligations and to follow our equality and other policies.

Equal
Opportunities
Data

Legal obligation: to comply with our obligations in respect of the Equality Act  and for reasons of substantial public interest.

To support any special exam requirements you have.

Health Data
Identity Data
Contact Data

Legal obligation: to comply with accessibility requirements and to ensure equality of opportunity or treatment.

To consider an appeal that you make or that is made on your behalf if you consent to this.

Health Data
Identity Data
Contact Data
Exam Data

Performance of a Contract: to allow us to administer and facilitate your exams and consider any appeals made.


To take payment or provide you with a refund.

Financial Data
Identity Data

Performance of a Contract: to allow us to take, and if necessary, refund, payments made by you for the provision of services by ICAEW to you as a student.

To run competitions

Identity Data
Contact Data

Performance of a contract: to manage a competition to which you have entered.

Tracking and monitoring student journeys and activity.

Identity Data
Education Data

Legitimate Interest: in or legitimate interest to monitor and understand the intake and trends of ICAEW students and their journeys.

To provide you with CABA services

Identity Data
Contact Data
Member Data

Legitimate Interest: in our legitimate interest to provide you with caba services benefits.

To ensure the authenticity of any documents submitted as part of your registration or any appeal, complaint or other application, to run eligibility checks on your eligibility for qualification and/or membership.

Background
Data
Criminal
Data
Education
Data

Legitimate interest: to ensure authenticity of documents as part of any appeals, complaints, or other applications.

For reasons of substantial public interest (preventing or detecting unlawful acts): To ensure the authenticity of any documents submitted as part of your registration, to run eligibility checks on your eligibility for qualification and/or membership.

 

To investigate and respond to any queries, disputes, appeals, complaints or other similar or related matters.

Identity Data 
Contact Data All relevant student and member data held by ICAEW

Legitimate interest:  in our legitimate interests to investigate, deal with disputes and respond to enquiries, appeals, complaints or other similar related matters.

To provide you with updates and information with regards to your exams and to send you other information or updates relating to our services.

Identity Data
Contact Data

Performance of a Contract: for ICAEW to communicate with you to provide all relevant information to you for the purposes of successfully completing your exams and providing you with updates relating to the services we provide to you.

To provide you with information with regards to changes to regulations or changes to the way rules are applied and other updates relevant to you.

Identity Data
Contract Data

Legitimate interest: in our legitimate interest in providing you with relevant information to assist you in your studies and associated activities.

To capture and create ICAEW case studies, testimonials, profiles for careers touchpoints e.g. brochures, websites, adverts, social media, email, Student Insights (content on ICAEW website)

Identity Data
Education Data
Career Data

Consent: where you have provided your consent for your data to be used as part of an ICAEW case study.

To check students’ eligibility for membership by reviewing CPD records to process delayed applications.

Identity Data
Education Data

Performance of a contract: in order to assist with the administration of your membership, where applicable.

Exam and qualification administration and management, to assess your eligibility for qualifications you apply for; to enable you to book and sit ICAEW exams; to invigilate remote exams, (including verifying the identity of the person taking the exam, observing the completion of the exam, managing incidents and help to prevent fraud); to manage and administer qualifications, and to communicate with you about the results of ICAEW exams you sit.

Identity Data
Online Invigilation Data
Exam Data

Performance of a contract: in order to provide you with a fair and secure exam process.

Performance of a contract: in order to provide you with a fair and secure exam process.

Identity Data
Contact Data
Exam Data

Consent: where you have provided your consent for ICAEW to share and publish your results and awards that you receive including publishing results online and at prize giving ceremonies.

Performance of a contract: sharing your results with your employer where relevant, in order to assist with administration of your training agreement.

Administering awards ceremonies.

Identity Data
Contact Data
Exam Data

Legitimate Interest: in our legitimate interest to facilitate award ceremonies.

For non-UK residents becoming ICAEW students, to manage and administer international routes to becoming an ICAEW student; to assess ability of prospective referee to act as a sponsor for prospective international student; and to assess eligibility.

Identity Data
Contact Data
Referee related data
Education data
Criminal data

Performance of a contract: in order to provide you with the services you are entitled to under your contract with us.

Direct Marketing, communicating with you to promote our services.

Identity Data
Contact Data

Consent: where you have consented to receiving the communications.

Legitimate Interests: in our legitimate interests as a professional body and regulator of chartered accountants, we will use your Personal Data for marketing purposes where we have a relevant or appropriate relationship with you or where there is a reasonable expectation of us doing so. 

Serving you with targeted and retargeted advertisements on both ICAEW and third party platforms and measuring the success of those advertisements.

Contact Data
Website Data

Consent: where you have consented to the use of cookies/website data to provide you with targeted and retargeted advertisements on ICAEW and third party platforms.

To run reports analysis on student data.

Identity Data
Contact Data

Legitimate interest: in our legitimate interest to understand the intake and trends of ICAEW students.

Anonymisation of personal data for the onward activities of Management Information and Business Intelligence.

All Personal Data

Legitimate Interest of the ICAEW for business improvement and intelligence purposes.

Audit related activities to ensure ICAEW understands its business practices.

A sample of all Personal Data

Legitimate Interest of the ICAEW to gain a true and fair understanding of current practices, with a view to organisational improvement.  

Serving you with targeted and retargeted advertisements and monitoring the success of those advertisements.

Identity Data
Contact Data
Cookie Data

Consent: where you have consented to the use of cookies to provide you with marketing related activities.

Conducting research.

Identity Data
Contact Data
Career Data
Education Data
Diversity and Inclusion Data

Consent: where you have consented to take part in our research activities.

Legitimate Interests: in our legitimate interests to understand more about our Students, their views, and how better to serve our Students.

Special Category Data

Where the information we process is special category or sensitive data such as your health data, the additional bases for processing that we rely on are:

  1. Where you have provided ICAEW with your explicit consent to the processing
  2. Where processing is necessary for the establishment, exercise or defence of legal claims
  3. Where processing is necessary for reasons of substantial public interest,

How long will Personal Data be retained?

We keep Personal Data that we obtain about you during your time as an ICAEW student. Examination scripts, qualification records and associated process documentation will be kept indefinitely for record and Regulatory evidence.

Automated Decision Making

Some exams may be marked using automated means. The correct answers and pass mark are determined by ICAEW. The examination mark and whether you have passed or failed an exam marked using automatic means will be automatically determined by reference to the number of correct and incorrect exam answers and the applicable pass mark. If you want to request a review of an exam mark which was determined through automated marking, you need to go through our standard review process by contacting us at the below email address. The automated marking will be checked and your result will be confirmed again to you: Student Support

.

Sharing your Personal Data

ICAEW may share your Personal Data with third-party processors who provide services to the organisation, where we have a legal obligation, contract or other legitimate interest to do so. These services include:

  1. external assessment, training and examination providers (including test centres) invigilators and providers of online invigilating services.
  2. tutors and ICAEW partners in learning;
  3. payment providers;
  4. business system providers;
  5. publishers;
  6. companies who run competitions on our behalf;
  7. companies who facilitate our communication with you including marketing communications you are registered for and communicating your exam results;
  8. website content and hosting providers, including analytics; and
  9. if you have special exam requirements such as access arrangements, extra time or other assistance due to illness, disability, religion or other extenuating circumstances, we may share your Personal Data (where necessary, including health data) with third party suppliers engaged by us who need to know such information in order to cater for your special requirements.

We may share your Personal Data with organisations where we have a legal obligation, contract or other legitimate interest to do so, including:

  1. Building landlords and facilities management organisations (CCTV and access control systems);
  2. Your employer/principal - to meet our contractual obligations. For example, if you have a training agreement with your employer/principal we will share your personal data with your employer/principal to ensure that your training and progress meets the standard required by your employer/principal.
  3. Evidence issuing authority: We will share your personal data with the issuing authority of any evidence you provide to ensure authenticity i.e. when you have sent us your educational qualifications and we check them with your educational institution or against UK ENIC managed by Ecctis Ltd.
  4. Publishing your exam results: We may share and publish your results and awards that you receive including publishing results online and at prize giving ceremonies. We will only do this where you have provided your consent.
  5. District and student societies: We will share your Personal Data with district societies and student societies to allow such societies to communicate with you, if you fall within their remit;
  6. International accountancy institutions: If you are on the Pathways route or a similar arrangement, we may share your Personal Data with the home body in your country of residence;
  7. Chartered Accountants Benevolent Association (caba) in order for caba to be able to provide services to you;
  8. Criminal convictions: If you disclose a criminal conviction, this will be shared with ICAEW's internal professional conduct team and depending on the circumstances may also be shared with third parties such as regulators or other professional bodies;
  9. Potential employers through our jobs portal: If you use our jobs portal, we may share your Personal Data with potential employers;
  10. Board and Committee Members or Representatives when appropriate and
  11. Regulators: When requested to provide such information.

Your Personal Data may be transferred to other third-party organisations in certain scenarios:

  1. If we're discussing selling or transferring part or all of our business. Personal Data may be transferred to prospective purchasers under suitable terms as to confidentiality;
  2. If we are reorganised or sold, Personal Data may be transferred to a buyer who can continue to provide services to you;
  3. If we are required to by law, or under any regulatory code or practice we follow, or if we are asked by any public or regulatory authority, for example the Police, we may need to share your Personal Data;
  4. If we are investigating or defending any legal claims your Personal Data may be transferred as required in connection with defending such investigations and/or claims.

Transferring Data Overseas

Please be aware that if you are an overseas student, we will be processing data both in the UK and local to you if you are attending a venue. In some cases, we or our suppliers may need to process Personal Data outside the European Economic Area (EEA) and/or United Kingdom (UK). Where this is the case we will only share the minimal amount of Personal Data necessary for the purpose of processing and, where possible, we will share the Personal Data in an anonymised form.

Whenever we transfer your Personal Data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  1. we will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the UK;
  2. where we use certain processors, we may use specific contracts approved by the UK which give Personal Data the same protection it has within the UK. When we rely on this measure we will ensure that the third-party can comply with the provision of such contracts and we have confirmed that the country to which the Personal Data is transferred has adequate data protection laws in place to protect Personal Data.

Please contact us at data.protection@icaew.com if you would like further information about the specific mechanism used by us when transferring your Personal Data.

Your Personal Data may be transferred to other third-party organisations in certain scenarios:

  1. If we are discussing a merger or acquisition, Personal Data may be transferred to respective third parties under suitable terms as to confidentiality;
  2. If we are reorganised or sold, Personal Data may be transferred to a buyer who can continue to provide services to you;
  3. If we are required to by law, or under any regulatory code or practice we follow, or if we are asked by any public or regulatory authority, for example the Police, we may need to share your Personal Data; or
  4. If we are investigating or defending any legal claims your Personal Data may be transferred as required in connection with defending such investigations and/or claims.

Whenever we transfer your Personal Data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  1. we will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the UK;
  2. where we use certain processors, we may use specific contracts approved by the UK which give Personal Data the same protection it has within the UK. When we rely on this measure we will ensure that the third-party can comply with the provision of such contracts and we have confirmed that the country to which the Personal Data is transferred has adequate data protection laws in place to protect Personal Data.

Please contact us at data.protection@icaew.com if you would like further information about the specific mechanism used by us when transferring your Personal Data.

How we protect your Personal Data

We have appropriate security measures in place to prevent Personal Data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your Personal Data to those who have a genuine business need to know it. Those processing your Personal Data will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Your Rights

Under data protection law, you have rights including:

  1. Your right of access – You have the right to ask us for copies of your Personal Data.
  2. Your right to rectification – You have the right to ask us to rectify Personal Data you think is inaccurate. You also have the right to ask us to complete Personal Data you think is incomplete.
  3. Your right to erasure – You have the right to ask us to erase your Personal Data in certain circumstances.
  4. Your right to restriction of processing – You have the right to ask us to restrict the processing of your Personal Data in certain circumstances.
  5. Your right to object to processing – You have the right to object to the processing of your Personal Data in certain circumstances.
  6. Your right to data portability – You have the right to ask that we transfer the Personal Data you gave us to another organisation, or to you, in certain circumstances.
  7. Rights related to automated decision making, including profiling -You have the right not to be subjected to a decision based solely on automated processing (including profiling) which may significantly affect you. We do not make any employment decisions, solely using automated decision-making technologies. 

In most cases we will deal with your request as soon as possible and at the latest within one calendar month of the request. If we need to extend the time period for responding to your request, we will let you know within the one-month period. We do not charge a fee for any such requests, unless there are exceptional circumstances.

If you wish to exercise any of your rights, please contact our Data Protection Office via email using dataprotection@icaew.com.

Complaints

If you have any concerns about the Personal Data we use about you, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, by contacting them at www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please feel free to contact us in the first instance via email using data.protection@icaew.com.