← All policies

policy

IT and Information Security Policy 

Version 2.14 · Published 7 October 2026

Information Security Policy sets guidelines and procedures for how RCG secures, protects, and manages the information it needs to conduct business. This policy applies to all employees, contractors, and partners of RCG, as well as any third-party vendors or service providers that may have access to assessment materials or any data that falls under GDPR and the Data Protection Act of 2018. 


Railway Competence Group is fully committed to complying with the Data Protection Act 2018 and the General Data Protection Regulation (GDPR).  Document management principles are outlined in this policy to ensure consistency across all formats. 

 

Data Locations

ACE360 

Apprentice contact details and results are hosted on ACE360. 

 

Testinvite 

Online test questions and answers linked to individual apprentices are hosted on Testinvite. 

 

Documents 

Physical security measures are in place to protect data at RCG offices. RCG offices can only be accessed via lockable doors, and only authorised staff receive keys. Outside of office hours, both the offices and building are locked and secured with key code burglar alarms. 

 

Email servers 

Email stored on OFFICE 365. 

Email servers are compliant with all UK and EU data protection regulations. 

 

Hard-drive memory on PCs and Laptops 

Employees of the RCG will have access to additional storage options, such as hard-drive memory on PCs and laptops. This information is unsecured and as such should not contain any confidential or personal information. Employees are responsible for following these guidelines. 

 

Password policy

All RCG passwords are covered by the same password policy. Meaning, all passwords must be: 

  • Private 

  • Unique 

  • Never written down 

  • Be at least 8 characters in length 

  • Contain a combination of letters and numbers 

  • Replaced when compromised 

Passwords may need to be shared with line managers in certain circumstances, such as sickness or holidays. Passwords should never be shared with anyone else. 

 

Acceptable Personal Use

RCG provides all its employees with systems, data and equipment for the purposes of the company's activities only. 

There is a security filter on the company's internet connection, so inappropriate sites will be blocked. 


These facilities/equipment should not be used for personal financial gain, to solicit others for unrelated activities, or to engage in political campaigns or lobbying. Tools provided by the organisation can never be used to publish defamatory or obscene material, infringe on someone's intellectual property, or violate any law. 


RCG may monitor electronic correspondence (including email, voice and text messages) so as to ensure the integrity of its information technology, or to prevent or detect criminal activity, or to comply with employment laws and policies. 

 

Social Media

RCG uses several social media accounts and encourages employees to promote the company through social media. 


RCG employees should be aware that their personal social media accounts should always reflect the company's values, ethics, and codes of conduct, and should never be used to transfer personal information. 


All social media accounts mentioning RCG are subject to this policy. 


Software Downloads

Internet downloaded software is an essential part of any business, but it is also a risk. Software downloads must be approved by IT provider.  

 

Leaving desk

Whenever an employee is away from their desk for an extended period, all paperwork containing personal information should be locked away. All employees will have lockable cabinets. 


If an employee is not actively using a device it must be locked and must not be left unattended whilst unlocked. 


Data Breach

Any suspected or actual breaches of security or confidentiality will be reported to the appropriate authorities immediately. RCG will conduct an internal investigation and take appropriate actions to prevent further breaches and to protect the confidentiality of candidate details and assessment materials. 


If you suspect a data breach you must report this immediately to Managing Partner-Delivery or alternatively the compliance manager. 


Security and Confidentiality of Materials

RCG (End-Point Assessment Organisation) will ensure the security and confidentiality of all materials related to the assessment process, including but not limited to candidate information, assessment results, and any other sensitive or confidential data. 


The accuracy and reliability of assessments rely on the safeguarding and confidentiality of sensitive information. For RCG, confidential information pertains to data that is not commonly known outside the organisation or is legally protected. Such information includes, but is not limited to: 

  • Grading 

  • Intellectual property 

  • Answer sheets or question banks 

  • Business plans, financial information and forecasts 

  • Information obtained regarding RCG’s EPA processes and materials used. 


Confidentiality

All employees, contractors, and partners of RCG, as well as any third-party vendors or service providers, will be required to sign a non-disclosure agreement before being granted access to assessment materials. This agreement prohibits the sharing, copying, or distribution of any assessment materials to any unauthorized parties. 


In case of emergencies, health or safety concerns, or audits, disclosure of confidential information may be necessary and agreed with RCG. All confidential materials, property, and information remain the property of the RCG. 


Procedure

RCG mandates that all employees/representatives/contractors and service providers uphold the trust and confidentiality of confidential information, and: 

  • Comply with data protection laws and GDPR. 

  • Follow RCG's IT and Information Security Policy and Procedure to maintain the security of materials/data and property. 

  • Access, use, store, or disclose confidential information solely for the agreed purposes/duties within their agreed upon role/contract with RCG. 

  • Only remove confidential materials or property from the organization's offices when agreed upon with management, in line with their agreed upon role responsibilities. 

  • Securely return or destroy any confidential materials, property, or copies of confidential information in their possession upon request by RCG management team. 


All RCG employees/representatives/contractors and service providers are accountable for maintaining the confidentiality of such data.  


Data Retention


Procedure

Railway Competence Group applies the following principles when handling apprentices' personal data: 

  • We will only use personal data with the candidate's permission and in association with delivery of End Point Assessments. 

  • Unless required by law, Railway Competence Group will never share a candidates' personal information with any other organisation. 

  • We only collect the information we need for the delivery of End-point Assessments and subsequent certification. 

  • Candidates' personal information is only seen by those who require it to provide the service. 

  • Candidate personal data is retained only as long as necessary. 

  • If changes are made to personal information, Railway Competence Group will update our records.  

  • Immediately correct inaccuracies or misleading information. 

  • Information about candidates is protected from accidental or unauthorised disclosure. 

  • Railway Competence Group will make personal data that we have stored available to the individual upon request and comply with all relevant legislation. 

  • Third parties working for Railway Competence Group must comply with this policy. 

  • Staff members are responsible for managing, storing appropriately, and disposing of the information they produce and receive on a day-to-day basis. 

  • Electronic data is held securely and is only accessed by authorised personnel. The server and all computers are firewall protected. 

Railway Competence Group must review and dispose of the information gathered and generated throughout the course of its business. 


Disposal Schedules

A long retention period carries additional risks, costs, and potential non-compliance with the Data Protection Act 2018. 


According to the Data Protection Act 2018, Railway Competence Group must not hold personal data for longer than is necessary. 


Please see table below regarding data types, retention periods, storage methods, review dates, and when to destroy documents safely. 


Type of Record 

Retention Period 

Reason for Length of Period 

Learner registration 

3 years after the qualification is completed 

Processing any queries; requirement to maintain contact details in the case of any legacy malpractice. 

Learner achievements/certification record 

In perpetuity 

Replacement certificates; authenticating achievement. 

RCG staff records 

3 years after data subject ceases to be on staff 

May be required for professional reference. 

5 years for data relating to proven malpractice 

Potential litigation 

Data may be held in perpetuity in cases of proven serious malpractice 

Potential litigation 

Personnel files, including training records, notes of disciplinary and grievance hearings, and appraisal forms 

6 years from end of employment 

References and potential litigation 

Some data relating to proven serious malpractice may be held in perpetuity 

Selected material may form part of the Institute Archive 

Letters of reference 

6 years from end of employment, by the author of the reference letter 

References and potential litigation 

Application forms / interview notes 

At least 6 months from the date of the interviews 

Time limits on litigation 

Facts relating to redundancies where fewer than 20 redundancies 

6 years from the date of redundancy 

As above 

Facts relating to redundancies where more than 20 redundancies 

12 years from the date of redundancies 

Limitation Act 1980 

Income Tax and NI returns including correspondence with tax office 

At least 3 years after the end of the financial year the records relate to 

Income Tax Employment Regulations 1993 

Statutory Maternity pay records and calculations 

As above 

Statutory Maternity Pay (General) Regulations 1986 

Statutory sick pay records and calculations 

As above 

Statutory Sick Pay (General) Regulations 1982 

Wages and salary records 

6 years from end of employment 

Taxes Management Act 1970 

Accident books and records and reports  of accidents 

3 years after the date of the last entry 

Social Security  (Claims and Payments) Regulations 1979, RIDDOR 1985 

Health Records 

During period of employment 

Management of Health and Safety at Work Regulations 

Health records where reason of termination of employment is connected with health including stress related illnesses 

3 years 

Limitation Period for personal injury claims 

Medical records kept by reasons of the Substances Hazardous to Health Regulations 1999 

40 years 

The Control of Substances Hazardous to Health Regulations 1999 


Anonymised data does not have retention periods. We will not destroy data records pending audits, litigation, or investigations. 


Managing Partner - Delivery is responsible for securely disposing of data, including backups, and maintaining an audit trail. 


When challenging the retention of personal data, GDPR Article 17 (Right to erasure) or the equivalent sections in the DPA 2018 should be applied. When Railway Competence Group is legally obliged to process personal data or processing is necessary for us to perform our functions, the right to erasure does not apply. 


Breaches and Reporting

Any suspected or actual breaches of security or confidentiality will be reported to the appropriate authorities immediately. RCG will conduct an internal investigation and take appropriate actions to prevent further breaches and to protect the confidentiality of assessment materials. 


Training

All employees and contractors of RCG will receive regular training on data protection and retention, including the importance of maintaining data security and compliance with this policy. This training will cover topics such as data protection legislation, data access controls, data disposal procedures, and incident response procedures. 


Compliance

Failure to comply with this policy may result in non-compliance with Ofqual's conditions of recognition. RCG will conduct regular compliance audits to ensure that this policy is being followed and that all data is being retained, processed, and disposed of in compliance with relevant legislation and regulations. Annual compliance audit will be undertaken by the Managing Partner-Delivery. 


Penalties for Non-Compliance

Violations of this policy may result in disciplinary action, including but not limited to termination of employment or contract, and/or legal action. In addition, any third-party vendors or service providers found to be in violation of this policy may be terminated from their contract with RCG. 

Rail apprenticeships · Train driver psychometric testing

Let's discuss your requirements

Speak with our team about rail apprenticeships, apprenticeship assessment requirements or Train Driver Psychometric Testing.